Author Topic: Internet Problems  (Read 2832 times)

Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« on: May 18, 2009, 09:35:59 AM »
Hello questolo, once again ill beasking for your help. I have some internet problems for a week now on my computer. The inernet connecion is available and unavailable very randomly, geting disconnecions also very randomly and usualy after the disconnections cant connect for an hour or more... Could you help me?Here are he HJT and COMBO FIX logs:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 17:27:52, on 2009.05.18Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16827)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exeC:\Program Files\BitDefender\BitDefender 2009\vsserv.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\IoctlSvc.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\BitDefender\BitDefender 2009\bdagent.exeC:\Program Files\BitDefender\BitDefender 2009\seccenter.exeC:\Program Files\DAEMON Tools Lite\daemon.exeC:\Program Files\Microsoft ActiveSync\wcescomm.exeC:\WINDOWS\system32\ctfmon.exeC:\PROGRA~1\MI3AA1~1\rapimgr.exeG:\pc\HiJackThis.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://127.0.0.1:9000/proxy.pacR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorunO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exeO23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exeO23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exeO23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe--End of file - 6227 bytesComboFix 09-05-17.04 - Administrator 2009.05.18 15:26.8 - NTFSx86Microsoft Windows XP Professional  5.1.2600.3.1257.370.1033.18.1023.622 [GMT 3:00]Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exeAV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.(((((((((((((((((((((((((((((((((((((((   Other Deletions   ))))))))))))))))))))))))))))))))))))))))))))))))).c:\windows\system32\mfc70.dlld:\recycler\S-1-5-21-1275210071-1957994488-1801674531-1005\Dd1.lnkd:\recycler\S-1-5-21-1275210071-1957994488-1801674531-1005\INFO2d:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\cmdaccess.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\cmds.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\configs.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\core.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\awp_map.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_747.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_assault.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_backalley.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_bbicotka.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_downed_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_estate.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_havana.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_havana_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_intercept.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_italy.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_italy_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_militia.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_mopo3.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_nnd.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_office.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_siege.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\cs_thunder.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_2minaret.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_airstrip.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_airstrip_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_aztec.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_aztec_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_aztec2.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_aztec3.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_cbble.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_cbble_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_chateau.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_clan1_mill.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_clan2_fire.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_clan3_heat.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_clan4_stone.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_cpl_fire.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dam_final.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_damaged.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dust-forever.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dust.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dust_castle.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dust_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dust2.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dust2_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dust4.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dust4ever.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dustybleek.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_dustmix4.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_indust.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_inetcafe.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_inferno.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_inferno_cz.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_nuke.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_piranesi.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_plaka.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_prodigy.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_quarry.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_raoni.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_rusty.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_slap.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_storm.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_survivor.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_torn.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_train.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\de_vertigo.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\fy_iceworld.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\ka_legoland.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\scoutzknivez.spawns.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\csdm\test.pld:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\custommenuitems.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\cvars.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\cvars.ini.bakd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\hamdata.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\maps.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\maps.ini.bakd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\modules.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\pausecfg.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\pausecfg.ini.bakd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\plugins.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\plugins.ini.bakd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\sample_plugins.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\shero\shconfig.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\shero\superhero.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\shero\superhero_20lvls.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\shero\superhero_default.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\speech.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\sql.cfgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\stats.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\users.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\users.ini.bakd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\addons\amxmodx\configs\weaprest.inid:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\custom.hpkd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd1\cstrike\liblist.gamd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd2.jpgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\Dd3.jpgd:\recycler\S-1-5-21-329068152-1644491937-725345543-1003\INFO2d:\recycler\S-1-5-21-329068152-1644491937-725345543-1004\Dd3.exed:\recycler\S-1-5-21-329068152-1644491937-725345543-1004\INFO2d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd21.com]\[PSP] Naruto ultimate ninja heroes [Multi5] [www.topetorrent.com].ISOd:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.001d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.002d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.003d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.004d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.005d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.006d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.007d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.008d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.009d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.010d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.011d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.012d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.013d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.014d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.015d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.016d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.017d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.018d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.019d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.020d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.021d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.022d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.023d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.024d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.025d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.026d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.027d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.028d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.029d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.030d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.031d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.032d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.033d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.034d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.035d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.036d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.037d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.038d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.039d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.040d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.041d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.042d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.043d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.044d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.045d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.046d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.047d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.048d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.049d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.050d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.051d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.052d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.053d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.054d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\c-j2hin.sfvd:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\chronic.nfod:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd22.com]\www.spatorrent.com.nfod:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd23\~uTorrentPartFile_3B13DB2C0.datd:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd23\Dungeon Siege - Throne of Agony.csod:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.r00d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.r01d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.r02d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.r03d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.r04d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.r05d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.r06d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.r07d:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.rard:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe-worm2.sfvd:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd24\oe.nfod:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd25.avid:\recycler\S-1-5-21-57989841-412668190-839522115-1003\Dd26.avid:\recycler\S-1-5-21-57989841-412668190-839522115-1003\INFO2d:\recycler\S-1-5-21-746137067-2052111302-725345543-500\Dd2.amxxd:\recycler\S-1-5-21-746137067-2052111302-725345543-500\INFO2d:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De2.mdsd:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De3.mdfd:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\BackgroundDownloader.exed:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\BNUpdate.exed:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\bnupdate.logd:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\dbghelp.dlld:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\DivxDecoder.dlld:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\fmod.dlld:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\ijl15.dlld:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\Launcher.exed:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\Patch.htmld:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\Patch.txtd:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\Repair.exed:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\Scan.dlld:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\unicows.dlld:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\World of Warcraft Install Log.htmld:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\WoW.exed:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\WowError.exed:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\WTF\Account\FXEL\SavedVariables.luad:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\WTF\Account\FXEL\SavedVariables.lua.bakd:\recycler\S-1-5-21-776561741-839522115-725345543-1003\De4\WTF\Config.wtfd:\recycler\S-1-5-21-776561741-839522115-725345543-1003\INFO2d:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\hl2.exed:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\french\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\german\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\german\steambackup.exed:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\italian\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\italian\steambackup.exed:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\japanese\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\korean\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\portuguese\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\russian\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\schinese\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\spanish\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\spanish\steambackup.exed:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\tchinese\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\backup\thai\steam.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\aboutdialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\accepted_cards.tgad:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Account.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\AccountPage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\BackupCompletionPage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\BackupCopyFilesPage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\BackupSelectDirectoryPage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\BackupSelectGamesPage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\BackupSelectOptionsPage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\BandwidthUsageDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\CDIcon.tgad:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\CDKeyReceipt.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ConfirmPasswordDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\CountryList.vdfd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\creditcard_back.tgad:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\creditcard_back_amex.tgad:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\CreditCardPreorderReceipt.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\CreditCardReceipt.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\DefragAppDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\DeleteCache.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\driverunknownpagedialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\driverunsupportedpagedialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\driverupdatepagedialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\DuplicateCC.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\FragmentationBadWarningDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\gameproperties_general.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\gameproperties_localfiles.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\gameproperties_shortcuts.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\gameproperties_updates.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\GamesDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\gamespage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\gamespage_small.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\InstallDirextXDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\InstallExplanationDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\InstallSubChooseApps.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\InstallSubChooseApps_SingleApp.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\InstallSubComplete.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\InstallSubComplete_RetailInstall.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\InstallSubConvertApps.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\InstallSubOptions.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\JoinGameDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\JoinGameDialogExpanded.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\JoinGameDialogExpanded_SSA.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\LaunchOptionsDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\MediaConfirmationDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\NotifyTrayHintDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\offline_english.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\offline_french.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\offline_german.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\offline_italian.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\offline_korean.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\offline_schinese.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\offline_spanish.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\offline_tchinese.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_ActivelyPreloading.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_ActivelyPreloading_NotPreorderable.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_ActivelyPreloading_Payed_NotPlayable.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_FinishedPreload_Countdown.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_FinishedPreload_NotPayed_NotPlayable.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_FinishedPreload_NotPayed_Playable.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_FinishedPreload_NotPreorderable.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_FinishedPreload_Payed_NotPlayable.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_NotPreloading.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_NotPreloading_NotPreorderable.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PreloadSubscription_NotPreloading_Payed_NotPlayable.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ProductMarketingDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ProductMarketingDialog_Initial.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ProductMarketingDialog_Preload.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ProductMarketingDialog_Released.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubBillingConfirmation.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubBillingInfo.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubBillingInfoReview.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubCreditCardAmex.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubCreditCardCVV2.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubCreditCardDiners.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubCreditCardDiscover.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubCreditCardInfo.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubCreditCardJCB.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubEmailContactEmail.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubIntro.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubShippingInfo.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\PurchaseSubUserInfo.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Alert.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Declined.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Declined_AVSFailure.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Declined_InsufficientFunds.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Denied_FromPreorder.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Preorder.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Success.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Success_FromPreorder.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_Success_WithShipping.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CC_UseLimit.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CDKey_Cancelled.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CDKey_InvalidKey.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CDKey_Rejected.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_CDKey_Success.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_PreorderCancelled.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_Server_Failure.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_Server_Timeout.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\Receipt_Server_Timeout_BFS.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\regionrestrictiondialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\regionrestrictiondialog_activation.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\RegisterSubEnterCDKey.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\RegisterSubEnterCDKey_RetailInstall.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\registersubintro.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\RetailInstalledFiles.txtd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\RetailInstallLockedDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SettingsSubInterface.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SettingsSubInternet.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SettingsSubLanguage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SettingsSubMessages.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SystemInfoPage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SystemRequirementsDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SpecialOffersDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\steambackup.exed:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SteamMonitorDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SteamRootDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\steamrootdialog_small.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SteamStatsDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\StorefrontDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\storepage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubChangeContactEmailIntro.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubChangeContactEmailValidated.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubChangePasswordChangePassword.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubChangePasswordChangeSecretQuestion.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubChangePasswordComplete.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubChangePasswordOptions.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubGamePropertiesContentPage.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubPanelConvertCDKeyFinished.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\SubPanelConvertCDKeyIntro.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\UpdateNewsDialog.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ValveSurveyInternetConnection.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ValveSurveyOverview.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ValveSurveyResults.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\cached\ValveSurveySummarizeData.resd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\220\dxsupport.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\240\dxsupport.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\2400\dxsupport_reqs.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\2410\dxsupport_reqs.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\260\dxsupport.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\280\dxsupport.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\300\dxsupport.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\340\dxsupport.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\340\dxsupport_reqs.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\380\dxsupport.cfgd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\html\DrvrUpdate_ATI1.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\html\DrvrUpdate_INTEL1.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\html\DrvrUpdate_NV1.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\drivercheck\html\HardwareRequirements.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\ClientGameInfo.vdfd:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\codename gordon.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\condition zero deleted scenes.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\condition zero.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\Counter-Strike Source.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\counter-strike.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\day of defeat source.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\day of defeat.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\dangerous waters.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\Darwinia.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\deathmatch classic.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\Dedicated Server install.htmld:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\dedicated server.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\Earth 2160.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\Half-Life 2 Demo.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\Half-Life 2 Lost Coast.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\Half-Life 2.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\Half-Life Blue Shift.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\half-life.icod:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\icon_blueshift.tgad:\recycler\S-1-5-21-842925246-73586283-725345543-1003\Dd1\Half-Life 2 Episode One\platform\steam\games\icon_blueshift_dull.tgad:\recycler\S-1-5-21-842925246-73
« Last Edit: May 18, 2009, 10:20:18 AM by FIxeL »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #1 on: May 18, 2009, 10:28:27 AM »
Download [color=\"#FF0000\"]OTListIt2[/color][/url] by OldTimer to your Desktop.
  • Close all windows and Double click on OTListIt2.exe to Run it
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up - OTListIt2.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
NOTE: Extras.txt should post with no problems
IF you do have problems with posting back the OTListIt2.txt file, because of an error from the message board
Please upload it in a reply using the UPLOAD>>BROWSE buttons

