It is currently Tue Sep 01, 2026 12:14 pm


Fresh log

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Fresh log

Postby TheExero » Mon Aug 17, 2009 7:03 pm

Hello again people. :cool: My computer seems a bit more slugish then normal i did some scans and defragged and whatnot doesn't seem to make much of a difference, anyway i have also been getting odd virus warnings in avg about win32 cryptor and other viruses i think AVG took care of it. I would still feel a bit better if i had some of you experts take a look at my log file just to make sure everything is in order. Again thank you for your time. :wobble:


Edit - Just noticed i posted a log with an old version here is a new log with an updated version.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:10:27 PM, on 8/17/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\MagicTune Premium\GammaTray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Users\Dean\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Logitech\SetPoint\LU\LULnchr.exe
C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\DAEMON Tools Pro\DTProShellHlp.exe
C:\Windows\system32\mshta.exe
C:\Windows\system32\mshta.exe
C:\Windows\system32\mshta.exe
C:\Windows\system32\mshta.exe
C:\Users\Dean\Desktop\hijackthis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: 74.125.19.147 hechoenperu.net
O1 - Hosts: 74.125.19.147 www.hechoenperu.net
O1 - Hosts: 74.125.19.147 http://hechoenperu.net
O1 - Hosts: 74.125.19.147 http://www.hechoenperu.net/index.php
O1 - Hosts: 74.125.19.147 portablessa.com
O1 - Hosts: 74.125.19.147 www.portablessa.com
O1 - Hosts: 74.125.19.147 http://portablessa.com
O1 - Hosts: 74.125.19.147 http://www.portablessa.com
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Dean\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: GammaTray.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-U ... E_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - (no file)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: MagicTuneEngine - Unknown owner - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Service.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9063 bytes
TheExero
Geek
Geek
 
Posts: 51
Joined: Sat Dec 01, 2007 12:00 am

Thanks given:0
Thanks received:0
Top

Re: Fresh log

Postby Gecko » Tue Aug 18, 2009 11:26 am

TheExero,

Yes your system is infected.
Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Fresh log

Postby TheExero » Wed Aug 19, 2009 7:50 am

There we go. TY for reply.


ComboFix 09-08-10.06 - Dean 08/19/2009 0:38.3.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.1359 [GMT -4:00]
Running from: c:\users\Dean\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
C:\data
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\recycler\S-1-5-21-117609710-1220945662-839522115-1003
c:\windows\Installer\10d38fb6.msi
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-07-19 to 2009-08-19 )))))))))))))))))))))))))))))))
.

2014-01-17 18:25 . 2014-01-17 18:25 -------- dc-h--w- c:\programdata\{B98A2B83-8BB0-42E7-AA1D-D6FA6E7C8F31}
2009-08-13 00:01 . 2009-08-13 00:01 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-08-13 00:01 . 2009-08-13 00:01 -------- d-----w- c:\programdata\AIM Toolbar
2009-08-13 00:01 . 2009-08-13 00:01 -------- d-----w- c:\program files\AIM Toolbar
2009-08-12 12:54 . 2009-07-31 12:01 2061592 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-08-12 12:54 . 2009-07-31 12:00 2000152 ----a-w- c:\programdata\avg8\update\backup\avgtray.exe
2009-08-12 12:54 . 2009-07-31 12:00 1213720 ----a-w- c:\programdata\avg8\update\backup\avgfrw.exe
2009-08-12 12:54 . 2009-07-31 12:00 1471768 ----a-w- c:\programdata\avg8\update\backup\avgupd.dll
2009-08-12 12:54 . 2009-07-31 12:00 1126168 ----a-w- c:\programdata\avg8\update\backup\avgupd.exe
2009-08-12 12:54 . 2009-07-31 12:00 758040 ----a-w- c:\programdata\avg8\update\backup\avginet.dll
2009-07-25 03:30 . 2009-08-17 05:38 -------- d-----w- c:\users\Dean\AppData\Roaming\Winamp
2009-07-24 22:01 . 2009-07-24 22:01 -------- d-----w- c:\users\Dean\AppData\Roaming\Logitech
2009-07-24 21:58 . 2008-11-07 20:37 301656 ----a-w- c:\windows\system32\BtCoreIf.dll
2009-07-24 21:58 . 2008-11-07 20:38 84496 ----a-w- c:\windows\system32\KemXML.dll
2009-07-24 21:58 . 2008-11-07 20:38 117264 ----a-w- c:\windows\system32\KemWnd.dll
2009-07-24 21:58 . 2008-11-07 20:38 145936 ----a-w- c:\windows\system32\KemUtil.dll
2009-07-24 21:58 . 2008-11-07 20:38 170512 ----a-w- c:\windows\system32\kemutb.dll
2009-07-24 21:58 . 2009-07-24 21:58 -------- d-----w- c:\programdata\Logitech
2009-07-24 21:57 . 2009-07-24 22:01 -------- d-----w- c:\program files\Common Files\Logishrd
2009-07-24 21:57 . 2009-07-24 21:57 -------- d-----w- c:\program files\Logitech
2009-07-24 21:57 . 2009-07-24 21:57 -------- d-----w- c:\programdata\LogiShrd

