thanks for ur kind reply, i have performed all the steps u have sent to me, but still my system is slow, the panda scan cannot find any spywares but it is finding some spywares in the paid version. i will here by attach all of my scanned files for your review, pls help me whats wrong with my pc!!!
ComboFix 08-06-03.4 - my accout 2008-06-05 19:23:53.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.72 [GMT 5.5:30]
Running from: C:\Documents and Settings\GOBI\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\_000111_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-05 to 2008-06-05 )))))))))))))))))))))))))))))))
.
2008-06-05 18:56 . 2005-02-25 09:05 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-05 17:36 . 2008-06-05 17:36 <DIR> d-------- C:\WINDOWS\LastGood
2008-06-05 17:36 . 2008-06-05 17:36 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-06-05 17:10 . 2008-06-05 17:10 <DIR> d--hs---- C:\FOUND.001
2008-06-04 17:04 . 2008-06-04 17:04 <DIR> d--hs---- C:\FOUND.000
2008-06-01 21:38 . 2008-06-01 21:38 <DIR> d-------- C:\Program Files\AutoStreamer
2008-06-01 18:58 . 2008-06-01 18:58 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe
2008-06-01 18:44 . 2008-06-01 18:46 67,108,864 --ah----- C:\pcwtest.tmp
2008-05-31 21:49 . 2008-05-31 21:49 <DIR> d-------- C:\Deckard
2008-05-29 18:07 . 2008-05-29 18:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-26 23:06 . 2008-05-26 23:06 <DIR> d-------- C:\Documents and Settings\my accout\Application Data\AVG7
2008-05-26 22:52 . 2008-05-26 22:52 <DIR> d-------- C:\Documents and Settings\my accout\Application Data\SUPERAntiSpyware.com
2008-05-26 21:31 . 2008-05-26 21:31 <DIR> d-------- C:\Documents and Settings\my accout\Application Data\Uniblue
2008-05-26 21:14 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-05-26 21:14 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\SETD.tmp
2008-05-26 21:13 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-05-26 21:13 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys
2008-05-26 21:10 . 2008-05-26 21:10 <DIR> d---s---- C:\Documents and Settings\my accout\UserData
2008-05-26 19:53 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-05-26 19:53 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-05-23 13:30 . 2008-05-23 13:30 <DIR> d-------- C:\Documents and Settings\my accout\Application Data\CyberLink
2008-05-22 20:02 . 2008-05-22 20:03 <DIR> d-------- C:\Documents and Settings\my accout\Application Data\Malwarebytes
2008-05-22 19:33 . 2008-05-22 19:33 <DIR> d-------- C:\Documents and Settings\my accout\Application Data\vlc
2008-05-22 19:08 . 2008-05-22 19:08 <DIR> d-------- C:\Documents and Settings\my accout
2008-05-20 21:41 . 2008-05-20 21:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Comodo
2008-05-20 21:19 . 2008-05-20 21:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-05-20 21:14 . 2008-05-20 21:14 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-05-20 21:14 . 2008-05-20 21:14 <DIR> d-------- C:\Documents and Settings\GOBI\Application Data\AVG7