Edit>In addition to the above 2 logs
Can you also do the following
Download [color=\"#FF0000\"]Rooter.exe[/color] to your desktop

    * Then doubleclick it to start the tool
    * A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
« Last Edit: May 18, 2009, 11:15:43 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #2 on: May 18, 2009, 02:23:54 PM »
Here are the 3 files.

OTListIt logfile created on: 2009.05.18 21:34:39 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8     Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000427 | Country: Lithuania | Language: LTH | Date Format: yyyy.MM.dd
 
1023,36 Mb Total Physical Memory | 673,77 Mb Available Physical Memory | 65,84% Memory free
2,40 Gb Paging File | 2,05 Gb Available in Paging File | 85,39% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 54,49 Gb Total Space | 10,48 Gb Free Space | 19,23% Space Free | Partition Type: NTFS
Drive D: | 178,40 Gb Total Space | 17,47 Gb Free Space | 9,79% Space Free | Partition Type: NTFS
Drive E: | 585,87 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
Drive G: | 3,82 Gb Total Space | 0,71 Gb Free Space | 18,62% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: BUSTED-PC2008
Current User Name: Administrator
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
 
[color=\"orange\"]========== Processes (SafeList) ==========[/color]
 
PRC - [2009.04.05 23:58:59 | 00,415,024 | ---- | M] (BitDefender SRL) -- C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
PRC - [2009.04.05 23:58:53 | 01,626,112 | ---- | M] (BitDefender S. R. L.) -- C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
PRC - [2008.04.14 05:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008.07.03 02:22:56 | 00,116,040 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008.06.08 09:31:04 | 00,877,864 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
PRC - [2009.02.18 14:44:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2006.12.19 10:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\WINDOWS\system32\IoctlSvc.exe
PRC - [2009.04.28 20:10:49 | 00,778,240 | ---- | M] (BitDefender S.R.L.) -- C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
PRC - [2009.04.28 20:10:49 | 00,438,272 | ---- | M] () -- C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
PRC - [2008.07.24 18:02:06 | 00,490,952 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\daemon.exe
PRC - [2006.11.13 13:39:52 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PRC - [2006.11.13 13:39:34 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe
PRC - [2009.05.18 21:23:28 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
 
[color=\"orange\"]========== Win32 Services (SafeList) ==========[/color]
 
SRV - [2008.07.03 02:22:56 | 00,116,040 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008.07.17 12:06:56 | 00,118,784 | ---- | M] (BitDefender S.R.L. http://www.bitdefender.com) -- C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe -- (Arrakis3 [On_Demand | Stopped])
SRV - [2008.07.25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008.07.25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008.07.29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008.04.14 05:42:04 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005.04.04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008.07.29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008.07.09 13:30:00 | 00,532,264 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped])
SRV - [2008.04.14 08:41:56 | 00,028,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll -- (Irmon [Auto | Running])
SRV - [2009.04.05 23:58:59 | 00,415,024 | ---- | M] (BitDefender SRL) -- C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe -- (LIVESRV [Auto | Running])
SRV - [2008.06.08 09:31:04 | 00,877,864 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3 [Auto | Running])
SRV - [2008.07.29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008.06.24 16:05:56 | 00,537,896 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2009.02.26 18:27:00 | 03,027,706 | ---- | M] (INCA Internet Co., Ltd.) -- C:\WINDOWS\system32\GameMon.des -- (npggsvc [On_Demand | Stopped])
SRV - [2009.02.18 14:44:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2003.07.28 13:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006.12.19 10:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\WINDOWS\system32\IoctlSvc.exe -- (PLFlash DeviceIoControl Service [Auto | Running])
SRV - [2009.04.05 23:57:30 | 00,323,584 | ---- | M] (S.C. BitDefender S.R.L) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll -- (scan [On_Demand | Stopped])
SRV - [2009.04.05 23:58:53 | 01,626,112 | ---- | M] (BitDefender S. R. L.) -- C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe -- (VSSERV [Auto | Running])
SRV - [2006.10.18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
 
[color=\"orange\"]========== Driver Services (SafeList) ==========[/color]
 
DRV - [2007.04.16 21:46:00 | 00,033,792 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdPPM.sys -- (AmdPPM [System | Running])
DRV - [2009.04.23 13:55:36 | 00,279,712 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\atksgt.sys -- (atksgt [Auto | Running])
DRV - [2008.09.18 11:09:12 | 00,111,112 | ---- | M] (BitDefender S.R.L. Bucharest, ROMANIA) -- C:\WINDOWS\system32\drivers\bdfm.sys -- (bdfm [On_Demand | Running])
DRV - [2009.04.05 23:58:56 | 00,104,328 | ---- | M] (BitDefender LLC) -- C:\WINDOWS\system32\DRIVERS\bdfndisf.sys -- (Bdfndisf [On_Demand | Running])
DRV - [2008.12.10 19:42:46 | 00,242,184 | ---- | M] (BitDefender S.R.L. Bucharest, ROMANIA) -- C:\WINDOWS\system32\drivers\bdfsfltr.sys -- (bdfsfltr [On_Demand | Running])
DRV - [2009.04.05 23:57:31 | 00,137,224 | ---- | M] (BitDefender LLC) -- C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys -- (bdftdif [System | Running])
DRV - [2009.04.05 23:57:31 | 00,008,832 | ---- | M] (BitDefender S.R.L.) -- C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys -- (BDSelfPr [On_Demand | Running])
DRV - [2008.10.06 17:16:16 | 00,082,696 | ---- | M] (BitDefender S.R.L.) -- C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys -- (BDVEDISK [Auto | Running])
DRV - [2008.01.29 12:01:28 | 00,016,168 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2009.03.27 22:53:26 | 00,025,280 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\system32\DRIVERS\hamachi.sys -- (hamachi [On_Demand | Stopped])
DRV - [2008.04.13 22:06:06 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2008.08.27 17:22:24 | 04,754,432 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2001.08.17 16:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\irsir.sys -- (irsir [On_Demand | Running])
DRV - [2009.04.23 13:55:36 | 00,025,888 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\lirsgt.sys -- (lirsgt [Auto | Running])
DRV - [2006.08.16 12:25:48 | 00,019,345 | ---- | M] (Motive, Inc.) -- C:\Program Files\Common Files\Motive\MREMPR5.sys -- (MREMPR5 [On_Demand | Stopped])
DRV - [2006.08.16 12:25:48 | 00,018,003 | ---- | M] (Motive, Inc.) -- C:\Program Files\Common Files\Motive\MRENDIS5.sys -- (MRENDIS5 [On_Demand | Stopped])
DRV - [2009.02.18 14:44:00 | 06,308,224 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2006.03.22 09:24:00 | 00,052,736 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2006.03.22 09:24:02 | 00,018,944 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2006.05.05 20:21:00 | 00,004,608 | ---- | M] (NVIDIA Corporation.) -- C:\WINDOWS\system32\Drivers\nvport.sys -- (nvport [System | Running])
DRV - [2006.03.29 09:49:26 | 00,009,856 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc [On_Demand | Running])
DRV - [2008.09.02 13:32:06 | 00,013,056 | ---- | M] () -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys -- (Profos [On_Demand | Stopped])
DRV - [2004.08.04 04:07:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008.08.20 20:58:58 | 00,044,944 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2008.04.13 22:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008.09.15 23:20:23 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2009.04.14 20:22:40 | 00,039,808 | ---- | M] (BitDefender S.R.L.) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys -- (Trufos [On_Demand | Stopped])
DRV - [2008.07.03 02:12:48 | 00,032,000 | ---- | M] (Apple, Inc.) -- C:\WINDOWS\System32\Drivers\usbaapl.sys -- (USBAAPL [On_Demand | Stopped])
DRV - [2008.04.14 00:26:50 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\usb8023x.sys -- (usb_rndisx [On_Demand | Stopped])
DRV - [2008.04.14 00:26:50 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\usb8023.sys -- (USB_RNDIS_51 [On_Demand | Stopped])
DRV - [2006.11.06 18:04:56 | 00,028,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\wceusbsh.sys -- (wceusbsh [On_Demand | Stopped])
 
[color=\"orange\"]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=\"orange\"]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
 
[color=\"orange\"]========== FireFox ==========[/color]
 
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.3.4
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2009\FFTOOLBAR\ [2009.04.05 23:43:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009.04.06 01:15:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009.04.29 00:01:59 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009.05.03 11:28:23 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2009\TBEXTENSION\ [2009.04.05 23:43:29 | 00,000,000 | ---D | M]
 
[2008.09.16 10:25:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions
[2008.09.16 10:25:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009.05.17 22:28:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\64udm5j1.default\extensions
[2009.05.02 01:43:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\64udm5j1.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2009.02.19 18:44:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\64udm5j1.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2008.09.16 12:08:58 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\FireFox\Profiles\64udm5j1.default\searchplugins\daemon-search.xml
[2009.05.17 22:28:39 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009.04.29 00:01:59 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008.09.17 18:25:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009.04.29 00:01:55 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009.04.29 00:01:55 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009.04.05 23:58:35 | 00,049,664 | ---- | M] () -- C:\Program Files\mozilla firefox\components\FFComm.dll
[2008.12.19 07:48:25 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008.12.19 07:48:25 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008.12.19 07:48:25 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008.12.19 07:48:25 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008.12.19 07:48:25 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008.12.19 07:48:25 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008.12.19 07:48:25 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
 
