<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
<channel>
	<title>Malware</title>
	<description>Malware Removal Threads</description>
	<link>http://www.atribune.org/forums/index.php</link>
	<pubDate>Fri, 30 Jul 2010 14:25:48 +0200</pubDate>
	<ttl>0</ttl>
	<item>
		<title>Please review my HJ log and other logs</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=6071</link>
		<description><![CDATA[I have an older PC that I am reviving and it has been abused.  I have cleaned it up as much as I can but am concerned that it is still infected.  It was behaving very slow, now better but still not optimum.  Items found and eventually cleaned were Win32/Viking.JB and Win32/Emerleox.gen!A.<br />One sign of a possible problem is that my View settings in Windows Explorer keep re-setting to default.  I like to un-hide known file extensions but they keep re-hiding.<br /><br />Below are my log files.  Please let me know if you need more info.<br />Thanks<br /><br />HIJACKTHIS LOGFILE:<br />Logfile of Trend Micro HijackThis v2.0.2<br />Scan saved at 7:43:24 PM, on 7/16/2010<br />Platform: Windows XP SP2 (WinNT 5.01.2600)<br />MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />Boot mode: Normal<br /><br />Running processes:<br />C:&#092;WIN98&#092;System32&#092;smss.exe<br />C:&#092;WIN98&#092;system32&#092;winlogon.exe<br />C:&#092;WIN98&#092;system32&#092;services.exe<br />C:&#092;WIN98&#092;system32&#092;lsass.exe<br />C:&#092;WIN98&#092;system32&#092;svchost.exe<br />c:&#092;Program Files&#092;Microsoft Security Essentials&#092;MsMpEng.exe<br />C:&#092;WIN98&#092;SYSTEM32&#092;acs.exe<br />C:&#092;WIN98&#092;system32&#092;svchost.exe<br />C:&#092;WIN98&#092;Explorer.EXE<br />C:&#092;WIN98&#092;system32&#092;msiexec.exe<br />C:&#092;WIN98&#092;system32&#092;svchost.exe<br />C:&#092;WIN98&#092;system32&#092;wuauclt.exe<br />C:&#092;WIN98&#092;system32&#092;CTHELPER.EXE<br />C:&#092;Program Files&#092;Microsoft Security Essentials&#092;msseces.exe<br />C:&#092;WIN98&#092;system32&#092;ctfmon.exe<br />C:&#092;Program Files&#092;NETGEAR&#092;WG311T&#092;wlancfg5.exe<br />C:&#092;WIN98&#092;System32&#092;svchost.exe<br />C:&#092;WIN98&#092;system32&#092;wuauclt.exe<br />F:&#092;Ad-AwareInstall.exe<br />F:&#092;HijackThis.exe<br />c:&#092;Program Files&#092;Microsoft Security Essentials&#092;MpCmdRun.exe<br /><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html" target="_blank">http://us.rd.yahoo.com/customize/ycomp_adb.../search/ie.html</a><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ycomp_adb...//www.yahoo.com</a><br />R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html" target="_blank">http://us.rd.yahoo.com/customize/ycomp_adb.../search/ie.html</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Adobe&#092;Acrobat 7.0&#092;ActiveX&#092;AcroIEHelper.dll<br />O4 - HKLM&#092;..&#092;Run: [WINDVDPatch] CTHELPER.EXE<br />O4 - HKLM&#092;..&#092;Run: [MSSE] "c:&#092;Program Files&#092;Microsoft Security Essentials&#092;msseces.exe" -hide -runkey<br />O4 - HKCU&#092;..&#092;Run: [ctfmon.exe] C:&#092;WIN98&#092;system32&#092;ctfmon.exe<br />O4 - HKUS&#092;S-1-5-18&#092;..&#092;Run: [DWQueuedReporting] "c:&#092;PROGRA~1&#092;COMMON~1&#092;MICROS~1&#092;DW&#092;dwtrig20.exe" -t (User 'SYSTEM')<br />O4 - HKUS&#092;.DEFAULT&#092;..&#092;Run: [DWQueuedReporting] "c:&#092;PROGRA~1&#092;COMMON~1&#092;MICROS~1&#092;DW&#092;dwtrig20.exe" -t (User 'Default user')<br />O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:&#092;Program Files&#092;NETGEAR&#092;WG311T&#092;wlancfg5.exe<br />O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1279162089461" target="_blank">http://www.update.microsoft.com/microsoftu...b?1279162089461</a><br />O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - <a href="http://us.mcafee.com/Apps/WSC/en-us/WscWlanScannerCtrl.cab" target="_blank">http://us.mcafee.com/Apps/WSC/en-us/WscWlanScannerCtrl.cab</a><br />O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:&#092;WIN98&#092;SYSTEM32&#092;acs.exe<br />O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:&#092;Program Files&#092;Symantec&#092;LiveUpdate&#092;ALUSchedulerSvc.exe (file missing)<br /><br />--<br />End of file - 3593 bytes<br /><br />MBAM LOG FILE:<br />Malwarebytes' Anti-Malware 1.46<br />www.malwarebytes.org<br /><br />Database version: 4317<br /><br />Windows 5.1.2600 Service Pack 2<br />Internet Explorer 7.0.5730.11<br /><br />7/15/2010 11:19:54 PM<br />mbam-log-2010-07-15 (23-19-54).txt<br /><br />Scan type: Quick scan<br />Objects scanned: 132455<br />Time elapsed: 1 hour(s), 31 minute(s), 29 second(s)<br /><br />Memory Processes Infected: 0<br />Memory Modules Infected: 0<br />Registry Keys Infected: 0<br />Registry Values Infected: 0<br />Registry Data Items Infected: 1<br />Folders Infected: 0<br />Files Infected: 1<br /><br />Memory Processes Infected:<br />(No malicious items detected)<br /><br />Memory Modules Infected:<br />(No malicious items detected)<br /><br />Registry Keys Infected:<br />(No malicious items detected)<br /><br />Registry Values Infected:<br />(No malicious items detected)<br /><br />Registry Data Items Infected:<br />HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Explorer&#092;Advanced&#092;Folder&#092;Hidden&#092;SHOWALL&#092;CheckedValue (Hijack.System.Hidden) -&gt; Bad: (0) Good: (1) -&gt; Quarantined and deleted successfully.<br /><br />Folders Infected:<br />(No malicious items detected)<br /><br />Files Infected:<br />C:&#092;GameSetup.exe (Worm.Fujacks) -&gt; Quarantined and deleted successfully.<br /><br />My comment - I have apparently cleaned up these findins with MBAM, Lavasoft Ad-Aware and Microsoft Security Essentials.  new logfile is clean.<br /><br /><br />OTL.TXT:<br />OTL logfile created on: 7/19/2010 10:50:03 PM - Run 1<br />OTL by OldTimer - Version 3.2.5.0     Folder = F:&#092;<br />Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation<br />Internet Explorer (Version = 8.0.6001.18702)<br />Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy<br /> <br />512.00 Mb Total Physical Memory | 180.00 Mb Available Physical Memory | 35.00% Memory free<br />1.00 Gb Paging File | 1.00 Gb Available in Paging File | 63.00% Paging File free<br />Paging file location(s): C:&#092;pagefile.sys 768 1536 [binary data]<br /> <br />%SystemDrive% = C: | %SystemRoot% = C:&#092;WIN98 | %ProgramFiles% = C:&#092;Program Files<br />Drive C: | 111.76 Gb Total Space | 96.43 Gb Free Space | 86.29% Space Free | Partition Type: FAT32<br />D: Drive not present or media not loaded<br />E: Drive not present or media not loaded<br />Drive F: | 960.32 Mb Total Space | 698.29 Mb Free Space | 72.71% Space Free | Partition Type: FAT32<br />G: Drive not present or media not loaded<br />H: Drive not present or media not loaded<br />I: Drive not present or media not loaded<br /> <br />Computer Name: SUE<br />Current User Name: S<br />Logged in as Administrator.<br /> <br />Current Boot Mode: Normal<br />Scan Mode: Current user<br />Company Name Whitelist: On<br />Skip Microsoft Files: On<br />File Age = 90 Days<br />Output = Standard<br />Quick Scan<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Processes (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />PRC - [2010/07/15 21:24:50 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Microsoft Security Essentials&#092;msseces.exe<br />PRC - [2010/07/12 03:55:40 | 001,352,832 | ---- | M] (Lavasoft) -- C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe<br />PRC - [2010/07/12 03:55:40 | 000,864,112 | ---- | M] (Lavasoft) -- C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWTray.exe<br />PRC - [2010/05/22 09:28:48 | 000,571,904 | ---- | M] (OldTimer Tools) -- F:&#092;OTL.exe<br />PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:&#092;Program Files&#092;Microsoft Security Essentials&#092;MsMpEng.exe<br />PRC - [2004/12/17 10:55:26 | 007,708,672 | ---- | M] () -- C:&#092;Program Files&#092;NETGEAR&#092;WG311T&#092;wlancfg5.exe<br />PRC - [2004/12/01 21:44:00 | 000,036,864 | ---- | M] () -- C:&#092;WIN98&#092;SYSTEM32&#092;acs.exe<br />PRC - [2004/08/04 12:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:&#092;WIN98&#092;explorer.exe<br />PRC - [2002/07/02 17:56:00 | 000,024,576 | ---- | M] (Creative Technology Ltd) -- C:&#092;WIN98&#092;SYSTEM32&#092;CTHELPER.EXE<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Modules (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />EXTRAS.TXT:<br />OTL Extras logfile created on: 7/19/2010 10:50:04 PM - Run 1<br />OTL by OldTimer - Version 3.2.5.0     Folder = F:&#092;<br />Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation<br />Internet Explorer (Version = 8.0.6001.18702)<br />Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy<br /> <br />512.00 Mb Total Physical Memory | 180.00 Mb Available Physical Memory | 35.00% Memory free<br />1.00 Gb Paging File | 1.00 Gb Available in Paging File | 63.00% Paging File free<br />Paging file location(s): C:&#092;pagefile.sys 768 1536 [binary data]<br /> <br />%SystemDrive% = C: | %SystemRoot% = C:&#092;WIN98 | %ProgramFiles% = C:&#092;Program Files<br />Drive C: | 111.76 Gb Total Space | 96.43 Gb Free Space | 86.29% Space Free | Partition Type: FAT32<br />D: Drive not present or media not loaded<br />E: Drive not present or media not loaded<br />Drive F: | 960.32 Mb Total Space | 698.29 Mb Free Space | 72.71% Space Free | Partition Type: FAT32<br />G: Drive not present or media not loaded<br />H: Drive not present or media not loaded<br />I: Drive not present or media not loaded<br /> <br />Computer Name: SUE<br />Current User Name: S<br />Logged in as Administrator.<br /> <br />Current Boot Mode: Normal<br />Scan Mode: Current user<br />Company Name Whitelist: On<br />Skip Microsoft Files: On<br />File Age = 90 Days<br />Output = Standard<br />Quick Scan<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Extra Registry (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== File Associations ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Classes&#092;&lt;extension&gt;]<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Shell Spawning ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Classes&#092;&lt;key&gt;&#092;shell&#092;[command]&#092;command]<br />batfile [open] -- "%1" %*<br />cmdfile [open] -- "%1" %*<br />comfile [open] -- "%1" %*<br />exefile [open] -- "%1" %*<br />htmlfile [edit] -- "C:&#092;Program Files&#092;Microsoft Office&#092;Office&#092;msohtmed.exe" %1 File not found<br />piffile [open] -- "%1" %*<br />regfile [merge] -- Reg Error: Key error.<br />scrfile [config] -- "%1"<br />scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)<br />scrfile [open] -- "%1" /S<br />txtfile [edit] -- Reg Error: Key error.<br />Unknown [openas] -- %SystemRoot%&#092;system32&#092;rundll32.exe %SystemRoot%&#092;system32&#092;shell32.dll,OpenAs_RunDLL %1<br />Directory [find] -- %SystemRoot%&#092;Explorer.exe (Microsoft Corporation)<br />Folder [open] -- %SystemRoot%&#092;Explorer.exe /idlist,%I,%L (Microsoft Corporation)<br />Folder [explore] -- %SystemRoot%&#092;Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)<br />Drive [find] -- %SystemRoot%&#092;Explorer.exe (Microsoft Corporation)<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Security Center Settings ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center]<br />"FirstRunDisabled" = 1<br />"UpdatesDisableNotify" = 0<br />"AntiVirusOverride" = 0<br />"FirewallOverride" = 0<br />"AntiVirusDisableNotify" = 0<br />"FirewallDisableNotify" = 0<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;AhnlabAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;ComputerAssociatesAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;KasperskyAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;McAfeeAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;McAfeeFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;PandaAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;PandaFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SophosAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SymantecAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SymantecFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TinyFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TrendAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TrendFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;ZoneLabsFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile&#092;GloballyOpenPorts&#092;List]<br />"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004<br />"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005<br />"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001<br />"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile]<br />"EnableFirewall" = 1<br />"DoNotAllowExceptions" = 0<br />"DisableNotifications" = 0<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile&#092;GloballyOpenPorts&#092;List]<br />"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007<br />"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008<br />"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004<br />"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005<br />"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001<br />"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Authorized Applications List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile&#092;AuthorizedApplications&#092;List]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile&#092;AuthorizedApplications&#092;List]<br />"C:&#092;Program Files&#092;Common Files&#092;AOL&#092;Loader&#092;aolload.exe" = C:&#092;Program Files&#092;Common Files&#092;AOL&#092;Loader&#092;aolload.exe:*:Enabled:AOL Loader -- (America Online, Inc.)<br />"C:&#092;Program Files&#092;Common Files&#092;AOL&#092;1128224247&#092;EE&#092;aolsoftware.exe" = C:&#092;Program Files&#092;Common Files&#092;AOL&#092;1128224247&#092;EE&#092;aolsoftware.exe:*:Enabled:AOL Services -- (America Online, Inc.)<br />"C:&#092;Program Files&#092;Common Files&#092;AOL&#092;1128224247&#092;EE&#092;aim6.exe" = C:&#092;Program Files&#092;Common Files&#092;AOL&#092;1128224247&#092;EE&#092;aim6.exe:*:Enabled:AIM -- (America Online, Inc.)<br />"C:&#092;Program Files&#092;iTunes&#092;iTunes.exe" = C:&#092;Program Files&#092;iTunes&#092;iTunes.exe:*:Enabled:iTunes -- File not found<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== HKEY_LOCAL_MACHINE Uninstall List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Uninstall]<br />"{00030409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Small Business<br />"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Disc 2<br />"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP<br />"{3CB41017-F5CA-4C56-934C-ED02156251E6}" = iTunes<br />"{3FCAADB8-EB1B-11D6-AB2D-0090271A23A2}" = Sound Blaster Live! Web 2K/XP<br />"{50D8FFDD-90CD-4859-841F-AA1961C7767A}" = QuickTime<br />"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting<br />"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures<br />"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.5<br />"{AC76BA86-7AD7-5464-3428-7E8A450000A7}" = Spelling Dictionaries For Adobe Reader Package<br />"{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}" = Symantec Network Drivers Update<br />"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware<br />"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware<br />"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials<br />"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)<br />"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01<br />"{FC321AD2-48B4-4013-B997-A65D5FBBD006}" = NETGEAR Wireless Adapter WG311T<br />"Ad-Aware" = Ad-Aware<br />"HijackThis" = HijackThis 2.0.2<br />"ie8" = Windows Internet Explorer 8<br />"InstallShield_{FC321AD2-48B4-4013-B997-A65D5FBBD006}" = NETGEAR Wireless Adapter WG311T<br />"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware<br />"Microsoft Security Essentials" = Microsoft Security Essentials<br />"Need For Speed III" = Need For Speed III<br />"NVIDIA Drivers" = NVIDIA Drivers<br />"RealPlayer 6.0" = RealPlayer<br />"Shockwaveflash" = Macromedia Flash Player 8<br />"Windows Media Format Runtime" = Windows Media Format Runtime<br />"Windows Media Player" = Windows Media Player 10<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Last 10 Event Log Errors ==========<!--colorc--></span><!--/colorc--><br /> <br />[ Application Events ]<br />Error - 7/17/2010 5:57:20 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:26 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:34 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:41 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:49 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:56 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:58:04 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:58:12 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:58:21 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 10:56:14 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 2.1.6805.0,<br /> P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />[ Application Events ]<br />Error - 7/17/2010 5:57:20 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:26 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:34 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:41 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:49 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:57:56 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:58:04 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:58:12 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 5:58:21 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P2 2.1.6805.0, P3 timeout, P4 1.1.6004.0, P5 local, P6 unspecified, P7 unspecified,<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />Error - 7/17/2010 10:56:14 PM | Computer Name = SUE | Source = MPSampleSubmission | ID = 5000<br />Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 2.1.6805.0,<br /> P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),<br /> P8 NIL, P9 NIL, P10 NIL.<br /> <br />[ System Events ]<br />Error - 7/18/2010 2:03:38 PM | Computer Name = SUE | Source = DCOM | ID = 10000<br />Description = Unable to start a DCOM Server: {98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C}.<br />The<br /> error:  "%2"  Happened while starting this command:  "C:&#092;Program Files&#092;Adobe&#092;Acrobat <br />7.0&#092;Reader&#092;AcroRd32Info.exe" /PDFShell -Embedding<br /> <br />Error - 7/18/2010 2:03:38 PM | Computer Name = SUE | Source = DCOM | ID = 10000<br />Description = Unable to start a DCOM Server: {98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C}.<br />The<br /> error:  "%2"  Happened while starting this command:  "C:&#092;Program Files&#092;Adobe&#092;Acrobat <br />7.0&#092;Reader&#092;AcroRd32Info.exe" /PDFShell -Embedding<br /> <br />Error - 7/18/2010 3:01:22 PM | Computer Name = SUE | Source = Service Control Manager | ID = 7001<br />Description = The Print Spooler service depends on the LexBce Server service which<br /> failed to start because of the following error:   %%1058<br /> <br />Error - 7/19/2010 9:42:44 PM | Computer Name = SUE | Source = Disk | ID = 262155<br />Description = The driver detected a controller error on &#092;Device&#092;Harddisk1&#092;D.<br /> <br />Error - 7/19/2010 9:43:44 PM | Computer Name = SUE | Source = Windows Update Agent | ID = 20<br />Description = Installation Failure: Windows failed to install the following update<br /> with error 0x800f0102: Security Update for Windows XP (KB923561).<br /> <br />Error - 7/19/2010 9:43:44 PM | Computer Name = SUE | Source = Windows Update Agent | ID = 20<br />Description = Installation Failure: Windows failed to install the following update<br /> with error 0x80070002: Security Update for Windows XP (KB958644).<br /> <br />Error - 7/19/2010 9:43:44 PM | Computer Name = SUE | Source = Windows Update Agent | ID = 20<br />Description = Installation Failure: Windows failed to install the following update<br /> with error 0x80070002: Security Update for Windows XP (KB958470).<br /> <br />Error - 7/19/2010 9:49:38 PM | Computer Name = SUE | Source = Service Control Manager | ID = 7031<br />Description = The Microsoft Antimalware Service service terminated unexpectedly.<br />  It has done this 1 time(s).  The following corrective action will be taken in <br />15000 milliseconds: Restart the service.<br /> <br />Error - 7/19/2010 9:49:38 PM | Computer Name = SUE | Source = Service Control Manager | ID = 7034<br />Description = The Atheros Configuration Service service terminated unexpectedly.<br />  It has done this 1 time(s).<br /> <br />Error - 7/19/2010 9:49:51 PM | Computer Name = SUE | Source = Service Control Manager | ID = 7031<br />Description = The Lavasoft Ad-Aware Service service terminated unexpectedly.  It<br /> has done this 1 time(s).  The following corrective action will be taken in 5000<br /> milliseconds: Restart the service.<br /> <br /> <br />&lt; End of report &gt;<br /><br />ROOTER.TXT:<br />Rooter.exe (v1.0.2) by Eric_71<br />.<br />SeDebugPrivilege granted successfully ...<br />.<br />Windows XP Home Edition (5.1.2600) Service Pack 2<br />[32_bits] - x86 Family 6 Model 7 Stepping 3, GenuineIntel<br />.<br />Error OpenService (wscsvc) : 1060<br />[SharedAccess] RUNNING (state:4)<br />Windows Firewall -&gt; Enabled<br />.<br />Internet Explorer 8.0.6001.18702<br />.<br />A:&#092;  [Removable]<br />C:&#092;  [Fixed-FAT32] .. ( Total:111 Go - Free:96 Go )<br />D:&#092;  [Removable]<br />E:&#092;  [CD_Rom]<br />F:&#092;  [Removable]<br />.<br />Scan : 23:05.03<br />Path : F:&#092;Rooter.exe<br />User : S ( Administrator -&gt; YES )<br />.<br />----------------------&#092;&#092; Processes<br />.<br />Locked [System Process] (0)<br />______ System (4)<br />______ &#092;SystemRoot&#092;System32&#092;smss.exe (276)<br />______ &#092;??&#092;C:&#092;WIN98&#092;system32&#092;csrss.exe (336)<br />______ &#092;??&#092;C:&#092;WIN98&#092;system32&#092;winlogon.exe (360)<br />______ C:&#092;WIN98&#092;system32&#092;services.exe (404)<br />______ C:&#092;WIN98&#092;system32&#092;lsass.exe (416)<br />______ C:&#092;WIN98&#092;system32&#092;svchost.exe (576)<br />______ C:&#092;WIN98&#092;system32&#092;svchost.exe (640)<br />______ c:&#092;Program Files&#092;Microsoft Security Essentials&#092;MsMpEng.exe (680)<br />______ C:&#092;WIN98&#092;SYSTEM32&#092;acs.exe (780)<br />______ C:&#092;WIN98&#092;system32&#092;svchost.exe (836)<br />______ C:&#092;WIN98&#092;system32&#092;svchost.exe (876)<br />______ C:&#092;WIN98&#092;system32&#092;svchost.exe (964)<br />______ C:&#092;WIN98&#092;Explorer.EXE (1100)<br />______ C:&#092;WIN98&#092;system32&#092;svchost.exe (1400)<br />______ C:&#092;WIN98&#092;system32&#092;CTHELPER.EXE (1424)<br />______ C:&#092;Program Files&#092;Microsoft Security Essentials&#092;msseces.exe (1440)<br />______ C:&#092;WIN98&#092;system32&#092;ctfmon.exe (1448)<br />______ C:&#092;Program Files&#092;NETGEAR&#092;WG311T&#092;wlancfg5.exe (1480)<br />______ C:&#092;WIN98&#092;system32&#092;svchost.exe (1792)<br />______ C:&#092;WIN98&#092;system32&#092;wdfmgr.exe (1848)<br />______ C:&#092;WIN98&#092;System32&#092;alg.exe (724)<br />______ C:&#092;WIN98&#092;System32&#092;svchost.exe (2056)<br />______ C:&#092;WIN98&#092;system32&#092;wuauclt.exe (2392)<br />______ C:&#092;WIN98&#092;system32&#092;taskmgr.exe (2592)<br />______ C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe (3792)<br />______ C:&#092;WIN98&#092;system32&#092;wbem&#092;unsecapp.exe (3896)<br />______ C:&#092;WIN98&#092;system32&#092;wbem&#092;wmiprvse.exe (3960)<br />______ C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWTray.exe (452)<br />______ F:&#092;Rooter.exe (1752)<br />.<br />----------------------&#092;&#092; Device&#092;Harddisk0&#092;<br />.<br />&#092;Device&#092;Harddisk0 [Sectors : 63 x 512 Bytes]<br />.<br />&#092;Device&#092;Harddisk0&#092;Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:120031478784)<br />.<br />----------------------&#092;&#092; Scheduled Tasks<br />.<br />C:&#092;WIN98&#092;Tasks&#092;DESKTOP.INI<br />C:&#092;WIN98&#092;Tasks&#092;SA.DAT<br />C:&#092;WIN98&#092;Tasks&#092;Tune-up Application Start.job<br />C:&#092;WIN98&#092;Tasks&#092;Desktop_.ini<br />C:&#092;WIN98&#092;Tasks&#092;MpIdleTask.job<br />C:&#092;WIN98&#092;Tasks&#092;MP Scheduled Scan.job<br />C:&#092;WIN98&#092;Tasks&#092;Ad-Aware Update (Weekly).job<br />.<br />----------------------&#092;&#092; Registry<br />.<br />.<br />----------------------&#092;&#092; Files & Folders<br />.<br />----------------------&#092;&#092; Scan completed at 23:05.06<br />.<br />C:&#092;Rooter$&#092;Rooter_1.txt - (19/07/2010 | 23:05.06)<br /><br />LOCKSEARC&gt;TXT:<br />LockSearch by jpshortstuff (05.11.09.1)<br />Log created at 23:08 on 19/07/2010 (S)<br />Scanning C:&#092;<br /><br /><br />C:&#092;hiberfil.sys<br />-------------------------<br /><br /><br />C:&#092;pagefile.sys<br />-------------------------<br /><br />-=E.O.F=-<br /><br />CKFILES.TXT:<br />CKScanner - Additional Security Risks - These are not necessarily bad<br />scanner sequence 3.MN.11<br /> ----- EOF ----- <br /><br />CKFILES.TXT:<br />CKScanner - Additional Security Risks - These are not necessarily bad<br />scanner sequence 3.MN.11<br /> ----- EOF ----- <br /><br />WVCHECK.EXE:<br />My comment - program opens and runs but does not open Notepad and no apparent log file generated!<br /><br />ARK.TXT:<br />CKScanner - Additional Security Risks - These are not necessarily bad<br />scanner sequence 3.MN.11<br /> ----- EOF -----]]></description>
