Author Topic: Win32/Heur  (Read 723 times)

Offline Amethyst

  • Newbie
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Win32/Heur
« on: April 26, 2009, 10:03:46 AM »
Hello guestolo. Been a while since i've been here.


While visiting Photobucket my PC got infected with win32/heur.

Now it's popping up with every exe I open.


Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:01:52 PM, on 4/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
C:\WINDOWS\SM1BG.EXE
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\Program Files\Samsung\DisplayManager\dmhkcore.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\Program Files\Xfire\xfiremusic.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\vsnp2uvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\program files\steam\steam.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.Email Removed.uk/web?isinit=true&query=%s
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {29aa1b1d-e701-464c-9a68-ee9053ffa441} - C:\WINDOWS\system32\buzakayo.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.16.0\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [DMHotKey] C:\Program Files\Samsung\DisplayManager\DMLoader.exe
O4 - HKLM\..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Xfire Music] "C:\Program Files\Xfire\xfiremusic.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [yujalepega] Rundll32.exe "C:\WINDOWS\system32\gusogire.dll",s
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.16.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.16.0\gears.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Laurence Smyth\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: wbsys.dll,C:\WINDOWS\system32\dapavama.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: system32 - {C40C81EC-6607-49E0-99F9-E4E39B5044CE} - sysprinters.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c9138abbc2a9e2) (gupdate1c9138abbc2a9e2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: SNM WLAN Service - Unknown owner - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 14209 bytes
Hiya
No, i'm not a scammer. I said I scammed someone to get banned because my activity on the markets was going to affect my GCSE grades. Sorry to those I [censored] with. Don't believe me? Find proof then. Oh wait, there is none.






<-----------TRANSACTIONS----------->

[color="#00ff00"][color="#ff0000"]Traded level 70 main for level 53 ancient to danielisew UNSUCCESSFUL

Bought level 60 ancient/range hybrid off jaamal UNSUCCESSFUL - he recovered next day

Bought level 86 main and pure ranger of MR.SANTA - Sent false details. Scammed. Left ttg. STILL OWES ME RANGER.[/color]

 Bought lvl 40str pure off BloodSplatter SUCCESSFUL --- TRUSTED

 Transfered Items for BloodSplatter  SUCCESSFUL

Sold sig to DeScReTe GoD - SUCCESSFUL- He went first - NO MM[/color]

[color="#ff8c00"]Sold sig to FagexFun.- SUCCESSFUL - I went first - NO MM - this guy is fishy. <[email protected]> and <[email protected]> both the same guy[/color]

[color="#00ff00"]Sold 2 sigs 200k to ttg forum ownage - took a while - SUCCESSFUL

Sold lvl 30 skiller to Holes 2mil - He went first NO MM - SUCCESSFUL - Trusted

Sharing acc's with 4rrows k1ss - TRUSTED - SO FAR SO GOOD -[/color]

[color="#ff0000"]Bought ownage skiller from gummybear (Gummy Bear) (Sythe) - Vietballer mmed - SCAMMED - Lost 6m[/color]

[color="#00ff00"]Transfered Items For X Spec Nuthin - SUCCESS

Transfered Items For BloodSplatter - SUCCESS

Sold Account To Phaded Flame - Original owner hacked back - SCAMMED

Dr. Tim transferred 300k of items - SUCCESSFUL - TRUSTED

Dr. Tim transferred 2m - SUCCESSFUL - You rule dude.

Dr. Tim transferred some items and 100k - SUCCESS

Sold Main to rs_g0d_2007Email Removed 900k - No MM - I WENT FIRST - SUCCESS

Sold lvl 58 account to m4rk0z 250k - SUCCESS

Dr. Tim transferred items again - SUCCESSFUL - MEGA VOUCH

Sold Range Pure to Last Kaos 1m - SUCCESSFUL

Sold Mage Pure to whiplash - Scron1x MMed - SUCCESS

Sold Lvl 71 to cassady - NO MM - SUCCESS

[color="#ff0000"]Bought Zerker Pure from Hawk Eyes - SCAMMED - He scammed it back, Yded is useless.[/color]

[/color]

Freebies

[color="#00ff00"]Gave free sig to BloodSplatter

Gave free sig to 4rrow k1ss - he gave me a pixel - i put stuff on it.[/color]



[size="3"][color="#0000ff"]<--------------------MMING/XFERING------------------>[/color][/size]

[color="#00ff00"]MMed for m4rk0z and Zero - Account swap - SUCCESS

Transferred 170k for Teh only 0ne - SUCCESS

Transferred 800k for m4rk0z - SUCCESS

Transferred 100k for Ash - SUCCESS

Transferred 500k for Judge - SUCCESS

Transferred 10m for Neph - SUCCESS

Transferred 18m for Neph - SUCCESS

MMed for Oynx and Ran3rben93 - 4m and Tank / Ancients - SUCCESS

MMed for Ran3rben93 and L337pker - 1.6m and a Pin - SUCCESS

MMed for Shenub and K Thx - 2.6m and 2 Pins - SUCCESS

MMed for iwillpku and Mickey - 500k and Mauler - SUCCESS

Gave Gtech Warriors Free Lvl 95 - SUCCESS - Great Guy.

Gave Ash Free Skiller - SUCCESS - Crazy Guy

Gave AbdulAlzherad free hybrid because he got scammed - SUCCESS

MMed 10m for r1ch b0y - SUCCESS[/color]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Win32/Heur
« Reply #1 on: April 26, 2009, 10:14:32 AM »
Hello again

Download [color=\"#FF0000\"]> ATF Cleaner <[/color] by Atribune and save it to your Desktop.

Double Click on ATF-Cleaner.exe to Run it
Check the boxes to the left of:

Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
*Prefetch (Windows XP) only.
Java Cache

The rest are optional - if you want to remove the lot, check "Select All".
Finally click Empty Selected. When you get the "Done Cleaning" message, click OK.
If you use Firefox browser
      Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit from the Main menu

download Malwarebytes' Anti-Malware from Here or Here
Save the installer to desktop

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to [color=\"#006400\"]Update Malwarebytes' Anti-Malware[/color] and [color=\"#006400\"]Launch Malwarebytes' Anti-Malware[/color], then click Finish.
       
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
       
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
       
  • Make sure that everything is checked, and click Remove Selected.
        * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
       
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Also post a fresh Hijackthis log

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Amethyst

  • Newbie
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Win32/Heur
« Reply #2 on: April 26, 2009, 10:56:11 AM »
Malwarebytes' Anti-Malware 1.36
Database version: 2043
Windows 5.1.2600 Service Pack 3

4/26/2009 4:40:12 PM
mbam-log-2009-04-26 (16-40-12).txt

Scan type: Quick Scan
Objects scanned: 83881
Time elapsed: 11 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 27
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 47
Files Infected: 1181

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{29aa1b1d-e701-464c-9a68-ee9053ffa441} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{29aa1b1d-e701-464c-9a68-ee9053ffa441} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/publisher,version=0.2.0 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/updater,version=0.2.0 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yujalepega (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\All Users\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo03 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo03\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060\resources\gid329 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060\resources\gid329\cid1124 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060\resources\gid329\cid1124\bebo03 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060\resources\gid329\cid1124\bebo03\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4060\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4115 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152\resources\gid329 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4152\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4520 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4520\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Updater (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Updater\4115 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Updater\4458 (Adware.VideoEgg) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\VideoEgg\Loader\4115\npvideoegg-loader.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\VideoEgg\user.dat (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\report.log (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\aol_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\audio_combo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\audio_source.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\bebo_tv_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\bebo_tv_watermark_1.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\big_gray_logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\big_logo_cropped.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\blank_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorders_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_slide copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_left_curve.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_top_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_horiz.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_vertical.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropzone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_instructions.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\eraser.CUR (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\eraser_cursor.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\file_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\file_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\help.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_camcorders.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_ff.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_webcams.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\loading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\loading_movie.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\locating.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_bottom.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_middle.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_top.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_btn_highlighted copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_slide_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\movie_placeholder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fast_forward_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind_to_start.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\playhead.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\powered_by.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\progress.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\skin.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\skin.zip (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_over_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\tab_slide_deselected.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\tape_control.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_medium.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_thumbnail.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_from.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg-large.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg-small.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_gray.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_green.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_orange.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_red.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\waiting_for_email.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcams_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcam_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcam_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\publisher.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\dataCollection.tmp (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\remoteblacklist (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\report.log (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\aol_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\audio_combo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\audio_source.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\bebo_tv_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\bebo_tv_watermark1.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\big_gray_logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\big_logo_cropped.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\blank_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\button_browse_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\button_browse_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\button_browse_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\button_browse_upcopy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\camcorders_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\camcorder_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\camcorder_slide copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\camcorder_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\corners_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\corners_bottom_left_curve.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\corners_bottom_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\corners_top_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\done.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\done_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\done_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\done_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\done_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\done_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dropshadow_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dropshadow_horiz.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dropshadow_vertical.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dropzone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dv_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dv_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dv_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dv_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\dv_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\email_instructions.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\email_sent.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\email_sent_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\email_sent_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\eraser.CUR (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\eraser_cursor.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\file_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\file_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\help.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_camcorder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_camcorders.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_camcorder_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_camcorder_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_ff.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_file_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_file_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_phone_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_phone_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_webcam.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_webcams.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_webcam_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\icon_webcam_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\loading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\loading_movie.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\locating.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\logo_bottom.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\logo_middle.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\logo_top.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\mobile_btn_highlighted copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\mobile_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\mobile_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\mobile_slide_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\movie_placeholder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\ok.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\ok_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\ok_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\player_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images\player_fast_forward_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laurence Smyth\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\be
Hiya
No, i'm not a scammer. I said I scammed someone to get banned because my activity on the markets was going to affect my GCSE grades. Sorry to those I [censored] with. Don't believe me? Find proof then. Oh wait, there is none.






<-----------TRANSACTIONS----------->

[color="#00ff00"][color="#ff0000"]Traded level 70 main for level 53 ancient to danielisew UNSUCCESSFUL

Bought level 60 ancient/range hybrid off jaamal UNSUCCESSFUL - he recovered next day

Bought level 86 main and pure ranger of MR.SANTA - Sent false details. Scammed. Left ttg. STILL OWES ME RANGER.[/color]

 Bought lvl 40str pure off BloodSplatter SUCCESSFUL --- TRUSTED

 Transfered Items for BloodSplatter  SUCCESSFUL

Sold sig to DeScReTe GoD - SUCCESSFUL- He went first - NO MM[/color]

[color="#ff8c00"]Sold sig to FagexFun.- SUCCESSFUL - I went first - NO MM - this guy is fishy. <[email protected]> and <[email protected]> both the same guy[/color]

[color="#00ff00"]Sold 2 sigs 200k to ttg forum ownage - took a while - SUCCESSFUL

Sold lvl 30 skiller to Holes 2mil - He went first NO MM - SUCCESSFUL - Trusted

Sharing acc's with 4rrows k1ss - TRUSTED - SO FAR SO GOOD -[/color]

[color="#ff0000"]Bought ownage skiller from gummybear (Gummy Bear) (Sythe) - Vietballer mmed - SCAMMED - Lost 6m[/color]

[color="#00ff00"]Transfered Items For X Spec Nuthin - SUCCESS

Transfered Items For BloodSplatter - SUCCESS

Sold Account To Phaded Flame - Original owner hacked back - SCAMMED

Dr. Tim transferred 300k of items - SUCCESSFUL - TRUSTED

Dr. Tim transferred 2m - SUCCESSFUL - You rule dude.

