Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

PC keeps freezing modem

  • 13-01-2008 6:39pm
    #1
    Registered Users, Registered Users 2 Posts: 3,944 ✭✭✭


    Problem started last week. My broadband connection is fine on my mac and GF's laptop. Once I connect it to my PC, the broadband connection seems to stop responding after a minute or two. All the lights are on my modem (power, dsl, internet and ethernet) so in theory everything is still working. When it freezes every other computer in the house can't get anything from the broadband connection. I can't even connect to the modems IP address to see if the connection is there or not.
    I did get a virus/malware last week but I've run antivirus and updates, ran Spybot S&D (all updates done through dial up unfortunately) and anything that was found was removed and fixed. The problem is still there. Could this be a virus or hardware issue?

    Any help appreiated.

    Pete.


Comments

  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Lets see if it is a malware issue

    Please download Deckard's System Scanner (DSS) and save it to your Desktop.
    • Close all other windows before proceeding.
    • Double-click on dss.exe and follow the prompts.
    • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
    • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.


  • Registered Users, Registered Users 2 Posts: 3,944 ✭✭✭pete4130


    Thanks Actorseeksjob,

    I ran that DSS software and these are the results....I hope you can tell me whats up!

    Thanks,

    Pete.






    Main:

    Deckard's System Scanner v20071014.68

    Run by PETER on 2008-01-13 22:00:30

    Computer is in Normal Mode.




    -- System Restore



    Successfully created a Deckard's System Scanner Restore Point.





    -- Last 5 Restore Point(s) --

    23: 2008-01-13 22:00:49 UTC - RP1583 - Deckard's System Scanner Restore Point

    22: 2008-01-13 19:19:40 UTC - RP1582 - Configured AVG 7.5

    21: 2008-01-13 18:58:55 UTC - RP1581 - Spybot-S&D Spyware removal

    20: 2008-01-13 17:27:23 UTC - RP1580 - Spybot-S&D Spyware removal

    19: 2008-01-13 13:56:49 UTC - RP1579 - Restore Operation





    -- First Restore Point --

    1: 2008-01-06 19:48:10 UTC - RP1561 - System Checkpoint





    Backed up registry hives.

    Performed disk cleanup.



    System Drive C: has 3.65 GiB (less than 15%) free.





    -- HijackThis Clone





    Emulating logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 2008-01-13 22:06:24

    Platform: Windows XP Service Pack 2 (5.01.2600)

    MSIE: Internet Explorer (7.00.5730.13)

    Boot mode: Normal



    Running processes:

    C:\WINDOWS\SYSTEM32\smss.exe

    C:\WINDOWS\SYSTEM32\winlogon.exe

    C:\WINDOWS\SYSTEM32\services.exe

    C:\WINDOWS\SYSTEM32\lsass.exe

    C:\WINDOWS\SYSTEM32\svchost.exe

    C:\WINDOWS\SYSTEM32\svchost.exe

    C:\WINDOWS\explorer.exe

    C:\WINDOWS\SYSTEM32\spoolsv.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE

    C:\WINDOWS\SYSTEM32\lxdlcoms.exe

    C:\WINDOWS\SYSTEM32\nvsvc32.exe

    C:\WINDOWS\SYSTEM32\svchost.exe

    C:\WINDOWS\SYSTEM32\svchost.exe

    C:\WINDOWS\BCMSMMSG.exe

    C:\WINDOWS\SYSTEM32\rundll32.exe

    C:\WINDOWS\SYSTEM32\rundll32.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe

    C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Grisoft\AVG7\avgamsvr.exe

    C:\Program Files\Grisoft\AVG7\avgemc.exe

    C:\Program Files\Grisoft\AVG7\avgupsvc.exe

    C:\Program Files\Grisoft\AVG7\avgcc.exe

    C:\Documents and Settings\PETER\Desktop\dss.exe



    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/ie/enu/gen/default.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/ie/enu/gen/default.htm

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com

    R3 - Default URLSearchHook is missing

    O2 - BHO: (no name) - {01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C} - C:\WINDOWS\system32\gebyv.dll (file missing)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: {8466eebe-9748-d75a-ef94-a0a206174b47} - {74b47160-2a0a-49fe-a57d-8479ebee6648} - C:\WINDOWS\system32\nxkjjmqv.dll (file missing)

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)

    O2 - BHO: (no name) - {FA16FE06-B462-470E-9653-79C54B1871FF} - C:\WINDOWS\system32\urqrsqp.dll (file missing)

    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe

    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

    O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe 1

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [KKqc] C:\WINDOWS\lalhmqvw.exe

    O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray

    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe

    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [lxdlmon.exe] "C:\Program Files\Lexmark 7500 Series\lxdlmon.exe"

    O4 - HKLM\..\Run: [lxdlamon] "C:\Program Files\Lexmark 7500 Series\lxdlamon.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe

    O4 - HKCU\..\Run: [mfmk] C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe

    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray

    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"

    O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s

    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')

    O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe

    O4 - Global Startup: Sitecom Wireless Utility.lnk = ?

    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm

    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll

    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll

    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O10 - Unknown file in Winsock LSP: C:\WINDOWS\SYSTEM32\nwprovau.dll

    O16 - DPF: Yahoo! Checkers () - http://download.games.yahoo.com/games/clients/y/kt3_x.cab

    O16 - DPF: Yahoo! Pool 2 () - http://download.games.yahoo.com/games/clients/y/pote_x.cab

    O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} () - http://www.thepaymentcentre.com/build/preload.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} () - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

    O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab

    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll

    O20 - Winlogon Notify: OemStartMenuData - C:\WINDOWS\system32\jr4025hmg.dll (file missing)

    O20 - Winlogon Notify: urqrsqp - C:\WINDOWS\system32\urqrsqp.dll (file missing)

    O20 - Winlogon Notify: wineij32 - C:\WINDOWS\system32\wineij32.dll (file missing)

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe

    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe

    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe

    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe

    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE

    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: lxdl_device - Unknown owner - C:\WINDOWS\SYSTEM32\lxdlcoms.exe

    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\SYSTEM32\nvsvc32.exe

    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    O24 - Desktop Component 0: - http://www.welsh-costume.co.uk/images/welsh-folk.jpg



    --

    End of file - 13141 bytes



    -- File Associations



    .scr - MicroStation Resource - shell\open\command - unable to read value





    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled



    R0 agp440 (Intel AGP Bus Filter) - c:\windows\\systemroot\system32\drivers\agp440.sys (file missing)

    R0 BTHidMgr (Bluetooth HID Manager Service) - c:\windows\system32\drivers\bthidmgr.sys <Not Verified; IVT Corporation; BlueSoleil(c)>

    R0 IABFilt (Iomega Snapshot Volume Filter) - c:\windows\system32\drivers\iabfilt.sys <Not Verified; Iomega; Iomega Volume Filter Driver>

    R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>

    R3 BlueletAudio (Bluetooth Audio Service) - c:\windows\system32\drivers\blueletaudio.sys <Not Verified; IVT Corporation; Windows (R) 2000 DDK driver>

    R3 Btcsrusb (Bluetooth USB For Bluetooth Service) - c:\windows\system32\drivers\btcusb.sys <Not Verified; IVT Corporation; Bluetooth USB Device Driver>

    R3 BTHidEnum (Bluetooth HID Enumerator) - c:\windows\system32\drivers\vbtenum.sys

    R3 VComm (Virtual Serial port driver) - c:\windows\system32\drivers\vcomm.sys <Not Verified; IVT Corporation; BlueSoleil>

    R3 VcommMgr (Bluetooth VComm Manager Service) - c:\windows\system32\drivers\vcommmgr.sys <Not Verified; IVT Corporation; BlueSoleil>



    S3 BT (Bluetooth PAN Network Adapter) - c:\windows\system32\drivers\btnetdrv.sys <Not Verified; IVT Corporation; BlueSoleil>

    S3 BTNetFilter (Bluetooth Network Filter) - c:\windows\system32\drivers\btnetfilter.sys

    S3 iAimTV2 - c:\windows\system32\drivers\watv03nt.sys (file missing)

    S3 MA-620 (Mobile Action MA-620 USB Infrared Adapter) - c:\windows\system32\drivers\ma-620.sys <Not Verified; Mobile Action Tech. Inc.; MA-620 Infrared Driver.>





    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled



    R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>

    R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>



    S2 BlueSoleil Hid Service - c:\program files\ivt corporation\bluesoleil\btntservice.exe (file missing)

    S2 FCI - c:\windows\system32\svchost.exe:ext.exe (file missing)

    S3 Adobe Version Cue CS3 - "c:\program files\common files\adobe\adobe version cue cs3\server\bin\versioncuecs3.exe" -win32service (file missing)

    S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>





    -- Device Manager: Disabled



    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

    Description: Bluetooth PAN Network Adapter

    Device ID: ROOT\NET\0000

    Manufacturer: IVT Corporation

    Name: Bluetooth PAN Network Adapter

    PNP Device ID: ROOT\NET\0000

    Service: BT





    -- Scheduled Tasks



    2008-01-08 22:19:04 284 --a
    C:\WINDOWS\Tasks\AppleSoftwareUpdate.job





    -- Files created between 2007-12-13 and 2008-01-13



    2008-01-13 19:19:40 0 d
    C:\Documents and Settings\All Users\Application Data\Grisoft

    2008-01-12 17:07:01 0 d
    C:\WINDOWS\network diagnostic

    2008-01-12 10:12:25 0 d
    C:\Program Files\NAV virus software

    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Equalizer

    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\All Users\Application Data\External Build System

    2008-01-11 22:39:24 0 d
    C:\Documents and Settings\All Users\Application Data\Bubble Noise

    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Application

    2008-01-11 17:53:02 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT

    2008-01-11 17:53:02 0 d
    C:\Documents and Settings\All Users\Application Data\Guitars

    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\All Users\Application Data\Audio Unit Effect

    2008-01-11 17:17:09 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT

    2008-01-06 00:04:53 0 dr-h
    C:\$VAULT$.AVG

    2008-01-05 13:19:24 0 d
    C:\Documents and Settings\PETER\Application Data\AVG7

    2008-01-05 13:18:37 0 d
    C:\Documents and Settings\LocalService\Application Data\AVG7

    2008-01-04 23:37:14 0 d
    C:\Program Files\Helper

    2008-01-04 22:29:01 84665 --ahs---- C:\WINDOWS\system32\vybeg.ini2

    2008-01-04 22:24:38 2 --a
    C:\-2006240221

    2008-01-04 16:42:13 204288 --a
    C:\WINDOWS\system32\pmtf3.dll

    2008-01-04 16:42:13 353280 --a
    C:\WINDOWS\system32\pmtf2.dll

    2008-01-04 16:42:13 205824 --a
    C:\WINDOWS\system32\pmtf1.dll

    2008-01-04 16:42:13 53248 --a
    C:\WINDOWS\system32\pmexr.dll

    2008-01-04 16:42:13 11776 --a
    C:\WINDOWS\system32\pmbm.dll

    2008-01-04 16:42:13 95525 --a
    C:\WINDOWS\system32\Photomatix25Lib3.dll

    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\Photomatix25Lib2.dll

    2008-01-04 16:42:13 278528 --a
    C:\WINDOWS\system32\Photomatix25Lib.dll

    2008-01-04 16:42:13 446464 --a
    C:\WINDOWS\system32\Photomatix_jpg.dll

    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\lcms.dll <Not Verified; Marti Maria; LittleCMS color engine>

    2008-01-04 16:42:13 782336 --a
    C:\WINDOWS\system32\IlmImf.dll

    2008-01-04 16:42:12 0 d
    C:\Program Files\Photomatix

    2007-12-19 14:19:18 38400 --a
    C:\WINDOWS\wl.exe <Not Verified; AMF; WinLock>

    2007-12-19 14:13:52 73216 --a
    C:\WINDOWS\WinLockDll.dll <Not Verified; AMF; WinLock>





    -- Find3M Report



    2008-01-13 19:17:02 0 d
    C:\Program Files\Common Files\Symantec Shared

    2008-01-13 19:15:54 12 --a
    C:\WINDOWS\bthservsdp.dat

    2008-01-12 18:03:44 0 d
    C:\Program Files\Nikon

    2008-01-12 11:59:52 0 d
    C:\Program Files\Common Files

    2008-01-11 22:31:44 0 d
    C:\Program Files\Common Files\Nikon

    2008-01-11 20:54:25 0 d
    C:\Documents and Settings\PETER\Application Data\Nikon