		<pubDate>Sat, 24 Jul 2010 03:43:45 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=6071</guid>
	</item>
	<item>
		<title><![CDATA[Looks like I've been hit again]]></title>
		<link>http://www.atribune.org/forums/index.php?showtopic=6072</link>
		<description><![CDATA[Well, I followed the directions in the "Before you post" thread and am still having problems.<br /><br />So here are the logs.<br /><br />And now the MBAM log:<br /><br />Malwarebytes' Anti-Malware 1.46<br />www.malwarebytes.org<br /><br />Database version: 4346<br /><br />Windows 5.1.2600 Service Pack 3<br />Internet Explorer 8.0.6001.18702<br /><br />7/25/2010 2:49:41 PM<br />mbam-log-2010-07-25 (14-49-41).txt<br /><br />Scan type: Quick scan<br />Objects scanned: 127948<br />Time elapsed: 9 minute(s), 57 second(s)<br /><br />Memory Processes Infected: 0<br />Memory Modules Infected: 0<br />Registry Keys Infected: 0<br />Registry Values Infected: 0<br />Registry Data Items Infected: 0<br />Folders Infected: 0<br />Files Infected: 0<br /><br />Memory Processes Infected:<br />(No malicious items detected)<br /><br />Memory Modules Infected:<br />(No malicious items detected)<br /><br />Registry Keys Infected:<br />(No malicious items detected)<br /><br />Registry Values Infected:<br />(No malicious items detected)<br /><br />Registry Data Items Infected:<br />(No malicious items detected)<br /><br />Folders Infected:<br />(No malicious items detected)<br /><br />Files Infected:<br />(No malicious items detected)<br /><br /><br /><br /><br />The Rooter log:<br /><br />Rooter.exe (v1.0.2) by Eric_71<br />.<br />SeDebugPrivilege granted successfully ...<br />.<br />Windows XP Home Edition (5.1.2600) Service Pack 3<br />[32_bits] - x86 Family 6 Model 10 Stepping 0, AuthenticAMD<br />.<br />[wscsvc] (Security Center) RUNNING (state:4)<br />[SharedAccess] RUNNING (state:4)<br />Windows Firewall -&gt; Enabled<br />.<br />Internet Explorer 8.0.6001.18702<br />Mozilla Firefox 3.6.7 (en-US)<br />.<br />C:&#092;  [Fixed-NTFS] .. ( Total:70 Go - Free:44 Go )<br />D:&#092;  [Fixed-FAT32] .. ( Total:3 Go - Free:1 Go )<br />E:&#092;  [CD_Rom]<br />F:&#092;  [CD_Rom]<br />G:&#092;  [Removable]<br />H:&#092;  [Removable]<br />I:&#092;  [Removable]<br />J:&#092;  [Removable]<br />K:&#092;  [Fixed-FAT32] .. ( Total:149 Go - Free:72 Go )<br />.<br />Scan : 19:06.29<br />Path : C:&#092;Documents and Settings&#092;Owner&#092;Desktop&#092;Rooter.exe<br />User : Owner ( Administrator -&gt; YES )<br />.<br />----------------------&#092;&#092; Processes<br />.<br />Locked [System Process] (0)<br />______ System (4)<br />______ &#092;SystemRoot&#092;System32&#092;smss.exe (560)<br />______ &#092;??&#092;C:&#092;WINDOWS&#092;system32&#092;csrss.exe (608)<br />______ &#092;??&#092;C:&#092;WINDOWS&#092;system32&#092;winlogon.exe (632)<br />______ C:&#092;WINDOWS&#092;system32&#092;services.exe (680)<br />______ C:&#092;WINDOWS&#092;system32&#092;lsass.exe (692)<br />______ C:&#092;WINDOWS&#092;system32&#092;Ati2evxx.exe (856)<br />______ C:&#092;WINDOWS&#092;system32&#092;svchost.exe (876)<br />______ C:&#092;WINDOWS&#092;system32&#092;svchost.exe (984)<br />______ C:&#092;WINDOWS&#092;System32&#092;svchost.exe (1084)<br />______ C:&#092;WINDOWS&#092;system32&#092;svchost.exe (1196)<br />______ C:&#092;WINDOWS&#092;system32&#092;svchost.exe (1360)<br />______ C:&#092;WINDOWS&#092;system32&#092;Ati2evxx.exe (1428)<br />______ C:&#092;WINDOWS&#092;Explorer.EXE (1516)<br />______ C:&#092;Program Files&#092;Alwil Software&#092;Avast5&#092;AvastSvc.exe (1656)<br />______ C:&#092;WINDOWS&#092;system32&#092;LEXBCES.EXE (1960)<br />______ C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe (1996)<br />______ C:&#092;WINDOWS&#092;system32&#092;LEXPPS.EXE (2044)<br />______ C:&#092;Program Files&#092;NVIDIA Corporation&#092;NvMixer&#092;NVMixerTray.exe (1040)<br />______ C:&#092;Program Files&#092;CyberLink&#092;PowerDVD&#092;PDVDServ.exe (1048)<br />______ C:&#092;Program Files&#092;Digital Media Reader&#092;shwiconem.exe (1060)<br />______ C:&#092;Program Files&#092;ATI Technologies&#092;ATI HYDRAVISION&#092;HydraDM.exe (1192)<br />______ C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe (1160)<br />______ C:&#092;Program Files&#092;Freecorder&#092;FLVSrvc.exe (1328)<br />______ C:&#092;PROGRA~1&#092;ALWILS~1&#092;Avast5&#092;avastUI.exe (968)<br />______ C:&#092;Program Files&#092;ATI Multimedia&#092;RemCtrl&#092;ATIRW.exe (1468)<br />______ C:&#092;Program Files&#092;AWS&#092;WeatherBug&#092;Weather.exe (1888)<br />______ C:&#092;WINDOWS&#092;system32&#092;svchost.exe (224)<br />______ C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe (228)<br />______ C:&#092;WINDOWS&#092;system32&#092;rundll32.exe (448)<br />______ C:&#092;Program Files&#092;Firebird&#092;Firebird_2_1&#092;bin&#092;fbguard.exe (2100)<br />______ C:&#092;Program Files&#092;Common Files&#092;New Boundary&#092;PrismXL&#092;PRISMXL.SYS (2468)<br />______ C:&#092;WINDOWS&#092;system32&#092;svchost.exe (2596)<br />______ C:&#092;Program Files&#092;Viewpoint&#092;Common&#092;ViewpointService.exe (2632)<br />______ C:&#092;Program Files&#092;Firebird&#092;Firebird_2_1&#092;bin&#092;fbserver.exe (3412)<br />______ C:&#092;WINDOWS&#092;System32&#092;alg.exe (3628)<br />______ C:&#092;Program Files&#092;Viewpoint&#092;Viewpoint Manager&#092;ViewMgr.exe (3924)<br />______ C:&#092;Documents and Settings&#092;Owner&#092;Local Settings&#092;Application Data&#092;Google&#092;Update&#092;1.2.183.29&#092;GoogleCrashHandler.exe (1296)<br />______ C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe (280)<br />______ C:&#092;WINDOWS&#092;notepad.exe (2788)<br />______ C:&#092;WINDOWS&#092;notepad.exe (4020)<br />______ C:&#092;Documents and Settings&#092;Owner&#092;Desktop&#092;Rooter.exe (2368)<br />.<br />----------------------&#092;&#092; Device&#092;Harddisk0&#092;<br />.<br />&#092;Device&#092;Harddisk0 [Sectors : 63 x 512 Bytes]<br />.<br />&#092;Device&#092;Harddisk0&#092;Partition1 --[ MBR ]-- (Start_Offset:3989260800 | Length:76034488320)<br />&#092;Device&#092;Harddisk0&#092;Partition2 (Start_Offset:32256 | Length:3989228544)<br />.<br />----------------------&#092;&#092; Scheduled Tasks<br />.<br />C:&#092;WINDOWS&#092;Tasks&#092;AppleSoftwareUpdate.job<br />C:&#092;WINDOWS&#092;Tasks&#092;desktop.ini<br />C:&#092;WINDOWS&#092;Tasks&#092;Google Software Updater.job<br />C:&#092;WINDOWS&#092;Tasks&#092;GoogleUpdateTaskMachineCore.job<br />C:&#092;WINDOWS&#092;Tasks&#092;GoogleUpdateTaskMachineUA.job<br />C:&#092;WINDOWS&#092;Tasks&#092;GoogleUpdateTaskUserS-1-5-21-2947025290-3301077733-503587302-1003Core.job<br />C:&#092;WINDOWS&#092;Tasks&#092;GoogleUpdateTaskUserS-1-5-21-2947025290-3301077733-503587302-1003UA.job<br />C:&#092;WINDOWS&#092;Tasks&#092;ISP signup reminder 1.job<br />C:&#092;WINDOWS&#092;Tasks&#092;ISP signup reminder 2.job<br />C:&#092;WINDOWS&#092;Tasks&#092;SA.DAT<br />.<br />----------------------&#092;&#092; Registry<br />.<br />.<br />----------------------&#092;&#092; Files & Folders<br />.<br />C:&#092;DOCUME~1&#092;Owner&#092;My Documents&#092;Apollo.WMV.ASF.ASX.To.DVD.Burner.v3.7.WinAll.Incl.KeyGen-EiTheL&#092;keygen.exe<br /><b>==&gt; Cracks & Keygens &lt;==</b><br />.<br />----------------------&#092;&#092; Scan completed at 19:06.46<br />.<br />C:&#092;Rooter$&#092;Rooter_1.txt - (25/07/2010 | 19:06.46).c<br /><br /><br /><br /><br />The Lock Search log:<br /><br />LockSearch by jpshortstuff (05.11.09.1)<br />Log created at 19:07 on 25/07/2010 (Owner)<br />Scanning C:&#092;<br /><br /><br />C:&#092;hiberfil.sys<br />-------------------------<br /><br /><br />C:&#092;pagefile.sys<br />-------------------------<br /><br />-=E.O.F=-<br /><br /><br /><br /><br />The CKScanner log:<br /><br />CKScanner - Additional Security Risks - These are not necessarily bad<br />c:&#092;documents and settings&#092;owner&#092;my documents&#092;apollo.wmv.asf.asx.to.dvd.burner.v3.7.winall.incl.keygen-eithel.zip<br />c:&#092;documents and settings&#092;owner&#092;my documents&#092;apollo.wmv.asf.asx.to.dvd.burner.v3.7.winall.incl.keygen-eithel&#092;eithel.nfo<br />c:&#092;documents and settings&#092;owner&#092;my documents&#092;apollo.wmv.asf.asx.to.dvd.burner.v3.7.winall.incl.keygen-eithel&#092;file_id.diz<br />c:&#092;documents and settings&#092;owner&#092;my documents&#092;apollo.wmv.asf.asx.to.dvd.burner.v3.7.winall.incl.keygen-eithel&#092;keygen.exe<br />c:&#092;documents and settings&#092;owner&#092;my documents&#092;sam.broadcaster.v4.2.2-yag&#092;crack&#092;serial.txt<br />scanner sequence 3.BC.11<br /> ----- EOF ----- <br /><br /><br /><br /><br />The WVCheck log:<br /><br />Windows Validation Check<br />Log Created On: 1912_25-07-2010<br />------------------------<br /><br />Windows Information<br />-----------------------<br />Windows Version: Windows XP Service Pack 3 <br />Windows Mode: Normal<br /><br /><br />WVCheck's Auto Update Check<br />-----------------------<br />Auto-Update Option: Download updates and install them automatically.<br />------------------------------<br />Last Success Time for Update Detection: 2010-07-22 16:52:54<br />Last Success Time for Update Download: 2010-07-14 12:00:07<br />Last Success Time for Update Installation: 2010-07-14 22:17:06<br /><br /><br />WVCheck's File Dump<br />-------------------<br />WVCheck found no known bad files.<br /><br /><br />WVCheck's Missing File Check<br />-------------------<br />WVCheck found no missing Windows files.<br /><br /><br />WVCheck's MBAM Quarantine Check<br />-------------------<br />There were no bad files quarantined by MBAM.<br /><br /><br />WVCheck's HOSTS File Check<br />-------------------<br />WVCheck found no bad lines in the hosts file.<br /><br /><br />WVCheck's MD5 Check<br />EXPERIMENTAL!!<br />-------------------<br />user32.dll - b26b135ff1b9f60c9388b4a7d16f600b<br /><br /><br />-------- End of File, program close at 1914_25-07-2010 --------<br /><br /><br /><br />And finally the GMER log:<br /><br />GMER 1.0.15.15281 - <a href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />Rootkit scan 2010-07-25 19:40:47<br />Windows 5.1.2600 Service Pack 3<br />Running: gmer.exe; Driver: C:&#092;DOCUME~1&#092;Owner&#092;LOCALS~1&#092;Temp&#092;kgxiqaoc.sys<br /><br /><br />---- System - GMER 1.0.15 ----<br /><br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwClose [0xAEE9ECD2]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwCreateKey [0xAEE9EB8E]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwDeleteKey [0xAEE9F142]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwDeleteValueKey [0xAEE9F06C]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwDuplicateObject [0xAEE9E764]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwOpenKey [0xAEE9EC68]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwOpenProcess [0xAEE9E6A4]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwOpenThread [0xAEE9E708]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwQueryValueKey [0xAEE9ED88]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwRenameKey [0xAEE9F210]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwRestoreKey [0xAEE9ED48]<br />SSDT            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwSetValueKey [0xAEE9EEC8]<br /><br />Code            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwCreateProcessEx [0xAEEABB9C]<br />Code            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwCreateSection [0xAEEAB9C0]<br />Code            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ZwLoadDriver [0xAEEABAFA]<br />Code            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               NtCreateSection<br />Code            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ObInsertObject<br />Code            &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)                                               ObMakeTemporaryObject<br /><br />---- Kernel code sections - GMER 1.0.15 ----<br /><br />PAGE            ntoskrnl.exe!ObInsertObject                                                                                                         8056503A 5 Bytes  JMP AEEA8F6C &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)<br />PAGE            ntoskrnl.exe!NtCreateSection                                                                                                        805652B3 7 Bytes  JMP AEEAB9C4 &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)<br />PAGE            ntoskrnl.exe!ZwCreateProcessEx                                                                                                      8057FE4C 7 Bytes  JMP AEEABBA0 &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)<br />PAGE            ntoskrnl.exe!ObMakeTemporaryObject                                                                                                  8059F8CA 5 Bytes  JMP AEEA75B4 &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)<br />PAGE            ntoskrnl.exe!ZwLoadDriver                                                                                                           805A3B73 7 Bytes  JMP AEEABAFE &#092;SystemRoot&#092;System32&#092;Drivers&#092;aswSP.SYS (avast! self protection module/ALWIL Software)<br />.rsrc           C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ql1240.sys                                                                                              entry point in ".rsrc" section [0xF7D53894]<br />init            C:&#092;WINDOWS&#092;system32&#092;drivers&#092;nvax.sys                                                                                                entry point in "init" section [0xF7409B8D]<br />init            C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;sunkfilt.sys                                                                                            entry point in "init" section [0xF802A300]<br /><br />---- User code sections - GMER 1.0.15 ----<br /><br />.text           C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe[280] ntdll.dll!NtProtectVirtualMemory                                                  7C90D6EE 5 Bytes  JMP 0132000A <br />.text           C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe[280] ntdll.dll!NtWriteVirtualMemory                                                    7C90DFAE 5 Bytes  JMP 0133000A <br />.text           C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe[280] ntdll.dll!KiUserExceptionDispatcher                                               7C90E47C 5 Bytes  JMP 0131000C <br />.text           C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe[280] ntdll.dll!LdrLoadDll                                                              7C9163C3 5 Bytes  JMP 004013F0 C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe (Firefox/Mozilla Corporation)<br />.text           C:&#092;WINDOWS&#092;System32&#092;svchost.exe[1084] ntdll.dll!NtProtectVirtualMemory                                                              7C90D6EE 5 Bytes  JMP 0092000A <br />.text           C:&#092;WINDOWS&#092;System32&#092;svchost.exe[1084] ntdll.dll!NtWriteVirtualMemory                                                                7C90DFAE 5 Bytes  JMP 0093000A <br />.text           C:&#092;WINDOWS&#092;System32&#092;svchost.exe[1084] ntdll.dll!KiUserExceptionDispatcher                                                           7C90E47C 5 Bytes  JMP 0091000C <br />.text           C:&#092;WINDOWS&#092;System32&#092;svchost.exe[1084] USER32.dll!GetCursorPos                                                                       7E42974E 5 Bytes  JMP 0088000A <br />.text           C:&#092;WINDOWS&#092;System32&#092;svchost.exe[1084] ole32.dll!CoCreateInstance                                                                    7750057E 3 Bytes  JMP 00DC000A <br />.text           C:&#092;WINDOWS&#092;System32&#092;svchost.exe[1084] ole32.dll!CoCreateInstance + 4                                                                77500582 1 Byte  [89]<br />.text           C:&#092;WINDOWS&#092;Explorer.EXE[1516] ntdll.dll!NtProtectVirtualMemory                                                                      7C90D6EE 5 Bytes  JMP 00B7000A <br />.text           C:&#092;WINDOWS&#092;Explorer.EXE[1516] ntdll.dll!NtWriteVirtualMemory                                                                        7C90DFAE 5 Bytes  JMP 00BD000A <br />.text           C:&#092;WINDOWS&#092;Explorer.EXE[1516] ntdll.dll!KiUserExceptionDispatcher                                                                   7C90E47C 5 Bytes  JMP 00B6000C <br /><br />---- Devices - GMER 1.0.15 ----<br /><br />Device          &#092;FileSystem&#092;Ntfs &#092;Ntfs                                                                                                              aswSP.SYS (avast! self protection module/ALWIL Software)<br /><br />AttachedDevice  &#092;FileSystem&#092;Ntfs &#092;Ntfs                                                                                                              aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)<br /><br />Device          &#092;FileSystem&#092;Fastfat &#092;FatCdrom                                                                                                       aswSP.SYS (avast! self protection module/ALWIL Software)<br /><br />AttachedDevice  &#092;Driver&#092;Tcpip &#092;Device&#092;Ip                                                                                                            aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)<br />AttachedDevice  &#092;Driver&#092;Tcpip &#092;Device&#092;Tcp                                                                                                           aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)<br />AttachedDevice  &#092;Driver&#092;Tcpip &#092;Device&#092;Udp                                                                                                           aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)<br />AttachedDevice  &#092;Driver&#092;Tcpip &#092;Device&#092;RawIp                                                                                                         aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)<br /><br />Device          &#092;FileSystem&#092;Fastfat &#092;Fat                                                                                                            aswSP.SYS (avast! self protection module/ALWIL Software)<br /><br />AttachedDevice  &#092;FileSystem&#092;Fastfat &#092;Fat                                                                                                            aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)<br />AttachedDevice  &#092;FileSystem&#092;Fastfat &#092;Fat                                                                                                            fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)<br /><br />Device           -&gt; &#092;Driver&#092;atapi &#092;Device&#092;Harddisk0&#092;DR0                                                                                             8348DEC5<br /><br />---- Registry - GMER 1.0.15 ----<br /><br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{47629D4B-2AD3-4e50-B716-A66C15C63153}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{47629D4B-2AD3-4e50-B716-A66C15C63153}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{47629D4B-2AD3-4e50-B716-A66C15C63153}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{47629D4B-2AD3-4e50-B716-A66C15C63153}&#092;InprocServer32@cd042efbbd7f7af1647644e76e06692b                  0xE2 0x63 0x26 0xF1 ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{604BB98A-A94F-4a5c-A67C-D8D3582C741C}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{604BB98A-A94F-4a5c-A67C-D8D3582C741C}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{604BB98A-A94F-4a5c-A67C-D8D3582C741C}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{604BB98A-A94F-4a5c-A67C-D8D3582C741C}&#092;InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b                  0x46 0x47 0x15 0xB0 ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{684373FB-9CD8-4e47-B990-5A4466C16034}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{684373FB-9CD8-4e47-B990-5A4466C16034}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{684373FB-9CD8-4e47-B990-5A4466C16034}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{684373FB-9CD8-4e47-B990-5A4466C16034}&#092;InprocServer32@2c81e34222e8052573023a60d06dd016                  0x25 0xDA 0xEC 0x7E ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{74554CCD-F60F-4708-AD98-D0152D08C8B9}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{74554CCD-F60F-4708-AD98-D0152D08C8B9}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{74554CCD-F60F-4708-AD98-D0152D08C8B9}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{74554CCD-F60F-4708-AD98-D0152D08C8B9}&#092;InprocServer32@2582ae41fb52324423be06337561aa48                  0x86 0x8C 0x21 0x01 ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{7EB537F9-A916-4339-B91B-DED8E83632C0}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{7EB537F9-A916-4339-B91B-DED8E83632C0}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{7EB537F9-A916-4339-B91B-DED8E83632C0}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{7EB537F9-A916-4339-B91B-DED8E83632C0}&#092;InprocServer32@caaeda5fd7a9ed7697d9686d4b818472                  0xCD 0x44 0xCD 0xB9 ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{948395E8-7A56-4fb1-843B-3E52D94DB145}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{948395E8-7A56-4fb1-843B-3E52D94DB145}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{948395E8-7A56-4fb1-843B-3E52D94DB145}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{948395E8-7A56-4fb1-843B-3E52D94DB145}&#092;InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d                  0xDF 0x20 0x58 0x62 ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}&#092;InprocServer32@4d370831d2c43cd13623e232fed27b7b                  0x31 0x77 0xE1 0xBA ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{DE5654CA-EB84-4df9-915B-37E957082D6D}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{DE5654CA-EB84-4df9-915B-37E957082D6D}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{DE5654CA-EB84-4df9-915B-37E957082D6D}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{DE5654CA-EB84-4df9-915B-37E957082D6D}&#092;InprocServer32@1d68fe701cdea33e477eb204b76f993d                  0x01 0x3A 0x48 0xFC ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{E39C35E8-7488-4926-92B2-2F94619AC1A5}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{E39C35E8-7488-4926-92B2-2F94619AC1A5}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{E39C35E8-7488-4926-92B2-2F94619AC1A5}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{E39C35E8-7488-4926-92B2-2F94619AC1A5}&#092;InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3                  0xF6 0x0F 0x4E 0x58 ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}&#092;InprocServer32@f5f62a6129303efb32fbe080bb27835b                  0x3D 0xCE 0xEA 0x26 ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}&#092;InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6                  0x2A 0xB7 0xCC 0xB5 ...