Author Topic: Spyware ruined my Internet  (Read 3387 times)

Offline faraz

  • Jr. Member
  • **
  • Posts: 75
  • Karma: +0/-0
    • View Profile
Spyware ruined my Internet
« Reply #20 on: February 09, 2011, 03:28:18 AM »
SystemLook 04.09.10 by jpshortstuff
Log created at 13:22 on 09/02/2011 by ALI
Administrator - Elevation successful

========== filefind ==========

Searching for "tcpip.sys"
C:\WINDOWS\system32\drivers\tcpip.sys   --a---- 359040 bytes   [08:00 01/09/2004]   [08:00 01/09/2004] 7B11118B078B88F87183FE69EDA43137

Searching for "termsrv.dll"
No files found.

-= EOF =-

Offline faraz

  • Jr. Member
  • **
  • Posts: 75
  • Karma: +0/-0
    • View Profile
Spyware ruined my Internet
« Reply #21 on: February 10, 2011, 11:28:26 AM »
problem is still persisting...............and same is the case wid icon

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Spyware ruined my Internet
« Reply #22 on: February 13, 2011, 05:25:21 PM »
sorry for the delay
Delete your copy of ComboFix from desktop
I need you to download a fresh copy from the following link
[color="#0000FF"]Link 1[/color]
Save it ONLY to your Desktop[/color]

Afterwards
I've uploaded a file to Mediafire>>termsrv.dll
I need you to save the file to your C: drive, so you now have C:\termsrv.dll
from the following link
http://www.mediafire.com/?k5ym81ykp49ztrd
Note: If you happen to save the file in a different location, I need you to navigate to that location and copy/paste termsrv.dll directly to C: folder

Copy ALL the below in the Code box and paste to an empty notepad file
Don't use anything else than notepad or the script will not work
To open Notepad you can go to Start>Programs>> Accessories, and then clicking Notepad.


Code: [Select]
Netsvcs::
xeoeobt
File::
c:\windows\system32\wxjgwkd.dll
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3666:TCP"=-
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uavslubi]
"ServiceDll"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uavslubi]
FCopy::
C:\termsrv.dll | c:\windows\System32\termsrv.dll
Save this as txtfile on your desktop, with the exact name of
CFScript

Temporarily disable your AntiVirus/AntiSpyware software so it won't interfere with this next step
Again, temporarily disable Avast protections so they don't interfere


Drag CFScript.txt into ComboFix.exe
Combofix will start>>Follow the prompts
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

When finished, it shall produce a log for you  with the same name C:\ComboFix.txt..
I'll need to see that log again

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline faraz

  • Jr. Member
  • **
  • Posts: 75
  • Karma: +0/-0
    • View Profile
Spyware ruined my Internet
« Reply #23 on: February 20, 2011, 06:06:00 AM »
ComboFix 11-02-19.02 - ALI 02/20/2011  15:47:29.7.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.894.598 [GMT 5:00]
Running from: c:\documents and settings\ALI\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ALI\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Anti-Virus *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

FILE ::
"c:\windows\system32\wxjgwkd.dll"
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\termsrv.dll
c:\windows\system32\wxjgwkd.dll

.
--------------- FCopy ---------------

c:\termsrv.dll --> c:\windows\System32\termsrv.dll
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_keifb
-------\Legacy_uavslubi
-------\Service_keifb
-------\Service_uavslubi


(((((((((((((((((((((((((   Files Created from 2011-01-20 to 2011-02-20  )))))))))))))))))))))))))))))))
.

2011-02-20 10:25 . 2011-02-20 08:33   295424   ----a-w-   c:\windows\system32\termsrv.dll
2011-02-17 19:42 . 2004-04-30 04:33   5248   ----a-w-   c:\windows\system32\drivers\vax347s.sys
2011-02-17 19:42 . 2005-07-08 09:44   159616   ----a-w-   c:\windows\system32\drivers\vax347b.sys
2011-02-17 19:42 . 2011-02-17 19:42   --------   d-----w-   c:\program files\Alcohol Soft
2011-02-17 08:13 . 2011-02-17 08:15   --------   d-----w-   c:\program files\BomberMan Collection
2011-02-15 08:27 . 2011-02-15 08:27   --------   d-----w-   c:\windows\A5W_DATA
2011-02-07 06:33 . 2011-02-07 06:33   --------   d-sh--w-   c:\documents and settings\NetworkService\IETldCache
2011-02-03 18:45 . 2011-02-04 11:26   --------   d-----w-   c:\program files\Tiff To PDF Component
2011-02-03 09:25 . 2011-02-03 09:25   --------   d-----w-   c:\documents and settings\ALI\Application Data\IGC
2011-02-03 09:25 . 2003-05-28 08:19   245408   ------w-   c:\windows\system32\unicows.dll
2011-02-03 09:24 . 2011-02-03 09:24   --------   d-----w-   c:\program files\IGC
2011-02-03 09:10 . 2004-07-15 19:19   266240   ----a-w-   c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iscript.dll
2011-02-03 09:10 . 2004-07-15 19:18   172032   ----a-w-   c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iuser.dll
2011-02-03 09:10 . 2004-07-15 19:20   69715   ----a-w-   c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\ctor.dll
2011-02-03 09:10 . 2004-07-15 19:20   733184   ----a-w-   c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iKernel.dll
2011-02-03 09:10 . 2004-07-15 19:18   5632   ----a-w-   c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
2011-02-03 09:10 . 2011-02-03 09:10   180356   ----a-w-   c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iGdi.dll
2011-02-03 09:10 . 2011-02-03 09:10   303236   ----a-w-   c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\setup.dll
2011-02-03 08:48 . 2011-02-03 08:48   --------   d-----w-   c:\documents and settings\ALI\Local Settings\Application Data\Mozilla
2011-02-03 08:48 . 2011-02-03 08:49   --------   d-----w-   c:\program files\Mozilla Sunbird
2011-02-01 07:05 . 2011-02-01 07:05   --------   d-----w-   c:\documents and settings\ALI\Local Settings\Application Data\ACDSee
2011-02-01 07:05 . 2011-02-01 07:07   --------   d-----w-   c:\documents and settings\ALI\Application Data\ACD Systems
2011-02-01 07:03 . 2011-02-04 11:11   --------   d-----w-   c:\program files\Common Files\ACD Systems
2011-02-01 07:02 . 2011-02-01 07:02   --------   d-----w-   c:\windows\Downloaded Installations
2011-01-29 22:27 . 2004-05-26 16:06   417792   ----a-w-   c:\windows\system32\ac3filter.ax
2011-01-29 22:27 . 2004-01-11 10:02   258048   ----a-w-   c:\windows\system32\gplmpgdec.ax
2011-01-28 18:19 . 2011-01-29 09:41   --------   d-----w-   c:\documents and settings\ALI\Application Data\DivX
2011-01-28 18:16 . 2011-01-28 18:16   --------   d-----w-   c:\program files\Common Files\DivX Shared
2011-01-24 14:40 . 2011-01-24 14:40   --------   d-----w-   c:\program files\RAR Password Cracker
2011-01-24 14:38 . 2011-01-24 14:38   --------   d-----w-   c:\program files\PDF Password Remover v2.2
2011-01-24 10:50 . 2011-01-24 10:50   --------   d-----w-   c:\documents and settings\ALI\Local Settings\Application Data\Identities
2011-01-22 16:30 . 2011-01-22 16:30   --------   d-----w-   c:\program files\MSN Messenger
2011-01-22 10:24 . 2011-01-22 10:24   --------   d-----w-   c:\documents and settings\ALI\Local Settings\Application Data\Yahoo

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-25 20:18 . 2010-12-25 20:18   315392   ----a-w-   c:\windows\HideWin.exe
2010-12-20 13:09 . 2011-01-19 08:45   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 13:08 . 2011-01-19 08:45   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
.

------- Sigcheck -------

[-] 2004-09-01 . 7B11118B078B88F87183FE69EDA43137 . 359040 . . [5.1.2600.2180] . . c:\windows\system32\drivers\tcpip.sys

[-] 2011-02-20 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
.
(((((((((((((((((((((((((((((   SnapShot@2011-02-07_06.29.07   )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-17 19:42 . 2011-02-17 19:42   49152              c:\windows\Installer\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\IconE9F814236.exe
+ 2011-02-17 19:42 . 2011-02-17 19:42   5120              c:\windows\Installer\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\IconE9F814234.exe
+ 2007-01-04 09:26 . 2011-02-20 10:53   453920              c:\windows\system32\drivers\fidbox2.dat
+ 2011-02-17 19:42 . 2011-02-17 19:42   959488              c:\windows\Installer\55e74ab.msi
+ 2007-01-04 09:26 . 2011-02-20 10:53   27322656              c:\windows\system32\drivers\fidbox.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]

[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77245F75-3D8C-40CD-8F64-F9AA1388406F}]
2010-11-12 11:06   2646528   ------w-   c:\program files\TheChatPhone Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
2010-12-01 06:27   2735200   ----a-w-   c:\program files\Zynga\tbZyng.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]
"{01193D00-C7F9-4C26-92A2-1CA91F170068}"= "c:\program files\TheChatPhone Toolbar\tbcore3.dll" [2010-11-12 2646528]

[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]

[HKEY_CLASSES_ROOT\clsid\{01193d00-c7f9-4c26-92a2-1ca91f170068}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7B13EC3E-999A-4B70-B9CB-2617B8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]
"{01193D00-C7F9-4C26-92A2-1CA91F170068}"= "c:\program files\TheChatPhone Toolbar\tbcore3.dll" [2010-11-12 2646528]

[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]

[HKEY_CLASSES_ROOT\clsid\{01193d00-c7f9-4c26-92a2-1ca91f170068}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-12-25 3179952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe" [2007-10-05 230664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^ALI^Start Menu^Programs^Startup^Encarta Dictionary Quickshelf.lnk]
path=c:\documents and settings\ALI\Start Menu\Programs\Startup\Encarta Dictionary Quickshelf.lnk
backup=c:\windows\pss\Encarta Dictionary Quickshelf.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ALI^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\ALI\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-05 22:44   500208   ------w-   c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-21 23:57   406992   ----a-w-   c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
2007-10-05 11:18   230664   ----a-w-   c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivX Download Manager]
2010-12-08 21:15   63360   ----a-w-   c:\program files\DivX\DivX Plus Web Player\DDMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-01-10 23:25   1230704   ----a-w-   c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-12-26 08:17   136176   ----atw-   c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 19:47   31016   ----a-w-   c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-03 20:06   1667584   ------w-   c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 05:32   1479680   ----a-w-   c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 11:49   14940040   ----a-r-   c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 11:07   2260480   --sha-r-   c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-01-01 04:49   39408   ----a-w-   c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 08:37   517096   ----a-w-   c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R0 vax347b;vax347b;c:\windows\system32\drivers\vax347b.sys [2/18/2011 12:42 AM 159616]
R0 vax347s;vax347s;c:\windows\system32\drivers\vax347s.sys [2/18/2011 12:42 AM 5248]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/30/2007 6:49 PM 24344]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/1/2007 9:49 AM 136176]
S2 keifb;Installer Universal;c:\windows\system32\svchost.exe -k netsvcs [9/1/2004 1:00 PM 14336]
S2 uavslubi;Network Image;c:\windows\system32\svchost.exe -k netsvcs [9/1/2004 1:00 PM 14336]
S2 xeoeobt;Config Microsoft;c:\windows\system32\svchost.exe -k netsvcs [9/1/2004 1:00 PM 14336]
S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe [2/21/2007 5:26 PM 151552]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
xeoeobt
uavslubi
keifb

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-07 23:32   128512   ----a-w-   c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2011-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2007-01-01 04:49]

2011-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2007-01-01 04:49]

2011-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003Core.job
- c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-26 08:17]

2011-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003UA.job
- c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-26 08:17]

2011-02-20 c:\windows\Tasks\User_Feed_Synchronization-{D5E359FE-18D3-4EDA-90CF-4EE7AB928AD4}.job
- c:\windows\system32\msfeedssync.exe [2009-03-07 23:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://search.thechatphone.com
uSearchAssistant =
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: QuickDefine - c:\program files\Common Files\Microsoft Shared\Reference Titles\eddefine.htm
LSP: c:\windows\system32\idmmbc.dll
Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - c:\program files\Common Files\Microsoft Shared\Information Retrieval\itss51.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-20 15:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...  

scanning hidden autostart entries ...

scanning hidden files ...  