O1 HOSTS File: (265491 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: 127.0.0.1   www.007guard.com
O1 - Hosts: 127.0.0.1   007guard.com
O1 - Hosts: 127.0.0.1   008i.com
O1 - Hosts: 127.0.0.1   www.008k.com
O1 - Hosts: 127.0.0.1   008k.com
O1 - Hosts: 127.0.0.1   www.00hq.com
O1 - Hosts: 127.0.0.1   00hq.com
O1 - Hosts: 127.0.0.1   010402.com
O1 - Hosts: 127.0.0.1   www.032439.com
O1 - Hosts: 127.0.0.1   032439.com
O1 - Hosts: 127.0.0.1   www.0scan.com
O1 - Hosts: 127.0.0.1   0scan.com
O1 - Hosts: 127.0.0.1   www.100888290cs.com
O1 - Hosts: 127.0.0.1   100888290cs.com
O1 - Hosts: 127.0.0.1   www.100sexlinks.com
O1 - Hosts: 127.0.0.1   100sexlinks.com
O1 - Hosts: 127.0.0.1   www.10sek.com
O1 - Hosts: 127.0.0.1   10sek.com
O1 - Hosts: 127.0.0.1   www.123topsearch.com
O1 - Hosts: 127.0.0.1   123topsearch.com
O1 - Hosts: 127.0.0.1   www.132.com
O1 - Hosts: 127.0.0.1   132.com
O1 - Hosts: 127.0.0.1   www.136136.net
O1 - Hosts: 127.0.0.1   136136.net
O1 - Hosts: 9198 more lines...
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - Reg Error: Value error. File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll (Bitdefender)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe" (BitDefender S.R.L.)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe" (BitDefender)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
O4 - HKCU..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 46 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter:  - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.09.15 22:13:23 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001.08.23 15:00:00 | 00,000,110 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{b0d76ea1-836f-11dd-bb52-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b0d76ea1-836f-11dd-bb52-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b0d76ea1-836f-11dd-bb52-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- [2004.08.04 01:56:48 | 01,314,816 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009.05.18 21:33:58 | 00,000,000 | ---D | M]
 
[color=\"orange\"]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2009.05.18 21:33:58 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009.05.18 15:26:08 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009.05.18 15:26:08 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009.05.18 15:26:08 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009.05.18 15:26:08 | 00,117,248 | ---- | C] () -- C:\WINDOWS\vFind.exe
[2009.05.18 15:26:08 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009.05.18 15:26:08 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009.05.18 15:26:08 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009.05.18 15:26:08 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009.05.18 15:25:51 | 00,000,000 | ---D | C] -- C:\ComboFix
[2009.05.18 07:44:11 | 00,053,760 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\lesa).doc
[2009.05.10 02:04:55 | 00,054,389 | ---- | C] () -- C:\romini.dmp
[2009.05.07 06:51:42 | 00,010,752 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document (3).doc
[2009.05.03 21:38:51 | 03,027,706 | ---- | C] (INCA Internet Co., Ltd.) -- C:\WINDOWS\System32\GameMon.des
[2009.05.03 14:31:03 | 40,076,9195 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\The.Meerkats.2008.720p.BluRay.x264-CiNEFiLE.mkv
[2009.05.03 11:25:54 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009.05.03 10:23:32 | 00,001,410 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Global RBF.lnk
[2009.05.03 10:23:32 | 00,001,264 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\i j j i RBF.lnk
[2009.05.03 10:10:32 | 00,000,000 | ---D | C] -- C:\Rohan_Global
[2009.05.02 20:05:04 | 19,466,94019 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\RohanBloodFeud_Global.exe
[2009.05.02 18:20:40 | 00,208,384 | ---- | C] (<YNK Intractive>) -- C:\WINDOWS\System32\uc_rohan_launching.dll
[2009.05.02 18:20:39 | 00,087,472 | ---- | C] (<NHN USA Inc>.) -- C:\WINDOWS\System32\ijjiChannelingPlugin.dll
[2009.05.02 18:04:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\RohanScreenShot
[2009.05.02 12:15:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Wolverine
[2009.05.02 12:14:08 | 00,000,837 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\X-Men Origins - Wolverine(tm).lnk
[2009.04.26 11:08:22 | 00,021,353 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\1_1.jpg
[2009.04.25 23:47:28 | 00,000,478 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Guild Wars.lnk
[2009.04.25 23:46:59 | 00,165,248 | ---- | C] (ArenaNet) -- C:\Documents and Settings\Administrator\Desktop\GwSetup.exe
[2009.04.25 18:51:50 | 00,014,340 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Obitaemyj.ostrov.Shvatka.2009.O.TS.ELEKTRI4KA.[uniongang.ru].avi.torrent
[2009.04.25 12:14:34 | 00,000,545 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Zeno Clash.lnk
[2009.04.23 20:06:05 | 73,404,8256 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\dmd-bbb.avi
[2009.04.23 20:04:25 | 73,399,2960 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\dmd-bba.avi
[2009.04.23 14:56:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Tages
[2009.04.23 13:55:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\InstallShield Installation Information
[2009.04.23 13:55:36 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2009.04.23 13:55:36 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2009.04.19 20:05:17 | 00,034,816 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document (2).doc
[2009.04.19 11:06:00 | 00,020,154 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Taras.Buljba.2009.Ñ…264.DVDRip.mp4.torrent
** - C:\Documents and Settings\Administrator\Desktop\Taras.Buljba.2009.?264.DVDRip.mp4.torrent
[2009.04.05 23:59:26 | 00,000,121 | ---- | C] () -- C:\WINDOWS\bdagent.INI
[2009.01.24 15:44:01 | 00,000,160 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2009.01.17 15:48:59 | 00,033,576 | ---- | C] () -- C:\WINDOWS\System32\BCGPOleAcc.dll
[2008.11.12 01:13:03 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008.11.03 20:57:01 | 00,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008.11.03 20:56:59 | 02,041,363 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2008.11.03 20:56:58 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008.11.03 20:56:58 | 00,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.11.03 20:56:58 | 00,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008.11.03 01:09:59 | 00,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008.10.28 18:40:48 | 00,173,552 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2008.10.09 15:31:54 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\txmlutil.dll
[2008.10.07 19:43:00 | 00,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008.10.07 10:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008.10.03 13:47:18 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.09.20 13:23:58 | 00,000,031 | ---- | C] () -- C:\WINDOWS\GunzLauncher.INI
[2008.09.16 12:29:06 | 00,138,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.09.15 23:20:23 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.06.05 09:58:26 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008.05.16 14:01:00 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008.05.16 14:01:00 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008.05.16 14:01:00 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008.05.16 14:01:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008.05.16 14:01:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007.01.31 13:50:32 | 00,913,408 | ---- | C] () -- C:\WINDOWS\System32\xreglib.dll
[2004.08.04 04:07:00 | 00,000,682 | ---- | C] () -- C:\WINDOWS\win.ini
[2004.08.04 04:07:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003.01.07 16:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
 
[color=\"orange\"]========== Files - Modified Within 30 Days ==========[/color]
 
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009.05.18 21:23:28 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009.05.18 17:59:42 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009.05.18 17:12:15 | 00,206,306 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009.05.18 17:10:28 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009.05.18 17:10:27 | 00,000,454 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2009.05.18 17:10:19 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009.05.18 17:10:18 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Administrator\Local Settings\desktop.ini
[2009.05.18 17:10:16 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009.05.18 17:09:22 | 00,081,984 | ---- | M] () -- C:\WINDOWS\System32\bdod.bin
[2009.05.18 15:32:02 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009.05.18 15:24:48 | 02,988,830 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2009.05.18 08:19:33 | 00,053,760 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\lesa).doc
[2009.05.15 21:08:10 | 00,000,286 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2009.05.14 21:52:25 | 00,054,389 | ---- | M] () -- C:\romini.dmp
[2009.05.14 17:50:08 | 00,117,248 | ---- | M] () -- C:\WINDOWS\vFind.exe
[2009.05.14 05:38:13 | 00,000,388 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[2009.05.07 10:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009.05.07 06:51:42 | 00,010,752 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document (3).doc
[2009.05.03 21:37:30 | 00,000,375 | ---- | M] () -- C:\WINDOWS\System32\BDUpdateV1.xml
[2009.05.03 10:23:32 | 00,001,410 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Global RBF.lnk
[2009.05.03 10:23:32 | 00,001,264 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\i j j i RBF.lnk
[2009.05.02 20:11:45 | 19,466,94019 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\RohanBloodFeud_Global.exe
[2009.05.02 12:14:08 | 00,000,837 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\X-Men Origins - Wolverine(tm).lnk
[2009.04.29 21:33:56 | 00,002,193 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009.04.28 20:02:53 | 00,034,816 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document (2).doc
[2009.04.27 13:33:12 | 00,000,211 | -HS- | M] () -- C:\boot .ini
[2009.04.27 13:33:11 | 00,000,682 | ---- | M] () -- C:\WINDOWS\win.ini
[2009.04.26 11:08:22 | 00,021,353 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\1_1.jpg
[2009.04.25 23:47:28 | 00,000,478 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Guild Wars.lnk
[2009.04.25 23:47:00 | 00,165,248 | ---- | M] (ArenaNet) -- C:\Documents and Settings\Administrator\Desktop\GwSetup.exe
[2009.04.25 18:51:50 | 00,014,340 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Obitaemyj.ostrov.Shvatka.2009.O.TS.ELEKTRI4KA.[uniongang.ru].avi.torrent
[2009.04.25 12:14:34 | 00,000,545 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Zeno Clash.lnk
[2009.04.23 13:55:36 | 00,279,712 | ---- | M] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2009.04.23 13:55:36 | 00,025,888 | ---- | M] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2009.04.20 12:56:28 | 00,031,232 | ---- | M] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009.04.19 11:06:01 | 00,020,154 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Taras.Buljba.2009.Ñ…264.DVDRip.mp4.torrent
** - C:\Documents and Settings\Administrator\Desktop\Taras.Buljba.2009.?264.DVDRip.mp4.torrent
< End of report >
=============================================================================