    2008-01-06 18:59:04 0 d
    C:\Program Files\iTunes

    2008-01-04 22:35:26 0 d
    C:\Program Files\Lexmark 7500 Series

    2008-01-04 22:35:25 0 d
    C:\Program Files\QuickTime

    2008-01-04 21:47:02 0 d
    C:\Program Files\Soulseek

    2008-01-02 09:44:04 0 d
    C:\Documents and Settings\PETER\Application Data\Adobe

    2007-12-21 14:58:56 0 d
    C:\Program Files\Common Files\Adobe

    2007-12-18 17:24:28 0 d
    C:\Documents and Settings\PETER\Application Data\Canon

    2007-12-12 21:13:15 0 d
    C:\Documents and Settings\PETER\Application Data\Skype

    2007-12-11 23:01:08 118 --a
    C:\WINDOWS\otstuk.bat

    2007-12-08 23:21:55 4615 --a
    C:\WINDOWS\mozver.dat

    2007-12-03 21:28:15 0 d--h
    C:\Program Files\InstallShield Installation Information

    2007-12-03 19:53:36 0 d
    C:\Documents and Settings\PETER\Application Data\Creative

    2007-12-03 19:04:50 0 d--h
    C:\Program Files\Creative Installation Information

    2007-12-03 19:03:40 0 d
    C:\Program Files\Creative

    2007-12-03 19:03:27 0 d
    C:\Program Files\Common Files\Creative

    2007-11-25 22:44:29 0 d
    C:\Documents and Settings\PETER\Application Data\AdobeUM

    2007-11-21 23:26:27 0 d
    C:\Program Files\FLVPlayer





    -- Registry Dump



    *Note* empty entries & legit default entries are not shown





    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C}]

    C:\WINDOWS\system32\gebyv.dll



    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74b47160-2a0a-49fe-a57d-8479ebee6648}]

    C:\WINDOWS\system32\nxkjjmqv.dll



    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA16FE06-B462-470E-9653-79C54B1871FF}]

    C:\WINDOWS\system32\urqrsqp.dll



    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/06/2007 23:43]

    "BCMSMMSG"="BCMSMMSG.exe" [29/08/2003 03:59 C:\WINDOWS\BCMSMMSG.exe]

    "DVDSentry"="C:\WINDOWS\System32\DSentry.exe" []

    "Tray Temperature"="C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe" []

    "nwiz"="nwiz.exe" [28/06/2007 23:43 C:\WINDOWS\SYSTEM32\nwiz.exe]

    "KKqc"="C:\WINDOWS\lalhmqvw.exe" []

    "DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" []

    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []

    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe" []

    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []

    "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" []

    "LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []

    "LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" []

    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [28/06/2007 23:43]

    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" []

    "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" []

    "@=" []

    "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" []

    "BluetoothAuthenticationAgent"="bthprops.cpl" [04/08/2004 07:56 C:\WINDOWS\SYSTEM32\bthprops.cpl]

    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [26/09/2007 14:42]

    "lxdlmon.exe"="C:\Program Files\Lexmark 7500 Series\lxdlmon.exe" []

    "lxdlamon"="C:\Program Files\Lexmark 7500 Series\lxdlamon.exe" []

    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" []

    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [13/01/2008 19:19]

    "avp"="C:\WINDOWS\avp.exe" []



    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "mfmk"="C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe" []

    "Steam"="" []

    "BitComet"="C:\Program Files\BitComet\BitComet.exe" []

    "CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" []

    "MtdAcqu"="C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" []

    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [04/01/2008 17:21]



    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]

    @=C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8



    C:\Documents and Settings\PETER\Start Menu\Programs\Startup\

    DESKTOP.INI [03/09/2002 08:00:00]



    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [21/10/2007 18:42:58]

    DESKTOP.INI [03/09/2002 08:00:00]

    Sitecom Wireless Utility.lnk - C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE [22/09/2007 22:32:19]



    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

    "{FA16FE06-B462-470E-9653-79C54B1871FF}"= C:\WINDOWS\system32\urqrsqp.dll [ ]



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OemStartMenuData]

    C:\WINDOWS\system32\jr4025hmg.dll



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqrsqp]

    urqrsqp.dll



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineij32]

    wineij32.dll



    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    "Authentication Packages"= msv1_0 C:\WINDOWS\system32\gebyv



    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]

    @=&quot;Service"



    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

    @=&quot;Volume shadow copy"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk

    backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk

    backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk

    backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^PETER^Start Menu^Programs^Startup^Iomega Product Registration.lnk]

    path=C:\Documents and Settings\PETER\Start Menu\Programs\Startup\Iomega Product Registration.lnk

    backup=C:\WINDOWS\pss\Iomega Product Registration.lnkStartup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]

    "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]

    "C:\Program Files\BitComet\BitComet.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iHP-100]

    C:\Program Files\iRiver\iHP100\iHPDetect.exe



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

    "C:\Program Files\iTunes\iTunesHelper.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]

    "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

    "C:\Program Files\QuickTime\qttask.exe" -atboottime



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

    "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

    C:\Program Files\Valve\Steam\\Steam.exe -silent



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]

    "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    bthsvcs BthServ





    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f99e6cd-2318-11dc-95f9-0007e95394b1}]

    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe



    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4bd4798-7d74-11dc-964b-000cf6315d28}]

    Auto\command- G:\AdobeR.exe e

    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e









    -- Hosts



    127.0.0.1 www.007guard.com

    127.0.0.1 007guard.com

    127.0.0.1 008i.com

    127.0.0.1 www.008k.com

    127.0.0.1 008k.com

    127.0.0.1 www.00hq.com

    127.0.0.1 00hq.com

    127.0.0.1 010402.com

    127.0.0.1 www.032439.com

    127.0.0.1 032439.com



    7845 more entries in hosts file.





    -- End of Deckard's System Scanner: finished at 2008-01-13 22:07:23


    Extra:



    Deckard's System Scanner v20071014.68

    Extra logfile - please post this as an attachment with your post.




    -- System Information



    Microsoft Windows XP Home Edition (build 2600) SP 2.0

    Architecture: X86; Language: English



    CPU 0: Intel(R) Pentium(R) 4 CPU 2.40GHz

    Percentage of Memory in Use: 54%

    Physical Memory (total/avail): 767 MiB / 345.41 MiB

    Pagefile Memory (total/avail): 1492.34 MiB / 1168.6 MiB

    Virtual Memory (total/avail): 2047.88 MiB / 1933.55 MiB



    A: is Removable (No Media)

    C: is Fixed (NTFS) - 111.72 GiB total, 3.65 GiB free.

    D: is Removable (No Media)

    E: is CDROM (No Media)

    F: is CDROM (No Media)

    G: is Removable (FAT)



    \\.\PHYSICALDRIVE1 - IOMEGA ZIP 250



    \\.\PHYSICALDRIVE0 - WDC WD1200JB-75CRA0 - 111.76 GiB - 2 partitions

    \PARTITION0 - Unknown - 39.19 MiB

    \PARTITION1 (bootable) - Installable File System - 111.72 GiB - C:



    \\.\PHYSICALDRIVE2 - LEXAR DIGITAL FILM USB Device - 54.91 MiB - 1 partition

    \PARTITION0 (bootable) - MS-DOS V4 Huge - 61.42 MiB - G:







    -- Security Center



    AUOptions is scheduled to auto-install.

    Windows Internal Firewall is enabled.



    AntiVirusDisableNotify is set.

    FirewallDisableNotify is set.



    AV: AVG 7.5.503 v7.5.503 (Grisoft)



    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"

    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"

    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"



    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\Kazaa Lite\\KazaaLite.kpp"="C:\\Program Files\\Kazaa Lite\\KazaaLite.kpp:*:Enabled:Kazaa Lite"

    "C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:WindowsÆ NetMeetingÆ"

    "C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"

    "C:\\Documents and Settings\\PETER\\Local Settings\\Temp\\I1106757523\\Windows\\NavDiag.exe"="C:\\Documents and Settings\\PETER\\Local Settings\\Temp\\I1106757523\\Windows\\NavDiag.exe:*:Disabled:LaunchAnywhere GUI"

    "C:\\Program Files\\NavDiag\\Navini Diagnostics.exe"="C:\\Program Files\\NavDiag\\Navini Diagnostics.exe:*:Disabled:LaunchAnywhere GUI"

    "C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"

    "C:\\Documents and Settings\\PETER\\Local Settings\\Temp\\I1106933393\\Windows\\NavDiag.exe"="C:\\Documents and Settings\\PETER\\Local Settings\\Temp\\I1106933393\\Windows\\NavDiag.exe:*:Disabled:LaunchAnywhere GUI"

    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:YServer Module"

    "C:\\Program Files\\Valve\\Steam\\Steam.exe"="C:\\Program Files\\Valve\\Steam\\Steam.exe:*:Enabled:Steam"

    "C:\\Program Files\\Valve\\Steam\\SteamApps\\pete4130\\counter-strike source\\hl2.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\pete4130\\counter-strike source\\hl2.exe:*:Enabled:hl2"

    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"

    "C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"

    "C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"="C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE"

    "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"

    "C:\\Program Files\\Valve\\Steam\\SteamApps\\pete4130\\half-life 2\\hl2.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\pete4130\\half-life 2\\hl2.exe:*:Enabled:hl2"

    "C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire"

    "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"

    "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

    "C:\\Program Files\\Electronic Arts\\Battlefield 2142 Demo\\BF2142.exe"="C:\\Program Files\\Electronic Arts\\Battlefield 2142 Demo\\BF2142.exe:*:Enabled:Battlefield 2"

    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"

    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    "C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"="C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe:*:Enabled:Adobe Version Cue CS3 Server"

    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"

    "C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil"

    "C:\\WINDOWS\\SYSTEM32\\lxdlcoms.exe"="C:\\WINDOWS\\SYSTEM32\\lxdlcoms.exe:*:Enabled:Lexmark Communications System"

    "C:\\Program Files\\Lexmark 7500 Series\\lxdlmon.exe"="C:\\Program Files\\Lexmark 7500 Series\\lxdlmon.exe:*:Enabled:Printer Device Monitor"

    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

    "C:\\DOCUME~1\\PETER\\LOCALS~1\\Temp\\win22C.exe"="C:\\DOCUME~1\\PETER\\LOCALS~1\\Temp\\win22C.exe:*:Enabled:win22C"

    "C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:svchost"

    "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"

    "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"

    "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"

    "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"

    "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

    "C:\\Program Files\\Nikon\\Capture NX\\Capture NX.exe"="C:\\Program Files\\Nikon\\Capture NX\\Capture NX.exe:*:Enabled:Capture NX"





    -- Environment Variables



    ALLUSERSPROFILE=C:\Documents and Settings\All Users

    APPDATA=C:\Documents and Settings\PETER\Application Data

    CLASSPATH=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip

    CLIENTNAME=Console

    CommonProgramFiles=C:\Program Files\Common Files

    COMPUTERNAME=FAMILY2

    ComSpec=C:\WINDOWS\system32\cmd.exe

    FP_NO_HOST_CHECK=NO

    HOMEDRIVE=C:

    HOMEPATH=\Documents and Settings\PETER

    LOGONSERVER=\\FAMILY2

    NUMBER_OF_PROCESSORS=1

    OS=Windows_NT

    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Adaptec Shared\System;C:\Program Files\QuickTime\QTSystem\

    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH

    PROCESSOR_ARCHITECTURE=x86

    PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel

    PROCESSOR_LEVEL=15

    PROCESSOR_REVISION=0209

    ProgramFiles=C:\Program Files

    PROMPT=$P$G

    QTJAVA=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip

    SESSIONNAME=Console

    SystemDrive=C:

    SystemRoot=C:\WINDOWS

    TEMP=C:\DOCUME~1\PETER\LOCALS~1\Temp

    TMP=C:\DOCUME~1\PETER\LOCALS~1\Temp

    USERDOMAIN=FAMILY2

    USERNAME=PETER

    USERPROFILE=C:\Documents and Settings\PETER

    windir=C:\WINDOWS





    -- User Profiles



    PETER (admin)

    Administrator (new local, admin)

    Guest (guest)