2008-05-20 21:13 . 2008-05-20 21:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-20 21:13 . 2008-05-21 18:08 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-05-20 21:06 . 2008-05-20 21:06 <DIR> d-------- C:\Program Files\Common Files\Softwin
2008-05-20 20:22 . 2008-05-20 20:22 <DIR> d-------- C:\Documents and Settings\GOBI\Application Data\Comodo
2008-05-20 20:22 . 2008-05-20 20:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-05-20 20:19 . 2008-05-20 20:19 <DIR> d-------- C:\Program Files\Comodo
2008-05-20 20:19 . 2008-05-20 18:45 211 --a------ C:\boot.ini.comodofirewall
2008-05-20 19:42 . 2008-05-20 19:29 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-20 19:42 . 2008-05-20 19:42 2,549 --a------ C:\WINDOWS\unins000.dat
2008-05-20 19:26 . 2008-05-20 19:26 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-20 19:20 . 2008-05-20 19:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-05-20 18:55 . 2008-05-20 18:55 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-05-18 18:56 . 2008-05-18 18:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-05-18 18:55 . 2008-05-18 18:55 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-05-16 21:05 . 2008-05-16 21:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-05-14 18:40 . 2008-05-14 18:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-14 18:39 . 2008-05-14 18:39 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-14 18:39 . 2008-05-14 18:39 <DIR> d-------- C:\Documents and Settings\GOBI\Application Data\SUPERAntiSpyware.com
2008-05-14 18:38 . 2008-05-14 18:38 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-14 18:32 . 2008-05-14 18:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-11 19:09 . 2008-05-11 19:10 63 --a------ C:\WINDOWS\WINHELP.BMK
2008-05-09 21:29 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-09 21:29 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-08 19:06 . 2008-05-08 19:06 <DIR> d-------- C:\Program Files\MSConfig CleanUp
2008-05-08 17:56 . 2008-05-08 17:56 <DIR> d-------- C:\Documents and Settings\GOBI\Application Data\Media Player Classic
2008-05-05 17:10 . 2008-05-05 17:10 <DIR> d-------- C:\Program Files\SoftwrapLicense
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-05 02:36 90,112 ----a-w C:\WINDOWS\DUMP34a7.tmp
2008-05-29 12:59 90,112 ----a-w C:\WINDOWS\DUMP907e.tmp
2008-05-05 11:40 560 ----a-w C:\WINDOWS\Fonts\SWFont9.fnt
2008-05-02 12:55 --------- d-----w C:\Documents and Settings\GOBI\Application Data\Dev-Cpp
2008-05-02 12:54 --------- d-----w C:\Program Files\Dev-Cpp
2008-05-01 14:59 --------- d-----w C:\Program Files\uTorrent
2008-05-01 14:59 --------- d-----w C:\Documents and Settings\GOBI\Application Data\uTorrent
2008-04-28 12:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Uniblue
2008-04-28 12:27 --------- d-----w C:\Program Files\Uniblue
2008-04-28 11:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-23 14:18 --------- d-----w C:\Program Files\My Lockbox
2008-04-16 12:13 --------- d-----w C:\Program Files\Eusing Free Registry Cleaner
2008-04-15 16:35 --------- d-----w C:\Documents and Settings\GOBI\Application Data\Uniblue
2008-04-15 16:02 --------- d-----w C:\Program Files\Registry Cleaner
