PDA

View Full Version : removed smitfraud now left with pop-ups



djsuz
2009-06-17, 03:10
Hi there,

I have read the FAQ's and several other posts throughout the course of the day.

I am currently running malwarebytes which has found one infected object.

I have so far used the smitfraudfix, rogueremover, ccleaner and spybot which found but didn't remove the two trojans.

I am running on vista home edition 32 bit if that makes a difference.

Thanks very much in advance

Here is a log file from Hijack

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:06:26, on 16/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
C:\Windows\msa.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoardLauncher.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe_ID0EXG] "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoardLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: Xenocode Sandbox Manager.lnk = C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe
O4 - Global Startup: Register Mask Pro 3.0.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - (no file)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: APSHook.dll,avgrsstx.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\Windows\SYSTEM32\astsrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Program Files\FileZilla Server\FileZilla Server.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hMailServer - hMailServer - C:\Program Files\hMailServer\Bin\hMailServer.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Unknown owner - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.33\bin\mysqld.exe

--
End of file - 12477 bytes

Malwarebytes' Anti-Malware 1.37
Database version: 2290
Windows 6.0.6001 Service Pack 1

16/06/2009 22:33:51
mbam-log-2009-06-16 (22-33-51).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 361635
Time elapsed: 3 hour(s), 8 minute(s), 3 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
C:\Windows\msa.exe (Trojan.Agent) -> Failed to unload process.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\msa.exe (Trojan.Agent) -> Delete on reboot.
c:\Windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\element painters\MediaTubeCodec_ver1.1463.0.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Shaba
2009-06-18, 08:43
Hi djsuz

Download gmer.zip (http://gmer.net/gmer.zip) and save to your desktop.
alternate download site (http://hype.free.googlepages.com/gmer.zip)

Unzip/extract the file to its own folder. (Click here (http://www.bleepingcomputer.com/tutorials/tutorial105.html) for information on how to do this if not sure. Win 2000 users click here (http://www.bleepingcomputer.com/tutorials/tutorial106.html).
When you have done this, disconnect from the Internet and close all running programs.
There is a small chance this application may crash your computer so save any work you have open.
Double-click on Gmer.exe to start the program.
Allow the gmer.sys driver to load if asked.
If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
Click on the Rootkit tab.
Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
Click on the "Scan" and wait for the scan to finish.
Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
Note: If you have any problems, try running GMER in SAFE MODE (http://www.bleepingcomputer.com/forums/tutorial61.html)"
Important! Please do not select the "Show all" checkbox during the scan..

djsuz
2009-06-18, 22:34
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-18 16:29:16
Windows 6.0.6001 Service Pack 1


---- Kernel code sections - GMER 1.0.15 ----

? system32\drivers\pyocrI.sys The system cannot find the path specified. !
? C:\Windows\System32\Drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload 8CBB146F 5 Bytes JMP 86BF71C8