    -- Add/Remove Programs



    --> "C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009

    --> "C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009

    --> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x0009

    --> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /l0x0009

    --> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_NOMADJUKEBOXTYPE2_U\Setup.exe" /remove /l0x0009

    --> "C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009

    --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

    --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu

    --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\System32\UninstIPP.isu

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1888DAFD-C634-4BC4-865C-3455E24F6177}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1888DAFD-C634-4BC4-865C-3455E24F6177}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3C080B57-0D1E-4C73-B03B-68A9EF9F23F3}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3C080B57-0D1E-4C73-B03B-68A9EF9F23F3}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDC05F7-83E4-4611-AD3C-A6EB2100332A}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDC05F7-83E4-4611-AD3C-A6EB2100332A}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{869D88A5-BD6C-4E39-8536-D95259EAD7E8}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{869D88A5-BD6C-4E39-8536-D95259EAD7E8}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{881A74B3-3D17-4842-B9AF-0761C6E6C4B5}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{881A74B3-3D17-4842-B9AF-0761C6E6C4B5}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B5BAAFAE-3561-463D-8E3F-91761A57ADB8}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B5BAAFAE-3561-463D-8E3F-91761A57ADB8}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD549B7B-3532-4160-80D4-3E3DD39A9AE5}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD549B7B-3532-4160-80D4-3E3DD39A9AE5}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DF9BF77-7E10-4973-965E-3B7013ABEA6D}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DF9BF77-7E10-4973-965E-3B7013ABEA6D}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe" -l0x9

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe" -l0x9 /remove

    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C029DB0E-C59F-417A-90F8-88FD5B2C4AE7}\setup.exe" -l0x9

    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf

    6310-6310i Handset Manager --> C:\WINDOWS\6310phmgunin.exe C:\Program Files\6310-6310i Handset Manager\FileList.ini

    688(I) Hunter-Killer --> C:\WINDOWS\System32\EAREMOVE.EXE C:\WINDOWS\System32\EA1.UIL

    Add or Remove Adobe Creative Suite 3 Master Collection --> C:\Program Files\Common Files\Adobe\Installers\4dcfd9b7e901b57f81f667144603236\Setup.exe

    Adobe After Effects CS3 Presets --> MsiExec.exe /I{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}

    Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}

    Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}

    Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}

    Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}

    Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}

    Adobe BridgeTalk Plugin CS3 --> MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}

    Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}

    Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}

    Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}

    Adobe Color Common Settings --> C:\Program Files\Common Files\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe

    Adobe Color Common Settings --> MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}

    Adobe Color EU Extra Settings --> MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}

    Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}

    Adobe Color NA Recommended Settings --> MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}

    Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}

    Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}

    Adobe Encore CS3 Codecs --> MsiExec.exe /I{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}

    Adobe ExtendScript Toolkit 2 --> C:\Program Files\Common Files\Adobe\Installers\5bc0f8414ec36c555a3e7e5ec2e225e\Setup.exe

    Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{1BCEA516-B4C5-4B2D-BFA0-AB7910BAD862}

    Adobe Extension Manager CS3 --> MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}

    Adobe Flash Player 9 ActiveX --> MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}

    Adobe Flash Player 9 Plugin --> MsiExec.exe /X{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}

    Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe

    Adobe Flash Video Encoder --> MsiExec.exe /I{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}

    Adobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}

    Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}

    Adobe Help Viewer CS3 --> MsiExec.exe /I{7ACFB90E-8FD0-4397-AD3A-5195412623A3}

    Adobe InDesign CS3 Icon Handler --> MsiExec.exe /I{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}

    Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}

    Adobe MotionPicture Color Files --> MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}

    Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}

    Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}

    Adobe Photoshop Elements --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop Elements\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop Elements\Uninst.dll"

    Adobe Premiere Pro CS3 Functional Content --> MsiExec.exe /I{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}

    Adobe Premiere Pro CS3 Third Party Content --> MsiExec.exe /I{485ACF57-F364-440A-8496-E1E81C8FA1AA}

    Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003}

    Adobe Reader Japanese Fonts --> MsiExec.exe /I{AC76BA86-7AD7-5760-0000-705000000001}

    Adobe Setup --> MsiExec.exe /I{4458C442-7376-4CF9-AF58-E8CEA6722363}

    Adobe Setup --> MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}

    Adobe Setup --> MsiExec.exe /I{D504303A-717D-414C-BA9F-FE01093E2EF8}

    Adobe Shockwave Player --> C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~2\Install.log

    Adobe SING CS3 --> MsiExec.exe /I{B671CBFD-4109-4D35-9252-3062D3CCB7B2}

    Adobe Soundbooth CS3 Codecs --> MsiExec.exe /I{0327FA9D-975C-448C-A086-577D57BB25B8}

    Adobe Stock Photos 1.0 --> MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}

    Adobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}

    Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}

    Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}

    Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}

    Adobe Version Cue CS3 Server --> MsiExec.exe /I{1D58229F-C505-45CA-8223-F35F3A34B963}

    Adobe Video Profiles --> MsiExec.exe /I{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}

    Adobe WAS CS3 --> MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}

    Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}

    Adobe XMP DVA Panels CS3 --> MsiExec.exe /I{0224CACC-994D-45F8-B973-D65056EA9C2F}

    Adobe XMP Panels CS3 --> MsiExec.exe /I{D5A31AB1-345D-47C7-A87B-036A669F6DF1}

    Advanced GIF Animator 2.23 --> "C:\Program Files\Advanced GIF Animator\unins000.exe"

    AHV content for Acrobat and Flash --> MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}

    Alien Skin Exposure Demo --> C:\PROGRA~1\Adobe\ADOBEP~1\Plug-Ins\ALIENS~1\Exposure\Unwise32.exe C:\PROGRA~1\Adobe\ADOBEP~1\Plug-Ins\ALIENS~1\Exposure\INSTALL.LOG

    AOL Instant Messenger --> C:\PROGRA~1\AIM\uninstll.exe -LOG= C:\PROGRA~1\AIM\install.log -OEM=

    Apple Mobile Device Support --> MsiExec.exe /I{3EBD3749-304E-4A4C-9575-C00E5F015217}

    Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}

    AquaNox --> C:\PROGRA~1\AquaNox\UNWISE.EXE C:\PROGRA~1\AquaNox\INSTALL.LOG

    ArcSoft PhotoBase 3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}\setup.exe" -l0x9 -uninst

    ArcSoft PhotoStudio 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{03F1CC67-5BD8-4C36-8394-76311B2AE69A}\setup.exe" -l0x9 -uninst

    ArcSoft VideoImpression 1.6FP --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ArcSoft\VideoImpression\Uninst.isu"

    AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL

    AVI/MPEG/RM/WMV Joiner 4.82 --> "C:\Program Files\AVI MPEG RM WMV Joiner\unins000.exe"

    AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"

    Azureus --> C:\Program Files\Azureus\Uninstall.exe

    Battlefield 2142 Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD347316-609E-4149-983C-84B40338D38A}\setup.exe" -l0x9 -removeonly

    BCM V.92 56K Modem --> C:\WINDOWS\BCMSMU.exe quiet

    Bentley MicroStation V8 XM Edition 08.09.02.52 --> MsiExec.exe /I{5414BD31-B475-461F-BE99-BCC00DEF8516}

    Beyond the Red Line --> C:/Documents and Settings/PETER/My Documents/ady/uninstall.exe

    Block Checker 2.0 --> "C:\Program Files\Block Checker\uninstall.exe"

    BlueSoleil --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B9F499B8-D1F0-42FC-84BE-CC552123CCCB}\setup.exe" -l0x9

    Canon CanoScan Toolbox 4.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BCE46757-7674-4416-BEDB-68205A60409E}\setup.exe" -l0x9 anything

    Classic PhoneTools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3436EE2-D5CB-4249-840B-3A0140CC34C3}\setup.exe" -l0x9 ControlPanel

    CoffeeCup GIF Animator --> C:\PROGRA~1\COFFEE~1\GIFANI~1\UNWISE.EXE C:\PROGRA~1\COFFEE~1\GIFANI~1\GAinst.LOG

    Creative Jukebox Driver --> C:\Program Files\Creative\Jukebox 3 Drivers\DrvUnins.exe /s

    Creative MediaSource --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\SETUP.EXE" -l0x9 /remove

    Creative MediaSource 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x9 /remove

    Creative Removable Disk Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9 /remove

    Creative System Information --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove

    Creative Zen Touch --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F13D54AA-EE45-4394-8510-C612A56FD9BC}\SETUP.EXE" -l0x9

    Creative ZEN Vision M Series --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31C44235-A613-4E95-B297-207BF6C6A8C1}\SETUP.EXE" -l0x9 /remove

    Data Doctor Recovery iPod(Evaluation) 3.0.1.5 --> C:\Program Files\Data Doctor Recovery iPod(Evaluation)\Uninstall.exe

    dBpowerAMP Music Converter --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.dat

    Dell Solution Center --> MsiExec.exe /X{11F1920A-56A2-4642-B6E0-3B31A12C9288}

    DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC

    DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER

    DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN

    DVDSentry --> MsiExec.exe /I{98DF85D9-96C0-4F57-A92E-C3539477EF5E}

    Easy CD Creator 5 Basic --> MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}

    FinePixViewer Ver.3.0 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{24ED4D80-8294-11D5-96CD-0040266301AD} /l1033

    Firmware modify tool --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D2C3C211-F8BB-4451-A826-E2ED54850D66}\Setup.exe"

    FlashFXP --> C:\PROGRA~1\FlashFXP\UNWISE.EXE C:\PROGRA~1\FlashFXP\INSTALL.LOG

    FLV Player 1.3.3 --> "C:\Program Files\FLVPlayer\uninstall.exe"

    GMail Drive Shell Extension --> rundll32.exe C:\WINDOWS\system32\ShellExt\GMailFS.dll,Uninstall C:\WINDOWS\system32\ShellExt\GMailFS.inf

    Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}

    Google SketchUp --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E1423608-F529-40A1-93CA-C7F396F30DF0}\setup.exe" -l0x9

    Half-Life --> "C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/70

    Half-Life(R) 2 --> MsiExec.exe /I{D45EC259-4A19-4656-B588-C2C360DD18EA}

    Half-Life: Blue Shift --> "C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/130

    iHP Manager VER 1.20 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{16D16514-F72B-49DA-9F3E-E5681BBD0A12}\Setup.exe" -l0x9

    Intel(R) PRO Network Adapters and Drivers --> Prounstl.exe

    Intel(R) PROSet --> MsiExec.exe /I{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}

    Iomega Automatic Backup Pro --> MsiExec.exe /X{6ABAF1E2-BEB6-4C32-BD9F-0CA733EE7453}

    Iomega Product Registration --> MsiExec.exe /X{90FF23FE-0E1B-40DF-A22E-B4C0372E5936}

    iPod for Windows 2005-02-07 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{78B50D1D-642C-4B89-BCC7-352EAE3614D7} /l1033

    iPod for Windows 2005-03-23 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{44A537A5-859C-43A6-8285-C0668142A090} /l1033

    iPod for Windows 2006-03-23 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB} /l1033

    iTunes --> MsiExec.exe /I{B045B608-4A47-4C77-9EAD-06C394503306}

    J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}

    Japanese Fonts Support For Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-5760-0000-800000000003}

    Kazaa Lite Revolution 2.6 English --> "C:\Program Files\Kazaa Lite Revolution\unins000.exe"

    Labtec WebCam Software --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BF45F502-D3F2-4E7C-91D8-9AA5A8141D08}\setup.exe" -l0x9

    LabtecÆ Camera Driver --> "C:\Program Files\Common Files\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT

    Lost Planet: Extreme Conditions Demo --> "C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/6530

    Macromedia Flash Player 8 --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5

    Manual CanoScan 9900F --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4919DA1-6AEB-4B23-86AD-71097C24939B}\setup.exe" -l0x9

    Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf

    Microsoft Office PowerPoint Viewer 2003 --> MsiExec.exe /X{90AF0409-6000-11D3-8CFE-0150048383C9}

    Microsoft Reader --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B6F7DBE7-2FE2-458F-A738-B10832746036}\Setup.exe" -L0x9

    Microsoft Windows Journal Viewer --> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA8}

    Microsoft Works 7.0 --> MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}

    Modem Helper --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel

    Mozilla Firefox (2.0.0.11) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe

    Mpeg Layer3 Codec FHG-Radium v1.263 --> C:\WINDOWS\UNWISE.EXE C:\audio\L3CODE~1\INSTALL.LOG