2008-04-15 14:15 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-04-15 14:15 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-04-15 14:15 --------- d-----w C:\Documents and Settings\GOBI\Application Data\Malwarebytes
2008-04-15 14:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-14 15:47 19,681 ----a-w C:\WINDOWS\oxymak.bin
2008-04-14 15:47 19,596 ----a-w C:\Program Files\Common Files\cukih.dl
2008-04-14 15:47 18,440 ----a-w C:\WINDOWS\zutujeha.com
2008-04-14 15:47 17,719 ----a-w C:\Documents and Settings\GOBI\Application Data\gacomawil.exe
2008-04-14 15:47 16,640 ----a-w C:\Documents and Settings\GOBI\Application Data\exuwur.reg
2008-04-14 15:47 15,919 ----a-w C:\WINDOWS\ehudopar.com
2008-04-14 15:47 15,448 ----a-w C:\WINDOWS\tebun.dll
2008-04-14 15:47 15,368 ----a-w C:\Documents and Settings\GOBI\Application Data\moku.scr
2008-04-14 15:47 14,522 ----a-w C:\Documents and Settings\GOBI\Application Data\hecywygu.bat
2008-04-14 15:47 13,144 ----a-w C:\Program Files\Common Files\ybyle.pif
2008-04-14 15:47 11,774 ----a-w C:\Program Files\Common Files\ihomojorow.dl
2008-04-14 15:47 10,396 ----a-w C:\Program Files\Common Files\xetujo.sys
2008-04-09 15:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-09 14:37 14,769 ----a-w C:\WINDOWS\bubag.exe
2008-04-09 14:37 10,300 ----a-w C:\Program Files\Common Files\ihawitafa.sys
2008-04-09 13:42 19,991 ----a-w C:\Documents and Settings\All Users\Application Data\ucyl.dll
2008-04-09 13:40 --------- d-----w C:\Program Files\WinClamAVShield
2008-04-09 13:40 --------- d-----w C:\Documents and Settings\GOBI\Application Data\Spyware Terminator
2008-04-08 16:34 16,686 ----a-w C:\WINDOWS\mahojoqupa.bat
2008-04-08 16:34 14,405 ----a-w C:\Documents and Settings\All Users\Application Data\yjyf.pif
2008-04-08 16:34 14,101 ----a-w C:\WINDOWS\vodohyto.dll
2008-04-08 16:34 12,889 ----a-w C:\WINDOWS\system32\bizizoheg.vbs
2008-04-08 16:08 19,292 ----a-w C:\Documents and Settings\All Users\Application Data\ijag.bin
2008-04-08 16:08 19,195 ----a-w C:\Documents and Settings\GOBI\Application Data\ketucefit.bat
2008-04-08 16:08 18,507 ----a-w C:\WINDOWS\system32\awijasenaz.sys
2008-04-08 16:08 18,173 ----a-w C:\WINDOWS\muvopiguk.dll
2008-04-08 16:08 17,039 ----a-w C:\WINDOWS\nedexa.exe
2008-04-08 16:08 16,818 ----a-w C:\Program Files\Common Files\jihihi.scr
2008-04-08 16:08 14,158 ----a-w C:\Documents and Settings\All Users\Application Data\enyx.exe
2008-04-08 16:08 13,164 ----a-w C:\WINDOWS\moha.exe
2008-04-08 16:08 12,003 ----a-w C:\Documents and Settings\GOBI\Application Data\vivadahofa.sys
2008-04-08 16:08 11,731 ----a-w C:\Program Files\Common Files\ypabiky.bat
2008-04-08 16:08 11,496 ----a-w C:\WINDOWS\ybicybunyp.scr
2008-04-08 16:08 11,058 ----a-w C:\WINDOWS\xupaw.pif
2008-04-05 14:56 --------- d-----w C:\Program Files\Real
2008-04-05 14:56 --------- d-----w C:\Program Files\Common Files\xing shared
2008-04-05 14:56 --------- d-----w C:\Program Files\Common Files\Real
2008-03-30 05:03 18,432 ----a-w C:\WINDOWS\ss3unstl.exe
2008-03-18 15:57 16,384 ----a-r C:\WINDOWS\hinhem.scr
.