<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}&#092;InprocServer32                                                   <br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}&#092;InprocServer32@ThreadingModel                                    Apartment<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}&#092;InprocServer32@                                                  C:&#092;WINDOWS&#092;system32&#092;OLE32.DLL<br />Reg             HKLM&#092;SOFTWARE&#092;Classes&#092;CLSID&#092;{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}&#092;InprocServer32@8a8aec57dd6508a385616fbc86791ec2                  0x6C 0x43 0x2D 0x1E ...<br />Reg             HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Shell Extensions&#092;Approved&#092;{95F092DC-FCE4-9AA5-40DE-843301A694E5}                     <br />Reg             HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Shell Extensions&#092;Approved&#092;{95F092DC-FCE4-9AA5-40DE-843301A694E5}@iaddgoccmndiilpkdb  0x6A 0x61 0x70 0x62 ...<br />Reg             HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Shell Extensions&#092;Approved&#092;{95F092DC-FCE4-9AA5-40DE-843301A694E5}@hajcmmnbgbhhpdcc    0x69 0x61 0x66 0x62 ...<br />Reg             HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Shell Extensions&#092;Approved&#092;{95F092DC-FCE4-9AA5-40DE-843301A694E5}@iapdnpkichhnjmebln  0x63 0x61 0x6F 0x62 ...<br /><br />---- Disk sectors - GMER 1.0.15 ----<br /><br />Disk            &#092;Device&#092;Harddisk0&#092;DR0                                                                                                               sector 60: copy of MBR<br /><br />---- Files - GMER 1.0.15 ----<br /><br />File            C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ql1240.sys                                                                                              suspicious modification<br />File            C:&#092;WINDOWS&#092;system32&#092;drivers&#092;atapi.sys                                                                                               suspicious modification<br /><br />---- EOF - GMER 1.0.15 ----<br /><br /><br /><br />]]></description>
		<pubDate>Sat, 24 Jul 2010 05:35:44 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=6072</guid>
	</item>
	<item>
		<title><![CDATA[Logs won't post]]></title>
		<link>http://www.atribune.org/forums/index.php?showtopic=6075</link>
		<description><![CDATA[I'm pasting logs from notepad.  The Post New and Preview buttons click through to Internet error page.  Any suggestions?  Thanks.  Blue<br /><br /><br />Just tried to post logs again.  Got this error/webpage:  Internet Explorer cannot display the webpage    What you can try: etc....<br /><br />Any ideas?<br />]]></description>
		<pubDate>Mon, 26 Jul 2010 00:44:30 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=6075</guid>
	</item>
	<item>
		<title>WSCNTFY is bugged, no exes</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=6068</link>
		<description><![CDATA[Today I was going across some websites, and must have accidentally downloaded something faulty. Bottom line is I can't do anything, no EXE's and it keeps bothering me to download anti-virus software. The interesting part is my computer is still runny fairly fast, however I have no idea what to do. I'm freaking out because I have a lot of data I do need to keep and restoring my computer is going to hinder me a few weeks trying to get back all that I would lose. I'll be glad to give more information but any help would be godly appreciated....<br /><br />-Max.]]></description>
		<pubDate>Tue, 06 Jul 2010 11:32:45 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=6068</guid>
	</item>
	<item>
		<title><![CDATA[Google searches redirect to ad websites[Re-Opened]]]></title>
		<link>http://www.atribune.org/forums/index.php?showtopic=6037</link>
		<description><![CDATA[Hello,<br /><br />My google search results lead to random websites with ads in them and I would appreciate any help you may be able to offer.<br /><br />I have followed all the instructions in the pinned thread "BEFORE YOU POST !!" except for Gmer, which would crash a few seconds after opening the file with the "gmer.exe has encountered a problem and needs to close" error. I tried renaming the file to 'test.exe' but still encountered the same problem.<br /><br />The other log files are pasted below in the following order: OTL's otl.txt then extras.txt; MBAM; Rooter; LockSearch; CKScanner.<br /><br />Thank you for your help!<br />The Leviathan<br /><br /><br /><br />===========================================================<br /><br /><br /><br /><br />OTL logfile created on: 5/9/2010 3:26:05 PM - Run 1<br />OTL by OldTimer - Version 3.2.4.1     Folder = C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop<br />Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />Internet Explorer (Version = 7.0.5730.13)<br />Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br /> <br />1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free<br />3.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free<br />Paging file location(s): C:&#092;pagefile.sys 2046 4092 [binary data]<br /> <br />%SystemDrive% = C: | %SystemRoot% = C:&#092;WINDOWS | %ProgramFiles% = C:&#092;Program Files<br />Drive C: | 19.13 Gb Total Space | 1.08 Gb Free Space | 5.63% Space Free | Partition Type: NTFS<br />Drive D: | 7.87 Gb Total Space | 0.99 Gb Free Space | 12.56% Space Free | Partition Type: NTFS<br />E: Drive not present or media not loaded<br />Drive F: | 465.76 Gb Total Space | 303.47 Gb Free Space | 65.16% Space Free | Partition Type: NTFS<br />G: Drive not present or media not loaded<br />H: Drive not present or media not loaded<br />Drive I: | 3.90 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS<br />Drive L: | 149.05 Gb Total Space | 1.48 Gb Free Space | 0.99% Space Free | Partition Type: NTFS<br />Drive M: | 74.53 Gb Total Space | 2.37 Gb Free Space | 3.18% Space Free | Partition Type: NTFS<br />Drive P: | 149.04 Gb Total Space | 4.47 Gb Free Space | 3.00% Space Free | Partition Type: NTFS<br /> <br />Computer Name: TheLeviathan<br />Current User Name: TheLeviathan<br />Logged in as Administrator.<br /> <br />Current Boot Mode: Normal<br />Scan Mode: Current user<br />Company Name Whitelist: On<br />Skip Microsoft Files: On<br />File Age = 90 Days<br />Output = Standard<br />Quick Scan<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Processes (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />PRC - [2010/05/09 15:24:43 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;OTL.exe<br />PRC - [2010/05/07 03:26:00 | 001,285,864 | ---- | M] (Lavasoft) -- C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe<br />PRC - [2010/05/07 03:26:00 | 000,834,248 | ---- | M] (Lavasoft) -- C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWTray.exe<br />PRC - [2010/03/21 21:30:02 | 002,909,696 | ---- | M] (SoftPerfect Research) -- C:&#092;Program Files&#092;NetWorx&#092;networx.exe<br />PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:&#092;Program Files&#092;Spybot - Search & Destroy&#092;TeaTimer.exe<br />PRC - [2008/11/24 04:51:57 | 000,181,312 | ---- | M] () -- C:&#092;Program Files&#092;Photodex&#092;ProShowGold&#092;scsiaccess.exe<br />PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:&#092;WINDOWS&#092;explorer.exe<br />PRC - [2005/11/15 14:28:04 | 000,085,744 | ---- | M] (Symantec Corporation) -- C:&#092;Program Files&#092;Symantec AntiVirus&#092;VPTray.exe<br />PRC - [2005/11/15 14:27:54 | 001,756,912 | ---- | M] (Symantec Corporation) -- C:&#092;Program Files&#092;Symantec AntiVirus&#092;Rtvscan.exe<br />PRC - [2005/11/15 14:27:44 | 000,020,208 | ---- | M] (Symantec Corporation) -- C:&#092;Program Files&#092;Symantec AntiVirus&#092;DefWatch.exe<br />PRC - [2005/10/04 13:42:50 | 000,177,776 | ---- | M] (Symantec Corporation) -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccSetMgr.exe<br />PRC - [2005/10/04 13:42:42 | 000,185,968 | ---- | M] (Symantec Corporation) -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccEvtMgr.exe<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Modules (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />MOD - [2010/05/09 15:24:43 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;OTL.exe<br />MOD - [2008/04/13 20:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:&#092;WINDOWS&#092;system32&#092;msscript.ocx<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Win32 Services (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />SRV - [2010/05/07 03:26:00 | 001,285,864 | ---- | M] (Lavasoft) [Auto | Running] -- C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe -- (Lavasoft Ad-Aware Service)<br />SRV - [2008/11/24 04:51:57 | 000,181,312 | ---- | M] () [Auto | Running] -- C:&#092;Program Files&#092;Photodex&#092;ProShowGold&#092;scsiaccess.exe -- (ScsiAccess)<br />SRV - [2008/11/23 12:29:10 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:&#092;Program Files&#092;Common Files&#092;Macrovision Shared&#092;FLEXnet Publisher&#092;FNPLicensingService.exe -- (FLEXnet Licensing Service)<br />SRV - [2005/11/15 14:27:56 | 000,169,200 | ---- | M] (symantec) [On_Demand | Stopped] -- C:&#092;Program Files&#092;Symantec AntiVirus&#092;SavRoam.exe -- (SavRoam)<br />SRV - [2005/11/15 14:27:54 | 001,756,912 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:&#092;Program Files&#092;Symantec AntiVirus&#092;Rtvscan.exe -- (Symantec AntiVirus)<br />SRV - [2005/11/15 14:27:44 | 000,020,208 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:&#092;Program Files&#092;Symantec AntiVirus&#092;DefWatch.exe -- (DefWatch)<br />SRV - [2005/10/19 18:39:34 | 000,214,672 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;SNDSrvc.exe -- (SNDSrvc)<br />SRV - [2005/10/04 13:42:50 | 000,177,776 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccSetMgr.exe -- (ccSetMgr)<br />SRV - [2005/10/04 13:42:48 | 000,083,568 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccPwdSvc.exe -- (ccPwdSvc)<br />SRV - [2005/10/04 13:42:42 | 000,185,968 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccEvtMgr.exe -- (ccEvtMgr)<br />SRV - [2005/03/30 22:48:22 | 000,992,864 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;SPBBC&#092;SPBBCSvc.exe -- (SPBBCSvc)<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Driver Services (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />DRV - [2010/03/28 22:57:46 | 000,038,976 | ---- | M] (microOLAP Technologies LTD) [Kernel | System | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;pssdk42.sys -- (PSSDK42)<br />DRV - [2010/02/16 05:00:00 | 001,324,720 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;VirusDefs&#092;20100508.003&#092;NAVEX15.SYS -- (NAVEX15)<br />DRV - [2010/02/16 05:00:00 | 000,084,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;VirusDefs&#092;20100508.003&#092;NAVENG.SYS -- (NAVENG)<br />DRV - [2010/02/04 11:53:02 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;Lbd.sys -- (Lbd)<br />DRV - [2009/11/20 16:26:50 | 000,025,984 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;tap0901.sys -- (tap0901)<br />DRV - [2009/11/16 11:11:12 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;EENGINE&#092;eeCtrl.sys -- (eeCtrl)<br />DRV - [2009/11/16 11:11:12 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;EENGINE&#092;EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)<br />DRV - [2008/04/13 14:45:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;gameenum.sys -- (gameenum)<br />DRV - [2008/04/13 13:45:32 | 000,059,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;GcKernel.sys -- (GcKernel)<br />DRV - [2007/11/20 18:35:48 | 000,049,792 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ser2pl.sys -- (Ser2pl)<br />DRV - [2007/04/18 09:59:40 | 000,098,600 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;COMMONFX.DLL -- (COMMONFX.DLL)<br />DRV - [2007/04/16 22:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;AmdPPM.sys -- (AmdPPM)<br />DRV - [2007/04/12 09:10:26 | 000,164,608 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;CT20XUT.DLL -- (CT20XUT.DLL)<br />DRV - [2007/04/12 09:10:26 | 000,066,816 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;CTHWIUT.DLL -- (CTHWIUT.DLL)<br />DRV - [2007/04/12 09:10:24 | 001,317,632 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;CTEXFIFX.DLL -- (CTEXFIFX.DLL)<br />DRV - [2007/04/12 09:10:22 | 000,323,328 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;CTEDSPSY.DLL -- (CTEDSPSY.DLL)<br />DRV - [2007/04/12 09:10:22 | 000,128,768 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;CTEDSPIO.DLL -- (CTEDSPIO.DLL)<br />DRV - [2007/04/12 09:10:20 | 000,280,320 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;CTEDSPFX.DLL -- (CTEDSPFX.DLL)<br />DRV - [2007/04/12 09:10:20 | 000,094,976 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;CTERFXFX.DLL -- (CTERFXFX.DLL)<br />DRV - [2007/04/12 09:10:18 | 000,168,192 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;CTEAPSFX.DLL -- (CTEAPSFX.DLL)<br />DRV - [2007/04/12 09:10:16 | 000,560,384 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;CTSBLFX.DLL -- (CTSBLFX.DLL)<br />DRV - [2007/04/12 09:10:16 | 000,546,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;CTAUDFX.DLL -- (CTAUDFX.DLL)<br />DRV - [2007/04/10 07:00:24 | 000,157,480 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ctsfm2k.sys -- (ctsfm2k)<br />DRV - [2007/04/10 06:59:04 | 000,126,760 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ctoss2k.sys -- (ossrv)<br />DRV - [2007/04/10 05:32:06 | 000,189,736 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;haP17v2k.sys -- (hap17v2k)<br />DRV - [2007/04/10 05:31:18 | 000,163,112 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;haP16v2k.sys -- (hap16v2k)<br />DRV - [2007/04/10 05:29:10 | 000,797,992 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ha10kx2k.sys -- (ha10kx2k)<br />DRV - [2007/04/10 05:28:36 | 000,092,968 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;emupia2k.sys -- (emupia)<br />DRV - [2007/04/10 05:25:46 | 000,014,632 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ctprxy2k.sys -- (ctprxy2k)<br />DRV - [2007/04/10 05:21:06 | 000,347,128 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ctdvda2k.sys -- (ctdvda2k)<br />DRV - [2007/04/10 05:20:38 | 000,520,488 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)<br />DRV - [2007/04/10 05:19:30 | 000,511,272 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ctac32k.sys -- (ctac32k)<br />DRV - [2006/10/22 13:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;nv4_mini.sys -- (nv)<br />DRV - [2005/10/19 18:39:04 | 000,195,728 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;SYMTDI.SYS -- (SYMTDI)<br />DRV - [2005/10/19 18:38:58 | 000,024,720 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;SYMREDRV.SYS -- (SYMREDRV)<br />DRV - [2005/09/17 01:20:06 | 000,108,168 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:&#092;Program Files&#092;Symantec&#092;SYMEVENT.SYS -- (SymEvent)<br />DRV - [2005/08/26 15:22:50 | 000,053,896 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:&#092;Program Files&#092;Symantec AntiVirus&#092;Savrtpel.sys -- (SAVRTPEL)<br />DRV - [2005/08/26 15:22:48 | 000,334,984 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:&#092;Program Files&#092;Symantec AntiVirus&#092;savrt.sys -- (SAVRT)<br />DRV - [2005/03/30 22:48:20 | 000,372,832 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;SPBBC&#092;SPBBCDrv.sys -- (SPBBCDrv)<br />DRV - [2004/08/22 17:31:48 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;d347prt.sys -- (d347prt)<br />DRV - [2004/08/22 17:31:10 | 000,155,136 | ---- | M] ( ) [Kernel | Boot | Running] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;d347bus.sys -- (d347bus)<br />DRV - [2003/10/30 23:22:38 | 000,077,312 | R--- | M] (VIA Technologies inc,.ltd) [Kernel | Boot | Running] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;viasraid.sys -- (viasraid)<br />DRV - [2001/08/17 14:02:50 | 000,002,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;HIDSwvd.sys -- (HIDSwvd)<br />DRV - [2001/08/17 14:02:32 | 000,008,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;hidgame.sys -- (hidgame)<br />DRV - [2001/08/17 10:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;msmpu401.sys -- (ms_mpu401)<br />DRV - [2001/08/17 09:28:02 | 000,907,456 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;HCF_MSFT.sys -- (HCF_MSFT)<br />DRV - [2001/08/17 08:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;el90xbc5.sys -- (EL90XBC)<br />DRV - [2001/07/30 11:34:28 | 000,585,840 | ---- | M] (Conexant Systems) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;HSF_CNXT.sys -- (winachsf)<br />DRV - [2001/07/16 12:17:30 | 000,076,610 | ---- | M] (Conexant Systems) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;basic2.sys -- (basic2)<br />DRV - [2001/07/16 12:16:58 | 000,539,917 | ---- | M] (Conexant Systems) [Kernel | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;v124nt.sys -- (V124)<br />DRV - [2001/07/15 19:05:54 | 000,067,222 | ---- | M] (Conexant Systems) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;rksample.sys -- (Rksample)<br />DRV - [2001/07/03 18:42:30 | 000,017,776 | ---- | M] (Conexant Systems) [Kernel | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;cnxtdiag.sys -- (Cnxtdiag)<br />DRV - [2001/06/24 18:16:36 | 000,427,215 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;k56nt.sys -- (K56)<br />DRV - [2001/06/24 18:16:08 | 000,124,189 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;fsksnt.sys -- (Fsks)<br />DRV - [2001/06/24 18:15:20 | 000,215,195 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;faxnt.sys -- (SoftFax)<br />DRV - [2001/06/24 18:14:18 | 000,059,375 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;tonesnt.sys -- (Tones)<br />DRV - [2001/06/24 18:13:56 | 000,308,403 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;fallback.sys -- (Fallback)<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Standard Registry (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Internet Explorer ==========<!--colorc--></span><!--/colorc--><br /> <br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page = %SystemRoot%&#092;system32&#092;blank.htm<br /> <br />IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://shop.thefreevpn.com/home.php" target="_blank">http://shop.thefreevpn.com/home.php</a><br />IE - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings: "ProxyEnable" = 0<br />IE - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings: "ProxyOverride" = &lt;local&gt;<br />IE - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings: "ProxyServer" = http=127.0.0.1:5555<br /> <br /> <br /> <br />O1 HOSTS File: ([2010/05/06 02:49:50 | 000,393,109 | R--- | M]) - C:&#092;WINDOWS&#092;system32&#092;drivers&#092;etc&#092;hosts<br />O1 - Hosts: 127.0.0.1       localhost<br />O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com<br />O1 - Hosts: 127.0.0.1	www.007guard.com<br />O1 - Hosts: 127.0.0.1	007guard.com<br />O1 - Hosts: 127.0.0.1	008i.com<br />O1 - Hosts: 127.0.0.1	www.008k.com<br />O1 - Hosts: 127.0.0.1	008k.com<br />O1 - Hosts: 127.0.0.1	www.00hq.com<br />O1 - Hosts: 127.0.0.1	00hq.com<br />O1 - Hosts: 127.0.0.1	010402.com<br />O1 - Hosts: 127.0.0.1	www.032439.com<br />O1 - Hosts: 127.0.0.1	032439.com<br />O1 - Hosts: 127.0.0.1	www.0scan.com<br />O1 - Hosts: 127.0.0.1	0scan.com<br />O1 - Hosts: 127.0.0.1	1000gratisproben.com<br />O1 - Hosts: 127.0.0.1	www.1000gratisproben.com<br />O1 - Hosts: 127.0.0.1	1001namen.com<br />O1 - Hosts: 127.0.0.1	www.1001namen.com<br />O1 - Hosts: 127.0.0.1	100888290cs.com<br />O1 - Hosts: 127.0.0.1	www.100888290cs.com<br />O1 - Hosts: 127.0.0.1	www.100sexlinks.com<br />O1 - Hosts: 127.0.0.1	100sexlinks.com<br />O1 - Hosts: 127.0.0.1	10sek.com<br />O1 - Hosts: 127.0.0.1	www.10sek.com<br />O1 - Hosts: 127.0.0.1	www.1-2005-search.com<br />O1 - Hosts: 13577 more lines...<br />O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:&#092;Program Files&#092;Orbitdownloader&#092;orbitcth.dll (Orbitdownloader.com)<br />O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Adobe&#092;Acrobat 7.0&#092;ActiveX&#092;AcroIEHelper.dll (Adobe Systems Incorporated)<br />O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:&#092;Program Files&#092;Spybot - Search & Destroy&#092;SDHelper.dll (Safer Networking Limited)<br />O3 - HKLM&#092;..&#092;Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:&#092;Program Files&#092;Orbitdownloader&#092;GrabPro.dll ()<br />O3 - HKCU&#092;..&#092;Toolbar&#092;WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:&#092;Program Files&#092;Orbitdownloader&#092;GrabPro.dll ()<br />O4 - HKLM..&#092;Run: [BlackBerryAutoUpdate] C:&#092;Program Files&#092;Common Files&#092;Research In Motion&#092;Auto Update&#092;RIMAutoUpdate.exe (Research In Motion Limited)<br />O4 - HKLM..&#092;Run: [NetWorx] C:&#092;Program Files&#092;NetWorx&#092;networx.exe (SoftPerfect Research)<br />O4 - HKLM..&#092;Run: [NvCplDaemon] C:&#092;WINDOWS&#092;System32&#092;NvCpl.DLL (NVIDIA Corporation)<br />O4 - HKLM..&#092;Run: [vptray] C:&#092;Program Files&#092;Symantec AntiVirus&#092;VPTray.exe (Symantec Corporation)<br />O4 - HKCU..&#092;Run: [SpybotSD TeaTimer] C:&#092;Program Files&#092;Spybot - Search & Destroy&#092;TeaTimer.exe (Safer-Networking Ltd.)