    MSN Toolbar --> C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\mtbs.exe c

    NewsLeecher v3.8 Final --> "C:\Program Files\NewsLeecher\unins000.exe"

    Nikon Message Center --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\Setup.exe" -l0x9 UNINSTALL

    NikonCapture --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{21DDC579-834B-4C14-8122-853994FA2214}\Setup.exe" -l0x9 UNINSTALL

    Nokia Connectivity Cable Driver --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{3ECED7D1-E469-4BC6-8A93-5CB0FFE5EBF5} /l2057

    Nokia PC Suite --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{9012E9AD-0183-4FAD-A379-BCC5B6C62098} /l2057

    NokiaFREE Unlock Codes Calculator --> "C:\Documents and Settings\PETER\Desktop\NokiaFREE Unlock Codes Calculator\uninst.exe"

    NVIDIA Drivers --> C:\WINDOWS\system32\nvudisp.exe UninstallGUI

    OmniPage SE --> MsiExec.exe /I{6249C22D-E6A8-407B-BA8B-40298848ED94}

    Opanda IExif 2.26 --> "C:\Program Files\Opanda\IExif 2.26\unins000.exe"

    Opanda PowerExif 1.2 Professional Trial --> "C:\Program Files\Opanda\PowerExif 1.2\unins000.exe"

    OpenAL --> "C:\Program Files\OpenAL\RunMeFirst (Open AL 2006-12-12).exe" /U

    Opposing Force --> "C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/50

    Paddy Power Poker --> "C:\Poker\Paddy Power Poker\_SetupPoker.exe" /uninstall

    Paint Shop Pro 7 --> MsiExec.exe /I{D6DE02C7-1F47-11D4-9515-00105AE4B89A}

    PDF Settings --> MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}

    Photomatix Pro version 2.5.4 --> "C:\Program Files\Photomatix\unins000.exe"

    PictureProject --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF3999BE-1A7B-4738-88AA-97BF14094A4A}\Setup.exe" -l0x9 UNINSTALL

    PictureProject In Touch Downloader 1.0 --> C:\Program Files\PictureProject In Touch Downloader\uninst.exe

    PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Yeah malware is definitely responsible.

    First I need you to turn off wordwrap, open notepad, click format, uncheck wordwrap


    Please download VundoFix.exe to your desktop
    • Double-click VundoFix.exe to run it.
    • Click the Scan for Vundo button.
    • Once it's done scanning, click the Remove Vundo button.
    • You will receive a prompt asking if you want to remove the files, click YES
    • Once you click yes, your desktop will go blank as it starts removing Vundo.
    • When completed, it will prompt that it will reboot your computer, click OK.
    • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
    Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.


    Reboot and post a new DSS log


  • Registered Users, Registered Users 2 Posts: 3,944 ✭✭✭pete4130


    Hi, I DL'd the VundoFix and ran it. It came back saying it found no files. I reboote and ran it again and it came back the same, saying it found no files.

    Here is the Main text that the DSS showed after the reboot (no extra came up this time)

    MAIN:


    Deckard's System Scanner v20071014.68

    Run by PETER on 2008-01-14 01:09:45

    Computer is in Normal Mode.




    System Drive C: has 3.68 GiB (less than 15%) free.





    -- HijackThis (run as PETER.exe)



    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 01:09:51, on 14/01/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)á¸

    MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0013)

    Boot mode: Normal



    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\system32\CTsvcCDA.EXE

    C:\WINDOWS\system32\lxdlcoms.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\BCMSMMSG.exe

    C:\WINDOWS\system32\RUNDLL32.EXE

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe

    C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\SYSTEM32\notepad.exe

    C:\Documents and Settings\PETER\Desktop\dss.exe

    C:\PROGRA~1\TRENDM~1\HIJACK~1\PETER.exe



    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/ie/enu/gen/default.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/ie/enu/gen/default.htm

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

    R3 - Default URLSearchHook is missing

    O2 - BHO: (no name) - {01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C} - C:\WINDOWS\system32\gebyv.dll (file missing)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: {8466eebe-9748-d75a-ef94-a0a206174b47} - {74b47160-2a0a-49fe-a57d-8479ebee6648} - C:\WINDOWS\system32\nxkjjmqv.dll (file missing)

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)

    O2 - BHO: (no name) - {FA16FE06-B462-470E-9653-79C54B1871FF} - C:\WINDOWS\system32\urqrsqp.dll (file missing)

    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe

    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

    O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe 1

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [KKqc] C:\WINDOWS\lalhmqvw.exe

    O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray

    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe

    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [lxdlmon.exe] "C:\Program Files\Lexmark 7500 Series\lxdlmon.exe"

    O4 - HKLM\..\Run: [lxdlamon] "C:\Program Files\Lexmark 7500 Series\lxdlamon.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe

    O4 - HKCU\..\Run: [mfmk] C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe

    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray

    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"

    O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s

    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8

    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

    O4 - Global Startup: BlueSoleil.lnk = ?

    O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE

    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm

    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll

    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net

    O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt3_x.cab

    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab

    O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

    O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O20 - Winlogon Notify: OemStartMenuData - C:\WINDOWS\system32\jr4025hmg.dll (file missing)

    O20 - Winlogon Notify: urqrsqp - urqrsqp.dll (file missing)

    O20 - Winlogon Notify: wineij32 - wineij32.dll (file missing)

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (file missing)

    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe (file missing)

    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE

    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: lxdl_device - - C:\WINDOWS\system32\lxdlcoms.exe

    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    O24 - Desktop Component 0: (no name) - http://www.welsh-costume.co.uk/images/welsh-folk.jpg



    --

    End of file - 12450 bytes



    -- Files created between 2007-12-14 and 2008-01-14



    2008-01-14 01:08:05 0 d
    C:\Program Files\Trend Micro

    2008-01-14 00:00:21 0 d
    C:\VundoFix Backups

    2008-01-13 19:19:40 0 d
    C:\Documents and Settings\All Users\Application Data\Grisoft

    2008-01-12 17:07:01 0 d
    C:\WINDOWS\network diagnostic

    2008-01-12 10:12:25 0 d
    C:\Program Files\NAV virus software

    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Equalizer

    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\All Users\Application Data\External Build System

    2008-01-11 22:39:24 0 d
    C:\Documents and Settings\All Users\Application Data\Bubble Noise

    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Application

    2008-01-11 17:53:02 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT

    2008-01-11 17:53:02 0 d
    C:\Documents and Settings\All Users\Application Data\Guitars

    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\All Users\Application Data\Audio Unit Effect

    2008-01-11 17:17:09 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT

    2008-01-06 00:04:53 0 dr-h
    C:\$VAULT$.AVG

    2008-01-05 13:19:24 0 d
    C:\Documents and Settings\PETER\Application Data\AVG7

    2008-01-05 13:18:37 0 d
    C:\Documents and Settings\LocalService\Application Data\AVG7

    2008-01-04 23:37:14 0 d
    C:\Program Files\Helper

    2008-01-04 22:29:01 84665 --ahs---- C:\WINDOWS\system32\vybeg.ini2

    2008-01-04 22:24:38 2 --a
    C:\-2006240221

    2008-01-04 16:42:13 204288 --a
    C:\WINDOWS\system32\pmtf3.dll

    2008-01-04 16:42:13 353280 --a
    C:\WINDOWS\system32\pmtf2.dll

    2008-01-04 16:42:13 205824 --a
    C:\WINDOWS\system32\pmtf1.dll

    2008-01-04 16:42:13 53248 --a
    C:\WINDOWS\system32\pmexr.dll

    2008-01-04 16:42:13 11776 --a
    C:\WINDOWS\system32\pmbm.dll

    2008-01-04 16:42:13 95525 --a
    C:\WINDOWS\system32\Photomatix25Lib3.dll

    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\Photomatix25Lib2.dll

    2008-01-04 16:42:13 278528 --a
    C:\WINDOWS\system32\Photomatix25Lib.dll

    2008-01-04 16:42:13 446464 --a
    C:\WINDOWS\system32\Photomatix_jpg.dll

    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\lcms.dll <Not Verified; Marti Maria; LittleCMS color engine>

    2008-01-04 16:42:13 782336 --a
    C:\WINDOWS\system32\IlmImf.dll

    2008-01-04 16:42:12 0 d
    C:\Program Files\Photomatix

    2007-12-19 14:19:18 38400 --a
    C:\WINDOWS\wl.exe <Not Verified; AMF; WinLock>

    2007-12-19 14:13:52 73216 --a
    C:\WINDOWS\WinLockDll.dll <Not Verified; AMF; WinLock>





    -- Find3M Report



    2008-01-14 00:29:17 12 --a
    C:\WINDOWS\bthservsdp.dat

    2008-01-13 19:17:02 0 d
    C:\Program Files\Common Files\Symantec Shared

    2008-01-12 18:03:44 0 d
    C:\Program Files\Nikon

    2008-01-12 11:59:52 0 d
    C:\Program Files\Common Files

    2008-01-11 22:31:44 0 d
    C:\Program Files\Common Files\Nikon

    2008-01-11 20:54:25 0 d
    C:\Documents and Settings\PETER\Application Data\Nikon

    2008-01-06 18:59:04 0 d
    C:\Program Files\iTunes

    2008-01-04 22:35:26 0 d
    C:\Program Files\Lexmark 7500 Series

    2008-01-04 22:35:25 0 d
    C:\Program Files\QuickTime

    2008-01-04 21:47:02 0 d
    C:\Program Files\Soulseek

    2008-01-02 09:44:04 0 d
    C:\Documents and Settings\PETER\Application Data\Adobe

    2007-12-21 14:58:56 0 d
    C:\Program Files\Common Files\Adobe

    2007-12-18 17:24:28 0 d
    C:\Documents and Settings\PETER\Application Data\Canon

    2007-12-12 21:13:15 0 d
    C:\Documents and Settings\PETER\Application Data\Skype

    2007-12-11 23:01:08 118 --a
    C:\WINDOWS\otstuk.bat

    2007-12-08 23:21:55 4615 --a
    C:\WINDOWS\mozver.dat

    2007-12-03 21:28:15 0 d--h
    C:\Program Files\InstallShield Installation Information

    2007-12-03 19:53:36 0 d
    C:\Documents and Settings\PETER\Application Data\Creative

    2007-12-03 19:04:50 0 d--h
    C:\Program Files\Creative Installation Information

    2007-12-03 19:03:40 0 d
    C:\Program Files\Creative

    2007-12-03 19:03:27 0 d
    C:\Program Files\Common Files\Creative

    2007-11-25 22:44:29 0 d
    C:\Documents and Settings\PETER\Application Data\AdobeUM

    2007-11-21 23:26:27 0 d
    C:\Program Files\FLVPlayer





    -- Registry Dump



    *Note* empty entries & legit default entries are not shown





    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C}]

    C:\WINDOWS\system32\gebyv.dll



    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74b47160-2a0a-49fe-a57d-8479ebee6648}]

    C:\WINDOWS\system32\nxkjjmqv.dll



    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA16FE06-B462-470E-9653-79C54B1871FF}]

    C:\WINDOWS\system32\urqrsqp.dll



    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/06/2007 23:43]

    "BCMSMMSG"="BCMSMMSG.exe" [29/08/2003 03:59 C:\WINDOWS\BCMSMMSG.exe]

    "DVDSentry"="C:\WINDOWS\System32\DSentry.exe" []

    "Tray Temperature"="C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe" []

    "nwiz"="nwiz.exe" [28/06/2007 23:43 C:\WINDOWS\SYSTEM32\nwiz.exe]

    "KKqc"="C:\WINDOWS\lalhmqvw.exe" []

    "DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" []

    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []

    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe" []

    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []

    "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" []

    "LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []

    "LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" []

    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [28/06/2007 23:43]

    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" []

    "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" []

    "@=" []

    "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" []

    "BluetoothAuthenticationAgent"="bthprops.cpl" [04/08/2004 07:56 C:\WINDOWS\SYSTEM32\bthprops.cpl]

    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [26/09/2007 14:42]

    "lxdlmon.exe"="C:\Program Files\Lexmark 7500 Series\lxdlmon.exe" []

    "lxdlamon"="C:\Program Files\Lexmark 7500 Series\lxdlamon.exe" []