---- User code sections - GMER 1.0.15 ----

.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!LdrShutdownThread 779AEC48 5 Bytes JMP 00246DAE
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!LdrGetDllHandle 779B5470 5 Bytes JMP 00246E38
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtAreMappedFilesTheSame 779C7ED8 5 Bytes JMP 002495DC
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCancelIoFile 779C7F18 5 Bytes JMP 0024A45A
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtClose 779C7F48 5 Bytes JMP 00248AD1
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCompactKeys 779C7F68 5 Bytes JMP 00251BF2
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCompressKey 779C7F98 5 Bytes JMP 00251B6F
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateFile 779C8008 5 Bytes JMP 0024A3B9
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateKey 779C8048 5 Bytes JMP 00251AB7
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateMailslotFile 779C8068 5 Bytes JMP 0024A321
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateNamedPipeFile 779C8088 5 Bytes JMP 0024A277
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreatePagingFile 779C80A8 5 Bytes JMP 0024A1EB
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateProcess 779C80C8 5 Bytes JMP 00246BCE
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateProcessEx 779C80D8 5 Bytes JMP 00246B33
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateSection 779C80F8 5 Bytes JMP 00250961
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateThread 779C8128 5 Bytes JMP 002469FA
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtDeleteFile 779C83E8 5 Bytes JMP 0024A168
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtDeleteKey 779C83F8 5 Bytes JMP 00251A1F
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtDeleteValueKey 779C8428 5 Bytes JMP 00251999
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtDeviceIoControlFile 779C8438 5 Bytes JMP 0024A0CA
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtDuplicateObject 779C8458 5 Bytes JMP 00248A3C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtEnumerateKey 779C8498 5 Bytes JMP 00251907
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtEnumerateValueKey 779C84C8 5 Bytes JMP 00251875
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtExtendSection 779C84D8 5 Bytes JMP 002508DB
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtFlushBuffersFile 779C8508 5 Bytes JMP 0024A044
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtFlushKey 779C8528 5 Bytes JMP 002517F2
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtFsControlFile 779C85A8 5 Bytes JMP 00249FA6
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtLoadKey 779C86A8 5 Bytes JMP 0025176C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtLoadKey2 779C86B8 5 Bytes JMP 002516E3
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtLoadKeyEx 779C86C8 5 Bytes JMP 00251657
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtLockFile 779C86D8 5 Bytes JMP 00249F08
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtLockRegistryKey 779C86F8 5 Bytes JMP 002515D4
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtMakeTemporaryObject 779C8728 5 Bytes JMP 002489B9
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtMapViewOfSection 779C8758 5 Bytes JMP 0025083D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtNotifyChangeDirectoryFile 779C8788 5 Bytes JMP 00249E6D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtNotifyChangeKey 779C8798 5 Bytes JMP 00251536
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtNotifyChangeMultipleKeys 779C87A8 5 Bytes JMP 00251492
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtOpenFile 779C87E8 5 Bytes JMP 0024A503
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtOpenKey 779C8818 5 Bytes JMP 00251409
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtOpenSection 779C8898 5 Bytes JMP 002507B4
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryAttributesFile 779C8988 5 Bytes JMP 00249DE7
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryDirectoryFile 779C89E8 5 Bytes JMP 00249D46
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryEaFile 779C8A18 5 Bytes JMP 00249CAB
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryFullAttributesFile 779C8A38 5 Bytes JMP 00249C25
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryInformationFile 779C8A58 5 Bytes JMP 00249B96
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryKey 779C8AE8 5 Bytes JMP 002512EE
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryMultipleValueKey 779C8AF8 5 Bytes JMP 0025125C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryObject 779C8B18 5 Bytes JMP 0024892A
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryOpenSubKeys 779C8B28 5 Bytes JMP 002511D6
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryOpenSubKeysEx 779C8B38 5 Bytes JMP 0025114A
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryQuotaInformationFile 779C8B58 5 Bytes JMP 00249541
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQuerySection 779C8B68 5 Bytes JMP 00250725
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQuerySecurityObject 779C8B78 5 Bytes JMP 0024861C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryValueKey 779C8C08 5 Bytes JMP 002510B8
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryVirtualMemory 779C8C18 5 Bytes JMP 0025060D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtQueryVolumeInformationFile 779C8C28 5 Bytes JMP 00249B07
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtReadFile 779C8C68 5 Bytes JMP 00249A6C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtReadFileScatter 779C8C78 5 Bytes JMP 002499D1
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtRenameKey 779C8CF8 5 Bytes JMP 00251032
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtReplaceKey 779C8D08 5 Bytes JMP 00250FA9
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtRestoreKey 779C8DC8 5 Bytes JMP 00250F20
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSaveKey 779C8DF8 5 Bytes JMP 00250E9A
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSaveKeyEx 779C8E08 5 Bytes JMP 00250E11
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSaveMergedKeys 779C8E18 5 Bytes JMP 00250D88
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetEaFile 779C8EB8 5 Bytes JMP 00249945
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetInformationFile 779C8F18 5 Bytes JMP 002498B6
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetInformationKey 779C8F38 5 Bytes JMP 00250CFC
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetInformationObject 779C8F48 5 Bytes JMP 0024889E
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetInformationProcess 779C8F58 5 Bytes JMP 0024696E
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetQuotaInformationFile 779C8FD8 5 Bytes JMP 002494B5
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetSecurityObject 779C8FE8 5 Bytes JMP 00248593
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetValueKey 779C9088 5 Bytes JMP 00250C55
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSetVolumeInformationFile 779C9098 5 Bytes JMP 00249827
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtSignalAndWaitForSingleObject 779C90B8 5 Bytes JMP 00248811
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtTerminateProcess 779C9128 5 Bytes JMP 0024782D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtTranslateFilePath 779C9198 5 Bytes JMP 00249429
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtUnloadKey 779C91B8 5 Bytes JMP 00250BD2
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtUnloadKey2 779C91C8 5 Bytes JMP 00250B4C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtUnloadKeyEx 779C91D8 5 Bytes JMP 00250AC6
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtUnlockFile 779C91E8 5 Bytes JMP 00249798
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtUnmapViewOfSection 779C9208 5 Bytes JMP 0025069F
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtWaitForMultipleObjects 779C9238 5 Bytes JMP 0024873F
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtWaitForSingleObject 779C9248 5 Bytes JMP 002486AB
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtWriteFile 779C9278 5 Bytes JMP 002496FD
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtWriteFileGather 779C9288 5 Bytes JMP 00249662
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ntdll.dll!NtCreateUserProcess 779C9438 5 Bytes JMP 00246A92
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!SetConsoleTitleW 776EF12F 5 Bytes JMP 00247ADE
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!QueryActCtxW 776F0302 5 Bytes JMP 00243EFA
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!CreateActCtxW 776FD0B2 5 Bytes JMP 00243DFA
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!ExitProcess 77703B54 5 Bytes JMP 00246D06
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!GetConsoleTitleW 77703E66 5 Bytes JMP 00247A3D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!GetCommandLineW 77704BF2 5 Bytes JMP 00246DE9
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!GetCommandLineA 77704DF8 5 Bytes JMP 00246D5F
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!CreateProcessInternalW 777098DD 5 Bytes JMP 00246C66
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!CreateRemoteThread 777246EF 5 Bytes JMP 00247C50
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!SetConsoleTitleA 77785FFD 5 Bytes JMP 002479A3
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] kernel32.dll!GetConsoleTitleA 777861B3 5 Bytes JMP 002478EC
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] gdi32.dll!GdiAddFontResourceW 7792E35B 5 Bytes JMP 002480AA
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] gdi32.dll!RemoveFontResourceExW 7794C90C 5 Bytes JMP 00247F48
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] USER32.dll!FindWindowA 77599DB7 5 Bytes JMP 0023A0D1
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] USER32.dll!GetWindowTextW 7759ACC3 5 Bytes JMP 0023A149
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] USER32.dll!GetWindowTextA 775A0F7B 5 Bytes JMP 00239DDC
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] USER32.dll!FindWindowExA 775A1001 5 Bytes JMP 00239FDB
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] USER32.dll!SetWindowTextW 775A925B 5 Bytes JMP 0023A20A
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] USER32.dll!FindWindowW 775A9949 5 Bytes JMP 0023A059
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] USER32.dll!SetWindowTextA 775BA7D9 5 Bytes JMP 00239EB3
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] USER32.dll!FindWindowExW 775C2DCA 5 Bytes JMP 00239F5D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!RegisterServiceCtrlHandlerA 766D2E78 5 Bytes JMP 00244D36
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!RegisterServiceCtrlHandlerExW 766DC7B3 5 Bytes JMP 00244B5C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!StartServiceCtrlDispatcherW 766DD8C3 5 Bytes JMP 002448E6
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!RegisterServiceCtrlHandlerW 766DDDB0 5 Bytes JMP 00244C9A
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!SetServiceStatus 766DE0C5 5 Bytes JMP 00244A1E
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!StartServiceW 766E2A49 5 Bytes JMP 002447A2
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!OpenSCManagerA 766EA275 5 Bytes JMP 00244415
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!OpenServiceA 766EA383 5 Bytes JMP 00245AAF
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!QueryServiceConfigW 766EC115 5 Bytes JMP 0024505D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!QueryServiceConfigA 766EC5E5 5 Bytes JMP 002450FF
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!QueryServiceStatusEx 766EEBF9 5 Bytes JMP 00244DD2
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!OpenSCManagerW 766EEECF 5 Bytes JMP 002443B5
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!OpenServiceW 766EFFC3 5 Bytes JMP 002451A1
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!CloseServiceHandle 766F00CD 5 Bytes JMP 0024581C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!QueryServiceStatus 766F038E 5 Bytes JMP 00244E77
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!RegisterServiceCtrlHandlerExA 7671109C 5 Bytes JMP 00244BFB
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!StartServiceA 767110DB 5 Bytes JMP 00244844
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!EnumServicesStatusExW 76713832 5 Bytes JMP 00244475
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!CreateServiceW 767138FF 5 Bytes JMP 002446A6
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!ControlService 76713B2D 5 Bytes JMP 0024577D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!DeleteService 76713BEE 5 Bytes JMP 00244649
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!GetServiceDisplayNameW 76714D47 5 Bytes JMP 0024523D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!GetServiceKeyNameW 76714DFC 5 Bytes JMP 00245381
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!EnumServicesStatusExA 76714FB3 5 Bytes JMP 002444ED
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!SetServiceBits 767564E1 5 Bytes JMP 00244ABA
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!EnumServicesStatusA 76756517 5 Bytes JMP 002445D7
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!QueryServiceObjectSecurity 767565F1 5 Bytes JMP 0024434C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!SetServiceObjectSecurity 767566A9 5 Bytes JMP 002442E9
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!ChangeServiceConfigA 767567A9 5 Bytes JMP 002456C9
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!ChangeServiceConfigW 76756951 5 Bytes JMP 00245615
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!CreateServiceA 76756C71 5 Bytes JMP 00244724
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!EnumDependentServicesA 76756ED5 5 Bytes JMP 0024556D
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!EnumDependentServicesW 76756FA9 5 Bytes JMP 002454C5
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!GetServiceDisplayNameA 76757081 5 Bytes JMP 002452DF
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!GetServiceKeyNameA 76757129 5 Bytes JMP 00245423
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!QueryServiceConfig2A 76757261 5 Bytes JMP 00244FB8
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!QueryServiceConfig2W 767573E9 5 Bytes JMP 00244F13
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!EnumServicesStatusW 76757931 5 Bytes JMP 00244565
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ADVAPI32.dll!StartServiceCtrlDispatcherA 76757C16 5 Bytes JMP 00244982
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ole32.dll!CoResumeClassObjects + 7 761FC0FF 5 Bytes JMP 0024E7F7
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ole32.dll!CoRegisterClassObject 762045AC 5 Bytes JMP 0024F0FD
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ole32.dll!CoGetClassObject 76226120 5 Bytes JMP 0024F1D3
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ole32.dll!CoCreateInstanceEx 7623E1CB 5 Bytes JMP 0024F27C
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ole32.dll!CoRevokeClassObject 762640C0 5 Bytes JMP 0024E996
.text C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe[4628] ole32.dll!CoGetInstanceFromFile 7629A4FC 5 Bytes JMP 0024F473