Dr. Tim transferred some items and 100k - SUCCESS

Sold Main to rs_g0d_2007Email Removed 900k - No MM - I WENT FIRST - SUCCESS

Sold lvl 58 account to m4rk0z 250k - SUCCESS

Dr. Tim transferred items again - SUCCESSFUL - MEGA VOUCH

Sold Range Pure to Last Kaos 1m - SUCCESSFUL

Sold Mage Pure to whiplash - Scron1x MMed - SUCCESS

Sold Lvl 71 to cassady - NO MM - SUCCESS

[color="#ff0000"]Bought Zerker Pure from Hawk Eyes - SCAMMED - He scammed it back, Yded is useless.[/color]

[/color]

Freebies

[color="#00ff00"]Gave free sig to BloodSplatter

Gave free sig to 4rrow k1ss - he gave me a pixel - i put stuff on it.[/color]



[size="3"][color="#0000ff"]<--------------------MMING/XFERING------------------>[/color][/size]

[color="#00ff00"]MMed for m4rk0z and Zero - Account swap - SUCCESS

Transferred 170k for Teh only 0ne - SUCCESS

Transferred 800k for m4rk0z - SUCCESS

Transferred 100k for Ash - SUCCESS

Transferred 500k for Judge - SUCCESS

Transferred 10m for Neph - SUCCESS

Transferred 18m for Neph - SUCCESS

MMed for Oynx and Ran3rben93 - 4m and Tank / Ancients - SUCCESS

MMed for Ran3rben93 and L337pker - 1.6m and a Pin - SUCCESS

MMed for Shenub and K Thx - 2.6m and 2 Pins - SUCCESS

MMed for iwillpku and Mickey - 500k and Mauler - SUCCESS

Gave Gtech Warriors Free Lvl 95 - SUCCESS - Great Guy.

Gave Ash Free Skiller - SUCCESS - Crazy Guy

Gave AbdulAlzherad free hybrid because he got scammed - SUCCESS

MMed 10m for r1ch b0y - SUCCESS[/color]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Win32/Heur
« Reply #3 on: April 26, 2009, 11:24:44 AM »
Download [color=\"#FF0000\"]Rooter.exe[/color] to your desktop

    * Then doubleclick it to start the tool
    * A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Download [color=\"#FF0000\"]OTListIt2[/color][/url] by OldTimer to your Desktop.
  • Close all windows and double click OTListIt2.exe
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up - OTListIt2.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
  • You may need to use two posts to get it all.

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Amethyst

  • Newbie
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Win32/Heur
« Reply #4 on: April 26, 2009, 11:42:32 AM »
ROOTER:

Microsoft Windows XP Professional (5.1.2600) Service Pack 3

C:\ [Fixed] - NTFS - (Total:79305 Mo/Free:3206 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
H:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

Sun 04/26/2009|17:32

----------------------\\  Processes..

--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
---------- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
---------- C:\Program Files\Bonjour\mDNSResponder.exe
---------- C:\Program Files\Google\Update\GoogleUpdate.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\PROGRA~1\AVG\AVG8\avgrsx.exe
---------- C:\WINDOWS\system32\HPZipm12.exe
---------- C:\PROGRA~1\AVG\AVG8\avgnsx.exe
---------- C:\WINDOWS\system32\PnkBstrA.exe
---------- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
---------- C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\wdfmgr.exe
---------- C:\Program Files\Viewpoint\Common\ViewpointService.exe
---------- C:\PROGRA~1\AVG\AVG8\avgemc.exe
---------- C:\Program Files\AVG\AVG8\avgcsrvx.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
---------- C:\WINDOWS\RTHDCPL.EXE
---------- C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
---------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
---------- C:\WINDOWS\AGRSMMSG.exe
---------- C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE
---------- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
---------- C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
---------- C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
---------- C:\WINDOWS\SM1BG.EXE
---------- C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
---------- C:\WINDOWS\vsnpstd.exe
---------- C:\Program Files\Xfire\xfiremusic.exe
---------- C:\PROGRA~1\AVG\AVG8\avgtray.exe
---------- C:\Program Files\iTunes\iTunesHelper.exe
---------- C:\WINDOWS\vsnp2uvc.exe
---------- C:\Program Files\Java\jre6\bin\jusched.exe
---------- C:\Program Files\Samsung\DisplayManager\dmhkcore.exe
---------- C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
---------- C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
---------- C:\Program Files\Messenger\msmsgs.exe
---------- C:\program files\steam\steam.exe
---------- C:\Program Files\iPod\bin\iPodService.exe
---------- C:\Program Files\Xfire\xfire.exe
---------- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
---------- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
---------- C:\Program Files\Windows Live\Messenger\usnsvc.exe
---------- C:\Program Files\Mozilla Firefox\firefox.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe

----------------------\\  Search..

----------------------\\  ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - Sun 04/26/2009|17:29
2 - "C:\Rooter$\Rooter_2.txt" - Sun 04/26/2009|17:33

----------------------\\  Scan completed at 17:33


OTListIt2:

OTListIt logfile created on: 4/26/2009 5:33:56 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0     Folder = C:\Documents and Settings\Laurence Smyth\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
894.07 Mb Total Physical Memory | 203.42 Mb Available Physical Memory | 22.75% Memory free
2.12 Gb Paging File | 1.42 Gb Available in Paging File | 67.23% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 77.45 Gb Total Space | 15.13 Gb Free Space | 19.54% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: YOUR-1E7F2E88C6
Current User Name: Laurence Smyth
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
 
[color=\"orange\"]========== Processes (SafeList) ==========[/color]
 
PRC - [2006/03/29 07:42:44 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2006/05/24 19:31:06 | 00,372,736 | ---- | M] () -- C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
PRC - [2008/10/01 14:06:14 | 00,116,040 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/02/02 21:06:48 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2008/08/29 11:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/09/10 22:18:01 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2006/03/29 07:42:44 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2006/01/20 19:20:00 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2008/04/14 01:12:19 | 00,975,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009/02/02 21:07:06 | 00,484,120 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2004/09/29 12:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2009/02/02 21:03:43 | 00,592,128 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2008/04/29 20:56:21 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe
PRC - [2008/04/08 00:45:10 | 00,241,734 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PRC - [2005/05/28 16:35:56 | 00,036,864 | R--- | M] () -- C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
PRC - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
PRC - [2007/01/04 22:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2009/02/02 21:03:34 | 00,903,960 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/02/02 21:05:27 | 00,687,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2006/01/03 02:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/04/05 01:44:58 | 16,120,832 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2006/03/28 21:27:16 | 00,634,880 | ---- | M] () -- C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
PRC - [2005/12/07 22:44:16 | 00,761,947 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2006/06/29 21:32:14 | 00,089,541 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
PRC - [2004/09/23 18:27:48 | 00,114,688 | ---- | M] (FarStone Tech. Inc.) -- C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE
PRC - [2004/11/03 04:24:46 | 00,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2006/04/25 22:05:48 | 02,764,800 | ---- | M] () -- C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
PRC - [2006/05/04 03:22:18 | 00,413,696 | ---- | M] (SAMSUNG ELECTRONICS) -- C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
PRC - [2003/08/27 15:20:00 | 00,094,208 | R--- | M] (Cypress Semiconductor) -- C:\WINDOWS\SM1BG.EXE
PRC - [2000/06/19 08:51:16 | 00,031,744 | ---- | M] () -- C:\Program Files\TextBridge Pro 9.0\Bin\InstantAccess.exe
PRC - [2004/06/10 13:48:04 | 00,286,720 | ---- | M] () -- C:\WINDOWS\vsnpstd.exe
PRC - [2006/11/21 03:12:50 | 00,253,650 | ---- | M] () -- C:\Program Files\Xfire\xfiremusic.exe
PRC - [2009/02/02 21:04:29 | 01,601,304 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2008/10/01 19:57:12 | 00,289,576 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2007/07/11 16:31:14 | 00,569,344 | ---- | M] (Sonix) -- C:\WINDOWS\vsnp2uvc.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2006/05/04 03:11:02 | 00,520,192 | ---- | M] (SAMSUNG) -- C:\Program Files\Samsung\DisplayManager\dmhkcore.exe
PRC - [2006/06/12 17:23:24 | 00,372,736 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
PRC - [2007/10/18 12:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
PRC - [2008/04/14 01:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2008/10/08 18:43:42 | 01,410,296 | ---- | M] (Valve Corporation) -- C:\program files\steam\steam.exe
PRC - [2008/10/01 19:57:00 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/04/11 00:22:58 | 03,111,248 | ---- | M] (Xfire Inc.) -- C:\Program Files\Xfire\xfire.exe
PRC - [2006/01/03 02:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/01/03 02:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2007/10/18 12:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe
PRC - [2009/04/23 18:16:41 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/04/26 17:30:03 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Laurence Smyth\Desktop\OTListIt2.exe
 
[color=\"orange\"]========== Win32 Services (SafeList) ==========[/color]
 
SRV - [2008/10/01 14:06:14 | 00,116,040 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2006/03/29 07:42:44 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2009/02/02 21:03:34 | 00,903,960 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running])
SRV - [2009/02/02 21:06:48 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2008/08/29 11:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/09/10 22:18:01 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c9138abbc2a9e2 [Auto | Stopped])
SRV - [2008/04/14 01:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005/11/14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008/10/01 19:57:00 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2006/01/20 19:20:00 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2006/12/14 02:21:20 | 00,045,056 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV [On_Demand | Stopped])
SRV - [2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/12/14 01:46:16 | 00,057,344 | ---- | M] () -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR [On_Demand | Stopped])
SRV - [2004/09/29 12:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2008/04/29 20:56:21 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2008/04/08 00:45:10 | 00,241,734 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running])
SRV - [2006/07/21 10:51:38 | 00,057,344 | ---- | M] () -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- (Samsung Update Plus [Auto | Stopped])
SRV - [2005/05/28 16:35:56 | 00,036,864 | R--- | M] () -- C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe -- (SNM WLAN Service [Auto | Running])
SRV - [2007/02/05 10:11:16 | 00,112,184 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service [On_Demand | Stopped])
SRV - [2006/12/14 02:02:08 | 00,069,632 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV [On_Demand | Stopped])
SRV - [2007/02/05 10:11:18 | 00,075,320 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV [On_Demand | Stopped])
SRV - [2006/05/24 19:31:06 | 00,372,736 | ---- | M] () -- C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe -- (StyleXPService [Auto | Running])
SRV - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])
SRV - [2007/10/18 12:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])
SRV - [2007/01/04 22:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service [Auto | Running])
SRV - [2007/10/25 16:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
 
[color=\"orange\"]========== Driver Services (SafeList) ==========[/color]
 