    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" []

    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [13/01/2008 19:19]

    "avp"="C:\WINDOWS\avp.exe" []



    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "mfmk"="C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe" []

    "Steam"="" []

    "BitComet"="C:\Program Files\BitComet\BitComet.exe" []

    "CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" []

    "MtdAcqu"="C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" []

    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [04/01/2008 17:21]



    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]

    @=C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8



    C:\Documents and Settings\PETER\Start Menu\Programs\Startup\

    DESKTOP.INI [03/09/2002 08:00:00]



    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [21/10/2007 18:42:58]

    DESKTOP.INI [03/09/2002 08:00:00]

    Sitecom Wireless Utility.lnk - C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE [22/09/2007 22:32:19]



    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

    "{FA16FE06-B462-470E-9653-79C54B1871FF}"= C:\WINDOWS\system32\urqrsqp.dll [ ]



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OemStartMenuData]

    C:\WINDOWS\system32\jr4025hmg.dll



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqrsqp]

    urqrsqp.dll



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineij32]

    wineij32.dll



    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    "Authentication Packages"= msv1_0 C:\WINDOWS\system32\gebyv



    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]

    @=&quot;Service"



    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

    @=&quot;Volume shadow copy"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk

    backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk

    backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk

    backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^PETER^Start Menu^Programs^Startup^Iomega Product Registration.lnk]

    path=C:\Documents and Settings\PETER\Start Menu\Programs\Startup\Iomega Product Registration.lnk

    backup=C:\WINDOWS\pss\Iomega Product Registration.lnkStartup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]

    "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]

    "C:\Program Files\BitComet\BitComet.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iHP-100]

    C:\Program Files\iRiver\iHP100\iHPDetect.exe



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

    "C:\Program Files\iTunes\iTunesHelper.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]

    "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

    "C:\Program Files\QuickTime\qttask.exe" -atboottime



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

    "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

    C:\Program Files\Valve\Steam\\Steam.exe -silent



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]

    "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    bthsvcs BthServ





    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f99e6cd-2318-11dc-95f9-0007e95394b1}]

    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe



    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4bd4798-7d74-11dc-964b-000cf6315d28}]

    Auto\command- G:\AdobeR.exe e

    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e









    -- End of Deckard's System Scanner: finished at 2008-01-14 01:10:15





    HiJackThis log:


    Mac OS X Version 10.4.11 (Build 8S2167)
    2008-01-13 21:00:43 +0000
    2008-01-13 21:00:44.222 SystemUIServer[83] lang is:en
    Jan 13 21:00:47 peter-conways-computer mDNSResponder: Adding browse domain local.
    Jan 13 21:00:50 peter-conways-computer mDNSResponder: NOTE: Wide-Area Service Discovery disabled to avoid crashing defective DNS relay 192.168.0.1.
    Jan 13 21:01:52 peter-conways-computer diskarbitrationd[37]: unable to mount /dev/disk1s1 (status code 0x00000047).
    2008-01-13 21:03:44.666 Nikon Transfer[225] path [/private/var/tmp/folders.501/TemporaryItems/Nikon_TransferLockFiles/] [1]
    2008-01-13 21:07:26.970 Capture NX[237] LSCopyItemInfoForURL() returned -35 for path /Volumes/Macintosh HD/dev.
    open dl ok /Library/Application Support/Nikon/Capture NX/BB.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/ColorBalance.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/ColorBooster.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/Curves.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/DLighting.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/ipmIntern.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/LCHEditor.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/NoiseReduction.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/PhotoEffects.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/RedEye.ipmopen dl ok /Library/Application Support/Nikon/Capture NX/USM.ipmcan't open dl /Applications/Nikon Software/Capture NX/Capture NX.app/Contents/PlugIns/Manager.spm (dlopen(/Applications/Nikon Software/Capture NX/Capture NX.app/Contents/PlugIns/Manager.spm, 1): image not found)open dl ok /Library/Application Support/Nikon/Capture NX/Manager.spmopen dl ok /Library/Application Support/Nikon/Capture NX/Manager.spmcan't open dl /Users/Pete/Library/Application Support/Nikon/Capture NX/Manager.spm (dlopen(/Users/Pete/Library/Application Support/Nikon/Capture NX/Manager.spm, 1): image not found)open dl ok /Library/Application Support/Nikon/Capture NX/NkJPEG.ffmopen dl ok /Library/Application Support/Nikon/Capture NX/NkNEF.ffmopen dl ok /Library/Application Support/Nikon/Capture NX/NkTIFF.ffmopen dl ok /Library/Application Support/Nikon/Capture NX/BB.ipmFailure occurred while attempting to load PictureControl dictionary
    Failure occurred while attempting to load PictureControl dictionary
    Jan 13 21:09:42 peter-conways-computer crashdump[247]: Adobe Photoshop CS2 crashed
    Jan 13 21:09:44 peter-conways-computer crashdump[247]: crash report written to: /Users/Pete/Library/Logs/CrashReporter/Adobe Photoshop CS2.crash.log
    Adobe LM Service: Started
    AdobeLM Service
    Looking for host time.euro.apple.com and service ntp
    host found : time.euro.apple.com
    13 Jan 23:04:01 ntpdate[338]: adjust time server 17.72.133.42 offset 0.173742 sec
    2008-01-13 23:04:01.400 SystemUIServer[83] lang is:en


    Thanks again for taking the time to help me out.

    Pete


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    I can't fix your PC until you uncheck word wrap in notepad, it makes the log impossible to read.

    Open notepad, click format, uncheck wordwrap, then run DSS and post the log


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 3,944 ✭✭✭pete4130


    Sorry about that, here is the log with word wrap unchecked in notepad.

    Thanks,

    Pete.

    Deckard's System Scanner v20071014.68

    Run by PETER on 2008-01-14 11:45:06

    Computer is in Normal Mode.




    System Drive C: has 3.69 GiB (less than 15%) free.





    -- HijackThis (run as PETER.exe)



    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:45:16, on 14/01/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0013)

    Boot mode: Normal



    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\system32\CTsvcCDA.EXE

    C:\WINDOWS\system32\lxdlcoms.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\BCMSMMSG.exe

    C:\WINDOWS\system32\RUNDLL32.EXE

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe

    C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\SYSTEM32\notepad.exe

    C:\Documents and Settings\PETER\Desktop\dss.exe

    C:\PROGRA~1\TRENDM~1\HIJACK~1\PETER.exe



    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/ie/enu/gen/default.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/ie/enu/gen/default.htm

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

    R3 - Default URLSearchHook is missing

    O2 - BHO: (no name) - {01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C} - C:\WINDOWS\system32\gebyv.dll (file missing)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: {8466eebe-9748-d75a-ef94-a0a206174b47} - {74b47160-2a0a-49fe-a57d-8479ebee6648} - C:\WINDOWS\system32\nxkjjmqv.dll (file missing)

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)

    O2 - BHO: (no name) - {FA16FE06-B462-470E-9653-79C54B1871FF} - C:\WINDOWS\system32\urqrsqp.dll (file missing)

    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe

    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

    O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe 1

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [KKqc] C:\WINDOWS\lalhmqvw.exe

    O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray

    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe

    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [lxdlmon.exe] "C:\Program Files\Lexmark 7500 Series\lxdlmon.exe"

    O4 - HKLM\..\Run: [lxdlamon] "C:\Program Files\Lexmark 7500 Series\lxdlamon.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe

    O4 - HKCU\..\Run: [mfmk] C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe

    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray

    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"

    O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s

    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8

    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

    O4 - Global Startup: BlueSoleil.lnk = ?

    O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE

    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm

    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll

    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net

    O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt3_x.cab

    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab

    O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

    O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O20 - Winlogon Notify: OemStartMenuData - C:\WINDOWS\system32\jr4025hmg.dll (file missing)

    O20 - Winlogon Notify: urqrsqp - urqrsqp.dll (file missing)

    O20 - Winlogon Notify: wineij32 - wineij32.dll (file missing)

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (file missing)

    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe (file missing)

    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE

    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: lxdl_device - - C:\WINDOWS\system32\lxdlcoms.exe

    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    O24 - Desktop Component 0: (no name) - http://www.welsh-costume.co.uk/images/welsh-folk.jpg



    --

    End of file - 12450 bytes



    -- Files created between 2007-12-14 and 2008-01-14



    2008-01-14 01:08:05 0 d
    C:\Program Files\Trend Micro

    2008-01-14 00:00:21 0 d
    C:\VundoFix Backups

    2008-01-13 19:19:40 0 d
    C:\Documents and Settings\All Users\Application Data\Grisoft

    2008-01-12 17:07:01 0 d
    C:\WINDOWS\network diagnostic

    2008-01-12 10:12:25 0 d
    C:\Program Files\NAV virus software

    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Equalizer

    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\All Users\Application Data\External Build System

    2008-01-11 22:39:24 0 d
    C:\Documents and Settings\All Users\Application Data\Bubble Noise

    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Application

    2008-01-11 17:53:02 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT

    2008-01-11 17:53:02 0 d
    C:\Documents and Settings\All Users\Application Data\Guitars

    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\All Users\Application Data\Audio Unit Effect

    2008-01-11 17:17:09 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT

    2008-01-06 00:04:53 0 dr-h
    C:\$VAULT$.AVG

    2008-01-05 13:19:24 0 d
    C:\Documents and Settings\PETER\Application Data\AVG7

    2008-01-05 13:18:37 0 d
    C:\Documents and Settings\LocalService\Application Data\AVG7

    2008-01-04 23:37:14 0 d
    C:\Program Files\Helper

    2008-01-04 22:29:01 84665 --ahs---- C:\WINDOWS\system32\vybeg.ini2

    2008-01-04 22:24:38 2 --a
    C:\-2006240221

    2008-01-04 16:42:13 204288 --a
    C:\WINDOWS\system32\pmtf3.dll

    2008-01-04 16:42:13 353280 --a
    C:\WINDOWS\system32\pmtf2.dll

    2008-01-04 16:42:13 205824 --a
    C:\WINDOWS\system32\pmtf1.dll

    2008-01-04 16:42:13 53248 --a
    C:\WINDOWS\system32\pmexr.dll

    2008-01-04 16:42:13 11776 --a
    C:\WINDOWS\system32\pmbm.dll

    2008-01-04 16:42:13 95525 --a
    C:\WINDOWS\system32\Photomatix25Lib3.dll

    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\Photomatix25Lib2.dll

    2008-01-04 16:42:13 278528 --a
    C:\WINDOWS\system32\Photomatix25Lib.dll

    2008-01-04 16:42:13 446464 --a
    C:\WINDOWS\system32\Photomatix_jpg.dll

    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\lcms.dll <Not Verified; Marti Maria; LittleCMS color engine>

    2008-01-04 16:42:13 782336 --a
    C:\WINDOWS\system32\IlmImf.dll

    2008-01-04 16:42:12 0 d
    C:\Program Files\Photomatix

    2007-12-19 14:19:18 38400 --a
    C:\WINDOWS\wl.exe <Not Verified; AMF; WinLock>

    2007-12-19 14:13:52 73216 --a
    C:\WINDOWS\WinLockDll.dll <Not Verified; AMF; WinLock>





    -- Find3M Report



    2008-01-14 11:37:24 12 --a
    C:\WINDOWS\bthservsdp.dat

    2008-01-13 19:17:02 0 d
    C:\Program Files\Common Files\Symantec Shared

    2008-01-12 18:03:44 0 d
    C:\Program Files\Nikon

    2008-01-12 11:59:52 0 d
    C:\Program Files\Common Files

    2008-01-11 22:31:44 0 d
    C:\Program Files\Common Files\Nikon

    2008-01-11 20:54:25 0 d
    C:\Documents and Settings\PETER\Application Data\Nikon

    2008-01-06 18:59:04 0 d
    C:\Program Files\iTunes

    2008-01-04 22:35:26 0 d
    C:\Program Files\Lexmark 7500 Series

    2008-01-04 22:35:25 0 d
    C:\Program Files\QuickTime

    2008-01-04 21:47:02 0 d
    C:\Program Files\Soulseek

    2008-01-02 09:44:04 0 d
    C:\Documents and Settings\PETER\Application Data\Adobe

    2007-12-21 14:58:56 0 d
    C:\Program Files\Common Files\Adobe

    2007-12-18 17:24:28 0 d
    C:\Documents and Settings\PETER\Application Data\Canon