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\keifb]
"ServiceDll"="c:\windows\system32\wxjgwkd.dll"
--

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uavslubi]
"ServiceDll"="c:\windows\system32\wxjgwkd.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):bf,30,54,38,b7,c2,50,fb,0c,2d,86,33,90,5f,38,9c,4b,aa,0d,04,13,
   1b,a7,08,15,1b,18,b4,3e,3e,5f,28,a6,db,9d,3e,4b,a6,99,5a,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{80d28757-c52c-4bc2-b1b9-28e250ffaaf3}]
@Denied: (Full) (Everyone)
"Model"=dword:0000016b
"Therad"=dword:00000016
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
   38,95,44,51,c4,5c,06,a5,56,2b,b8,06,52,ef,38,3c,45,e2,58,83,e0,8b,c5,07,bb,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1100)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\klogon.dll

- - - - - - - > 'lsass.exe'(1156)
c:\windows\system32\idmmbc.dll

- - - - - - - > 'explorer.exe'(3696)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\scrchpg.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\windows\system32\wscntfy.exe
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2011-02-20  16:00:41 - machine was rebooted
ComboFix-quarantined-files.txt  2011-02-20 11:00
ComboFix2.txt  2011-02-09 09:49
ComboFix3.txt  2011-02-07 06:33

Pre-Run: 7,518,257,152 bytes free
Post-Run: 7,574,437,888 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 65976F3A927095766E65583A042477B4

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Spyware ruined my Internet
« Reply #24 on: February 20, 2011, 07:27:46 PM »
Can you delete CFScript.txt, we're going to redo that step
Copy ALL the below in the Code box and paste to an empty notepad file
Don't use anything else than notepad or the script will not work
To open Notepad you can go to Start>Programs>> Accessories, and then clicking Notepad.


Code: [Select]
NetSvc::
xeoeobt
uavslubi
keifb
Driver::
xeoeobt
uavslubi
keifb
File::
c:\windows\system32\wxjgwkd.dll
Registry::
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\keifb]
"ServiceDll"=-
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uavslubi]
"ServiceDll"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\keifb]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uavslubi]
Save this as txtfile on your desktop, with the exact name of
CFScript

Temporarily disable your AntiVirus/AntiSpyware software so it won't interfere with this next step
Again, temporarily disable Avast protections so they don't interfere


Drag CFScript.txt into ComboFix.exe
Combofix will start>>Follow the prompts
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

When finished, it shall produce a log for you  with the same name C:\ComboFix.txt..
I'll need to see that log again

keep me informed how things are now running please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline faraz

  • Jr. Member
  • **
  • Posts: 75
  • Karma: +0/-0
    • View Profile
Spyware ruined my Internet
« Reply #25 on: March 18, 2011, 01:37:59 AM »
[size="5"][color="#FF0000"]sorry 4 late reply ,i was away from city.................[/color][/size]




**************************************************************************

ComboFix 11-03-14.06 - ALI 03/18/2011  11:20:36.8.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.894.533 [GMT 5:00]
Running from: c:\documents and settings\ALI\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ALI\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Anti-Virus *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
FILE ::
"c:\windows\system32\wxjgwkd.dll"
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_KEIFB
-------\Legacy_UAVSLUBI
-------\Legacy_XEOEOBT
-------\Service_keifb
-------\Service_uavslubi
-------\Service_xeoeobt
.
.
(((((((((((((((((((((((((   Files Created from 2011-02-18 to 2011-03-18  )))))))))))))))))))))))))))))))
.
.
2011-03-01 12:10 . 2003-05-14 16:07   389120   ----a-w-   c:\windows\system32\actskn43.ocx
2011-03-01 12:10 . 2011-03-01 12:10   --------   d-----w-   c:\program files\Audio File Cutter
2011-03-01 12:10 . 2000-05-21 19:00   608448   ----a-w-   c:\windows\system32\Comctl32.ocx
2011-02-28 17:23 . 2011-02-28 17:23   --------   d-----w-   C:\training
2011-02-28 17:23 . 2011-02-28 17:23   --------   d-----w-   C:\Photoshop
2011-02-24 06:43 . 2011-02-24 06:43   --------   d--h--w-   c:\windows\PIF
2011-02-21 07:11 . 2011-02-21 07:11   286720   ----a-w-   c:\windows\iun503.exe
2011-02-21 07:11 . 2011-02-21 07:11   --------   d-----w-   c:\program files\TEKKEN 3
2011-02-20 10:25 . 2011-02-20 08:33   295424   ----a-w-   c:\windows\system32\termsrv.dll
2011-02-17 19:42 . 2004-04-30 04:33   5248   ----a-w-   c:\windows\system32\drivers\vax347s.sys
2011-02-17 19:42 . 2005-07-08 09:44   159616   ----a-w-   c:\windows\system32\drivers\vax347b.sys
2011-02-17 19:42 . 2011-02-17 19:42   --------   d-----w-   c:\program files\Alcohol Soft
2011-02-17 08:13 . 2011-02-17 08:15   --------   d-----w-   c:\program files\BomberMan Collection
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-25 20:18 . 2010-12-25 20:18   315392   ----a-w-   c:\windows\HideWin.exe
2010-12-20 13:09 . 2011-01-19 08:45   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 13:08 . 2011-01-19 08:45   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
.
.
(((((((((((((((((((((((((((((   SnapShot@2011-02-07_06.29.07   )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-17 19:42 . 2011-02-17 19:42   49152              c:\windows\Installer\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\IconE9F814236.exe
+ 2011-02-17 19:42 . 2011-02-17 19:42   5120              c:\windows\Installer\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\IconE9F814234.exe
+ 2007-01-04 09:26 . 2011-03-18 06:25   918304              c:\windows\system32\drivers\fidbox2.dat
+ 2011-02-17 19:42 . 2011-02-17 19:42   959488              c:\windows\Installer\55e74ab.msi
+ 2007-01-04 09:26 . 2011-03-18 06:25   34746912              c:\windows\system32\drivers\fidbox.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77245F75-3D8C-40CD-8F64-F9AA1388406F}]
2010-11-12 11:06   2646528   ------w-   c:\program files\TheChatPhone Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
2010-12-01 06:27   2735200   ----a-w-   c:\program files\Zynga\tbZyng.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]
"{01193D00-C7F9-4C26-92A2-1CA91F170068}"= "c:\program files\TheChatPhone Toolbar\tbcore3.dll" [2010-11-12 2646528]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_CLASSES_ROOT\clsid\{01193d00-c7f9-4c26-92a2-1ca91f170068}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7B13EC3E-999A-4B70-B9CB-2617B8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]
"{01193D00-C7F9-4C26-92A2-1CA91F170068}"= "c:\program files\TheChatPhone Toolbar\tbcore3.dll" [2010-11-12 2646528]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_CLASSES_ROOT\clsid\{01193d00-c7f9-4c26-92a2-1ca91f170068}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-12-25 3179952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe" [2007-10-05 230664]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^ALI^Start Menu^Programs^Startup^Encarta Dictionary Quickshelf.lnk]
path=c:\documents and settings\ALI\Start Menu\Programs\Startup\Encarta Dictionary Quickshelf.lnk
backup=c:\windows\pss\Encarta Dictionary Quickshelf.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^ALI^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\ALI\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-05 22:44   500208   ------w-   c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-21 23:57   406992   ----a-w-   c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
2007-10-05 11:18   230664   ----a-w-   c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivX Download Manager]
2010-12-08 21:15   63360   ----a-w-   c:\program files\DivX\DivX Plus Web Player\DDMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-01-10 23:25   1230704   ----a-w-   c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-12-26 08:17   136176   ----atw-   c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 19:47   31016   ----a-w-   c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-03 20:06   1667584   ------w-   c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 05:32   1479680   ----a-w-   c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 11:49   14940040   ----a-r-   c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 11:07   2260480   --sha-r-   c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-01-01 04:49   39408   ----a-w-   c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 08:37   517096   ----a-w-   c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3666:TCP"= 3666:TCP:pqhtmzbg
.
R0 vax347b;vax347b;c:\windows\system32\drivers\vax347b.sys [2/18/2011 12:42 AM 159616]
R0 vax347s;vax347s;c:\windows\system32\drivers\vax347s.sys [2/18/2011 12:42 AM 5248]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/30/2007 6:49 PM 24344]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/1/2007 9:49 AM 136176]
S2 qxyozne;Support Task;c:\windows\system32\svchost.exe -k netsvcs [9/1/2004 1:00 PM 14336]
S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe [2/21/2007 5:26 PM 151552]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
qxyozne
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-07 23:32   128512   ----a-w-   c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-12 c:\windows\Tasks\AdobeAAMUpdater-1.0-MAGMA-ALI.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-01-03 22:44]
.
2011-03-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2007-01-01 04:49]
.
2011-03-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2007-01-01 04:49]
.
2011-03-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003Core.job
- c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-26 08:17]
.
2011-03-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003UA.job
- c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-26 08:17]
.
2011-03-18 c:\windows\Tasks\User_Feed_Synchronization-{D5E359FE-18D3-4EDA-90CF-4EE7AB928AD4}.job
- c:\windows\system32\msfeedssync.exe [2009-03-07 23:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://search.thechatphone.com
uSearchAssistant =
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: QuickDefine - c:\program files\Common Files\Microsoft Shared\Reference Titles\eddefine.htm
LSP: c:\windows\system32\idmmbc.dll
Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - c:\program files\Common Files\Microsoft Shared\Information Retrieval\itss51.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-18 11:28
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ...
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qxyozne]
"ServiceDll"="c:\windows\system32\wxjgwkd.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):bf,30,54,38,b7,c2,50,fb,0c,2d,86,33,90,5f,38,9c,4b,aa,0d,04,13,
   1b,a7,08,15,1b,18,b4,3e,3e,5f,28,a6,db,9d,3e,4b,a6,99,5a,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{80d28757-c52c-4bc2-b1b9-28e250ffaaf3}]
@Denied: (Full) (Everyone)
"Model"=dword:0000016b
"Therad"=dword:00000016
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
   38,95,44,eb,6d,27,42,80,c2,b8,87,b7,e9,22,b2,b5,0c,95,0d,83,e0,8b,c5,07,bb,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1100)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\klogon.dll
.
- - - - - - - > 'lsass.exe'(1156)
c:\windows\system32\idmmbc.dll
.
- - - - - - - > 'explorer.exe'(3968)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\scrchpg.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2011-03-18  11:32:50 - machine was rebooted
ComboFix-quarantined-files.txt  2011-03-18 06:32
ComboFix2.txt  2011-02-20 11:00
ComboFix3.txt  2011-02-09 09:49
ComboFix4.txt  2011-02-07 06:33
.
Pre-Run: 2,288,766,976 bytes free
Post-Run: 2,616,303,616 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 54D88BD7E205BE2B33CE1777E499197A

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Spyware ruined my Internet
« Reply #26 on: March 19, 2011, 11:07:44 AM »
Delete your copy of ComboFix and delete CFScript.txt from desktop, we're again going to redo that step

Redownload a fresh copy of ComboFix from the following link
[color="#0000FF"]Link 1[/color]
Save it ONLY to your Desktop

Copy ALL the below in the Code box and paste to an empty notepad file
Don't use anything else than notepad or the script will not work
To open Notepad you can go to Start>Programs>> Accessories, and then clicking Notepad.