DRV - [2006/06/29 21:13:08 | 01,160,320 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\DRIVERS\AGRSM.sys -- (AgereSoftModem [On_Demand | Running])
DRV - [2007/07/26 14:19:24 | 00,547,904 | ---- | M] (Atheros Communications, Inc.) -- C:\WINDOWS\system32\DRIVERS\ar5211.sys -- (AR5211 [On_Demand | Running])
DRV - [2006/03/29 07:50:14 | 01,522,688 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2009/02/02 21:07:45 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
DRV - [2009/02/02 21:07:41 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
DRV - [2009/02/02 21:07:49 | 00,107,272 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX [System | Running])
DRV - [2004/10/15 12:50:20 | 00,015,295 | ---- | M] (Brother Industries Ltd.) -- C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys -- (BrScnUsb [On_Demand | Stopped])
DRV - [2006/04/12 18:04:46 | 00,065,784 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\System32\Drivers\btwusb.sys -- (BTWUSB [On_Demand | Stopped])
DRV - [2006/10/18 02:00:00 | 00,002,432 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp [System | Running])
DRV - [2006/10/18 02:00:00 | 00,002,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k [System | Running])
DRV - [2006/03/29 20:59:12 | 00,027,648 | ---- | M] (Samsung Electronics,.LTD) -- C:\WINDOWS\system32\drivers\SamsungEDS.sys -- (DNSeFilter [On_Demand | Running])
DRV - [2005/10/27 05:18:05 | 00,004,300 | ---- | M] () -- C:\WINDOWS\system32\MEMIO.SYS -- (DOSMEMIO [Auto | Running])
DRV - [2004/05/18 22:43:54 | 00,005,088 | ---- | M] () -- C:\WINDOWS\system32\drivers\FBAPI.sys -- (FBAPI [Auto | Running])
DRV - [2008/04/17 14:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2007/09/25 17:37:48 | 00,013,352 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\WINDOWS\system32\DRIVERS\ggflt.sys -- (ggflt [On_Demand | Stopped])
DRV - [2007/09/25 17:37:50 | 00,020,520 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\WINDOWS\system32\DRIVERS\ggsemc.sys -- (ggsemc [On_Demand | Stopped])
DRV - [2007/09/29 10:36:13 | 00,026,056 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\system32\DRIVERS\hamachi.sys -- (hamachi [On_Demand | Running])
DRV - [2008/04/13 17:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2006/04/06 22:20:44 | 04,258,816 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2007/05/11 17:31:22 | 00,041,888 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys -- (LVUSBSta [On_Demand | Stopped])
DRV - [2007/05/11 17:31:36 | 03,580,832 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\lvuvc.sys -- (LVUVC [On_Demand | Stopped])
DRV - [2009/02/24 18:42:14 | 00,116,736 | ---- | M] (MagicISO, Inc.) -- C:\WINDOWS\system32\DRIVERS\mcdbus.sys -- (mcdbus [On_Demand | Running])
DRV - [2008/04/13 19:53:09 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped])
DRV - [2004/08/04 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2007/03/08 00:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2005/11/17 04:28:32 | 00,028,928 | ---- | M] (REDC) -- C:\WINDOWS\system32\DRIVERS\rimmptsk.sys -- (rimmptsk [On_Demand | Running])
DRV - [2005/11/02 01:54:50 | 00,051,584 | ---- | M] (REDC) -- C:\WINDOWS\system32\DRIVERS\rimsptsk.sys -- (rimsptsk [On_Demand | Running])
DRV - [2005/11/02 02:08:00 | 00,308,992 | ---- | M] (REDC) -- C:\WINDOWS\system32\DRIVERS\rixdptsk.sys -- (rismxdp [On_Demand | Running])
DRV - [2004/05/18 22:43:58 | 00,043,512 | ---- | M] () -- C:\WINDOWS\System32\drivers\RITCPT.SYS -- (RITCPT [Boot | Running])
DRV - [2004/08/04 13:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Stopped])
DRV - [2006/01/19 02:41:58 | 00,080,512 | ---- | M] (Realtek Semiconductor Corporation                           ) -- C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys -- (RTL8023xp [On_Demand | Running])
DRV - [2004/08/03 23:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Stopped])
DRV - [2007/04/23 13:54:46 | 00,083,208 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s115bus.sys -- (s115bus [On_Demand | Stopped])
DRV - [2007/04/23 13:54:48 | 00,015,112 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s115mdfl.sys -- (s115mdfl [On_Demand | Stopped])
DRV - [2007/04/23 13:54:48 | 00,108,680 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s115mdm.sys -- (s115mdm [On_Demand | Stopped])
DRV - [2007/04/23 13:54:50 | 00,100,488 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s115mgmt.sys -- (s115mgmt [On_Demand | Stopped])
DRV - [2007/04/23 13:54:50 | 00,098,568 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s115obex.sys -- (s115obex [On_Demand | Stopped])
DRV - [2007/04/24 09:33:34 | 00,083,336 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s125bus.sys -- (s125bus [On_Demand | Stopped])
DRV - [2007/11/13 11:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2007/08/22 20:51:28 | 09,611,520 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\snp2uvc.sys -- (SNP2UVC [On_Demand | Stopped])
DRV - [2005/06/20 21:27:02 | 00,390,912 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\snpstd.sys -- (snpstd [On_Demand | Stopped])
DRV - [2008/07/18 21:30:00 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006/01/16 19:15:24 | 00,470,112 | ---- | M] (Atheros Communications, Inc.) -- C:\WINDOWS\system32\DRIVERS\SSB2413.sys -- (SSB2413 [On_Demand | Stopped])
DRV - [2001/08/17 13:53:32 | 00,006,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\serscan.sys -- (StillCam [On_Demand | Running])
DRV - [2005/10/31 22:44:39 | 00,010,880 | ---- | M] (Windows ® 2000 DDK provider) -- C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe -- (StyleXPHelper [System | Running])
DRV - [2005/12/07 22:30:52 | 00,191,936 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])
DRV - [2008/07/22 20:32:44 | 00,032,000 | ---- | M] (Apple, Inc.) -- C:\WINDOWS\System32\Drivers\usbaapl.sys -- (USBAAPL [On_Demand | Stopped])
DRV - [2008/04/13 19:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
DRV - [2007/07/11 11:40:18 | 00,012,416 | ---- | M] (LG Electronics Inc.) -- C:\WINDOWS\system32\DRIVERS\lgusbbus.sys -- (usbbus [On_Demand | Stopped])
DRV - [2007/07/11 16:51:48 | 00,019,840 | ---- | M] (LG Electronics Inc.) -- C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys -- (UsbDiag [On_Demand | Stopped])
DRV - [2001/05/07 11:56:02 | 00,019,805 | R--- | M] (Thesycon GmbH, Germany) -- C:\WINDOWS\System32\Drivers\usbio.sys -- (USBIO [On_Demand | Stopped])
DRV - [2007/07/11 11:45:00 | 00,021,632 | ---- | M] (LG Electronics Inc.) -- C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys -- (USBModem [On_Demand | Stopped])
DRV - [2008/02/12 04:42:38 | 00,232,472 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\system32\Drivers\vmm.sys -- (vmm [System | Running])
DRV - [2008/02/05 02:50:44 | 00,059,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys -- (VPCNetS2 [On_Demand | Running])
DRV - [2005/08/08 00:09:00 | 00,183,159 | ---- | M] () -- C:\WINDOWS\System32\drivers\VVBackd5.sys -- (VVBackd5 [Boot | Running])
DRV - [2008/12/04 07:43:26 | 00,024,576 | ---- | M] (Exent Technologies Ltd.) -- C:\Program Files\GameTap\bin\Release\X4HSX32.Sys -- (X4HSX32 [Auto | Running])
 
[color=\"orange\"]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=\"orange\"]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src...autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
 
[color=\"orange\"]========== FireFox ==========[/color]
 
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.0.20080710
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.16.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:0.9
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.9
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/02/02 21:08:01 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [2009/02/02 21:02:26 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/10 21:02:45 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX\ [2009/04/25 10:44:55 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/23 18:17:30 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/23 18:17:29 | 00,000,000 | ---D | M]
 
[2008/08/26 15:57:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Extensions
[2008/08/26 15:57:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/26 14:45:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Firefox\Profiles\s2jlcsgt.default\extensions
[2008/02/12 08:50:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Firefox\Profiles\s2jlcsgt.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
[2007/06/27 21:55:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Firefox\Profiles\s2jlcsgt.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2007/05/09 18:57:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Firefox\Profiles\s2jlcsgt.default\extensions\{A7F962B4-3B89-4c03-847C-F3740A63D241}(2)
[2007/05/09 18:45:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Firefox\Profiles\s2jlcsgt.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}(2)
[2007/05/09 18:48:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Firefox\Profiles\s2jlcsgt.default\extensions\{C1CCF2A6-D735-4817-866A-993A66CF9A3D}(2)
[2009/03/24 23:35:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Laurence Smyth\Application Data\mozilla\Firefox\Profiles\s2jlcsgt.default\extensions\[email protected]
[2009/04/26 14:45:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2007/05/09 18:52:56 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2007/05/09 18:17:13 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}(2)
[2009/04/23 18:17:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/04/27 17:42:59 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}(2)
[2008/07/14 14:09:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/03/10 21:03:43 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/08 16:32:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2007/05/09 18:45:46 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\talkback@mozilla(2).org
[2007/05/09 18:17:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\talkback@mozilla(3).org
[2009/04/23 18:16:28 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/23 18:16:28 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/19 20:33:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/02/19 20:33:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/19 20:33:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/19 20:33:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/02/19 20:33:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/19 20:33:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/19 20:33:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
 
O1 HOSTS File: (813 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: 192.168.2.30 HP000D9D14FC46
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - Reg Error: Key error. File not found
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]----------------------------)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.16.0\gears.dll (Google Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]----------------------------)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]----------------------------)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [DMHotKey] C:\Program Files\Samsung\DisplayManager\DMLoader.exe (SAMSUNG)
O4 - HKLM..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe ()
O4 - HKLM..\Run: [farstone]  File not found
O4 - HKLM..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h ()
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE ()
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart (FarStone Tech. Inc.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe (Sonix)
O4 - HKLM..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe ()
O4 - HKLM..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Xfire Music] "C:\Program Files\Xfire\xfiremusic.exe" ()
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] "c:\program files\steam\steam.exe" -silent (Valve Corporation)
O4 - HKLM..\RunOnceEx: [Register Homesite+.exe] "C:\Program Files\Macromedia\HomeSite+\Homesite+.exe" /REGSERVER (Macromedia, Inc.)
O4 - HKLM..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe File not found
O4 - Startup: C:\Documents and Settings\Laurence Smyth\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\xfire.exe (Xfire Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm File not found
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html ()
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html ()
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html ()
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.16.0\gears.dll (Google Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Laurence Smyth\Start Menu\Programs\IMVU\Run IMVU.lnk File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 122 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab (CBreakshotControl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} http://messenger.zone.msn.com/binary/Chess.cab57176.cab (ZoneChess Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab (Minesweeper Flags Class)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Filter:  - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\dapavama.dll) - C:\WINDOWS\system32\dapavama.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O21 - SSODL: system32 - {C40C81EC-6607-49E0-99F9-E4E39B5044CE} -  File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/08/31 19:53:27 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{40772314-95bd-11db-a5a0-001377336c06}\Shell\Auto\command - "" = E:\tel.xls.exe -- File not found
O33 - MountPoints2\{40772314-95bd-11db-a5a0-001377336c06}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{40772317-95bd-11db-a5a0-001377336c06}\Shell\Auto\command - "" = G:\tel.xls.exe -- File not found
O33 - MountPoints2\{40772317-95bd-11db-a5a0-001377336c06}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{40772318-95bd-11db-a5a0-001377336c06}\Shell\Auto\command - "" = H:\tel.xls.exe -- File not found
O33 - MountPoints2\{40772318-95bd-11db-a5a0-001377336c06}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{df020ac6-cc42-11dd-a878-001167044828}\Shell - "" = AutoRun
O33 - MountPoints2\{df020ac6-cc42-11dd-a878-001167044828}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{df020ac6-cc42-11dd-a878-001167044828}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) -  File not found
 