<br />O7 - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;Explorer: NoDriveTypeAutoRun = 145<br />O8 - Extra context menu item: &Download by Orbit - C:&#092;Program Files&#092;Orbitdownloader&#092;orbitmxt.dll (Orbitdownloader.com)<br />O8 - Extra context menu item: &Grab video by Orbit - C:&#092;Program Files&#092;Orbitdownloader&#092;orbitmxt.dll (Orbitdownloader.com)<br />O8 - Extra context menu item: Do&wnload selected by Orbit - C:&#092;Program Files&#092;Orbitdownloader&#092;orbitmxt.dll (Orbitdownloader.com)<br />O8 - Extra context menu item: Down&load all by Orbit - C:&#092;Program Files&#092;Orbitdownloader&#092;orbitmxt.dll (Orbitdownloader.com)<br />O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:&#092;Program Files&#092;Spybot - Search & Destroy&#092;SDHelper.dll (Safer Networking Limited)<br />O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe File not found<br />O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe File not found<br />O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} <a href="http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab" target="_blank">http://download.macromedia.com/pub/shockwa...director/sw.cab</a> (Shockwave ActiveX Control)<br />O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227441747655" target="_blank">http://update.microsoft.com/windowsupdate/...b?1227441747655</a> (WUWebControl Class)<br />O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227451822000" target="_blank">http://update.microsoft.com/microsoftupdat...b?1227451822000</a> (MUWebControl Class)<br />O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab</a> (Java Plug-in 1.6.0_20)<br />O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab</a> (Java Plug-in 1.6.0_20)<br />O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab</a> (Java Plug-in 1.6.0_20)<br />O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} <a href="http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab" target="_blank">http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab</a> (RIM AxLoader)<br />O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a> (Reg Error: Key error.)<br />O17 - HKLM&#092;System&#092;CCS&#092;Services&#092;Tcpip&#092;Parameters: DhcpNameServer = 192.168.2.1<br />O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:&#092;WINDOWS&#092;explorer.exe (Microsoft Corporation)<br />O20 - Winlogon&#092;Notify&#092;NavLogon: DllName - C:&#092;WINDOWS&#092;system32&#092;NavLogon.dll - C:&#092;WINDOWS&#092;system32&#092;NavLogon.dll (Symantec Corporation)<br />O24 - Desktop BackupWallPaper: C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;Microsoft&#092;Wallpaper1.bmp<br />O32 - HKLM CDRom: AutoRun - 1<br />O32 - AutoRun File - [2008/11/23 07:33:13 | 000,000,000 | ---- | M] () - C:&#092;AUTOEXEC.BAT -- [ NTFS ]<br />O33 - MountPoints2&#092;{71ef8876-23e8-11df-9865-0050da29b0ad}&#092;Shell&#092;AutoRun&#092;command - "" = J:&#092;slacker.synclauncher.exe -- File not found<br />O33 - MountPoints2&#092;{71ef8876-23e8-11df-9865-0050da29b0ad}&#092;Shell&#092;slacker&#092;command - "" = J:&#092;slacker.synclauncher.exe -- File not found<br />O34 - HKLM BootExecute: (autocheck autochk *) -  File not found<br />O34 - HKLM BootExecute: (lsdelete) - C:&#092;WINDOWS&#092;System32&#092;lsdelete.exe ()<br />O35 - HKLM&#092;..comfile [open] -- "%1" %*<br />O35 - HKLM&#092;..exefile [open] -- "%1" %*<br />O37 - HKLM&#092;...com [@ = comfile] -- "%1" %*<br />O37 - HKLM&#092;...exe [@ = exefile] -- "%1" %*<br /> <br />NetSvcs: 6to4 -  File not found<br />NetSvcs: Ias - C:&#092;WINDOWS&#092;system32&#092;ias [2008/11/23 02:15:11 | 000,000,000 | ---D | M]<br />NetSvcs: Iprip -  File not found<br />NetSvcs: Irmon -  File not found<br />NetSvcs: NWCWorkstation -  File not found<br />NetSvcs: Nwsapagent -  File not found<br />NetSvcs: WmdmPmSp -  File not found<br /> <br />MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk - C:&#092;Program Files&#092;Adobe&#092;Acrobat 7.0&#092;Reader&#092;reader_sl.exe - (Adobe Systems Incorporated)<br />MsConfig - StartUpReg: <b>Adobe Photo Downloader</b> - hkey= - key= - C:&#092;Program Files&#092;Adobe&#092;Photoshop Elements 6.0&#092;apdproxy.exe File not found<br />MsConfig - StartUpReg: <b>ccApp</b> - hkey= - key= - C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccApp.exe (Symantec Corporation)<br />MsConfig - StartUpReg: <b>chkeilor</b> - hkey= - key= - C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;mejrju&#092;qgqisysguard.exe File not found<br />MsConfig - StartUpReg: <b>ctfmon.exe</b> - hkey= - key= -  File not found<br />MsConfig - StartUpReg: <b>CTHelper</b> - hkey= - key= -  File not found<br />MsConfig - StartUpReg: <b>CTxfiHlp</b> - hkey= - key= -  File not found<br />MsConfig - StartUpReg: <b>DivXUpdate</b> - hkey= - key= - C:&#092;Program Files&#092;DivX&#092;DivX Update&#092;DivXUpdate.exe ()<br />MsConfig - StartUpReg: <b>MSMSGS</b> - hkey= - key= - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe File not found<br />MsConfig - StartUpReg: <b>NvCplDaemon</b> - hkey= - key= -  File not found<br />MsConfig - StartUpReg: <b>NvMediaCenter</b> - hkey= - key= -  File not found<br />MsConfig - StartUpReg: <b>nwiz</b> - hkey= - key= -  File not found<br />MsConfig - StartUpReg: <b>pqxduivu</b> - hkey= - key= - C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;cuykgf&#092;ocsnsysguard.exe File not found<br />MsConfig - StartUpReg: <b>QuickTime Task</b> - hkey= - key= - C:&#092;Program Files&#092;QuickTime&#092;qttask.exe (Apple Computer, Inc.)<br />MsConfig - StartUpReg: <b>ypetnpgj</b> - hkey= - key= - C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;nxemvp&#092;qvnhsysguard.exe File not found<br />MsConfig - State: "system.ini" - 0<br />MsConfig - State: "win.ini" - 0<br />MsConfig - State: "bootini" - 0<br />MsConfig - State: "services" - 0<br />MsConfig - State: "startup" - 2<br /> <br />SafeBootMin: Base - Driver Group<br />SafeBootMin: Boot Bus Extender - Driver Group<br />SafeBootMin: Boot file system - Driver Group<br />SafeBootMin: File system - Driver Group<br />SafeBootMin: Filter - Driver Group<br />SafeBootMin: Lavasoft Ad-Aware Service - C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe (Lavasoft)<br />SafeBootMin: PCI Configuration - Driver Group<br />SafeBootMin: PNP Filter - Driver Group<br />SafeBootMin: Primary disk - Driver Group<br />SafeBootMin: SCSI Class - Driver Group<br />SafeBootMin: sermouse.sys - Driver<br />SafeBootMin: System Bus Extender - Driver Group<br />SafeBootMin: vds - Service<br />SafeBootMin: vga.sys - Driver<br />SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers<br />SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive<br />SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive<br />SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller<br />SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc<br />SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard<br />SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse<br />SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters<br />SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter<br />SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System<br />SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive<br />SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy<br />SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume<br />SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices<br /> <br />SafeBootNet: Base - Driver Group<br />SafeBootNet: Boot Bus Extender - Driver Group<br />SafeBootNet: Boot file system - Driver Group<br />SafeBootNet: File system - Driver Group<br />SafeBootNet: Filter - Driver Group<br />SafeBootNet: Lavasoft Ad-Aware Service - C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe (Lavasoft)<br />SafeBootNet: NDIS Wrapper - Driver Group<br />SafeBootNet: NetBIOSGroup - Driver Group<br />SafeBootNet: NetDDEGroup - Driver Group<br />SafeBootNet: Network - Driver Group<br />SafeBootNet: NetworkProvider - Driver Group<br />SafeBootNet: PCI Configuration - Driver Group<br />SafeBootNet: PNP Filter - Driver Group<br />SafeBootNet: PNP_TDI - Driver Group<br />SafeBootNet: Primary disk - Driver Group<br />SafeBootNet: rdpdd.sys - C:&#092;WINDOWS&#092;system32&#092;rdpdd.cpo ()<br />SafeBootNet: SCSI Class - Driver Group<br />SafeBootNet: sermouse.sys - Driver<br />SafeBootNet: Streams Drivers - Driver Group<br />SafeBootNet: System Bus Extender - Driver Group<br />SafeBootNet: TDI - Driver Group<br />SafeBootNet: UploadMgr - Service<br />SafeBootNet: vga.sys - Driver<br />SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers<br />SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive<br />SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive<br />SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller<br />SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc<br />SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard<br />SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse<br />SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net<br />SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient<br />SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService<br />SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans<br />SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters<br />SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter<br />SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System<br />SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive<br />SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume<br />SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices<br /> <br />ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)<br />ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)<br />ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow<br />ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4<br />ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation<br />ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%&#092;system32&#092;regsvr32.exe /s /n /i:/UserInstall %SystemRoot%&#092;system32&#092;themeui.dll<br />ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java<br />ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack<br />ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe<br />ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring<br />ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%&#092;Outlook Express&#092;setup50.exe" /APP:OE /CALLER:WINNT /user /install<br />ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:&#092;WINDOWS&#092;INF&#092;msnetmtg.inf,NetMtg.Install.PerUser.NT<br />ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow<br />ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx<br />ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help<br />ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes<br />ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6<br />ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Security Update for Windows XP (KB923789)<br />ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:&#092;WINDOWS&#092;INF&#092;msmsgs.inf,BLC.QuietInstall.PerUser<br />ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW<br />ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools<br />ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements<br />ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player<br />ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access<br />ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders<br />ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%&#092;Outlook Express&#092;setup50.exe" /APP:WAB /CALLER:WINNT /user /install<br />ActiveX: {77D921A1-8271-E407-E91A-B868F2F1B700} - NetShow<br />ActiveX: {7B4B3D63-E7C6-1DE0-43E6-F2973C88CCC7} - IE7 Uninstall Stub<br />ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll<br />ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:&#092;WINDOWS&#092;system32&#092;ie4uinit.exe -BaseSettings<br />ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:&#092;WINDOWS&#092;system32&#092;Rundll32.exe C:&#092;WINDOWS&#092;system32&#092;mscories.dll,Install<br />ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding<br />ActiveX: {AE6FCF2B-21B5-088B-2F0E-CCAE5A9C4349} - Browser Customizations<br />ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework<br />ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts<br />ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler<br />ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1<br />ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player<br />ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help<br />ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface<br />ActiveX: &lt;{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:&#092;WINDOWS&#092;system32&#092;ieudinit.exe<br />ActiveX: &gt;{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:&#092;WINDOWS&#092;inf&#092;unregmp2.exe /ShowWMP<br />ActiveX: &gt;{26923b43-4d38-484f-9b9e-de460746276c} - C:&#092;WINDOWS&#092;system32&#092;ie4uinit.exe -UserIconConfig<br />ActiveX: &gt;{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP<br />ActiveX: &gt;{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP<br />ActiveX: &gt;{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%&#092;system32&#092;shmgrate.exe OCInstallUserConfigOE<br /> <br />Drivers32: msacm.iac2 - C:&#092;WINDOWS&#092;system32&#092;iac25_32.ax (Intel Corporation)<br />Drivers32: msacm.l3acm - C:&#092;WINDOWS&#092;system32&#092;l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)<br />Drivers32: msacm.sl_anet - C:&#092;WINDOWS&#092;System32&#092;sl_anet.acm (Sipro Lab Telecom Inc.)<br />Drivers32: msacm.trspch - C:&#092;WINDOWS&#092;System32&#092;tssoft32.acm (DSP GROUP, INC.)<br />Drivers32: vidc.cvid - C:&#092;WINDOWS&#092;System32&#092;iccvid.dll (Radius Inc.)<br />Drivers32: vidc.iv31 - C:&#092;WINDOWS&#092;System32&#092;ir32_32.dll ()<br />Drivers32: vidc.iv32 - C:&#092;WINDOWS&#092;System32&#092;ir32_32.dll ()<br />Drivers32: vidc.iv41 - C:&#092;WINDOWS&#092;System32&#092;ir41_32.ax (Intel Corporation)<br />Drivers32: vidc.iv50 - C:&#092;WINDOWS&#092;System32&#092;ir50_32.dll (Intel Corporation)<br /> <br />CREATERESTOREPOINT<br />Restore point Set: OTL Restore Point (17465059307421696)<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Files/Folders - Created Within 90 Days ==========<!--colorc--></span><!--/colorc--><br /> <br />[2010/05/09 15:24:42 | 000,570,880 | ---- | C] (OldTimer Tools) -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;OTL.exe<br />[2010/05/09 02:02:44 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Malwarebytes<br />[2010/05/09 02:02:34 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;mbamswissarmy.sys<br />[2010/05/09 02:02:33 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;Malwarebytes<br />[2010/05/09 02:02:32 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;mbam.sys<br />[2010/05/09 02:02:32 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;Malwarebytes' Anti-Malware<br />[2010/05/09 01:46:59 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Malware removal<br />[2010/05/09 01:46:22 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;NetworkService&#092;Application Data&#092;Identities<br />[2010/05/07 03:26:44 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;Lbd.sys<br />[2010/05/07 03:26:43 | 000,000,000 | ---D | C] -- C:&#092;WINDOWS&#092;System32&#092;DRVSTORE<br />[2010/05/07 03:26:35 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;SBREDrv.sys<br />[2010/05/07 03:24:42 | 000,000,000 | -H-D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}<br />[2010/05/07 03:24:10 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;Lavasoft<br />[2010/05/07 03:24:10 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;Lavasoft<br />[2010/05/06 02:02:02 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;Spybot - Search & Destroy<br />[2010/05/06 02:02:02 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;Spybot - Search & Destroy<br />[2010/05/05 00:01:46 | 000,156,672 | ---- | C] (Radioactive) -- C:&#092;WINDOWS&#092;System32&#092;rmc_fixasf.exe<br />[2010/05/05 00:01:39 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;mdnslib<br />[2010/05/04 23:59:38 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;FLVService<br />[2010/05/04 23:59:32 | 000,000,000 | ---D | C] -- C:&#092;WINDOWS&#092;Replay Media Catcher<br />[2010/05/04 23:46:44 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;DonationCoder<br />[2010/05/04 23:36:43 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;Orbitdownloader<br />[2010/05/04 22:15:22 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;NetworkService&#092;Application Data&#092;Macromedia<br />[2010/05/04 21:16:32 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;NetworkService&#092;Application Data&#092;Adobe<br />[2010/05/01 03:24:04 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Return<br />[2010/05/01 00:10:03 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;FreeVPN<br />[2010/04/25 16:18:10 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Bills<br />[2010/04/25 01:20:53 | 000,000,000 | ---D | C] -- C:&#092;WINDOWS&#092;Sun<br />[2010/04/25 01:20:47 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;Sun<br />[2010/04/25 01:20:44 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;Common Files&#092;Java<br />[2010/04/25 01:20:00 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;Java<br />[2010/04/25 01:19:20 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun<br />[2010/04/18 22:31:43 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;Common Files&#092;DivX Shared<br />[2010/04/18 22:31:20 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;DivX<br />[2010/04/18 22:30:22 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;DivX<br />[2010/04/16 02:59:37 | 000,000,000 | ---D | C] -- C:&#092;WINDOWS&#092;System32&#092;Adobe<br />[2010/04/10 17:24:58 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Orbit Downloads<br />[2010/04/10 17:20:10 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;GrabPro<br />[2010/04/10 17:20:07 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Orbit<br />[2010/03/30 21:58:24 | 000,353,592 | ---- | C] (DivX, Inc.) -- C:&#092;WINDOWS&#092;System32&#092;DivXControlPanelApplet.cpl<br />[2010/03/28 22:57:46 | 000,038,976 | ---- | C] (microOLAP Technologies LTD) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;pssdk42.sys<br />[2010/03/28 22:57:45 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;SoftPerfect<br />[2010/03/28 22:57:45 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;NetWorx<br />[2010/03/28 22:21:34 | 000,025,984 | ---- | C] (The OpenVPN Project) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;tap0901.sys<br />[2010/03/26 00:34:18 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;youtube<br />[2010/03/25 21:01:42 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;BB backup<br />[2010/02/22 00:04:29 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;DELL<br />[2010/02/21 23:55:51 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;Deployment<br />[2010/02/17 15:54:53 | 000,000,000 | ---D | C] -- C:&#092;WINDOWS&#092;System32&#092;appmgmt<br />[2010/02/15 09:48:00 | 000,000,000 | RH-D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Recent<br />[2010/02/15 09:41:13 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;eXpress TimeStamp Toucher<br />[2010/02/14 02:28:14 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;DeviantART<br />[2010/02/13 19:23:28 | 000,000,000 | ---D | C] -- C:&#092;Program Files&#092;Microsoft Silverlight<br />[2010/02/10 04:04:49 | 000,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;Identities<br />[2008/11/23 10:18:17 | 000,155,136 | ---- | C] ( ) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;d347bus.sys<br />[2008/11/23 10:18:17 | 000,005,248 | ---- | C] ( ) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;d347prt.sys<br />[2007/04/09 13:32:58 | 000,034,816 | ---- | C] ( ) -- C:&#092;WINDOWS&#092;System32&#092;a3d.dll<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Files - Modified Within 90 Days ==========<!--colorc--></span><!--/colorc--><br /> <br />[2010/05/09 15:24:43 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;OTL.exe<br />[2010/05/09 15:19:41 | 000,088,566 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;nvapps.xml<br />[2010/05/09 15:19:41 | 000,002,206 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;wpa.dbl<br />[2010/05/09 15:18:17 | 000,000,472 | ---- | M] () -- C:&#092;WINDOWS&#092;tasks&#092;Ad-Aware Update (Weekly).job<br />[2010/05/09 15:16:45 | 000,000,006 | -H-- | M] () -- C:&#092;WINDOWS&#092;tasks&#092;SA.DAT<br />[2010/05/09 15:16:20 | 000,002,048 | --S- | M] () -- C:&#092;WINDOWS&#092;bootstat.dat<br />[2010/05/09 08:01:18 | 014,680,064 | -H-- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;NTUSER.DAT<br />[2010/05/09 08:01:17 | 000,030,120 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;BMXStateBkp-{00000000-00000000-0000000C-00001102-00000004-00511102}.rfx<br />[2010/05/09 08:01:17 | 000,030,120 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;BMXState-{00000000-00000000-0000000C-00001102-00000004-00511102}.rfx<br />[2010/05/09 08:01:17 | 000,027,408 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;BMXCtrlState-{00000000-00000000-0000000C-00001102-00000004-00511102}.rfx<br />[2010/05/09 08:01:17 | 000,027,408 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;BMXBkpCtrlState-{00000000-00000000-0000000C-00001102-00000004-00511102}.rfx<br />[2010/05/09 08:01:17 | 000,011,564 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;DVCState-{00000000-00000000-0000000C-00001102-00000004-00511102}.rfx<br />[2010/05/09 08:01:00 | 000,000,278 | -HS- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;ntuser.ini<br />[2010/05/09 06:48:48 | 000,188,416 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />[2010/05/09 02:22:14 | 000,000,261 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;YouTube - Marvel Ultimate Alliance part 35 Pitfall Wolverine.url<br />[2010/05/08 04:33:50 | 000,000,292 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;factorydirect.url<br />[2010/05/07 03:26:20 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;SBREDrv.sys<br />[2010/05/07 03:26:19 | 000,015,880 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;lsdelete.exe<br />[2010/05/07 03:05:13 | 000,000,227 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News.url<br />[2010/05/07 03:05:13 | 000,000,195 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Past Podcasts  Podcasts  CBC Radio.url<br />[2010/05/07 01:32:49 | 000,000,298 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;factorydirect1.url<br />[2010/05/06 02:49:50 | 000,393,109 | R--- | M] () -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;etc&#092;hosts<br />[2010/05/06 02:06:55 | 000,393,109 | R--- | M] () -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;etc&#092;hosts.20100506-024950.backup<br />[2010/05/06 02:06:01 | 000,393,109 | R--- | M] () -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;etc&#092;hosts.20100506-020654.backup<br />[2010/05/05 03:05:52 | 000,000,192 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Malcolm Gladwell - Outliers (book) - Wikipedia.url<br />[2010/05/05 03:05:51 | 000,000,208 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Low self-discharge NiMH battery - Wikipedia, the free encyclopedia.url<br />[2010/05/05 03:05:51 | 000,000,200 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Wall Street (1987 film) - Wikipedia, the free encyclopedia.url<br />[2010/05/05 03:05:51 | 000,000,195 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;The Wealthy Barber.url<br />[2010/05/05 00:05:58 | 000,156,672 | ---- | M] (Radioactive) -- C:&#092;WINDOWS&#092;System32&#092;rmc_fixasf.exe<br />[2010/05/05 00:05:57 | 000,237,568 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;rmc_rtspdl.dll<br />[2010/05/04 23:46:44 | 000,000,046 