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-19 04:31 . 2008-04-13 21:03 -------- d-----w- c:\programdata\avg8
2009-08-18 18:21 . 2008-08-27 16:18 -------- d-----w- c:\programdata\Google Updater
2009-08-17 05:38 . 2007-12-28 20:17 -------- d-----w- c:\users\Dean\AppData\Roaming\uTorrent
2009-08-14 20:53 . 2008-09-06 20:55 -------- d-----w- c:\program files\Warcraft III
2009-08-13 00:01 . 2007-11-17 00:37 -------- d-----w- c:\program files\AIM6
2009-08-13 00:01 . 2007-12-28 18:15 -------- d-----w- c:\programdata\Viewpoint
2009-08-12 23:58 . 2008-05-22 13:37 -------- d-----w- c:\programdata\AOL Downloads
2009-08-08 18:14 . 2007-12-28 18:57 1356 ----a-w- c:\users\Dean\AppData\Local\d3d9caps.dat
2009-07-31 12:00 . 2009-07-15 12:25 3476760 ----a-w- c:\programdata\avg8\update\backup\avgui.exe
2009-07-26 02:33 . 2007-12-28 16:55 -------- d-----w- c:\users\Dean\AppData\Roaming\NoNameScript
2009-07-25 03:32 . 2008-01-21 16:18 -------- d-----w- c:\program files\Winamp
2009-07-24 21:59 . 2009-07-24 21:59 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-07-24 21:57 . 2007-12-28 16:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-19 00:19 . 2009-05-30 11:57 -------- d-----w- c:\programdata\PMB Files
2009-07-12 04:47 . 2009-01-09 00:14 -------- d-----w- c:\program files\Phantasy Star Online Blue Burst
2009-07-08 23:46 . 2009-04-06 17:19 -------- d-----w- c:\program files\Mozilla Firefox 3.1 Beta 3
2009-07-08 15:45 . 2008-09-23 20:10 -------- d-----w- c:\users\Dean\AppData\Roaming\Skype
2009-07-08 00:34 . 2009-07-08 00:34 -------- d-----w- c:\program files\Free WMA MP3 Converter
2009-07-08 00:32 . 2009-07-08 00:29 -------- d-----w- c:\program files\Free WMA to MP3 Converter
2009-07-07 21:32 . 2009-07-07 21:32 -------- d-----r- c:\program files\Skype
2009-07-07 21:32 . 2009-07-07 21:32 -------- d-----w- c:\program files\Common Files\Skype
2009-07-07 21:32 . 2008-09-23 19:59 -------- d-----w- c:\programdata\Skype
2009-07-07 20:06 . 2008-09-23 20:11 -------- d-----w- c:\users\Dean\AppData\Roaming\skypePM
2009-07-06 22:26 . 2009-07-06 22:26 -------- d-----w- c:\programdata\Webcammax
2009-07-06 22:26 . 2009-07-06 22:26 -------- d-----w- c:\program files\WebcamMax
2009-06-30 23:19 . 2009-07-02 01:50 106496 ----a-w- c:\users\Dean\AppData\Roaming\Mozilla\Plugins\npcoolirisplugin.dll
2009-06-22 20:02 . 2008-02-16 21:19 -------- d--h--w- c:\users\Dean\AppData\Roaming\ijjigame
2009-06-22 19:57 . 2009-06-22 19:57 383645136 ----a-w- c:\users\Dean\AppData\Roaming\ijjigame\U_GBOUND_setup.exe
2009-06-22 19:21 . 2008-02-16 21:19 -------- d-----w- c:\programdata\IJJIGame
2009-06-03 21:48 . 2009-06-22 19:21 779720 ----a-w- c:\programdata\IJJIGame\PurpleBean.exe
2009-05-30 13:23 . 2009-05-30 13:23 45056 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{48E16DC7-79EC-45F1-847A-F8D3C620515E}\MapleStory.exe1_801DA03C4E824858A615529E6AFB9A78.exe
2009-05-30 13:23 . 2009-05-30 13:23 45056 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{48E16DC7-79EC-45F1-847A-F8D3C620515E}\MapleStory.exe_801DA03C4E824858A615529E6AFB9A78.exe
2009-05-30 13:23 . 2009-05-30 13:23 10134 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{48E16DC7-79EC-45F1-847A-F8D3C620515E}\ARPPRODUCTICON.exe
2009-05-30 13:13 . 2009-05-30 13:13 3584 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2009-05-29 15:18 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-05-29 15:12 . 2006-11-02 12:37 37665 ----a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont
2009-05-27 22:08 . 2009-06-22 19:21 591320 ----a-w- c:\programdata\IJJIGame\ExLauncher.exe
2009-05-26 21:31 . 2009-06-22 19:20 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe
2009-05-21 20:48 . 2009-05-21 20:48 552 ----a-w- c:\users\Dean\AppData\Local\d3d8caps.dat
2007-12-28 23:30 . 2007-12-28 23:19 24 --sh--w- c:\windows\SE0F92C5D.tmp
2008-10-23 14:54 . 2008-10-21 19:30 2048 --sha-w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-10-23 14:54 . 2008-10-21 19:30 2048 --sha-w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Google Update"="c:\users\Dean\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-05-16 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-19 227840]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-04-06 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-06 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-06 81920]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GammaTray.lnk - c:\program files\MagicTune Premium\GammaTray.exe [2008-5-6 36864]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-7-24 809488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableStatusMessages"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete\0autocheck lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):dc,5c,05,e8,71,e0,c9,01