(((((((((((((((((((((((((((((
[email protected]_20.48.51.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-04 11:49:58 2,048 ----a-w C:\WINDOWS\bootstat.dat
+ 2008-06-05 11:40:50 2,048 ----a-w C:\WINDOWS\bootstat.dat
+ 2008-06-05 11:44:08 7,224 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{F0BC551C-67EC-4C48-A55F-4FE129E8A12D}.bin
- 2004-08-04 06:30:00 66,560 ----a-w C:\WINDOWS\system32\cdm.dll
+ 2007-07-30 13:49:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
- 2004-08-04 06:30:00 66,560 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2007-07-30 13:49:20 92,504 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
- 2004-08-04 06:30:00 2,804,224 ----a-w C:\WINDOWS\system32\dllcache\msi.dll
+ 2005-05-04 09:15:32 2,890,240 ----a-w C:\WINDOWS\system32\dllcache\msi.dll
- 2004-08-04 06:30:00 77,312 ----a-w C:\WINDOWS\system32\dllcache\msiexec.exe
+ 2005-05-04 09:15:36 78,848 ----a-w C:\WINDOWS\system32\dllcache\msiexec.exe
- 2004-08-04 06:30:00 331,264 ----a-w C:\WINDOWS\system32\dllcache\msihnd.dll
+ 2005-05-04 09:15:36 271,360 ----a-w C:\WINDOWS\system32\dllcache\msihnd.dll
- 2004-08-04 06:30:00 884,736 ----a-w C:\WINDOWS\system32\dllcache\msimsg.dll
+ 2005-05-04 09:15:36 884,736 ----a-w C:\WINDOWS\system32\dllcache\msimsg.dll
- 2004-08-04 06:30:00 44,032 ----a-w C:\WINDOWS\system32\dllcache\msisip.dll
+ 2005-05-04 09:15:36 15,360 ----a-w C:\WINDOWS\system32\dllcache\msisip.dll
- 2004-08-04 12:00:00 430,592 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
+ 2007-07-30 13:49:36 549,720 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2004-08-04 12:00:00 111,104 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2007-07-30 13:49:16 53,080 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2004-08-04 12:00:00 1,134,592 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-07-30 13:49:42 1,712,984 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2004-08-04 12:00:00 112,640 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2007-07-30 13:49:32 325,976 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
- 2004-08-04 12:00:00 36,864 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2007-07-30 13:48:40 33,624 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
- 2004-08-04 12:00:00 120,320 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-07-30 13:49:28 203,096 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
- 2004-08-04 06:30:00 2,804,224 ----a-w C:\WINDOWS\system32\msi.dll
+ 2005-05-04 09:15:32 2,890,240 ----a-w C:\WINDOWS\system32\msi.dll
- 2004-08-04 06:30:00 77,312 ----a-w C:\WINDOWS\system32\msiexec.exe
+ 2005-05-04 09:15:36 78,848 ----a-w C:\WINDOWS\system32\msiexec.exe
- 2004-08-04 06:30:00 331,264 ----a-w C:\WINDOWS\system32\msihnd.dll
+ 2005-05-04 09:15:36 271,360 ----a-w C:\WINDOWS\system32\msihnd.dll
- 2004-08-04 06:30:00 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
+ 2005-05-04 09:15:36 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
- 2004-08-04 06:30:00 44,032 ----a-w C:\WINDOWS\system32\msisip.dll
+ 2005-05-04 09:15:36 15,360 ----a-w C:\WINDOWS\system32\msisip.dll
+ 2007-07-30 13:48:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2005-05-04 09:15:26 13,536 ------w C:\WINDOWS\system32\spmsg.dll
- 2004-08-04 12:00:00 430,592 ----a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-07-30 13:49:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
- 2004-08-04 12:00:00 111,104 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-30 13:49:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
- 2004-08-04 12:00:00 1,134,592 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-30 13:49:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