[color=\"orange\"]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[36 C:\WINDOWS\System32\*.tmp files]
[2009/04/26 17:29:58 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\DOCUME~1\LAUREN~1\Desktop\OTListIt2.exe
[2009/04/26 17:26:37 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/04/26 17:26:28 | 00,267,612 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\Desktop\Rooter.exe
[2009/04/26 16:20:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Laurence Smyth\Application Data\Malwarebytes
[2009/04/26 16:19:40 | 00,000,696 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/26 16:19:34 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/26 16:19:30 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/26 16:19:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/26 16:19:25 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/26 16:18:12 | 02,967,800 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\DOCUME~1\LAUREN~1\Desktop\mbam-setup.exe
[2009/04/26 16:00:11 | 00,001,734 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\Desktop\HijackThis.lnk
[2009/04/26 16:00:08 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/04/26 15:58:56 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\DOCUME~1\LAUREN~1\Desktop\HJTInstall.exe
[2009/04/26 00:43:22 | 06,642,878 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\01_merry_christmas_mr.mp3
[2009/04/26 00:32:24 | 09,121,010 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\Merry chrismas Mr. Lawrence.mp3
[2009/04/26 00:17:15 | 00,054,476 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\flagfinal1.jpg
[2009/04/25 23:48:53 | 00,102,009 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\isabanner.png
[2009/04/25 23:12:26 | 00,117,486 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\isa.png
[2009/04/22 22:17:03 | 00,004,286 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\NewtonRaphson.agg
[2009/04/22 20:29:03 | 01,271,990 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\Desktop\Coursework CORE 3 MATHS.docx
[2009/04/21 21:14:09 | 00,013,635 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\n1022180368_8863.jpg
[2009/04/20 20:57:45 | 00,000,000 | ---D | C] -- C:\DOCUME~1\LAUREN~1\My Documents\R4Alice
[2009/04/20 20:34:53 | 00,000,848 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Status Monitor.lnk
[2009/04/20 20:29:53 | 00,000,000 | ---D | C] -- C:\DOCUME~1\LAUREN~1\My Documents\Backup
[2009/04/20 20:13:01 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/04/20 20:07:21 | 00,077,824 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\Desktop\Startup.exe
[2009/04/19 21:42:41 | 00,000,000 | ---D | C] -- C:\DOCUME~1\LAUREN~1\My Documents\My Scans
[2009/04/19 21:42:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Laurence Smyth\Local Settings\Application Data\IsolatedStorage
[2009/04/19 21:42:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Laurence Smyth\Local Settings\Application Data\HP
[2009/04/19 21:20:57 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2009/04/19 21:20:56 | 00,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2009/04/19 21:12:58 | 00,000,000 | ---D | C] -- C:\DOCUME~1\LAUREN~1\My Documents\DvoConsumer.portal_files
[2009/04/19 21:10:14 | 00,459,400 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\PDF.pdf
[2009/04/19 16:41:14 | 00,468,879 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\DUKE3DS016nds.rar
[2009/04/19 16:23:57 | 01,289,983 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\My Documents\Sonic and Knuckles (JUE) [!].zip
[2009/04/19 15:36:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HP
[2009/04/19 15:31:43 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2009/04/19 15:24:51 | 00,000,000 | ---D | C] -- C:\Program Files\Hewlett-Packard
[2009/04/19 15:22:47 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Hewlett-Packard
[2009/04/19 15:19:03 | 00,009,864 | R--- | C] () -- C:\WINDOWS\System32\hptcpmui.hlp
[2009/04/19 15:19:03 | 00,003,399 | R--- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2009/04/19 15:19:03 | 00,000,147 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2009/04/19 15:19:02 | 00,212,992 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hptcpmui.dll
[2009/04/19 15:19:01 | 00,102,400 | R--- | C] (Hewlett Packard) -- C:\WINDOWS\System32\hpzjrd01.dll
[2009/04/19 15:19:00 | 00,122,880 | R--- | C] (Hewlett Packard) -- C:\WINDOWS\System32\hptcpmon.dll
[2009/04/19 15:19:00 | 00,098,304 | R--- | C] (Hewlett Packard Company) -- C:\WINDOWS\System32\hpzjsn01.dll
[2009/04/19 15:19:00 | 00,073,728 | R--- | C] (Hewlett Packard) -- C:\WINDOWS\System32\hptcpmib.dll
[2009/04/19 15:17:16 | 00,001,036 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2009/04/19 15:12:30 | 00,000,000 | ---D | C] -- C:\Program Files\HP
[2009/04/19 15:08:13 | 00,068,383 | ---- | C] () -- C:\WINDOWS\hpoins05.dat
[2009/04/19 15:08:13 | 00,019,696 | ---- | C] () -- C:\WINDOWS\hpomdl05.dat
[2009/04/19 01:15:39 | 00,000,000 | ---D | C] -- C:\Program Files\Panasonic
[2009/04/18 00:05:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Laurence Smyth\Local Settings\Application Data\Aspyr
[2009/04/18 00:05:01 | 00,000,000 | ---D | C] -- C:\DOCUME~1\LAUREN~1\My Documents\Aspyr
[2009/04/17 22:15:32 | 03,727,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_35.dll
[2009/04/17 22:15:24 | 00,081,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_3.dll
[2009/04/17 22:05:10 | 00,116,736 | ---- | C] (MagicISO, Inc.) -- C:\WINDOWS\System32\drivers\mcdbus.sys
[2009/04/17 22:05:05 | 00,000,000 | ---D | C] -- C:\Program Files\MagicDisc
[2009/04/17 20:57:52 | 00,000,000 | ---D | C] -- C:\Program Files\MagicISO
[2009/04/17 17:40:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Blizzard
[2009/04/17 17:38:11 | 00,000,000 | ---D | C] -- C:\Program Files\World of Warcraft Trial
[2009/04/16 15:52:52 | 00,000,802 | ---- | C] () -- C:\DOCUME~1\LAUREN~1\Desktop\Short cut for HS-DHGLCB2.lnk
[2009/04/16 15:52:30 | 00,000,000 | ---D | C] -- C:\Program Files\BUFFALO
[2009/04/16 15:09:47 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Autograph 3
[2009/04/16 15:09:46 | 00,000,000 | ---D | C] -- C:\Program Files\Autograph 3.20
[2009/04/16 14:30:07 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft V
Hiya
No, i'm not a scammer. I said I scammed someone to get banned because my activity on the markets was going to affect my GCSE grades. Sorry to those I [censored] with. Don't believe me? Find proof then. Oh wait, there is none.






<-----------TRANSACTIONS----------->

[color="#00ff00"][color="#ff0000"]Traded level 70 main for level 53 ancient to danielisew UNSUCCESSFUL

Bought level 60 ancient/range hybrid off jaamal UNSUCCESSFUL - he recovered next day

Bought level 86 main and pure ranger of MR.SANTA - Sent false details. Scammed. Left ttg. STILL OWES ME RANGER.[/color]

 Bought lvl 40str pure off BloodSplatter SUCCESSFUL --- TRUSTED

 Transfered Items for BloodSplatter  SUCCESSFUL

Sold sig to DeScReTe GoD - SUCCESSFUL- He went first - NO MM[/color]

[color="#ff8c00"]Sold sig to FagexFun.- SUCCESSFUL - I went first - NO MM - this guy is fishy. <[email protected]> and <[email protected]> both the same guy[/color]

[color="#00ff00"]Sold 2 sigs 200k to ttg forum ownage - took a while - SUCCESSFUL

Sold lvl 30 skiller to Holes 2mil - He went first NO MM - SUCCESSFUL - Trusted

Sharing acc's with 4rrows k1ss - TRUSTED - SO FAR SO GOOD -[/color]

[color="#ff0000"]Bought ownage skiller from gummybear (Gummy Bear) (Sythe) - Vietballer mmed - SCAMMED - Lost 6m[/color]

[color="#00ff00"]Transfered Items For X Spec Nuthin - SUCCESS

Transfered Items For BloodSplatter - SUCCESS

Sold Account To Phaded Flame - Original owner hacked back - SCAMMED

Dr. Tim transferred 300k of items - SUCCESSFUL - TRUSTED

Dr. Tim transferred 2m - SUCCESSFUL - You rule dude.

Dr. Tim transferred some items and 100k - SUCCESS

Sold Main to rs_g0d_2007Email Removed 900k - No MM - I WENT FIRST - SUCCESS

Sold lvl 58 account to m4rk0z 250k - SUCCESS

Dr. Tim transferred items again - SUCCESSFUL - MEGA VOUCH

Sold Range Pure to Last Kaos 1m - SUCCESSFUL

Sold Mage Pure to whiplash - Scron1x MMed - SUCCESS

Sold Lvl 71 to cassady - NO MM - SUCCESS

[color="#ff0000"]Bought Zerker Pure from Hawk Eyes - SCAMMED - He scammed it back, Yded is useless.[/color]

[/color]

Freebies

[color="#00ff00"]Gave free sig to BloodSplatter

Gave free sig to 4rrow k1ss - he gave me a pixel - i put stuff on it.[/color]



[size="3"][color="#0000ff"]<--------------------MMING/XFERING------------------>[/color][/size]

[color="#00ff00"]MMed for m4rk0z and Zero - Account swap - SUCCESS

Transferred 170k for Teh only 0ne - SUCCESS

Transferred 800k for m4rk0z - SUCCESS

Transferred 100k for Ash - SUCCESS

Transferred 500k for Judge - SUCCESS

Transferred 10m for Neph - SUCCESS

Transferred 18m for Neph - SUCCESS

MMed for Oynx and Ran3rben93 - 4m and Tank / Ancients - SUCCESS

MMed for Ran3rben93 and L337pker - 1.6m and a Pin - SUCCESS

MMed for Shenub and K Thx - 2.6m and 2 Pins - SUCCESS

MMed for iwillpku and Mickey - 500k and Mauler - SUCCESS

Gave Gtech Warriors Free Lvl 95 - SUCCESS - Great Guy.

Gave Ash Free Skiller - SUCCESS - Crazy Guy

Gave AbdulAlzherad free hybrid because he got scammed - SUCCESS

MMed 10m for r1ch b0y - SUCCESS[/color]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Win32/Heur
« Reply #5 on: April 26, 2009, 12:02:55 PM »
I would like to run one more scanner please
Download ComboFix from one of these locations:

[color=\"#0000FF\"]Link 1[/color]
[color=\"#0000FF\"]Link 2[/color]
[color=\"#FF0000\"]Save it ONLY to your Desktop[/color]

      --------------------------------------------------------------------
[color=\"#2E8B57\"]Temporarily Disable your AntiVirus/AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with this tool
[/color]
AVG 8
Please open the AVG 8 Control Center, by right clicking on the AVG 8 icon on task bar.

    * Click on Tools.
    * Select Advanced.
    * In the left hand pane, scroll down to "Resident Shield".
    * In the main pane, deselect the option to "Enable Resident Shield."
     