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{EB4737C2-484F-4876-8DF3-0C64561D4F20}c:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= UDP:c:\program files\ea games\battlefield 2\bf2_w32ded.exe:bf2_w32ded
"UDP Query User{9BEF9801-4483-4C1F-A9E9-0D172FFA05C9}c:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= TCP:c:\program files\ea games\battlefield 2\bf2_w32ded.exe:bf2_w32ded
"TCP Query User{43560610-263D-4F4F-AE45-441D6293F3BE}c:\\program files\\ccp\\eve\\bin\\exefile.exe"= UDP:c:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"UDP Query User{5CC37E5A-7235-441D-9448-AE5FDA178D6C}c:\\program files\\ccp\\eve\\bin\\exefile.exe"= TCP:c:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"TCP Query User{AE6C95B1-64CB-4255-A440-37657D01990A}c:\\program files\\mirc\\uninstall.exe _=c\program files\mirc\mirc.exe"= UDP:c:\program files\mirc\uninstall.exe _=c\program files\mirc\mirc.exe:mIRC
"UDP Query User{D4AFB2BE-4BF3-46E8-824B-66BC6AA28944}c:\\program files\\mirc\\uninstall.exe _=c\program files\mirc\mirc.exe"= TCP:c:\program files\mirc\uninstall.exe _=c\program files\mirc\mirc.exe:mIRC
"{950EDD3B-8D40-4AA0-AB4F-6F3DE1F5A8CD}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E933B1BF-3D62-4608-83C1-907EE0242D1D}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{61BDF907-58BB-4EAD-83E3-89FAAF1C6C52}"= UDP:c:\program files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{6606EDBD-8B54-45F8-9020-16CC65F080CA}"= TCP:c:\program files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{B896ACE7-4C8E-47F4-AA57-5E60F4A6D634}"= UDP:c:\program files\Sierra Entertainment\World in Conflict\wic.exe:World in Conflict
"{52997E27-DFD7-4069-B081-2B326883E009}"= TCP:c:\program files\Sierra Entertainment\World in Conflict\wic.exe:World in Conflict
"{11B5172C-9CD5-4A9D-9D71-C793D5FF01EB}"= UDP:c:\program files\Sierra Entertainment\World in Conflict\wic_online.exe:World in Conflict - Online Only
"{D9182564-D276-4075-8AE1-1FFDB920C2A8}"= TCP:c:\program files\Sierra Entertainment\World in Conflict\wic_online.exe:World in Conflict - Online Only
"{6FA4DD91-5242-4D36-AE9E-5D61B1D9CA54}"= UDP:c:\program files\Sierra Entertainment\World in Conflict\wic_ds.exe:World in Conflict - Dedicated Server
"{1B0857FA-2407-481D-9C5E-7E2283C664ED}"= TCP:c:\program files\Sierra Entertainment\World in Conflict\wic_ds.exe:World in Conflict - Dedicated Server
"{438CD315-614D-4F59-B540-F2C9CD816EE1}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{60152EEC-784B-46D9-B4AB-DE616B6AF7F5}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{16A05885-6C40-419B-9AD8-09170A7AFB79}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{DFB793D0-1865-4B57-A676-CA69B309F2F6}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{0F1A98FA-7B5C-4825-AE0D-C2A5A79FE305}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{3C1A373D-8AD5-4D6E-A0A0-0AFCD148FBA2}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{3EEC58BD-58A9-47E5-93EB-54CB19BED76A}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{D58899FA-E1DA-4445-B3A3-DC5F4FC9F355}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{DE9105C2-B9B1-455A-9C37-162AB50A2480}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{C766C4B3-3AFB-434A-9412-1878E723C09A}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"TCP