- 2004-08-04 12:00:00 112,640 ----a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-07-30 13:49:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
- 2004-08-04 12:00:00 36,864 ----a-w C:\WINDOWS\system32\wups.dll
+ 2007-07-30 13:48:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
+ 2007-07-30 13:49:12 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
- 2004-08-04 12:00:00 120,320 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 13:49:28 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-07-16 15:17 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-05 20:26 185896]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^desktop.ini]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
backup=C:\WINDOWS\pss\desktop.iniCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^GOBI^Start Menu^Programs^Startup^desktop.ini]
path=C:\Documents and Settings\GOBI\Start Menu\Programs\Startup\desktop.ini
backup=C:\WINDOWS\pss\desktop.iniStartup
[HKLM\~\startupfolder\C:^Documents and Settings^my accout^Start Menu^Programs^Startup^desktop.ini]
path=C:\Documents and Settings\my accout\Start Menu\Programs\Startup\desktop.ini
backup=C:\WINDOWS\pss\desktop.iniStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-ra------ 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-07-16 15:17 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
"ose"=3 (0x3)
"gusvc"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"XCOMM"=2 (0x2)
"VSSERV"=2 (0x2)
"LIVESRV"=2 (0x2)
"CmdAgent"=2 (0x2)
"bdss"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Documents and Settings\\GOBI\\My Documents\\downloads sw\\utorrent-1.8-beta-9704.upx.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\AVGAMSVR.EXE"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\AVGEMC.EXE"=
R0 MPRIFL;MPRIFL;C:\WINDOWS\system32\DRIVERS\MPRIFL.SYS [2007-12-13 20:13]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-30 00:01]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-30 00:05]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-28 03:30:02 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\blastclnnn.exe
"2008-04-28 12:27:32 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-05-08 12:27:24 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-05-26 16:46:58 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-05 19:25:27
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-05 19:25:52
ComboFix-quarantined-files.txt 2008-06-05 13:55:50
ComboFix2.txt 2008-06-04 15:19:06
Pre-Run: 15,009,218,560 bytes free
Post-Run: 15,046,918,144 bytes free
269 --- E O F --- 2008-06-05 13:27:24
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:55:50 PM, on 6/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{14A66D03-F0BF-42F3-9E08-AFE9CC690A15}: NameServer = 202.88.152.8,202.88.152.6
O17 - HKLM\System\CS1\Services\Tcpip\..\{14A66D03-F0BF-42F3-9E08-AFE9CC690A15}: NameServer = 202.88.152.8,202.88.152.6
O17 - HKLM\System\CS2\Services\Tcpip\..\{14A66D03-F0BF-42F3-9E08-AFE9CC690A15}: NameServer = 202.88.152.8,202.88.152.6
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
--
End of file - 2900 bytes
Deckard's System Scanner v20071014.68
Run by my accout on 2008-06-06 19:02:21
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Percentage of Memory in Use: 90% (more than 75%).
Total Physical Memory: 224 MiB (512 MiB recommended).
-- HijackThis (run as my accout.exe) -------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:02:35 PM, on 6/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\MYACCO~1.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{14A66D03-F0BF-42F3-9E08-AFE9CC690A15}: NameServer = 202.88.152.8,202.88.152.6
O17 - HKLM\System\CS1\Services\Tcpip\..\{14A66D03-F0BF-42F3-9E08-AFE9CC690A15}: NameServer = 202.88.152.8,202.88.152.6