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;DonationCoder_urlsnooper_InstallInfo.dat<br />[2010/05/04 23:46:38 | 000,000,073 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;-1<br />[2010/05/04 23:36:44 | 000,000,726 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Orbit.lnk<br />[2010/05/04 19:00:39 | 000,000,213 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;HDH Invitational #1.url<br />[2010/05/04 18:18:54 | 000,000,426 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;YouTube - HuskyStarcraft's Channel.url<br />[2010/05/04 02:52:34 | 000,000,207 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Consumer Life.url<br />[2010/05/04 02:52:34 | 000,000,206 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Consumer Life-.url<br />[2010/05/04 01:59:49 | 000,000,430 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;YouTube - HDstarcraft's Channel.url<br />[2010/05/02 16:33:51 | 000,026,112 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Hello.doc<br />[2010/05/02 05:33:13 | 000,000,217 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;HDH Invitational - Liquipedia Starcraft 2 Wiki.url<br />[2010/05/01 00:10:05 | 000,000,666 | ---- | M] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;FreeVPN.lnk<br />[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;mbamswissarmy.sys<br />[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;mbam.sys<br />[2010/04/28 15:23:22 | 000,032,256 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Schedule 2010.doc<br />[2010/04/28 03:57:51 | 000,000,256 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;pool.bin<br />[2010/04/28 03:14:54 | 000,000,204 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;The U.S. Military's War On PowerPoint - Powerpoint - Gizmodo.url<br />[2010/04/25 15:32:03 | 000,000,140 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;De' Longhi Customer Care.url<br />[2010/04/25 14:51:45 | 000,000,204 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;HowardForums Your Mobile Phone Community & Resource - GSM vs AWS.url<br />[2010/04/25 14:51:40 | 000,000,290 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;tilt photography.url<br />[2010/04/25 14:51:39 | 000,000,229 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Turn Your XBMC Media Center into a Video Game Console - Xbmc - Lifehacker.url<br />[2010/04/25 06:51:28 | 000,000,208 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Marvel Games  Wolverine MRD Escape.url<br />[2010/04/25 05:47:27 | 000,000,154 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;De'Longhi Accessories.url<br />[2010/04/25 05:32:46 | 000,000,274 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;The Globe and Mail.url<br />[2010/04/25 05:31:36 | 000,000,156 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Broadcaster - Canada's Communications Magazine.url<br />[2010/04/25 05:29:32 | 000,000,214 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Money.url<br />[2010/04/25 05:03:27 | 000,000,255 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Calgary.url<br />[2010/04/25 05:03:27 | 000,000,208 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Technology & Scien.url<br />[2010/04/25 05:03:27 | 000,000,201 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Cana.url<br />[2010/04/25 04:45:30 | 000,000,156 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;XBMC.url<br />[2010/04/25 04:40:14 | 000,000,212 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;top-10-hard-drive-upgrades-and-fixes.url<br />[2010/04/25 03:45:29 | 000,000,188 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;imgur The Simple Image Sharer  Image Gallery.url<br />[2010/04/25 03:05:01 | 000,000,231 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;GSM Classic Mobile Cellular.url<br />[2010/04/25 02:27:32 | 000,000,238 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Tati LCD - Christopher Bradshaw's Project Bin.url<br />[2010/04/25 00:50:37 | 000,000,154 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Worldline.ca - Unlimited Call the World - NOW OVER 50 COUNTRIES  Low Cost Calls.url<br />[2010/04/25 00:44:03 | 000,000,117 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;1011295.com - Rates.url<br />[2010/04/25 00:39:24 | 000,000,189 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;how-it-works.url<br />[2010/04/25 00:27:08 | 000,000,289 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;RedFlagDeals.url<br />[2010/04/24 18:50:04 | 000,000,243 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;League of Legends.url<br />[2010/04/24 18:09:38 | 000,000,383 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Find a Costco warehouse.url<br />[2010/04/24 16:51:20 | 000,000,655 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Costco - Houseware.url<br />[2010/04/24 15:51:55 | 000,000,238 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;BlackBerry OS 6.0 screenshots, details! « Boy Genius Report.url<br />[2010/04/24 06:32:45 | 000,000,242 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Dell Lightning, Flash, Thunder and Smoke leak out « Boy Genius Report.url<br />[2010/04/23 00:40:21 | 000,000,668 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;imjkyhgres.url<br />[2010/04/22 05:15:05 | 000,000,134 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;January 2010 Covers.url<br />[2010/04/22 05:00:05 | 000,000,694 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;imgremjns.url<br />[2010/04/22 03:24:36 | 000,000,160 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Comic Related - Hot Shot of the Week.url<br />[2010/04/19 23:32:02 | 000,000,196 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;YouTube - galleyuk's Channel.url<br />[2010/04/19 23:31:54 | 000,000,215 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;A Dangerous Man Lawrence After Arabia - Wikipedia, the free encyclopedia.url<br />[2010/04/19 14:20:57 | 000,000,285 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;sandbox app - Google Search.url<br />[2010/04/19 04:14:57 | 000,000,801 | ---- | M] () -- C:&#092;WINDOWS&#092;win.ini<br />[2010/04/19 04:14:57 | 000,000,227 | ---- | M] () -- C:&#092;WINDOWS&#092;system.ini<br />[2010/04/19 04:14:57 | 000,000,211 | -HS- | M] () -- C:&#092;boot.ini<br />[2010/04/18 19:19:42 | 000,000,210 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;NationStates • View topic - Official Factbook of the Sagittarian Navy (Done).url<br />[2010/04/18 03:14:25 | 000,001,588 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;K-7 14.6 MP Digital SLR Bundle with Shake Reduction, 720p HD Video and DA 18-55mm f-3.5-5.6 AL Weather Resistant Lens  Digital Cameras & Digital Camcorders  Dell Canada.url<br />[2010/04/15 03:34:29 | 000,000,262 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Build your own “Super OTA TV Antenna”  Digital Home.url<br />[2010/04/14 05:28:46 | 000,000,588 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;settingsbkup.sfm<br />[2010/04/14 05:28:46 | 000,000,588 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;settings.sfm<br />[2010/04/13 00:33:52 | 000,000,229 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;UT99.org - Unreal Tournament GOTY » Forum » View topic - TUTORIAL Tweak your UT graphics to the maximum.url<br />[2010/04/04 06:21:44 | 000,081,920 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Sales Application.doc<br />[2010/04/04 06:15:06 | 000,081,920 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Sales Application1.doc<br />[2010/04/04 03:10:11 | 000,000,176 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Normal-Tanks game official site.url<br />[2010/03/30 21:58:24 | 000,353,592 | ---- | M] (DivX, Inc.) -- C:&#092;WINDOWS&#092;System32&#092;DivXControlPanelApplet.cpl<br />[2010/03/29 02:59:13 | 005,867,828 | -H-- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Local Settings&#092;Application Data&#092;IconCache.db<br />[2010/03/28 22:57:46 | 000,038,976 | ---- | M] (microOLAP Technologies LTD) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;pssdk42.sys<br />[2010/03/25 20:41:14 | 000,001,729 | ---- | M] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;Desktop Manager.lnk<br />[2010/03/25 12:17:02 | 000,131,072 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Degree.doc<br />[2010/03/25 12:16:30 | 000,131,072 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Degree1.doc<br />[2010/03/21 14:07:50 | 000,000,212 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Aviation Document Booklet (New Licence Booklet) - Flight Crew Licensing - General Aviation - Aviation Safety - Air Transportation - Transport Canada.url<br />[2010/03/14 19:05:01 | 000,464,860 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;PerfStringBackup.INI<br />[2010/03/14 19:05:01 | 000,397,560 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;perfh009.dat<br />[2010/03/14 19:05:01 | 000,059,780 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;perfc009.dat<br />[2010/03/12 02:47:45 | 000,000,219 | ---- | M] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Extreme™ 3D Pro.url<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Files Created - No Company Name ==========<!--colorc--></span><!--/colorc--><br /> <br />[2010/05/07 03:59:01 | 000,015,880 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;lsdelete.exe<br />[2010/05/07 03:28:22 | 000,000,472 | ---- | C] () -- C:&#092;WINDOWS&#092;tasks&#092;Ad-Aware Update (Weekly).job<br />[2010/05/07 02:35:52 | 000,000,227 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News.url<br />[2010/05/05 14:25:25 | 000,000,195 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Past Podcasts  Podcasts  CBC Radio.url<br />[2010/05/05 00:01:46 | 000,237,568 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;rmc_rtspdl.dll<br />[2010/05/04 23:46:44 | 000,000,046 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;DonationCoder_urlsnooper_InstallInfo.dat<br />[2010/05/04 23:46:38 | 000,000,073 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;-1<br />[2010/05/04 23:36:44 | 000,000,726 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Orbit.lnk<br />[2010/05/02 16:18:54 | 000,026,112 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Hello.doc<br />[2010/05/02 05:35:24 | 000,000,213 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;HDH Invitational #1.url<br />[2010/05/02 05:33:13 | 000,000,217 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;HDH Invitational - Liquipedia Starcraft 2 Wiki.url<br />[2010/05/01 00:10:05 | 000,000,666 | ---- | C] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;FreeVPN.lnk<br />[2010/04/28 15:23:07 | 000,032,256 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Summer 2010.doc<br />[2010/04/28 03:14:53 | 000,000,204 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;copy to word document The U.S. Military's War On PowerPoint - Powerpoint - Gizmodo.url<br />[2010/04/27 00:15:07 | 000,000,206 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Consumer Life.url<br />[2010/04/27 00:12:54 | 000,000,207 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Consumer Life-.url<br />[2010/04/25 06:51:28 | 000,000,208 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Marvel Games  Wolverine MRD Escape.url<br />[2010/04/25 05:51:13 | 000,000,200 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Wall Street (1987 film) - Wikipedia, the free encyclopedia.url<br />[2010/04/25 05:47:27 | 000,000,154 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;De'Longhi Accessories.url<br />[2010/04/25 05:32:46 | 000,000,274 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;The Globe and Mail.url<br />[2010/04/25 05:31:36 | 000,000,156 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Broadcaster - Canada's Communications Magazine.url<br />[2010/04/25 05:29:32 | 000,000,214 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Money -.url<br />[2010/04/25 04:45:49 | 000,000,229 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Turn Your XBMC Media Center into a Video Game Console - Xbmc - Lifehacker.url<br />[2010/04/25 04:45:30 | 000,000,156 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;XBMC.url<br />[2010/04/25 04:40:14 | 000,000,212 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;top-10-hard-drive-upgrades-and-fixes.url<br />[2010/04/25 04:05:34 | 000,000,290 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;tilt photography.url<br />[2010/04/25 03:45:28 | 000,000,188 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;imgur The Simple Image Sharer  Image Gallery.url<br />[2010/04/25 03:35:18 | 000,000,204 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;HowardForums Your Mobile Phone Community & Resource - GSM vs AWS.url<br />[2010/04/25 03:05:01 | 000,000,231 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;GSM Classic Mobile Cellular Retro Vintage Brick Phone.url<br />[2010/04/25 02:27:32 | 000,000,238 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Tati LCD - Christopher Bradshaw's Project Bin.url<br />[2010/04/25 00:44:03 | 000,000,117 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;1011295.com - Rates.url<br />[2010/04/25 00:42:18 | 000,000,154 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Worldline.ca - Unlimited Call the World - NOW OVER 50 COUNTRIES  Low Cost Calls.url<br />[2010/04/25 00:39:24 | 000,000,189 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;how-it-works.url<br />[2010/04/25 00:29:01 | 000,000,208 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Low self-discharge NiMH battery - Wikipedia, the free encyclopedia.url<br />[2010/04/25 00:27:08 | 000,000,289 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;RedFlagDeals.url<br />[2010/04/24 18:50:04 | 000,000,243 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;League of Legends.url<br />[2010/04/24 18:09:29 | 000,000,383 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Find a Costco warehouse.url<br />[2010/04/24 17:56:11 | 000,000,140 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;De' Longhi Customer Care.url<br />[2010/04/24 06:36:59 | 000,000,238 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;BlackBerry OS 6.0 screenshots, details! « Boy Genius Report.url<br />[2010/04/24 06:32:45 | 000,000,242 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Dell Lightning, Flash, Thunder and Smoke leak out « Boy Genius Report.url<br />[2010/04/24 05:23:27 | 000,000,655 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Costco - Housewares.url<br />[2010/04/23 14:59:11 | 000,000,255 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Calgary.url<br />[2010/04/22 05:15:05 | 000,000,134 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;January 2010 Covers.url<br />[2010/04/22 05:00:05 | 000,000,694 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;imgremjns.url<br />[2010/04/22 05:00:05 | 000,000,668 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;imjkyhgres.url<br />[2010/04/22 03:24:36 | 000,000,160 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Comic Related - Hot Shot of the Week.url<br />[2010/04/19 23:36:58 | 000,000,195 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;The Wealthy Barber - borrow from Cherry.url<br />[2010/04/19 23:34:08 | 000,000,192 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Malcolm Gladwell - Outliers (book) - Wikipedia.url<br />[2010/04/19 14:31:42 | 000,000,201 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Canada -.url<br />[2010/04/19 14:20:57 | 000,000,285 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;sandbox app - Google Search.url<br />[2010/04/19 14:04:26 | 000,000,208 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;CBC News - Technology & Science -.url<br />[2010/04/18 19:19:42 | 000,000,210 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;NationStates • View topic - Official Factbook of the Sagittarian Navy (Done).url<br />[2010/04/17 05:39:40 | 000,000,215 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;A Dangerous Man Lawrence After Arabia - Wikipedia, the free encyclopedia.url<br />[2010/04/17 03:40:10 | 000,001,588 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;K-7 14.6 MP Digital SLR Bundle with Shake Reduction, 720p HD Video and DA 18-55mm f-3.5-5.6 AL Weather Resistant Lens  Digital Cameras & Digital Camcorders  Dell Canada.url<br />[2010/04/15 03:34:29 | 000,000,262 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Build your own “Super OTA TV Antenna”  Digital Home.url<br />[2010/04/13 00:33:52 | 000,000,229 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;UT99.org - Unreal Tournament GOTY » Forum » View topic - TUTORIAL Tweak your UT graphics to the maximum.url<br />[2010/04/11 23:44:55 | 000,000,196 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;YouTube - galleyuk's Channel.url<br />[2010/04/07 00:00:22 | 000,000,426 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;YouTube - HuskyStarcraft's Channel.url<br />[2010/04/06 23:51:27 | 000,000,430 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;YouTube - HDstarcraft's Channel.url<br />[2010/04/04 16:38:31 | 000,000,298 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;factorydirect.url<br />[2010/04/04 06:07:41 | 000,081,920 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Sales Application.doc<br />[2010/04/04 03:10:11 | 000,000,176 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Normal-Tanks game official site.url<br />[2010/04/02 15:32:51 | 000,000,292 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;factorydirect1.url<br />[2010/03/25 20:41:14 | 000,001,729 | ---- | C] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;Desktop Manager.lnk<br />[2010/03/25 12:17:02 | 000,131,072 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Degree.doc<br />[2010/03/25 12:16:30 | 000,131,072 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Degree2.doc<br />[2010/03/14 22:10:44 | 000,000,261 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;YouTube - Marvel Ultimate Alliance part 35 Pitfall Wolverine.url<br />[2010/03/03 14:48:42 | 000,000,212 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Aviation Document Booklet (New Licence Booklet) - Flight Crew Licensing - General Aviation - Aviation Safety - Air Transportation - Transport Canada.url<br />[2010/03/02 02:18:10 | 000,000,219 | ---- | C] () -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Extreme™ 3D Pro.url<br />[2010/02/22 00:05:10 | 000,000,766 | ---- | C] () -- C:&#092;WINDOWS&#092;Uninstall.ico<br />[2010/02/22 00:04:41 | 000,151,552 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;SSCoInst.exe<br />[2010/02/22 00:04:41 | 000,135,168 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;SVSetup.Exe<br />[2010/02/22 00:04:41 | 000,057,344 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;SSCoInst.dll<br />[2010/02/22 00:04:41 | 000,053,248 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;SVSetup.dll<br />[2010/02/22 00:04:39 | 000,020,594 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;Dels3LMK.DLL<br />[2010/02/22 00:04:39 | 000,000,533 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;Dels3LMK.SMT<br />[2009/12/07 01:41:34 | 000,000,126 | ---- | C] () -- C:&#092;WINDOWS&#092;kaillera.ini<br />[2009/11/22 03:56:15 | 000,000,000 | ---- | C] () -- C:&#092;WINDOWS&#092;vpc32.INI<br />[2009/11/22 03:39:35 | 000,000,043 | ---- | C] () -- C:&#092;WINDOWS&#092;wininit.ini<br />[2009/06/14 08:58:18 | 000,000,132 | ---- | C] () -- C:&#092;WINDOWS&#092;winamp.ini<br />[2008/12/05 13:23:07 | 000,000,635 | ---- | C] () -- C:&#092;WINDOWS&#092;ef.INI<br />[2008/11/24 02:09:50 | 000,004,841 | ---- | C] () -- C:&#092;WINDOWS&#092;Ascd_tmp.ini<br />[2008/11/24 02:09:47 | 000,005,824 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;ASUSHWIO.SYS<br />[2008/11/23 10:31:28 | 000,000,376 | ---- | C] () -- C:&#092;WINDOWS&#092;ODBC.INI<br />[2007/04/12 09:10:28 | 000,105,728 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;APOMgrH.dll<br />[2007/04/09 13:55:14 | 000,097,785 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;instwdm.ini<br />[2007/04/09 13:55:14 | 000,000,054 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;ctzapxx.ini<br />[2007/04/09 13:33:50 | 000,043,520 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;CTBurst.dll<br />[2006/10/22 13:22:00 | 001,662,976 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;nvwdmcpl.dll<br />[2006/10/22 13:22:00 | 001,470,464 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;nview.dll<br />[2006/10/22 13:22:00 | 001,019,904 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;nvwimg.dll<br />[2006/10/22 13:22:00 | 000,581,632 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;nvhwvid.dll<br />[2006/10/22 13:22:00 | 000,466,944 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;nvshell.dll<br />[2006/10/22 13:22:00 | 000,286,720 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;nvnt4cpl.dll<br />[2006/10/22 13:22:00 | 000,212,992 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;nvapi.dll<br />[2006/10/02 10:25:18 | 000,000,307 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;kill.ini<br />[2005/06/16 11:17:16 | 000,071,680 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;ctmmactl.dll<br />[2004/08/22 18:04:56 | 000,069,120 | ---- | C] () -- C:&#092;WINDOWS&#092;daemon.dll<br />[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;OUTLPERF.INI<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== LOP Check ==========<!--colorc--></span><!--/colorc--><br /> <br />[2010/01/29 16:46:59 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;Research In Motion<br />[2010/03/28 22:57:45 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;SoftPerfect<br />[2010/05/07 03:24:46 | 000,000,000 | -H-D | M] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}<br />[2010/01/29 17:05:42 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Blackberry Desktop<br />[2010/05/04 23:46:44 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;DonationCoder<br />[2010/04/10 17:27:26 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;GrabPro<br />[2008/11/24 04:52:04 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Netscape<br />[2010/05/04 23:58:24 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Orbit<br />[2008/11/24 04:51:24 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Photodex<br />[2010/01/29 16:48:57 | 000,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Research In Motion<br />[2010/05/09 15:18:17 | 000,000,472 | ---- | M] () -- C:&#092;WINDOWS&#092;Tasks&#092;Ad-Aware Update (Weekly).job<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Purity Check ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Custom Scans ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;*.* &gt;<!--colorc--></span><!--/colorc--><br />[2010/05/09 15:15:52 | 000,001,822 | ---- | M] () -- C:&#092;aaw7boot.log<br />[2008/11/23 07:33:13 | 000,000,000 | ---- | M] () -- C:&#092;AUTOEXEC.BAT<br />[2010/04/19 04:14:57 | 000,000,211 | -HS- | M] () -- C:&#092;boot.ini<br />[2008/11/23 07:33:13 | 000,000,000 | ---- | M] () -- C:&#092;CONFIG.SYS<br />[2008/11/23 07:33:13 | 000,000,000 | RHS- | M] () -- C:&#092;IO.SYS<br />[2008/11/23 07:33:13 | 000,000,000 | RHS- | M] () -- C:&#092;MSDOS.SYS<br />[2008/11/23 08:24:27 | 000,047,564 | RHS- | M] () -- C:&#092;NTDETECT.COM<br />[2008/11/23 09:25:16 | 000,250,048 | RHS- | M] () -- C:&#092;ntldr<br />[2010/05/09 15:16:03 | 2145,386,496 | -HS- | M] () -- C:&#092;pagefile.sys<br />[2008/11/24 04:52:11 | 000,001,761 | ---- | M] () -- C:&#092;photodex-presenter-install.log<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %systemroot%&#092;*. /mp /s &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %systemroot%&#092;system32&#092;*.dll /lockedfiles &gt;<!