Code: [Select]
Netsvcs::
qxyozne
Driver::
qxyozne
File::
c:\windows\system32\wxjgwkd.dll
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3666:TCP"=-
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qxyozne]
"ServiceDll"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qxyozne]
FCopy::
C:\termsrv.dll | c:\windows\System32\termsrv.dll
Save this as txtfile on your desktop, with the exact name of
CFScript

Temporarily disable your AntiVirus/AntiSpyware software so it won't interfere with this next step



Drag CFScript.txt into ComboFix.exe
Combofix will start>>Follow the prompts
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

When finished, it shall produce a log for you  with the same name C:\ComboFix.txt..
I'll need to see that log again

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline faraz

  • Jr. Member
  • **
  • Posts: 75
  • Karma: +0/-0
    • View Profile
Spyware ruined my Internet
« Reply #27 on: April 12, 2011, 11:51:30 AM »
ComboFix 11-04-11.04 - ALI 04/12/2011  21:34:44.9.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.894.482 [GMT 5:00]
Running from: c:\documents and settings\ALI\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ALI\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Anti-Virus *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
 * Created a new restore point
.
FILE ::
"c:\windows\system32\wxjgwkd.dll"
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\ALI\Application Data\facemoods.com
c:\documents and settings\ALI\WINDOWS
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.4.17.5\bh\facemoods.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoods.crx
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoods.png
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsApp.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsEng.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsTlbr.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\uninstall.exe
c:\program files\facemoods.com\sqlite3.dll
C:\termsrv.dll
.
.
--------------- FCopy ---------------
.
c:\termsrv.dll --> c:\windows\System32\termsrv.dll
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_QXYOZNE
-------\Service_qxyozne
.
.
(((((((((((((((((((((((((   Files Created from 2011-03-12 to 2011-04-12  )))))))))))))))))))))))))))))))
.
.
2011-04-10 22:03 . 2011-04-10 22:03   --------   d-----w-   c:\program files\FreeGamePick.com
2011-04-05 08:11 . 2011-04-05 08:11   --------   d-----w-   C:\control
2011-04-04 07:50 . 2011-04-10 22:48   --------   d-----w-   c:\program files\Pocket Tanks Deluxe
2011-04-02 10:43 . 2011-04-02 10:43   --------   d-----w-   c:\program files\All Video Joiner
2011-03-29 11:43 . 2011-03-29 11:43   --------   d-----w-   c:\program files\uTorrent
2011-03-24 15:33 . 2011-03-24 15:33   --------   d-----w-   c:\documents and settings\ALI\Application Data\GRETECH
2011-03-24 15:28 . 2011-03-24 15:28   --------   d-----w-   c:\program files\GRETECH
2011-03-22 17:42 . 2011-03-22 17:42   --------   d-----w-   c:\documents and settings\ALI\Local Settings\Application Data\ALLConverter
2011-03-22 17:42 . 2011-03-22 17:42   --------   d-----w-   c:\program files\ALLConverter PRO
2011-03-22 17:42 . 2011-03-22 17:48   --------   d-----w-   c:\documents and settings\ALI\Local Settings\Application Data\ALLPlayer
2011-03-22 17:41 . 2007-10-07 09:36   258048   ----a-w-   c:\windows\system32\libFLAC.dll
2011-03-22 17:41 . 2011-03-22 17:42   --------   d-----w-   c:\program files\OpenSubtitlesPlayer
2011-03-22 05:45 . 2011-03-22 05:45   --------   d-----w-   c:\windows\system32\wbem\Repository
2011-03-21 06:08 . 1998-07-30 07:51   305152   ----a-w-   c:\windows\IsUninst.exe
2011-03-18 10:29 . 2011-03-18 10:29   --------   d-----w-   c:\documents and settings\ALI\IGC
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-21 07:11 . 2011-02-21 07:11   286720   ----a-w-   c:\windows\iun503.exe
2011-02-20 08:33 . 2011-02-20 10:25   295424   ----a-w-   c:\windows\system32\termsrv.dll
.
.
------- Sigcheck -------
.
[-] 2004-09-01 . 7B11118B078B88F87183FE69EDA43137 . 359040 . . [5.1.2600.2180] . . c:\windows\system32\drivers\tcpip.sys
.
[-] 2011-02-20 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
.
(((((((((((((((((((((((((((((   SnapShot@2011-02-07_06.29.07   )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-22 05:43 . 2011-03-22 05:47   25852              c:\windows\system32\Restore\rstrlog.dat
+ 2011-03-26 06:21 . 2011-03-26 06:21   6820              c:\windows\system32\d3d9caps.dat
+ 2010-12-25 20:25 . 2010-12-07 14:22   810496              c:\windows\system32\xvidcore.dll
+ 2011-04-01 07:10 . 2011-04-01 07:10   235168              c:\windows\system32\Macromed\Flash\FlashUtil10o_ActiveX.exe
+ 2011-04-01 07:10 . 2011-04-01 07:10   311456              c:\windows\system32\Macromed\Flash\FlashUtil10o_ActiveX.dll
+ 2007-01-04 09:26 . 2011-04-12 16:40   992288              c:\windows\system32\drivers\fidbox2.dat
+ 2011-03-21 17:02 . 2011-03-21 17:02   4792320              c:\windows\system32\config\systemprofile\ntuser.dat
+ 2007-01-04 09:26 . 2011-04-12 16:40   39153440              c:\windows\system32\drivers\fidbox.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77245F75-3D8C-40CD-8F64-F9AA1388406F}]
2010-11-12 11:06   2646528   ------w-   c:\program files\TheChatPhone Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
2010-12-01 06:27   2735200   ----a-w-   c:\program files\Zynga\tbZyng.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]
"{01193D00-C7F9-4C26-92A2-1CA91F170068}"= "c:\program files\TheChatPhone Toolbar\tbcore3.dll" [2010-11-12 2646528]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_CLASSES_ROOT\clsid\{01193d00-c7f9-4c26-92a2-1ca91f170068}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7B13EC3E-999A-4B70-B9CB-2617B8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200]
"{01193D00-C7F9-4C26-92A2-1CA91F170068}"= "c:\program files\TheChatPhone Toolbar\tbcore3.dll" [2010-11-12 2646528]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_CLASSES_ROOT\clsid\{01193d00-c7f9-4c26-92a2-1ca91f170068}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB02381.TBSB02381]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-12-25 3179952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe" [2007-10-05 230664]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^ALI^Start Menu^Programs^Startup^Encarta Dictionary Quickshelf.lnk]
path=c:\documents and settings\ALI\Start Menu\Programs\Startup\Encarta Dictionary Quickshelf.lnk
backup=c:\windows\pss\Encarta Dictionary Quickshelf.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^ALI^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\ALI\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-05 22:44   500208   ------w-   c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-21 23:57   406992   ----a-w-   c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALLUpdate]
2011-02-26 18:11   1022464   ----a-w-   c:\program files\OpenSubtitlesPlayer\ALLUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivX Download Manager]
2010-12-08 21:15   63360   ----a-w-   c:\program files\DivX\DivX Plus Web Player\DDMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-01-10 23:25   1230704   ----a-w-   c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-12-26 08:17   136176   ----atw-   c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 19:47   31016   ----a-w-   c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-03 20:06   1667584   ------w-   c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 05:32   1479680   ----a-w-   c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 11:49   14940040   ----a-r-   c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 11:07   2260480   --sha-r-   c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-01-01 04:49   39408   ----a-w-   c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 08:37   517096   ----a-w-   c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/30/2007 6:49 PM 24344]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/1/2007 9:49 AM 136176]
S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe [2/21/2007 5:26 PM 151552]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-07 23:32   128512   ----a-w-   c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-11 c:\windows\Tasks\AdobeAAMUpdater-1.0-MAGMA-ALI.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-01-03 22:44]
.
2011-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2007-01-01 04:49]
.
2011-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2007-01-01 04:49]
.
2011-04-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003Core.job
- c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-26 08:17]
.
2011-04-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003UA.job
- c:\documents and settings\ALI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-26 08:17]
.
2011-04-12 c:\windows\Tasks\User_Feed_Synchronization-{D5E359FE-18D3-4EDA-90CF-4EE7AB928AD4}.job
- c:\windows\system32\msfeedssync.exe [2009-03-07 23:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://search.thechatphone.com
uSearchAssistant =
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: QuickDefine - c:\program files\Common Files\Microsoft Shared\Reference Titles\eddefine.htm
LSP: c:\windows\system32\idmmbc.dll
Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - c:\program files\Common Files\Microsoft Shared\Information Retrieval\itss51.dll
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files\facemoods.com\facemoods\1.4.17.5\bh\facemoods.dll
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsTlbr.dll
MSConfigStartUp-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-12 21:42
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ...
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):bf,30,54,38,b7,c2,50,fb,0c,2d,86,33,90,5f,38,9c,4b,aa,0d,04,13,
   1b,a7,08,15,1b,18,b4,3e,3e,5f,28,a6,db,9d,3e,4b,a6,99,5a,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{80d28757-c52c-4bc2-b1b9-28e250ffaaf3}]
@Denied: (Full) (Everyone)
"Model"=dword:0000016b
"Therad"=dword:00000016
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
   38,95,44,eb,6d,27,42,80,c2,b8,87,b7,e9,22,b2,b5,0c,95,0d,83,e0,8b,c5,07,bb,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(784)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\klogon.dll
.
- - - - - - - > 'lsass.exe'(840)
c:\windows\system32\idmmbc.dll
.
- - - - - - - > 'explorer.exe'(588)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\scrchpg.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2011-04-12  21:48:08 - machine was rebooted
ComboFix-quarantined-files.txt  2011-04-12 16:48
ComboFix2.txt  2011-03-18 06:32
ComboFix3.txt  2011-02-20 11:00
ComboFix4.txt  2011-02-09 09:49
ComboFix5.txt  2011-04-12 16:33
.
Pre-Run: 2,630,664,192 bytes free
Post-Run: 2,706,141,184 bytes free
.
Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - E6EBF0D6365DC6D47C6D5FA21DC436DD

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Spyware ruined my Internet
« Reply #28 on: April 12, 2011, 01:07:02 PM »
How are things running now?
You are waiting too long between replies, I'll lock this topic in a few days if you don't return

Since it's been so long, can you delete your copy of OTL.exe
REDownload [color="#FF0000"]OTL.exe[/color][/url] by OldTimer to your Desktop.
  • Close all windows and double click on OTL.exe to run it
  • Select "Use Safelist" under 'Extra Registry'
  • Click Run Scan and let the program run uninterrupted.
  • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline faraz

  • Jr. Member
  • **
  • Posts: 75
  • Karma: +0/-0
    • View Profile
Spyware ruined my Internet
« Reply #29 on: April 13, 2011, 08:45:33 AM »
[size="4"][color="#0000FF"]Sory i was checking whether system works normaly or not..................[/color][/size]
[size="4"][color="#0000FF"]
[/color][/size]

[size="4"][color="#0000FF"]But after the last run of combofix with script you have mentioned.............Problem arises again[/color][/size]
here the logs
******************************************************************************************************************

OTL logfile created on: 4/13/2011 6:35:11 PM - Run 5
OTL by OldTimer - Version 3.2.22.3     Folder = C:\Documents and Settings\ALI\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
894.00 Mb Total Physical Memory | 631.00 Mb Available Physical Memory | 71.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25.00 Gb Total Space | 1.25 Gb Free Space | 4.99% Space Free | Partition Type: NTFS
Drive D: | 25.00 Gb Total Space | 2.53 Gb Free Space | 10.13% Space Free | Partition Type: NTFS
Drive E: | 49.70 Gb Total Space | 1.61 Gb Free Space | 3.23% Space Free | Partition Type: NTFS
Drive F: | 49.34 Gb Total Space | 1.65 Gb Free Space | 3.34% Space Free | Partition Type: NTFS
Drive G: | 6.34 Gb Total Space | 0.59 Gb Free Space | 9.36% Space Free | Partition Type: FAT32
Drive H: | 12.64 Gb Total Space | 6.53 Gb Free Space | 51.67% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 12.97 Gb Free Space | 4.35% Space Free | Partition Type: NTFS
 