O17 - HKLM\System\CS2\Services\Tcpip\..\{14A66D03-F0BF-42F3-9E08-AFE9CC690A15}: NameServer = 202.88.152.8,202.88.152.6
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
--
End of file - 2799 bytes
-- Files created between 2008-05-06 and 2008-06-06 -----------------------------
2008-06-05 22:24:24 0 dr-h----- C:\Documents and Settings\GOBI\Recent
2008-06-05 22:10:46 0 d-------- C:\Program Files\SpywareBlaster
2008-06-05 19:43:41 0 d-------- C:\Program Files\Panda Security
2008-06-05 18:56:02 0 d-------- C:\WINDOWS\system32\PreInstall
2008-06-05 17:36:04 0 d--h----- C:\WINDOWS\$hf_mig$
2008-06-05 17:10:14 0 d--hs---- C:\FOUND.001
2008-06-05 08:13:26 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-06-04 20:44:58 68096 --a------ C:\WINDOWS\zip.exe
2008-06-04 20:44:58 49152 --a------ C:\WINDOWS\VFind.exe
2008-06-04 20:44:58 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-06-04 20:44:58 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-06-04 20:44:58 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-06-04 20:44:58 98816 --a------ C:\WINDOWS\sed.exe
2008-06-04 20:44:58 80412 --a------ C:\WINDOWS\grep.exe
2008-06-04 20:44:58 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-06-04 17:04:06 0 d--hs---- C:\FOUND.000
2008-06-01 21:38:19 0 d-------- C:\Program Files\AutoStreamer
2008-06-01 18:58:33 25992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe <Not Verified; Sysinternals -
www.sysinternals.com; Page File Defragmenter>
2008-05-29 18:07:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-28 19:25:16 0 dr------- C:\Documents and Settings\my accout\Recent
2008-05-27 23:14:56 0 d-------- C:\Documents and Settings\my accout\Application Data\Google
2008-05-26 23:06:41 0 d-------- C:\Documents and Settings\my accout\Application Data\AVG7
2008-05-26 22:52:41 0 d-------- C:\Documents and Settings\my accout\Application Data\SUPERAntiSpyware.com
2008-05-26 21:31:51 0 d-------- C:\Documents and Settings\my accout\Application Data\Uniblue
2008-05-26 21:10:35 0 d---s---- C:\Documents and Settings\my accout\UserData
2008-05-23 13:30:32 0 d-------- C:\Documents and Settings\my accout\Application Data\CyberLink
2008-05-22 20:02:58 0 d-------- C:\Documents and Settings\my accout\Application Data\Malwarebytes
2008-05-22 19:33:37 0 d-------- C:\Documents and Settings\my accout\Application Data\vlc
2008-05-22 19:20:27 0 d-------- C:\Documents and Settings\my accout\Application Data\Macromedia
2008-05-22 19:20:26 0 d-------- C:\Documents and Settings\my accout\Application Data\Adobe
2008-05-22 19:12:18 0 d-------- C:\Documents and Settings\my accout\Application Data\Real
2008-05-22 19:12:04 0 d-------- C:\Documents and Settings\my accout\Application Data\Identities
2008-05-22 19:08:54 0 d-------- C:\Documents and Settings\my accout\Templates
2008-05-22 19:08:54 0 dr------- C:\Documents and Settings\my accout\Start Menu
2008-05-22 19:08:54 0 dr------- C:\Documents and Settings\my accout\SendTo
2008-05-22 19:08:54 0 d-------- C:\Documents and Settings\my accout\PrintHood
2008-05-22 19:08:54 3407872 --a------ C:\Documents and Settings\my accout\NTUSER.DAT
2008-05-22 19:08:54 0 d-------- C:\Documents and Settings\my accout\NetHood
2008-05-22 19:08:54 0 dr------- C:\Documents and Settings\my accout\My Documents
2008-05-22 19:08:54 0 d--h----- C:\Documents and Settings\my accout\Local Settings
2008-05-22 19:08:54 0 dr------- C:\Documents and Settings\my accout\Favorites
2008-05-22 19:08:54 0 d-------- C:\Documents and Settings\my accout\Desktop
2008-05-22 19:08:54 0 d---s---- C:\Documents and Settings\my accout\Cookies
2008-05-22 19:08:54 0 dr------- C:\Documents and Settings\my accout\Application Data