    2007-12-12 21:13:15 0 d
    C:\Documents and Settings\PETER\Application Data\Skype

    2007-12-11 23:01:08 118 --a
    C:\WINDOWS\otstuk.bat

    2007-12-08 23:21:55 4615 --a
    C:\WINDOWS\mozver.dat

    2007-12-03 21:28:15 0 d--h
    C:\Program Files\InstallShield Installation Information

    2007-12-03 19:53:36 0 d
    C:\Documents and Settings\PETER\Application Data\Creative

    2007-12-03 19:04:50 0 d--h
    C:\Program Files\Creative Installation Information

    2007-12-03 19:03:40 0 d
    C:\Program Files\Creative

    2007-12-03 19:03:27 0 d
    C:\Program Files\Common Files\Creative

    2007-11-25 22:44:29 0 d
    C:\Documents and Settings\PETER\Application Data\AdobeUM

    2007-11-21 23:26:27 0 d
    C:\Program Files\FLVPlayer





    -- Registry Dump



    *Note* empty entries & legit default entries are not shown





    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C}]

    C:\WINDOWS\system32\gebyv.dll



    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74b47160-2a0a-49fe-a57d-8479ebee6648}]

    C:\WINDOWS\system32\nxkjjmqv.dll



    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA16FE06-B462-470E-9653-79C54B1871FF}]

    C:\WINDOWS\system32\urqrsqp.dll



    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/06/2007 23:43]

    "BCMSMMSG"="BCMSMMSG.exe" [29/08/2003 03:59 C:\WINDOWS\BCMSMMSG.exe]

    "DVDSentry"="C:\WINDOWS\System32\DSentry.exe" []

    "Tray Temperature"="C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe" []

    "nwiz"="nwiz.exe" [28/06/2007 23:43 C:\WINDOWS\SYSTEM32\nwiz.exe]

    "KKqc"="C:\WINDOWS\lalhmqvw.exe" []

    "DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" []

    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []

    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe" []

    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []

    "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" []

    "LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []

    "LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" []

    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [28/06/2007 23:43]

    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" []

    "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" []

    "@=" []

    "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" []

    "BluetoothAuthenticationAgent"="bthprops.cpl" [04/08/2004 07:56 C:\WINDOWS\SYSTEM32\bthprops.cpl]

    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [26/09/2007 14:42]

    "lxdlmon.exe"="C:\Program Files\Lexmark 7500 Series\lxdlmon.exe" []

    "lxdlamon"="C:\Program Files\Lexmark 7500 Series\lxdlamon.exe" []

    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" []

    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [13/01/2008 19:19]

    "avp"="C:\WINDOWS\avp.exe" []



    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "mfmk"="C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe" []

    "Steam"="" []

    "BitComet"="C:\Program Files\BitComet\BitComet.exe" []

    "CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" []

    "MtdAcqu"="C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" []

    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [04/01/2008 17:21]



    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]

    @=C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8



    C:\Documents and Settings\PETER\Start Menu\Programs\Startup\

    DESKTOP.INI [03/09/2002 08:00:00]



    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [21/10/2007 18:42:58]

    DESKTOP.INI [03/09/2002 08:00:00]

    Sitecom Wireless Utility.lnk - C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE [22/09/2007 22:32:19]



    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

    "{FA16FE06-B462-470E-9653-79C54B1871FF}"= C:\WINDOWS\system32\urqrsqp.dll [ ]



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OemStartMenuData]

    C:\WINDOWS\system32\jr4025hmg.dll



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqrsqp]

    urqrsqp.dll



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineij32]

    wineij32.dll



    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    "Authentication Packages"= msv1_0 C:\WINDOWS\system32\gebyv



    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]

    @=&quot;Service"



    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

    @=&quot;Volume shadow copy"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk

    backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk

    backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]

    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk

    backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^PETER^Start Menu^Programs^Startup^Iomega Product Registration.lnk]

    path=C:\Documents and Settings\PETER\Start Menu\Programs\Startup\Iomega Product Registration.lnk

    backup=C:\WINDOWS\pss\Iomega Product Registration.lnkStartup



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]

    "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]

    "C:\Program Files\BitComet\BitComet.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iHP-100]

    C:\Program Files\iRiver\iHP100\iHPDetect.exe



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

    "C:\Program Files\iTunes\iTunesHelper.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]

    "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

    "C:\Program Files\QuickTime\qttask.exe" -atboottime



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

    "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

    C:\Program Files\Valve\Steam\\Steam.exe -silent



    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]

    "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet



    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    bthsvcs BthServ





    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f99e6cd-2318-11dc-95f9-0007e95394b1}]

    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe



    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4bd4798-7d74-11dc-964b-000cf6315d28}]

    Auto\command- G:\AdobeR.exe e

    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e









    -- End of Deckard's System Scanner: finished at 2008-01-14 11:45:41


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Sorry to be a pain, but it's still on :)

    There should be no spaces in between the lines, that means wordwrap is off. Once you have that sorted and post a log, make sure it has no lines, can fix you up.


  • Registered Users, Registered Users 2 Posts: 3,944 ✭✭✭pete4130


    Hi again, I think the problem with the spacing was due to the fact I had to copy the log onto my memory stick and open it on my mac to paste it into the thread, for whatever reason it put spaces in the report. I'm on dial up here in the PC to copy and paste it directly, so hopefully, fingers crossed it will work this time.

    Cheers,

    Pete.


    Deckard's System Scanner v20071014.68
    Run by PETER on 2008-01-14 21:51:53
    Computer is in Normal Mode.

    System Drive C: has 2.88 GiB (less than 15%) free.


    -- HijackThis (run as PETER.exe)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:52:09, on 14/01/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\system32\lxdlcoms.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\SYSTEM32\notepad.exe
    C:\Documents and Settings\PETER\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\PETER.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/ie/enu/gen/default.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/ie/enu/gen/default.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C} - C:\WINDOWS\system32\gebyv.dll (file missing)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: {8466eebe-9748-d75a-ef94-a0a206174b47} - {74b47160-2a0a-49fe-a57d-8479ebee6648} - C:\WINDOWS\system32\nxkjjmqv.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)
    O2 - BHO: (no name) - {FA16FE06-B462-470E-9653-79C54B1871FF} - C:\WINDOWS\system32\urqrsqp.dll (file missing)
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe 1
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [KKqc] C:\WINDOWS\lalhmqvw.exe
    O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [lxdlmon.exe] "C:\Program Files\Lexmark 7500 Series\lxdlmon.exe"
    O4 - HKLM\..\Run: [lxdlamon] "C:\Program Files\Lexmark 7500 Series\lxdlamon.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
    O4 - HKCU\..\Run: [mfmk] C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
    O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: BlueSoleil.lnk = ?
    O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
    O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt3_x.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: OemStartMenuData - C:\WINDOWS\system32\jr4025hmg.dll (file missing)
    O20 - Winlogon Notify: urqrsqp - urqrsqp.dll (file missing)
    O20 - Winlogon Notify: wineij32 - wineij32.dll (file missing)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe (file missing)
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxdl_device - - C:\WINDOWS\system32\lxdlcoms.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O24 - Desktop Component 0: (no name) - http://www.welsh-costume.co.uk/images/welsh-folk.jpg

    --
    End of file - 12390 bytes

    -- Files created between 2007-12-14 and 2008-01-14

    2008-01-14 01:08:05 0 d
    C:\Program Files\Trend Micro
    2008-01-14 00:00:21 0 d
    C:\VundoFix Backups
    2008-01-13 19:19:40 0 d
    C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-01-12 17:07:01 0 d
    C:\WINDOWS\network diagnostic
    2008-01-12 10:12:25 0 d
    C:\Program Files\NAV virus software
    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Equalizer
    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\All Users\Application Data\External Build System
    2008-01-11 22:39:24 0 d
    C:\Documents and Settings\All Users\Application Data\Bubble Noise
    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Application
    2008-01-11 17:53:02 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
    2008-01-11 17:53:02 0 d
    C:\Documents and Settings\All Users\Application Data\Guitars
    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\All Users\Application Data\Audio Unit Effect
    2008-01-11 17:17:09 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT
    2008-01-06 00:04:53 0 dr-h
    C:\$VAULT$.AVG
    2008-01-05 13:19:24 0 d
    C:\Documents and Settings\PETER\Application Data\AVG7
    2008-01-05 13:18:37 0 d
    C:\Documents and Settings\LocalService\Application Data\AVG7
    2008-01-04 23:37:14 0 d
    C:\Program Files\Helper
    2008-01-04 22:29:01 84665 --ahs---- C:\WINDOWS\system32\vybeg.ini2
    2008-01-04 22:24:38 2 --a
    C:\-2006240221
    2008-01-04 16:42:13 204288 --a
    C:\WINDOWS\system32\pmtf3.dll
    2008-01-04 16:42:13 353280 --a
    C:\WINDOWS\system32\pmtf2.dll
    2008-01-04 16:42:13 205824 --a
    C:\WINDOWS\system32\pmtf1.dll
    2008-01-04 16:42:13 53248 --a
    C:\WINDOWS\system32\pmexr.dll
    2008-01-04 16:42:13 11776 --a
    C:\WINDOWS\system32\pmbm.dll
    2008-01-04 16:42:13 95525 --a
    C:\WINDOWS\system32\Photomatix25Lib3.dll
    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\Photomatix25Lib2.dll
    2008-01-04 16:42:13 278528 --a
    C:\WINDOWS\system32\Photomatix25Lib.dll
    2008-01-04 16:42:13 446464 --a
    C:\WINDOWS\system32\Photomatix_jpg.dll
    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\lcms.dll <Not Verified; Marti Maria; LittleCMS color engine>
    2008-01-04 16:42:13 782336 --a
    C:\WINDOWS\system32\IlmImf.dll
    2008-01-04 16:42:12 0 d
    C:\Program Files\Photomatix
    2007-12-19 14:19:18 38400 --a
    C:\WINDOWS\wl.exe <Not Verified; AMF; WinLock>
    2007-12-19 14:13:52 73216 --a
    C:\WINDOWS\WinLockDll.dll <Not Verified; AMF; WinLock>


    -- Find3M Report

    2008-01-14 11:37:24 12 --a
    C:\WINDOWS\bthservsdp.dat
    2008-01-13 19:17:02 0 d
    C:\Program Files\Common Files\Symantec Shared
    2008-01-12 18:03:44 0 d
    C:\Program Files\Nikon
    2008-01-12 11:59:52 0 d
    C:\Program Files\Common Files
    2008-01-11 22:31:44 0 d
    C:\Program Files\Common Files\Nikon
    2008-01-11 20:54:25 0 d
    C:\Documents and Settings\PETER\Application Data\Nikon
    2008-01-06 18:59:04 0 d
    C:\Program Files\iTunes
    2008-01-04 22:35:26 0 d
    C:\Program Files\Lexmark 7500 Series
    2008-01-04 22:35:25 0 d
    C:\Program Files\QuickTime
    2008-01-04 21:47:02 0 d
    C:\Program Files\Soulseek
    2008-01-02 09:44:04 0 d
    C:\Documents and Settings\PETER\Application Data\Adobe
    2007-12-21 14:58:56 0 d
    C:\Program Files\Common Files\Adobe
    2007-12-18 17:24:28 0 d
    C:\Documents and Settings\PETER\Application Data\Canon
    2007-12-12 21:13:15 0 d
    C:\Documents and Settings\PETER\Application Data\Skype
    2007-12-11 23:01:08 118 --a
    C:\WINDOWS\otstuk.bat
    2007-12-08 23:21:55 4615 --a
    C:\WINDOWS\mozver.dat
    2007-12-03 21:28:15 0 d--h
    C:\Program Files\InstallShield Installation Information
    2007-12-03 19:53:36 0 d
    C:\Documents and Settings\PETER\Application Data\Creative
    2007-12-03 19:04:50 0 d--h
    C:\Program Files\Creative Installation Information
    2007-12-03 19:03:40 0 d
    C:\Program Files\Creative
    2007-12-03 19:03:27 0 d
    C:\Program Files\Common Files\Creative
    2007-11-25 22:44:29 0 d
    C:\Documents and Settings\PETER\Application Data\AdobeUM
    2007-11-21 23:26:27 0 d
    C:\Program Files\FLVPlayer