Computer Name: MAGMA | User Name: ALI | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011/04/13 15:24:13 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALI\Desktop\OTL.exe
PRC - [2010/12/26 01:31:49 | 003,179,952 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2010/11/12 16:06:50 | 000,197,632 | ---- | M] () -- C:\Program Files\TheChatPhone Toolbar\TbHelper2.exe
PRC - [2009/10/15 14:51:51 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2008/11/10 01:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/10/05 16:18:50 | 000,230,664 | ---- | M] (Kaspersky Lab) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
PRC - [2004/09/01 13:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011/04/13 15:24:13 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALI\Desktop\OTL.exe
MOD - [2009/03/26 20:35:39 | 000,034,224 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\idmmkb.dll
MOD - [2004/09/01 13:00:00 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Disabled | Stopped] --  -- (HidServ)
SRV - [2010/06/14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2008/11/10 01:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2007/10/05 16:18:50 | 000,230,664 | ---- | M] (Kaspersky Lab) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe -- (AVP)
SRV - [2007/02/21 17:26:40 | 000,151,552 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe -- (bepldr)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2010/02/26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/02/26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/02/26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009/03/25 14:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/10/05 14:48:04 | 000,190,736 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (klif)
DRV - [2007/07/18 15:39:54 | 000,110,096 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (kl1)
DRV - [2007/05/30 18:49:06 | 000,024,344 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2007/03/26 16:21:06 | 004,395,008 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/02/03 01:03:24 | 001,975,296 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/06/18 23:37:34 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004/08/13 23:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.thechatphone.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: [email protected]:1.2009p
FF - prefs.js..extensions.enabledItems: {e2fda1a4-762b-4020-b5ad-a41df1933103}:1.0b1
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/28 23:19:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/28 23:19:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files\Mozilla Sunbird\components [2011/02/03 13:48:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files\Mozilla Sunbird\plugins
 
[2011/02/03 13:49:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ALI\Application Data\Mozilla\Extensions
[2011/02/03 13:49:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ALI\Application Data\Mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28}
[2011/02/03 13:49:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ALI\Application Data\Mozilla\Sunbird\Profiles\02738zse.default\extensions
[2011/02/03 13:48:42 | 000,000,000 | ---D | M] (Lightning stub extension for Sunbird) -- C:\PROGRAM FILES\MOZILLA SUNBIRD\EXTENSIONS\{E2FDA1A4-762B-4020-B5AD-A41DF1933103}
[2011/02/03 13:48:42 | 000,000,000 | ---D | M] (Timezone Definitions for Mozilla Calendar) -- C:\PROGRAM FILES\MOZILLA SUNBIRD\EXTENSIONS\[email protected]
[2011/03/22 22:45:06 | 000,002,048 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchostpl.xml
 
O1 HOSTS File: ([2011/04/12 21:41:54 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (TBSB02381 Class) - {77245F75-3D8C-40CD-8F64-F9AA1388406F} - C:\Program Files\TheChatPhone Toolbar\tbcore3.dll ()
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files\OpenSubtitlesPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (TheChatPhone Toolbar) - {01193D00-C7F9-4C26-92A2-1CA91F170068} - C:\Program Files\TheChatPhone Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (TheChatPhone Toolbar) - {01193D00-C7F9-4C26-92A2-1CA91F170068} - C:\Program Files\TheChatPhone Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [UserFaultCheck]  File not found
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\ie_banner_deny.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: QuickDefine - C:\Program Files\Common Files\Microsoft Shared\Reference Titles\eddefine.htm ()
O9 - Extra Button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\SCIEPlgn.dll (Kaspersky Lab)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Documents and Settings\ALI\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ALI\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/12/25 23:49:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/04/13 15:24:02 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ALI\Desktop\OTL.exe
[2011/04/12 22:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentBar
[2011/04/12 22:03:33 | 000,000,000 | ---D | C] -- C:\extensions
[2011/04/12 21:50:28 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/04/12 21:48:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/04/11 03:03:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FreeGamePick.com
[2011/04/11 03:03:00 | 000,000,000 | ---D | C] -- C:\Program Files\FreeGamePick.com
[2011/04/09 11:43:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Start Menu\Programs\MYIE2
[2011/04/08 12:47:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\ALI\Recent
[2011/04/05 13:11:50 | 000,000,000 | ---D | C] -- C:\control
[2011/04/04 12:50:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Pocket Tanks Deluxe
[2011/04/04 12:50:53 | 000,000,000 | ---D | C] -- C:\Program Files\Pocket Tanks Deluxe
[2011/04/02 15:43:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\All Video Joiner
[2011/04/02 15:43:31 | 000,000,000 | ---D | C] -- C:\Program Files\All Video Joiner
[2011/04/01 12:08:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/03/30 12:29:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Desktop\2011 Muzik
[2011/03/29 16:43:15 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2011/03/27 16:50:58 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/03/24 20:33:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\My Documents\GomPlayer
[2011/03/24 20:33:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Application Data\GRETECH
[2011/03/24 20:29:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GOM Player
[2011/03/24 20:28:48 | 000,000,000 | ---D | C] -- C:\Program Files\GRETECH
[2011/03/23 22:16:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Desktop\Den
[2011/03/22 22:43:15 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/03/22 22:42:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ALLConverter PRO
[2011/03/22 22:42:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Local Settings\Application Data\ALLConverter
[2011/03/22 22:42:44 | 000,000,000 | ---D | C] -- C:\Program Files\ALLConverter PRO
[2011/03/22 22:42:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\OpenSubtitlesPlayer
[2011/03/22 22:42:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Local Settings\Application Data\ALLPlayer
[2011/03/22 22:41:12 | 000,000,000 | ---D | C] -- C:\Program Files\OpenSubtitlesPlayer
[2011/03/21 11:08:30 | 000,305,152 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2011/03/18 15:29:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\IGC
[2011/03/18 11:19:45 | 000,000,000 | RHSD | C] -- C:\cmdcons
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011/04/13 18:31:54 | 039,447,328 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2011/04/13 18:23:01 | 000,000,970 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003UA.job
[2011/04/13 18:02:03 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/13 15:35:50 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D5E359FE-18D3-4EDA-90CF-4EE7AB928AD4}.job
[2011/04/13 15:28:09 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/13 15:24:13 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALI\Desktop\OTL.exe
[2011/04/13 15:18:11 | 000,000,876 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/13 15:18:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/13 15:18:05 | 937,938,944 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/13 15:13:16 | 000,992,288 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2011/04/13 15:13:16 | 000,556,028 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2011/04/13 15:13:16 | 000,109,940 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.idx
[2011/04/13 02:00:00 | 000,000,338 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-MAGMA-ALI.job
[2011/04/12 23:38:44 | 000,014,590 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Don_t_be_afraid_of_the_dark_Eng_2011_DVDrip_XvID-[Fenopy.eu].torrent
[2011/04/12 22:05:01 | 000,016,773 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\The.Girl.With.The.Dragon.Tattoo[2009]DvDrip-aXXo.5670645.TPB.torrent
[2011/04/12 22:01:51 | 000,000,651 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/04/12 22:00:49 | 000,033,770 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\26A4D05CA746E2A4DA00180181965311ABCF04C6.torrent
[2011/04/12 21:58:01 | 000,028,534 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Don__039_t_Be_Afraid_of_The_Dark_DVD_rip_avi.torrent
[2011/04/12 21:41:54 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/12 16:09:41 | 000,035,295 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Fraz Ali _CV latest.pdf
[2011/04/12 15:44:04 | 001,428,174 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\165621710161870_32760.mp4
[2011/04/12 02:44:25 | 010,488,748 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\137651706308368_25484.mp4
[2011/04/12 01:50:18 | 000,028,160 | ---- | M] () -- C:\Documents and Settings\ALI\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/11 13:23:02 | 000,000,918 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003Core.job
[2011/04/11 03:03:02 | 000,001,783 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Chess Mafia.lnk
[2011/04/10 15:54:36 | 000,470,601 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\IELTS Preparation Tips.mht
[2011/04/09 15:23:51 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/09 11:43:36 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\MYIE2.lnk
[2011/04/07 11:13:42 | 000,032,721 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\DP_AnnualAccounts_2009.pdf
[2011/04/06 13:57:03 | 000,447,676 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\232.pdf
[2011/04/05 13:14:12 | 000,000,926 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to edict.lnk
[2011/04/05 02:27:42 | 000,156,547 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\assessment-levels.pdf
[2011/04/04 12:50:58 | 000,000,750 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Pocket Tanks Deluxe.lnk
[2011/04/02 15:43:37 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\All Video Joiner.lnk
[2011/04/02 00:57:47 | 000,966,016 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\IELTSApplicationFormNovember2010.pdf
[2011/04/01 14:15:27 | 000,000,339 | RHS- | M] () -- C:\boot.ini
[2011/03/27 20:39:16 | 000,065,649 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\scan0114.jpg
[2011/03/26 19:55:49 | 000,865,555 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\AEO Newsletter 1-2011.pdf
[2011/03/26 11:21:37 | 000,006,820 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/03/24 20:29:24 | 000,000,783 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2011/03/23 21:41:40 | 000,094,639 | ---- | M] () -- C:\Documents and Settings\ALI\My Documents\Technical-Jobs-in-Islamabad-Based-Construction-Company.jpg
[2011/03/22 22:42:49 | 000,000,794 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\ALLConverter PRO.lnk
[2011/03/22 22:42:49 | 000,000,776 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ALLConverter PRO.lnk
[2011/03/22 22:42:22 | 000,001,671 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\OpenSubtitlesPlayer V4.6.lnk
[2011/03/22 22:42:22 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\OpenSubtitlesPlayer V4.6.lnk
[2011/03/18 11:15:30 | 000,000,339 | ---- | M] () -- C:\Boot.bak
[2011/03/17 11:34:37 | 000,334,731 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Techlogix-Pakistan-Jobs.JPG
[2011/03/17 11:34:07 | 000,495,072 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Pizza-Hut-Pakistan-Jobs.JPG
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011/04/12 23:38:43 | 000,014,590 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Don_t_be_afraid_of_the_dark_Eng_2011_DVDrip_XvID-[Fenopy.eu].torrent
[2011/04/12 22:05:01 | 000,016,773 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\The.Girl.With.The.Dragon.Tattoo[2009]DvDrip-aXXo.5670645.TPB.torrent
[2011/04/12 22:00:49 | 000,033,770 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\26A4D05CA746E2A4DA00180181965311ABCF04C6.torrent
[2011/04/12 21:58:00 | 000,028,534 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Don__039_t_Be_Afraid_of_The_Dark_DVD_rip_avi.torrent
[2011/04/12 16:10:39 | 000,035,295 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Fraz Ali _CV latest.pdf
[2011/04/12 15:43:31 | 001,428,174 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\165621710161870_32760.mp4
[2011/04/12 02:41:29 | 010,488,748 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\137651706308368_25484.mp4
[2011/04/11 03:03:02 | 000,001,783 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Chess Mafia.lnk
[2011/04/10 15:54:27 | 000,470,601 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\IELTS Preparation Tips.mht
[2011/04/09 11:43:36 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\MYIE2.lnk
[2011/04/07 11:13:42 | 000,032,721 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\DP_AnnualAccounts_2009.pdf
[2011/04/06 13:56:53 | 000,447,676 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\232.pdf
[2011/04/05 13:14:12 | 000,000,926 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to edict.lnk
[2011/04/05 02:27:20 | 000,156,547 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\assessment-levels.pdf
[2011/04/04 12:50:58 | 000,000,750 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Pocket Tanks Deluxe.lnk
[2011/04/02 15:43:37 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\All Video Joiner.lnk
[2011/04/02 00:56:08 | 000,966,016 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\IELTSApplicationFormNovember2010.pdf
[2011/03/29 16:43:16 | 000,000,651 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/03/27 20:39:25 | 000,065,649 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\scan0114.jpg
[2011/03/26 19:55:29 | 000,865,555 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\AEO Newsletter 1-2011.pdf
[2011/03/26 11:21:37 | 000,006,820 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/03/24 20:29:24 | 000,000,783 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2011/03/23 21:39:08 | 000,094,639 | ---- | C] () -- C:\Documents and Settings\ALI\My Documents\Technical-Jobs-in-Islamabad-Based-Construction-Company.jpg
[2011/03/22 22:42:49 | 000,000,794 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\ALLConverter PRO.lnk
[2011/03/22 22:42:49 | 000,000,776 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ALLConverter PRO.lnk
[2011/03/22 22:42:22 | 000,001,671 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\OpenSubtitlesPlayer V4.6.lnk
[2011/03/22 22:42:22 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\OpenSubtitlesPlayer V4.6.lnk
[2011/03/22 22:41:56 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\libFLAC.dll
[2011/03/22 10:53:22 | 937,938,944 | -HS- | C] () -- C:\hiberfil.sys
[2011/03/17 11:34:37 | 000,334,731 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Techlogix-Pakistan-Jobs.JPG
[2011/03/17 11:34:07 | 000,495,072 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Pizza-Hut-Pakistan-Jobs.JPG
[2011/02/22 15:49:08 | 000,042,379 | ---- | C] () -- C:\WINDOWS\convfac.ini
[2011/02/22 15:49:08 | 000,014,775 | ---- | C] () -- C:\WINDOWS\convit.ini
[2011/02/15 13:27:23 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2011/02/07 11:12:22 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/02/07 11:12:22 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/02/07 11:12:22 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/02/07 11:12:22 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/02/07 11:12:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/02/06 17:18:44 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\FreeImage3.dll
[2011/02/06 17:18:44 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\FreeImage.dll
[2011/02/06 17:18:44 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\DVM.dll
[2011/02/06 17:18:43 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\RegisterExe.exe
[2011/01/24 19:39:08 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\pwdremover.dat
[2011/01/24 19:39:08 | 000,000,036 | ---- | C] () -- C:\WINDOWS\verypdf.ini
[2011/01/21 16:11:39 | 000,000,070 | ---- | C] () -- C:\WINDOWS\GECKOS.INI
[2011/01/14 17:09:27 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
[2011/01/14 17:09:27 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
[2011/01/14 17:09:27 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\unacev2.dll
[2011/01/14 17:09:26 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar3.dll
[2011/01/14 15:59:21 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll.old
[2011/01/08 17:52:27 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/12/26 01:35:27 | 000,028,160 | ---- | C] () -- C:\Documents and Settings\ALI\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/26 01:31:02 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/12/26 01:28:18 | 003,568,328 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/26 01:26:00 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/12/26 01:25:58 | 000,810,496 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/12/26 01:25:58 | 000,568,850 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2010/12/26 01:25:58 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/12/26 01:25:57 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010/12/26 01:25:56 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/12/26 01:25:55 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2010/12/26 01:19:12 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2010/12/26 01:17:48 | 000,021,896 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2010/12/26 01:11:37 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010/12/26 01:09:03 | 003,107,788 | R--- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2010/12/26 01:09:03 | 000,128,813 | R--- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010/12/26 01:08:01 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/12/26 01:07:56 | 000,021,582 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010/12/26 01:07:44 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/12/25 23:51:56 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/12/25 23:46:12 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2007/10/05 16:18:24 | 000,013,924 | ---- | C] () -- C:\WINDOWS\System32\drivers\klop.dat
[2007/01/04 14:26:24 | 000,082,061 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2007/01/04 14:26:24 | 000,081,549 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2007/01/04 14:26:04 | 039,447,328 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2007/01/04 14:26:04 | 000,992,288 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2004/09/01 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/09/01 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/09/01 13:00:00 | 000,395,530 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/09/01 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/09/01 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/09/01 13:00:00 | 000,059,644 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/09/01 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/09/01 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/09/01 13:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2004/09/01 13:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/09/01 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/09/01 13:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/09/01 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >




[color="#FF0000"]*****************************************************************************************************[/color]
[color="#FF0000"]
[/color]


OTL Extras logfile created on: 4/13/2011 6:35:11 PM - Run 5
OTL by OldTimer - Version 3.2.22.3     Folder = C:\Documents and Settings\ALI\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
894.00 Mb Total Physical Memory | 631.00 Mb Available Physical Memory | 71.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25.00 Gb Total Space | 1.25 Gb Free Space | 4.99% Space Free | Partition Type: NTFS
Drive D: | 25.00 Gb Total Space | 2.53 Gb Free Space | 10.13% Space Free | Partition Type: NTFS
Drive E: | 49.70 Gb Total Space | 1.61 Gb Free Space | 3.23% Space Free | Partition Type: NTFS
Drive F: | 49.34 Gb Total Space | 1.65 Gb Free Space | 3.34% Space Free | Partition Type: NTFS
Drive G: | 6.34 Gb Total Space | 0.59 Gb Free Space | 9.36% Space Free | Partition Type: FAT32
Drive H: | 12.64 Gb Total Space | 6.53 Gb Free Space | 51.67% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 12.97 Gb Free Space | 4.35% Space Free | Partition Type: NTFS
 
Computer Name: MAGMA | User Name: ALI | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{078E59A5-668C-D895-1BFF-68AB834A95F3}" = Catalyst Control Center Graphics Full New
"{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B6E7EA9-D17E-A9BB-7CE0-A1C737EFB5EE}" = Catalyst Control Center Localization Swedish
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0FE9DBCE-AB97-90AC-DC4B-BB6C2EDAFF71}" = CCC Help Hungarian
"{12F9942A-E85D-44A6-B054-0B3BC9009625}" = Opera 10.01
"{155FD632-60F5-A777-538C-3194E889C1D0}" = Catalyst Control Center Localization Greek
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{181EAEE6-AAE5-485B-8BAC-0FB564626781}" = Brava! Reader 7.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B9B5B3B-28E7-4E59-A80D-D670AA984514}" = Nokia Connectivity Cable Driver
"{1E44E5A6-4DCE-F13F-E00E-22076CE97FEA}" = CCC Help Turkish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}" = Nokia PC Suite
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26C70E22-6E6D-B28F-9039-5E2052C2A3BB}" = CCC Help Danish
"{29138741-C0FD-3812-EA30-3D4790DBF951}" = CCC Help Korean
"{2BFCBEDB-79F3-17C4-67B8-A0098E214F6A}" = Catalyst Control Center Graphics Full Existing
"{324B54DB-8576-73C9-7089-9373FFD85E18}" = CCC Help Chinese Traditional
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{38797561-17CD-94D2-F422-D83D5133B427}" = CCC Help Chinese Standard
"{3A6898A1-538B-562F-7339-8C5DA25B7254}" = Catalyst Control Center Localization Polish
"{3D190422-5A11-BB51-18B8-7C404DB0E46A}" = Catalyst Control Center Localization Chinese Standard
"{4063CCFF-AEB3-B34C-7D1A-4B32CE46E368}" = CCC Help German
"{41D38ED0-B916-667A-FDD2-965D04D128D5}" = CCC Help Spanish
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4FB3FCC4-AAB5-AED5-4412-B21DABE87025}" = Catalyst Control Center Localization Korean
"{4FDF7A38-81F4-55F3-1661-CC211DBC96A2}" = CCC Help English
"{52E1EC3F-B8E4-19B5-7EE6-A728B64A4310}" = CCC Help Swedish
"{55BD9B64-A9A8-44DF-E4AE-BDF60F5D4E90}" = CCC Help Thai
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5B014615-5EB8-EE17-4256-A7B1640819A3}" = CCC Help Italian
"{5B852893-9997-AE56-ED51-5F332938B543}" = Skins
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{64417030-62FB-42EE-99AD-02231A56E862}" = BomberMan Collection
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6E33F77B-952D-0FF5-87C4-7CDB66B0E8A1}" = Catalyst Control Center Localization Czech
"{709A7F8D-E1DA-A26F-2C10-B91CDA616FD9}" = CCC Help Portuguese
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{79B986AD-54D8-4498-AA06-89808829ACC0}" = Kaspersky Anti-Virus 6.0 for Windows Workstations
"{79DE041C-BCA2-EFBF-5BC1-B89CCC2893D2}" = CCC Help Polish
"{7BD95C90-3FAA-F55C-E9C2-2951F19474A2}" = Catalyst Control Center Localization Portuguese
"{80B4EB2E-F609-F443-E114-5D935412F085}" = CCC Help Greek
"{80EB1351-E642-33EA-0BF9-C681D616E270}" = CCC Help Czech
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{854B9E99-4007-E575-8E8E-3EDFA5B64CA9}" = CCC Help Dutch
"{8D5C88CA-2B55-C174-5AC3-643A638C91C8}" = Catalyst Control Center Localization Italian
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90502AE6-C689-A70E-D03D-1AFB6C233EA0}" = Catalyst Control Center Localization Norwegian
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9370105C-71BB-4FF9-A85B-36D79B95457A}_is1" = ALLConverter PRO 1.1
"{96639158-501C-D2C4-D25A-B6A86AA4B906}" = Catalyst Control Center Localization Danish
"{977AB934-E01A-DDEC-CF30-B686D5C0A248}" = Catalyst Control Center Localization French
"{982476DE-F2B9-00B0-36E3-DA06948EC1B4}" = Catalyst Control Center Localization Finnish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A4E913EC-8F82-14BB-F31F-0B983F540968}" = Catalyst Control Center Localization Spanish
"{A75BF1D0-C7C3-CB55-EE17-3225387FD154}" = ccc-core-static
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA39701D-F5EA-7EC9-D311-08AB84970CD8}" = Catalyst Control Center Localization German
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{AD69F082-B9EE-29BE-14A9-6B453A0B644A}" = CCC Help Japanese
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C122B78E-8ACA-BDF3-D150-78B26C3C4B94}" = Catalyst Control Center Graphics Light
"{C1E28A5C-94A0-DE77-52FC-177C2930FC48}" = Catalyst Control Center Localization Hungarian
"{C7DA7D9E-56A7-1E08-1B47-427AE3B0C254}" = Catalyst Control Center Core Implementation
"{CBE269E6-CB57-7F2E-3A11-3FF3DE4C1B5D}" = CCC Help Norwegian
"{CFAF33CA-01A5-5FD7-70F4-0195A0FBFD8E}" = CCC Help French
"{D0CA80F4-880D-8929-A78D-54E2CC46565D}" = Catalyst Control Center Localization Dutch
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB40817E-C5E6-6818-47F2-0359EAE14271}" = Catalyst Control Center Localization Japanese
"{DC49E045-EB3F-9A88-7404-933FF86D9E2F}" = CCC Help Finnish
"{E0DB1A31-F468-8E22-B158-C7756F4DE68E}" = CCC Help Russian
"{E0FF82C1-E2DE-D6D3-A264-F9FBCFFE7D24}" = Catalyst Control Center Localization Russian
"{E33A3E61-E7DA-65FB-75B4-AA68B6F9D83B}" = ccc-utility
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E65906BF-1BB5-0D31-A62C-54A56B687EF5}" = Catalyst Control Center Localization Thai
"{E97C3316-8C49-2267-0976-C6A56C5DC2F8}" = Catalyst Control Center Localization Turkish
"{F0C2AD51-9F09-4B75-82EE-74DA80F708D8}" = Nitro PDF Professional
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F17CE6DC-028C-C02E-3739-2C2802C08D7C}" = Catalyst Control Center Localization Chinese Traditional
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"34EA302E7F4CBD17A19E33BBCB72363234956D7E" = Windows Driver Package - Nokia Modem  (06/09/2010 4.5)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor  (05/27/2006 1.3.2.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"All Video Joiner_is1" = All Video Joiner 3.6
"Ambush Pack for Pocket Tanks Deluxe_is1" = Ambush Pack 1.00 for Pocket Tanks Deluxe
"ATI Display Driver" = ATI Display Driver
"Audio File Cutter_is1" = Audio File Cutter 3.40
"BurstCopy_is1" = BurstCopy v2.700
"Chaos Pack for Pocket Tanks Deluxe_is1" = Chaos Pack 1.00 for Pocket Tanks Deluxe
"Chess Mafia_is1" = Chess Mafia
"DivX Setup.divx.com" = DivX Setup
"EEEE705096F837B7907659F100C9FE6DA001970F" = Windows Driver Package - Nokia Modem  (06/09/2010 7.01.0.7)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EWED 2000 A" = Microsoft Encarta World English Dictionary
"Flamethrower Pack for Pocket Tanks Deluxe_is1" = Flamethrower Pack 1.00 for Pocket Tanks Deluxe
"Foxit Reader" = Foxit Reader
"Fuzz Pack for Pocket Tanks Deluxe_is1" = Fuzz Pack v1.0 for Pocket Tanks Deluxe
"GOM Player" = GOM Player
"Gravity Pack for Pocket Tanks Deluxe_is1" = Gravity Pack v1.1 for Pocket Tanks Deluxe
"ie8" = Windows Internet Explorer 8
"InstallWIX_{79B986AD-54D8-4498-AA06-89808829ACC0}" = Kaspersky Anti-Virus 6.0 for Windows Workstations
"Internet Download Manager" = Internet Download Manager
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.53
"Magic Pack for Pocket Tanks Deluxe_is1" = Magic Pack v1.0 for Pocket Tanks Deluxe
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"MYIE2" = MYIE2 Browser (remove only)
"Nano Pack for Pocket Tanks Deluxe_is1" = Nano Pack v1.0 for Pocket Tanks Deluxe
"Nokia PC Suite" = Nokia PC Suite
"Nuke Pack for Pocket Tanks Deluxe_is1" = Nuke Pack 1.00 for Pocket Tanks Deluxe
"OpenSubtitlesPlayer_is1" = OpenSubtitlesPlayer V4.X
"Party Pack for Pocket Tanks Deluxe_is1" = Party Pack for Pocket Tanks Deluxe
"PDF Password Remover v2.2_is1" = PDF Password Remover v2.2
"Pocket Tanks Deluxe_is1" = Pocket Tanks Deluxe 1.00b
"Product_Name" = TEKKEN 3
"RAR Password Cracker" = RAR Password Cracker 4.12
"Snowball Pack for Pocket Tanks Deluxe_is1" = Snowball Pack v1.1 for Pocket Tanks Deluxe
"Super Pack for Pocket Tanks Deluxe_is1" = Super Pack v1.11 for Pocket Tanks Deluxe
"TheChatPhone Toolbar" = TheChatPhone Toolbar
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"VLC media player" = VLC media player 1.0.1
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"Zynga Toolbar" = Zynga Toolbar
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = µTorrent
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 2/2/2011 11:41:28 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x0ecdadb2.
 