OTListIt Extras logfile created on: 2009.05.18 21:34:39 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8     Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000427 | Country: Lithuania | Language: LTH | Date Format: yyyy.MM.dd
 
1023,36 Mb Total Physical Memory | 673,77 Mb Available Physical Memory | 65,84% Memory free
2,40 Gb Paging File | 2,05 Gb Available in Paging File | 85,39% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 54,49 Gb Total Space | 10,48 Gb Free Space | 19,23% Space Free | Partition Type: NTFS
Drive D: | 178,40 Gb Total Space | 17,47 Gb Free Space | 9,79% Space Free | Partition Type: NTFS
Drive E: | 585,87 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
Drive G: | 3,82 Gb Total Space | 0,71 Gb Free Space | 18,62% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: BUSTED-PC2008
Current User Name: Administrator
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
 
[color=\"orange\"]========== File Associations ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
[color=\"orange\"]========== Security Center Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"58910:TCP" = 58910:TCP:*:Enabled:Pando Media Booster
"58910:UDP" = 58910:UDP:*:Enabled:Pando Media Booster
"7001:TCP" = 7001:TCP:*:Enabled:port
"7002:TCP" = 7002:TCP:*:Enabled:Sword of the new world
 
[color=\"orange\"]========== Authorized Applications List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2006.11.13 13:39:34 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
[2006.11.13 13:39:52 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
[2006.11.13 13:39:54 | 04,270,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
File not found -- D:\Games\Combar Arms\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
File not found -- D:\Games\Combar Arms\Combat Arms\Engine.exe:*Enabled:Engine.exe
File not found -- D:\Games\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe
File not found -- D:\Games\Combat Arms EU\Engine.exe:*Enabled:Engine.exe
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008.09.15 23:18:20 | 00,267,056 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent
[2008.09.16 12:28:15 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA
[2008.11.22 23:37:32 | 00,183,112 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB
[2008.07.09 13:30:02 | 20,246,824 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2008.05.27 18:31:30 | 00,868,352 | ---- | M] (NHN USA inc.) -- C:\ijji\ENGLISH\u_gunz.exe:*:Enabled:<ijji Downloader>
[2008.08.25 11:03:58 | 21,619,952 | ---- | M] (Eden Games) -- C:\Program Files\Atari\AITD\Alone.exe:*:Enabled:Alone In The Dark
[2006.11.13 13:39:34 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
[2006.11.13 13:39:52 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
[2006.11.13 13:39:54 | 04,270,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[2009.02.27 22:39:02 | 01,410,296 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe:*:Enabled:Steam
[2008.07.16 13:06:34 | 02,772,992 | ---- | M] (Electronic Arts) -- C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager
[2008.06.19 09:53:28 | 02,589,992 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe:*:Enabled:Nero ControlCenter
[2009.04.29 00:01:55 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox
[2009.01.29 20:46:44 | 00,155,648 | ---- | M] (Nexon) -- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager
[2009.01.29 21:49:46 | 00,155,648 | ---- | M] (Nexon) -- C:\Documents and Settings\All Users\Application Data\NexonEU\NGM\NGM.exe:*:Enabled:Nexon Game Manager
[2005.06.09 16:01:32 | 00,397,312 | ---- | M] (Valve) -- D:\serverdoc\CS_server\counter-strike\hlds.exe:*:Enabled:HLDS Launcher
[2005.06.09 16:01:16 | 00,086,016 | ---- | M] (Non Steam Powered) -- D:\serverdoc\CS_server\counter-strike\cstrike.exe:*:Enabled:Counter-Strike Launcher
[2005.06.09 16:01:16 | 00,086,016 | ---- | M] (Non Steam Powered) -- D:\Games\counter-strike\cstrike.exe:*:Enabled:Counter-Strike Launcher
[2009.03.12 20:30:34 | 00,282,624 | ---- | M] (www.moofdev.net) -- D:\RatioMaster-1.7.5\RatioMaster.exe:*:Enabled:Ratio Master
[2009.04.29 21:38:49 | 00,098,304 | ---- | M] () -- C:\Program Files\Steam\steamapps\fxel\team fortress 2\hl2.exe:*:Enabled:hl2
[2008.04.14 05:42:18 | 00,029,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper
[2004.10.26 23:23:26 | 03,440,640 | ---- | M] (The 3DO Company) -- D:\Games\heroes3\h3wog.exe:*:Enabled:Heroes of Might and Magic® III
[2008.08.08 15:31:52 | 25,507,624 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
[2006.09.19 07:49:24 | 01,929,216 | ---- | M] () -- D:\Games\World Series of Poker TOC\WSOPTOC.exe:*:Enabled:WSOPTOC
[2009.04.30 18:01:02 | 53,159,576 | ---- | M] (Raven Software) -- D:\Games\X-Men Origins - Wolverine(tm)\Binaries\Wolverine.exe:*:Enabled:X-Men Origins - Wolverine
 
[color=\"orange\"]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis®
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{055FEF8E-4B86-400F-A5C6-8FAC0042DCD9}" = NVIDIA PureVideo Decoder
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{1023383E-D9F6-478C-A965-23A4657B3C9A}" = Sacred 2
"{1DCC7418-2089-4BDD-B321-3771956160FC}" = ijji Auto Installer
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skypeâ„¢ Beta 4.0
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(tm) 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{44F61424-3998-4203-A1B5-A64E7E12B1D4}_is1" = Lemonade Tycoon 2
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{510B3FF8-0585-4BBB-BADE-770F31F3EBFA}" = Age of Empires Scenarios for Pocket PC
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{628C3D50-F524-4C49-A958-672CE7953756}" = The Lord of the Rings - Conquestâ„¢
"{64F67489-76BB-4CDD-A236-F954BE774B35}" = NVIDIA PhysX
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6D22289D-ED59-4F97-B636-2111EC64F5D4}" = Apple Mobile Device Support
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7F0B94C6-828C-4EDE-A86B-ECF4D792B68D}" = Activision®
"{7F7E4FA7-6F32-4DE2-917E-361E034AED7A}" = Spider-Man(tm) - Web of Shadows
"{891D0B03-05DF-4CD1-B267-268FDA1CB309}" = Nero 8
"{8DD2C528-67CF-40C0-B4C1-2A81533FB54C}" = Atlantica Online
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90240409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Resource Kit
"{9312191B-30A5-44E1-8D8D-6936FE06CDE8}" = Wanted: Weapons of Fate
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{A2A60894-E3ED-46FE-9A6A-7CF7A87572A0}" = Opera 9.64
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{B0A88235-FDF0-4DCD-88A0-D78EA2D03AB9}" = iTunes
"{B392AFBE-E3B9-4CE6-A9D8-A06FAE9BC79C}" = Application Suite
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B8D3C597-2395-43D2-9D2B-7B617D719933}" = ABBYY eFormFiller 2.5 v6
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D54049D3-256C-4E19-AAE9-861F6B00BF29}" = AGEIA GAME System Software
"{D694797C-4E0F-4004-97D6-F8C2C38DF324}" = Age of Empires The Rise of Rome Campaigns for Pocket PC
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War(tm)
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{E144A786-D2DD-428B-9C1A-0EE3FA3515EA}" = Rappelz_USA
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{E34E9B33-46EC-4252-A52F-DDA3978CC0AF}" = Syberia
"{EA4481CC-EF73-40DB-8E4D-0712FD702B4D}" = Age of Empires Gold Edition for Pocket PC
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F959B396-6E53-4B2D-88AF-5B65FAF9F4D5}" = BitDefender Total Security 2009
"{FD052FB9-FE90-4438-B355-15EDC89D8FB1}" = Microsoft Games for Windows - LIVE Redistributable
"7-Zip" = 7-Zip 4.57
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Alone In The Dark_is1" = Alone In The Dark
"Are You Smarter Than A 5th Grader Make The Grade1.078" = Are You Smarter Than A 5th Grader Make The Grade
"Ashampoo Movie Shrink & Burn 3_is1" = Ashampoo Movie Shrink & Burn 3.02
"AviSynth" = AviSynth 2.5
"Azgard" = Azgard
"Azgard Defence_is1" = Azgard Defence 1.0
"Combat Arms" = Combat Arms
"Combat Arms EU" = Combat Arms EU
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DSMT5" = MathType 5
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Fallout 3 - The Pitt" = Fallout 3 - The Pitt
"Foxit Reader" = Foxit Reader
"Granado Espada_is1" = Granado Espada
"Guild Wars" = Guild Wars
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{7F0B94C6-828C-4EDE-A86B-ECF4D792B68D}" = X-Men Origins - Wolverine(tm)
"InstallShield_{7F7E4FA7-6F32-4DE2-917E-361E034AED7A}" = Spider-Man(tm) - Web of Shadows
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War(tm)
"InstallShield_{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"IsoBuster_is1" = IsoBuster 2.4
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.2.5 (Full)
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero8280_Micro_is1" = Nero 8 Micro v8.2.8.0
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"PunkBusterSvc" = PunkBuster Services
"Rayman Pocket" = Rayman Pocket
"RegCure" = RegCure 1.4.0.4
"Rohan_RBF" = Rohan_RBF
"SpeedUpMyPC_is1" = Uniblue SpeedUpMyPC 3
"Steam App 440" = Team Fortress 2

"Strippoker II Mariah" = Strippoker II Mariah
"SUPER ©" = SUPER © Version 2008.bld.33 (Sep 2, 2008)
"Sword of The New World_is1" = Sword of The New World
"TOEFL Sample Questions" = TOEFL Sample Questions
"Videora iPhone Converter" = Videora iPhone Converter 3.08
"Warfare Incorporated(tm) for Pocket PC" = Warfare Incorporated(tm) for Pocket PC
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World Series of Poker TOC" = World Series of Poker: TOC
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
 
[color=\"orange\"]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{12C85315-0989-4C28-8956-33458F464DD6}" = The Chronicles of Riddick - Assault on Dark Athena
"Dreamlords" = Dreamlords - The Reawakening
"ijji.com" = ijji
"uTorrent" = µTorrent
 
[color=\"orange\"]========== Last 10 Event Log Errors ==========[/color]
 
[ System Events ]
Error - 2009.05.17 01:23:48 | Computer Name = BUSTED-PC2008 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
 or more  time sources, however none of the sources are currently accessible.   No attempt
 to contact a source will be made for 14 minutes.  NtpClient has no source of accurate
 time.
 