2008-05-21 20:00:37 0 dr------- C:\Documents and Settings\Administrator\Recent
2008-05-20 21:41:51 0 d-------- C:\Documents and Settings\Administrator\Application Data\Comodo
2008-05-20 21:19:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-05-20 21:14:31 0 d-------- C:\Documents and Settings\GOBI\Application Data\AVG7
2008-05-20 21:14:01 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-05-20 21:13:50 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-05-20 21:13:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-20 20:22:06 0 d-------- C:\Documents and Settings\GOBI\Application Data\Comodo
2008-05-20 20:22:05 0 d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-05-20 20:19:46 0 d-------- C:\Program Files\Comodo
2008-05-20 19:42:37 691545 --a------ C:\WINDOWS\unins000.exe
2008-05-20 19:42:37 2549 --a------ C:\WINDOWS\unins000.dat
2008-05-20 19:20:38 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-05-20 18:55:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-05-19 17:43:32 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-05-18 18:59:13 0 d--hs---- C:\WINDOWS\CSC
2008-05-18 18:56:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-05-18 18:55:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-05-16 21:09:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-05-16 21:05:11 0 d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-05-14 18:40:45 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-14 18:39:36 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-14 18:39:35 0 d-------- C:\Documents and Settings\GOBI\Application Data\SUPERAntiSpyware.com
2008-05-14 18:38:47 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-14 18:32:42 0 d-------- C:\Program Files\Trend Micro
2008-05-08 19:06:24 0 d-------- C:\Program Files\MSConfig CleanUp
2008-05-08 17:56:17 0 d-------- C:\Documents and Settings\GOBI\Application Data\Media Player Classic
-- Find3M Report ---------------------------------------------------------------
2008-05-12 21:33:48 65 --a------ C:\AUTOEXEC.BAT
2008-05-05 17:10:04 0 d-------- C:\Program Files\SoftwrapLicense
2008-05-02 18:24:44 0 d-------- C:\Program Files\Dev-Cpp
2008-05-01 20:29:08 0 d-------- C:\Program Files\uTorrent
2008-04-28 17:57:24 0 d-------- C:\Program Files\Uniblue
2008-04-23 19:48:56 0 d-------- C:\Program Files\My Lockbox
2008-04-16 17:43:28 0 d-------- C:\Program Files\Eusing Free Registry Cleaner
2008-04-15 21:32:20 0 d-------- C:\Program Files\Registry Cleaner
2008-04-15 19:49:04 12586 --a------ C:\WINDOWS\viwucyb.dll
2008-04-15 19:49:04 16755 --a------ C:\WINDOWS\system32\afeheguqa.bat
2008-04-15 19:49:04 15599 --a------ C:\WINDOWS\qavidewi.bat
2008-04-15 19:49:04 11725 --a------ C:\WINDOWS\lapufafy.pif
2008-04-15 19:49:04 11062 --a------ C:\WINDOWS\dedavavu.sys
2008-04-15 19:49:04 12236 --a------ C:\WINDOWS\byhojad.com
2008-04-15 19:49:04 17108 --a------ C:\WINDOWS\akoly.vbs
2008-04-15 19:49:04 17906 --a------ C:\Program Files\Common Files\yfylyru.inf
2008-04-15 19:49:04 12603 --a------ C:\Program Files\Common Files\otawecas.dll
2008-04-15 19:49:04 17466 --a------ C:\Program Files\Common Files\imiju.dl
2008-04-15 19:49:04 16350 --a------ C:\Program Files\Common Files\fagamib.inf
2008-04-15 19:45:36 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-15 19:45:24 0 d-------- C:\Program Files\Common Files\Download Manager
2008-04-14 21:17:06 18440 --a------ C:\WINDOWS\zutujeha.com
2008-04-14 21:17:06 15448 --a------ C:\WINDOWS\tebun.dll
2008-04-14 21:17:06 19681 --a------ C:\WINDOWS\oxymak.bin
2008-04-14 21:17:06 15919 --a------ C:\WINDOWS\ehudopar.com
2008-04-14 21:17:06 13144 --a------ C:\Program Files\Common Files\ybyle.pif
2008-04-14 21:17:06 10396 --a------ C:\Program Files\Common Files\xetujo.sys