Query User{031D6352-A9DE-4415-8C31-FA9FA90D209B}c:\\users\\dean\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\dean\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{2C1E54DB-03E6-45FA-95F2-16478AF1F3C6}c:\\users\\dean\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\dean\program files\utorrent\utorrent.exe:utorrent.exe
"{92660E8B-3266-4186-89D6-A4DDD872EFBE}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{4CCF7DE0-1EF6-462E-BEB9-9476B3F30CAC}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{A685AF62-2636-4B61-98D3-ED179DA1589C}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{4CAC8DA7-4924-418E-B15C-9D5B08AD068C}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{139D8427-79E9-4D1B-ACCD-AD902D3E9C89}"= UDP:c:\program files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{4ED5E072-A613-4E26-9B81-33FCA8242381}"= TCP:c:\program files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"TCP Query User{DA89EAC7-E635-497A-BCD4-2791F70E0209}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{91DB992A-AE7D-48A0-9450-CFBC6E8E0E57}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"{255B158F-4E39-497C-B458-2DB382CBD764}"= UDP:c:\users\Dean\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{4DE80F6E-AD15-43E1-AF66-15851E3F4107}"= TCP:c:\users\Dean\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{9D30FEEF-CD6A-4BAB-8C32-E93F4BE70142}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= UDP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III
"UDP Query User{CEA15E7F-D713-4D11-85F7-4D83230F5F95}c:\\program files\\aspyr\\guitar hero iii\\gh3.exe"= TCP:c:\program files\aspyr\guitar hero iii\gh3.exe:Guitar Hero III
"TCP Query User{26A9B3B1-29C3-4FCA-ADD4-E45E6905714C}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{A34285AD-3F48-48FD-A4C2-5A7FC7FA7FC3}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{AF26ABE9-CD4B-4D68-AFBC-DF3ADDDBBD37}"= UDP:c:\program files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{FC2E9B77-AA73-4518-B43F-88BC015A3056}"= TCP:c:\program files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"TCP Query User{14A0C5FF-55D2-4F9F-833E-D240D258B4E0}c:\\ijji\\english\\u_gbound.exe"= UDP:c:\ijji\english\u_gbound.exe:<ijji Downloader>
"UDP Query User{0E50D8E3-4BF7-4F03-834B-DB58DF0B8A05}c:\\ijji\\english\\u_gbound.exe"= TCP:c:\ijji\english\u_gbound.exe:<ijji Downloader>
"TCP Query User{596119E7-C847-42E6-B920-5E00161823C9}c:\\ijji\\english\\gunbound revolution\\gunbound.gme"= UDP:c:\ijji\english\gunbound revolution\gunbound.gme:GunBound
"UDP Query User{D8A38433-8292-4AE3-B426-B92365BA01FD}c:\\ijji\\english\\gunbound revolution\\gunbound.gme"= TCP:c:\ijji\english\gunbound revolution\gunbound.gme:GunBound