Error - 2009.05.17 01:23:48 | Computer Name = BUSTED-PC2008 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
 manually  configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
 again in 15  minutes.  The error was: A socket operation was attempted to an unreachable
 host. (0x80072751)
 
Error - 2009.05.17 01:23:48 | Computer Name = BUSTED-PC2008 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
 or more  time sources, however none of the sources are currently accessible.   No attempt
 to contact a source will be made for 14 minutes.  NtpClient has no source of accurate
 time.
 
Error - 2009.05.18 08:26:41 | Computer Name = BUSTED-PC2008 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the 23204D475C412633A264A44D9CDD6CD1
 service to connect.
 
Error - 2009.05.18 08:28:48 | Computer Name = BUSTED-PC2008 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the 1B093463084A7D8575B53373BD6983DF
 service to connect.
 
Error - 2009.05.18 08:28:49 | Computer Name = BUSTED-PC2008 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the 7308817500C3D289B89F254013F1A5F1
 service to connect.
 
Error - 2009.05.18 08:31:52 | Computer Name = BUSTED-PC2008 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the A5FBDA995B53896556F180F1EDBF97B8
 service to connect.
 
Error - 2009.05.18 08:31:53 | Computer Name = BUSTED-PC2008 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the D27A7119571F3B6F70650967908B2849
 service to connect.
 
Error - 2009.05.18 10:12:05 | Computer Name = BUSTED-PC2008 | Source = Service Control Manager | ID = 70
« Last Edit: May 18, 2009, 02:49:49 PM by guestolo »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #3 on: May 18, 2009, 02:44:42 PM »
Quote
NOTE: Extras.txt should post with no problems
IF you do have problems with posting back the OTListIt2.txt file, because of an error from the message board
Please upload it in a reply using the UPLOAD>>BROWSE buttons
You only had to upload OTListIt2.txt

Not the other 2, I'm going to edit your last post to include the logs in a reply
Give me time to look them over

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #4 on: May 18, 2009, 03:12:11 PM »
Can you do the following:
Go to START>>RUN>>type the following: cmd
Hit OK

At the prompt, type the following: ipconfig /flushdns
Note the single space after ipconfig and before /
Then hit enter on your keyboard
When done, exit the command prompt

Go to START>>RUN>>type the following: services.msc
Hit OK
In the Service configuration window
look on the right hand side for this service
name---- DNS Client

Double click on it--- STOP the service--If running
In the drop down menu, change the startup type to Manual
Apply and OK it, exit the Services window

Double click  on OTListIt2.exe on destkop to Run it
Copy the contents of the paths below in Blue to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

[color=\"#0000FF\"]:OTLI
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found

:files

:commands
[emptytemp]
[start explorer]
[Reboot][/color]
  • Return to OTListIt2, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.
  • Close all Browser windows, including this one    
  • Then Click the red Run Fix button.
       
  • Let the program run unhindered, reboot when it is done
  • Then post the new OTL2 log
« Last Edit: May 18, 2009, 03:12:46 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #5 on: May 19, 2009, 11:10:24 AM »
Here is the new OTListIt log.
P.S. If it shouldve done something, it didnt, becouse i still cant connect to the internet.
« Last Edit: May 19, 2009, 11:11:56 AM by FIxeL »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #6 on: May 19, 2009, 11:16:08 AM »
You can't connect at all to the Internet in either IE or Firefox?

I actually wanted to see the results of the fixes we did
There should be a text file on your desktop
It should have a name that represents Date of fix

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #7 on: May 20, 2009, 12:10:31 AM »
Computer was always connecting to the internet by he PPOE Dial up, but now it can connect by the dial, it can connec very rearly bu gets dissconection after 1-5 min.
Heres the file you wanted:

========== OTLISTIT ==========
Process Explorer.EXE killed successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
========== FILES ==========
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Administrator\Local Settings\temp\WCESLog.log scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
 
OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05192009_183631

Files moved on Reboot...
C:\Documents and Settings\Administrator\Local Settings\temp\WCESLog.log moved successfully.

Registry entries deleted on Reboot...

Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #8 on: May 20, 2009, 01:53:17 PM »
[quote name=\'FIxeL\' post=\'462792\' date=\'May 20 2009, 08:10 AM\']Computer was always connecting to the internet by he PPOE Dial up, but now it can connect by the dial very rearly and if it connects gets disconnection after 1-5 min.
Heres the file you wanted:

========== OTLISTIT ==========
Process Explorer.EXE killed successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
========== FILES ==========
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Administrator\Local Settings\temp\WCESLog.log scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
 
OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05192009_183631

Files moved on Reboot...
C:\Documents and Settings\Administrator\Local Settings\temp\WCESLog.log moved successfully.

Registry entries deleted on Reboot...[/quote]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #9 on: May 20, 2009, 02:00:28 PM »
Can you do the following
Delete your copy of ComboFix

REDownload ComboFix from one of these locations:

[color=\"#0000FF\"]Link 1[/color]
[color=\"#0000FF\"]Link 2[/color]
[color=\"#FF0000\"]Save it ONLY to your Desktop[/color]

If you must use a Pendrive to transfer it to the desktop, do so, but leave the Pen drive inserted to the computer

      --------------------------------------------------------------------
[color=\"#2E8B57\"]Temporarily Disable your AntiVirus/AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with this tool
[/color]
With Avast, you can Right click on it's icon by the clock and choose to "Stop On Access Protections"
Ok the prompt


  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


[color=\"#2e8b57\"]**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[/color]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply

NOTE: Do not mouseclick inside ComboFix window as it's running, it may cause it to stall
ComboFix will/may run again on startup, it will prompt that it's creating a log
This process could take up to 10 minutes, let it run uninterrupted please
« Last Edit: May 20, 2009, 02:06:59 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #10 on: May 23, 2009, 11:52:18 AM »
Hello, bad things are happening with my computers... Firstly the main pc that i posted the problem. Now from the blue, it doesnt turn on,  when i press the turn on button the lights shows, and after 2 secs it freezes. It even doesnt reach the black screen where it shows your computer specs... Do you know what could it be? Secondly my laptop. I was able to pos the logs from my main computer with laptop help, but now its the same problem, i cant connect to the internet. It just stucks at ,,Connecting thrue WAN miniport (ppoe)... " and after that an error message follows, same as it was for my main pc. After some modem configuration i was able to make it transfer WiFi, so thats why im able to post this message. Do you have any idea what could it be ? Thank you for you time.
« Last Edit: May 23, 2009, 11:55:33 AM by FIxeL »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #11 on: May 24, 2009, 08:25:19 AM »
The modem configuration, I have no idea what you did

Need way more info, Modem model/type
Router make/model
ISP

The computer that won't boot, do you have your XP CD?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #12 on: May 24, 2009, 09:58:00 AM »
I just configurated the router that i could transfer wireless internet that i could connect to the internet via laptop. Its not a problem with the modem, becouse i have two of them and is the same problem with both of them. The coumputer that could boo, at that time i didnt even reach the point that it could start from a CD, i couldnt turn on the computer for 4 days, but today i pressed the button and it turned on normaly, maybe problems with mother board or something like that? Secondly on the laptop today while i was conneced on the internet , the internet suddenly was gone, and i couldnt connected neither thrue PPPOE nor WiFI, but i did a system restrore back to 4 days ago, and i was able to connect again thrue WiFi ( no, i didnt install any new programs ). Sadly i still cant connect thrue PPPOE neither with stationary pc nor with lapotop. Is there any possibility that sationary pc was infected by some kind of virus , which i transfered to laptop while transfering the logs?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #13 on: May 24, 2009, 10:15:12 AM »
From the looks of the combofix log you first ran, there's a good chance your Flash drive is infected

Do the following on the Desktop computer
download Flash_Disinfector and save it to your desktop
  • Double on Flash_Disinfector.exe  to run it. If you receive a prompt, please allow it.
       
  • You will be prompted to plug in your flash drive. Plug it in. If you have more than one, plug them in
  • Flash_Disinfector will start disinfecting your flash and hard drives. This takes a few seconds. Your desktop will disappear in the meantime.
  • When done, a message box will appear. Click OK. Your desktop should now appear. If it doesn't, press Ctrl + Shift + Esc to open Task Manager.
       
  • Click on File > New Task (Run...). Type in explorer.exe and press Enter. Your desktop should now appear.
[color=\"#4169E1\"]Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.[/color]

Leave any external Flash drive, external harddrive,etc.. connected
If you have a copy of ComboFix on the desktop computer, delete it
REDownload ComboFix from one of these locations:

[color=\"#0000FF\"]Link 1[/color]
[color=\"#0000FF\"]Link 2[/color]
Save it ONLY to your Desktop

      --------------------------------------------------------------------
[color=\"#2E8B57\"]Temporarily Disable your AntiVirus/AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with this tool[/color]
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


[color=\"#2e8b57\"]**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[/color]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply

NOTE: Do not mouseclick inside ComboFix window as it's running, it may cause it to stall
ComboFix will/may run again on startup, it will prompt that it's creating a log
This process could take up to 10 minutes, let it run uninterrupted please

NOTE:Download and Run Flash_Disinfector.exe on the Laptop also

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #14 on: May 24, 2009, 11:40:27 AM »
Well, i still cant connect to the internet. And combofix cant download the recovery console becouse theres no internet on the stationary pc. Heres the laptop combofix:

ComboFix 09-05-23.04 - Alma 2009.05.24 18:32.3 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium   6.0.6001.1.1257.370.1033.18.1023.372 [GMT 3:00]
Running from: c:\users\Alma\Downloads\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
SP: BitDefender Antispyware *enabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\acovcnt.exe

.
(((((((((((((((((((((((((   Files Created from 2009-04-24 to 2009-05-24  )))))))))))))))))))))))))))))))
.