    -- Registry Dump

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C}]
    C:\WINDOWS\system32\gebyv.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74b47160-2a0a-49fe-a57d-8479ebee6648}]
    C:\WINDOWS\system32\nxkjjmqv.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA16FE06-B462-470E-9653-79C54B1871FF}]
    C:\WINDOWS\system32\urqrsqp.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/06/2007 23:43]
    "BCMSMMSG"="BCMSMMSG.exe" [29/08/2003 03:59 C:\WINDOWS\BCMSMMSG.exe]
    "DVDSentry"="C:\WINDOWS\System32\DSentry.exe" []
    "Tray Temperature"="C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe" []
    "nwiz"="nwiz.exe" [28/06/2007 23:43 C:\WINDOWS\SYSTEM32\nwiz.exe]
    "KKqc"="C:\WINDOWS\lalhmqvw.exe" []
    "DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" []
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []
    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe" []
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []
    "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" []
    "LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []
    "LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" []
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [28/06/2007 23:43]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" []
    "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" []
    "@=" []
    "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" []
    "BluetoothAuthenticationAgent"="bthprops.cpl" [04/08/2004 07:56 C:\WINDOWS\SYSTEM32\bthprops.cpl]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [26/09/2007 14:42]
    "lxdlmon.exe"="C:\Program Files\Lexmark 7500 Series\lxdlmon.exe" []
    "lxdlamon"="C:\Program Files\Lexmark 7500 Series\lxdlamon.exe" []
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" []
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [13/01/2008 19:19]
    "avp"="C:\WINDOWS\avp.exe" []

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "mfmk"="C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe" []
    "Steam"="" []
    "BitComet"="C:\Program Files\BitComet\BitComet.exe" []
    "CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" []
    "MtdAcqu"="C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" []
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [04/01/2008 17:21]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
    @=C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8

    C:\Documents and Settings\PETER\Start Menu\Programs\Startup\
    DESKTOP.INI [03/09/2002 08:00:00]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [21/10/2007 18:42:58]
    DESKTOP.INI [03/09/2002 08:00:00]
    Sitecom Wireless Utility.lnk - C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE [22/09/2007 22:32:19]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{FA16FE06-B462-470E-9653-79C54B1871FF}"= C:\WINDOWS\system32\urqrsqp.dll [ ]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OemStartMenuData]
    C:\WINDOWS\system32\jr4025hmg.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqrsqp]
    urqrsqp.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineij32]
    wineij32.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 C:\WINDOWS\system32\gebyv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @=&quot;Volume shadow copy"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
    backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
    backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
    backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^PETER^Start Menu^Programs^Startup^Iomega Product Registration.lnk]
    path=C:\Documents and Settings\PETER\Start Menu\Programs\Startup\Iomega Product Registration.lnk
    backup=C:\WINDOWS\pss\Iomega Product Registration.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
    "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
    "C:\Program Files\BitComet\BitComet.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iHP-100]
    C:\Program Files\iRiver\iHP100\iHPDetect.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "C:\Program Files\iTunes\iTunesHelper.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
    "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "C:\Program Files\QuickTime\qttask.exe" -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    C:\Program Files\Valve\Steam\\Steam.exe -silent

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs BthServ


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f99e6cd-2318-11dc-95f9-0007e95394b1}]
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4bd4798-7d74-11dc-964b-000cf6315d28}]
    Auto\command- G:\AdobeR.exe e
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e




    -- End of Deckard's System Scanner: finished at 2008-01-14 21:52:39


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Perfect

    1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {01FFE86F-9ACD-4B0B-9114-2B1B557DAF2C} - C:\WINDOWS\system32\gebyv.dll (file missing)
    O2 - BHO: {8466eebe-9748-d75a-ef94-a0a206174b47} - {74b47160-2a0a-49fe-a57d-8479ebee6648} - C:\WINDOWS\system32\nxkjjmqv.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)
    O2 - BHO: (no name) - {FA16FE06-B462-470E-9653-79C54B1871FF} - C:\WINDOWS\system32\urqrsqp.dll (file missing)
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (file missing)
    O4 - HKLM\..\Run: [KKqc] C:\WINDOWS\lalhmqvw.exe
    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
    O4 - HKCU\..\Run: [mfmk] C:\PROGRA~1\COMMON~1\mfmk\mfmkm.exe
    O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab
    O20 - Winlogon Notify: OemStartMenuData - C:\WINDOWS\system32\jr4025hmg.dll (file missing)
    O20 - Winlogon Notify: urqrsqp - urqrsqp.dll (file missing)
    O20 - Winlogon Notify: wineij32 - wineij32.dll (file missing)


    2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




    Please download the OTMoveIt2 by OldTimer.
    • Save it to your desktop.
    • Please double-click OTMoveIt2.exe to run it.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      C:\Program Files\Helper
      C:\WINDOWS\system32\vybeg.ini2
      C:\-2006240221
      C:\WINDOWS\wl.exe 
      C:\WINDOWS\WinLockDll.dll
      C:\WINDOWS\otstuk.bat
      
    • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      purity
      
    • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt2
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


    Reboot and post a new DSS log


  • Registered Users, Registered Users 2 Posts: 3,944 ✭✭✭pete4130


    Here is the OTMoveit reults:

    C:\Program Files\Helper moved successfully.
    C:\WINDOWS\system32\vybeg.ini2 moved successfully.
    C:\-2006240221 moved successfully.
    C:\WINDOWS\wl.exe moved successfully.
    DllUnregisterServer procedure not found in C:\WINDOWS\WinLockDll.dll
    C:\WINDOWS\WinLockDll.dll NOT unregistered.
    C:\WINDOWS\WinLockDll.dll moved successfully.
    C:\WINDOWS\otstuk.bat moved successfully.
    [Manual Searches]
    < purity >

    OTMoveIt2 v1.0.6 log created on 01152008_000406


    And here is the new DSS report:

    Deckard's System Scanner v20071014.68
    Run by PETER on 2008-01-15 00:21:12
    Computer is in Normal Mode.

    System Drive C: has 2.86 GiB (less than 15%) free.


    -- HijackThis (run as PETER.exe)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:21:16, on 15/01/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\system32\lxdlcoms.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\PETER\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\PETER.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/ie/enu/gen/default.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/ie/enu/gen/default.htm
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe 1
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [lxdlmon.exe] "C:\Program Files\Lexmark 7500 Series\lxdlmon.exe"
    O4 - HKLM\..\Run: [lxdlamon] "C:\Program Files\Lexmark 7500 Series\lxdlamon.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
    O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: BlueSoleil.lnk = ?
    O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
    O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt3_x.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C5ABC99A-2FA7-4656-8051-34A977802D07}: NameServer = 213.94.190.235 213.94.190.195
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe (file missing)
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxdl_device - - C:\WINDOWS\system32\lxdlcoms.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O24 - Desktop Component 0: (no name) - http://www.welsh-costume.co.uk/images/welsh-folk.jpg

    --
    End of file - 11165 bytes

    -- Files created between 2007-12-15 and 2008-01-15

    2008-01-14 01:08:05 0 d
    C:\Program Files\Trend Micro
    2008-01-14 00:00:21 0 d
    C:\VundoFix Backups
    2008-01-13 19:19:40 0 d
    C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-01-12 17:07:01 0 d
    C:\WINDOWS\network diagnostic
    2008-01-12 10:12:25 0 d
    C:\Program Files\NAV virus software
    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Equalizer
    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\All Users\Application Data\External Build System
    2008-01-11 22:39:24 0 d
    C:\Documents and Settings\All Users\Application Data\Bubble Noise
    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Application
    2008-01-11 17:53:02 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
    2008-01-11 17:53:02 0 d
    C:\Documents and Settings\All Users\Application Data\Guitars
    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\All Users\Application Data\Audio Unit Effect
    2008-01-11 17:17:09 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT
    2008-01-06 00:04:53 0 dr-h
    C:\$VAULT$.AVG
    2008-01-05 13:19:24 0 d
    C:\Documents and Settings\PETER\Application Data\AVG7
    2008-01-05 13:18:37 0 d
    C:\Documents and Settings\LocalService\Application Data\AVG7
    2008-01-04 16:42:13 204288 --a
    C:\WINDOWS\system32\pmtf3.dll
    2008-01-04 16:42:13 353280 --a
    C:\WINDOWS\system32\pmtf2.dll
    2008-01-04 16:42:13 205824 --a
    C:\WINDOWS\system32\pmtf1.dll
    2008-01-04 16:42:13 53248 --a
    C:\WINDOWS\system32\pmexr.dll
    2008-01-04 16:42:13 11776 --a
    C:\WINDOWS\system32\pmbm.dll
    2008-01-04 16:42:13 95525 --a
    C:\WINDOWS\system32\Photomatix25Lib3.dll
    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\Photomatix25Lib2.dll
    2008-01-04 16:42:13 278528 --a
    C:\WINDOWS\system32\Photomatix25Lib.dll
    2008-01-04 16:42:13 446464 --a
    C:\WINDOWS\system32\Photomatix_jpg.dll
    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\lcms.dll <Not Verified; Marti Maria; LittleCMS color engine>
    2008-01-04 16:42:13 782336 --a
    C:\WINDOWS\system32\IlmImf.dll
    2008-01-04 16:42:12 0 d
    C:\Program Files\Photomatix


    -- Find3M Report

    2008-01-15 00:09:07 12 --a
    C:\WINDOWS\bthservsdp.dat
    2008-01-13 19:17:02 0 d
    C:\Program Files\Common Files\Symantec Shared
    2008-01-12 18:03:44 0 d
    C:\Program Files\Nikon
    2008-01-12 11:59:52 0 d
    C:\Program Files\Common Files
    2008-01-11 22:31:44 0 d
    C:\Program Files\Common Files\Nikon
    2008-01-11 20:54:25 0 d
    C:\Documents and Settings\PETER\Application Data\Nikon
    2008-01-06 18:59:04 0 d
    C:\Program Files\iTunes
    2008-01-04 22:35:26 0 d
    C:\Program Files\Lexmark 7500 Series
    2008-01-04 22:35:25 0 d
    C:\Program Files\QuickTime
    2008-01-04 21:47:02 0 d
    C:\Program Files\Soulseek
    2008-01-02 09:44:04 0 d
    C:\Documents and Settings\PETER\Application Data\Adobe
    2007-12-21 14:58:56 0 d
    C:\Program Files\Common Files\Adobe
    2007-12-18 17:24:28 0 d
    C:\Documents and Settings\PETER\Application Data\Canon
    2007-12-12 21:13:15 0 d
    C:\Documents and Settings\PETER\Application Data\Skype
    2007-12-08 23:21:55 4615 --a
    C:\WINDOWS\mozver.dat
    2007-12-03 21:28:15 0 d--h
    C:\Program Files\InstallShield Installation Information
    2007-12-03 19:53:36 0 d
    C:\Documents and Settings\PETER\Application Data\Creative
    2007-12-03 19:04:50 0 d--h
    C:\Program Files\Creative Installation Information
    2007-12-03 19:03:40 0 d
    C:\Program Files\Creative
    2007-12-03 19:03:27 0 d
    C:\Program Files\Common Files\Creative
    2007-11-25 22:44:29 0 d
    C:\Documents and Settings\PETER\Application Data\AdobeUM
    2007-11-21 23:26:27 0 d
    C:\Program Files\FLVPlayer


    -- Registry Dump

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/06/2007 23:43]
    "BCMSMMSG"="BCMSMMSG.exe" [29/08/2003 03:59 C:\WINDOWS\BCMSMMSG.exe]
    "DVDSentry"="C:\WINDOWS\System32\DSentry.exe" []
    "Tray Temperature"="C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe" []
    "nwiz"="nwiz.exe" [28/06/2007 23:43 C:\WINDOWS\SYSTEM32\nwiz.exe]
    "DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" []
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []
    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe" []
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []
    "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" []
    "LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []
    "LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" []
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [28/06/2007 23:43]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" []
    "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" []
    "@=" []
    "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" []
    "BluetoothAuthenticationAgent"="bthprops.cpl" [04/08/2004 07:56 C:\WINDOWS\SYSTEM32\bthprops.cpl]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [26/09/2007 14:42]
    "lxdlmon.exe"="C:\Program Files\Lexmark 7500 Series\lxdlmon.exe" []
    "lxdlamon"="C:\Program Files\Lexmark 7500 Series\lxdlamon.exe" []
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" []
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [13/01/2008 19:19]
    "avp"="C:\WINDOWS\avp.exe" []