"TCP Query User{5C7713FA-4C3E-4240-8585-DF7F9E246E39}c:\\program files\\warcraft iii\\war3.exe"= UDP:c:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{40F3A658-0A9C-4653-B21D-4DB766DC8B7A}c:\\program files\\warcraft iii\\war3.exe"= TCP:c:\program files\warcraft iii\war3.exe:Warcraft III
"{306937A3-0FF7-4E28-AD46-1F237EDD6615}"= UDP:c:\program files\Playlogic\WorldShift\bin\WorldShift.exe:WorldShift
"{BDAB8D7D-1D88-48EC-AF4F-8A1B4CBB8A1A}"= TCP:c:\program files\Playlogic\WorldShift\bin\WorldShift.exe:WorldShift
"{74B7AF2C-762D-4D81-8A75-7CEC786DDF1F}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{13DB11B1-9497-4E5E-B06A-C3EE34977B23}c:\\program files\\warcraft iii\\war3.exe"= UDP:c:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{EAD11FF0-3578-42C5-A5CC-D15898E04096}c:\\program files\\warcraft iii\\war3.exe"= TCP:c:\program files\warcraft iii\war3.exe:Warcraft III
"TCP Query User{831F420F-B95D-4636-A6EA-C4B323BB96F0}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{D8141D13-7EEB-49BA-90B2-E09A0DCE3092}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{5E2A8198-C0BC-41B1-B359-E141F145E577}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{757BDA30-9D50-4CFE-8C6C-76E49650DA5A}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"TCP Query User{6D1B0F3D-772A-474E-A593-F0575D81C440}c:\\program files\\microsoft games\\age of empires\\empiresx.exe"= UDP:c:\program files\microsoft games\age of empires\empiresx.exe:Age of Empires, the Rise of Rome
"UDP Query User{2505F921-B7EE-4DF4-8A67-5DB1B6EAA494}c:\\program files\\microsoft games\\age of empires\\empiresx.exe"= TCP:c:\program files\microsoft games\age of empires\empiresx.exe:Age of Empires, the Rise of Rome
"TCP Query User{8E7F6B57-B2B6-4494-8433-97FFC8F8D559}c:\\windows\\system32\\dplaysvr.exe"= UDP:c:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"UDP Query User{7F2E59A5-2350-47FA-B2F6-FC3FAA42609B}c:\\windows\\system32\\dplaysvr.exe"= TCP:c:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"TCP Query User{6AE62F6A-0D2A-426D-B65A-CBAD5CC3CCB2}c:\\program files\\microsoft games\\age of empires\\empiresx.exe"= UDP:c:\program files\microsoft games\age of empires\empiresx.exe:Age of Empires, the Rise of Rome
"UDP Query User{D6D3BB79-3F8E-401A-8946-FBC85CB639B1}c:\\program files\\microsoft games\\age of empires\\empiresx.exe"= TCP:c:\program files\microsoft games\age of empires\empiresx.exe:Age of Empires, the Rise of Rome
"TCP Query User{5B8F11F3-52B5-406F-B748-C64A03EB1B86}c:\\windows\\system32\\dplaysvr.exe"= UDP:c:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"UDP Query User{F8937B95-4108-4182-AD98-EB0A167E0360}c:\\windows\\system32\\dplaysvr.exe"= TCP:c:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"{0A9EFEA6-06ED-430B-803C-F8A53A8A6DCA}"= UDP:443:ooVoo TCP port 443
"{B499F0E5-2A48-4A27-81F0-EEE9890788C2}"= TCP:443:ooVoo UDP port 443
"{B62B3371-B2DA-4D24-996F-33433E7C12DB}"= UDP:37674:ooVoo TCP port 37674
"{D01451B4-A625-480F-8AD2-1E89CEEB8C30}"= TCP:37674:ooVoo UDP port 37674
"{F7221266-6099-4A27-8E8F-4643591C8A47}"= TCP:37675:ooVoo UDP port 37675