Error - 2/3/2011 6:13:49 AM | Computer Name = MAGMA | Source = Application Hang | ID = 1002
Description = Hanging application mplayerc.exe, version 6.4.9.0, hang module hungapp,
 version 0.0.0.0, hang address 0x00000000.
 
Error - 2/3/2011 6:45:51 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0xee2386ab.
 
Error - 2/3/2011 1:28:43 PM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x175d15ca.
 
Error - 2/4/2011 12:22:18 PM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module mshtml.dll, version 8.0.6001.18702, fault address 0x003475d1.
 
Error - 2/5/2011 5:04:52 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
 0.0.0.0, fault address 0x00000000.
 
Error - 2/5/2011 6:45:04 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x189da8a2.
 
Error - 2/6/2011 7:50:34 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0xee2386ab.
 
Error - 2/6/2011 8:33:11 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x0e22f892.
 
Error - 2/6/2011 8:37:22 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x100cfcb2.
 
[ Application Events ]
Error - 2/2/2011 11:41:28 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x0ecdadb2.
 
Error - 2/3/2011 6:13:49 AM | Computer Name = MAGMA | Source = Application Hang | ID = 1002
Description = Hanging application mplayerc.exe, version 6.4.9.0, hang module hungapp,
 version 0.0.0.0, hang address 0x00000000.
 
Error - 2/3/2011 6:45:51 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0xee2386ab.
 
Error - 2/3/2011 1:28:43 PM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x175d15ca.
 
Error - 2/4/2011 12:22:18 PM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module mshtml.dll, version 8.0.6001.18702, fault address 0x003475d1.
 
Error - 2/5/2011 5:04:52 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
 0.0.0.0, fault address 0x00000000.
 
Error - 2/5/2011 6:45:04 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x189da8a2.
 
Error - 2/6/2011 7:50:34 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.21

Offline faraz

  • Jr. Member
  • **
  • Posts: 75
  • Karma: +0/-0
    • View Profile
Spyware ruined my Internet
« Reply #30 on: April 13, 2011, 08:47:39 AM »
[size="4"][color="#0000FF"]Sory i was checking whether system works normaly or not..................[/color][/size]
[size="4"] [/size]
[size="4"][color="#0000FF"]But after the last run of combofix with script you have mentioned.............Problem arises again[/color][/size]
here the logs
******************************************************************************************************************

OTL logfile created on: 4/13/2011 6:35:11 PM - Run 5
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Documents and Settings\ALI\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
894.00 Mb Total Physical Memory | 631.00 Mb Available Physical Memory | 71.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25.00 Gb Total Space | 1.25 Gb Free Space | 4.99% Space Free | Partition Type: NTFS
Drive D: | 25.00 Gb Total Space | 2.53 Gb Free Space | 10.13% Space Free | Partition Type: NTFS
Drive E: | 49.70 Gb Total Space | 1.61 Gb Free Space | 3.23% Space Free | Partition Type: NTFS
Drive F: | 49.34 Gb Total Space | 1.65 Gb Free Space | 3.34% Space Free | Partition Type: NTFS
Drive G: | 6.34 Gb Total Space | 0.59 Gb Free Space | 9.36% Space Free | Partition Type: FAT32
Drive H: | 12.64 Gb Total Space | 6.53 Gb Free Space | 51.67% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 12.97 Gb Free Space | 4.35% Space Free | Partition Type: NTFS
 
Computer Name: MAGMA | User Name: ALI | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
[color="#E56717"]========== Processes (SafeList) ==========[/color]
 
PRC - [2011/04/13 15:24:13 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALI\Desktop\OTL.exe
PRC - [2010/12/26 01:31:49 | 003,179,952 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2010/11/12 16:06:50 | 000,197,632 | ---- | M] () -- C:\Program Files\TheChatPhone Toolbar\TbHelper2.exe
PRC - [2009/10/15 14:51:51 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2008/11/10 01:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/10/05 16:18:50 | 000,230,664 | ---- | M] (Kaspersky Lab) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
PRC - [2004/09/01 13:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
 
 
[color="#E56717"]========== Modules (SafeList) ==========[/color]
 
MOD - [2011/04/13 15:24:13 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALI\Desktop\OTL.exe
MOD - [2009/03/26 20:35:39 | 000,034,224 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\idmmkb.dll
MOD - [2004/09/01 13:00:00 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
 
 
[color="#E56717"]========== Win32 Services (SafeList) ==========[/color]
 
SRV - File not found [Disabled | Stopped] --  -- (HidServ)
SRV - [2010/06/14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2008/11/10 01:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2007/10/05 16:18:50 | 000,230,664 | ---- | M] (Kaspersky Lab) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe -- (AVP)
SRV - [2007/02/21 17:26:40 | 000,151,552 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe -- (bepldr)
 
 
[color="#E56717"]========== Driver Services (SafeList) ==========[/color]
 
DRV - [2010/02/26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/02/26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/02/26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009/03/25 14:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/10/05 14:48:04 | 000,190,736 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (klif)
DRV - [2007/07/18 15:39:54 | 000,110,096 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (kl1)
DRV - [2007/05/30 18:49:06 | 000,024,344 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2007/03/26 16:21:06 | 004,395,008 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/02/03 01:03:24 | 001,975,296 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/06/18 23:37:34 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004/08/13 23:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
 
 
[color="#E56717"]========== Standard Registry (SafeList) ==========[/color]
 
 
[color="#E56717"]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.thechatphone.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
[color="#E56717"]========== FireFox ==========[/color]
 
FF - prefs.js..extensions.enabledItems: [email protected]:1.2009p
FF - prefs.js..extensions.enabledItems: {e2fda1a4-762b-4020-b5ad-a41df1933103}:1.0b1
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/28 23:19:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/28 23:19:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files\Mozilla Sunbird\components [2011/02/03 13:48:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files\Mozilla Sunbird\plugins
 
[2011/02/03 13:49:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ALI\Application Data\Mozilla\Extensions
[2011/02/03 13:49:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ALI\Application Data\Mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28}
[2011/02/03 13:49:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ALI\Application Data\Mozilla\Sunbird\Profiles\02738zse.default\extensions
[2011/02/03 13:48:42 | 000,000,000 | ---D | M] (Lightning stub extension for Sunbird) -- C:\PROGRAM FILES\MOZILLA SUNBIRD\EXTENSIONS\{E2FDA1A4-762B-4020-B5AD-A41DF1933103}
[2011/02/03 13:48:42 | 000,000,000 | ---D | M] (Timezone Definitions for Mozilla Calendar) -- C:\PROGRAM FILES\MOZILLA SUNBIRD\EXTENSIONS\[email protected]
[2011/03/22 22:45:06 | 000,002,048 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchostpl.xml
 
O1 HOSTS File: ([2011/04/12 21:41:54 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (TBSB02381 Class) - {77245F75-3D8C-40CD-8F64-F9AA1388406F} - C:\Program Files\TheChatPhone Toolbar\tbcore3.dll ()
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files\OpenSubtitlesPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (TheChatPhone Toolbar) - {01193D00-C7F9-4C26-92A2-1CA91F170068} - C:\Program Files\TheChatPhone Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (TheChatPhone Toolbar) - {01193D00-C7F9-4C26-92A2-1CA91F170068} - C:\Program Files\TheChatPhone Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [UserFaultCheck]  File not found
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\ie_banner_deny.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: QuickDefine - C:\Program Files\Common Files\Microsoft Shared\Reference Titles\eddefine.htm ()
O9 - Extra Button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\SCIEPlgn.dll (Kaspersky Lab)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Documents and Settings\ALI\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ALI\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/12/25 23:49:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
[color="#E56717"]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2011/04/13 15:24:02 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ALI\Desktop\OTL.exe
[2011/04/12 22:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentBar
[2011/04/12 22:03:33 | 000,000,000 | ---D | C] -- C:\extensions
[2011/04/12 21:50:28 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/04/12 21:48:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/04/11 03:03:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FreeGamePick.com
[2011/04/11 03:03:00 | 000,000,000 | ---D | C] -- C:\Program Files\FreeGamePick.com
[2011/04/09 11:43:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Start Menu\Programs\MYIE2
[2011/04/08 12:47:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\ALI\Recent
[2011/04/05 13:11:50 | 000,000,000 | ---D | C] -- C:\control
[2011/04/04 12:50:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Pocket Tanks Deluxe
[2011/04/04 12:50:53 | 000,000,000 | ---D | C] -- C:\Program Files\Pocket Tanks Deluxe
[2011/04/02 15:43:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\All Video Joiner
[2011/04/02 15:43:31 | 000,000,000 | ---D | C] -- C:\Program Files\All Video Joiner
[2011/04/01 12:08:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/03/30 12:29:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Desktop\2011 Muzik
[2011/03/29 16:43:15 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2011/03/27 16:50:58 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/03/24 20:33:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\My Documents\GomPlayer
[2011/03/24 20:33:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Application Data\GRETECH
[2011/03/24 20:29:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GOM Player
[2011/03/24 20:28:48 | 000,000,000 | ---D | C] -- C:\Program Files\GRETECH
[2011/03/23 22:16:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Desktop\Den
[2011/03/22 22:43:15 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/03/22 22:42:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ALLConverter PRO
[2011/03/22 22:42:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Local Settings\Application Data\ALLConverter
[2011/03/22 22:42:44 | 000,000,000 | ---D | C] -- C:\Program Files\ALLConverter PRO
[2011/03/22 22:42:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\OpenSubtitlesPlayer
[2011/03/22 22:42:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\Local Settings\Application Data\ALLPlayer
[2011/03/22 22:41:12 | 000,000,000 | ---D | C] -- C:\Program Files\OpenSubtitlesPlayer
[2011/03/21 11:08:30 | 000,305,152 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2011/03/18 15:29:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALI\IGC
[2011/03/18 11:19:45 | 000,000,000 | RHSD | C] -- C:\cmdcons
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
[color="#E56717"]========== Files - Modified Within 30 Days ==========[/color]
 