--colorc--></span><!--/colorc--><br />[2008/08/26 03:24:28 | 000,347,136 | ---- | M] (Microsoft Corporation)<b> Unable to obtain MD5</b> -- C:&#092;WINDOWS&#092;system32&#092;dxtmsft.dll<br />[2008/08/26 03:24:28 | 000,214,528 | ---- | M] (Microsoft Corporation)<b> Unable to obtain MD5</b> -- C:&#092;WINDOWS&#092;system32&#092;dxtrans.dll<br />[2007/08/13 19:54:10 | 000,191,488 | ---- | M] (Microsoft Corporation)<b> Unable to obtain MD5</b> -- C:&#092;WINDOWS&#092;system32&#092;iepeers.dll<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %systemroot%&#092;Tasks&#092;*.job /lockedfiles &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %systemroot%&#092;system32&#092;drivers&#092;*.sys /lockedfiles &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %systemroot%&#092;System32&#092;config&#092;*.sav  &gt;<!--colorc--></span><!--/colorc--><br />[2008/11/23 02:17:14 | 000,090,112 | ---- | M] () -- C:&#092;WINDOWS&#092;system32&#092;config&#092;default.sav<br />[2008/11/23 02:17:14 | 000,630,784 | ---- | M] () -- C:&#092;WINDOWS&#092;system32&#092;config&#092;software.sav<br />[2008/11/23 02:17:13 | 000,438,272 | ---- | M] () -- C:&#092;WINDOWS&#092;system32&#092;config&#092;system.sav<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %systemroot%&#092;system32&#092;drivers&#092;*.sys /90 &gt;<!--colorc--></span><!--/colorc--><br />[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;mbam.sys<br />[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;mbamswissarmy.sys<br />[2010/03/28 22:57:46 | 000,038,976 | ---- | M] (microOLAP Technologies LTD) -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;pssdk42.sys<br />[2010/05/07 03:26:20 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;SBREDrv.sys<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %PROGRAMFILES%&#092;*. &gt;<!--colorc--></span><!--/colorc--><br />[2009/11/02 15:53:25 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Adobe<br />[2009/11/24 21:44:15 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;CDisplay<br />[2010/04/25 01:20:44 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Common Files<br />[2008/11/23 07:29:34 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;ComPlus Applications<br />[2008/11/23 09:59:05 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;CONEXANT<br />[2008/11/23 10:18:17 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;D-Tools<br />[2010/02/22 00:04:29 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;DELL<br />[2010/04/18 22:32:10 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;DivX<br />[2010/02/15 09:41:14 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;eXpress TimeStamp Toucher<br />[2010/05/08 04:34:14 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;FreeVPN<br />[2010/02/22 00:05:10 | 000,000,000 | -H-D | M] -- C:&#092;Program Files&#092;InstallShield Installation Information<br />[2010/01/29 16:40:34 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Internet Explorer<br />[2010/04/25 01:20:00 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Java<br />[2010/05/07 03:24:50 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Lavasoft<br />[2010/05/09 02:02:38 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Malwarebytes' Anti-Malware<br />[2008/11/23 10:30:34 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Microsoft ActiveSync<br />[2008/11/23 07:33:36 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;microsoft frontpage<br />[2009/06/18 10:46:06 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Microsoft Office<br />[2009/10/18 08:04:15 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Microsoft Rich Tools<br />[2010/02/13 19:23:28 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Microsoft Silverlight<br />[2008/11/23 09:30:00 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Movie Maker<br />[2009/06/18 10:45:51 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;MSECache<br />[2008/11/23 07:29:19 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;MSN<br />[2008/11/23 07:28:57 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;MSN Gaming Zone<br />[2008/12/05 13:41:01 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Nero<br />[2008/11/23 09:27:22 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;NetMeeting<br />[2010/03/28 22:57:45 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;NetWorx<br />[2008/11/23 07:29:19 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Online Services<br />[2010/05/04 23:36:44 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Orbitdownloader<br />[2008/11/23 09:27:18 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Outlook Express<br />[2008/11/24 04:51:45 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Photodex<br />[2008/11/24 04:52:04 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Photodex Presenter<br />[2009/04/08 21:24:04 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;QuickTime<br />[2010/01/29 16:46:01 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Research In Motion<br />[2008/11/24 04:54:20 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Soundslides<br />[2010/05/06 03:03:57 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Spybot - Search & Destroy<br />[2009/11/22 03:47:15 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Symantec<br />[2010/05/09 15:17:26 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Symantec AntiVirus<br />[2008/11/23 07:38:05 | 000,000,000 | -H-D | M] -- C:&#092;Program Files&#092;Uninstall Information<br />[2008/11/24 02:10:55 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;VIA<br />[2008/11/24 23:58:36 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;VideoLAN<br />[2008/11/23 10:02:17 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Windows Media Connect 2<br />[2008/11/23 10:02:16 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Windows Media Player<br />[2008/11/23 09:27:18 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Windows NT<br />[2008/12/05 13:39:47 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;Windows Sidebar<br />[2008/11/23 07:49:25 | 000,000,000 | -H-D | M] -- C:&#092;Program Files&#092;WindowsUpdate<br />[2008/11/24 23:59:10 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;WinRAR<br />[2008/11/23 07:33:36 | 000,000,000 | ---D | M] -- C:&#092;Program Files&#092;xerox<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;WindowsUpdate&#092;Auto Update&#092;Results&#092;Install|LastSuccessTime /rs &gt;<!--colorc--></span><!--/colorc--><br />&lt; End of report &gt;<br /><br /><br /><br /><br /><br /><br /><br />OTL Extras logfile created on: 5/9/2010 3:26:05 PM - Run 1<br />OTL by OldTimer - Version 3.2.4.1     Folder = C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop<br />Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />Internet Explorer (Version = 7.0.5730.13)<br />Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br /> <br />1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free<br />3.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free<br />Paging file location(s): C:&#092;pagefile.sys 2046 4092 [binary data]<br /> <br />%SystemDrive% = C: | %SystemRoot% = C:&#092;WINDOWS | %ProgramFiles% = C:&#092;Program Files<br />Drive C: | 19.13 Gb Total Space | 1.08 Gb Free Space | 5.63% Space Free | Partition Type: NTFS<br />Drive D: | 7.87 Gb Total Space | 0.99 Gb Free Space | 12.56% Space Free | Partition Type: NTFS<br />E: Drive not present or media not loaded<br />Drive F: | 465.76 Gb Total Space | 303.47 Gb Free Space | 65.16% Space Free | Partition Type: NTFS<br />G: Drive not present or media not loaded<br />H: Drive not present or media not loaded<br />Drive I: | 3.90 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS<br />Drive L: | 149.05 Gb Total Space | 1.48 Gb Free Space | 0.99% Space Free | Partition Type: NTFS<br />Drive M: | 74.53 Gb Total Space | 2.37 Gb Free Space | 3.18% Space Free | Partition Type: NTFS<br />Drive P: | 149.04 Gb Total Space | 4.47 Gb Free Space | 3.00% Space Free | Partition Type: NTFS<br /> <br />Computer Name: THELEVIATHAN<br />Current User Name: TheLeviathan<br />Logged in as Administrator.<br /> <br />Current Boot Mode: Normal<br />Scan Mode: Current user<br />Company Name Whitelist: On<br />Skip Microsoft Files: On<br />File Age = 90 Days<br />Output = Standard<br />Quick Scan<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Extra Registry (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== File Associations ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Classes&#092;&lt;extension&gt;]<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Shell Spawning ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Classes&#092;&lt;key&gt;&#092;shell&#092;[command]&#092;command]<br />batfile [open] -- "%1" %*<br />cmdfile [open] -- "%1" %*<br />comfile [open] -- "%1" %*<br />exefile [open] -- "%1" %*<br />htmlfile [edit] -- "C:&#092;Program Files&#092;Microsoft Office&#092;OFFICE11&#092;msohtmed.exe" %1 (Microsoft Corporation)<br />htmlfile [print] -- "C:&#092;Program Files&#092;Microsoft Office&#092;OFFICE11&#092;msohtmed.exe" /p %1 (Microsoft Corporation)<br />piffile [open] -- "%1" %*<br />regfile [merge] -- Reg Error: Key error.<br />scrfile [config] -- "%1"<br />scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)<br />scrfile [open] -- "%1" /S<br />txtfile [edit] -- Reg Error: Key error.<br />Unknown [openas] -- %SystemRoot%&#092;system32&#092;rundll32.exe %SystemRoot%&#092;system32&#092;shell32.dll,OpenAs_RunDLL %1<br />Directory [AddToPlaylistVLC] -- C:&#092;Program Files&#092;VideoLAN&#092;VLC&#092;vlc.exe --started-from-file --playlist-enqueue "%1" ()<br />Directory [find] -- %SystemRoot%&#092;Explorer.exe (Microsoft Corporation)<br />Directory [PlayWithVLC] -- C:&#092;Program Files&#092;VideoLAN&#092;VLC&#092;vlc.exe --started-from-file --no-playlist-enqueue "%1" ()<br />Folder [open] -- %SystemRoot%&#092;Explorer.exe /idlist,%I,%L (Microsoft Corporation)<br />Folder [explore] -- %SystemRoot%&#092;Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)<br />Drive [find] -- %SystemRoot%&#092;Explorer.exe (Microsoft Corporation)<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Security Center Settings ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center]<br />"AntiVirusDisableNotify" = 0<br />"FirewallDisableNotify" = 0<br />"UpdatesDisableNotify" = 0<br />"AntiVirusOverride" = 0<br />"FirewallOverride" = 0<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;AhnlabAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;ComputerAssociatesAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;KasperskyAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;McAfeeAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;McAfeeFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;PandaAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;PandaFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SophosAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SymantecAntiVirus]<br />"DisableMonitoring" = 1<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SymantecFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TinyFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TrendAntiVirus]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TrendFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;ZoneLabsFirewall]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile&#092;GloballyOpenPorts&#092;List]<br />"65533:TCP" = 65533:TCP:*:Enabled:Services<br />"52344:TCP" = 52344:TCP:*:Enabled:Services<br />"2382:TCP" = 2382:TCP:*:Enabled:Services<br />"1941:TCP" = 1941:TCP:*:Enabled:Services<br />"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop<br />"2102:TCP" = 2102:TCP:*:Enabled:Services<br />"2704:TCP" = 2704:TCP:*:Enabled:Services<br />"4509:TCP" = 4509:TCP:*:Enabled:Services<br />"7518:TCP" = 7518:TCP:*:Enabled:Services<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile]<br />"EnableFirewall" = 1<br />"DoNotAllowExceptions" = 0<br />"DisableNotifications" = 0<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile&#092;GloballyOpenPorts&#092;List]<br />"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007<br />"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008<br />"65533:TCP" = 65533:TCP:*:Enabled:Services<br />"52344:TCP" = 52344:TCP:*:Enabled:Services<br />"2382:TCP" = 2382:TCP:*:Enabled:Services<br />"1941:TCP" = 1941:TCP:*:Enabled:Services<br />"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop<br />"2102:TCP" = 2102:TCP:*:Enabled:Services<br />"2704:TCP" = 2704:TCP:*:Enabled:Services<br />"4509:TCP" = 4509:TCP:*:Enabled:Services<br />"7518:TCP" = 7518:TCP:*:Enabled:Services<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Authorized Applications List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile&#092;AuthorizedApplications&#092;List]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile&#092;AuthorizedApplications&#092;List]<br />"M:&#092;Microsoft Games&#092;Flight Simulator 9&#092;fs9.exe" = M:&#092;Microsoft Games&#092;Flight Simulator 9&#092;fs9.exe:*:Enabled:Microsoft Flight Simulator -- (Microsoft Corporation)<br />"C:&#092;WINDOWS&#092;system32&#092;dpnsvr.exe" = C:&#092;WINDOWS&#092;system32&#092;dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server -- (Microsoft Corporation)<br />"L:&#092;Microsoft Games&#092;Flight Simulator 9&#092;fs9.exe" = L:&#092;Microsoft Games&#092;Flight Simulator 9&#092;fs9.exe:*:Enabled:Microsoft Flight Simulator -- (Microsoft Corporation)<br />"C:&#092;Program Files&#092;VideoLAN&#092;VLC&#092;vlc.exe" = C:&#092;Program Files&#092;VideoLAN&#092;VLC&#092;vlc.exe:*:Enabled:VLC media player -- ()<br />"C:&#092;Program Files&#092;Orbitdownloader&#092;orbitdm.exe" = C:&#092;Program Files&#092;Orbitdownloader&#092;orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)<br />"C:&#092;Program Files&#092;Orbitdownloader&#092;orbitnet.exe" = C:&#092;Program Files&#092;Orbitdownloader&#092;orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== HKEY_LOCAL_MACHINE Uninstall List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Uninstall]<br />"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero BurningROM<br />"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java&#153; 6 Update 20<br />"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook<br />"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP<br />"{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime<br />"{3b340a5d-8adf-4379-8edd-871acef5687b}" = Nero 9<br />"{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}" = DAEMON Tools<br />"{46B63F23-2B4A-4525-A827-688026BE5E40}" = Symantec AntiVirus<br />"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater<br />"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress<br />"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053<br />"{60c731fb-c951-41ce-ad41-8e54c8594609}" = Nero Disc Copy Gadget Help<br />"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable<br />"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights<br />"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express<br />"{86F4F32B-77C7-4951-B33C-05D41A8190C1}" = Microsoft RichCopy 4.0<br />"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight<br />"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003<br />"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system<br />"{9497EBAA-87AD-41E6-8ED6-E1E52995A76C}" = VIA Integrated Setup Wizard<br />"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress<br />"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0<br />"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles<br />"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center<br />"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy<br />"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1<br />"{B7618997-1B89-4680-A39B-342BBEF8E0D6}_is1" = FreeVPN v3.22<br />"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit<br />"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter<br />"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1<br />"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM<br />"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware<br />"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit<br />"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer<br />"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial<br />"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget<br />"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)<br />"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01<br />"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter<br />"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights<br />"Ad-Aware" = Ad-Aware<br />"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX<br />"Adobe Shockwave Player" = Adobe Shockwave Player 11.5<br />"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1<br />"CDisplay_is1" = CDisplay 1.8<br />"CNXT_MODEM_PCI_VEN_14F1&DEV_2013&SUBSYS_201314F1" = SoftK56 Data Fax<br />"Dell Laser Printer 1110" = Dell Laser Printer 1110 Software Uninstall<br />"DivX Setup.divx.com" = DivX Setup<br />"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs<br />"ie7" = Windows Internet Explorer 7<br />"InstallShield_{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime<br />"InstallShield_{9497EBAA-87AD-41E6-8ED6-E1E52995A76C}" = VIA Integrated Setup Wizard<br />"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)<br />"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware<br />"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP<br />"NetWorx_is1" = NetWorx 5.1<br />"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs<br />"NVIDIA Drivers" = NVIDIA Drivers<br />"Orbit_is1" = Orbit Downloader<br />"Photodex Presenter" = Photodex Presenter<br />"ProShow Gold" = ProShow Gold<br />"Soundslides" = Soundslides<br />"VLC media player" = VLC media player 0.9.6<br />"Windows Media Format Runtime" = Windows Media Format 11 runtime<br />"Windows Media Player" = Windows Media Player 11<br />"Windows XP Service Pack" = Windows XP Service Pack 3<br />"WinImage" = WinImage<br />"WinRAR archiver" = WinRAR archiver<br />"WMFDist11" = Windows Media Format 11 runtime<br />"wmp11" = Windows Media Player 11<br />"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== HKEY_CURRENT_USER Uninstall List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Uninstall]<br />"eXpress TimeStamp Toucher" = eXpress TimeStamp Toucher<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Last 10 Event Log Errors ==========<!--colorc--></span><!--/colorc--><br /> <br />[ Application Events ]<br />Error - 5/8/2010 12:23:11 AM | Computer Name = THELEVIATHAN | Source = Symantec AntiVirus | ID = 16711685<br />Description =       Threat Found!Threat: Trojan.ByteVerify in File: P:&#092;backup&#092;Documents<br /> and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-2e95c8bf-4adddc82.zip&gt;&gt;Dun.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat:  in File: P:&#092;backup&#092;Documents<br /> and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-2e95c8bf-4adddc82.zip<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat: Trojan.ByteVerify in File: P:&#092;backup&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-30b9e234-16d4d616.zip&gt;&gt;BnnnnBaa.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    <br /> <br />Error - 5/8/2010 12:23:11 AM | Computer Name = THELEVIATHAN | Source = Symantec AntiVirus | ID = 16711685<br />Description =       Threat Found!Threat: Trojan Horse in File: P:&#092;backup&#092;Documents<br /> and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-30b9e234-16d4d616.zip&gt;&gt;VaannnaaBaa.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat: Trojan Horse in File: P:&#092;backup&#092;Documents<br /> and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-30b9e234-16d4d616.zip&gt;&gt;Dnnny.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat: Trojan.ByteVerify in File: P:&#092;backup&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-30b9e234-16d4d616.zip&gt;&gt;Bnnnnn.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    <br /> <br />Error - 5/8/2010 12:23:12 AM | Computer Name = THELEVIATHAN | Source = Symantec AntiVirus | ID = 16711685<br />Description =       Threat Found!Threat: Trojan Horse in File: P:&#092;backup&#092;Documents<br /> and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-30b9e234-16d4d616.zip&gt;&gt;Den.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat: Trojan.ByteVerify in File: P:&#092;backup&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-30b9e234-16d4d616.zip&gt;&gt;Din.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat: Trojan.ByteVerify in File: P:&#092;backup&#092;Documents and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-30b9e234-16d4d616.zip&gt;&gt;Dun.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    <br /> <br />Error - 5/8/2010 12:24:11 AM | Computer Name = THELEVIATHAN | Source = Symantec AntiVirus | ID = 16711685<br />Description =       Threat Found!Threat:  in File: P:&#092;backup&#092;Documents and Settings&#092;TheLeviathan&#092;Application<br /> Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;cnte-dhncgts.jar-30b9e234-16d4d616.zip<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat: Downloader in File: P:&#092;backup&#092;Documents<br /> and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;jvmimpro.jar-51fad18-2e802fa5.zip&gt;&gt;vmain.class<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat:  in File: P:&#092;backup&#092;Documents<br /> and Settings&#092;TheLeviathan&#092;Application Data&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;javapi&#092;v1.0&#092;jar&#092;jvmimpro.jar-51fad18-2e802fa5.zip<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    <br /> <br />Error - 5/8/2010 1:11:50 AM | Computer Name = THELEVIATHAN | Source = Symantec AntiVirus | ID = 16711685<br />Description =       Threat Found!Threat: Trojan Horse in File: P:&#092;comp backup&#092;Backup<br /> May 3 2009&#092;jars&#092;Java Games&#092;DigitalRed Shuffleboard v20&#092;b-shuff2.zip&gt;&gt;Shuffleboard.2.00.7650.exe<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    Threat Found!Threat:  in File: P:&#092;comp backup&#092;Backup<br /> May 3 2009&#092;jars&#092;Java Games&#092;DigitalRed Shuffleboard v20&#092;b-shuff2.zip by: Manual<br /> scan.  Action: Quarantine succeeded.  Action Description: The file was quarantined<br /> successfully.    Threat Found!Threat: Trojan Horse in File: P:&#092;New Folder&#092;New Folder&#092;Backup<br /> May 3 2009&#092;jars&#092;Java Games&#092;DigitalRed Shuffleboard v20&#092;b-shuff2.zip&gt;&gt;Shuffleboard.2.00.7650.exe<br /> by: Manual scan.  Action: Quarantine succeeded.  Action Description: The file was<br /> quarantined successfully.    <br /> <br />[ System Events ]<br />Error - 5/9/2010 1:50:54 AM | Computer Name = THELEVIATHAN | Source = Service Control Manager | ID = 7034<br />Description = The Symantec Event Manager service terminated unexpectedly.  It has<br /> done this 1 time(s).<br /> <br />Error - 5/9/2010 1:50:54 AM | Computer Name = THELEVIATHAN | Source = Service Control Manager | ID = 7034<br />Description = The Symantec AntiVirus Definition Watcher service terminated unexpectedly.<br />  It has done this 1 time(s).