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="" []
    "BitComet"="C:\Program Files\BitComet\BitComet.exe" []
    "CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" []
    "MtdAcqu"="C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" []
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [04/01/2008 17:21]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
    @=C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8

    C:\Documents and Settings\PETER\Start Menu\Programs\Startup\
    DESKTOP.INI [03/09/2002 08:00:00]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [21/10/2007 18:42:58]
    DESKTOP.INI [03/09/2002 08:00:00]
    Sitecom Wireless Utility.lnk - C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE [22/09/2007 22:32:19]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 C:\WINDOWS\system32\gebyv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @=&quot;Volume shadow copy"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
    backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
    backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
    backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^PETER^Start Menu^Programs^Startup^Iomega Product Registration.lnk]
    path=C:\Documents and Settings\PETER\Start Menu\Programs\Startup\Iomega Product Registration.lnk
    backup=C:\WINDOWS\pss\Iomega Product Registration.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
    "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
    "C:\Program Files\BitComet\BitComet.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iHP-100]
    C:\Program Files\iRiver\iHP100\iHPDetect.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "C:\Program Files\iTunes\iTunesHelper.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
    "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "C:\Program Files\QuickTime\qttask.exe" -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    C:\Program Files\Valve\Steam\\Steam.exe -silent

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs BthServ


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f99e6cd-2318-11dc-95f9-0007e95394b1}]
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4bd4798-7d74-11dc-964b-000cf6315d28}]
    Auto\command- G:\AdobeR.exe e
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e




    -- End of Deckard's System Scanner: finished at 2008-01-15 00:21:40


  • Advertisement
  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Nearly done

    1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe


    2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



    Please download the OTMoveIt2 by OldTimer.
    • Save it to your desktop.
    • Please double-click OTMoveIt2.exe to run it.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      C:\WINDOWS\avp.exe
      G:\AdobeR.exe
      
    • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      purity
      
    • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt2
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



    Backup Your Registry with ERUNT
    • Please use the following link and scroll down to ERUNT and download it.
      http://aumha.org/freeware/freeware.php
    • For version with the Installer:
      Use the setup program to install ERUNT on your computer
    • For the zipped version:
      Unzip all the files into a folder of your choice.
    Click Erunt.exe to backup your registry to the folder of your choice.

    Note: to restore your registry, go to the folder and start ERDNT.exe



    Now we need to fix your problems by making a .reg file. Copy the code below into a Notepad file. Name the file as fix.reg, change the "Save as Type" to "All files" and save it on the desktop.
    Windows Registry Editor Version 5.00
    
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f99e6cd-2318-11dc-95f9-0007e95394b1}]
    
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4bd4798-7d74-11dc-964b-000cf6315d28}]
    
    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa]
    "Authentication Packages"=hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,\
    00
    


    Then double click on the fix.reg file, when it prompts to merge click "Yes".


    Reboot and post a new DSS log


  • Registered Users, Registered Users 2 Posts: 3,944 ✭✭✭pete4130


    Thank you so much for your patience with this for me.

    Here is the newest DSS report.




    Deckard's System Scanner v20071014.68
    Run by PETER on 2008-01-15 01:08:37
    Computer is in Normal Mode.

    System Drive C: has 2.8 GiB (less than 15%) free.


    -- HijackThis (run as PETER.exe)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 01:08:45, on 15/01/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\system32\lxdlcoms.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE
    C:\Documents and Settings\PETER\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\PETER.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/ie/enu/gen/default.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/ie/enu/gen/default.htm
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe 1
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [lxdlmon.exe] "C:\Program Files\Lexmark 7500 Series\lxdlmon.exe"
    O4 - HKLM\..\Run: [lxdlamon] "C:\Program Files\Lexmark 7500 Series\lxdlamon.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
    O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: BlueSoleil.lnk = ?
    O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
    O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt3_x.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe (file missing)
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxdl_device - - C:\WINDOWS\system32\lxdlcoms.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O24 - Desktop Component 0: (no name) - http://www.welsh-costume.co.uk/images/welsh-folk.jpg

    --
    End of file - 10845 bytes

    -- Files created between 2007-12-15 and 2008-01-15

    2008-01-14 01:08:05 0 d
    C:\Program Files\Trend Micro
    2008-01-14 00:00:21 0 d
    C:\VundoFix Backups
    2008-01-13 19:19:40 0 d
    C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-01-12 17:07:01 0 d
    C:\WINDOWS\network diagnostic
    2008-01-12 10:12:25 0 d
    C:\Program Files\NAV virus software
    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Equalizer
    2008-01-11 22:39:24 268 -r-h
    C:\Documents and Settings\All Users\Application Data\External Build System
    2008-01-11 22:39:24 0 d
    C:\Documents and Settings\All Users\Application Data\Bubble Noise
    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\PETER\Application Data\Application
    2008-01-11 17:53:02 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
    2008-01-11 17:53:02 0 d
    C:\Documents and Settings\All Users\Application Data\Guitars
    2008-01-11 17:53:02 268 -r-h
    C:\Documents and Settings\All Users\Application Data\Audio Unit Effect
    2008-01-11 17:17:09 20 ---h
    C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT
    2008-01-06 00:04:53 0 dr-h
    C:\$VAULT$.AVG
    2008-01-05 13:19:24 0 d
    C:\Documents and Settings\PETER\Application Data\AVG7
    2008-01-05 13:18:37 0 d
    C:\Documents and Settings\LocalService\Application Data\AVG7
    2008-01-04 16:42:13 204288 --a
    C:\WINDOWS\system32\pmtf3.dll
    2008-01-04 16:42:13 353280 --a
    C:\WINDOWS\system32\pmtf2.dll
    2008-01-04 16:42:13 205824 --a
    C:\WINDOWS\system32\pmtf1.dll
    2008-01-04 16:42:13 53248 --a
    C:\WINDOWS\system32\pmexr.dll
    2008-01-04 16:42:13 11776 --a
    C:\WINDOWS\system32\pmbm.dll
    2008-01-04 16:42:13 95525 --a
    C:\WINDOWS\system32\Photomatix25Lib3.dll
    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\Photomatix25Lib2.dll
    2008-01-04 16:42:13 278528 --a
    C:\WINDOWS\system32\Photomatix25Lib.dll
    2008-01-04 16:42:13 446464 --a
    C:\WINDOWS\system32\Photomatix_jpg.dll
    2008-01-04 16:42:13 274432 --a
    C:\WINDOWS\system32\lcms.dll <Not Verified; Marti Maria; LittleCMS color engine>
    2008-01-04 16:42:13 782336 --a
    C:\WINDOWS\system32\IlmImf.dll
    2008-01-04 16:42:12 0 d
    C:\Program Files\Photomatix


    -- Find3M Report

    2008-01-15 01:06:27 12 --a
    C:\WINDOWS\bthservsdp.dat
    2008-01-13 19:17:02 0 d
    C:\Program Files\Common Files\Symantec Shared
    2008-01-12 18:03:44 0 d
    C:\Program Files\Nikon
    2008-01-12 11:59:52 0 d
    C:\Program Files\Common Files
    2008-01-11 22:31:44 0 d
    C:\Program Files\Common Files\Nikon
    2008-01-11 20:54:25 0 d
    C:\Documents and Settings\PETER\Application Data\Nikon
    2008-01-06 18:59:04 0 d
    C:\Program Files\iTunes
    2008-01-04 22:35:26 0 d
    C:\Program Files\Lexmark 7500 Series
    2008-01-04 22:35:25 0 d
    C:\Program Files\QuickTime
    2008-01-04 21:47:02 0 d
    C:\Program Files\Soulseek
    2008-01-02 09:44:04 0 d
    C:\Documents and Settings\PETER\Application Data\Adobe
    2007-12-21 14:58:56 0 d
    C:\Program Files\Common Files\Adobe
    2007-12-18 17:24:28 0 d
    C:\Documents and Settings\PETER\Application Data\Canon
    2007-12-12 21:13:15 0 d
    C:\Documents and Settings\PETER\Application Data\Skype
    2007-12-08 23:21:55 4615 --a
    C:\WINDOWS\mozver.dat
    2007-12-03 21:28:15 0 d--h
    C:\Program Files\InstallShield Installation Information
    2007-12-03 19:53:36 0 d
    C:\Documents and Settings\PETER\Application Data\Creative
    2007-12-03 19:04:50 0 d--h
    C:\Program Files\Creative Installation Information
    2007-12-03 19:03:40 0 d
    C:\Program Files\Creative
    2007-12-03 19:03:27 0 d
    C:\Program Files\Common Files\Creative
    2007-11-25 22:44:29 0 d
    C:\Documents and Settings\PETER\Application Data\AdobeUM
    2007-11-21 23:26:27 0 d
    C:\Program Files\FLVPlayer


    -- Registry Dump

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/06/2007 23:43]
    "BCMSMMSG"="BCMSMMSG.exe" [29/08/2003 03:59 C:\WINDOWS\BCMSMMSG.exe]
    "DVDSentry"="C:\WINDOWS\System32\DSentry.exe" []
    "Tray Temperature"="C:\DOCUME~1\PETER\LOCALS~1\Temp\MiniBug.exe" []
    "nwiz"="nwiz.exe" [28/06/2007 23:43 C:\WINDOWS\SYSTEM32\nwiz.exe]
    "DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" []
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []
    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe" []
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []
    "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" []
    "LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []
    "LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" []
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [28/06/2007 23:43]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" []
    "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" []
    "@=" []
    "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" []
    "BluetoothAuthenticationAgent"="bthprops.cpl" [04/08/2004 07:56 C:\WINDOWS\SYSTEM32\bthprops.cpl]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [26/09/2007 14:42]
    "lxdlmon.exe"="C:\Program Files\Lexmark 7500 Series\lxdlmon.exe" []
    "lxdlamon"="C:\Program Files\Lexmark 7500 Series\lxdlamon.exe" []
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" []
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [13/01/2008 19:19]
    "avp"="C:\WINDOWS\avp.exe" []

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="" []
    "BitComet"="C:\Program Files\BitComet\BitComet.exe" []
    "CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" []
    "MtdAcqu"="C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" []
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [04/01/2008 17:21]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
    @=C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=en&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000003.00000008&b=00000082.0000000f.0000001b&c=00000082.0000001f.0000004b&d=00000082.00000049.000000b9&e=00000083.00000018.000000a8

    C:\Documents and Settings\PETER\Start Menu\Programs\Startup\
    DESKTOP.INI [03/09/2002 08:00:00]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [21/10/2007 18:42:58]
    DESKTOP.INI [03/09/2002 08:00:00]
    Sitecom Wireless Utility.lnk - C:\Program Files\Sitecom\Sitecom Wireless Network USB Adapter Turbo G WL-172\Installer\WLANUTL.EXE [22/09/2007 22:32:19]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @=&quot;Volume shadow copy"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
    backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
    backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
    backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^PETER^Start Menu^Programs^Startup^Iomega Product Registration.lnk]
    path=C:\Documents and Settings\PETER\Start Menu\Programs\Startup\Iomega Product Registration.lnk
    backup=C:\WINDOWS\pss\Iomega Product Registration.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
    "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
    "C:\Program Files\BitComet\BitComet.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iHP-100]
    C:\Program Files\iRiver\iHP100\iHPDetect.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "C:\Program Files\iTunes\iTunesHelper.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
    "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "C:\Program Files\QuickTime\qttask.exe" -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    C:\Program Files\Valve\Steam\\Steam.exe -silent

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs BthServ




    -- End of Deckard's System Scanner: finished at 2008-01-15 01:09:12


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Hello

    Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner and click Accept

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases


        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer

        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save as Text button:
        [*]Save the file to your desktop.
        [*]Copy and paste that information in your next post.


        Also tell me how your PC is running


      • Registered Users, Registered Users 2 Posts: 3,944 ✭✭✭pete4130


        I've tried to run the Kaspersky Online Scanner on IE. I haven't used IE for a long time and it's updated itself to IE7 now I think. It's giving me trouble allowing me to let activex run on it. I hit the yellow information bar and the only option to come up is to open the Information Bar Help and no option to allow Activex to run.

        Thanks,

        Pete.


      Advertisement