"TCP Query User{7CEAE316-9B03-4428-BCEF-FE58E02BB2F5}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{764C6A62-545C-452E-A76A-70A7CCBCEFA3}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"TCP Query User{CA1CBCBD-AD63-4077-ACA1-A977903AA3C7}c:\\program files\\ea games\\battlefield 2\\bf2.exe"= UDP:c:\program files\ea games\battlefield 2\bf2.exe:BF2
"UDP Query User{5DC51E25-6138-4B5E-A5C5-95A9A7C0B51E}c:\\program files\\ea games\\battlefield 2\\bf2.exe"= TCP:c:\program files\ea games\battlefield 2\bf2.exe:BF2
"TCP Query User{E5F52782-21DE-449A-8BFE-AE13772DC9FE}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{FCCBF1E7-250A-4A1A-8D64-09EB91F8B92A}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{4A379C76-BBB6-47FD-A577-0A3E74292144}c:\\users\\dean\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\dean\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{98B00113-9F26-4DC6-80BC-4197914724F4}c:\\users\\dean\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\dean\program files\utorrent\utorrent.exe:utorrent.exe
"{474BC0DC-E3CE-46FC-AC6D-0EB0E57E7681}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{8F2D81D5-6B8E-4B59-B74C-2B7FC6B8B1E1}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"TCP Query User{25DD3DBE-B484-4219-8DF7-3DA0B13D74B1}c:\\ijji\\english\\u_gbound.exe"= UDP:c:\ijji\english\u_gbound.exe:<ijji Downloader>
"UDP Query User{5BB592F9-6076-46C7-9E9F-D72E22BF276E}c:\\ijji\\english\\u_gbound.exe"= TCP:c:\ijji\english\u_gbound.exe:<ijji Downloader>
"TCP Query User{1372F3A7-86E0-4896-8B0D-BF3B62CE0454}c:\\ijji\\english\\gunbound revolution\\gunbound.gme"= UDP:c:\ijji\english\gunbound revolution\gunbound.gme:GunBound
"UDP Query User{01BE0512-7558-4041-87C0-262CA267D1F9}c:\\ijji\\english\\gunbound revolution\\gunbound.gme"= TCP:c:\ijji\english\gunbound revolution\gunbound.gme:GunBound
"TCP Query User{F61FE15A-0F02-4E7F-896F-33F02EC9D4B6}c:\\program files\\ea games\\battlefield 2\\mods\\stats\\server\\udrive\\usr\\local\\apache2\\bin\\apache.exe"= UDP:c:\program files\ea games\battlefield 2\mods\stats\server\udrive\usr\local\apache2\bin\apache.exe:Apache HTTP Server
"UDP Query User{A16A3D80-8113-415E-B96B-5AE7CCF9995F}c:\\program files\\ea games\\battlefield 2\\mods\\stats\\server\\udrive\\usr\\local\\apache2\\bin\\apache.exe"= TCP:c:\program files\ea games\battlefield 2\mods\stats\server\udrive\usr\local\apache2\bin\apache.exe:Apache HTTP Server
"TCP Query User{26A9D77D-446F-435E-AD1E-DCBD89CBC548}c:\\program files\\ea games\\battlefield 2\\mods\\stats\\server\\udrive\\usr\\local\\mysql\\bin\\mysqld-opt.exe"= UDP:c:\program files\ea games\battlefield 2\mods\stats\server\udrive\usr\local\mysql\bin\mysqld-opt.exe:mysqld-opt
"UDP Query User{33B15FBF-6F32-4640-8574-4003C252B0BC}c:\\program files\\ea games\\battlefield 2\\mods\\stats\\server\\udrive\\usr\\local\\mysql\\bin\\mysqld-opt.exe"= TCP:c:\program files\ea games\battlefield 2\mods\stats\server\udrive\usr\local\mysql\bin\mysqld-opt.exe:mysqld-opt
"TCP Query User{5AE3E59D-F8F1-447F-A817-3640BED950E5}k:\\left4dead.exe"= UDP:K:\left4dead.exe:left4dead