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [87E9161E] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [87E90AD4] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [87E91748] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [87E90B9C] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [87E90C1A] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [87EA629A] \SystemRoot\System32\Drivers\sptd.sys

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74A57BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74A998C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [74A5D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [74A4F527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74A57599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74A4E43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74A8B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [74A5D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74A5012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74A50095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74A471F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74ADD802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74A775E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74A4DAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74A4668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74A466BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3596] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74A51E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 844631E8
Device \Driver\netbt \Device\NetBT_Tcpip_{21EC751A-F0DF-4D8B-AF1C-5809AD679589} 8F5FB1E8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 8445F1E8
Device \Driver\usbuhci \Device\USBPDO-0 869861E8
Device \Driver\usbuhci \Device\USBPDO-1 869861E8
Device \Driver\usbehci \Device\USBPDO-2 86960790
Device \Driver\usbuhci \Device\USBPDO-3 869861E8
Device \Driver\usbuhci \Device\USBPDO-4 869861E8
Device \Driver\netbt \Device\NetBT_Tcpip_{4246B7FF-D8FF-47BD-8DE9-0D5CE6915CBB} 8F5FB1E8

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBPDO-5 869861E8
Device \Driver\usbehci \Device\USBPDO-6 86960790
Device \Driver\volmgr \Device\HarddiskVolume1 8445F1E8
Device \Driver\volmgr \Device\HarddiskVolume2 8445F1E8
Device \Driver\cdrom \Device\CdRom0 86B601E8
Device \Driver\cdrom \Device\CdRom1 86B601E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 844621E8
Device \Driver\iaStor \Device\Ide\iaStor0 844611E8
Device \Driver\atapi \Device\Ide\IdePort0 844621E8
Device \Driver\atapi \Device\Ide\IdePort1 844621E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 844611E8
Device \Driver\netbt \Device\NetBT_Tcpip_{FFED5106-B83C-4906-8224-4A088F0C7757} 8F5FB1E8
Device \Driver\netbt \Device\NetBt_Wins_Export 8F5FB1E8
Device \Driver\BTHUSB \Device\00000079 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\iScsiPrt \Device\RaidPort0 86B751E8

AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBFDO-0 869861E8
Device \Driver\usbuhci \Device\USBFDO-1 869861E8
Device \Driver\BTHUSB \Device\0000007b bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\usbehci \Device\USBFDO-2 86960790
Device \Driver\usbuhci \Device\USBFDO-3 869861E8
Device \Driver\usbuhci \Device\USBFDO-4 869861E8
Device \Driver\usbuhci \Device\USBFDO-5 869861E8
Device \Driver\usbehci \Device\USBFDO-6 86960790
---- Processes - GMER 1.0.15 ----

Library C:\Program (*** hidden *** ) @ C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe [4628] 0x002D0000

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3703d869
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4E 0x0E 0x16 0xF7 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFB 0x9B 0x82 0x3A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF4 0x46 0xB0 0x8E ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e3703d869
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4E 0x0E 0x16 0xF7 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFB 0x9B 0x82 0x3A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF4 0x46 0xB0 0x8E ...

Shaba
2009-06-19, 11:35
Download random's system information tool (RSIT) by random/random from here (http://images.malwareremoval.com/random/RSIT.exe) and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

djsuz
2009-06-19, 14:13
Logfile of random's system information tool 1.06 (written by random/random)
Run by Element Painters at 2009-06-19 07:59:26
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 16 GB (7%) free of 231 GB
Total RAM: 2038 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:00:18, on 19/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoardLauncher.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\msfeedssync.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\WebReaper\WebReaper.exe
C:\Program Files\Microsoft Expression\Web 2\WebDesigner\EXPRWD.EXE
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Element Painters\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Element Painters.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe_ID0EXG] "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoardLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: Xenocode Sandbox Manager.lnk = C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe
O4 - Global Startup: Register Mask Pro 3.0.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - (no file)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: APSHook.dll,avgrsstx.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\Windows\SYSTEM32\astsrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Program Files\FileZilla Server\FileZilla Server.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hMailServer - hMailServer - C:\Program Files\hMailServer\Bin\hMailServer.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Unknown owner - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.33\bin\mysqld.exe

--
End of file - 12738 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\User_Feed_Synchronization-{FDDAB75D-16A0-492C-9C1B-EA42F62C7D74}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{145B29F4-A56B-4b90-BBAC-45784EBEBBB7}]
StumbleUpon Launcher - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll [2007-10-24 987832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-01-04 304736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-05-19 1107224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-24 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
VeriSoft Access Manager - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll [2006-11-21 71192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5093EB4C-3E93-40AB-9266-B607BA87BDC8} - StumbleUpon Toolbar - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll [2007-10-24 987832]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2007-01-16 634880]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-28 1045800]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-03-09 4390912]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-02-12 174872]
"QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2007-02-13 159744]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-03-01 472776]
"WAWifiMessage"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [2007-01-10 317128]
"CognizanceTS"=c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll [2003-12-22 17920]
"SynTPStart"=C:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-09-15 102400]
"MSConfig"=C:\Windows\system32\msconfig.exe [2008-01-19 227840]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-14 644696]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
"WrtMon.exe"=C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe [2006-09-20 20480]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-01-04 185872]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-05-19 1947928]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]
"Adobe_ID0EXG"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoardLauncher.exe [2008-06-11 472448]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"=C:\Windows\SMINST\launcher.exe [2006-11-07 44128]
"Uninstall Adobe Download Manager"=C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2009-06-04 66048]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-12 68856]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
C:\Program Files\HP\QuickPlay\QPService.exe [2007-04-23 176128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2006-12-20 719664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
C:\PROGRA~1\COMMON~1\Intuit\QUICKB~1\QBUpdate\qbupdate.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
C:\PROGRA~1\WinZip\WZQKPICK.EXE [2008-04-28 415072]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Register Mask Pro 3.0.lnk -