<br /> <br />Error - 5/9/2010 1:50:54 AM | Computer Name = THELEVIATHAN | Source = Service Control Manager | ID = 7034<br />Description = The Java Quick Starter service terminated unexpectedly.  It has done<br /> this 1 time(s).<br /> <br />Error - 5/9/2010 1:50:54 AM | Computer Name = THELEVIATHAN | Source = Service Control Manager | ID = 7031<br />Description = The Lavasoft Ad-Aware Service service terminated unexpectedly.  It<br /> has done this 1 time(s).  The following corrective action will be taken in 5000<br /> milliseconds: Restart the service.<br /> <br />Error - 5/9/2010 1:50:54 AM | Computer Name = THELEVIATHAN | Source = Service Control Manager | ID = 7034<br />Description = The NVIDIA Display Driver Service service terminated unexpectedly.<br />  It has done this 1 time(s).<br /> <br />Error - 5/9/2010 1:50:54 AM | Computer Name = THELEVIATHAN | Source = Service Control Manager | ID = 7034<br />Description = The ScsiAccess service terminated unexpectedly.  It has done this <br />1 time(s).<br /> <br />Error - 5/9/2010 1:56:57 AM | Computer Name = THELEVIATHAN | Source = Ftdisk | ID = 262189<br />Description = The system could not sucessfully load the crash dump driver.<br /> <br />Error - 5/9/2010 1:56:57 AM | Computer Name = THELEVIATHAN | Source = Ftdisk | ID = 262193<br />Description = Configuring the Page file for crash dump failed. Make sure there is<br /> a page  file on the boot partition and that is large enough to contain all physical<br />memory.<br /> <br />Error - 5/9/2010 3:16:33 PM | Computer Name = THELEVIATHAN | Source = Ftdisk | ID = 262189<br />Description = The system could not sucessfully load the crash dump driver.<br /> <br />Error - 5/9/2010 3:16:33 PM | Computer Name = THELEVIATHAN | Source = Ftdisk | ID = 262193<br />Description = Configuring the Page file for crash dump failed. Make sure there is<br /> a page  file on the boot partition and that is large enough to contain all physical<br />memory.<br /> <br /> <br />&lt; End of report &gt;<br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />Malwarebytes' Anti-Malware 1.46<br />www.malwarebytes.org<br /><br />Database version: 4080<br /><br />Windows 5.1.2600 Service Pack 3<br />Internet Explorer 7.0.5730.13<br /><br />5/9/2010 2:08:45 AM<br />mbam-log-2010-05-09 (02-08-45).txt<br /><br />Scan type: Quick scan<br />Objects scanned: 124542<br />Time elapsed: 5 minute(s), 36 second(s)<br /><br />Memory Processes Infected: 0<br />Memory Modules Infected: 0<br />Registry Keys Infected: 0<br />Registry Values Infected: 0<br />Registry Data Items Infected: 0<br />Folders Infected: 0<br />Files Infected: 0<br /><br />Memory Processes Infected:<br />(No malicious items detected)<br /><br />Memory Modules Infected:<br />(No malicious items detected)<br /><br />Registry Keys Infected:<br />(No malicious items detected)<br /><br />Registry Values Infected:<br />(No malicious items detected)<br /><br />Registry Data Items Infected:<br />(No malicious items detected)<br /><br />Folders Infected:<br />(No malicious items detected)<br /><br />Files Infected:<br />(No malicious items detected)<br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />Rooter.exe (v1.0.2) by Eric_71<br />.<br />SeDebugPrivilege granted successfully ...<br />.<br />Windows XP . (5.1.2600) Service Pack 3<br />[32_bits] - x86 Family 15 Model 47 Stepping 0, AuthenticAMD<br />.<br />[wscsvc] (Security Center) RUNNING (state:4)<br />[SharedAccess] RUNNING (state:4)<br />Windows Firewall -&gt; Enabled<br />.<br />Internet Explorer 7.0.5730.13<br />.<br />A:&#092;  [Removable]<br />C:&#092;  [Fixed-NTFS] .. ( Total:19 Go - Free:1 Go )<br />D:&#092;  [Fixed-NTFS] .. ( Total:7 Go - Free:0 Go )<br />E:&#092;  [CD_Rom]<br />F:&#092;  [Fixed-NTFS] .. ( Total:465 Go - Free:303 Go )<br />I:&#092;  [CD_Rom]<br />L:&#092;  [Fixed-NTFS] .. ( Total:149 Go - Free:1 Go )<br />M:&#092;  [Fixed-NTFS] .. ( Total:74 Go - Free:2 Go )<br />P:&#092;  [Fixed-NTFS] .. ( Total:149 Go - Free:4 Go )<br />.<br />Scan : 15:34.01<br />Path : C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Rooter.exe<br />User : TheLeviathan ( Administrator -&gt; YES )<br />.<br />----------------------&#092;&#092; Processes<br />.<br />Locked [System Process] (0)<br />______ System (4)<br />______ &#092;SystemRoot&#092;System32&#092;smss.exe (688)<br />______ &#092;??&#092;C:&#092;WINDOWS&#092;system32&#092;csrss.exe (748)<br />______ &#092;??&#092;C:&#092;WINDOWS&#092;system32&#092;winlogon.exe (788)<br />______ C:&#092;WINDOWS&#092;system32&#092;services.exe (864)<br />______ C:&#092;WINDOWS&#092;system32&#092;lsass.exe (876)<br />______ C:&#092;WINDOWS&#092;system32&#092;svchost.exe (1080)<br />______ C:&#092;WINDOWS&#092;system32&#092;svchost.exe (1188)<br />______ C:&#092;WINDOWS&#092;System32&#092;svchost.exe (1252)<br />______ C:&#092;WINDOWS&#092;System32&#092;svchost.exe (1516)<br />______ C:&#092;WINDOWS&#092;System32&#092;svchost.exe (1632)<br />______ C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccSetMgr.exe (1688)<br />______ C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccEvtMgr.exe (1724)<br />______ C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe (1832)<br />______ C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe (1908)<br />______ C:&#092;Program Files&#092;Symantec AntiVirus&#092;DefWatch.exe (2016)<br />______ C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe (208)<br />______ C:&#092;WINDOWS&#092;system32&#092;nvsvc32.exe (240)<br />______ C:&#092;Program Files&#092;Photodex&#092;ProShowGold&#092;ScsiAccess.exe (276)<br />______ C:&#092;Program Files&#092;Symantec AntiVirus&#092;Rtvscan.exe (380)<br />______ C:&#092;WINDOWS&#092;System32&#092;wbem&#092;unsecapp.exe (732)<br />______ C:&#092;WINDOWS&#092;System32&#092;alg.exe (904)<br />______ C:&#092;WINDOWS&#092;System32&#092;wbem&#092;wmiprvse.exe (1536)<br />______ C:&#092;WINDOWS&#092;system32&#092;wscntfy.exe (2720)<br />______ C:&#092;WINDOWS&#092;Explorer.EXE (2916)<br />______ C:&#092;PROGRA~1&#092;SYMANT~1&#092;VPTray.exe (3216)<br />______ C:&#092;Program Files&#092;NetWorx&#092;networx.exe (3540)<br />______ C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe (3548)<br />______ C:&#092;Program Files&#092;Spybot - Search & Destroy&#092;TeaTimer.exe (3564)<br />______ C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWTray.exe (3984)<br />______ C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE (220)<br />______ C:&#092;Documents and Settings&#092;TheLeviathan&#092;Desktop&#092;Rooter.exe (3316)<br />.<br />----------------------&#092;&#092; Device&#092;Harddisk0&#092;<br />.<br />&#092;Device&#092;Harddisk0 [Sectors : 63 x 512 Bytes]<br />.<br />&#092;Device&#092;Harddisk0&#092;Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:8447330304)<br />.<br />----------------------&#092;&#092; Scheduled Tasks<br />.<br />C:&#092;WINDOWS&#092;Tasks&#092;Ad-Aware Update (Weekly).job<br />C:&#092;WINDOWS&#092;Tasks&#092;desktop.ini<br />C:&#092;WINDOWS&#092;Tasks&#092;SA.DAT<br />.<br />----------------------&#092;&#092; Registry<br />.<br />.<br />----------------------&#092;&#092; Files & Folders<br />.<br />----------------------&#092;&#092; Scan completed at 15:34.21<br />.<br />C:&#092;Rooter$&#092;Rooter_1.txt - (09/05/2010 | 15:34.21)<br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />LockSearch by jpshortstuff (05.11.09.1)<br />Log created at 15:35 on 09/05/2010 (TheLeviathan)<br />Scanning C:&#092;<br /><br /><br />C:&#092;pagefile.sys<br />-------------------------<br /><br />-=E.O.F=-<br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />CKScanner - Additional Security Risks - These are not necessarily bad<br />scanner sequence 3.RP.11<br /> ----- EOF ----- <br /><br /><br /><br />]]></description>
		<pubDate>Mon, 10 May 2010 04:44:49 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=6037</guid>
	</item>
	<item>
		<title>BEFORE YOU POST !!</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=424</link>
		<description><![CDATA[Welcome to Atribune.org!  <img src="http://www.atribune.org/forums/style_emoticons/default/cool.gif" style="vertical-align:middle" emoid="B)" border="0" alt="cool.gif" /><br /><br />Before we can help you, we need you to help us by completing the following procedure.<br /><br /><b><u>Step 1 : Preparation</u></b><br /><br /><br /><b>Backup Your Registry with ERUNT</b><ul><li>Please use the following link and scroll down to ERUNT and download it.<br /><a href="http://aumha.org/freeware/freeware.php" target="_blank">http://aumha.org/freeware/freeware.php</a></li><li>For version with the Installer:<br />Use the setup program to install ERUNT on your computer</li><li>For the zipped version:<br />Unzip all the files into a folder of your choice.</li></ul>Click Erunt.exe to backup your registry to the folder of your choice.<br /><br />Note: <i><!--coloro:green--><span style="color:green"><!--/coloro-->to restore your registry, go to the folder and start <b>ERDNT.exe</b><!--colorc--></span><!--/colorc--></i><br /><br /><br /><br />Download <a href="http://oldtimer.geekstogo.com/TFC.exe" target="_blank"><!--coloro:#000000--><span style="color:#000000"><!--/coloro--><b>TFC</b><!--colorc--></span><!--/colorc--></a> to your desktop<br /><ul><li>Open the file and close any other windows.</li><li>It <b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->will close all programs itself<!--colorc--></span><!--/colorc--></b> when run, make sure to let it run uninterrupted.</li><li>Click the Start button to begin the process. The program should not take long to finish its job</li><li>Once its finished it should <b>reboot your machine</b>, if not, do this yourself to ensure a complete clean</li></ul><br /><br /><br /><br /><b><u>Step 2 : Cleaning</u></b><br /><br /><br />Please download Malwarebytes' Anti-Malware from <a href="http://www.malwarebytes.org/mbam-download.php" target="_blank"><!--coloro:#2E8B57--><span style="color:#2E8B57"><!--/coloro--><b>Here</b><!--colorc--></span><!--/colorc--></a><br /><br />Double Click mbam-setup.exe to install the application.<ul><li>Make sure a checkmark is placed next to <b>Update Malwarebytes' Anti-Malware</b> and <b>Launch Malwarebytes' Anti-Malware</b>, then click Finish.</li><li>If an update is found, it will download and install the latest version.</li><li>Once the program has loaded, select "<b>Perform Quick Scan</b>", then click <b>Scan</b>. </li><li>The scan may take some time to finish,so please be patient.</li><li>When the scan is complete, click OK, then Show Results to view the results.</li><li>Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.</li><li>When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)</li><li>The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.</li><li>Copy&Paste the entire report in your next reply.</li></ul><br />Extra Note:<br /><!--coloro:#2E8B57--><span style="color:#2E8B57"><!--/coloro--><b>If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.</b><!--colorc--></span><!--/colorc--><br /><br /><b><i>Note:</i></b> Some infections will prevent MBAM from running. If MBAM won't run, try renaming the file mbam-setup.exe to a random name, and then try again.<br /><br /><i><b>Extra Note:</b></i> Do not run a full scan with MBAM. It is not required or needed, and in fact makes our job tougher.<br /><br /><br /><br />Reboot your PC and run a full scan with your anti-virus program. This scan along with Malwarebytes should remove most malware.<br /><br /><br /><br />If you're still having problems, continue to the next step. Otherwise, read <a href="http://www.atribune.org/forums/index.php?showtopic=5342" target="_blank"><b>"Preventing Malware and Safe Computing"</b></a> to prevent future Spyware/Hijack attacks.<br /><br /><br /><br /><b><u>Step 3 : Post on the forum</u> </b><br /><br /><br /><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->Peer-to-peer programs/cracks/keygens/warez :<!--colorc--></span><!--/colorc--></b><br /><br />Downloading cracks and keygens from p2p programs ( Limewire, eMule, uTorrent ) is the most common way of how people get infected. We do not support the use of illegal software, that is why if you wish to get help on the forums, <b>ALL</b> p2p programs, cracks and keygens must be removed before posting. Failure to do so will result in your helper refusing to help you until they are completely removed.<br /><br />If you download cracks you will get infected, that is a guarantee. We wont be here to help you every time, users who keep getting infected from using p2p programs will have to reformat, so use some common sense and avoid illegal software as they always contain spyware. It just isn't worth it.<br /><br /><br /><br />Download <a href="http://oldtimer.geekstogo.com/OTL.exe" target="_blank"><b><!--coloro:red--><span style="color:red"><!--/coloro-->OTL<!--colorc--></span><!--/colorc--></b></a>  to your Desktop<br /><ul><li>Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.</li><li>Under the Custom Scan box paste this in<br /><br /><b>netsvcs<br />msconfig<br />safebootminimal<br />safebootnetwork<br />activex<br />drivers32<br />%SYSTEMDRIVE%&#092;*.*<br />%systemroot%&#092;system32&#092;Spool&#092;prtprocs&#092;w32x86&#092;*.*<br />%systemroot%&#092;system32&#092;*.wt<br />%systemroot%&#092;system32&#092;*.ruy<br />%systemroot%&#092;Fonts&#092;*.com<br />%systemroot%&#092;Fonts&#092;*.dll<br />%systemroot%&#092;Fonts&#092;*.ini<br />%systemroot%&#092;Fonts&#092;*.ini2<br />%systemroot%&#092;REPAIR&#092;*.bak1<br />%systemroot%&#092;REPAIR&#092;*.ini<br />%systemroot%&#092;system32&#092;*.jpg <br />%systemroot%&#092;*.jpg <br />%systemroot%&#092;*.png <br />%systemroot%&#092;*.scr<br />%systemroot%&#092;*._sy<br />%APPDATA%&#092;Adobe&#092;Update&#092;*.*<br />%ALLUSERSPROFILE%&#092;Favorites&#092;*.*<br />%APPDATA%&#092;Update&#092;*.*<br />%APPDATA%&#092;Microsoft&#092;*.*<br />%PROGRAMFILES%&#092;*.*<br />CREATERESTOREPOINT<br />%systemroot%&#092;*. /mp /s<br />%systemroot%&#092;system32&#092;*.dll /lockedfiles<br />%systemroot%&#092;Tasks&#092;*.job /lockedfiles<br />%systemroot%&#092;System32&#092;config&#092;*.sav <br />%PROGRAMFILES%&#092;*.<br />HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;WindowsUpdate&#092;Auto Update&#092;Results&#092;Install|LastSuccessTime /rs<br />HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Policies&#092;Microsoft&#092;Windows&#092;WindowsUpdate&#092;AU<br /></b><br /><br /></li><li>Click the <u>Quick Scan</u> button. Do not change any settings unless otherwise told to do so. The scan wont take long.<br /><ul><li>When the scan completes, it will open two notepad windows. <b>OTL.Txt</b> and <b>Extras.Txt</b>. These are saved in the same location as OTL.</li><li>Please copy <b>(Edit-&gt;Select All, Edit-&gt;Copy)</b> the contents of these files, one at a time</li></ul></li></ul><br /><br /><br />Download <a href="http://eric71.geekstogo.com/tools/Rooter.exe" target="_blank"><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->Rooter.exe<!--colorc--></span><!--/colorc--></b></a> to your desktop<ul><li>Then doubleclick it to start the tool</li><li>A Notepad file containing the report will open, also found at %systemdrive%&#092;Rooter.txt.</li></ul><br /><br /><br />Download <a href="http://jpshortstuff.247fixes.com/LockSearch.exe" target="_blank"><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><b>LockSearch</b><!--colorc--></span><!--/colorc--></a> to your desktop<br /><ul><li>A window will pop up, Press 2 and then Enter. A scan will start, let it run uninterrupted. It should only take a few minutes.</li><li>A log will appear when it is finished, it will also be saved in the same location as <!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><b>LockSearch</b><!--colorc--></span><!--/colorc-->, which should be on your desktop. Post the contents of the log in your reply</li></ul><br /><br /><br />Download <!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><b>CKScanner</b><!--colorc--></span><!--/colorc--> from <a href="http://downloads.malwareremoval.com/CKScanner.exe" target="_blank"><b>here</b></a><br /><br /><u><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->Important :<!--colorc--></span><!--/colorc--></b></u> Save it to your desktop.<br /><ul><li>Doubleclick CKScanner.exe and click <b>Search For Files</b>.</li><li>After a very short time, when the cursor hourglass disappears, click <b>Save List To File</b>.</li><li>A message box will verify that the file is saved.</li><li>Double-click the <b>CKFiles.txt</b> icon on your desktop and copy/paste the contents in your next reply.</li></ul><br /><br /><br /><ul><li>Please download WVCheck by Artellos from one of the mirrors below;<br /><blockquote><a href="http://artellos.com/ccount/click.php?id=7" target="_blank">Artellos.com (exe)</a><br /><a href="http://artellos.com/ccount/click.php?id=8" target="_blank">Artellos.com (zip)</a></blockquote></li><li>After the download, run WVCheck.exe</li><li>As indicated by the prompt, This program can take a while depending on your hard drive space.</li><li>Once the program is done, copy the contents of the notepad file into your topic.</li></ul><br /><br /><br /><br /><u><b>One final scan</b></u><br /><br />Download the <a href="http://www.gmer.net/gmer.zip" target="_blank"><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><b>GMER Rootkit Scanner</b><!--colorc--></span><!--/colorc--></a>. Unzip it to your Desktop.<br /><br /><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><b>Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.</b><!--colorc--></span><!--/colorc--><br /><ul><li> Double click GMER.exe.<br /><img src="http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif" border="0" class="linked-image" /></li><li> If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on <b>NO</b>, then use the following settings for a more complete scan.. </li><li> In the right panel, you will see several boxes that have been checked. Ensure the following are <b>UNCHECKED</b> ... <ul><li> IAT/EAT</li><li> Drives/Partition other than Systemdrive (typically C:&#092;) </li><li> Show All (don't miss this one)<br /><a href="http://www.geekstogo.com/misc/guide_icons/GMER_instructions.jpg" target="_blank"><img src="http://www.geekstogo.com/misc/guide_icons/GMER_thumb.jpg" border="0" class="linked-image" /></a> <br /><i>Click the image to enlarge it</i></li></ul></li><li> Then click the Scan button & wait for it to finish. </li><li> Once done click on the <b>[Save..]</b> button, and in the File name area, type in <b>"ark.txt"</b>  </li><li>Save the log where you can easily find it, such as your desktop.</li></ul><i>**Caution**<br />Rootkit scans often produce false positives. Do NOT take any action on any "&lt;--- ROOKIT" entries </i><br />Please copy and paste the report into your Post.<br /><br /><br /><br /><br />Then go to the Malware Removal forum <a href="http://www.atribune.org/forums/index.php?showforum=9" target="_blank"><b>here</b></a> and post your OTL log along <b>with the MBAM, Rooter, LockSearch, CKScanner, WVCheck, and GMER logs</b> in a topic there. If you know the name of your infection put this in your topic title. Please do not make multiple topics as this will waste helpers time, have some patience as your log will get handled eventually.<br /><br /><br /><br />If you haven't received a response in over three days, then go and post in <a href="http://www.atribune.org/forums/index.php?showforum=41" target="_blank"><b>The Waiting Room</b></a>, make sure to include a link to your original topic. <b>Do not</b> post HijackThis logs in your waiting room topic, they will just be removed.<br /><br /><br /><br /><br /><br />If you don't follow the steps in this topic and go straight to the Malware Removal forum, our first reply will be to send you back here. These steps are designed to help fix a lot of cases and get important things done from the start, it will save us all time.<br /><br /><br /><br />You will need to register to post on the forum:<ul><li><b><a href="http://www.atribune.org/forums/index.php?act=Reg&CODE=00" target="_blank">Register at Atribune.org</a></b></li><li><b><a href="http://www.atribune.org/forums/index.php?showforum=9" target="_blank">Post in the HiJackThis and Malware Removal Forum</a></b></li></ul><br /><br /><br /><b>Warning :</b><br /><br /><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><b>DO NOT</b><!--colorc--></span><!--/colorc--> follow advice from a topic other than your own. Other topics may have similar problems but please do NOT follow the advice given. Doing so will/can cause your PC some damage. ALL PC's have different situations. I cannot and will not stress this any more.<br /><br /><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><b>DO NOT</b><!--colorc--></span><!--/colorc--> run any tools used on the forum here unless instructed to by a helper, otherwise you may damage your PC !<br /><br /><br /><br />Regards<br /><br /><br />Atribune.org Staff]]></description>
		<pubDate>Wed, 17 Aug 2005 11:09:02 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=424</guid>
	</item>
	<item>
		<title>vundoo like symptoms - rootkit like activity</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5991</link>
		<description><![CDATA[Tuesday 9 Feb 2010 happily doing Google searches on Firefox 3.6. Stopped at 18:30 GMT to do a manual Windows Update on my SP2 partition. When that had finished re-booted into my SP3 partition and did a Windows Update. Re-booted to my SP2 partition and had symptoms best matched by the wiki entry for vundoo (redirect to ransomware list on wiki page and constant disk access causing explorer to crash). My SP3 partition showed symptoms the next day. After installing 7 to my software test disk (in caddy) it showed symptoms approximately 24 hours later also. <br /><br />I am not worried about the 7 install as it is only for software testing so would be re-formatted within the 30 day activation period to be replaced with various win 9x from ghost images, again for software testing (to ensure everything I write works correctly from 3.11 to 7).<br /><br />My ISP provides a free anti-virus/firewall package that updates automatically.<br /><br />The only time I have problems is when Windows Update forces me to use IE. This time Malware Bytes, SAS & Hijack This show nothing of note. <br /><br />As it matched vundoo I tried vundoofix :-<br />"VundoFix V7.0.6<br /><br />Scan started at 18:10:08 23/02/2010<br /><br />Listing files found while scanning....<br /><br />No infected files were found."<br /><br />I have followed your instructions ("http://www.atribune.org/forums/index.php?showtopic=424") on my SP3 partition (smallest footprint) and gathered logs as instructed before this post.<br /><br />However GMER 1.0.15.15281 had :-<br />SOFTWARE&#092;Classes&#092;InternetExplorerApplication<br />in the bottom pane for at least 2 hours so I have posted an incomplete log and will re-attempt after this post.]]></description>
		<pubDate>Sat, 27 Feb 2010 09:55:16 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5991</guid>
	</item>
	<item>
		<title>Preventing Malware and Safe Computing</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5342</link>