[2011/04/13 18:31:54 | 039,447,328 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2011/04/13 18:23:01 | 000,000,970 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003UA.job
[2011/04/13 18:02:03 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/13 15:35:50 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D5E359FE-18D3-4EDA-90CF-4EE7AB928AD4}.job
[2011/04/13 15:28:09 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/13 15:24:13 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALI\Desktop\OTL.exe
[2011/04/13 15:18:11 | 000,000,876 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/13 15:18:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/13 15:18:05 | 937,938,944 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/13 15:13:16 | 000,992,288 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2011/04/13 15:13:16 | 000,556,028 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2011/04/13 15:13:16 | 000,109,940 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.idx
[2011/04/13 02:00:00 | 000,000,338 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-MAGMA-ALI.job
[2011/04/12 23:38:44 | 000,014,590 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Don_t_be_afraid_of_the_dark_Eng_2011_DVDrip_XvID-[Fenopy.eu].torrent
[2011/04/12 22:05:01 | 000,016,773 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\The.Girl.With.The.Dragon.Tattoo[2009]DvDrip-aXXo.5670645.TPB.torrent
[2011/04/12 22:01:51 | 000,000,651 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/04/12 22:00:49 | 000,033,770 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\26A4D05CA746E2A4DA00180181965311ABCF04C6.torrent
[2011/04/12 21:58:01 | 000,028,534 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Don__039_t_Be_Afraid_of_The_Dark_DVD_rip_avi.torrent
[2011/04/12 21:41:54 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/12 16:09:41 | 000,035,295 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Fraz Ali _CV latest.pdf
[2011/04/12 15:44:04 | 001,428,174 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\165621710161870_32760.mp4
[2011/04/12 02:44:25 | 010,488,748 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\137651706308368_25484.mp4
[2011/04/12 01:50:18 | 000,028,160 | ---- | M] () -- C:\Documents and Settings\ALI\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/11 13:23:02 | 000,000,918 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1177238915-725345543-1003Core.job
[2011/04/11 03:03:02 | 000,001,783 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Chess Mafia.lnk
[2011/04/10 15:54:36 | 000,470,601 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\IELTS Preparation Tips.mht
[2011/04/09 15:23:51 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/09 11:43:36 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\MYIE2.lnk
[2011/04/07 11:13:42 | 000,032,721 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\DP_AnnualAccounts_2009.pdf
[2011/04/06 13:57:03 | 000,447,676 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\232.pdf
[2011/04/05 13:14:12 | 000,000,926 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to edict.lnk
[2011/04/05 02:27:42 | 000,156,547 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\assessment-levels.pdf
[2011/04/04 12:50:58 | 000,000,750 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Pocket Tanks Deluxe.lnk
[2011/04/02 15:43:37 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\All Video Joiner.lnk
[2011/04/02 00:57:47 | 000,966,016 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\IELTSApplicationFormNovember2010.pdf
[2011/04/01 14:15:27 | 000,000,339 | RHS- | M] () -- C:\boot.ini
[2011/03/27 20:39:16 | 000,065,649 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\scan0114.jpg
[2011/03/26 19:55:49 | 000,865,555 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\AEO Newsletter 1-2011.pdf
[2011/03/26 11:21:37 | 000,006,820 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/03/24 20:29:24 | 000,000,783 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2011/03/23 21:41:40 | 000,094,639 | ---- | M] () -- C:\Documents and Settings\ALI\My Documents\Technical-Jobs-in-Islamabad-Based-Construction-Company.jpg
[2011/03/22 22:42:49 | 000,000,794 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\ALLConverter PRO.lnk
[2011/03/22 22:42:49 | 000,000,776 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ALLConverter PRO.lnk
[2011/03/22 22:42:22 | 000,001,671 | ---- | M] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\OpenSubtitlesPlayer V4.6.lnk
[2011/03/22 22:42:22 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\OpenSubtitlesPlayer V4.6.lnk
[2011/03/18 11:15:30 | 000,000,339 | ---- | M] () -- C:\Boot.bak
[2011/03/17 11:34:37 | 000,334,731 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Techlogix-Pakistan-Jobs.JPG
[2011/03/17 11:34:07 | 000,495,072 | ---- | M] () -- C:\Documents and Settings\ALI\Desktop\Pizza-Hut-Pakistan-Jobs.JPG
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
[color="#E56717"]========== Files Created - No Company Name ==========[/color]
 
[2011/04/12 23:38:43 | 000,014,590 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Don_t_be_afraid_of_the_dark_Eng_2011_DVDrip_XvID-[Fenopy.eu].torrent
[2011/04/12 22:05:01 | 000,016,773 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\The.Girl.With.The.Dragon.Tattoo[2009]DvDrip-aXXo.5670645.TPB.torrent
[2011/04/12 22:00:49 | 000,033,770 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\26A4D05CA746E2A4DA00180181965311ABCF04C6.torrent
[2011/04/12 21:58:00 | 000,028,534 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Don__039_t_Be_Afraid_of_The_Dark_DVD_rip_avi.torrent
[2011/04/12 16:10:39 | 000,035,295 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Fraz Ali _CV latest.pdf
[2011/04/12 15:43:31 | 001,428,174 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\165621710161870_32760.mp4
[2011/04/12 02:41:29 | 010,488,748 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\137651706308368_25484.mp4
[2011/04/11 03:03:02 | 000,001,783 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Chess Mafia.lnk
[2011/04/10 15:54:27 | 000,470,601 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\IELTS Preparation Tips.mht
[2011/04/09 11:43:36 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\MYIE2.lnk
[2011/04/07 11:13:42 | 000,032,721 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\DP_AnnualAccounts_2009.pdf
[2011/04/06 13:56:53 | 000,447,676 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\232.pdf
[2011/04/05 13:14:12 | 000,000,926 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to edict.lnk
[2011/04/05 02:27:20 | 000,156,547 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\assessment-levels.pdf
[2011/04/04 12:50:58 | 000,000,750 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Pocket Tanks Deluxe.lnk
[2011/04/02 15:43:37 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\All Video Joiner.lnk
[2011/04/02 00:56:08 | 000,966,016 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\IELTSApplicationFormNovember2010.pdf
[2011/03/29 16:43:16 | 000,000,651 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/03/27 20:39:25 | 000,065,649 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\scan0114.jpg
[2011/03/26 19:55:29 | 000,865,555 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\AEO Newsletter 1-2011.pdf
[2011/03/26 11:21:37 | 000,006,820 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/03/24 20:29:24 | 000,000,783 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2011/03/23 21:39:08 | 000,094,639 | ---- | C] () -- C:\Documents and Settings\ALI\My Documents\Technical-Jobs-in-Islamabad-Based-Construction-Company.jpg
[2011/03/22 22:42:49 | 000,000,794 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\ALLConverter PRO.lnk
[2011/03/22 22:42:49 | 000,000,776 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ALLConverter PRO.lnk
[2011/03/22 22:42:22 | 000,001,671 | ---- | C] () -- C:\Documents and Settings\ALI\Application Data\Microsoft\Internet Explorer\Quick Launch\OpenSubtitlesPlayer V4.6.lnk
[2011/03/22 22:42:22 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\OpenSubtitlesPlayer V4.6.lnk
[2011/03/22 22:41:56 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\libFLAC.dll
[2011/03/22 10:53:22 | 937,938,944 | -HS- | C] () -- C:\hiberfil.sys
[2011/03/17 11:34:37 | 000,334,731 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Techlogix-Pakistan-Jobs.JPG
[2011/03/17 11:34:07 | 000,495,072 | ---- | C] () -- C:\Documents and Settings\ALI\Desktop\Pizza-Hut-Pakistan-Jobs.JPG
[2011/02/22 15:49:08 | 000,042,379 | ---- | C] () -- C:\WINDOWS\convfac.ini
[2011/02/22 15:49:08 | 000,014,775 | ---- | C] () -- C:\WINDOWS\convit.ini
[2011/02/15 13:27:23 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2011/02/07 11:12:22 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/02/07 11:12:22 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/02/07 11:12:22 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/02/07 11:12:22 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/02/07 11:12:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/02/06 17:18:44 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\FreeImage3.dll
[2011/02/06 17:18:44 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\FreeImage.dll
[2011/02/06 17:18:44 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\DVM.dll
[2011/02/06 17:18:43 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\RegisterExe.exe
[2011/01/24 19:39:08 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\pwdremover.dat
[2011/01/24 19:39:08 | 000,000,036 | ---- | C] () -- C:\WINDOWS\verypdf.ini
[2011/01/21 16:11:39 | 000,000,070 | ---- | C] () -- C:\WINDOWS\GECKOS.INI
[2011/01/14 17:09:27 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
[2011/01/14 17:09:27 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
[2011/01/14 17:09:27 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\unacev2.dll
[2011/01/14 17:09:26 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar3.dll
[2011/01/14 15:59:21 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll.old
[2011/01/08 17:52:27 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/12/26 01:35:27 | 000,028,160 | ---- | C] () -- C:\Documents and Settings\ALI\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/26 01:31:02 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/12/26 01:28:18 | 003,568,328 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/26 01:26:00 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/12/26 01:25:58 | 000,810,496 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/12/26 01:25:58 | 000,568,850 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2010/12/26 01:25:58 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/12/26 01:25:57 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010/12/26 01:25:56 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/12/26 01:25:55 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2010/12/26 01:19:12 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2010/12/26 01:17:48 | 000,021,896 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2010/12/26 01:11:37 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010/12/26 01:09:03 | 003,107,788 | R--- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2010/12/26 01:09:03 | 000,128,813 | R--- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010/12/26 01:08:01 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/12/26 01:07:56 | 000,021,582 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010/12/26 01:07:44 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/12/25 23:51:56 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/12/25 23:46:12 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2007/10/05 16:18:24 | 000,013,924 | ---- | C] () -- C:\WINDOWS\System32\drivers\klop.dat
[2007/01/04 14:26:24 | 000,082,061 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2007/01/04 14:26:24 | 000,081,549 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2007/01/04 14:26:04 | 039,447,328 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2007/01/04 14:26:04 | 000,992,288 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2004/09/01 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/09/01 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/09/01 13:00:00 | 000,395,530 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/09/01 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/09/01 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/09/01 13:00:00 | 000,059,644 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/09/01 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/09/01 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/09/01 13:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2004/09/01 13:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/09/01 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/09/01 13:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/09/01 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
 
[color="#E56717"]========== Alternate Data Streams ==========[/color]
 
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >




[color="#FF0000"]*****************************************************************************************************[/color]


OTL Extras logfile created on: 4/13/2011 6:35:11 PM - Run 5
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Documents and Settings\ALI\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
894.00 Mb Total Physical Memory | 631.00 Mb Available Physical Memory | 71.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25.00 Gb Total Space | 1.25 Gb Free Space | 4.99% Space Free | Partition Type: NTFS
Drive D: | 25.00 Gb Total Space | 2.53 Gb Free Space | 10.13% Space Free | Partition Type: NTFS
Drive E: | 49.70 Gb Total Space | 1.61 Gb Free Space | 3.23% Space Free | Partition Type: NTFS
Drive F: | 49.34 Gb Total Space | 1.65 Gb Free Space | 3.34% Space Free | Partition Type: NTFS
Drive G: | 6.34 Gb Total Space | 0.59 Gb Free Space | 9.36% Space Free | Partition Type: FAT32
Drive H: | 12.64 Gb Total Space | 6.53 Gb Free Space | 51.67% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 12.97 Gb Free Space | 4.35% Space Free | Partition Type: NTFS
 
Computer Name: MAGMA | User Name: ALI | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
[color="#E56717"]========== Extra Registry (SafeList) ==========[/color]
 
 
[color="#E56717"]========== File Associations ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[color="#E56717"]========== Shell Spawning ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[color="#E56717"]========== Security Center Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
[color="#E56717"]========== System Restore Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
[color="#E56717"]========== Firewall Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[color="#E56717"]========== Authorized Applications List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
 
 
[color="#E56717"]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{078E59A5-668C-D895-1BFF-68AB834A95F3}" = Catalyst Control Center Graphics Full New
"{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B6E7EA9-D17E-A9BB-7CE0-A1C737EFB5EE}" = Catalyst Control Center Localization Swedish
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0FE9DBCE-AB97-90AC-DC4B-BB6C2EDAFF71}" = CCC Help Hungarian
"{12F9942A-E85D-44A6-B054-0B3BC9009625}" = Opera 10.01
"{155FD632-60F5-A777-538C-3194E889C1D0}" = Catalyst Control Center Localization Greek
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{181EAEE6-AAE5-485B-8BAC-0FB564626781}" = Brava! Reader 7.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B9B5B3B-28E7-4E59-A80D-D670AA984514}" = Nokia Connectivity Cable Driver
"{1E44E5A6-4DCE-F13F-E00E-22076CE97FEA}" = CCC Help Turkish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}" = Nokia PC Suite
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26C70E22-6E6D-B28F-9039-5E2052C2A3BB}" = CCC Help Danish
"{29138741-C0FD-3812-EA30-3D4790DBF951}" = CCC Help Korean
"{2BFCBEDB-79F3-17C4-67B8-A0098E214F6A}" = Catalyst Control Center Graphics Full Existing
"{324B54DB-8576-73C9-7089-9373FFD85E18}" = CCC Help Chinese Traditional
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{38797561-17CD-94D2-F422-D83D5133B427}" = CCC Help Chinese Standard
"{3A6898A1-538B-562F-7339-8C5DA25B7254}" = Catalyst Control Center Localization Polish
"{3D190422-5A11-BB51-18B8-7C404DB0E46A}" = Catalyst Control Center Localization Chinese Standard
"{4063CCFF-AEB3-B34C-7D1A-4B32CE46E368}" = CCC Help German
"{41D38ED0-B916-667A-FDD2-965D04D128D5}" = CCC Help Spanish
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4FB3FCC4-AAB5-AED5-4412-B21DABE87025}" = Catalyst Control Center Localization Korean
"{4FDF7A38-81F4-55F3-1661-CC211DBC96A2}" = CCC Help English
"{52E1EC3F-B8E4-19B5-7EE6-A728B64A4310}" = CCC Help Swedish
"{55BD9B64-A9A8-44DF-E4AE-BDF60F5D4E90}" = CCC Help Thai
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5B014615-5EB8-EE17-4256-A7B1640819A3}" = CCC Help Italian
"{5B852893-9997-AE56-ED51-5F332938B543}" = Skins
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{64417030-62FB-42EE-99AD-02231A56E862}" = BomberMan Collection
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6E33F77B-952D-0FF5-87C4-7CDB66B0E8A1}" = Catalyst Control Center Localization Czech
"{709A7F8D-E1DA-A26F-2C10-B91CDA616FD9}" = CCC Help Portuguese
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{79B986AD-54D8-4498-AA06-89808829ACC0}" = Kaspersky Anti-Virus 6.0 for Windows Workstations
"{79DE041C-BCA2-EFBF-5BC1-B89CCC2893D2}" = CCC Help Polish
"{7BD95C90-3FAA-F55C-E9C2-2951F19474A2}" = Catalyst Control Center Localization Portuguese
"{80B4EB2E-F609-F443-E114-5D935412F085}" = CCC Help Greek
"{80EB1351-E642-33EA-0BF9-C681D616E270}" = CCC Help Czech
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{854B9E99-4007-E575-8E8E-3EDFA5B64CA9}" = CCC Help Dutch
"{8D5C88CA-2B55-C174-5AC3-643A638C91C8}" = Catalyst Control Center Localization Italian
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90502AE6-C689-A70E-D03D-1AFB6C233EA0}" = Catalyst Control Center Localization Norwegian
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9370105C-71BB-4FF9-A85B-36D79B95457A}_is1" = ALLConverter PRO 1.1
"{96639158-501C-D2C4-D25A-B6A86AA4B906}" = Catalyst Control Center Localization Danish
"{977AB934-E01A-DDEC-CF30-B686D5C0A248}" = Catalyst Control Center Localization French
"{982476DE-F2B9-00B0-36E3-DA06948EC1B4}" = Catalyst Control Center Localization Finnish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A4E913EC-8F82-14BB-F31F-0B983F540968}" = Catalyst Control Center Localization Spanish
"{A75BF1D0-C7C3-CB55-EE17-3225387FD154}" = ccc-core-static
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA39701D-F5EA-7EC9-D311-08AB84970CD8}" = Catalyst Control Center Localization German
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{AD69F082-B9EE-29BE-14A9-6B453A0B644A}" = CCC Help Japanese
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C122B78E-8ACA-BDF3-D150-78B26C3C4B94}" = Catalyst Control Center Graphics Light
"{C1E28A5C-94A0-DE77-52FC-177C2930FC48}" = Catalyst Control Center Localization Hungarian
"{C7DA7D9E-56A7-1E08-1B47-427AE3B0C254}" = Catalyst Control Center Core Implementation
"{CBE269E6-CB57-7F2E-3A11-3FF3DE4C1B5D}" = CCC Help Norwegian
"{CFAF33CA-01A5-5FD7-70F4-0195A0FBFD8E}" = CCC Help French
"{D0CA80F4-880D-8929-A78D-54E2CC46565D}" = Catalyst Control Center Localization Dutch
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB40817E-C5E6-6818-47F2-0359EAE14271}" = Catalyst Control Center Localization Japanese
"{DC49E045-EB3F-9A88-7404-933FF86D9E2F}" = CCC Help Finnish
"{E0DB1A31-F468-8E22-B158-C7756F4DE68E}" = CCC Help Russian
"{E0FF82C1-E2DE-D6D3-A264-F9FBCFFE7D24}" = Catalyst Control Center Localization Russian
"{E33A3E61-E7DA-65FB-75B4-AA68B6F9D83B}" = ccc-utility
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E65906BF-1BB5-0D31-A62C-54A56B687EF5}" = Catalyst Control Center Localization Thai
"{E97C3316-8C49-2267-0976-C6A56C5DC2F8}" = Catalyst Control Center Localization Turkish
"{F0C2AD51-9F09-4B75-82EE-74DA80F708D8}" = Nitro PDF Professional
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F17CE6DC-028C-C02E-3739-2C2802C08D7C}" = Catalyst Control Center Localization Chinese Traditional
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"34EA302E7F4CBD17A19E33BBCB72363234956D7E" = Windows Driver Package - Nokia Modem  (06/09/2010 4.5)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor  (05/27/2006 1.3.2.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"All Video Joiner_is1" = All Video Joiner 3.6
"Ambush Pack for Pocket Tanks Deluxe_is1" = Ambush Pack 1.00 for Pocket Tanks Deluxe
"ATI Display Driver" = ATI Display Driver
"Audio File Cutter_is1" = Audio File Cutter 3.40
"BurstCopy_is1" = BurstCopy v2.700
"Chaos Pack for Pocket Tanks Deluxe_is1" = Chaos Pack 1.00 for Pocket Tanks Deluxe
"Chess Mafia_is1" = Chess Mafia
"DivX Setup.divx.com" = DivX Setup
"EEEE705096F837B7907659F100C9FE6DA001970F" = Windows Driver Package - Nokia Modem  (06/09/2010 7.01.0.7)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EWED 2000 A" = Microsoft Encarta World English Dictionary
"Flamethrower Pack for Pocket Tanks Deluxe_is1" = Flamethrower Pack 1.00 for Pocket Tanks Deluxe
"Foxit Reader" = Foxit Reader
"Fuzz Pack for Pocket Tanks Deluxe_is1" = Fuzz Pack v1.0 for Pocket Tanks Deluxe
"GOM Player" = GOM Player
"Gravity Pack for Pocket Tanks Deluxe_is1" = Gravity Pack v1.1 for Pocket Tanks Deluxe
"ie8" = Windows Internet Explorer 8
"InstallWIX_{79B986AD-54D8-4498-AA06-89808829ACC0}" = Kaspersky Anti-Virus 6.0 for Windows Workstations
"Internet Download Manager" = Internet Download Manager
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.53
"Magic Pack for Pocket Tanks Deluxe_is1" = Magic Pack v1.0 for Pocket Tanks Deluxe
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"MYIE2" = MYIE2 Browser (remove only)
"Nano Pack for Pocket Tanks Deluxe_is1" = Nano Pack v1.0 for Pocket Tanks Deluxe
"Nokia PC Suite" = Nokia PC Suite
"Nuke Pack for Pocket Tanks Deluxe_is1" = Nuke Pack 1.00 for Pocket Tanks Deluxe
"OpenSubtitlesPlayer_is1" = OpenSubtitlesPlayer V4.X
"Party Pack for Pocket Tanks Deluxe_is1" = Party Pack for Pocket Tanks Deluxe
"PDF Password Remover v2.2_is1" = PDF Password Remover v2.2
"Pocket Tanks Deluxe_is1" = Pocket Tanks Deluxe 1.00b
"Product_Name" = TEKKEN 3
"RAR Password Cracker" = RAR Password Cracker 4.12
"Snowball Pack for Pocket Tanks Deluxe_is1" = Snowball Pack v1.1 for Pocket Tanks Deluxe
"Super Pack for Pocket Tanks Deluxe_is1" = Super Pack v1.11 for Pocket Tanks Deluxe
"TheChatPhone Toolbar" = TheChatPhone Toolbar
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"VLC media player" = VLC media player 1.0.1
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"Zynga Toolbar" = Zynga Toolbar
 
[color="#E56717"]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = µTorrent
 
[color="#E56717"]========== Last 10 Event Log Errors ==========[/color]
 
[ Application Events ]
Error - 2/2/2011 11:41:28 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x0ecdadb2.
 
Error - 2/3/2011 6:13:49 AM | Computer Name = MAGMA | Source = Application Hang | ID = 1002
Description = Hanging application mplayerc.exe, version 6.4.9.0, hang module hungapp,
 version 0.0.0.0, hang address 0x00000000.
 
Error - 2/3/2011 6:45:51 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0xee2386ab.
 
Error - 2/3/2011 1:28:43 PM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x175d15ca.
 
Error - 2/4/2011 12:22:18 PM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module mshtml.dll, version 8.0.6001.18702, fault address 0x003475d1.
 
Error - 2/5/2011 5:04:52 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
 0.0.0.0, fault address 0x00000000.
 
Error - 2/5/2011 6:45:04 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x189da8a2.
 
Error - 2/6/2011 7:50:34 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0xee2386ab.
 
Error - 2/6/2011 8:33:11 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x0e22f892.
 
Error - 2/6/2011 8:37:22 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x100cfcb2.
 
[ Application Events ]
Error - 2/2/2011 11:41:28 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x0ecdadb2.
 
Error - 2/3/2011 6:13:49 AM | Computer Name = MAGMA | Source = Application Hang | ID = 1002
Description = Hanging application mplayerc.exe, version 6.4.9.0, hang module hungapp,
 version 0.0.0.0, hang address 0x00000000.
 
Error - 2/3/2011 6:45:51 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0xee2386ab.
 
Error - 2/3/2011 1:28:43 PM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module unknown, version 0.0.0.0, fault address 0x175d15ca.
 
Error - 2/4/2011 12:22:18 PM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
 module mshtml.dll, version 8.0.6001.18702, fault address 0x003475d1.
 
Error - 2/5/2011 5:04:52 AM | Computer Name = MAGMA | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting mod

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Spyware ruined my Internet
« Reply #31 on: April 13, 2011, 08:53:02 AM »
Can you give a little detail of exactly what kind of problems your having please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline faraz

  • Jr. Member
  • **
  • Posts: 75
  • Karma: +0/-0
    • View Profile
Spyware ruined my Internet
« Reply #32 on: April 14, 2011, 07:57:03 AM »
[quote name='guestolo' date='13 April 2011 - 06:53 PM' timestamp='1302702782' post='477963']
Can you give a little detail of exactly what kind of problems your having please
[/quote]

First a message of  "Win32 generic host problem" appears & afterwards my desktop appearance blinks changes to classic window appearance & then reverts backs to its original xp appearance

but after that my audio stops working & i m not able to use internet......
in order to rectify audio problem i hav to go to control panel and add hardware......

but lan/internet problem persists there & i have to restart the pc in oder to get connect to internet again