C:\Users\Element Painters\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe
Xenocode Sandbox Manager.lnk - C:\Users\Element Painters\AppData\Local\Xenocode\Start\2.11\Xenocode.Sandbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="APSHook.dll,avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ad7d43e-5b72-11dd-8dd3-001e3703d869}]
shell\AutoRun\command - G:\Autoplay.exe -auto


======File associations======

.js - edit -
.js - open -
.txt - open - "C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe" "%1"

======List of files/folders created in the last 1 months======

2009-06-19 07:59:26 ----DC---- C:\rsit
2009-06-17 09:10:34 ----D---- C:\Program Files\Secunia
2009-06-16 19:21:58 ----D---- C:\Users\Element Painters\AppData\Roaming\Malwarebytes
2009-06-16 19:21:50 ----D---- C:\ProgramData\Malwarebytes
2009-06-16 19:21:49 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-16 17:04:11 ----D---- C:\Windows\temp
2009-06-16 17:03:02 ----AC---- C:\smitfiles.txt
2009-06-16 16:56:40 ----D---- C:\Program Files\RogueRemover FREE
2009-06-16 16:48:05 ----D---- C:\Program Files\Trend Micro
2009-06-16 16:28:34 ----A---- C:\Windows\system32\tmp.txt
2009-06-16 16:28:34 ----A---- C:\Users\Element Painters\AppData\Roaming\SetValue.bat
2009-06-16 16:28:34 ----A---- C:\Users\Element Painters\AppData\Roaming\GetValue.vbs
2009-06-16 16:28:12 ----AC---- C:\rapport.txt
2009-06-16 16:27:50 ----A---- C:\Windows\system32\WS2Fix.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\VCCLSID.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\VACFix.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\swxcacls.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\swsc.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\swreg.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\SrchSTS.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\Process.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\o4Patch.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\IEDFix.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\IEDFix.C.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\dumphive.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\Agent.OMZ.Fix.exe
2009-06-16 16:27:50 ----A---- C:\Windows\system32\404Fix.exe
2009-06-16 16:23:44 ----A---- C:\Windows\ntbtlog.txt
2009-06-16 09:32:02 ----D---- C:\Program Files\WebReaper
2009-06-14 11:21:12 ----A---- C:\Windows\system32\EncDec.dll
2009-06-14 11:21:11 ----A---- C:\Windows\system32\psisdecd.dll
2009-06-13 11:51:55 ----D---- C:\Program Files\MagicDisc
2009-06-11 17:31:03 ----A---- C:\Windows\system32\mshtml.dll
2009-06-11 17:30:58 ----A---- C:\Windows\system32\ieframe.dll
2009-06-11 17:30:57 ----A---- C:\Windows\system32\urlmon.dll
2009-06-11 17:30:56 ----A---- C:\Windows\system32\wininet.dll
2009-06-11 17:30:55 ----A---- C:\Windows\system32\iertutil.dll
2009-06-11 17:30:55 ----A---- C:\Windows\system32\iedkcs32.dll
2009-06-11 17:30:54 ----A---- C:\Windows\system32\msfeeds.dll
2009-06-11 17:30:53 ----A---- C:\Windows\system32\ieaksie.dll
2009-06-11 17:30:52 ----A---- C:\Windows\system32\occache.dll
2009-06-11 17:30:51 ----A---- C:\Windows\system32\ieUnatt.exe
2009-06-11 17:30:51 ----A---- C:\Windows\system32\ieencode.dll
2009-06-11 17:30:50 ----A---- C:\Windows\system32\mstime.dll
2009-06-11 17:30:48 ----A---- C:\Windows\system32\jsproxy.dll
2009-06-10 12:30:59 ----D---- C:\Users\Element Painters\AppData\Roaming\Corel
2009-06-10 12:29:38 ----D---- C:\Program Files\Common Files\Corel
2009-06-10 12:29:27 ----D---- C:\Program Files\Common Files\Protexis
2009-06-10 12:29:26 ----D---- C:\ProgramData\Corel
2009-06-10 12:24:53 ----D---- C:\Program Files\Corel
2009-06-10 11:26:33 ----A---- C:\Windows\system32\localspl.dll
2009-06-10 11:20:46 ----A---- C:\Windows\system32\rpcrt4.dll
2009-06-04 21:05:32 ----D---- C:\Program Files\QuickTime
2009-06-02 12:46:57 ----D---- C:\Program Files\Microsoft Synchronization Services
2009-06-02 12:46:37 ----D---- C:\Program Files\hMailServer
2009-06-02 12:46:37 ----A---- C:\Windows\system32\atl70.dll
2009-06-01 09:45:50 ----D---- C:\Program Files\Core Services
2009-05-31 23:25:18 ----D---- C:\Users\Element Painters\AppData\Roaming\onOne Software
2009-05-31 23:25:18 ----A---- C:\Windows\system32\ASTSRV.EXE
2009-05-31 23:25:12 ----D---- C:\ProgramData\onOne Software
2009-05-31 23:21:04 ----A---- C:\Windows\system32\Deco_32.dll
2009-05-31 18:30:59 ----D---- C:\Users\Element Painters\AppData\Roaming\Mask Pro 4.0
2009-05-31 16:18:46 ----D---- C:\Program Files\onOne Software
2009-05-30 20:31:10 ----D---- C:\Users\Element Painters\AppData\Roaming\WinRAR
2009-05-30 20:30:27 ----D---- C:\Program Files\WinRAR
2009-05-30 12:10:37 ----D---- C:\Program Files\Common Files\Control Panels
2009-05-30 08:42:34 ----D---- C:\Program Files\Common Files\FontLab
2009-05-30 08:42:33 ----D---- C:\Program Files\FontLab
2009-05-28 20:57:25 ----D---- C:\Users\Element Painters\AppData\Roaming\Blender Foundation
2009-05-23 21:28:10 ----D---- C:\Users\Element Painters\AppData\Roaming\dvdcss

======List of files/folders modified in the last 1 months======

2009-06-19 08:00:14 ----D---- C:\Users\Element Painters\AppData\Roaming\BitTorrent
2009-06-19 07:59:43 ----D---- C:\Windows\Prefetch
2009-06-19 05:06:25 ----SHD---- C:\System Volume Information
2009-06-18 18:53:59 ----SHD---- C:\Windows\Installer
2009-06-18 18:53:58 ----SHD---- C:\Config.Msi
2009-06-18 18:53:01 ----D---- C:\Windows\System32
2009-06-18 14:47:22 ----D---- C:\Windows\Tasks
2009-06-18 14:47:21 ----D---- C:\ProgramData\Google Updater
2009-06-17 09:57:56 ----D---- C:\Program Files\Common Files\Adobe
2009-06-17 09:57:28 ----D---- C:\ProgramData\Adobe
2009-06-17 09:56:35 ----D---- C:\Program Files\Adobe
2009-06-17 09:53:28 ----D---- C:\Program Files\Opera
2009-06-17 09:42:11 ----D---- C:\Program Files\Safari
2009-06-17 09:28:50 ----D---- C:\ProgramData\NOS
2009-06-17 09:28:20 ----D---- C:\Program Files\NOS
2009-06-17 09:17:36 ----D---- C:\Windows\SMINST
2009-06-17 09:10:51 ----D---- C:\Windows\system32\Tasks
2009-06-17 09:10:35 ----D---- C:\Windows\system32\drivers
2009-06-17 09:10:34 ----RD---- C:\Program Files
2009-06-17 02:08:37 ----HDC---- C:\$AVG8.VAULT$
2009-06-16 22:43:06 ----D---- C:\Windows\inf
2009-06-16 22:43:06 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-06-16 22:38:12 ----AD---- C:\Windows
2009-06-16 19:21:50 ----HD---- C:\ProgramData
2009-06-16 17:13:54 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-06-16 16:31:51 ----SD---- C:\Windows\Downloaded Program Files
2009-06-15 03:10:36 ----D---- C:\Windows\Microsoft.NET
2009-06-15 03:10:10 ----RSD---- C:\Windows\assembly
2009-06-15 03:05:55 ----D---- C:\Windows\winsxs
2009-06-15 03:05:53 ----D---- C:\Windows\ehome
2009-06-14 13:27:25 ----HD---- C:\Program Files\InstallShield Installation Information
2009-06-14 10:36:40 ----D---- C:\Windows\system32\catroot2
2009-06-14 10:36:40 ----D---- C:\Windows\system32\catroot
2009-06-13 03:27:00 ----D---- C:\Program Files\Internet Explorer
2009-06-13 03:17:07 ----D---- C:\ProgramData\Microsoft Help
2009-06-13 03:14:26 ----D---- C:\Program Files\Microsoft Works
2009-06-12 18:29:14 ----D---- C:\Program Files\Mozilla Firefox
2009-06-10 12:29:38 ----D---- C:\Program Files\Common Files
2009-06-02 22:59:10 ----D---- C:\Windows\Minidump
2009-06-02 12:46:56 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-06-01 19:00:57 ----AD---- C:\ProgramData\TEMP
2009-06-01 12:51:12 ----A---- C:\Windows\system32\mrt.exe
2009-05-31 18:28:33 ----A---- C:\Windows\system32\prsgrc.dll
2009-05-31 18:28:33 ----A---- C:\Windows\system32\bjtux74.dll
2009-05-31 13:24:10 ----D---- C:\Users\Element Painters\AppData\Roaming\Adobe
2009-05-31 13:06:25 ----D---- C:\Windows\Logs
2009-05-29 16:11:44 ----D---- C:\ProgramData\Skype
2009-05-29 16:01:14 ----D---- C:\Users\Element Painters\AppData\Roaming\skypePM
2009-05-26 17:03:48 ----RSD---- C:\Windows\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-05-19 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-05-19 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-05-19 108552]
R1 eabfiltr;eabfiltr; C:\Windows\system32\DRIVERS\eabfiltr.sys [2006-11-30 8192]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2008-01-20 33292]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-01-23 37376]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\Windows\system32\DRIVERS\ATSwpDrv.sys [2007-03-28 140424]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-19 19456]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-28 29184]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-01-02 78128]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-01-02 80688]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-01-02 16560]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-03-19 23400]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-03-12 1747936]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys [2009-02-24 116736]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-19 49664]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-03-05 76288]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-19 88576]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2007-01-16 983936]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-03-28 199472]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-19 11264]
S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys []
S3 amie80h3;amie80h3; C:\Windows\system32\drivers\amie80h3.sys []
S3 aujasnkj;aujasnkj; \??\C:\Users\ELEMEN~1\AppData\Local\Temp\aujasnkj.sys []
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 464384]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2008-04-28 220160]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 E100B;Intel(R) PRO Adapter Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-11-02 163328]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-01-19 19712]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-01-19 18304]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [2009-03-24 7808]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-03-05 36864]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2006-11-02 654336]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
R2 ASBroker;Logon Session Broker; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 ASChannel;Local Communication Channel; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 astcc;AST Service; C:\Windows\SYSTEM32\astsrv.exe [2008-05-07 57344]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-05-19 908568]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-05-19 298776]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [2007-04-23 262243]
R2 hMailServer;hMailServer; C:\Program Files\hMailServer\Bin\hMailServer.exe [2009-05-18 5038080]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-09-19 65536]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2007-02-12 355096]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-12-14 61440]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 SwitchBoard;Adobe SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2008-06-11 660864]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
S2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [2007-04-23 106593]
S2 FileZilla Server;FileZilla Server FTP server; C:\Program Files\FileZilla Server\FileZilla Server.exe []
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 183280]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-01-08 68096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-03-09 655624]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2009-06-04 66048]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-02-12 880640]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe []
S3 wampapache;wampapache; c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe [2008-12-10 24636]
S3 wampmysqld;wampmysqld; c:\wamp\bin\mysql\mysql5.1.33\bin\mysqld.exe [2009-03-16 6562432]

-----------------EOF-----------------

djsuz
2009-06-19, 14:14
info.txt logfile of random's system information tool 1.06 2009-06-19 08:00:31