2009-05-24 15:39 . 2009-05-24 15:39   --------   d-----w   c:\users\Alma\AppData\Local\temp
2009-05-22 11:36 . 2009-05-22 11:36   552   ----a-w   c:\users\Alma\AppData\Local\d3d8caps.dat
2009-05-21 16:20 . 2009-05-21 16:20   --------   d-----w   c:\programdata\PopCap Games
2009-05-20 21:06 . 2008-05-27 05:17   11776   ----a-w   c:\windows\system32\msshooks.dll
2009-05-20 21:06 . 2008-05-27 04:59   18904   ----a-w   c:\windows\system32\StructuredQuerySchemaTrivial.bin
2009-05-20 21:06 . 2008-05-27 04:59   106605   ----a-w   c:\windows\system32\StructuredQuerySchema.bin
2009-05-20 21:06 . 2008-05-27 05:17   34816   ----a-w   c:\windows\system32\msscb.dll
2009-05-20 20:49 . 2008-04-12 03:32   784896   ----a-w   c:\windows\system32\rpcrt4.dll
2009-05-20 19:54 . 2009-05-20 19:54   --------   d-----w   c:\programdata\WindowsSearch
2009-05-20 15:44 . 2009-05-20 15:44   --------   d-----w   C:\PerfLogs
2009-05-19 04:31 . 2008-10-22 01:22   2048   ----a-w   c:\windows\system32\tzres.dll
2009-05-18 20:38 . 2009-05-21 12:36   81984   ----a-w   c:\windows\system32\bdod.bin
2009-05-18 20:01 . 2008-07-27 18:00   96760   ----a-w   c:\windows\system32\dfshim.dll
2009-05-18 20:01 . 2008-07-27 18:00   282112   ----a-w   c:\windows\system32\mscoree.dll
2009-05-18 20:01 . 2008-07-27 18:00   41984   ----a-w   c:\windows\system32\netfxperf.dll
2009-05-18 20:01 . 2008-07-27 18:00   158720   ----a-w   c:\windows\system32\mscorier.dll
2009-05-18 20:01 . 2008-07-27 18:00   83968   ----a-w   c:\windows\system32\mscories.dll
2009-05-18 18:39 . 2009-05-18 18:39   --------   d-----w   c:\users\Alma\AppData\Roaming\BitDefender
2009-05-18 18:37 . 2009-05-18 18:52   --------   d-----w   c:\programdata\BitDefender
2009-05-18 18:37 . 2009-05-18 18:39   --------   d-----w   c:\program files\BitDefender
2009-05-18 18:34 . 2009-05-18 18:38   --------   d-----w   c:\program files\Common Files\BitDefender
2009-05-18 14:52 . 2009-05-18 14:52   --------   d-----w   c:\programdata\Avg7
2009-05-18 14:24 . 2008-12-05 04:32   428544   ----a-w   c:\windows\system32\EncDec.dll
2009-05-18 14:23 . 2008-12-05 04:32   293376   ----a-w   c:\windows\system32\psisdecd.dll
2009-05-18 14:21 . 2009-04-13 14:39   4656976   ----a-w   c:\programdata\Microsoft\Windows Defender\Definition Updates\{4EC83B49-73C3-4D71-8FB7-A47AEF310DBC}\mpengine.dll
2009-05-18 14:20 . 2008-10-21 05:25   296960   ----a-w   c:\windows\system32\gdi32.dll
2009-05-18 14:20 . 2008-12-06 04:42   376832   ----a-w   c:\windows\system32\winhttp.dll
2009-05-18 14:18 . 2008-08-12 03:39   443392   ----a-w   c:\windows\system32\win32spl.dll
2009-05-18 14:18 . 2008-01-19 07:36   37888   ----a-w   c:\windows\system32\printcom.dll
2009-05-18 14:18 . 2008-08-28 03:40   712704   ----a-w   c:\windows\system32\WindowsCodecs.dll
2009-05-18 14:18 . 2008-08-28 03:40   425472   ----a-w   c:\windows\system32\PhotoMetadataHandler.dll
2009-05-18 14:18 . 2008-08-28 03:40   347136   ----a-w   c:\windows\system32\WindowsCodecsExt.dll
2009-05-18 14:18 . 2009-02-13 08:49   1255936   ----a-w   c:\windows\system32\lsasrv.dll
2009-05-18 14:16 . 2008-09-10 03:40   1334272   ----a-w   c:\windows\system32\msxml6.dll
2009-05-18 13:57 . 2008-10-16 21:13   1809944   ----a-w   c:\windows\system32\wuaueng.dll
2009-05-18 13:57 . 2008-10-16 21:09   51224   ----a-w   c:\windows\system32\wuauclt.exe
2009-05-18 13:57 . 2008-10-16 21:09   43544   ----a-w   c:\windows\system32\wups2.dll
2009-05-18 13:57 . 2008-10-16 20:56   1524736   ----a-w   c:\windows\system32\wucltux.dll
2009-05-18 13:56 . 2008-10-16 21:12   561688   ----a-w   c:\windows\system32\wuapi.dll
2009-05-18 13:56 . 2008-10-16 21:08   34328   ----a-w   c:\windows\system32\wups.dll
2009-05-18 13:56 . 2008-10-16 20:55   83456   ----a-w   c:\windows\system32\wudriver.dll
2009-05-18 13:55 . 2008-10-16 11:08   162064   ----a-w   c:\windows\system32\wuwebv.dll
2009-05-18 13:55 . 2008-10-16 10:56   31232   ----a-w   c:\windows\system32\wuapp.exe