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


[color=\"#2e8b57\"]**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[/color]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply

NOTE: Do not mouseclick inside ComboFix window as it's running, it may cause it to stall
ComboFix will/may run again on startup, it will prompt that it's creating a log
This process could take up to 10 minutes, let it run uninterrupted please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Amethyst

  • Newbie
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Win32/Heur
« Reply #6 on: April 26, 2009, 12:46:09 PM »
ComboFix 09-04-25.A3 - Laurence Smyth 04/26/2009 18:15.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.894.203 [GMT 1:00]
Running from: c:\documents and settings\Laurence Smyth\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF


(((((((((((((((((((((((((   Files Created from 2009-05-26 to 2009-4-26  )))))))))))))))))))))))))))))))
.

2009-04-26 16:26 . 2009-04-26 16:33    --------    d-----w    C:\Rooter$
2009-04-26 15:20 . 2009-04-26 15:20    --------    d-----w    c:\documents and settings\Laurence Smyth\Application Data\Malwarebytes
2009-04-26 15:19 . 2009-04-06 14:32    15504    ----a-w    c:\windows\system32\drivers\mbam.sys
2009-04-26 15:19 . 2009-04-06 14:32    38496    ----a-w    c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-26 15:19 . 2009-04-26 15:19    --------    d-----w    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-26 15:19 . 2009-04-26 15:20    --------    d-----w    c:\program files\Malwarebytes' Anti-Malware
2009-04-26 15:00 . 2009-04-26 15:00    --------    d-----w    c:\program files\Trend Micro
2009-04-20 19:13 . 2009-04-20 19:13    --------    d-----w    c:\program files\CCleaner
2009-04-19 20:42 . 2009-04-19 20:42    --------    d-----w    c:\documents and settings\Laurence Smyth\Local Settings\Application Data\IsolatedStorage
2009-04-19 20:42 . 2009-04-19 20:42    --------    d-----w    c:\documents and settings\Laurence Smyth\Local Settings\Application Data\HP
2009-04-19 20:20 . 2001-08-17 21:36    5632    ----a-w    c:\windows\system32\ptpusb.dll
2009-04-19 20:20 . 2008-04-14 00:12    159232    ----a-w    c:\windows\system32\ptpusd.dll
2009-04-19 14:36 . 2009-04-19 14:36    --------    d-----w    c:\documents and settings\All Users\Application Data\HP
2009-04-19 14:31 . 2009-04-19 14:33    --------    d-----w    c:\program files\Common Files\HP
2009-04-19 14:24 . 2009-04-19 14:25    --------    d-----w    c:\program files\Hewlett-Packard
2009-04-19 14:22 . 2009-04-19 14:22    --------    d-----w    c:\program files\Common Files\Hewlett-Packard
2009-04-19 14:20 . 2004-10-01 04:01    139345    ----a-w    c:\windows\system32\hpzlnt12.dll
2009-04-19 14:17 . 2009-04-19 14:18    1036    ----a-w    c:\windows\hpntwksetup.ini
2009-04-19 14:14 . 2004-09-29 11:15    204800    ----a-w    c:\windows\system32\HPZipr12.dll
2009-04-19 14:14 . 2004-09-29 11:14    69632    ----a-w    c:\windows\system32\HPZipm12.exe
2009-04-19 14:14 . 2004-09-29 11:09    57344    ----a-w    c:\windows\system32\HPZisn12.dll
2009-04-19 14:14 . 2004-09-29 11:09    94208    ----a-w    c:\windows\system32\HPZipt12.dll
2009-04-19 14:14 . 2004-09-29 11:08    61440    ----a-w    c:\windows\system32\HPZinw12.exe
2009-04-19 14:14 . 2004-09-29 11:12    278584    ----a-w    c:\windows\system32\HPZidr12.dll
2009-04-19 14:12 . 2009-04-19 14:36    --------    d-----w    c:\program files\HP
2009-04-19 14:08 . 2009-04-19 14:40    68383    ----a-w    c:\windows\hpoins05.dat
2009-04-19 14:08 . 2004-12-14 17:39    19696    ------w    c:\windows\hpomdl05.dat
2009-04-19 00:15 . 2009-04-19 00:15    --------    d-----w    c:\program files\Panasonic
2009-04-19 00:15 . 2006-02-27 10:45    36864    ----a-w    c:\windows\system32\SDDEVMGR.dll
2009-04-17 23:05 . 2009-04-17 23:05    --------    d-----w    c:\documents and settings\Laurence Smyth\Local Settings\Application Data\Aspyr
2009-04-17 21:15 . 2007-07-19 17:14    3727720    ----a-w    c:\windows\system32\d3dx9_35.dll
2009-04-17 21:15 . 2007-04-04 17:53    81768    ----a-w    c:\windows\system32\xinput1_3.dll
2009-04-17 21:05 . 2009-02-24 17:42    116736    ----a-w    c:\windows\system32\drivers\mcdbus.sys
2009-04-17 21:05 . 2009-04-17 21:05    --------    d-----w    c:\program files\MagicDisc
2009-04-17 19:57 . 2009-04-17 20:13    --------    d-----w    c:\program files\MagicISO
2009-04-17 16:40 . 2009-04-17 16:40    --------    d-----w    c:\documents and settings\All Users\Application Data\Blizzard
2009-04-17 16:38 . 2009-04-17 16:40    --------    d-----w    c:\program files\World of Warcraft Trial
2009-04-16 14:52 . 2009-04-16 14:52    --------    d-----w    c:\program files\BUFFALO
2009-04-16 14:09 . 2009-04-16 14:18    --------    d-----w    c:\program files\Common Files\Autograph 3
2009-04-16 14:09 . 2009-04-16 14:23    --------    d-----w    c:\program files\Autograph 3.20
2009-04-16 13:27 . 2009-04-16 13:27    --------    d-----w    c:\program files\Microsoft.NET
2009-04-16 13:21 . 2009-04-16 13:21    --------    d-----w    c:\documents and settings\Laurence Smyth\Local Settings\Application Data\Microsoft Help
2009-04-16 13:19 . 2009-04-24 17:17    --------    d-----w    c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-16 13:18 . 2009-04-16 13:18    --------    d--h--r    C:\MSOCache
2009-04-15 19:23 . 2009-03-06 14:22    284160    -c----w    c:\windows\system32\dllcache\pdh.dll
2009-04-15 19:23 . 2009-02-09 12:10    401408    -c----w    c:\windows\system32\dllcache\rpcss.dll
2009-04-15 19:23 . 2009-02-06 11:11    110592    -c----w    c:\windows\system32\dllcache\services.exe
2009-04-15 19:23 . 2009-02-09 12:10    473600    -c----w    c:\windows\system32\dllcache\fastprox.dll
2009-04-15 19:23 . 2009-02-06 10:10    227840    -c----w    c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 19:23 . 2009-02-09 12:10    453120    -c----w    c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 19:23 . 2009-02-09 12:10    729088    -c----w    c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 19:23 . 2009-02-09 12:10    714752    -c----w    c:\windows\system32\dllcache\ntdll.dll
2009-04-15 19:23 . 2009-02-09 12:10    617472    -c----w    c:\windows\system32\dllcache\advapi32.dll
2009-04-15 19:22 . 2008-05-03 11:55    2560    ------w    c:\windows\system32\xpsp4res.dll
2009-04-15 19:21 . 2008-04-21 12:08    215552    -c----w    c:\windows\system32\dllcache\wordpad.exe
2009-04-14 09:07 . 2009-03-10 21:26    1403264    ----a-w    c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-04-14 09:07 . 2009-03-10 21:18    453512    ----a-w    c:\windows\system32\KB905474\wgasetup.exe
2009-04-14 09:07 . 2009-02-09 17:51    12490    ----a-w    c:\windows\system32\KB905474\wga_eula.txt
2009-04-14 09:07 . 2009-04-14 09:07    --------    d-----w    c:\windows\system32\KB905474
2009-04-11 15:52 . 2004-02-08 18:55    180132    ----a-w    c:\windows\system32\GDIPlus.tlb
2009-04-11 15:52 . 2003-02-19 14:07    303104    ----a-w    c:\windows\system32\cmcs21.dll
2009-04-11 15:52 . 2003-02-19 14:06    438272    ----a-w    c:\windows\system32\cmcs21.ocx
2009-04-11 15:52 . 2009-04-12 15:25    --------    d-----w    c:\program files\Doom Builder
2009-04-10 23:23 . 2009-04-10 23:23    41808    ----a-w    c:\windows\system32\xfcodec.dll
2009-04-08 21:23 . 2009-04-08 22:01    --------    d-----w    c:\documents and settings\Laurence Smyth\Application Data\fretsonfire
2009-04-08 21:22 . 2009-04-08 22:21    --------    d-----w    c:\program files\Frets on Fire
2009-04-05 18:34 . 2009-04-20 19:46    --------    d-----w    c:\documents and settings\All Users\Application Data\Electronic Arts
2009-04-05 18:34 . 2009-04-05 18:34    --------    d-----w    C:\ProgramData
2009-04-03 17:11 . 2009-04-05 18:34    --------    d-----w    c:\program files\Electronic Arts
2009-04-01 19:53 . 2009-04-01 19:53    --------    d-----w    c:\program files\Common Files\DirectX

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-26 17:23 . 2008-10-05 16:38    --------    d-----w    c:\program files\Steam
2009-04-26 16:33 . 2009-04-26 16:29    3929    ----a-w    C:\Rooter.txt
2009-04-26 16:31 . 2007-01-28 17:58    --------    d-----w    c:\documents and settings\Laurence Smyth\Application Data\uTorrent
2009-04-26 13:15 . 2006-08-31 19:17    84120    ----a-w    c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-25 09:44 . 2007-02-02 20:10    --------    d-----w    c:\program files\Google
2009-04-24 16:51 . 2007-12-07 21:10    --------    d-----w    c:\program files\Xfire
2009-04-21 16:45 . 2006-08-31 19:19    --------    d-----w    c:\program files\Symantec
2009-04-20 23:56 . 2009-03-24 19:31    --------    d-----w    c:\documents and settings\Laurence Smyth\Application Data\DNA
2009-04-20 19:50 . 2007-03-01 18:48    --------    d-----w    c:\program files\Canon
2009-04-20 19:49 . 2008-09-04 21:44    --------    d-----w    c:\program files\Image-Line
2009-04-20 19:44 . 2006-08-31 19:19    --------    d-----w    c:\program files\Common Files\Symantec Shared
2009-04-20 19:41 . 2008-12-29 13:32    --------    d-----w    c:\program files\PageBreeze
2009-04-20 19:35 . 2006-08-31 18:59    --------    d--h--w    c:\program files\InstallShield Installation Information
2009-04-20 16:55 . 2008-04-13 18:10    45    ----a-w    C:\TEST.XML
2009-04-20 16:55 . 2009-03-24 19:31    --------    d-----w    c:\program files\DNA
2009-04-18 00:09 . 2007-12-07 21:10    --------    d-----w    c:\documents and settings\Laurence Smyth\Application Data\Xfire
2009-04-17 18:58 . 2008-07-01 20:13    34    ----a-w    c:\documents and settings\Laurence Smyth\jagex_runescape_preferences.dat
2009-04-17 16:30 . 2007-03-17 12:46    --------    d-----w    c:\program files\Microsoft Games
2009-04-12 15:25 . 2008-11-06 23:57    --------    d-----w    c:\program files\Skulltag
2009-04-08 15:31 . 2006-08-31 18:57    --------    d-----w    c:\program files\Java
2009-04-03 16:50 . 2007-03-12 18:44    --------    d-----w    c:\program files\Sony
2009-04-03 16:50 . 2008-04-20 18:59    --------    d-----w    c:\program files\Vstplugins
2009-04-03 16:47 . 2007-02-04 15:32    --------    d-----w    c:\program files\SEGA
2009-03-28 23:03 . 2007-04-30 18:45    --------    d-----w    c:\program files\Messenger Plus! Live
2009-03-23 19:45 . 2009-03-23 19:44    --------    d-----w    c:\program files\Microsoft Virtual PC
2009-03-23 19:22 . 2009-03-23 19:21    --------    d-----w    c:\documents and settings\Laurence Smyth\Application Data\Emulators
2009-03-13 23:00 . 2009-03-13 23:00    --------    d-----w    c:\program files\ASC Games
2009-03-09 04:19 . 2008-12-11 18:47    410984    ----a-w    c:\windows\system32\deploytk.dll
2009-03-06 23:12 . 2007-03-08 18:41    --------    d-----w    c:\documents and settings\All Users\Application Data\Bluetooth
2009-03-06 20:08 . 2007-07-28 13:17    --------    d--h--r    c:\documents and settings\Laurence Smyth\Application Data\yahoo!
2009-03-06 14:22 . 2006-08-31 18:29    284160    ----a-w    c:\windows\system32\pdh.dll
2009-02-26 23:20 . 2008-07-31 22:41    --------    d-----w    c:\program files\DOSBox-0.72
2009-02-26 18:44 . 2008-08-04 19:14    --------    d-----w    c:\program files\Microsoft Silverlight
2009-02-20 08:10 . 2006-08-31 18:29    666112    ----a-w    c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2006-08-31 18:29    81920    ----a-w    c:\windows\system32\ieencode.dll
2009-02-15 20:10 . 2009-02-05 23:26    43520    ----a-w    c:\windows\system32\CmdLineExt03.dll
2009-02-09 12:10 . 2006-08-31 18:29    729088    ----a-w    c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2006-08-31 18:29    401408    ----a-w    c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2006-08-31 18:29    714752    ----a-w    c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2006-08-31 18:29    617472    ----a-w    c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2006-08-31 18:29    1846784    ----a-w    c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2006-08-31 18:29    110592    ----a-w    c:\windows\system32\services.exe
2009-02-06 11:06 . 2006-08-31 18:29    2145280    ----a-w    c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2006-08-31 18:29    35328    ----a-w    c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59    2023936    ----a-w    c:\windows\system32\ntkrnlpa.exe
2009-02-04 20:08 . 2008-11-24 00:48    98304    ----a-w    c:\windows\system32\CmdLineExt.dll
2009-02-03 19:59 . 2006-08-31 18:29    56832    ----a-w    c:\windows\system32\secur32.dll
2009-02-02 20:06 . 2008-06-22 11:24    10520    ----a-w    c:\windows\system32\avgrsstx.dll
2007-01-27 08:41 . 2007-01-27 08:41    137    ----a-w    c:\documents and settings\Laurence Smyth\Local Settings\Application Data\fusioncache.dat
2006-08-31 19:17 . 2007-01-27 08:41    12328    ----a-w    c:\documents and settings\Laurence Smyth\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-08-31 19:16 . 2006-08-31 19:16    136    ----a-w    c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2003-08-27 14:19 . 2007-01-27 08:42    36963    -c--a-r    c:\program files\Common Files\SM1updtr.dll
2006-05-03 10:06 . 2007-05-11 06:57    163328    --sh--r    c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2007-05-11 06:57    31232    --sh--r    c:\windows\system32\msfDX.dll
.

------- Sigcheck -------

[-] 2008-04-14 00:12    975872    561A50497324F378E30F55D09B4E1258    c:\windows\explorer.exe
[-] 2007-06-13 11:26    1033216    7712DF0CDDE3A5AC89843E61CD5B3658    c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 10:23    975360    9784E0719124E4A23989AEF9E7CA02D6    c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 12:00    1032192    A0732187050030AE399B241436565E64    c:\windows\$NtUninstallKB938828$\explorer.exe
[-] 2008-04-14 00:12    975872    561A50497324F378E30F55D09B4E1258    c:\windows\ServicePackFiles\i386\explorer.exe
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Steam"="c:\program files\steam\steam.exe" [2008-10-08 1410296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-03 45056]
"EDS"="c:\program files\Samsung\Samsung EDS\EDSAgent.exe" [2006-03-28 634880]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-07 761947]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2006-05-18 151552]
"RestoreIT!"="c:\program files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" [2004-09-23 114688]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2006-04-25 2764800]
"DMHotKey"="c:\program files\Samsung\DisplayManager\DMLoader.exe" [2005-11-23 356352]
"DisplayManager"="c:\program files\Samsung\DisplayManager\DisplayManager.exe" [2006-05-04 413696]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Xfire Music"="c:\program files\Xfire\xfiremusic.exe" [2006-11-21 253650]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-02 1601304]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2007-07-11 569344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-04-05 16120832]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2006-06-29 89541]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Laurence Smyth\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files\Xfire\xfire.exe [2009-4-11 3111248]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 23:34    24576    ----a-w    c:\program files\AlienGUIse\fastload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-02 20:06    10520    ----a-w    c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Laurence Smyth^Start Menu^Programs^Startup^hamachi.lnk]
path=c:\documents and settings\Laurence Smyth\Start Menu\Programs\Startup\hamachi.lnk
backup=c:\windows\pss\hamachi.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Laurence Smyth^Start Menu^Programs^Startup^RocketDock.lnk]
path=c:\documents and settings\Laurence Smyth\Start Menu\Programs\Startup\RocketDock.lnk
backup=c:\windows\pss\RocketDock.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Laurence Smyth^Start Menu^Programs^Startup^YouTube Uploader.lnk]
path=c:\documents and settings\Laurence Smyth\Start Menu\Programs\Startup\YouTube Uploader.lnk
backup=c:\windows\pss\YouTube Uploader.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\xerox\\nwwia\\XrxFTPLt.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Soldat\\Soldat.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology2\\aom.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Documents and Settings\\Laurence Smyth\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\HaloPC_DS\\haloded.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires\\EMPIRESX.EXE"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\Program Files\\Steam\\SteamApps\\4methyst\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Server\\haloded.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Custom Edition\\haloce.exe"=
"c:\\Program Files\\Steam\\SteamApps\\4methyst\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\4methyst\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skulltag\\skulltag.exe"=
"c:\\Program Files\\Skulltag\\IdeSE.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto\\WINO\\Grand Theft Auto.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Skulltag\\rcon_utility.exe"=
"c:\\Program Files\\duke3d\\eduke32.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe"=
"c:\\Program Files\\Steam\\SteamApps\\4methyst\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\4methyst\\garrysmod\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\4methyst\\source sdk base 2007\\hl2.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\BUFFALO\\NASNAVI\\NasNavi.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

R2 gupdate1c9138abbc2a9e2;Google Update Service (gupdate1c9138abbc2a9e2);c:\program files\Google\Update\GoogleUpdate.exe [2008-09-10 133104]
R3 cpuz;cpuz;

R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2007-09-25 13352]
R3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
R3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
R3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
R3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
R3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
R3 s125bus;Sony Ericsson Device 125 driver (WDM);c:\windows\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
R3 SSB2413;SSB2413 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\SSB2413.sys [2006-01-16 470112]
S0 RITCPT;RITCPT;

S0 VVBackd5;VVBackd5;

S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-02-02 325128]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-02-02 107272]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-02 903960]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-02 298264]
S2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [2005-10-27 4300]
S2 FBAPI;FBAPI;c:\windows\system32\drivers\FBAPI.sys [2004-05-18 5088]
S2 SNM WLAN Service;SNM WLAN Service;c:\program files\samsung\Samsung Network Manager\SNMWLANService.exe [2005-05-28 36864]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.sys [2006-03-29 27648]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df020ac6-cc42-11dd-a878-001167044828}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-04-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]

2009-04-26 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-09-10 21:18]

2009-04-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-14 21:18]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-farstone - (no file)


.
------- Supplementary Scan -------
.
uStart Page =
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://search.Email Removed.uk/web?isinit=true&query=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Laurence Smyth\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\documents and settings\Laurence Smyth\Application Data\Mozilla\Firefox\Profiles\s2jlcsgt.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: c:\documents and settings\Laurence Smyth\Application Data\Mozilla\Firefox\Profiles\s2jlcsgt.default\extensions\[email protected]\plugins\npDyyno.dll
FF - plugin: c:\program files\Dyyno\Dyyno Player\npvlc.dll
FF - plugin: c:\program files\GameTap\bin\Release\npgametaptool.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvideoegg-loader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-26 18:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...  

scanning hidden autostart entries ...

scanning hidden files ...  

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2441246391-1590902497-1390251581-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1180)
c:\windows\system32\Ati2evxx.dll
c:\program files\AlienGUIse\fastload.dll

- - - - - - - > 'explorer.exe'(2452)
c:\program files\Xfire\xfire_toucan_36594.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ntshrui.dll
c:\progra~1\TEXTBR~1.0\Bin\TBMHOOK.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
c:\program files\Samsung\MagicKBD\MagicKBD.exe
c:\program files\Samsung\DisplayManager\dmhkcore.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2009-04-26 18:33 - machine was rebooted
ComboFix-quarantined-files.txt  2009-04-26 17:33

Pre-Run: 16,119,672,832 bytes free
Post-Run: 16,425,390,080 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
386    --- E O F ---    2009-04-24 17:17
Hiya
No, i'm not a scammer. I said I scammed someone to get banned because my activity on the markets was going to affect my GCSE grades. Sorry to those I [censored] with. Don't believe me? Find proof then. Oh wait, there is none.






<-----------TRANSACTIONS----------->

[color="#00ff00"][color="#ff0000"]Traded level 70 main for level 53 ancient to danielisew UNSUCCESSFUL

Bought level 60 ancient/range hybrid off jaamal UNSUCCESSFUL - he recovered next day

Bought level 86 main and pure ranger of MR.SANTA - Sent false details. Scammed. Left ttg. STILL OWES ME RANGER.[/color]

 Bought lvl 40str pure off BloodSplatter SUCCESSFUL --- TRUSTED

 Transfered Items for BloodSplatter  SUCCESSFUL

Sold sig to DeScReTe GoD - SUCCESSFUL- He went first - NO MM[/color]

[color="#ff8c00"]Sold sig to FagexFun.- SUCCESSFUL - I went first - NO MM - this guy is fishy. <[email protected]> and <[email protected]> both the same guy[/color]

[color="#00ff00"]Sold 2 sigs 200k to ttg forum ownage - took a while - SUCCESSFUL

Sold lvl 30 skiller to Holes 2mil - He went first NO MM - SUCCESSFUL - Trusted

Sharing acc's with 4rrows k1ss - TRUSTED - SO FAR SO GOOD -[/color]

[color="#ff0000"]Bought ownage skiller from gummybear (Gummy Bear) (Sythe) - Vietballer mmed - SCAMMED - Lost 6m[/color]

[color="#00ff00"]Transfered Items For X Spec Nuthin - SUCCESS

Transfered Items For BloodSplatter - SUCCESS

Sold Account To Phaded Flame - Original owner hacked back - SCAMMED

Dr. Tim transferred 300k of items - SUCCESSFUL - TRUSTED

Dr. Tim transferred 2m - SUCCESSFUL - You rule dude.

Dr. Tim transferred some items and 100k - SUCCESS

Sold Main to rs_g0d_2007Email Removed 900k - No MM - I WENT FIRST - SUCCESS

Sold lvl 58 account to m4rk0z 250k - SUCCESS

Dr. Tim transferred items again - SUCCESSFUL - MEGA VOUCH

Sold Range Pure to Last Kaos 1m - SUCCESSFUL

Sold Mage Pure to whiplash - Scron1x MMed - SUCCESS

Sold Lvl 71 to cassady - NO MM - SUCCESS

[color="#ff0000"]Bought Zerker Pure from Hawk Eyes - SCAMMED - He scammed it back, Yded is useless.[/color]

[/color]

Freebies

[color="#00ff00"]Gave free sig to BloodSplatter

Gave free sig to 4rrow k1ss - he gave me a pixel - i put stuff on it.[/color]



[size="3"][color="#0000ff"]<--------------------MMING/XFERING------------------>[/color][/size]

[color="#00ff00"]MMed for m4rk0z and Zero - Account swap - SUCCESS

Transferred 170k for Teh only 0ne - SUCCESS

Transferred 800k for m4rk0z - SUCCESS

Transferred 100k for Ash - SUCCESS

Transferred 500k for Judge - SUCCESS

Transferred 10m for Neph - SUCCESS

Transferred 18m for Neph - SUCCESS

MMed for Oynx and Ran3rben93 - 4m and Tank / Ancients - SUCCESS

MMed for Ran3rben93 and L337pker - 1.6m and a Pin - SUCCESS

MMed for Shenub and K Thx - 2.6m and 2 Pins - SUCCESS

MMed for iwillpku and Mickey - 500k and Mauler - SUCCESS

Gave Gtech Warriors Free Lvl 95 - SUCCESS - Great Guy.

Gave Ash Free Skiller - SUCCESS - Crazy Guy

Gave AbdulAlzherad free hybrid because he got scammed - SUCCESS

MMed 10m for r1ch b0y - SUCCESS[/color]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Win32/Heur
« Reply #7 on: April 26, 2009, 02:49:21 PM »
Can you do the following

go to this link
http://www.virustotal.com/flash/index_en.html
Browse to the file

c:\windows\explorer.exe
Then use the SEND FILE button
Let it finish scanning
Could you post back the results this scan back here please
Or better yet, just link to the results page

Also, ensure AVG resident protection is now reenabled
« Last Edit: April 26, 2009, 02:49:59 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Amethyst

  • Newbie
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Win32/Heur
« Reply #8 on: April 26, 2009, 02:57:05 PM »
[quote name=\'guestolo\' post=\'461919\' date=\'Apr 26 2009, 01:49 PM\']Can you do the following

go to this link
http://www.virustotal.com/flash/index_en.html
Browse to the file

c:\windows\explorer.exe
Then use the SEND FILE button
Let it finish scanning
Could you post back the results this scan back here please
Or better yet, just link to the results page

Also, ensure AVG resident protection is now reenabled[/quote]

Here you go guestolo: http://www.virustotal.com/analisis/31cc283...d1a5771683ae8ab

Thanks for your time, i'm not getting any pop-ups from AVG now.
Hiya
No, i'm not a scammer. I said I scammed someone to get banned because my activity on the markets was going to affect my GCSE grades. Sorry to those I [censored] with. Don't believe me? Find proof then. Oh wait, there is none.






<-----------TRANSACTIONS----------->

[color="#00ff00"][color="#ff0000"]Traded level 70 main for level 53 ancient to danielisew UNSUCCESSFUL

Bought level 60 ancient/range hybrid off jaamal UNSUCCESSFUL - he recovered next day

Bought level 86 main and pure ranger of MR.SANTA - Sent false details. Scammed. Left ttg. STILL OWES ME RANGER.[/color]

 Bought lvl 40str pure off BloodSplatter SUCCESSFUL --- TRUSTED

 Transfered Items for BloodSplatter  SUCCESSFUL

Sold sig to DeScReTe GoD - SUCCESSFUL- He went first - NO MM[/color]

[color="#ff8c00"]Sold sig to FagexFun.- SUCCESSFUL - I went first - NO MM - this guy is fishy. <[email protected]> and <[email protected]> both the same guy[/color]

[color="#00ff00"]Sold 2 sigs 200k to ttg forum ownage - took a while - SUCCESSFUL

Sold lvl 30 skiller to Holes 2mil - He went first NO MM - SUCCESSFUL - Trusted

Sharing acc's with 4rrows k1ss - TRUSTED - SO FAR SO GOOD -[/color]

[color="#ff0000"]Bought ownage skiller from gummybear (Gummy Bear) (Sythe) - Vietballer mmed - SCAMMED - Lost 6m[/color]

[color="#00ff00"]Transfered Items For X Spec Nuthin - SUCCESS

Transfered Items For BloodSplatter - SUCCESS

Sold Account To Phaded Flame - Original owner hacked back - SCAMMED

Dr. Tim transferred 300k of items - SUCCESSFUL - TRUSTED

Dr. Tim transferred 2m - SUCCESSFUL - You rule dude.

Dr. Tim transferred some items and 100k - SUCCESS

Sold Main to rs_g0d_2007Email Removed 900k - No MM - I WENT FIRST - SUCCESS

Sold lvl 58 account to m4rk0z 250k - SUCCESS

Dr. Tim transferred items again - SUCCESSFUL - MEGA VOUCH

Sold Range Pure to Last Kaos 1m - SUCCESSFUL

Sold Mage Pure to whiplash - Scron1x MMed - SUCCESS

Sold Lvl 71 to cassady - NO MM - SUCCESS

[color="#ff0000"]Bought Zerker Pure from Hawk Eyes - SCAMMED - He scammed it back, Yded is useless.[/color]

[/color]

Freebies

[color="#00ff00"]Gave free sig to BloodSplatter

Gave free sig to 4rrow k1ss - he gave me a pixel - i put stuff on it.[/color]



[size="3"][color="#0000ff"]<--------------------MMING/XFERING------------------>[/color][/size]

[color="#00ff00"]MMed for m4rk0z and Zero - Account swap - SUCCESS

Transferred 170k for Teh only 0ne - SUCCESS

Transferred 800k for m4rk0z - SUCCESS

Transferred 100k for Ash - SUCCESS

Transferred 500k for Judge - SUCCESS

Transferred 10m for Neph - SUCCESS

Transferred 18m for Neph - SUCCESS

MMed for Oynx and Ran3rben93 - 4m and Tank / Ancients - SUCCESS

MMed for Ran3rben93 and L337pker - 1.6m and a Pin - SUCCESS

MMed for Shenub and K Thx - 2.6m and 2 Pins - SUCCESS

MMed for iwillpku and Mickey - 500k and Mauler - SUCCESS

Gave Gtech Warriors Free Lvl 95 - SUCCESS - Great Guy.

Gave Ash Free Skiller - SUCCESS - Crazy Guy

Gave AbdulAlzherad free hybrid because he got scammed - SUCCESS

MMed 10m for r1ch b0y - SUCCESS[/color]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Win32/Heur
« Reply #9 on: April 26, 2009, 03:05:02 PM »
Quote
Now it's popping up with every exe I open.

Your logs look good, but I would like to run a AV software on your computer
There is nothing to install with this

Please download [color=\"purple\"]DrWeb-CureIt[/color][/b] and save it to your Desktop. Do NOT perform a scan yet

Again, temporarily disable your Resident protection with AVG so it won't interfere with this scanner

  • Double-click on drweb-cureit.exe to start the program.
    An Express Scan of your PC notice will appear.
  • Under Start the Express Scan Now, Click OK to start the scan.
    This is a short scan that will scan the files currently running in memory.
    If something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan tab and UNcheck Heuristic analysis
  • Back at the main window, click Custom Scan, then Select drives (a red dot will show which drives have been chosen).
  • Then click the Start/Stop Scanning button (green arrow on the right, and the scan will start.
  • When finished, a message will be displayed at the bottom advising if any viruses were found.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found.

If so, click it, then click the next icon right below and select Move incurable.
(This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit when you have finished.
  • [color=\"red\"]Important![/color] Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Amethyst

  • Newbie
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Win32/Heur
« Reply #10 on: April 26, 2009, 03:25:21 PM »
It's not giving me an option to save a report, as nothing was found.
Hiya
No, i'm not a scammer. I said I scammed someone to get banned because my activity on the markets was going to affect my GCSE grades. Sorry to those I [censored] with. Don't believe me? Find proof then. Oh wait, there is none.






<-----------TRANSACTIONS----------->

[color="#00ff00"][color="#ff0000"]Traded level 70 main for level 53 ancient to danielisew UNSUCCESSFUL

Bought level 60 ancient/range hybrid off jaamal UNSUCCESSFUL - he recovered next day

Bought level 86 main and pure ranger of MR.SANTA - Sent false details. Scammed. Left ttg. STILL OWES ME RANGER.[/color]

 Bought lvl 40str pure off BloodSplatter SUCCESSFUL --- TRUSTED

 Transfered Items for BloodSplatter  SUCCESSFUL

Sold sig to DeScReTe GoD - SUCCESSFUL- He went first - NO MM[/color]

[color="#ff8c00"]Sold sig to FagexFun.- SUCCESSFUL - I went first - NO MM - this guy is fishy. <[email protected]> and <[email protected]> both the same guy[/color]

[color="#00ff00"]Sold 2 sigs 200k to ttg forum ownage - took a while - SUCCESSFUL

Sold lvl 30 skiller to Holes 2mil - He went first NO MM - SUCCESSFUL - Trusted

Sharing acc's with 4rrows k1ss - TRUSTED - SO FAR SO GOOD -[/color]

[color="#ff0000"]Bought ownage skiller from gummybear (Gummy Bear) (Sythe) - Vietballer mmed - SCAMMED - Lost 6m[/color]

[color="#00ff00"]Transfered Items For X Spec Nuthin - SUCCESS

Transfered Items For BloodSplatter - SUCCESS

Sold Account To Phaded Flame - Original owner hacked back - SCAMMED

Dr. Tim transferred 300k of items - SUCCESSFUL - TRUSTED

Dr. Tim transferred 2m - SUCCESSFUL - You rule dude.

Dr. Tim transferred some items and 100k - SUCCESS

Sold Main to rs_g0d_2007Email Removed 900k - No MM - I WENT FIRST - SUCCESS

Sold lvl 58 account to m4rk0z 250k - SUCCESS

Dr. Tim transferred items again - SUCCESSFUL - MEGA VOUCH

Sold Range Pure to Last Kaos 1m - SUCCESSFUL

Sold Mage Pure to whiplash - Scron1x MMed - SUCCESS

Sold Lvl 71 to cassady - NO MM - SUCCESS

[color="#ff0000"]Bought Zerker Pure from Hawk Eyes - SCAMMED - He scammed it back, Yded is useless.[/color]

[/color]

Freebies

[color="#00ff00"]Gave free sig to BloodSplatter

Gave free sig to 4rrow k1ss - he gave me a pixel - i put stuff on it.[/color]



[size="3"][color="#0000ff"]<--------------------MMING/XFERING------------------>[/color][/size]

[color="#00ff00"]MMed for m4rk0z and Zero - Account swap - SUCCESS

Transferred 170k for Teh only 0ne - SUCCESS

Transferred 800k for m4rk0z - SUCCESS

Transferred 100k for Ash - SUCCESS

Transferred 500k for Judge - SUCCESS

Transferred 10m for Neph - SUCCESS

Transferred 18m for Neph - SUCCESS

MMed for Oynx and Ran3rben93 - 4m and Tank / Ancients - SUCCESS

MMed for Ran3rben93 and L337pker - 1.6m and a Pin - SUCCESS

MMed for Shenub and K Thx - 2.6m and 2 Pins - SUCCESS

MMed for iwillpku and Mickey - 500k and Mauler - SUCCESS

Gave Gtech Warriors Free Lvl 95 - SUCCESS - Great Guy.