======Uninstall list======

-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
Acrobat.com-->msiexec /qb /x {77DCDCE3-2DED-62F3-8154-05E745472D07}
Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe After Effects CS3 Presets-->MsiExec.exe /I{4B215C29-1A3E-4736-92AA-10C83FA56EB9}
Adobe After Effects CS3-->C:\Program Files\Common Files\Adobe\Installers\b7dd24a87e82dcf8af8876fd727b7cf\Setup.exe
Adobe After Effects CS3-->MsiExec.exe /I{8AF3FB06-BDA3-42A3-995C-308812D2F094}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Adobe Color EU Extra Settings CS4-->MsiExec.exe /I{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
Adobe Color NA Recommended Settings CS4-->MsiExec.exe /I{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe Download Manager-->"C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Extension Manager CS3-->MsiExec.exe /I{D7A53E41-3F32-4A44-989C-53DDEBB2130C}
Adobe Fireworks CS3-->C:\Program Files\Common Files\Adobe\Installers\bbef028176efa5abf0233d3e1747be8\Setup.exe
Adobe Fireworks CS3-->MsiExec.exe /I{E16110F7-1C85-4675-99F4-7938F832C825}
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Illustrator CS3-->C:\Program Files\Common Files\Adobe\Installers\a04a925a57548091300ada368235fc6\Setup.exe
Adobe Illustrator CS3-->MsiExec.exe /I{F08E8D2E-F132-4742-9C87-D5FF223A016A}
Adobe InDesign CS-->RunDll32 "C:\Program Files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll",LaunchSetup "C:\Program Files\InstallShield Installation Information\{416DFEDD-9F1B-4EFC-AF70-FCA891AE0251}\zidxp.exe"
Adobe InDesign CS3 Icon Handler-->MsiExec.exe /I{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
Adobe InDesign CS3-->C:\Program Files\Common Files\Adobe\Installers\05ba3a63f36684fe0c5dde2ebe6f8f5\Setup.exe
Adobe InDesign CS3-->MsiExec.exe /I{CB3F8375-B600-4B9F-83C9-238ED1E583FD}
Adobe kuler-->msiexec /qb /x {E4D41458-B6F7-8363-0AA2-F822E489CA8F}
Adobe kuler-->MsiExec.exe /I{E4D41458-B6F7-8363-0AA2-F822E489CA8F}
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe Media Player-->msiexec /qb /x {39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
Adobe Media Player-->MsiExec.exe /I{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
Adobe MotionPicture Color Files-->MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
Adobe Photoshop CS-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x9
Adobe Photoshop CS3-->C:\Program Files\Common Files\Adobe\Installers\2ac78060bc5856b0c1cf873bb919b58\Setup.exe
Adobe Photoshop CS3-->MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 9.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Adobe Setup-->MsiExec.exe /I{130C33C3-F900-461A-B2D3-D1C0F118A883}
Adobe Setup-->MsiExec.exe /I{15C768E2-AB61-4DE3-952F-6B237A834951}
Adobe Setup-->MsiExec.exe /I{2C294A0B-DF22-4023-B168-8C7645B10019}
Adobe Setup-->MsiExec.exe /I{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}
Adobe Setup-->MsiExec.exe /I{56B8B892-317E-4FDE-9E4D-44B189848A27}
Adobe Setup-->MsiExec.exe /I{D1BB4446-AE9C-4256-9A7F-4D46604D2462}
Adobe Shockwave Player 11-->C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
Adobe SING CS3-->MsiExec.exe /I{3F9B2FD2-1C83-4401-9967-C3636638E958}
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe SVG Viewer 3.0-->C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log
Adobe SwitchBoard 1.0-->C:\Program Files\Common Files\Adobe\Installers\e343e49b6e54b5a15f248a76155dc41\Setup.exe --uninstall=1
Adobe SwitchBoard 1.0-->MsiExec.exe /I{345F0ED4-999A-48C8-AD2D-FE953FA26EFC}
Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe Video Profiles-->MsiExec.exe /I{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP DVA Panels CS3-->MsiExec.exe /I{0224CACC-994D-45F8-B973-D65056EA9C2F}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
Apple Mobile Device Support-->MsiExec.exe /I{659B48CD-0608-4ED5-94C0-0B6C87114F10}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
AusLogics BoostSpeed-->"C:\Program Files\Auslogics\AusLogics BoostSpeed\unins000.exe"
AuthenTec Fingerprint Sensor Minimum Install-->MsiExec.exe /I{B61B6668-A674-4A06-8405-51944D5CCDDD}
AVG Free 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Big Fish Games Client-->C:\Program Files\bfgclient\Uninstall.exe
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Canon iP6320D-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP6320D\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP6320D /L0x0009
Canon MP Navigator EX 1.0-->"C:\Program Files\Canon\MP Navigator EX 1.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator EX 1.0\uninst.ini
Canon Utilities Solution Menu-->C:\Program Files\Canon\SolutionMenu\uninst.exe uninst.ini
CanoScan LiDE 90-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2412\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2412 /L0x0009
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Content-->MsiExec.exe /I{B369483E-0728-405C-8F8C-3427B263B01F}
Corel Painter 11 - ICA-->MsiExec.exe /I{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}
Corel Painter 11 - IPM-->MsiExec.exe /I{7EC69F77-5494-4E1F-8BC6-956DAA5A91F2}
Corel Painter 11-->c:\Program Files\Corel\Corel Painter 11\Setup\SetupARP.exe /arp
Corel Painter 11-->MsiExec.exe /I{28F8F8F0-C278-454A-9507-46B344AAD188}
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
ESU for Microsoft Vista-->MsiExec.exe /X{1517A7CB-5F00-4A88-8F06-E89B6DB63784}
FocalPoint 1.0-->"C:\Program Files\InstallShield Installation Information\{9EB46587-4354-411C-BBAC-A9BBB2131F3D}\setup.exe" -runfromtemp -l0x0009 -uninst -removeonly
FontLab Studio 5-->"C:\Program Files\FontLab\Studio5\Uninstall.exe" "C:\Program Files\FontLab\Studio5\install.log"
FoxyTunes for Firefox-->"C:\PROGRA~1\MOZILL~1\firefox.exe" -chrome chrome://foxytunes/content/extras/uninstallExtension.xul
Genuine Fractals 5.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC38B36B-90F8-4C1F-8AC9-236B851B8871}\setup.exe" -l0x9 -uninst -removeonly
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
hMailServer 5.1.2-B346-->"C:\Program Files\hMailServer\unins000.exe"
HP Active Support Library 32 bit components-->MsiExec.exe /I{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}
HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{11BB336F-0E58-4977-B866-F24FA334616B}\setup.exe -runfromtemp -l0x0409
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
HP Help and Support-->MsiExec.exe /I{9061CEF2-51F5-42C9-8A70-9ED351C6597A}
HP Integrated Module with Bluetooth wireless technology-->MsiExec.exe /X{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}
HP Photosmart Essential 2.0-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
HP Quick Launch Buttons 6.20 B1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x0009 uninst
HP QuickPlay 3.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
HP Update-->MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
HP User Guides 0057-->MsiExec.exe /I{DDFD9BA2-8E26-4E49-92AE-882424DAB1BC}
HP Wireless Assistant-->MsiExec.exe /I{D32067CD-7409-4792-BFA0-1469BCD8F0C8}
HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
IconHandler 32 bit-->MsiExec.exe /X{1AED4ABF-0852-4B3F-9F87-00CF88F25CE0}
IETester v0.3.3 (remove only)-->"C:\Program Files\Core Services\IETester\uninstall.exe"
Intel Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Intellihance Pro 4.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32C7FDDF-8D18-4B29-B81A-CDA512093274}\setup.exe" -l0x9 -uninst -removeonly
iPod To Computer Transfer 3.1-->"C:\Program Files\iPod To Computer Transfer\unins000.exe"
iTunes-->MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Langauge-->MsiExec.exe /I{840BF2FE-033D-437C-89D1-AAA206BA13B6}
Last.fm 1.5.4.24567-->"C:\Program Files\Last.fm\unins000.exe"
LiveUpdate Notice (Symantec Corporation)-->MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
Magic ISO Maker v5.5 (build 0276)-->C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
MagicDisc 2.7.106-->C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Malwarebytes' RogueRemover-->"C:\Program Files\RogueRemover FREE\unins000.exe"
Mask Pro 4.1-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2DFAC810-6DD8-4E23-96A4-BEB118408203}\setup.exe" -l0x9 -uninst -removeonly
Media Lab SiteGrinder 2 (Basic & Pro)-->C:\Program Files\Adobe\Adobe Photoshop CS3\Plug-Ins\Media Lab SiteGrinder 2\Uninstall SiteGrinder 2.exe
Media Player Codec Pack 2.2.0-->C:\Windows\system32\C2MP\Uninst.exe
Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 3.5-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
Microsoft Expression Web 2 MUI (English)-->MsiExec.exe /X{90120000-0045-0409-0000-0000000FF1CE}
Microsoft Expression Web 2-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall XWEB /dll XSETUP.DLL
Microsoft Expression Web 2-->MsiExec.exe /X{90120000-0045-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs-->MsiExec.exe /X{90120000-00B2-0409-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server Compact 3.5 ENU-->MsiExec.exe /I{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
Motorola SM56 Data Fax Modem-->rundll32.exe sm56co6a.dll,SM56UnInstaller
Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSCU for Microsoft Vista-->MsiExec.exe /X{3FFB3B34-D639-4384-9AE9-DDE58430D86F}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
Notepad++-->C:\Program Files\Notepad++\uninstall.exe
Opera 9.64-->MsiExec.exe /X{A2A60894-E3ED-46FE-9A6A-7CF7A87572A0}
PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
PhotoFrame Pro 3.1-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5F073685-ADDB-4D5A-98E9-0F795989A57F}\setup.exe" -l0x9 -uninst -removeonly
PhotoTools 1.0 Professional Edition-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B01DD5B7-9862-43D7-BCA3-7882A17E4328}\setup.exe" -l0x9 -uninst -removeonly
PhotoTune 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C723788-585C-4537-92AC-CF616209197C}\setup.exe" -l0x9 -uninst -removeonly
Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"
Presto! PageManager 7.15.16-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}\PMSetup.exe" -l0x9 anythinganything -removeonly
QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
RocketDock 1.3.5-->"C:\Program Files\RocketDock\unins000.exe"
Roxio Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
Roxio MyDVD Basic v9-->MsiExec.exe /I{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}
Safari-->MsiExec.exe /I{C5C649A8-1D21-4C83-9B08-7B3752E580F4}
ScanSoft OmniPage SE 4-->MsiExec.exe /X{DEE88727-779B-47A9-ACEF-F87CA5F92A65}
Secunia PSI-->"C:\Program Files\Secunia\PSI\uninstall.exe"
Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0045-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0045-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0045-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0045-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0045-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
Security Update for Visio 2007 (KB947590)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
StumbleUpon IE Toolbar-->C:\Program Files\StumbleUpon\uninstall.exe
SupportSoft Assisted Service-->MsiExec.exe /I{5A3F6A80-7913-475E-8B96-477A952CFA43}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Tri-Peaks 2: Quest for the Ruby Ring-->"C:\Program Files\Tri-Peaks 2 - Quest for the Ruby Ring\Uninstall.exe"
Ultimate Dominoes (remove only)-->"C:\Program Files\Ultimate Dominoes\Uninstall.exe"
Unlocker 1.8.7-->C:\Program Files\Unlocker\uninst.exe
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0045-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft Expression Web 2 (KB957827)-->msiexec /package {90120000-0045-0000-0000-0000000FF1CE} /uninstall {DCA28998-1FE8-4CEA-818D-027D8B15F119}
Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
Update for Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
Update for Microsoft Office OneNote 2007 Help (KB963670)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2744EF05-38E1-4D5D-B333-E021EDAEA245}
Update for Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
Update for Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
VeriSoft Access Manager-->rundll32.exe "c:\Program Files\Bioscrypt\VeriSoft\Bin\SetupHelper.dll",ExecMain /Uninstall {0ABA40AF-288D-41F1-B735-C5155692CD7D}
Vertus Fluid Mask 3 3.0.10-->"C:\Program Files\Vertus Fluid Mask 3\Uninstall.exe"
VLC media player 0.9.9-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WampServer 2.0-->"c:\wamp\unins000.exe"
Waterscape Solitaire: American Falls-->"C:\Program Files\Waterscape Solitaire - American Falls\Uninstall.exe"
WebReaper v10-->"C:\Program Files\WebReaper\unins000.exe"
Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{C6CA8874-5F22-4AF0-9BE3-016BF299C536}
Windows Live Mail-->MsiExec.exe /I{63C1109E-D977-49ED-BCE3-D00D0BF187D6}
Windows Live Messenger-->MsiExec.exe /X{0AAA9C97-74D4-47CE-B089-0B147EF3553C}
Windows Live Photo Gallery-->MsiExec.exe /X{3C52E7DA-C431-4239-B66B-1BF703D5B194}
Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5}
Windows Live Sync-->MsiExec.exe /X{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}
Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Windows Live Writer-->MsiExec.exe /X{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WinZip 11.2-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}
Wise-FTP-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F22C63FE-DBA4-4FDA-9306-55AA627CE6C7}\Setup.exe" -l0x9
Xara3D6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3783869-5D14-4838-A042-910DF816D070}\setup.exe" -l0x9

======Hosts File======

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

======Security center information======

AV: AVG Anti-Virus Free
AS: AVG Anti-Virus Free (disabled)
AS: Spybot - Search and Destroy
AS: Windows Defender

======System event log======

Computer Name: ElementPaint-PC
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 7558055
Source Name: Service Control Manager
Time Written: 20090619115659.000000-000
Event Type: Error
User:

Computer Name: ElementPaint-PC
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 7558056
Source Name: Service Control Manager
Time Written: 20090619115709.000000-000
Event Type: Error
User:

Computer Name: ElementPaint-PC
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 7558057
Source Name: Service Control Manager
Time Written: 20090619115719.000000-000
Event Type: Error
User:

Computer Name: ElementPaint-PC
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 7558058
Source Name: Service Control Manager
Time Written: 20090619115729.000000-000
Event Type: Error
User:

Computer Name: ElementPaint-PC
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 7558059
Source Name: Service Control Manager
Time Written: 20090619115740.000000-000
Event Type: Error
User:

=====Application event log=====

Computer Name: ElementPaint-PC
Event Code: 513
Message: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.

System Error:
Access is denied.
.
Record Number: 41725
Source Name: Microsoft-Windows-CAPI2
Time Written: 20090618040034.000000-000
Event Type: Error
User:

Computer Name: ElementPaint-PC
Event Code: 513
Message: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.

System Error:
Access is denied.
.
Record Number: 41726
Source Name: Microsoft-Windows-CAPI2
Time Written: 20090618040041.000000-000
Event Type: Error
User:

Computer Name: ElementPaint-PC
Event Code: 1010
Message: The Collect Procedure for the "EmdCache" service in DLL "C:\Windows\system32\emdmgmt.dll" generated an exception or returned an invalid status. The performance data returned by the counter DLL will not be returned in the Perf Data Block. The first four bytes (DWORD) of the Data section contains the exception code or status code.
Record Number: 41732
Source Name: Microsoft-Windows-Perflib
Time Written: 20090618161338.000000-000
Event Type: Error
User:

Computer Name: ElementPaint-PC
Event Code: 513
Message: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.

System Error:
Access is denied.
.
Record Number: 41744
Source Name: Microsoft-Windows-CAPI2
Time Written: 20090619090618.000000-000
Event Type: Error
User:

Computer Name: ElementPaint-PC
Event Code: 513
Message: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.

System Error:
Access is denied.
.
Record Number: 41745
Source Name: Microsoft-Windows-CAPI2
Time Written: 20090619090622.000000-000
Event Type: Error
User:

=====Security event log=====

Computer Name: ElementPaint-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 45384
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619120012.158000-000
Event Type: Audit Failure
User:

Computer Name: ElementPaint-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 45385
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619120012.205000-000
Event Type: Audit Failure
User:

Computer Name: ElementPaint-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 45386
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619120012.252000-000
Event Type: Audit Failure
User:

Computer Name: ElementPaint-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 45387
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619120012.338000-000
Event Type: Audit Failure
User:

Computer Name: ElementPaint-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 45388
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619120012.407000-000
Event Type: Audit Failure
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;c:\Program Files\Bioscrypt\VeriSoft\bin;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"PLATFORM"=MCD
"PCBRAND"=Pavilion
"OnlineServices"=Online Services
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------

Also let me just add that last night whilst listening to music on itunes the sound was stuttering. Not just in itunes but in VLC media player so I am assuming there is something to do with a codec?

Shaba
2009-06-19, 15:45
Please download GooredFix (http://jpshortstuff.247fixes.com/GooredFix.exe) and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.

djsuz
2009-06-19, 16:38
GooredFix v1.92 by jpshortstuff
Log created at 10:38 on 19/06/2009 running Option #1 (Element Painters)
Firefox version 3.0.11 (en-GB)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.11\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.11\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord"

Shaba
2009-06-19, 16:59
Do you still have popups?

djsuz
2009-06-19, 17:07
No but since removing the virus I am left with stuttering sound in all my media players.
What could be causing this now?
I have never had a problem with the sound and it's a fairly new laptop.

Any ideas as I don't feel confident that the remnants are completely gone.

Thanks for your time Shaba.

Shaba
2009-06-19, 19:07
Corrupted codecs perhaps.

FFDShow (http://www.free-codecs.com/download/FFDshow.htm) should help.

djsuz
2009-06-19, 19:11
Do I just click all the way through and not change any of the settings prior to install?

Shaba
2009-06-19, 20:19
Yes, default settings should be fine.

djsuz
2009-06-19, 20:59
Cheers,

Ok so itunes playback seems to be fine, have tested for one hour and no stuttering. Testing VLC now and it so far is all well and good.

So I am assuming I am virus/malware free now?

Shaba
2009-06-20, 11:55
Let's check this first:

Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a fresh HijackThis log.

If you need a tutorial, see here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif)

djsuz
2009-06-20, 22:27
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:26:08, on 20/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoardLauncher.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\WebReaper\WebReaper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Windows\system32\msfeedssync.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe_ID0EXG] "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoardLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Register Mask Pro 3.0.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - (no file)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: APSHook.dll,avgrsstx.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\Windows\SYSTEM32\astsrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Program Files\FileZilla Server\FileZilla Server.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hMailServer - hMailServer - C:\Program Files\hMailServer\Bin\hMailServer.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Unknown owner - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.33\bin\mysqld.exe

--
End of file - 12648 bytes

djsuz
2009-06-20, 22:28
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Saturday, June 20, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Saturday, June 20, 2009 16:05:27
Records in database: 2371145
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 296140
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 05:45:44

No malware has been detected. The scan area is clean.

The selected area was scanned.

Shaba
2009-06-21, 10:40
Good :)

Still problems?

djsuz
2009-06-21, 16:48
No Shaba,

I defragmented my disk drive yesterday to speed it up a bit.
No stuttering and no popups.
You guys provide a wonderful service and I am very much grateful that you helped me.
Thanks Shaba and I hope I don't have to speak to you again!

Shaba
2009-06-21, 18:01
Good :)

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Please download JavaRa (http://sourceforge.net/project/downloading.php?groupname=javara&filename=JavaRa.zip&use_mirror=osdn) and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

Double-click on JavaRa.exe to start the program.
From the drop-down menu, choose English and click on Select.
JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
A logfile will pop up. Please save it to a convenient location.

Then download and install Java Runtime Environment (JRE) 6 Update 14 (http://java.sun.com/javase/downloads/index.jsp)

Looking over your log, it seems you don't have any evidence of a third party firewall.

As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

1) Comodo (http://www.personalfirewall.comodo.com/download_firewall.html) (Uncheck during installation "Install COMODO Antivirus (Recommended)"!, "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage")
2) Online Armor (http://www.tallemu.com/online_armor_free.html)
3) PC Tools (http://www.pctools.com/firewall/download/)
4) Sunbelt/Kerio (http://www.sunbelt-software.com/Kerio-Download.cfm)
5) ZoneAlarm (http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za) (uncheck ZoneAlarm Spy Blocker during installation if you choose this one)

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

Next we remove all used tools.

Please download OTCleanIt (http://oldtimer.geekstogo.com/OTC.exe) and save it to desktop.

Double-click OTC.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software and keep your other programs up-to-date Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector (http://secunia.com/software_inspector/)
F-secure Health Check (http://www.f-secure.com/weblog/archives/00001356.html)

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Malwarebytes' Anti-Malware - Malwarebytes''Anti-Malware is a new and powerful anti-malware tool. It is
totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

Malwarebytes' Anti-Malware Setup Guide (http://www.lognrock.com/forum/index.php?showtopic=6926)

Malwarebytes' Anti-Malware Scanning Guide (http://www.lognrock.com/forum/index.php?showtopic=6913)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. See also a hosts file tutorial here (http://malwareremoval.com/forum/viewtopic.php?t=22187)
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://forums.spybot.info/showthread.php?t=279)

Happy surfing and stay clean! :bigthumb:

djsuz
2009-06-23, 19:22
Sorry to bug you again but I don't know whether you want me to post a new thread or carry on with this one.

So it seems that I am not completely clean.

I have followed you instructions Shaba and am now on the Comodo scan.

Unfortunately it has found an unclassified malware in a game I have installed.

the file ends in mxglvqz.exe if thats any help

I Apologize if you want me to start a new thread Shaba.

Shaba
2009-06-23, 19:31
It can be false positive as well.

I will need file path.

djsuz
2009-06-23, 19:38
No problem,

C:\Program Files\Tri-Peaks 2 - Quest for the ruby ring\mxglvqz.exe

Thanks again Shaba

Shaba
2009-06-23, 20:25
Please upload it to virusscan.jotti.org and post back results.

djsuz
2009-06-23, 20:49
IKarus found a trojan agent
Norman found Malware.DTRN
CP Secure found Backdoor.W32.Spyboter.fb

Everything else found nothing

Shaba
2009-06-23, 20:59
So I'd say that it is false positive and you can ignore it :)

djsuz
2009-06-23, 21:03
Thank the lord!!

Well thanks again Shaba, you are indeed one cool cat.

Have a great day

:wav:

Shaba
2009-06-26, 10:57
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.