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-25 01:19 . 2008-01-06 14:48   --------   d-----w   c:\users\Alma\AppData\Roaming\uTorrent
2009-05-25 01:19 . 2008-08-30 22:45   --------   d-----w   c:\program files\iTunes
2009-05-25 01:19 . 2008-08-22 07:29   --------   d-----w   c:\program files\Common Files\Steam
2009-05-25 01:19 . 2008-08-11 06:04   --------   d-----w   c:\program files\DAEMON Tools
2009-05-25 01:19 . 2008-08-08 19:04   --------   d-----w   c:\program files\DAEMON Tools Pro
2009-05-25 01:19 . 2008-07-17 20:47   --------   d-----w   c:\program files\QuickTime
2009-05-25 01:19 . 2008-02-15 17:40   --------   d-----w   c:\program files\Common Files\Motive
2009-05-25 01:19 . 2008-01-10 18:34   --------   d-----w   c:\program files\FlashGet
2009-05-25 01:19 . 2008-01-07 20:59   --------   d-----w   c:\program files\Google
2009-05-25 01:19 . 2007-03-22 22:01   --------   d-----w   c:\program files\ATK Hotkey
2009-05-21 19:33 . 2007-05-09 13:08   80102   ----a-w   c:\users\Alma\AppData\Roaming\nvModes.dat
2009-05-21 12:36 . 2007-01-10 19:43   12   ----a-w   c:\windows\bthservsdp.dat
2009-05-20 19:26 . 2009-05-20 19:26   0   ---ha-w   c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-05-20 15:50 . 2006-11-02 12:37   --------   d-----w   c:\program files\Windows Calendar
2009-05-20 15:50 . 2006-11-02 12:37   --------   d-----w   c:\program files\Windows Sidebar
2009-05-20 15:50 . 2006-11-02 11:18   --------   d-----w   c:\program files\Windows Mail
2009-05-20 15:50 . 2006-11-02 12:37   --------   d-----w   c:\program files\Windows Collaboration
2009-05-20 15:50 . 2006-11-02 12:37   --------   d-----w   c:\program files\Windows Journal
2009-05-20 15:50 . 2006-11-02 12:37   --------   d-----w   c:\program files\Windows Photo Gallery
2009-05-20 15:50 . 2006-11-02 12:37   --------   d-----w   c:\program files\Windows Defender
2009-05-20 15:44 . 2006-11-02 10:25   665600   ----a-w   c:\windows\inf\drvindex.dat
2009-05-20 08:25 . 2006-11-02 10:32   101888   ----a-w   c:\windows\system32\ifxcardm.dll
2009-05-20 08:25 . 2006-11-02 10:32   82432   ----a-w   c:\windows\system32\axaltocm.dll
2009-05-19 12:39 . 2008-07-09 23:35   --------   d-----w   c:\program files\Microsoft Silverlight
2009-05-19 03:30 . 2008-07-03 10:22   --------   d-----w   c:\program files\7-Zip
2009-05-18 19:05 . 2008-09-18 08:12   242184   ----a-w   c:\windows\system32\drivers\bdfsfltr.sys
2009-05-18 19:05 . 2008-10-17 11:01   104328   ----a-w   c:\windows\system32\drivers\bdfndisf.sys
2009-05-18 19:05 . 2008-09-04 13:33   82696   ----a-w   c:\windows\system32\drivers\BDVEDISK.sys
2009-05-18 14:59 . 2007-03-22 22:00   --------   d--h--w   c:\program files\InstallShield Installation Information
2009-05-18 14:55 . 2007-03-22 22:03   --------   d-----w   c:\program files\ASUS
2009-05-18 14:49 . 2008-08-29 03:56   --------   d-----w   c:\programdata\BlazeVideo
2009-03-17 03:38 . 2009-05-18 14:17   13824   ----a-w   c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-05-18 14:17   24064   ----a-w   c:\windows\system32\amxread.dll
2009-03-03 04:46 . 2009-05-18 14:19   3599328   ----a-w   c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-05-18 14:19   3547632   ----a-w   c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-05-18 14:10   827392   ----a-w   c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-05-18 14:19   183296   ----a-w   c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-05-18 14:19   551424   ----a-w   c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-05-18 14:19   26112   ----a-w   c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-05-18 14:10   78336   ----a-w   c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-05-18 14:19   98304   ----a-w   c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-05-18 14:19   54784   ----a-w   c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-05-18 14:19   44032   ----a-w   c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-05-18 14:19   666624   ----a-w   c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-05-18 14:19   17408   ----a-w   c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-05-18 14:10   26624   ----a-w   c:\windows\system32\ieUnatt.exe
2009-05-18 19:05 . 2008-10-30 14:34   49664   ----a-w   c:\program files\mozilla firefox\components\FFComm.dll
1999-05-06 06:22 . 2007-01-10 19:12   224150   --sha-r   c:\windows\ConfigSetRoot\IO.SYS
1999-05-06 06:22 . 2007-01-10 19:12   1026   --sha-r   c:\windows\ConfigSetRoot\MSDOS.SYS
2000-06-21 20:22 . 2007-01-10 19:12   0   --sha-w   c:\windows\ConfigSetRoot\DOS\EBD.SYS
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-07 171448]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-09-18 171464]
"Steam"="d:\games\Half-Life 2\\Steam.exe" [2008-08-18 1271032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 815104]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-09 289064]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-05-18 778240]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-05-18 69632]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-10 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-10 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-10 81920]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-12-01 4186112]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^MultiFrame.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MultiFrame.lnk
backup=c:\windows\pss\MultiFrame.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{37974EF6-6BE4-4E08-8076-D4AA1EF6BDD5}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{848F4764-436F-486B-B099-857603464931}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{EB657023-CE1E-4F8A-ADFD-3DC7A1A0B80B}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{6776BF1E-5820-4EC0-AC30-536D56E41E2B}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{70BF4E6F-01C0-4926-9856-8BB9D6D06F7E}d:\\games\\counter-strike\\cs 1.6 real edition 2007 third edition by nitroxi\\cstrike.exe"= UDP:d:\games\counter-strike\cs 1.6 real edition 2007 third edition by nitroxi\cstrike.exe:ByMeR-CS 1.6 Real Edition 2007
"UDP Query User{2ADF9242-26A7-495D-A9E4-C161633CF64B}d:\\games\\counter-strike\\cs 1.6 real edition 2007 third edition by nitroxi\\cstrike.exe"= TCP:d:\games\counter-strike\cs 1.6 real edition 2007 third edition by nitroxi\cstrike.exe:ByMeR-CS 1.6 Real Edition 2007
"TCP Query User{18E36698-9EF7-46E7-BA31-C1AF55152881}d:\\games\\counter-strike\\hl.exe"= UDP:d:\games\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{7C65D889-D40B-4AE9-B350-A0A57F83A684}d:\\games\\counter-strike\\hl.exe"= TCP:d:\games\counter-strike\hl.exe:Half-Life Launcher
"TCP Query User{043EAF6F-191C-416D-B577-972BF892BD82}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F749DDCD-AE51-4787-BBFF-D043CF580CC7}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{AF36D253-BF0B-4FDD-AF01-7C2169125E2E}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{AC111115-B288-4D6A-9A5B-69F9D8D0FED5}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet
"TCP Query User{B4FECA0E-E2F4-4023-91DF-28E5F6A359E4}c:\\users\\alma\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\alma\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{76E734CC-C393-449E-A5AE-4C0C49DDCAB0}c:\\users\\alma\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\alma\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{7E082822-3CC0-4BA9-87DA-D69569B7F34D}c:\\games\\css\\brain.exe"= UDP:c:\games\css\brain.exe:brain
"UDP Query User{C4BC9895-2616-4D43-879E-63483967A8A3}c:\\games\\css\\brain.exe"= TCP:c:\games\css\brain.exe:brain
"TCP Query User{FB741D62-8427-4DD2-B82A-743383045C5C}c:\\users\\alma\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\alma\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{9442D1A9-6554-4405-AABA-15677489AAED}c:\\users\\alma\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\alma\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{D27475FD-524E-492F-A431-1CF130D4C407}c:\\program files\\ftp commander deluxe\\cftpdeluxe.exe"= UDP:c:\program files\ftp commander deluxe\cftpdeluxe.exe:cFTPdeluxe
"UDP Query User{59D51658-4096-4CF7-BBA4-A2C61A975C66}c:\\program files\\ftp commander deluxe\\cftpdeluxe.exe"= TCP:c:\program files\ftp commander deluxe\cftpdeluxe.exe:cFTPdeluxe
"TCP Query User{96DC96E3-437F-4723-A46B-8EAD1B29DBEC}c:\\games\\css\\brain.exe"= UDP:c:\games\css\brain.exe:brain
"UDP Query User{375A8200-9E16-4B80-9C97-67988BB3E28F}c:\\games\\css\\brain.exe"= TCP:c:\games\css\brain.exe:brain
"TCP Query User{EB42D986-4DF9-4DF2-8CEB-A11B927A7FA8}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{98CC32A6-586E-4997-A75D-41127909FDD4}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{4EF04D00-2974-4F99-A036-190D9AC69855}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{AB08ABED-780B-4EA6-8784-0734B933EC4C}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{9D89F978-EF10-4C6E-8812-3D4117C41B2B}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{BE5662E0-F412-4A62-A423-32FA1E7DDAF3}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser
"{B6C1EF7C-DD9C-4A1B-8440-FCD7673125E1}"= UDP:d:\games\Space Siege\GPGNet\GPG.Multiplayer.Client.exe:GPGNet
"{3A15AA5C-13CF-4513-AF53-FC4CFF2D2412}"= TCP:d:\games\Space Siege\GPGNet\GPG.Multiplayer.Client.exe:GPGNet
"TCP Query User{E102AB03-729F-4DEF-A943-10FC4310B5F7}d:\\games\\half-life 2 deathmatch\\hl2.exe"= UDP:d:\games\half-life 2 deathmatch\hl2.exe:hl2
"UDP Query User{6982632E-7722-44AD-A76A-229FA1C7FF9A}d:\\games\\half-life 2 deathmatch\\hl2.exe"= TCP:d:\games\half-life 2 deathmatch\hl2.exe:hl2
"TCP Query User{909B75E5-A079-4FD0-BED3-17D2DD0FFE0E}d:\\games\\half-life 2\\steamapps\\user\\half-life 2\\hl2.exe"= UDP:d:\games\half-life 2\steamapps\user\half-life 2\hl2.exe:hl2
"UDP Query User{A8F4DC0C-D047-4F99-8165-AF7207217A31}d:\\games\\half-life 2\\steamapps\\user\\half-life 2\\hl2.exe"= TCP:d:\games\half-life 2\steamapps\user\half-life 2\hl2.exe:hl2
"TCP Query User{4C900E48-66F3-4838-884D-7E55FFA59A6C}d:\\games\\half-life 2\\steamapps\\user\\counter-strike source\\hl2.exe"= UDP:d:\games\half-life 2\steamapps\user\counter-strike source\hl2.exe:hl2
"UDP Query User{A3A374AA-7DFB-47E9-8C59-0C22EBABB5FB}d:\\games\\half-life 2\\steamapps\\user\\counter-strike source\\hl2.exe"= TCP:d:\games\half-life 2\steamapps\user\counter-strike source\hl2.exe:hl2
"TCP Query User{39B779AA-D833-42E3-874E-34C8CC8A157F}d:\\games\\team fortress 2\\hl2.exe"= UDP:d:\games\team fortress 2\hl2.exe:hl2
"UDP Query User{00897F1E-FE4B-4908-8118-E55BB6F651A2}d:\\games\\team fortress 2\\hl2.exe"= TCP:d:\games\team fortress 2\hl2.exe:hl2
"{D863F00D-B4DF-4D03-B324-DF0648D56951}"= UDP:c:\program files\WinSCP\WinSCP.exe:WinSCP
"{200C38B6-EE6F-4916-BB31-BC998656F5BD}"= TCP:c:\program files\WinSCP\WinSCP.exe:WinSCP
"TCP Query User{6E227D66-4006-4248-AC82-D97A442419CB}c:\\program files\\itunes\\itunes.exe"= UDP:c:\program files\itunes\itunes.exe:iTunes
"UDP Query User{7735EF64-31EE-40F6-8FC4-E6F3581B8260}c:\\program files\\itunes\\itunes.exe"= TCP:c:\program files\itunes\itunes.exe:iTunes
"{E87305EF-6219-42FA-98DC-8C96BE7BC70A}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{A7A906C2-2656-4D00-94F4-26E83C3409EF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008.09.04 16:33 82696]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:\windows\System32\StkCSrv.exe [2006.12.10 19:31 24576]
R3 bdfm;BDFM;c:\windows\System32\drivers\bdfm.sys [2008.09.18 11:09 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\System32\drivers\bdfndisf.sys [2008.10.17 14:01 104328]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\System32\drivers\StkCMini.sys [2006.12.21 21:36 1132544]
R3 WCPU;WCPU;c:\program files\P4G\WCPU.sys [2007.03.23 01:11 11120]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008.07.17 12:06 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs   REG_MULTI_SZ      BthServ
bdx   REG_MULTI_SZ      scan
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-BlazeServoTool - c:\program files\BlazeVideo\BlazeDTV 3.5\MediaDetector.exe
SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.asus.com
uInternet Settings,ProxyOverride = *.local
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {930FB9FE-64F0-4BD2-B60E-B3E2E9D7E070} = 212.59.0.1,212.59.0.2
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
FF - ProfilePath - c:\users\Alma\AppData\Roaming\Mozilla\Firefox\Profiles\9rv9g461.default\
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-24 18:39
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...  

scanning hidden autostart entries ...

scanning hidden files ...  

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-05-24 18:43
ComboFix-quarantined-files.txt  2009-05-24 15:43
ComboFix2.txt  2008-08-23 18:50
ComboFix3.txt  2008-08-23 12:04

Pre-Run: 21.929.824.256 bytes free
Post-Run: 22.440.161.280 bytes free

257   --- E O F ---   2009-05-20 21:07



Stationary pc combo fix:


ComboFix 09-05-23.04 - Administrator 2009.05.24 19:23.9 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1257.370.1033.18.1023.705 [GMT 3:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Outdated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((   Files Created from 2009-04-24 to 2009-05-24  )))))))))))))))))))))))))))))))
.