		<description><![CDATA[<!--sizeo:5--><span style="font-size:18pt;line-height:100%"><!--/sizeo--><b>Preventing Malware and Safe Computing</b><!--sizec--></span><!--/sizec--><br /><br /><br />The following are some valuable tips for maintaining a secure PC and ensuring that your PC will not get infected in the future.<br /><br /><br /><u><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo-->Backups :<!--sizec--></span><!--/sizec--><!--colorc--></span><!--/colorc--></b></u><br /><br /><br />It is extremely important that you make regular backups. Having these can make all the difference if your PC ever has a problem.<br /><br /><br /><b>Backup Your Registry with ERUNT</b><ul><li>Please use the following link and scroll down to ERUNT and download it.<br /><a href="http://aumha.org/freeware/freeware.php" target="_blank">http://aumha.org/freeware/freeware.php</a></li><li>For version with the Installer:<br />Use the setup program to install ERUNT on your computer</li><li>For the zipped version:<br />Unzip all the files into a folder of your choice.</li></ul>Click Erunt.exe to backup your registry to the folder of your choice.<br /><br />Note: <i><!--coloro:green--><span style="color:green"><!--/coloro-->to restore your registry, go to the folder and start <b>ERDNT.exe</b><!--colorc--></span><!--/colorc--></i><br /><br /><br /><br /><b>Now create a fresh system restore point</b><br /><br />Download <a href="http://www.dougknox.com/xp/utils/SysRestorePoint_v13.zip" target="_blank"><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->SysRestorePoint<!--colorc--></span><!--/colorc--></b></a> to your desktop and unzip it to it's own folder.<br /><ul><li>Double click SysRestorePoint.exe so that we can make a new system restore point.</li><li>A box will pop up after it has made a new point, usually after a few seconds. Close that window and exit the program.</li></ul><br /><br /><ul><li><a href="http://www.geekstogo.com/2008/06/19/options-for-home-computer-data-backup-part-1/" target="_blank"><b>Keep a backup of your important files</b></a> - Now, more than ever, it's especially important to protect your digital files and memories.  This article is full of good information on alternatives for home backup solutions.</li></ul><br /><br /><br />If you run Vista Premium, Business or Ultimate you have the ability to set automatic backups of your files.<br /><ul><li>Click <b><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->Start<!--colorc--></span><!--/colorc--></b> &gt; <b><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->All Programs<!--colorc--></span><!--/colorc--></b> &gt; <b><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->Accessories<!--colorc--></span><!--/colorc--></b> &gt; <b><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->System Tools<!--colorc--></span><!--/colorc--></b> &gt; <b><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->Backup Status and Configuration<!--colorc--></span><!--/colorc--></b></li><li>Click <b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->Back up files<!--colorc--></span><!--/colorc--></b>, and then follow the steps in the wizard.</li><li>Select where you want to back up to ... <i>another partition,hard drive, CD or DVD</i>.</li><li>Select which files you want to back up :<br /><br /><i>Pictures, Music, Videos, E-mail, Documents, etc</i><br /><br /></li><li>Select how often to back up:<br /><br /><i>Daily, Weekly or Monthly</i>.<br /><br /></li><li>Select the <i>day/time</i><br /><br />Then click on <b><!--coloro:#2E8B57--><span style="color:#2E8B57"><!--/coloro--><u>Save settings and Exit</u><!--colorc--></span><!--/colorc--></b>.</li></ul><br /><br /><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><u>To restore the files:</u><!--colorc--></span><!--/colorc--><br /><br />Click <b>Restore files</b> and then follow the steps in the wizard.<br /><br /><br /><b>Note</b>:<br />The ability to set up automatic backups is not included in Windows Vista Home Basic ; however, Windows will periodically remind you to back up your files. It is <b>NOT</b> recommended to backup to the same drive that your Operating System is located on.<br /><br /><br /><br /><br />Now if you ever have a PC problem, you should easily be able to restore your PC to a previous time.<br /><br /><br /><br /><u><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo-->Peer-to-Peer ( p2p ) programs :<!--sizec--></span><!--/sizec--><!--colorc--></span><!--/colorc--></b></u><br /><br /><br />Peer-to-peer programs, <b>eg : LimeWire, Bitlord, Kazaa</b>, are the most common way to get infected. Malware writers use these programs to spread infections as it is the easiest way for them. The majority of infections we see in the Malware Removal forum are due to people using p2p programs to download cracks/keygens/warez. These are not only illegal, but will always contain some form of malware.<br /><br />You have no way of verifying that the things you download are legitimate or that they don't contain malware. Even with an up to date anti-virus and firewall, these things will still infect you. It is highly recommend that you uninstall all peer-to-peer programs. It just isn't worth it.<br /><br /><br /><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><u>Note :</u><!--colorc--></span><!--/colorc--><br /><br />Other common ways of getting infected are dis-reputable sites forcing you to download and install a codec. Or viruses using Instant Messaging programs (msn, AIM) to send a file claiming it to be "photos" from a friend, only for it to turn out to be a virus.<br /><br /><br /><br /><u><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo-->Security Programs :<!--sizec--></span><!--/sizec--><!--colorc--></span><!--/colorc--></b></u><br /><br /><br />It is essential these days to have a few security programs installed and running on your machine. However, there are a few caveats, you should not install more than one anti-virus or firewall. This actually does more harm than good, and will cause a lot of issues for your PC.<br /><br /><ul><li>It is important to have a good anti-spyware program. We highly recommend <a href="http://www.malwarebytes.org/mbam.php" target="_blank"><b>MalwareBytes Anti-Malware</b></a> and <a href="http://www.superantispyware.com/" target="_blank"><b>SUPERAntiSpyware</b></a><br /><br /></li><li><a href="http://www.javacoolsoftware.com/sbdownload.html" target="_blank"><b><!--coloro:red--><span style="color:red"><!--/coloro-->SpywareBlaster<!--colorc--></span><!--/colorc--></b></a> protects against bad ActiveX, it immunizes your PC against them.<br /><br /></li><li><a href="http://www.javacoolsoftware.com/sgdownload.html" target="_blank"><b><!--coloro:red--><span style="color:red"><!--/coloro-->SpywareGuard<!--colorc--></span><!--/colorc--></b></a> offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.<br /><br /></li><li> Some good free firewalls are <a href="http://www.tallemu.com/free-firewall-protection-software.html" target="_blank"><b><!--coloro:red--><span style="color:red"><!--/coloro-->Online Armor<!--colorc--></span><!--/colorc--></b></a> or <a href="http://www.agnitum.com/products/outpostfree/index.php" target="_blank"><b><!--coloro:red--><span style="color:red"><!--/coloro-->Outpost<!--colorc--></span><!--/colorc--></b></a> or <a href="http://www.sunbeltsoftware.com/Home-Home-Office/Sunbelt-Personal-Firewall/" target="_blank"><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->Sunbelt Personal Firewall<!--colorc--></span><!--/colorc--></b></a>.<br />Make sure you only use one firewall though. A tutorial on understanding and using firewalls may be found <a href="http://www.bleepingcomputer.com/tutorials/tutorial60.html" target="_blank"><b>here</b></a>.<br /><br /></li><li> Here are some good anti-virus programs, make sure you only use one though :<br /><a href="http://www.free-av.com" target="_blank"><b>AntiVir</b></a> or <a href="http://www.avast.com/eng/avast_4_home.html" target="_blank"><b>avast!</b></a> or <a href="http://free.avg.com/download?prd=afe" target="_blank"><b>AVG</b></a>.</li></ul><br /><br />It is important to keep these programs up to date. I would recommend using them once every 10 days.<br /><br /><br /><br /><u><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo-->Internet Browsers :<!--sizec--></span><!--/sizec--><!--colorc--></span><!--/colorc--></b></u><br /><br /><br />Picking the right internet browser is very important. You need to find one that suits your needs but that is also safe.<br /><ul><li><b>Mozilla's Firefox</b> browser is fantastic, as is <b>Opera</b>. Both are far more secure than Internet Explorer, immune to almost all known browser hijackers, and also have the best built-in pop up blockers (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from <br /><a href="http://www.mozilla.org/products/firefox/" target="_blank"><b><!--coloro:red--><span style="color:red"><!--/coloro-->Here<!--colorc--></span><!--/colorc--></b></a><br /><br />While Opera can be downloaded from <a href="http://www.opera.com/" target="_blank"><b><!--coloro:red--><span style="color:red"><!--/coloro-->Here<!--colorc--></span><!--/colorc--></b></a>.</li></ul><br /><br />If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.<br /><ul><li><a href="https://addons.mozilla.org/en-US/firefox/addon/722" target="_blank"><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><b>NoScript</b><!--colorc--></span><!--/colorc--></a> - for blocking ads and other potential website attacks</li><li><a href="http://www.siteadvisor.com/download/ff_preinstall.html" target="_blank"><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><b>McAfee SiteAdvisor</b><!--colorc--></span><!--/colorc--></a> - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling</li></ul><br /><br /><br /><br /><br />Although, if you prefer staying with Internet Explorer I highly recommend you do this :<br /><br /><b><u>Make Internet Explorer more secure</u></b><br /><ul><li>Click <b>Start</b> &gt; <b>Run</b></li><li>Type <b>Inetcpl.cpl</b> & click <b>OK</b></li><li>Click on the <b>Security</b> tab</li><li>Click <b>Reset all zones to default level</b></li><li>Make sure the <b>Internet Zone</b> is selected & Click <b>Custom level</b></li><li>In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".</li><li>Next Click <b>OK</b>, then <b>Apply</b> button and then <b>OK</b> to exit the Internet Properties page.</li></ul><br /><br /><br /><u><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo-->Extras : <!--sizec--></span><!--/sizec--><!--colorc--></span><!--/colorc--></b></u><br /><br /><br />Below are a few more steps that we highly recommend<br /><br /><ul><li><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><b>OpenDNS</b><!--colorc--></span><!--/colorc--> is a very valuable feature that we <b><u>strongly endorse</u></b> here. It gives your PC the benefit of extra safety and increased browser speed. Enabling this takes hardly any time and is not complicated at all, even novice users will be able to set it up with the guide below.<br /><br />Another huge advantage of using OpenDNS is that it <!--coloro:#008000--><span style="color:#008000"><!--/coloro--><b>blocks phishing websites</b><!--colorc--></span><!--/colorc--> from loading on your computer. It uses data from Phishtank, a community site that is also used by Yahoo! Mail to determine if some particular website is part of any online phishing scam.<br /><br />To set this just have a look at the easy-to-use guide <a href="https://www.opendns.com/homenetwork/start/" target="_blank"><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><b>here</b><!--colorc--></span><!--/colorc--></a><br /><br /></li><li>There are certain programs that are security vulnerabilities, it is recommended that you keep everything updated. Two of the main vulnerabilities are <b>Java and Adobe Reader</b>. You can find the latest version of Java <a href="http://java.sun.com/javase/downloads/index.jsp" target="_blank"><b>here</b></a>, you will want the Java SE Runtime Environment (JRE) one. Make sure to uninstall all previous versions of Java as well since they can be exploited.<br /><br />You can also find the latest version of Adobe Reader <a href="http://www.adobe.com/products/acrobat/readstep2.html" target="_blank"><b>here</b></a><br /><br /><br /><u><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->Suggestion :<!--colorc--></span><!--/colorc--></u><br /><br />Foxit is a great <!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><u>free PDF alternative</u><!--colorc--></span><!--/colorc-->. It uses fewer system resources and is <b>not vulnerable to the exploits</b> affecting Adobe Reader. Providing full PDF functionality, Foxit is rapidly becoming the PDF reader of choice for many. Get it <a href="http://www.foxitsoftware.com/pdf/rd_intro.php" target="_blank"><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><b>here</b><!--colorc--></span><!--/colorc--></a><br /><br /></li><li>Keep Windows updated by regularly checking their website at :<br /><a href="http://windowsupdate.microsoft.com/" target="_blank">http://windowsupdate.microsoft.com/</a><br />This will ensure your computer has always the latest security updates available installed on your computer.<br /><br /></li><li><a href="http://oldtimer.geekstogo.com/TFC.exe" target="_blank"><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><b>TFC</b><!--colorc--></span><!--/colorc--></a> - Cleans temporary files from IE and Windows, empties the recycle bin and more.  Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.<br /><br /></li><li><a href="http://www.filehippo.com/updatechecker/FHsetup.exe" target="_blank"><!--coloro:#8B0000--><span style="color:#8B0000"><!--/coloro--><b>FileHippo Update Checker</b><!--colorc--></span><!--/colorc--></a> is an extremely helpful program that will tell you which of your programs need to be updated. Its important to <!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><u><b>keep programs up to date</b></u><!--colorc--></span><!--/colorc--> so that malware doesn't exploit any old security flaws.<br /><br /></li><li><b><!--coloro:Blue--><span style="color:Blue"><!--/coloro--> <u>Recovery Console</u><!--colorc--></span><!--/colorc--></b> - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the <b>Recovery Console</b> in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see <a href="http://support.microsoft.com/kb/307654" target="_blank"><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><b>This Article</b><!--colorc--></span><!--/colorc--></a>. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.</li></ul><br /><br /><u><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo-->Advanced Tips :<!--sizec--></span><!--/sizec--><!--colorc--></span><!--/colorc--></b></u><br /><br /><br />The following suggestions are considered to be rather complicated for the average user, so I only recommend them if you know what you are doing or have a desire to learn more complicated procedures. A few of these programs listed below are paid products, I have tried to use free alternatives but it hasn't always been possible.<br /><br />I have also tried to link to tutorials for each of the tools recommended. This tutorial is not to answer questions on how to use them<br /><br /><br /><b><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro--><u>Image Backups </u><!--colorc--></span><!--/colorc--></b><br /><br />What is an image backup ? To put it simply, it will back up all your data into a single file, including system and registry data, allowing you to do an easy, fast, and complete PC restore should your computer ever crash. <br /><br />Here are some suggestions<br /><br /><a href="http://www.runtime.org/driveimage-xml.htm" target="_blank"><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><b>DriveImage</b><!--colorc--></span><!--/colorc--></a> ( my personal recommendation, it is also free )<br /><a href="http://www.acronis.com/homecomputing/products/trueimage/" target="_blank"><b><!--coloro:#A0522D--><span style="color:#A0522D"><!--/coloro-->Acronis<!--colorc--></span><!--/colorc--></b></a><br /><a href="http://www.macrium.com/" target="_blank"><!--coloro:#000000--><span style="color:#000000"><!--/coloro--><b>Macrium Reflect</b><!--colorc--></span><!--/colorc--></a><br /><br /><br /><br /><b><u><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->Limited User Account<!--colorc--></span><!--/colorc--></u></b><br /><br />Using a Limited User Account can help decrease the effect of malware and other potential damaging things for your PC. A Limited User account lets you use most of the capabilities of the computer, but only an Administrator can make changes that affect other users of the computer.<br /><br />Have a read of the following article for more detailed instructions on how to go about setting it up<br /><br /><a href="http://www.microsoft.com/protect/computer/advanced/useraccount.mspx" target="_blank"><b>Click</b></a><br /><br /><br /><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro--><u>Tip :</u><!--colorc--></span><!--/colorc--> This sort of account would be very beneficial to use among any children in your family, or among those who are not comp savvy that have access to your PC.<br /><br /><br /><br /><b><u><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->DropMyRights<!--colorc--></span><!--/colorc--></u></b><br /><br />The following program is only for use on on <b>Windows XP</b> machines, this tool is not needed on Windows Vista or Windows Server 2008, because by default users are not administrators.<br /><br />It can be downloaded from <a href="http://download.cnet.com/DropMyRights/3000-2144_4-10722877.html" target="_blank"><b>here</b></a><br /><br /><br />This program greatly increases the security of Windows XP by <i>running selected programs in a restricted environment</i> ( i.e. with lower rights ) even when logged on to Windows XP as an Administrator. It simply blocks them from performing certain security-breaking functions.<br /><br /><br />You can find a guide here on how to use it <a href="http://www.techsupportalert.com/safe-surfing.php#c" target="_blank"><!--coloro:#A0522D--><span style="color:#A0522D"><!--/coloro--><b>here</b><!--colorc--></span><!--/colorc--></a><br /><br /><br /><br /><b><u><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->Sandbox Programs<!--colorc--></span><!--/colorc--></u></b><br /><br />One of the <b>best forms of protection</b> that you can use for your PC is a sandbox program. In laymans terms, what they do is let you install and run programs in a virtual environment, so any changes made will happen in the virtual environment and not in the real PC. <br /><br />So if your PC was to get infected by a piece of malware while in this virtual setting, or anything else that may damage the machine, all you have to do is close this virtual session, reboot the PC, and it will be back to normal. <br /><br /><br />Here are some sandbox programs that I recommend<br /><br /><a href="http://www.returnilvirtualsystem.com/" target="_blank"><b><!--coloro:#A0522D--><span style="color:#A0522D"><!--/coloro-->Returnil<!--colorc--></span><!--/colorc--></b></a><br /><a href="http://www.sandboxie.com/" target="_blank"><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->Sandboxie<!--colorc--></span><!--/colorc--></b></a><br /><br /><br /><br /><b><u><!--coloro:#0000FF--><span style="color:#0000FF"><!--/coloro-->HIPS<!--colorc--></span><!--/colorc--></u></b><br /><br />These programs <i>may conflict with your other security protection programs</i>. If this is the case ( ie : you notice massive slow down or BSODs ) then uninstall them.<br /><br /><br />HIPS ( <b>Host Based Intrusion Prevention System</b> ) is considered as one the best steps in protecting your PC. What these programs do are prevent changes made to your PC by unauthorised sources. It allows you to very closely monitor what runs on your PC.<br /><br />Here are some recommendations<br /><br /><a href="http://diamondcs.com.au/processguard/" target="_blank"><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->ProcessGuard<!--colorc--></span><!--/colorc--></b></a><br /><a href="http://www.threatfire.com/" target="_blank"><b><!--coloro:#A0522D--><span style="color:#A0522D"><!--/coloro-->Threatfire<!--colorc--></span><!--/colorc--></b></a> ( there is a tutorial located in this link as well )<br /><a href="http://www.drivesentry.com/" target="_blank"><b><!--coloro:#000000--><span style="color:#000000"><!--/coloro-->DriveSentry<!--colorc--></span><!--/colorc--></b></a> ( this is a firewall so it will conflict with other firewalls )<br /><br /><br />Now after all these steps, your PC will be extremely secure. However it is important to note that you can still get infected if you are not careful. One of the best security programs you can have is common sense. As malware gets more sophisticated, you need to be more wary. If you do get caught though and the above steps cant help fix it, we will be here to help you out<br /><br /><br /><u>Regards</u><br /><br /><b>The Atribune.org Team</b>]]></description>
		<pubDate>Fri, 16 Jan 2009 20:17:50 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5342</guid>
	</item>
	<item>
		<title>Would you like to learn to fight malware ?</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5185</link>
		<description><![CDATA[Are you interested in joining the fight against malware ? Below is a list of free online schools where you can learn such skills and help give back to the community. It is important to note that <b>there is a lot of work and learning</b> involved, but as long as you have the <u>desire and are in it for the long haul</u>, you will be able to get through it.<br /><br />It is preferable to have some computer knowledge but is <b>not essential</b>. The training is a steady progress so you wont be dropped into the deep end straight away.<br /><br />Students that complete training are expected to <i>"pay it forward"</i> by assisting in the forums, where they can continue to keep abreast of evolving malware and removal techniques. <br /><br /><br /><u><b><!--coloro:#FF0000--><span style="color:#FF0000"><!--/coloro-->Note :<!--colorc--></span><!--/colorc--></b></u> You should not enroll in more than one school at the start as you will find it a lot of work.<br /><br />The list of schools is below<br /><ul><li><a href="http://www.geekstogo.com/forum/Would-you-like-to-learn-to-fight-malware-t4817.html" target="_blank"><b>GeekU</b></a></li><li><a href="http://www.malwareremoval.com/forum/viewtopic.php?t=233" target="_blank"><b>Malware Removal University</b></a></li><li><a href="http://www.247fixes.com/forums/topic/4215-would-you-like-to-learn-how-to-fight-malware/" target="_blank"><b>247 Academy</b></a></li></ul><br /><br /><br />Good luck !]]></description>
		<pubDate>Fri, 26 Dec 2008 17:30:31 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5185</guid>
	</item>
	<item>
		<title>Tried Vundofix..But no luck..PLz help</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5183</link>
		<description><![CDATA[Hi,<br /><br />My laptop is infected with Vundo virus and the dll is created in system32 folder under the name KhfgFxyw.dll. I scanned the system using McAfee and it was unable to clean it. Now my automatic updates is showing turned off warnings but when i go to control panel it still shows ON. Some random ad sites are popping up and opening in IE every now and then. Thats when i tried vundofix. It scanned my laptop and showed a message that No infected files were found. But the dll is still present in system32 folder, McAfee still detects it as Vundo . Please help.<br />I have a very important assignment coming up and need to work on my laptop and this virus is driving me crazy. Please help.<br /><br />Screenshot attached.<br /><br />Thanks.Gouri <br />]]></description>
		<pubDate>Fri, 26 Dec 2008 09:54:41 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5183</guid>
	</item>
</channel>
</rss>