Gave Ash Free Skiller - SUCCESS - Crazy Guy

Gave AbdulAlzherad free hybrid because he got scammed - SUCCESS

MMed 10m for r1ch b0y - SUCCESS[/color]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Win32/Heur
« Reply #11 on: April 26, 2009, 03:36:34 PM »
It doesn't even appear that you scanned your whole computer?
That scan was way to fast
Did you select the appropriate drives?

Here's a different set of instructions
Besides download the program again, do the following

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
       
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A [color=\"#FF0000\"]red[/color] dot shows which drives have been chosen.
       
  • Click the green arrow at the right, and the scan will start.
       
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
       
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:

          This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured.
       
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
       
  • Save the report to your desktop. The report will be called DrWeb.csv
       
  • Close Dr.Web Cureit.
  • Reboot your computer
       
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Amethyst

  • Newbie
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Win32/Heur
« Reply #12 on: April 27, 2009, 04:48:04 PM »
firedank1943224199.xml;C:\Documents and Settings\Laurence Smyth\My Documents\My Received Files\lyl4t1769773776\History;Modification of Win32.Yasv.924;Moved.;
SUPER.exe;C:\Program Files\eRightSoft\SUPER;Probably DLOADER.Trojan;Incurable.Moved.;
main.js;C:\Program Files\Messenger Plus! Live\Scripts\Now Playing;Probably SCRIPT.Virus;Incurable.Moved.;
mirc.exe;C:\Program Files\mIRC;Program.mIRC.623;Incurable.Moved.;
A0666542.EXE;C:\System Volume Information\_restore{CEAF88E4-3C49-4DD4-94C4-7B3C2A953770}\RP418;Program.PsExec.170;Incurable.Moved.;
A0666575.bat;C:\System Volume Information\_restore{CEAF88E4-3C49-4DD4-94C4-7B3C2A953770}\RP418;Probably BATCH.Virus;Incurable.Moved.;
c0ac79.msi\stream003;C:\WINDOWS\Installer\c0ac79.msi;Trojan.PWS.Wsgame.origin;;
c0ac79.msi;C:\WINDOWS\Installer;Archive contains infected objects;Moved.;
pskill.exe;C:\WINDOWS\system32;Tool.Prockill;Incurable.Moved.;
xwpdlx20.ocx;C:\WINDOWS\system32;BackDoor.NetDevil.51;Deleted.;
Hiya
No, i'm not a scammer. I said I scammed someone to get banned because my activity on the markets was going to affect my GCSE grades. Sorry to those I [censored] with. Don't believe me? Find proof then. Oh wait, there is none.






<-----------TRANSACTIONS----------->

[color="#00ff00"][color="#ff0000"]Traded level 70 main for level 53 ancient to danielisew UNSUCCESSFUL

Bought level 60 ancient/range hybrid off jaamal UNSUCCESSFUL - he recovered next day

Bought level 86 main and pure ranger of MR.SANTA - Sent false details. Scammed. Left ttg. STILL OWES ME RANGER.[/color]

 Bought lvl 40str pure off BloodSplatter SUCCESSFUL --- TRUSTED

 Transfered Items for BloodSplatter  SUCCESSFUL

Sold sig to DeScReTe GoD - SUCCESSFUL- He went first - NO MM[/color]

[color="#ff8c00"]Sold sig to FagexFun.- SUCCESSFUL - I went first - NO MM - this guy is fishy. <[email protected]> and <[email protected]> both the same guy[/color]

[color="#00ff00"]Sold 2 sigs 200k to ttg forum ownage - took a while - SUCCESSFUL

Sold lvl 30 skiller to Holes 2mil - He went first NO MM - SUCCESSFUL - Trusted

Sharing acc's with 4rrows k1ss - TRUSTED - SO FAR SO GOOD -[/color]

[color="#ff0000"]Bought ownage skiller from gummybear (Gummy Bear) (Sythe) - Vietballer mmed - SCAMMED - Lost 6m[/color]

[color="#00ff00"]Transfered Items For X Spec Nuthin - SUCCESS

Transfered Items For BloodSplatter - SUCCESS

Sold Account To Phaded Flame - Original owner hacked back - SCAMMED

Dr. Tim transferred 300k of items - SUCCESSFUL - TRUSTED

Dr. Tim transferred 2m - SUCCESSFUL - You rule dude.

Dr. Tim transferred some items and 100k - SUCCESS

Sold Main to rs_g0d_2007Email Removed 900k - No MM - I WENT FIRST - SUCCESS

Sold lvl 58 account to m4rk0z 250k - SUCCESS

Dr. Tim transferred items again - SUCCESSFUL - MEGA VOUCH

Sold Range Pure to Last Kaos 1m - SUCCESSFUL

Sold Mage Pure to whiplash - Scron1x MMed - SUCCESS

Sold Lvl 71 to cassady - NO MM - SUCCESS

[color="#ff0000"]Bought Zerker Pure from Hawk Eyes - SCAMMED - He scammed it back, Yded is useless.[/color]

[/color]

Freebies

[color="#00ff00"]Gave free sig to BloodSplatter

Gave free sig to 4rrow k1ss - he gave me a pixel - i put stuff on it.[/color]



[size="3"][color="#0000ff"]<--------------------MMING/XFERING------------------>[/color][/size]

[color="#00ff00"]MMed for m4rk0z and Zero - Account swap - SUCCESS

Transferred 170k for Teh only 0ne - SUCCESS

Transferred 800k for m4rk0z - SUCCESS

Transferred 100k for Ash - SUCCESS

Transferred 500k for Judge - SUCCESS

Transferred 10m for Neph - SUCCESS

Transferred 18m for Neph - SUCCESS

MMed for Oynx and Ran3rben93 - 4m and Tank / Ancients - SUCCESS

MMed for Ran3rben93 and L337pker - 1.6m and a Pin - SUCCESS

MMed for Shenub and K Thx - 2.6m and 2 Pins - SUCCESS

MMed for iwillpku and Mickey - 500k and Mauler - SUCCESS

Gave Gtech Warriors Free Lvl 95 - SUCCESS - Great Guy.

Gave Ash Free Skiller - SUCCESS - Crazy Guy

Gave AbdulAlzherad free hybrid because he got scammed - SUCCESS

MMed 10m for r1ch b0y - SUCCESS[/color]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Win32/Heur
« Reply #13 on: April 29, 2009, 08:37:09 PM »
Can you let me know how things are now running please
Any problems?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Amethyst

  • Newbie
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Win32/Heur
« Reply #14 on: May 01, 2009, 08:49:17 AM »
[quote name=\'guestolo\' post=\'462002\' date=\'Apr 29 2009, 08:37 PM\']Can you let me know how things are now running please
Any problems?[/quote]


Nope. Everything is good.

Just one more question, I made an account a while back then I changed the email and it says it's not verified even though I have verified it. I changed the email after It was created to something else, yet i click resend validation and it says it's already verified when it's not.
Hiya
No, i'm not a scammer. I said I scammed someone to get banned because my activity on the markets was going to affect my GCSE grades. Sorry to those I [censored] with. Don't believe me? Find proof then. Oh wait, there is none.






<-----------TRANSACTIONS----------->

[color="#00ff00"][color="#ff0000"]Traded level 70 main for level 53 ancient to danielisew UNSUCCESSFUL

Bought level 60 ancient/range hybrid off jaamal UNSUCCESSFUL - he recovered next day

Bought level 86 main and pure ranger of MR.SANTA - Sent false details. Scammed. Left ttg. STILL OWES ME RANGER.[/color]

 Bought lvl 40str pure off BloodSplatter SUCCESSFUL --- TRUSTED

 Transfered Items for BloodSplatter  SUCCESSFUL

Sold sig to DeScReTe GoD - SUCCESSFUL- He went first - NO MM[/color]

[color="#ff8c00"]Sold sig to FagexFun.- SUCCESSFUL - I went first - NO MM - this guy is fishy. <[email protected]> and <[email protected]> both the same guy[/color]

[color="#00ff00"]Sold 2 sigs 200k to ttg forum ownage - took a while - SUCCESSFUL

Sold lvl 30 skiller to Holes 2mil - He went first NO MM - SUCCESSFUL - Trusted

Sharing acc's with 4rrows k1ss - TRUSTED - SO FAR SO GOOD -[/color]

[color="#ff0000"]Bought ownage skiller from gummybear (Gummy Bear) (Sythe) - Vietballer mmed - SCAMMED - Lost 6m[/color]

[color="#00ff00"]Transfered Items For X Spec Nuthin - SUCCESS

Transfered Items For BloodSplatter - SUCCESS

Sold Account To Phaded Flame - Original owner hacked back - SCAMMED

Dr. Tim transferred 300k of items - SUCCESSFUL - TRUSTED

Dr. Tim transferred 2m - SUCCESSFUL - You rule dude.

Dr. Tim transferred some items and 100k - SUCCESS

Sold Main to rs_g0d_2007Email Removed 900k - No MM - I WENT FIRST - SUCCESS

Sold lvl 58 account to m4rk0z 250k - SUCCESS

Dr. Tim transferred items again - SUCCESSFUL - MEGA VOUCH

Sold Range Pure to Last Kaos 1m - SUCCESSFUL

Sold Mage Pure to whiplash - Scron1x MMed - SUCCESS

Sold Lvl 71 to cassady - NO MM - SUCCESS

[color="#ff0000"]Bought Zerker Pure from Hawk Eyes - SCAMMED - He scammed it back, Yded is useless.[/color]

[/color]

Freebies

[color="#00ff00"]Gave free sig to BloodSplatter

Gave free sig to 4rrow k1ss - he gave me a pixel - i put stuff on it.[/color]



[size="3"][color="#0000ff"]<--------------------MMING/XFERING------------------>[/color][/size]

[color="#00ff00"]MMed for m4rk0z and Zero - Account swap - SUCCESS

Transferred 170k for Teh only 0ne - SUCCESS

Transferred 800k for m4rk0z - SUCCESS

Transferred 100k for Ash - SUCCESS

Transferred 500k for Judge - SUCCESS

Transferred 10m for Neph - SUCCESS

Transferred 18m for Neph - SUCCESS

MMed for Oynx and Ran3rben93 - 4m and Tank / Ancients - SUCCESS

MMed for Ran3rben93 and L337pker - 1.6m and a Pin - SUCCESS

MMed for Shenub and K Thx - 2.6m and 2 Pins - SUCCESS

MMed for iwillpku and Mickey - 500k and Mauler - SUCCESS

Gave Gtech Warriors Free Lvl 95 - SUCCESS - Great Guy.

Gave Ash Free Skiller - SUCCESS - Crazy Guy

Gave AbdulAlzherad free hybrid because he got scammed - SUCCESS

MMed 10m for r1ch b0y - SUCCESS[/color]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Win32/Heur
« Reply #15 on: May 02, 2009, 12:05:31 AM »
Are you talking about an account you made here at the forum
If so, can you PM me the email you used please, don't post it back here directly at this topic
Also, what username did you use

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here