2009-05-19 15:36 . 2009-05-19 15:36   --------   d-----w   C:\_OTListIt
2009-05-18 18:49 . 2009-05-18 18:50   --------   d-----w   C:\Rooter$
2009-05-03 07:10 . 2009-05-03 20:12   --------   d-----w   C:\Rohan_Global
2009-05-02 15:20 . 2009-03-11 15:20   208384   ----a-w   c:\windows\system32\uc_rohan_launching.dll
2009-05-02 15:20 . 2009-01-29 08:53   87472   ----a-w   c:\windows\system32\ijjiChannelingPlugin.dll
2009-05-01 22:43 . 2009-04-30 16:58   503808   ----a-w   c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\64udm5j1.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2009-05-01 22:43 . 2009-04-16 01:36   81920   ----a-w   c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\64udm5j1.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-20 07:49 . 2009-04-05 20:51   81984   ----a-w   c:\windows\system32\bdod.bin
2009-05-18 12:23 . 2008-09-15 20:18   --------   d-----w   c:\documents and settings\Administrator\Application Data\uTorrent
2009-05-03 08:52 . 2008-09-15 19:59   --------   d--h--w   c:\program files\InstallShield Installation Information
2009-05-03 08:28 . 2008-10-17 10:30   --------   d-----w   c:\program files\Microsoft ActiveSync
2009-05-03 08:28 . 2009-01-29 13:39   --------   d-----w   c:\program files\Pando Networks
2009-05-03 08:26 . 2009-02-22 17:24   --------   d-----w   c:\program files\CombatTools
2009-05-02 09:13 . 2008-10-04 16:25   --------   d-----w   c:\program files\AGEIA Technologies
2009-05-02 09:13 . 2008-10-08 18:28   --------   d-----w   c:\program files\Common Files\Wise Installation Wizard
2009-04-29 18:39 . 2009-02-27 19:38   --------   d-----w   c:\program files\Steam
2009-04-23 11:56 . 2009-04-23 11:56   --------   d-----w   c:\documents and settings\All Users\Application Data\Tages
2009-04-23 10:55 . 2009-04-23 10:55   --------   d-----w   c:\documents and settings\Administrator\Application Data\InstallShield Installation Information
2009-04-23 10:55 . 2009-04-23 10:55   279712   ----a-w   c:\windows\system32\drivers\atksgt.sys
2009-04-23 10:55 . 2009-04-23 10:55   25888   ----a-w   c:\windows\system32\drivers\lirsgt.sys
2009-04-06 05:02 . 2009-04-06 04:43   664   ----a-w   c:\windows\system32\d3d9caps.dat
2009-04-05 22:31 . 2008-09-15 20:09   71720   ----a-w   c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-05 22:02 . 2009-04-05 22:02   --------   d-----w   c:\program files\MSXML 4.0
2009-04-05 21:48 . 2009-04-05 21:48   --------   d-----w   c:\program files\Windows Media Connect 2
2009-04-05 20:58 . 2008-10-17 11:01   104328   ----a-w   c:\windows\system32\drivers\bdfndisf.sys
2009-04-05 20:45 . 2009-04-05 20:43   --------   d-----w   c:\documents and settings\All Users\Application Data\BitDefender
2009-04-05 20:43 . 2009-04-05 20:43   --------   d-----w   c:\documents and settings\Administrator\Application Data\BitDefender
2009-04-05 20:43 . 2009-04-05 20:43   --------   d-----w   c:\program files\BitDefender
2009-04-05 20:43 . 2009-04-05 20:41   --------   d-----w   c:\program files\Common Files\BitDefender
2009-04-05 15:52 . 2009-04-05 15:52   --------   d-----w   c:\documents and settings\Administrator\Application Data\QuickScan
2009-04-04 17:49 . 2008-09-16 07:48   --------   d-----w   c:\program files\Spybot - Search & Destroy
2009-04-01 19:06 . 2009-04-01 19:06   --------   d-----w   c:\documents and settings\All Users\Application Data\wanted
2009-04-01 19:04 . 2008-10-14 14:55   418480   ----a-w   c:\windows\system32\wrap_oal.dll
2009-04-01 19:04 . 2008-10-14 14:55   115432   ----a-w   c:\windows\system32\OpenAL32.dll
2009-04-01 13:58 . 2009-04-01 13:11   8   ----a-w   c:\windows\system32\nvModes.dat
2009-04-01 06:11 . 2008-09-15 20:31   --------   d-----w   c:\documents and settings\Administrator\Application Data\Skype
2009-03-31 18:29 . 2009-03-31 18:28   --------   d-----w   c:\program files\ABBYY eFormFiller 2.5
2009-03-31 18:29 . 2009-03-31 18:29   --------   d-----w   c:\documents and settings\Administrator\Application Data\ABBYY
2009-03-31 18:28 . 2009-03-31 18:28   --------   d-----w   c:\documents and settings\All Users\Application Data\ABBYY
2009-03-31 17:53 . 2008-09-28 10:08   --------   d-----w   c:\documents and settings\Administrator\Application Data\skypePM
2009-03-30 19:35 . 2008-09-16 08:39   --------   d-----w   c:\program files\Opera
2009-03-27 21:49 . 2009-03-27 19:53   --------   d-----w   c:\documents and settings\Administrator\Application Data\Hamachi
2009-03-27 19:53 . 2009-03-27 19:53   25280   ----a-w   c:\windows\system32\drivers\hamachi.sys
2009-03-26 18:25 . 2009-03-26 17:57   --------   d-----w   c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-03-26 18:25 . 2009-03-26 18:25   --------   d-----w   c:\program files\NVIDIA Corporation
2009-03-26 17:54 . 2009-03-26 17:54   --------   d-----w   c:\documents and settings\Administrator\Application Data\Uniblue
2009-03-26 17:54 . 2009-03-26 17:54   --------   d-----w   c:\program files\Uniblue
2009-03-06 14:22 . 2008-04-14 02:42   284160   ----a-w   c:\windows\system32\pdh.dll
2009-03-03 18:05 . 2009-03-03 18:03   858181   ----a-w   c:\documents and settings\Administrator\Application Data\Hide IP NG\hideipng-update.exe
2009-03-03 00:18 . 2008-04-14 02:42   826368   ----a-w   c:\windows\system32\wininet.dll
2009-04-05 20:58 . 2008-10-30 14:34   49664   ----a-w   c:\program files\mozilla firefox\components\FFComm.dll
2006-05-03 09:06 . 2008-11-02 22:09   163328   --sh--r   c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2008-11-02 22:09   31232   --sh--r   c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2008-11-02 22:09   216064   --sh--r   c:\windows\system32\nbDX.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-04-28 778240]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-04-05 69632]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-02-20 124928]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\ijji\\ENGLISH\\u_gunz.exe"=
"c:\\Program Files\\Atari\\AITD\\Alone.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonEU\\NGM\\NGM.exe"=
"d:\\serverdoc\\CS_server\\counter-strike\\hlds.exe"=
"d:\\serverdoc\\CS_server\\counter-strike\\cstrike.exe"=
"d:\\Games\\counter-strike\\cstrike.exe"=
"d:\\RatioMaster-1.7.5\\RatioMaster.exe"=
"c:\\Program Files\\Steam\\steamapps\\fxel\\team fortress 2\\hl2.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"d:\\Games\\heroes3\\h3wog.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Games\\World Series of Poker TOC\\WSOPTOC.exe"=
"d:\\Games\\X-Men Origins - Wolverine(tm)\\Binaries\\Wolverine.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"58910:TCP"= 58910:TCP:Pando Media Booster
"58910:UDP"= 58910:UDP:Pando Media Booster
"7001:TCP"= 7001:TCP:port
"7002:TCP"= 7002:TCP:Sword of the new world

R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008.10.06 17:16 82696]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008.09.18 11:09 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008.10.17 14:01 104328]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008.07.17 12:06 118784]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 USB_RNDIS_51;ZTE USB Remote NDIS Device Driver;c:\windows\system32\drivers\usb8023.sys [2008.04.14 00:26 12800]
S3 XDva190;XDva190;\??\c:\windows\system32\XDva190.sys --> c:\windows\system32\XDva190.sys [?]
S3 XDva260;XDva260;\??\c:\windows\system32\XDva260.sys --> c:\windows\system32\XDva260.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx   REG_MULTI_SZ      scan
.
Contents of the 'Scheduled Tasks' folder

2009-04-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 14:57]

2009-05-24 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-06-07 19:01]

2009-05-14 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-06-07 19:01]

2009-05-15 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-03-26 08:13]

2009-03-26 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-03-26 08:13]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\64udm5j1.default\
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonEU\NGM\npNxGameeu.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll

---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-24 19:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...  

scanning hidden autostart entries ...

scanning hidden files ...  

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-776561741-1532298954-1417001333-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-776561741-1532298954-1417001333-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b8,2d,97,83,ff,01,cd,72,c0,be,07,a7,e3,24,fa,a4,c0,76,ac,d8,5d,36,b1,
   af,87,d8,c9,61,47,61,5e,1b,63,6f,96,7a,a2,9f,39,d0,03,c4,c5,f1,13,8a,eb,c3,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50

[HKEY_USERS\S-1-5-21-776561741-1532298954-1417001333-500\Software\SecuROM\License information*]
"datasecu"=hex:21,42,af,05,16,d0,00,d2,52,ff,58,bf,c1,59,a3,9a,54,98,ba,31,62,
   0a,e7,9d,30,8f,d8,28,70,5f,e2,b0,40,93,1e,32,e1,3d,fd,76,fa,bf,5e,ca,ec,c2,\
"rkeysecu"=hex:d0,f0,fd,3a,41,25,01,85,9e,93,62,9f,e0,62,7b,01
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3488)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\BitDefender\BitDefender 2009\bdshelxt.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\txmlutil.dll
c:\program files\BitDefender\BitDefender 2009\txmlx.dll
c:\program files\BitDefender\BitDefender 2009\ENU\bdshelxt.ui
c:\program files\Nero\Nero8\Nero BackItUp\NBShell.dll
c:\program files\BitDefender\BitDefender 2009\bdfvsctx.dll
c:\program files\BitDefender\BitDefender 2009\ENU\bdfvsctx.ui
c:\program files\BitDefender\BitDefender 2009\fshredctx.dll
c:\program files\BitDefender\BitDefender 2009\ENU\fshredctx.ui
c:\program files\WinRAR\rarext.dll
c:\program files\7-Zip\7-zip.dll
.
Completion time: 2009-05-24 19:27
ComboFix-quarantined-files.txt  2009-05-24 16:27
ComboFix2.txt  2009-05-18 12:33
ComboFix3.txt  2009-05-15 09:20
ComboFix4.txt  2009-05-15 09:13
ComboFix5.txt  2009-05-24 16:22

Pre-Run: 11.148.865.536 bytes free
Post-Run: 11.124.903.936 bytes free

210   --- E O F ---   2009-05-14 22:11

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #15 on: May 24, 2009, 11:49:12 AM »
On the Stationary computer
What happens when you boot to Safe mode with Networking, are you able to connect then?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #16 on: May 24, 2009, 02:13:43 PM »
No, cant connect then either. Would it make any diffrence if i try to connect the modem and PC not with enthernet but with USB?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #17 on: May 24, 2009, 02:16:18 PM »
You could try it, your option

I have no idea what modem./router configuration you have, you didn't supply the info

They are seperate units aren't they?
When did you install BitDefender? Before these problems started with internet connection?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline FIxeL

  • Full Member
  • ***
  • Posts: 145
  • Karma: +0/-0
    • View Profile
Internet Problems
« Reply #18 on: May 24, 2009, 02:32:50 PM »
On stationary pc its for more than 2-3 months so way before the problems started and on laptop i dont quite remember if before or after, becouse i havent used it for a while and the antivirus was old and outdated, i took laptop out when the problems sarted with the stationary pc . Though then i could connect to the internet with the laptop via PPPOE although i couldnt connect with the stationary.
I got two modems: ZTE 831 and a router/modem SpeedTough 585. At the momment im connected with laptop thrue wireless internet from the router.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Internet Problems
« Reply #19 on: May 24, 2009, 02:37:20 PM »
Are you using both modem and modem/router
Were you able to just use the Modem at one time?

If you could, can you shut down All PC's
disconnect power to modems>>Unplug them

Connect Stationary PC directly to just modem
Power up the modem, let it detect connection
Power up Stat. PC, does it connect?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here