"UDP Query User{615A3CE0-8C89-426A-9FFB-49CBDEBF4393}k:\\left4dead.exe"= TCP:K:\left4dead.exe:left4dead
"TCP Query User{AF3C203B-3A5A-4FF2-B451-17DD6D59F015}c:\\program files\\left 4 dead\\left4dead.exe"= UDP:c:\program files\left 4 dead\left4dead.exe:left4dead
"UDP Query User{C20CE33D-A6EE-44FD-9E3D-D294A55925B1}c:\\program files\\left 4 dead\\left4dead.exe"= TCP:c:\program files\left 4 dead\left4dead.exe:left4dead
"{E86EBFE8-3438-47D0-9AD9-4582A2284AF3}"= UDP:5353:Adobe CSI CS4
"{6122A0D6-2D95-43EB-BEA2-A83992945117}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{FA01B65D-FC1B-4B3F-B746-CA1544A20790}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"TCP Query User{EBD7C553-A0FF-4E5C-9E51-5DB1DD47E3E3}c:\\program files\\thq\\dawn of war - dark crusade\\darkcrusade.exe"= UDP:c:\program files\thq\dawn of war - dark crusade\darkcrusade.exe:DarkCrusade
"UDP Query User{9FD07EB2-DF3B-4FE4-BAB6-E95E8D8E09B6}c:\\program files\\thq\\dawn of war - dark crusade\\darkcrusade.exe"= TCP:c:\program files\thq\dawn of war - dark crusade\darkcrusade.exe:DarkCrusade
"{8556CB50-CFE7-4FFA-81BD-4094CA2571CA}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{508BF38F-F1FC-4701-BC76-C2297073163C}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{B89290AC-C2A2-4E0E-8103-611CBC9C4EA6}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{0A9CA4E8-1A6E-4E20-98A0-E0E08C154090}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"TCP Query User{D468A7BC-63BA-4DE6-ABFC-359D012CEA39}c:\\program files\\thq\\company of heroes\\reliccoh.exe"= UDP:c:\program files\thq\company of heroes\reliccoh.exe:RelicCOH
"UDP Query User{5F3B8816-5E84-4361-8DA1-E88B444EEA33}c:\\program files\\thq\\company of heroes\\reliccoh.exe"= TCP:c:\program files\thq\company of heroes\reliccoh.exe:RelicCOH
"{055ABF4C-7EF9-4332-87A1-827EF30CC6F0}"= UDP:c:\program files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:The Battle for Middle-earth(tm) II
"{F62E10E3-7E39-4425-8EC1-2C7844F0EAB1}"= TCP:c:\program files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:The Battle for Middle-earth(tm) II
"TCP Query User{2FF37211-0A6B-422E-8C93-B8B412A09847}c:\\program files\\winamp remote\\bin\\orbtray.exe"= UDP:c:\program files\winamp remote\bin\orbtray.exe:Orb
"UDP Query User{36067DE2-6ECB-4B62-9494-08C1D59E9CBC}c:\\program files\\winamp remote\\bin\\orbtray.exe"= TCP:c:\program files\winamp remote\bin\orbtray.exe:Orb
"{CC563D3E-6B2F-4F66-93CC-51B22B31CA44}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{85AEEF51-EBDF-4BA4-94DF-9CBB6AE0C61F}"= UDP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{535B2676-35FF-4880-9F79-593A1874EA0E}"= TCP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"TCP Query User{B508A6E0-5497-4579-B8E7-FBC8D10A49DB}c:\\program files\\microsoft games\\age of empires\\empires.exe"= UDP:c:\program files\microsoft games\age of empires\empires.exe:Age of Empires
"UDP Query User{1F498001-3E7A-41E7-ABF8-EF4F3154A76D}c:\\program files\\microsoft games\\age of empires\\empires.exe"= TCP:c:\program files\microsoft games\age of empires\empires.exe:Age of Empires