2008-04-14 21:17:06 11774 --a------ C:\Program Files\Common Files\ihomojorow.dl
2008-04-14 21:17:06 19596 --a------ C:\Program Files\Common Files\cukih.dl
2008-04-09 20:07:46 14769 --a------ C:\WINDOWS\bubag.exe
2008-04-09 20:07:46 10300 --a------ C:\Program Files\Common Files\ihawitafa.sys
2008-04-09 20:01:40 12708 --a------ C:\WINDOWS\uwibufary.com
2008-04-09 20:01:40 11673 --a------ C:\WINDOWS\system32\abow.com
2008-04-09 20:01:40 11042 --a------ C:\WINDOWS\inado.dll
2008-04-09 20:01:40 18127 --a------ C:\WINDOWS\emawo.bat
2008-04-09 20:01:40 17383 --a------ C:\Program Files\Common Files\zekaqec.scr
2008-04-09 20:01:40 18946 --a------ C:\Program Files\Common Files\yzat.com
2008-04-09 20:01:40 16146 --a------ C:\Program Files\Common Files\vote.dat
2008-04-09 20:01:40 19824 --a------ C:\Program Files\Common Files\akar._sy
2008-04-09 20:01:40 12715 --a------ C:\Program Files\Common Files\ajepuzehak.ban
2008-04-09 20:01:38 13296 --a------ C:\Program Files\Common Files\xoxipes.sys
2008-04-09 20:01:38 18801 --a------ C:\Program Files\Common Files\enufuw.ban
2008-04-09 19:12:36 13735 --a------ C:\WINDOWS\ymykisa.exe
2008-04-09 19:12:36 13752 --a------ C:\WINDOWS\xuwukise.dat
2008-04-09 19:12:36 11670 --a------ C:\WINDOWS\ihubyqen.reg
2008-04-09 19:12:36 17539 --a------ C:\Program Files\Common Files\uzyjigo.dat
2008-04-09 19:12:34 18958 --a------ C:\WINDOWS\system32\upavuv.vbs
2008-04-09 19:12:34 14540 --a------ C:\WINDOWS\asanud.pif
2008-04-09 19:12:34 18591 --a------ C:\Program Files\Common Files\ucatob.exe
2008-04-09 19:12:34 12129 --a------ C:\Program Files\Common Files\lifegen.sys
2008-04-09 19:12:34 10630 --a------ C:\Program Files\Common Files\esosaco.sys
2008-04-09 19:12:34 10935 --a------ C:\Program Files\Common Files\cobid.lib
2008-04-09 19:10:52 0 d-------- C:\Program Files\WinClamAVShield
2008-04-08 22:04:56 14101 --a------ C:\WINDOWS\vodohyto.dll
2008-04-08 22:04:56 12889 --a------ C:\WINDOWS\system32\bizizoheg.vbs
2008-04-08 22:04:56 16686 --a------ C:\WINDOWS\mahojoqupa.bat
2008-04-08 21:38:30 11496 --a------ C:\WINDOWS\ybicybunyp.scr
2008-04-08 21:38:30 11058 --a------ C:\WINDOWS\xupaw.pif
2008-04-08 21:38:30 18507 --a------ C:\WINDOWS\system32\awijasenaz.sys
2008-04-08 21:38:30 17039 --a------ C:\WINDOWS\nedexa.exe
2008-04-08 21:38:30 18173 --a------ C:\WINDOWS\muvopiguk.dll
2008-04-08 21:38:30 13164 --a------ C:\WINDOWS\moha.exe
2008-04-08 21:38:30 11731 --a------ C:\Program Files\Common Files\ypabiky.bat
2008-04-08 21:38:30 16818 --a------ C:\Program Files\Common Files\jihihi.scr
2008-03-30 10:33:46 18432 --a------ C:\WINDOWS\ss3unstl.exe
2008-03-18 21:27:56 16384 -ra------ C:\WINDOWS\hinhem.scr
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [07/16/2007 03:17 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^desktop.ini]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
backup=C:\WINDOWS\pss\desktop.iniCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GOBI^Start Menu^Programs^Startup^desktop.ini]
path=C:\Documents and Settings\GOBI\Start Menu\Programs\Startup\desktop.ini
backup=C:\WINDOWS\pss\desktop.iniStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^my accout^Start Menu^Programs^Startup^desktop.ini]
path=C:\Documents and Settings\my accout\Start Menu\Programs\Startup\desktop.ini
backup=C:\WINDOWS\pss\desktop.iniStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
"ose"=3 (0x3)
"gusvc"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"XCOMM"=2 (0x2)
"VSSERV"=2 (0x2)
"LIVESRV"=2 (0x2)
"CmdAgent"=2 (0x2)
"bdss"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
-- End of Deckard's System Scanner: finished at 2008-06-06 19:03:33 ------------
pls verify and help me, i am using only this forum!!