R2 CAMTHWDM;WebcamMax, WDM Video Capture;c:\windows\System32\drivers\CAMTHWDM.sys [3/11/2008 9:14 AM 941784]
R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [3/28/2009 10:05 AM 55280]
R2 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/28/2007 2:15 PM 24652]
R3 xcbdaNtsc;ViXS Tuner Card (NTSC);c:\windows\System32\drivers\xcbda.sys [11/17/2006 11:51 PM 147328]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\System32\drivers\PPJoyBus.sys [1/23/2004 4:33 PM 13952]
S3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\System32\drivers\PPortJoy.sys [1/23/2004 4:32 PM 28800]
S4 TeamViewer;TeamViewer 3;c:\program files\TeamViewer3\TeamViewer_Service.exe [10/7/2008 2:31 AM 185640]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-11-19 07:06]

2009-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1750895592-24388651-1354914393-1000Core.job
- c:\users\Dean\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-16 23:46]

2009-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1750895592-24388651-1354914393-1000UA.job
- c:\users\Dean\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-16 23:46]

2009-08-19 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 13:20]

2008-09-25 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 13:20]

2009-07-14 c:\windows\Tasks\User_Feed_Synchronization-{9F664F7E-F9C6-4BC8-8F86-D2ED866C1F26}.job
- c:\windows\system32\msfeedssync.exe [2009-05-29 11:31]
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: &AIM Toolbar Search - c:\programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
FF - ProfilePath - c:\users\Dean\AppData\Roaming\Mozilla\Firefox\Profiles\t5tymc2i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/sli ... ie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/sli ... rab&query=
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\users\Dean\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\users\Dean\AppData\Roaming\Mozilla\plugins\npcoolirisplugin.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PsSdk30]
"ImagePath"="\??\c:\windows\system32\Drivers\PsSdk30.drv"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1750895592-24388651-1354914393-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5e,2b,38,32,b9,c6,39,0b,17,6a,db,f1,9d,b4,69,9c,dc,85,49,ae,b9,9a,22,
21,40,0c,fc,cd,ae,3d,64,ee,b8,65,25,bd,e1,45,36,a2,11,c1,47,bc,96,d6,08,32,\
"??"=hex:aa,d3,ad,10,3e,21,e1,5a,ee,a5,d7,2f,8a,be,03,83

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(2620)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\MagicTune Premium\MagicTuneEngine.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\windows\ehome\ehsched.exe
c:\users\Dean\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\windows\ehome\ehrecvr.exe
.
**************************************************************************
.
Completion time: 2009-08-19 1:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-19 05:07
ComboFix2.txt 2008-11-10 14:19
ComboFix3.txt 2008-11-09 15:16

Pre-Run: 105,711,390,720 bytes free
Post-Run: 104,954,953,728 bytes free

390 --- E O F --- 2009-05-29 14:26
TheExero
Geek
Geek
 
Posts: 51
Joined: Sat Dec 01, 2007 12:00 am

Thanks given:0
Thanks received:0
Top

Re: Fresh log

Postby Gecko » Thu Aug 20, 2009 11:20 pm

TheExero,

Could you please tell me what is in the following folder:
c:\programdata\{B98A2B83-8BB0-42E7-AA1D-D6FA6E7C8F31}

The dates on this entry are vary strange 2014-01-17 18:25 ???
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Fresh log

Postby TheExero » Thu Aug 20, 2009 11:28 pm

I had to enable "show hidden files and folders" to find it and when i looked inside i found iconpackager.exe and other related files. It's a program i used to change the way icons look on my system but i don't know why it's a hidden file.

Also another issue i been having is when i go to youtube or Face book or other sites i can't view the preview images on the thumbnails for all video thumbnails and image thumbnails but it works in IE. Also sometimes i lose control of firefox and it minimizes to a small window and plays music until i end the task in the task manager. Don't know if this is related but it seems strange. :roll:
TheExero
Geek
Geek
 
Posts: 51
Joined: Sat Dec 01, 2007 12:00 am

Thanks given:0
Thanks received:0
Top

Re: Fresh log

Postby Gecko » Sun Aug 23, 2009 11:49 pm

TheExero,

I went through you log again and I don't really see anything bad.

As for firefox, go tools > options > Content tab make sure "Load images Auto" is check and also check it's "Exceptions"
If that does work try uninstalling firefox and then reinstall it.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Fresh log

Postby TheExero » Mon Aug 24, 2009 7:34 pm

Yeah Fire Fox works now ty. And glad to hear i'm not infected with any nasty virtual critters. :lol:
TheExero
Geek
Geek
 
Posts: 51
Joined: Sat Dec 01, 2007 12:00 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron