Author Topic: My pc has gone very slow - just want to be sure there's nothing strange!  (Read 1532 times)

0 Members and 1 Guest are viewing this topic.

Offline Aoife

  • Newbie
  • *
  • Posts: 7
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:09, on 18/09/2009
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\WerCon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/home.php?ref=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [SBRegRebootCleaner] C:\Program Files\Sunbelt Software\CounterSpy\SBRC.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Turbine Download Manager Tray Icon] "C:\Users\Aoife\Games\Turbine Download Manager\TurbineDownloadManagerIcon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~4.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.kewlbox.com/games/play.aspx"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: Secunia PSI (RC1).lnk = C:\Program Files\Secunia\PSI (RC1)\psi.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O8 - Extra context menu item: &AOL Toolbar Cerca - c:\program files\aol\aol toolbar 5.0\resources\it-it\local\search.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-ie/wlscctrl2.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-IE/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - http://l.yimg.com/jh/games/web_games/playtime/mahjongescape/PTGameLauncher.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Users\Aoife\Games\Turbine Download Manager\TurbineMessageService.exe
O23 - Service: Turbine Network Service - Live (LiveTurbineNetworkService) - Turbine, Inc. - C:\Users\Aoife\Games\Turbine Download Manager\TurbineNetworkService.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 14950 bytes

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #1 on: September 18, 2009, 05:59:11 PM »
Hi, Aoife.  Welcome to LandzDown Forum. 

Aside from at least one out-dated software as well as being behind on Service Packs, nothing untoward is shown in your log so let's take a closer look with RSIT.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Aoife

  • Newbie
  • *
  • Posts: 7
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #2 on: September 18, 2009, 06:58:31 PM »
Thanks for your help Corrine ^^

I haven't updated service packs because I was worried they'd ask for license numbers etc., we've moved house since buying this pc & I have no idea where any of the stuff that came with it is :/

Logfile of random's system information tool 1.06 (written by random/random)
Run by Aoife at 2009-09-18 20:37:56
Microsoft® Windows Vista™ Home Premium 
System drive C: has 13 GB (6%) free of 227 GB
Total RAM: 3070 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:39:51, on 18/09/2009
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Aoife\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Aoife.exe
C:\Windows\system32\SearchProtocolHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/home.php?ref=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [SBRegRebootCleaner] C:\Program Files\Sunbelt Software\CounterSpy\SBRC.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Turbine Download Manager Tray Icon] "C:\Users\Aoife\Games\Turbine Download Manager\TurbineDownloadManagerIcon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~4.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.kewlbox.com/games/play.aspx"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: Secunia PSI (RC1).lnk = C:\Program Files\Secunia\PSI (RC1)\psi.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O8 - Extra context menu item: &AOL Toolbar Cerca - c:\program files\aol\aol toolbar 5.0\resources\it-it\local\search.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-ie/wlscctrl2.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-IE/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - http://l.yimg.com/jh/games/web_games/playtime/mahjongescape/PTGameLauncher.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Users\Aoife\Games\Turbine Download Manager\TurbineMessageService.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 14762 bytes

======Scheduled tasks folder======

C:\Windows\tasks\HPCeeScheduleForAoife.job
C:\Windows\tasks\User_Feed_Synchronization-{239A0911-01DA-42BF-B6B5-A88188D885B8}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-12-18 817936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Supporto di collegamento per Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-13 222448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar Launcher - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-07-31 1086816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Guida per l'accesso a Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-05-17 2423872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-07-31 1086816]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! ¤u¨ã¦C - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-12-18 817936]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-05-17 2423872]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-09-19 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-09-19 8497696]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-09-19 81920]
"SynTPStart"=C:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-09-15 102400]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2007-09-30 181544]
"QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2007-09-19 202032]
"OnScreenDisplay"=C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [2007-09-04 554320]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-08-16 218408]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-02-25 1006264]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-16 75008]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-09-13 480560]
"WAWifiMessage"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [2007-01-08 311296]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-08-17 81000]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
""= []
"SBCSTray"=C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe [2007-12-21 698864]
"SBRegRebootCleaner"=C:\Program Files\Sunbelt Software\CounterSpy\SBRC.exe [2007-12-21 141808]
"SpybotSnD"=C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 5365592]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2007-08-07 200704]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-25 149280]
"Turbine Download Manager Tray Icon"=C:\Users\Aoife\Games\Turbine Download Manager\TurbineDownloadManagerIcon.exe [2009-09-17 472568]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-05-12 1232896]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2007-08-23 455968]
"HPAdvisor"=C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2007-10-01 1783136]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe [2008-05-17 171448]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2006-11-02 125440]
"Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2009-03-18 4363504]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"=C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~4.EXE [2008-11-04 460216]

C:\Users\Aoife\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe
Secunia PSI (RC1).lnk - C:\Program Files\Secunia\PSI (RC1)\psi.exe
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBCSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SBCSSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\autorun.exe
shell\install\command - F:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{391c6d32-b8a5-11dd-b146-001e683f6382}]
shell\AutoRun\command - G:\autoplay.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-09-18 20:37:56 ----D---- C:\rsit
2009-09-17 12:00:31 ----D---- C:\ProgramData\PMB Files
2009-09-17 12:00:15 ----D---- C:\Program Files\Pando Networks
2009-09-17 11:59:04 ----D---- C:\ProgramData\Turbine
2009-09-17 11:47:33 ----D---- C:\Windows\system32\URTTEMP
2009-09-09 19:00:02 ----A---- C:\Windows\clientshell.INI
2009-09-09 18:54:00 ----D---- C:\Users\Aoife\AppData\Roaming\BitCometLite
2009-09-09 10:42:12 ----A---- C:\Windows\system32\jscript.dll
2009-09-09 10:42:07 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-09-09 10:42:06 ----A---- C:\Windows\system32\mf.dll
2009-09-09 10:42:05 ----A---- C:\Windows\system32\rrinstaller.exe
2009-09-09 10:42:05 ----A---- C:\Windows\system32\mfps.dll
2009-09-09 10:42:05 ----A---- C:\Windows\system32\mfpmp.exe
2009-09-09 10:42:05 ----A---- C:\Windows\system32\mferror.dll
2009-09-09 10:41:38 ----A---- C:\Windows\system32\netiohlp.dll
2009-09-09 10:41:37 ----A---- C:\Windows\system32\tcpipcfg.dll
2009-09-09 10:41:36 ----A---- C:\Windows\system32\TCPSVCS.EXE
2009-09-09 10:41:36 ----A---- C:\Windows\system32\ROUTE.EXE
2009-09-09 10:41:36 ----A---- C:\Windows\system32\NETSTAT.EXE
2009-09-09 10:41:36 ----A---- C:\Windows\system32\netiougc.exe
2009-09-09 10:41:36 ----A---- C:\Windows\system32\netevent.dll
2009-09-09 10:41:36 ----A---- C:\Windows\system32\MRINFO.EXE
2009-09-09 10:41:36 ----A---- C:\Windows\system32\HOSTNAME.EXE
2009-09-09 10:41:36 ----A---- C:\Windows\system32\finger.exe
2009-09-09 10:41:36 ----A---- C:\Windows\system32\ARP.EXE
2009-09-09 10:40:08 ----A---- C:\Windows\system32\wlanmsm.dll
2009-09-09 10:40:07 ----A---- C:\Windows\system32\wlansec.dll
2009-09-09 10:40:06 ----A---- C:\Windows\system32\wlansvc.dll
2009-09-09 10:40:06 ----A---- C:\Windows\system32\L2SecHC.dll
2009-09-09 10:40:05 ----A---- C:\Windows\system32\wlanhlp.dll
2009-09-09 10:40:05 ----A---- C:\Windows\system32\wlanapi.dll
2009-09-04 19:20:13 ----A---- C:\Windows\CountryWars Uninstall Log.txt
2009-09-03 19:21:02 ----D---- C:\Windows\CountryWars
2009-09-03 19:19:34 ----A---- C:\Windows\CountryWars Setup Log.txt
2009-09-03 00:49:07 ----A---- C:\Windows\system32\gameux.dll
2009-09-03 00:49:07 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-09-03 00:49:06 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-09-02 19:58:35 ----D---- C:\Users\Aoife\AppData\Roaming\skypePM
2009-09-02 19:56:58 ----D---- C:\Users\Aoife\AppData\Roaming\Skype
2009-09-02 19:55:06 ----D---- C:\Program Files\Common Files\Skype
2009-09-02 19:55:05 ----RD---- C:\Program Files\Skype
2009-09-02 19:54:53 ----D---- C:\ProgramData\Skype
2009-09-02 09:09:11 ----A---- C:\Windows\system32\javaws.exe
2009-09-02 09:09:11 ----A---- C:\Windows\system32\javaw.exe
2009-09-02 09:09:11 ----A---- C:\Windows\system32\java.exe
2009-09-02 09:06:14 ----A---- C:\Windows\system32\tzres.dll

======List of files/folders modified in the last 1 months======

2009-09-18 20:38:17 ----D---- C:\Windows\Temp
2009-09-18 14:48:42 ----SHD---- C:\System Volume Information
2009-09-18 10:12:05 ----D---- C:\Program Files\Mozilla Firefox
2009-09-18 09:58:24 ----D---- C:\Windows\system32\drivers
2009-09-17 19:42:39 ----D---- C:\Users\Aoife\AppData\Roaming\Mozilla
2009-09-17 13:59:35 ----D---- C:\Windows\registration
2009-09-17 12:00:31 ----HD---- C:\ProgramData
2009-09-17 12:00:15 ----RD---- C:\Program Files
2009-09-17 11:59:07 ----D---- C:\Windows
2009-09-17 11:58:45 ----SHD---- C:\Windows\Installer
2009-09-17 11:58:44 ----D---- C:\Windows\winsxs
2009-09-17 11:56:11 ----D---- C:\Windows\System32
2009-09-17 11:56:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-09-17 11:56:02 ----D---- C:\Windows\inf
2009-09-17 11:55:22 ----D---- C:\Program Files\Internet Explorer
2009-09-17 11:48:31 ----RSD---- C:\Windows\assembly
2009-09-17 11:33:05 ----D---- C:\Windows\Prefetch
2009-09-16 12:52:20 ----D---- C:\Windows\system32\catroot2
2009-09-13 18:47:02 ----D---- C:\Users\Aoife\AppData\Roaming\uTorrent
2009-09-11 18:02:07 ----HD---- C:\Program Files\InstallShield Installation Information
2009-09-10 10:42:52 ----D---- C:\Windows\system32\Tasks
2009-09-10 10:42:51 ----D---- C:\Windows\Tasks
2009-09-10 09:43:44 ----D---- C:\Windows\rescache
2009-09-10 09:22:42 ----D---- C:\Windows\system32\it-IT
2009-09-10 09:22:41 ----D---- C:\Windows\system32\migration
2009-09-09 23:44:33 ----D---- C:\Windows\system32\catroot
2009-09-09 23:44:25 ----D---- C:\Program Files\Windows Mail
2009-09-09 23:44:00 ----D---- C:\ProgramData\Microsoft Help
2009-09-09 23:42:15 ----D---- C:\Windows\ehome
2009-09-04 09:02:22 ----D---- C:\Windows\Microsoft.NET
2009-09-04 08:54:24 ----D---- C:\Windows\AppPatch
2009-09-03 11:26:12 ----D---- C:\Users\Aoife\AppData\Roaming\Hewlett-Packard
2009-09-03 10:50:51 ----D---- C:\ProgramData\Hewlett-Packard
2009-09-03 10:46:04 ----D---- C:\SWSetup
2009-09-02 19:55:06 ----D---- C:\Program Files\Common Files
2009-09-02 09:08:59 ----D---- C:\Program Files\Java
2009-08-28 23:38:20 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-08-17 23152]
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-08-17 114768]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-08-17 51376]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2007-08-07 33052]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-08-17 20560]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-08-17 53328]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2008-12-11 271360]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2008-12-11 18048]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-03-21 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-12-06 761856]
R3 CmBatt;Driver batteria a metodo di controllo ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-02-25 14208]
R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDART.sys [2007-09-10 176640]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 HpqRemHid;HP Remote Control HID Device; C:\Windows\system32\DRIVERS\HpqRemHid.sys [2007-07-11 7168]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-06-20 984064]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-06-20 208896]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys [2008-07-28 116736]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-03-07 1059112]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-09-19 7626400]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 SBAPIFS;SBAPIFS; \??\C:\Windows\system32\drivers\sbapifs.sys []
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-02-25 82432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-09-15 191408]
R3 usbvideo;Dispositivo video USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-02-25 132864]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-06-20 660480]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-02-25 11264]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 464384]
S3 drmkaud;Decodificatore audio DRM del kernel Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 E100B;Intel(R) PRO Adapter Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-11-02 163328]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-02-06 55280]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-19 1380864]
S3 MSKSSRV;Proxy di servizio di flusso Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Proxy clock di flusso Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Proxy di gestione qualità di flusso Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Convertitore a T/Sito a sito per flusso Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [2008-02-19 7808]
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-08-17 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-08-17 138680]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 QPCapSvc;QuickPlay Background Capture Service (QBCS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [2007-09-30 271760]
R2 QPSched;QuickPlay Task Scheduler (QTS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [2007-09-30 112016]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-01-09 272024]
R2 SBCSSvc;Sunbelt CounterSpy Antispyware; C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe [2007-12-21 788976]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-07-10 386560]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-08-17 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-08-17 352920]
S2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-06-16 94208]
S2 LiveTurbineMessageService;Turbine Message Service - Live; C:\Users\Aoife\Games\Turbine Download Manager\TurbineMessageService.exe [2009-09-17 267760]
S3 Com4Qlb;Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [2007-03-05 110592]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-05-14 655624]
S3 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 GameConsoleService;GameConsoleService; C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2008-05-06 165416]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-17 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usprserv;User Privilege Service; C:\Windows\System32\svchost.exe [2006-11-02 22016]

-----------------EOF-----------------

info.txt file:

info.txt logfile of random's system information tool 1.06 2009-09-18 20:39:57

======Uninstall list======

-->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
-->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
-->"C:\Program Files\HP Games\Chicken Invaders 3 - Revenge of the Yolk\Uninstall.exe"
-->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
-->"C:\Program Files\HP Games\Digby's Donuts\Uninstall.exe"
-->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
-->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
-->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
-->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
-->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
-->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
-->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
-->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
-->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
-->"C:\Program Files\HP Games\Shooting Stars Pool\Uninstall.exe"
-->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
-->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
-->"C:\Program Files\HP Games\Trijinx\Uninstall.exe"
-->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
-->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->C:\Program Files\Conexant\SmartAudio\SETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
µTorrent-->"C:\Program Files\uTorrent\uninstall.exe"
5 Realms Of Cards-->"C:\Windows\5 Realms Of Cards\uninstall.exe" "/U:C:\Users\Aoife\Games\Card Games!\Uninstall\uninstall.xml"
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Adobe Color EU Recommended Settings CS4-->MsiExec.exe /I{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}
Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
Adobe Color NA Extra Settings CS4-->MsiExec.exe /I{098A2A49-7CF3-4F08-A38D-FB879117152A}
Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
Adobe Device Central CS4-->MsiExec.exe /I{67F0E67A-8E93-4C2C-B29D-47C48262738A}
Adobe Drive CS4-->MsiExec.exe /I{16E16F01-2E2D-4248-A42F-76261C147B6C}
Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}
Adobe Media Player-->msiexec /qb /x {39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
Adobe Media Player-->MsiExec.exe /I{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}
Adobe Photoshop CS4-->C:\Program Files\Common Files\Adobe\Installers\faf656ef605427ee2f42989c3ad31b8\Setup.exe --uninstall=1
Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}
Adobe Photoshop CS4-->MsiExec.exe /I{E4848436-0345-47E2-B648-8B522FCDA623}
Adobe Reader 8.1.2 - Italiano-->MsiExec.exe /I{AC76BA86-7AD7-1040-7B44-A81200000003}
Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
Adobe Setup-->MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}
Adobe Shockwave Player 11-->C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
Adobe Shockwave Player-->MsiExec.exe /X{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}
AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
AOL Toolbar 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
Assistente per l'accesso a Windows Live-->MsiExec.exe /I{6F695BCF-9BDC-48AB-8D46-D57CFAD7A248}
Atheros Driver Installation Program-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\setup.exe" -l0x10  -removeonly
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
CA Yahoo! Anti-Spy (remove only)-->"C:\Program Files\CA Yahoo! Anti-Spy\uninstall.exe"
CABAL Online v3.3-->"C:\Users\Aoife\Downloading\Cabal\CABAL Online (Europe)\unins000.exe"
CABAL Update 408-->"C:\Users\Aoife\Downloading\Cabal\CABAL Online (Europe)\unins001.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -IQh30CFza.INF
Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Dungeons and Dragons Online™ - Eberron Unlimited™ - Live-->"C:\Users\Aoife\Games\D&D\Uninstall.exe" /silent /query 15b35190-c6f9-11d9-9669-0800200c9a66_is1
DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe"  -uninstall
EA Link-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{F5577101-33CC-4711-8235-3A95BCD49DB0} /l1040
eMule-->"C:\Program Files\eMule\Uninstall.exe"
ESU for Microsoft Vista-->MsiExec.exe /I{B037F79A-1564-4FCD-B441-69675098418A}
EU Update 417-->"C:\Users\Aoife\Downloading\Cabal\CABAL Online (Europe)\unins002.exe"
FATE-->"C:\Program Files\WildGames\FATE\Uninstall.exe"
Free Realms Installer-->C:\Program Files\Sony Online Entertainment\uninst.exe
Google Earth-->MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Gothic III-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{02B244A2-7F6A-42E8-A36F-8C385D7A1625}\setup.exe" -l0x9  -removeonly
Hauppauge MCE XP/Vista Software Encoder (2.0.25149)-->C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDA_HSF\UIU32m.exe -U -I*.INF
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall  /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}\setup.exe -runfromtemp -l0x0409
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD0E2B92-3814-46F0-893B-4612EA010C7E}\setup.exe" -l0x9  -removeonly
HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}\setup.exe" -l0x9  -removeonly
HP Help and Support-->MsiExec.exe /X{31216452-5540-4C96-B754-94890A63D5AB}
HP Quick Launch Buttons 6.30 E1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x0010 uninst
HP QuickPlay 3.6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe"  -uninstall
HP QuickTouch 1.00 C4-->MsiExec.exe /I{7DC4A410-9986-4329-9E5D-687B2C42CA39}
HP Total Care Advisor-->MsiExec.exe /X{b02df929-29a7-4fd2-9a70-81a644b635f7}
HP Update-->MsiExec.exe /X{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}
HP User Guides 0087-->MsiExec.exe /I{4D49757C-367A-4333-BDB3-68966162B14E}
HP Wireless Assistant-->MsiExec.exe /I{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}
HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe"  -uninstall
LastChaos-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0AF3FEAE-B651-4421-97EF-4808A588B4E5}\Setup.exe" -l0x9
Liong The Lost Amulets-->"C:\Windows\Liong The Lost Amulets\uninstall.exe" "/U:C:\Users\Aoife\Downloading\The Lost Amulets\Uninstall\uninstall.xml"
MagicDisc 2.7.105-->C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 3.5 - Language Pack SP1 (italiano)-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - ita\setup.exe
Microsoft .NET Framework 3.5 Language Pack SP1 - ita-->MsiExec.exe /I{55CA4086-0D2C-30E3-A7B5-C76BA737CECE}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0410-0000-0000000FF1CE} /uninstall {0A75DA12-55CB-4DE5-8B6A-74D97847204E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0410-0000-0000000FF1CE} /uninstall {0A75DA12-55CB-4DE5-8B6A-74D97847204E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Access MUI (Italian) 2007-->MsiExec.exe /X{90120000-0015-0410-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel 2007 Help - Aggiornamento (KB963678)-->msiexec /package {90120000-0016-0410-0000-0000000FF1CE} /uninstall {9F57BDED-B51B-4D2F-B360-5B4EFAAF0F1A}
Microsoft Office Excel 2007 Help - Aggiornamento (KB963678)-->msiexec /package {90120000-0016-0410-0000-0000000FF1CE} /uninstall {9F57BDED-B51B-4D2F-B360-5B4EFAAF0F1A}
Microsoft Office Excel MUI (Italian) 2007-->MsiExec.exe /X{90120000-0016-0410-0000-0000000FF1CE}
Microsoft Office Groove MUI (Italian) 2007-->MsiExec.exe /X{90120000-00BA-0410-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Italian) 2007-->MsiExec.exe /X{90120000-0044-0410-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office OneNote MUI (Italian) 2007-->MsiExec.exe /X{90120000-00A1-0410-0000-0000000FF1CE}
Microsoft Office Outlook 2007 Help - Aggiornamento (KB963677)-->msiexec /package {90120000-001A-0410-0000-0000000FF1CE} /uninstall {2278E02A-AB15-4BF7-B2B4-5C0EEB4B7EEB}
Microsoft Office Outlook MUI (Italian) 2007-->MsiExec.exe /X{90120000-001A-0410-0000-0000000FF1CE}
Microsoft Office Powerpoint 2007 Help - Aggiornamento (KB963669)-->msiexec /package {90120000-0018-0410-0000-0000000FF1CE} /uninstall {C76C02F1-B07F-4974-876A-A18DEC9887C8}
Microsoft Office Powerpoint 2007 Help - Aggiornamento (KB963669)-->msiexec /package {90120000-0018-0410-0000-0000000FF1CE} /uninstall {C76C02F1-B07F-4974-876A-A18DEC9887C8}
Microsoft Office PowerPoint MUI (Italian) 2007-->MsiExec.exe /X{90120000-0018-0410-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (Italian)-->MsiExec.exe /X{95120000-00AF-0410-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Italian) 2007-->MsiExec.exe /X{90120000-001F-0410-0000-0000000FF1CE}
Microsoft Office Proofing (Italian) 2007-->MsiExec.exe /X{90120000-002C-0410-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0410-0000-0000000FF1CE} /uninstall {322296D4-1EAE-4030-9FBC-D2787EB25FA2}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0410-0000-0000000FF1CE} /uninstall {322296D4-1EAE-4030-9FBC-D2787EB25FA2}
Microsoft Office Publisher MUI (Italian) 2007-->MsiExec.exe /X{90120000-0019-0410-0000-0000000FF1CE}
Microsoft Office Shared MUI (Italian) 2007-->MsiExec.exe /X{90120000-006E-0410-0000-0000000FF1CE}
Microsoft Office Word 2007 Help - Aggiornamento (KB963665)-->msiexec /package {90120000-001B-0410-0000-0000000FF1CE} /uninstall {E5B82DB3-DD7D-4C45-BC5E-09864B26F9BC}
Microsoft Office Word 2007 Help - Aggiornamento (KB963665)-->msiexec /package {90120000-001B-0410-0000-0000000FF1CE} /uninstall {E5B82DB3-DD7D-4C45-BC5E-09864B26F9BC}
Microsoft Office Word MUI (Italian) 2007-->MsiExec.exe /X{90120000-001B-0410-0000-0000000FF1CE}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Works-->MsiExec.exe /I{34A08914-7A33-4040-A959-1577BF5AFF8A}
Mozilla Firefox (3.5.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
Neffy 1,2,1,4-->C:\Program Files\Neffy\uninst.exe
NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0010 -removeonly
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
OGA Notifier 1.7.0105.35.0-->MsiExec.exe /I{BCCB055C-7F64-4B13-90F5-078DE693EE00}
OpenOffice.org Installer 1.0-->MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
Pacchetto di compatibilità per Office System 2007-->MsiExec.exe /X{90120000-0020-0410-0000-0000000FF1CE}
Pando Media Booster-->C:\Program Files\Pando Networks\Media Booster\uninst.exe
PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
Pet Racer-->C:\Program Files\Pet Racer\uninstall Pet Racer.exe
Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe"  -uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"
QuickPlay SlingPlayer 0.4.4-->"C:\Program Files\HP\QuickPlay\unins000.exe"
Raccolta foto di Windows Live-->MsiExec.exe /X{A973AD04-558F-4810-9B1B-0664C930490B}
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x10 anything
Runes of Magic-->"C:\Users\Aoife\Downloading\Runes of Magic\Runes of Magic\unins000.exe"
Secunia PSI (RC1)-->"C:\Program Files\Secunia\PSI (RC1)\uninstall.exe"
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
Se

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #3 on: September 18, 2009, 07:36:43 PM »
Hi, Aoife.

Your log cut off due to board software restrictions.  Please go to C:\RSIT\info.txt and copy the remainder of the log following the item below and paste it here as a reply.

Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}


After doing that, let's take care of the old SunJava and take a look at another log.

Go to Add/Remove programs and uninstall the following:

Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}


Please download JavaRa and unzip it to your desktop.

  • Double-click on JavaRa.exe to start the program.  (Windows Vista users Right-click JavaRa.exe > Select Run as Administrator)
  • Click on Remove Older Versions to remove older versions of Java.
  • A logfile will pop up. Please save it to a convenient location.

Then download and install Java SE Runtime Environment (JRE) 6 Update 16.   

Download Link: Java SE Runtime Environment 6u16

Note:  UNCHECK any pre-checked toolbar and/or software options presented with the update.  They are not part of the software update and are completely optional.   

Please download ATF Cleaner by Atribune from http://www.atribune.org/index.php?option=c...5&Itemid=25 . Save it to your Desktop.

Run ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
  • Click Exit on the Main menu to close the program.
  • Shutdown/restart the computer.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Please post contents of that file in your next reply.

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Aoife

  • Newbie
  • *
  • Posts: 7
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #4 on: September 19, 2009, 09:41:17 AM »
Hi Corrine, Apologies!

I'm following your instructions slowly but surely, I have a small baby & an 11 yr old  :D who keep me on my toes. The weekend is my busiest time as my husband keeps baby amused while I get those million & one things done ;)
I do appreciate hugely the attention you are paying to me & my beloved laptop  :rose:
(especially as you've probably already figured out that it's not an emergency & it's probably a case of me being overly cautious!)
I live in Italy (hubby being the Italian one) & hope the Italian won't cause you problems

ps Spybot should now be updated, I thought it was on automatic update (atleast it was), will keep my eye on it

here is the rest of the info file:
Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
Skype web features-->MsiExec.exe /I{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}
Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Strumento di caricamento di Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TES Construction Set-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\CSUninstall\Setup.exe" -l0x9
The Sims™ Life Stories-->MsiExec.exe /I{2284D904-C138-4B58-93EC-5C362AB5130A}
Treasure Masters Inc-->"C:\Windows\Treasure Masters Inc\uninstall.exe" "/U:C:\Program Files\Treasure Masters Inc\Uninstall\uninstall.xml"
Turbine Download Manager - Live-->"C:\Users\Aoife\Games\Turbine Download Manager\UninstallTDM.exe" /silent /query 62289540-dc30-11dc-95ff-0800200c9a66_is1
Uninstall Phoenix Dynasty Online-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{15DF6FD4-7653-4BBA-B4E7-87C5B1273FED}\setup.exe"  -uninst
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Microsoft Office Outlook 2007 (KB969907)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462}
Update for Outlook 2007 Junk Email Filter (kb973514)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {03B11C77-336F-43B4-9B43-79890BA84504}
VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Voyage Century Online-->"C:\Users\Aoife\Downloading\VCO\Voyage Century Online\unins000.exe"
Warcraft III-->C:\Windows\War3Unin.exe C:\Windows\War3Unin.dat
Windows Live Call-->MsiExec.exe /I{49C77D21-F91F-4296-B7DF-19C5FF51AF4D}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{E171E280-0BAE-4460-9F47-CA96D17828B6}
Windows Live Family Safety-->MsiExec.exe /X{42146067-CB25-4560-8DA1-EBE8AFC37147}
Windows Live Messenger-->MsiExec.exe /X{5AE2BE5E-930A-481C-817E-C373E8910C8A}
Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
Windows Live Sync-->MsiExec.exe /X{EF321705-AE33-4E6E-ACEA-18EDF7F24144}
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
Yahoo! ¤u¨ã¦C-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
Yahoo! Browser Services-->C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
Yahoo! Install Manager-->C:\Windows\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail-->C:\Windows\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Widgets-->C:\PROGRA~1\Yahoo!\Widgets\uninstall.exe
YouSendIt Express-->C:\Program Files\InstallShield Installation Information\{CBB6F775-E76E-49F7-98D3-1519414B1E4B}\setup.exe -runfromtemp -l0x0409

=====HijackThis Backups=====

O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) [2008-07-23]
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Aoife\AppData\Local\Temp\fccyyWNE.dll,#1 [2008-07-23]
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Aoife\AppData\Local\Temp\cbXPjhHx.dll,c [2008-07-23]
O4 - HKCU\..\Run: [BM3c1ecfbb] Rundll32.exe "C:\Users\Aoife\AppData\Local\Temp\srrqntjb.dll",s [2008-07-23]
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\hgGwUoPH.dll,#1 [2008-07-23]
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Aoife\AppData\Local\Temp\fccyyWNE.dll,#1 [2008-07-23]
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) [2008-07-23]
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file) [2008-07-23]
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2008-07-23]
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab [2009-07-16]

======Hosts File======

127.0.0.1   www.007guard.com
127.0.0.1   007guard.com
127.0.0.1   008i.com
127.0.0.1   www.008k.com
127.0.0.1   008k.com
127.0.0.1   www.00hq.com
127.0.0.1   00hq.com
127.0.0.1   010402.com
127.0.0.1   www.032439.com
127.0.0.1   032439.com

======Security center information======

AV: avast! antivirus 4.8.1351 [VPS 090917-0]
AS: Spybot - Search and Destroy (outdated)
AS: Windows Defender
AS: Sunbelt Software Sunbelt CounterSpy 2.5.1043 (outdated)
AS: avast! antivirus 4.8.1351 [VPS 090917-0]

======System event log======

Computer Name: PC-Aoife
Event Code: 7036
Message: Il servizio Servizio rilevamento automatico proxy WinHTTP è ora in modalità arrestato.
Record Number: 160648
Source Name: Service Control Manager
Time Written: 20090918145542.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Aoife
Event Code: 7036
Message: Il servizio Servizio rilevamento automatico proxy WinHTTP è ora in modalità esecuzione.
Record Number: 160649
Source Name: Service Control Manager
Time Written: 20090918161714.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Aoife
Event Code: 7036
Message: Il servizio Servizio rilevamento automatico proxy WinHTTP è ora in modalità arrestato.
Record Number: 160650
Source Name: Service Control Manager
Time Written: 20090918163344.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Aoife
Event Code: 7036
Message: Il servizio Servizio rilevamento automatico proxy WinHTTP è ora in modalità esecuzione.
Record Number: 160651
Source Name: Service Control Manager
Time Written: 20090918181217.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Aoife
Event Code: 7036
Message: Il servizio Servizio rilevamento automatico proxy WinHTTP è ora in modalità arrestato.
Record Number: 160652
Source Name: Service Control Manager
Time Written: 20090918182847.000000-000
Event Type: Informazioni
User:

=====Application event log=====

Computer Name: PC-Aoife
Event Code: 1001
Message: Bucket errato 725378071, tipo 5
Nome evento: AppHangB1
Risposta: Nessuno
ID CAB: 0

Firma problema:
P1: FWClient.exe
P2: 7401.625.1.0
P3: 4a435d1c
P4: 24cb
P5: 0
P6:
P7:
P8:
P9:
P10:

File allegati:
C:\Users\Aoife\AppData\Local\Temp\WERD002.tmp.version.txt

I file potrebbero essere disponibili qui:
C:\Users\Aoife\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report1edce6dc
Record Number: 21138
Source Name: Windows Error Reporting
Time Written: 20090918141333.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Aoife
Event Code: 1002
Message: Il programma FWClient.exe versione 7401.625.1.0 non interagisce più con Windows ed è stato chiuso. Per vedere se sono disponibili ulteriori informazioni sul problema, verificare la cronologia del problema in Segnalazioni di problemi e soluzioni nel Pannello di controllo. ID processo: 15f4 Ora di avvio: 01ca3862a6fa8a04 Ora di chiusura: 16
Record Number: 21139
Source Name: Application Hang
Time Written: 20090918141336.000000-000
Event Type: Errore
User:

Computer Name: PC-Aoife
Event Code: 0
Message: Il servizio è stato arrestato.
Record Number: 21140
Source Name: Turbine Message Service
Time Written: 20090918142228.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Aoife
Event Code: 9010
Message: Richiesta di disattivazione di Gestione finestre desktop creata dal processo (dndclient.exe)
Record Number: 21141
Source Name: Desktop Window Manager
Time Written: 20090918142336.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Aoife
Event Code: 5
Message: Unsupported service control request (see data below)
Record Number: 21142
Source Name: LightScribeService
Time Written: 20090918183955.000000-000
Event Type: Informazioni
User:

=====Security event log=====

Computer Name: PC-Aoife
Event Code: 4648
Message: È stato tentato un accesso utilizzando credenziali esplicite.

Soggetto:
   ID protezione:      S-1-5-18
   Nome account:      PC-AOIFE$
   Dominio account:      WORKGROUP
   ID accesso:      0x3e7
   GUID accesso:      {00000000-0000-0000-0000-000000000000}

Account di cui sono state utilizzate le credenziali:
   Nome account:      SYSTEM
   Dominio account:      NT AUTHORITY
   GUID accesso:      {00000000-0000-0000-0000-000000000000}

Server di destinazione:
   Nome server di destinazione:   localhost
   Informazioni aggiuntive:   localhost

Informazioni sul processo:
   ID processo:      0x2a0
   Nome processo:      C:\Windows\System32\services.exe

Informazioni di rete:
   Indirizzo di rete:   -
   Porta:         -

Questo evento viene generato quando un processo tenta di far accedere un account specificando esplicitamente le credenziali dell'account. Generalmente si verifica in configurazioni di tipo batch, ad esempio attività pianificate, oppure quando si utilizza il comando RUNAS.
Record Number: 29380
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090918080255.080810-000
Event Type: Controllo riuscito
User:

Computer Name: PC-Aoife
Event Code: 4624
Message: Accesso di un account riuscito.

Soggetto:
   ID protezione:      S-1-5-18
   Nome account:      PC-AOIFE$
   Dominio account:      WORKGROUP
   ID accesso:      0x3e7

Tipo di accesso:         5

Nuovo accesso:
   ID protezione:      S-1-5-18
   Nome account:      SYSTEM
   Dominio account:      NT AUTHORITY
   ID accesso:      0x3e7
   GUID accesso:      {00000000-0000-0000-0000-000000000000}

Informazioni sul processo:
   ID processo:      0x2a0
   Nome processo:      C:\Windows\System32\services.exe

Informazioni di rete:
   Nome workstation:   
   Indirizzo rete di origine:   -
   Porta di origine:      -

Informazioni di autenticazione dettagliate:
   Processo di accesso:      Advapi 
   Pacchetto di autenticazione:   Negotiate
   Servizi transitati:   -
   Nome pacchetto (solo NTLM):   -
   Lunghezza chiave:      0

Questo evento viene generato quando viene creata una sessione di accesso. Viene generato nel computer in cui è stato effettuato l'accesso.

Il campo Soggetto indica l'account nel sistema locale che ha richiesto l'accesso. Generalmente si tratta di un servizio, quale il servizio Server, o di un processo locale, ad esempio Winlogon.exe o Services.exe.

Il campo Tipo di accesso indica il tipo di accesso che è stato effettuato. I tipi più comuni sono 2 (interattivo) e 3 (rete).

Il campo Nuovo accesso indica l'account per il quale è stato creato il nuovo accesso, vale a dire l'account che ha effettuato l'accesso.

Il campo Informazioni di rete indica l'origine della richiesta di accesso remota. Il nome della workstation non è sempre disponibile e può essere vuoto in alcuni casi.

Il campo Informazioni di autenticazione fornisce informazioni dettagliate sulla specifica richiesta di accesso.
   - GUID accesso è un identificatore univoco che può essere utilizzato per correlare questo evento a un evento KDC.
   - Servizi transitati indica quali servizi intermedi hanno partecipato alla richiesta di accesso.
   - Nome pacchetto indica quale sottoprotocollo dei protocolli NTLM è stato utilizzato.
   - Lunghezza chiave indica la lunghezza della chiave di sessione generata. Se non è stata richiesta alcuna chiave di sessione, la lunghezza sarà pari a zero.
Record Number: 29381
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090918080255.080810-000
Event Type: Controllo riuscito
User:

Computer Name: PC-Aoife
Event Code: 4672
Message: Privilegi speciali assegnati a nuovo accesso.

Soggetto:
   ID protezione:      S-1-5-18
   Nome account:      SYSTEM
   Dominio account:      NT AUTHORITY
   ID accesso:      0x3e7

Privilegi:      SeAssignPrimaryTokenPrivilege
         SeTcbPrivilege
         SeSecurityPrivilege
         SeTakeOwnershipPrivilege
         SeLoadDriverPrivilege
         SeBackupPrivilege
         SeRestorePrivilege
         SeDebugPrivilege
         SeAuditPrivilege
         SeSystemEnvironmentPrivilege
         SeImpersonatePrivilege
Record Number: 29382
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090918080255.080810-000
Event Type: Controllo riuscito
User:

Computer Name: PC-Aoife
Event Code: 4904
Message: Tentativo di registrare un'origine evento di protezione.

Soggetto:
   ID protezione:      S-1-5-18
   Nome account:      PC-AOIFE$
   Dominio account:      WORKGROUP
   ID accesso:      0x3e7

Processo:
   ID processo:   0x638
   Nome processo:   C:\Windows\System32\VSSVC.exe

Origine evento:
   Nome origine:   VSSAudit
   ID origine evento:   0x3fdad5
Record Number: 29383
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090918081809.082810-000
Event Type: Controllo riuscito
User:

Computer Name: PC-Aoife
Event Code: 4905
Message: Tentativo di annullare la registrazione di un'origine evento di protezione.

Soggetto
   ID protezione:      S-1-5-18
   Nome account:      PC-AOIFE$
   Dominio account:      WORKGROUP
   ID accesso:      0x3e7

Processo:
   ID processo:   0x638
   Nome processo:   C:\Windows\System32\VSSVC.exe

Origine evento:
   Nome origine:   VSSAudit
   ID origine evento:   0x3fdad5
Record Number: 29384
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090918081809.083810-000
Event Type: Controllo riuscito
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\CyberLink\Power2Go\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=6802
"NUMBER_OF_PROCESSORS"=2
"PLATFORM"=MCD
"PCBRAND"=Pavilion
"OnlineServices"=Servizi in linea
"USERPART"=E:

-----------------EOF-----------------

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #5 on: September 19, 2009, 12:33:02 PM »
Hi, Aoife.

Thank you for the rest of the log.  I see from the log that this computer had signs of a Virtumundo infection last year.  For that reason, it is very important that you follow all the steps.  So, when you have a break from the million & one things that need doing, please follow my instructions for SunJava.  Next run ATF Cleaner and then Malwarebytes (MBAM).

Take your time and follow one step at a time.  Although in a different time zone, we'll catch up with one another.  Family first. :)
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Aoife

  • Newbie
  • *
  • Posts: 7
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #6 on: September 19, 2009, 12:58:15 PM »
Hi Corrine,
Yes, I did have problems with a Virtumondo infection after a stupid error I made! I thought I had resolved it & since then I've tried to be very careful.
I've done everything that was in your instructions as hubby was good enough to bring the little man for a walk :D & here is my result:

Malwarebytes' Anti-Malware 1.41
Database version: 2823
Windows 6.0.6000

19/09/2009 14:52:13
mbam-log-2009-09-19 (14-52-13).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|)
Objects scanned: 405236
Time elapsed: 2 hour(s), 3 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #7 on: September 19, 2009, 01:12:14 PM »
Hi, Aoife.  I expect your little one is enjoying his time with father.  :)

Indeed, Vundo was still hanging on your computer.  Considering how long it has been there, I would like to take the cleanup a step further, just as a precaution.

Please follow these instructions carefully.

Download ComboFix from one of the following locations:

Link 1
Link 2

!!! IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications. If not disabled, these programs will likely interfere with cleanup process. This can usually be accomplished by a right-click on the icon in the System Tray.  This can usually be accomplished by a right-click on the icon in the System Tray. 

Note:  If you use AVG, you must also open the AVG 8 Control Center, by right clicking on the AVG 8 icon on task bar as well as the following:
  • Click on Tools.
  • Select Advanced Settings.
  • In the left hand pane, scroll down to "Resident Shield".
  • In the main pane, deselect the option to "Enable Resident Shield."
  • To re-enable AVG 8, please select "Enable Resident Shield" again.

Now, please run ComboFix:
  • Note:  If infections are found, ComboFix will automatically reboot the machine to complete the removal process.  Please ensure all opened windows are closed before proceeding.
  • Double-click ComboFix.exe on your desktop and follow the prompts.
  • As part of the process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it is strongly recommended to have this pre-installed on your machine before doing any malware removal. The Recovery Console will allow you to start up the computer in a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    Please note: If the Microsoft Windows Recovery Console is already installed on the computer, ComboFix will continue the malware removal procedures.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console.
  • When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

  • After the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

  • Click "Yes" to continue scanning for malware.
  • When finished, a log will be produced. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Aoife

  • Newbie
  • *
  • Posts: 7
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #8 on: September 20, 2009, 06:35:12 PM »
Here is my ComboFix log:
I don't understand why Sunbelt is showing up as I uninstalled it...

ComboFix 09-09-18.02 - Aoife 20/09/2009 16:13.3.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6000.0.1252.39.1040.18.3070.1791 [GMT 2:00]
Eseguito da: c:\users\Aoife\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090919-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1351 [VPS 090919-0] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Sunbelt Software Sunbelt CounterSpy 2.5.1043 *enabled* (Outdated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((   Files Creati Da 2009-08-20 al 2009-09-20  )))))))))))))))))))))))))))))))))))
.

2009-09-20 14:21 . 2009-09-20 14:21   --------   d-----w-   c:\users\Public\AppData\Local\temp
2009-09-20 14:21 . 2009-09-20 14:21   --------   d-----w-   c:\users\Default\AppData\Local\temp
2009-09-20 14:21 . 2009-09-20 14:21   --------   d-----w-   c:\users\AoifeTemp\AppData\Local\temp
2009-09-20 13:23 . 2009-09-20 13:24   --------   d-----w-   c:\users\Aoife\AppData\Local\Adobe
2009-09-20 13:23 . 2009-09-20 13:51   --------   d-----w-   c:\users\Aoife\AppData\Local\ApplicationHistory
2009-09-19 10:38 . 2009-09-19 10:38   --------   d-----w-   c:\users\Aoife\AppData\Roaming\Malwarebytes
2009-09-19 10:38 . 2009-09-10 12:54   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-19 10:38 . 2009-09-19 10:38   --------   d-----w-   c:\programdata\Malwarebytes
2009-09-19 10:38 . 2009-09-10 12:53   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-09-19 10:38 . 2009-09-19 10:38   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-09-19 10:07 . 2009-09-19 10:07   --------   d-----w-   c:\program files\Java
2009-09-18 18:37 . 2009-09-18 18:39   --------   d-----w-   C:\rsit
2009-09-17 11:56 . 2009-09-17 11:56   --------   d-----w-   c:\users\Aoife\AppData\Local\Turbine
2009-09-17 10:03 . 2009-09-17 10:03   --------   d-----w-   c:\users\Aoife\AppData\Local\Turbine,_Inc
2009-09-17 10:00 . 2009-09-20 14:21   --------   d-----w-   c:\users\Aoife\AppData\Local\PMB Files
2009-09-17 10:00 . 2009-09-20 13:45   --------   d-----w-   c:\programdata\PMB Files
2009-09-17 10:00 . 2009-09-17 10:00   --------   d-----w-   c:\program files\Pando Networks
2009-09-17 09:59 . 2009-09-17 09:59   --------   d-----w-   c:\programdata\Turbine
2009-09-17 09:57 . 2009-09-17 09:57   93   ----a-w-   c:\users\Aoife\AppData\Local\fusioncache.dat
2009-09-17 09:47 . 2009-09-17 09:47   --------   d-----w-   c:\windows\system32\URTTEMP
2009-09-09 16:54 . 2009-09-09 16:54   --------   d-----w-   c:\users\Aoife\AppData\Roaming\BitCometLite
2009-09-09 08:42 . 2009-06-10 12:07   2855424   ----a-w-   c:\windows\system32\mf.dll
2009-09-09 08:42 . 2009-06-10 12:07   98816   ----a-w-   c:\windows\system32\mfps.dll
2009-09-09 08:42 . 2009-06-10 10:15   24576   ----a-w-   c:\windows\system32\mfpmp.exe
2009-09-09 08:42 . 2009-06-10 10:14   52736   ----a-w-   c:\windows\system32\rrinstaller.exe
2009-09-09 08:42 . 2009-06-10 08:50   2048   ----a-w-   c:\windows\system32\mferror.dll
2009-09-09 08:40 . 2009-07-11 19:24   289280   ----a-w-   c:\windows\system32\wlanmsm.dll
2009-09-09 08:40 . 2009-07-11 19:24   299520   ----a-w-   c:\windows\system32\wlansec.dll
2009-09-09 08:40 . 2009-07-11 19:26   123904   ----a-w-   c:\windows\system32\L2SecHC.dll
2009-09-09 08:40 . 2009-07-11 19:24   502784   ----a-w-   c:\windows\system32\wlansvc.dll
2009-09-09 08:40 . 2009-07-11 19:24   67584   ----a-w-   c:\windows\system32\wlanhlp.dll
2009-09-09 08:40 . 2009-07-11 19:24   47104   ----a-w-   c:\windows\system32\wlanapi.dll
2009-09-03 17:21 . 2009-09-03 17:21   --------   d-----w-   c:\windows\CountryWars
2009-09-02 22:49 . 2009-08-29 03:41   1686528   ----a-w-   c:\windows\system32\gameux.dll
2009-09-02 22:49 . 2009-08-29 03:40   28672   ----a-w-   c:\windows\system32\Apphlpdm.dll
2009-09-02 22:49 . 2009-08-28 23:31   4247552   ----a-w-   c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-02 17:58 . 2009-09-17 11:33   --------   d-----w-   c:\users\Aoife\AppData\Roaming\skypePM
2009-09-02 17:56 . 2009-09-17 11:56   --------   d-----w-   c:\users\Aoife\AppData\Roaming\Skype
2009-09-02 17:55 . 2009-09-02 17:55   --------   d-----w-   c:\program files\Common Files\Skype
2009-09-02 17:55 . 2009-09-02 17:56   --------   d-----r-   c:\program files\Skype
2009-09-02 17:54 . 2009-09-02 17:55   --------   d-----w-   c:\programdata\Skype
2009-09-02 07:06 . 2009-06-22 08:44   2048   ----a-w-   c:\windows\system32\tzres.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-19 10:07 . 2008-12-18 13:47   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-09-18 19:02 . 2008-08-25 13:31   --------   d-----w-   c:\program files\Spybot - Search & Destroy
2009-09-17 15:43 . 2008-05-10 12:41   27335   ----a-w-   c:\users\Aoife\AppData\Roaming\nvModes.dat
2009-09-17 09:56 . 2008-02-25 05:49   692196   ----a-w-   c:\windows\system32\perfh010.dat
2009-09-17 09:56 . 2008-02-25 05:49   119556   ----a-w-   c:\windows\system32\perfc010.dat
2009-09-13 16:47 . 2008-05-15 17:46   --------   d-----w-   c:\users\Aoife\AppData\Roaming\uTorrent
2009-09-11 16:02 . 2008-02-24 21:57   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-09-09 21:44 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-09-09 21:44 . 2008-02-24 22:40   --------   d-----w-   c:\programdata\Microsoft Help
2009-09-03 09:26 . 2008-05-10 06:55   --------   d-----w-   c:\users\Aoife\AppData\Roaming\Hewlett-Packard
2009-09-03 08:50 . 2008-02-24 22:55   --------   d-----w-   c:\programdata\Hewlett-Packard
2009-09-02 17:58 . 2009-09-02 17:58   56   ---ha-w-   c:\programdata\ezsidmv.dat
2009-08-17 16:10 . 2008-06-17 14:43   1279456   ----a-w-   c:\windows\system32\aswBoot.exe
2009-08-17 16:05 . 2008-06-17 14:43   114768   ----a-w-   c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-06-17 14:43   20560   ----a-w-   c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:05 . 2008-06-17 14:43   53328   ----a-w-   c:\windows\system32\drivers\aswMonFlt.sys
2009-08-17 16:04 . 2008-06-17 14:43   51376   ----a-w-   c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2008-06-17 14:43   23152   ----a-w-   c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:02 . 2008-06-17 14:43   97480   ----a-w-   c:\windows\system32\AvastSS.scr
2009-08-14 17:16 . 2009-09-09 08:41   213592   ----a-w-   c:\windows\system32\drivers\netio.sys
2009-08-14 16:42 . 2009-09-09 08:41   167424   ----a-w-   c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40 . 2009-09-09 08:41   103936   ----a-w-   c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-09 08:41   15360   ----a-w-   c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-09 08:41   9728   ----a-w-   c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-09 08:41   17920   ----a-w-   c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-09 08:41   11264   ----a-w-   c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-09 08:41   27136   ----a-w-   c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-09 08:41   8704   ----a-w-   c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-09 08:41   19968   ----a-w-   c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-09 08:41   10240   ----a-w-   c:\windows\system32\finger.exe
2009-08-14 14:24 . 2009-09-09 08:41   813568   ----a-w-   c:\windows\system32\drivers\tcpip.sys
2009-08-14 14:23 . 2009-09-09 08:41   22016   ----a-w-   c:\windows\system32\netiougc.exe
2009-07-30 07:57 . 2008-08-25 13:31   --------   d-----w-   c:\programdata\Spybot - Search & Destroy
2009-07-21 21:52 . 2009-07-29 06:07   915456   ----a-w-   c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 06:07   109056   ----a-w-   c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 06:07   71680   ----a-w-   c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 06:07   133632   ----a-w-   c:\windows\system32\ieUnatt.exe
2009-07-21 14:46 . 2008-06-07 19:44   4868   ----a-w-   c:\users\Aoife\AppData\Roaming\wklnhst.dat
2009-07-17 14:52 . 2009-08-12 13:16   71680   ----a-w-   c:\windows\system32\atl.dll
2009-07-14 13:02 . 2009-08-12 13:16   313344   ----a-w-   c:\windows\system32\wmpdxm.dll
2009-07-14 13:01 . 2009-08-12 13:16   4096   ----a-w-   c:\windows\system32\dxmasf.dll
2009-07-14 13:00 . 2009-08-12 13:16   7680   ----a-w-   c:\windows\system32\spwmp.dll
2009-07-14 11:11 . 2009-08-12 13:16   8147968   ----a-w-   c:\windows\system32\wmploc.DLL
2009-06-26 11:26 . 2009-06-26 11:24   103936   ----a-w-   c:\users\AoifeTemp\AppData\Local\GDIPFONTCACHEV1.DAT
2008-02-25 06:29 . 2008-02-25 06:15   8192   --sha-w-   c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((   SnapShot@2009-09-19_13.38.10   )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-02-24 21:53 . 2009-09-20 07:37   54066              c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-20 07:37   66274              c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-05-11 07:36 . 2009-09-20 07:37   11252              c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3824510552-3789898071-2641794859-1000_UserData.bin
+ 2008-05-10 06:41 . 2009-09-20 14:12   16384              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-05-10 06:41 . 2009-09-19 13:22   16384              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-10 06:41 . 2009-09-20 14:12   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-10 06:41 . 2009-09-19 13:22   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-10 06:41 . 2009-09-20 14:12   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-05-10 06:41 . 2009-09-19 13:22   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-10 18:01 . 2009-09-19 17:07   35240              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-09-19 13:03 . 2009-09-19 13:03   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-20 07:34 . 2009-09-20 07:34   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-20 07:34 . 2009-09-20 07:34   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-09-19 13:03 . 2009-09-19 13:03   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-13 15:55 . 2009-09-20 07:39   245760              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-05-13 15:55 . 2009-09-19 13:09   245760              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
(((((((((((((((((((((((((((((((((((((   Punti Reg Caricati   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-05-12 1232896]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 1783136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-05-17 171448]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-02-25 1006264]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-19 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

c:\users\Aoife\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2008-11-22 575488]
Secunia PSI (RC1).lnk - c:\program files\Secunia\PSI (RC1)\psi.exe [2008-2-22 626688]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BC785C10-4D6C-4BF5-91D7-1430CD5995A7}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{61DCC48D-D635-4825-B4EB-B257BA961349}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2961FD73-7DF0-4329-9CB5-92E9BAC863B0}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{F764626F-FE19-48B0-AE6B-5D23E70CDC0B}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{F9B540F3-7103-4705-BF29-F792F46B76EB}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{04C8D81F-364B-4F0E-9AB4-D5C596957D65}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{0BC130E4-FC52-4E93-A437-A516B8D5C032}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{F207602C-4686-436F-90C0-C6ACBEAA23FC}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{4C7E9D4F-A9DB-42BB-BA6B-0834388A2F26}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{51DA1DD8-0D62-49FA-8248-9F7B83DBF9E5}c:\\program files\\myspace\\im\\myspaceim.exe"= UDP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"UDP Query User{1FFEF558-7446-4574-9A23-0D6D955B2A17}c:\\program files\\myspace\\im\\myspaceim.exe"= TCP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"{51DD7F4A-625D-49A2-957B-6A2D60764ED7}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{8AD3BF2E-F6E7-4520-970B-EFC484E5EB19}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{FDB21A0B-5F66-4A1B-849B-DA440E06C76E}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{A27FD36B-6BA4-4F01-8F19-3B22D048A1EB}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{AAEBEA67-932B-47E5-9107-A9DA4D9E720C}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{68DBB0A3-6494-4E0C-BB3B-44FE07BCD7D2}"= UDP:61435:eMule_TCP
"{C2A2B87E-AFD8-47E5-AB81-3F813521442F}"= TCP:61445:eMule_UDP
"TCP Query User{A3FF2B80-9805-4AE2-A69A-A5320FA4C100}c:\\program files\\emule\\emule.exe"= Disabled:UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{6B8037EE-8B2D-4333-9FB1-A1B02D94DF64}c:\\program files\\emule\\emule.exe"= Disabled:TCP:c:\program files\emule\emule.exe:eMule
"{AF21EA50-2C00-45AF-A82B-641DFA0917FC}"= TCP:16355:Kad
"{D6FC92BA-02C5-4986-A214-7716D3F54FAB}"= UDP:c:\users\Aoife\Downloading\Cabal\CABAL Online (Europe)\cabal.exe:Cabal
"{F4FA84F1-9F51-4669-A36E-19A04CF150B5}"= TCP:c:\users\Aoife\Downloading\Cabal\CABAL Online (Europe)\cabal.exe:Cabal
"TCP Query User{B7638CA1-6A55-4BF6-A35D-DF96256F1CE0}c:\\users\\aoife\\downloading\\rohan\\rohanclient.exe"= UDP:c:\users\aoife\downloading\rohan\rohanclient.exe:rohanclient.exe
"UDP Query User{855FC9D0-983C-4B2F-83E8-F428D77DEFFB}c:\\users\\aoife\\downloading\\rohan\\rohanclient.exe"= TCP:c:\users\aoife\downloading\rohan\rohanclient.exe:rohanclient.exe
"{3032606E-1EA9-46BA-AEEE-565B94C98639}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{5E8A2504-C6EA-44E8-9FD3-FF7FFC9CDE0A}"= UDP:5353:Adobe CSI CS4
"{EB2DD85A-FCFE-4891-9064-275A9A4D202C}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{88884C2F-D654-4A49-B616-D05CE0CF1F2A}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{AE286A47-58C1-4A8B-935E-4D666778A3FB}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{6C725920-9001-4760-A88A-5AE8E0BD485A}c:\\users\\aoife\\games\\nuova cartella\\up.exe"= UDP:c:\users\aoife\games\nuova cartella\up.exe:up.exe
"UDP Query User{AB506B2F-F369-4F8A-9CAD-9CE9EEB0556E}c:\\users\\aoife\\games\\nuova cartella\\up.exe"= TCP:c:\users\aoife\games\nuova cartella\up.exe:up.exe
"TCP Query User{5F6BED0D-FBB5-49EC-9152-8B0F372F2759}c:\\users\\aoife\\downloads\\pdo_downloader_7324.exe"= UDP:c:\users\aoife\downloads\pdo_downloader_7324.exe:pdo_downloader_7324.exe
"UDP Query User{6369A684-16B6-4978-A1FF-DDF4A3F50F11}c:\\users\\aoife\\downloads\\pdo_downloader_7324.exe"= TCP:c:\users\aoife\downloads\pdo_downloader_7324.exe:pdo_downloader_7324.exe
"{F35258A0-89FE-4906-A67A-51BAE6F63059}"= UDP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{01D4676F-587A-41FA-8896-9C33EFC552DB}"= TCP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{4336C885-4AF2-4B6E-9E5E-C0A84C895072}"= UDP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{60C3D2C6-40D3-432C-8D6C-AFA97DDB2F69}"= TCP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{18E44CE4-3E83-4381-979F-CA485FE1CBA3}"= c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"TCP Query User{78E8A1C3-3E66-485D-8F76-29AF5E635F65}c:\\users\\aoife\\games\\d&d\\dndclient.exe"= UDP:c:\users\aoife\games\d&d\dndclient.exe:dndclient
"UDP Query User{31DBF085-B4AE-4E4C-8659-91D01F80D2A6}c:\\users\\aoife\\games\\d&d\\dndclient.exe"= TCP:c:\users\aoife\games\d&d\dndclient.exe:dndclient
"{C31697DC-B240-4FD0-A0EC-12944557CA57}"= UDP:c:\users\Aoife\Games\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{C21B1370-743B-45FC-933D-C1AAD33EF884}"= TCP:c:\users\Aoife\Games\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{4C492529-412B-4CCD-9F08-B6A89709D126}"= UDP:c:\users\Aoife\Games\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"{5FA9368F-F7E8-4AAD-A178-300CA221F38E}"= TCP:c:\users\Aoife\Games\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [17/06/2008 16:43 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [17/06/2008 16:43 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [17/06/2008 16:43 53328]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [30/07/2009 09:29 1153368]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [05/05/2009 10:36 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
S3 PSI;PSI;c:\windows\System32\drivers\psi_mf.sys [19/02/2008 10:24 7808]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'

2009-09-11 c:\windows\Tasks\HPCeeScheduleForAoife.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-02-24 10:58]

2009-09-19 c:\windows\Tasks\User_Feed_Synchronization-{239A0911-01DA-42BF-B6B5-A88188D885B8}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.facebook.com/home.php?ref=home
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &AOL Toolbar Cerca - c:\program files\aol\aol toolbar 5.0\resources\it-it\local\search.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} - hxxp://l.yimg.com/jh/games/web_games/playtime/mahjongescape/PTGameLauncher.cab
FF - ProfilePath - c:\users\Aoife\AppData\Roaming\Mozilla\Firefox\Profiles\y5ahmmus.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=home|http://www.thebreastcancersite.com/clickToGive/home.faces?siteId=2
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

AddRemove-15b35190-c6f9-11d9-9669-0800200c9a66_is1 - c:\users\Aoife\Games\D&D\Uninstall.exe
AddRemove-62289540-dc30-11dc-95ff-0800200c9a66_is1 - c:\users\Aoife\Games\Turbine Download Manager\UninstallTDM.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-20 16:21
Windows 6.0.6000  NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\S-1-5-21-3824510552-3789898071-2641794859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*X*v*i*D*-*K*n*ã*"!\OpenWithList]
@Class="Shell"

[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'Explorer.exe'(3236)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Ora fine scansione: 2009-09-20 16:24
ComboFix-quarantined-files.txt  2009-09-20 14:24
ComboFix2.txt  2009-09-19 14:20

Pre-Run: 28,955,365,376 byte disponibili
Post-Run: 28,320,374,784 byte disponibili

287   --- E O F ---   2009-09-18 20:35

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #9 on: September 20, 2009, 09:55:37 PM »
Hi, Aoife.

We'll take a look at any Sunbelt leftovers later.  First, please provide a copy of the first run of ComboFix:  ComboFix2.txt

Thank you.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Aoife

  • Newbie
  • *
  • Posts: 7
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #10 on: September 20, 2009, 10:02:36 PM »
Here you go this one must be from before I uninstalled Sunbelt (after getting a msg from Combo that it was still running even though I'd exited it). Once it's all ok I'd like to reinstall it as I'm quite happy with how it blocks stuff :)

ComboFix 09-09-18.02 - Aoife 19/09/2009 16:10.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6000.0.1252.39.1040.18.3070.1926 [GMT 2:00]
Eseguito da: c:\users\Aoife\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090918-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1351 [VPS 090918-0] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Sunbelt Software Sunbelt CounterSpy 2.5.1043 *enabled* (Outdated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((   Files Creati Da 2009-08-19 al 2009-09-19  )))))))))))))))))))))))))))))))))))
.

2009-09-19 14:17 . 2009-09-19 14:17   --------   d-----w-   c:\users\Public\AppData\Local\temp
2009-09-19 14:17 . 2009-09-19 14:17   --------   d-----w-   c:\users\Default\AppData\Local\temp
2009-09-19 14:17 . 2009-09-19 14:17   --------   d-----w-   c:\users\AoifeTemp\AppData\Local\temp
2009-09-19 10:38 . 2009-09-19 10:38   --------   d-----w-   c:\users\Aoife\AppData\Roaming\Malwarebytes
2009-09-19 10:38 . 2009-09-10 12:54   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-19 10:38 . 2009-09-19 10:38   --------   d-----w-   c:\programdata\Malwarebytes
2009-09-19 10:38 . 2009-09-10 12:53   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-09-19 10:38 . 2009-09-19 10:38   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-09-19 10:07 . 2009-09-19 10:07   --------   d-----w-   c:\program files\Java
2009-09-18 18:37 . 2009-09-18 18:39   --------   d-----w-   C:\rsit
2009-09-17 11:56 . 2009-09-17 11:56   --------   d-----w-   c:\users\Aoife\AppData\Local\Turbine
2009-09-17 10:03 . 2009-09-17 10:03   --------   d-----w-   c:\users\Aoife\AppData\Local\Turbine,_Inc
2009-09-17 10:00 . 2009-09-17 21:34   --------   d-----w-   c:\users\Aoife\AppData\Local\PMB Files
2009-09-17 10:00 . 2009-09-17 10:00   --------   d-----w-   c:\programdata\PMB Files
2009-09-17 10:00 . 2009-09-17 10:00   --------   d-----w-   c:\program files\Pando Networks
2009-09-17 09:59 . 2009-09-17 09:59   --------   d-----w-   c:\programdata\Turbine
2009-09-17 09:57 . 2009-09-17 09:57   93   ----a-w-   c:\users\Aoife\AppData\Local\fusioncache.dat
2009-09-17 09:47 . 2009-09-17 09:47   --------   d-----w-   c:\windows\system32\URTTEMP
2009-09-09 16:54 . 2009-09-09 16:54   --------   d-----w-   c:\users\Aoife\AppData\Roaming\BitCometLite
2009-09-09 08:42 . 2009-06-10 12:07   2855424   ----a-w-   c:\windows\system32\mf.dll
2009-09-09 08:42 . 2009-06-10 12:07   98816   ----a-w-   c:\windows\system32\mfps.dll
2009-09-09 08:42 . 2009-06-10 10:15   24576   ----a-w-   c:\windows\system32\mfpmp.exe
2009-09-09 08:42 . 2009-06-10 10:14   52736   ----a-w-   c:\windows\system32\rrinstaller.exe
2009-09-09 08:42 . 2009-06-10 08:50   2048   ----a-w-   c:\windows\system32\mferror.dll
2009-09-09 08:40 . 2009-07-11 19:24   289280   ----a-w-   c:\windows\system32\wlanmsm.dll
2009-09-09 08:40 . 2009-07-11 19:24   299520   ----a-w-   c:\windows\system32\wlansec.dll
2009-09-09 08:40 . 2009-07-11 19:26   123904   ----a-w-   c:\windows\system32\L2SecHC.dll
2009-09-09 08:40 . 2009-07-11 19:24   502784   ----a-w-   c:\windows\system32\wlansvc.dll
2009-09-09 08:40 . 2009-07-11 19:24   67584   ----a-w-   c:\windows\system32\wlanhlp.dll
2009-09-09 08:40 . 2009-07-11 19:24   47104   ----a-w-   c:\windows\system32\wlanapi.dll
2009-09-03 17:21 . 2009-09-03 17:21   --------   d-----w-   c:\windows\CountryWars
2009-09-02 22:49 . 2009-08-29 03:41   1686528   ----a-w-   c:\windows\system32\gameux.dll
2009-09-02 22:49 . 2009-08-29 03:40   28672   ----a-w-   c:\windows\system32\Apphlpdm.dll
2009-09-02 22:49 . 2009-08-28 23:31   4247552   ----a-w-   c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-02 17:58 . 2009-09-17 11:33   --------   d-----w-   c:\users\Aoife\AppData\Roaming\skypePM
2009-09-02 17:56 . 2009-09-17 11:56   --------   d-----w-   c:\users\Aoife\AppData\Roaming\Skype
2009-09-02 17:55 . 2009-09-02 17:55   --------   d-----w-   c:\program files\Common Files\Skype
2009-09-02 17:55 . 2009-09-02 17:56   --------   d-----r-   c:\program files\Skype
2009-09-02 17:54 . 2009-09-02 17:55   --------   d-----w-   c:\programdata\Skype
2009-09-02 07:06 . 2009-06-22 08:44   2048   ----a-w-   c:\windows\system32\tzres.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-19 10:07 . 2008-12-18 13:47   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-09-18 19:02 . 2008-08-25 13:31   --------   d-----w-   c:\program files\Spybot - Search & Destroy
2009-09-17 15:43 . 2008-05-10 12:41   27335   ----a-w-   c:\users\Aoife\AppData\Roaming\nvModes.dat
2009-09-17 09:56 . 2008-02-25 05:49   692196   ----a-w-   c:\windows\system32\perfh010.dat
2009-09-17 09:56 . 2008-02-25 05:49   119556   ----a-w-   c:\windows\system32\perfc010.dat
2009-09-13 16:47 . 2008-05-15 17:46   --------   d-----w-   c:\users\Aoife\AppData\Roaming\uTorrent
2009-09-11 16:02 . 2008-02-24 21:57   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-09-09 21:44 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-09-09 21:44 . 2008-02-24 22:40   --------   d-----w-   c:\programdata\Microsoft Help
2009-09-03 09:26 . 2008-05-10 06:55   --------   d-----w-   c:\users\Aoife\AppData\Roaming\Hewlett-Packard
2009-09-03 08:50 . 2008-02-24 22:55   --------   d-----w-   c:\programdata\Hewlett-Packard
2009-09-02 17:58 . 2009-09-02 17:58   56   ---ha-w-   c:\programdata\ezsidmv.dat
2009-08-17 16:10 . 2008-06-17 14:43   1279456   ----a-w-   c:\windows\system32\aswBoot.exe
2009-08-17 16:05 . 2008-06-17 14:43   114768   ----a-w-   c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-06-17 14:43   20560   ----a-w-   c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:05 . 2008-06-17 14:43   53328   ----a-w-   c:\windows\system32\drivers\aswMonFlt.sys
2009-08-17 16:04 . 2008-06-17 14:43   51376   ----a-w-   c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2008-06-17 14:43   23152   ----a-w-   c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:02 . 2008-06-17 14:43   97480   ----a-w-   c:\windows\system32\AvastSS.scr
2009-08-14 17:16 . 2009-09-09 08:41   213592   ----a-w-   c:\windows\system32\drivers\netio.sys
2009-08-14 16:42 . 2009-09-09 08:41   167424   ----a-w-   c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40 . 2009-09-09 08:41   103936   ----a-w-   c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-09 08:41   15360   ----a-w-   c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-09 08:41   9728   ----a-w-   c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-09 08:41   17920   ----a-w-   c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-09 08:41   11264   ----a-w-   c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-09 08:41   27136   ----a-w-   c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-09 08:41   8704   ----a-w-   c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-09 08:41   19968   ----a-w-   c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-09 08:41   10240   ----a-w-   c:\windows\system32\finger.exe
2009-08-14 14:24 . 2009-09-09 08:41   813568   ----a-w-   c:\windows\system32\drivers\tcpip.sys
2009-08-14 14:23 . 2009-09-09 08:41   22016   ----a-w-   c:\windows\system32\netiougc.exe
2009-07-30 07:57 . 2008-08-25 13:31   --------   d-----w-   c:\programdata\Spybot - Search & Destroy
2009-07-22 13:53 . 2009-07-22 13:53   --------   d-----w-   c:\program files\Sony Online Entertainment
2009-07-21 21:52 . 2009-07-29 06:07   915456   ----a-w-   c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 06:07   109056   ----a-w-   c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 06:07   71680   ----a-w-   c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 06:07   133632   ----a-w-   c:\windows\system32\ieUnatt.exe
2009-07-21 14:46 . 2008-06-07 19:44   4868   ----a-w-   c:\users\Aoife\AppData\Roaming\wklnhst.dat
2009-07-17 14:52 . 2009-08-12 13:16   71680   ----a-w-   c:\windows\system32\atl.dll
2009-07-14 13:02 . 2009-08-12 13:16   313344   ----a-w-   c:\windows\system32\wmpdxm.dll
2009-07-14 13:01 . 2009-08-12 13:16   4096   ----a-w-   c:\windows\system32\dxmasf.dll
2009-07-14 13:00 . 2009-08-12 13:16   7680   ----a-w-   c:\windows\system32\spwmp.dll
2009-07-14 11:11 . 2009-08-12 13:16   8147968   ----a-w-   c:\windows\system32\wmploc.DLL
2009-06-26 11:26 . 2009-06-26 11:24   103936   ----a-w-   c:\users\AoifeTemp\AppData\Local\GDIPFONTCACHEV1.DAT
2008-02-25 06:29 . 2008-02-25 06:15   8192   --sha-w-   c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((   SnapShot@2009-09-19_13.38.10   )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-02-24 21:53 . 2009-09-19 13:51   54050              c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-19 13:51   66242              c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-05-11 07:36 . 2009-09-19 13:05   11236              c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3824510552-3789898071-2641794859-1000_UserData.bin
+ 2008-05-11 07:36 . 2009-09-19 13:51   11236              c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3824510552-3789898071-2641794859-1000_UserData.bin
+ 2008-05-10 06:41 . 2009-09-19 14:14   16384              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-05-10 06:41 . 2009-09-19 13:22   16384              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-05-10 06:41 . 2009-09-19 13:22   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-10 06:41 . 2009-09-19 14:14   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-10 06:41 . 2009-09-19 13:22   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-10 06:41 . 2009-09-19 14:14   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-10 18:01 . 2009-09-19 13:48   35080              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-09-19 13:49 . 2009-09-19 13:49   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-19 13:03 . 2009-09-19 13:03   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-19 13:03 . 2009-09-19 13:03   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-19 13:49 . 2009-09-19 13:49   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-05-13 15:55 . 2009-09-19 13:09   245760              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-05-13 15:55 . 2009-09-19 13:54   245760              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
(((((((((((((((((((((((((((((((((((((   Punti Reg Caricati   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-05-12 1232896]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 1783136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-05-17 171448]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-02-25 1006264]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-19 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

c:\users\Aoife\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2008-11-22 575488]
Secunia PSI (RC1).lnk - c:\program files\Secunia\PSI (RC1)\psi.exe [2008-2-22 626688]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BC785C10-4D6C-4BF5-91D7-1430CD5995A7}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{61DCC48D-D635-4825-B4EB-B257BA961349}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2961FD73-7DF0-4329-9CB5-92E9BAC863B0}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{F764626F-FE19-48B0-AE6B-5D23E70CDC0B}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{F9B540F3-7103-4705-BF29-F792F46B76EB}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{04C8D81F-364B-4F0E-9AB4-D5C596957D65}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{0BC130E4-FC52-4E93-A437-A516B8D5C032}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{F207602C-4686-436F-90C0-C6ACBEAA23FC}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{4C7E9D4F-A9DB-42BB-BA6B-0834388A2F26}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{51DA1DD8-0D62-49FA-8248-9F7B83DBF9E5}c:\\program files\\myspace\\im\\myspaceim.exe"= UDP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"UDP Query User{1FFEF558-7446-4574-9A23-0D6D955B2A17}c:\\program files\\myspace\\im\\myspaceim.exe"= TCP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"{51DD7F4A-625D-49A2-957B-6A2D60764ED7}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{8AD3BF2E-F6E7-4520-970B-EFC484E5EB19}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{FDB21A0B-5F66-4A1B-849B-DA440E06C76E}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{A27FD36B-6BA4-4F01-8F19-3B22D048A1EB}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{AAEBEA67-932B-47E5-9107-A9DA4D9E720C}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{68DBB0A3-6494-4E0C-BB3B-44FE07BCD7D2}"= UDP:61435:eMule_TCP
"{C2A2B87E-AFD8-47E5-AB81-3F813521442F}"= TCP:61445:eMule_UDP
"TCP Query User{A3FF2B80-9805-4AE2-A69A-A5320FA4C100}c:\\program files\\emule\\emule.exe"= Disabled:UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{6B8037EE-8B2D-4333-9FB1-A1B02D94DF64}c:\\program files\\emule\\emule.exe"= Disabled:TCP:c:\program files\emule\emule.exe:eMule
"{AF21EA50-2C00-45AF-A82B-641DFA0917FC}"= TCP:16355:Kad
"{D6FC92BA-02C5-4986-A214-7716D3F54FAB}"= UDP:c:\users\Aoife\Downloading\Cabal\CABAL Online (Europe)\cabal.exe:Cabal
"{F4FA84F1-9F51-4669-A36E-19A04CF150B5}"= TCP:c:\users\Aoife\Downloading\Cabal\CABAL Online (Europe)\cabal.exe:Cabal
"TCP Query User{B7638CA1-6A55-4BF6-A35D-DF96256F1CE0}c:\\users\\aoife\\downloading\\rohan\\rohanclient.exe"= UDP:c:\users\aoife\downloading\rohan\rohanclient.exe:rohanclient.exe
"UDP Query User{855FC9D0-983C-4B2F-83E8-F428D77DEFFB}c:\\users\\aoife\\downloading\\rohan\\rohanclient.exe"= TCP:c:\users\aoife\downloading\rohan\rohanclient.exe:rohanclient.exe
"{3032606E-1EA9-46BA-AEEE-565B94C98639}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{5E8A2504-C6EA-44E8-9FD3-FF7FFC9CDE0A}"= UDP:5353:Adobe CSI CS4
"{EB2DD85A-FCFE-4891-9064-275A9A4D202C}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{88884C2F-D654-4A49-B616-D05CE0CF1F2A}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{AE286A47-58C1-4A8B-935E-4D666778A3FB}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{6C725920-9001-4760-A88A-5AE8E0BD485A}c:\\users\\aoife\\games\\nuova cartella\\up.exe"= UDP:c:\users\aoife\games\nuova cartella\up.exe:up.exe
"UDP Query User{AB506B2F-F369-4F8A-9CAD-9CE9EEB0556E}c:\\users\\aoife\\games\\nuova cartella\\up.exe"= TCP:c:\users\aoife\games\nuova cartella\up.exe:up.exe
"TCP Query User{5F6BED0D-FBB5-49EC-9152-8B0F372F2759}c:\\users\\aoife\\downloads\\pdo_downloader_7324.exe"= UDP:c:\users\aoife\downloads\pdo_downloader_7324.exe:pdo_downloader_7324.exe
"UDP Query User{6369A684-16B6-4978-A1FF-DDF4A3F50F11}c:\\users\\aoife\\downloads\\pdo_downloader_7324.exe"= TCP:c:\users\aoife\downloads\pdo_downloader_7324.exe:pdo_downloader_7324.exe
"{F35258A0-89FE-4906-A67A-51BAE6F63059}"= UDP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{01D4676F-587A-41FA-8896-9C33EFC552DB}"= TCP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{4336C885-4AF2-4B6E-9E5E-C0A84C895072}"= UDP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{60C3D2C6-40D3-432C-8D6C-AFA97DDB2F69}"= TCP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{18E44CE4-3E83-4381-979F-CA485FE1CBA3}"= c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"TCP Query User{78E8A1C3-3E66-485D-8F76-29AF5E635F65}c:\\users\\aoife\\games\\d&d\\dndclient.exe"= UDP:c:\users\aoife\games\d&d\dndclient.exe:dndclient
"UDP Query User{31DBF085-B4AE-4E4C-8659-91D01F80D2A6}c:\\users\\aoife\\games\\d&d\\dndclient.exe"= TCP:c:\users\aoife\games\d&d\dndclient.exe:dndclient
"{C31697DC-B240-4FD0-A0EC-12944557CA57}"= UDP:c:\users\Aoife\Games\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{C21B1370-743B-45FC-933D-C1AAD33EF884}"= TCP:c:\users\Aoife\Games\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{4C492529-412B-4CCD-9F08-B6A89709D126}"= UDP:c:\users\Aoife\Games\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"{5FA9368F-F7E8-4AAD-A178-300CA221F38E}"= TCP:c:\users\Aoife\Games\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [17/06/2008 16:43 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [17/06/2008 16:43 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [17/06/2008 16:43 53328]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [30/07/2009 09:29 1153368]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [05/05/2009 10:36 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
S3 PSI;PSI;c:\windows\System32\drivers\psi_mf.sys [19/02/2008 10:24 7808]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'

2009-09-11 c:\windows\Tasks\HPCeeScheduleForAoife.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-02-24 10:58]

2009-09-18 c:\windows\Tasks\User_Feed_Synchronization-{239A0911-01DA-42BF-B6B5-A88188D885B8}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.facebook.com/home.php?ref=home
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &AOL Toolbar Cerca - c:\program files\aol\aol toolbar 5.0\resources\it-it\local\search.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} - hxxp://l.yimg.com/jh/games/web_games/playtime/mahjongescape/PTGameLauncher.cab
FF - ProfilePath - c:\users\Aoife\AppData\Roaming\Mozilla\Firefox\Profiles\y5ahmmus.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=home|http://www.thebreastcancersite.com/clickToGive/home.faces?siteId=2
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKLM-Run-SBRegRebootCleaner - c:\program files\Sunbelt Software\CounterSpy\SBRC.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-19 16:17
Windows 6.0.6000  NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\S-1-5-21-3824510552-3789898071-2641794859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*X*v*i*D*-*K*n*ã*"!\OpenWithList]
@Class="Shell"

[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'Explorer.exe'(5512)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Ora fine scansione: 2009-09-19 16:20
ComboFix-quarantined-files.txt  2009-09-19 14:20

Pre-Run: 22,535,925,760 byte disponibili
Post-Run: 22,419,292,160 byte disponibili

285   --- E O F ---   2009-09-18 20:35

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: My pc has gone very slow - just want to be sure there's nothing strange!
« Reply #11 on: September 20, 2009, 11:12:40 PM »
Hi, Aoife.  Thank you. 

1.  The Sunbelt Counterspy remnant was removed and shouldn't show up after the computer is restarted.

2.  It appears that at some time you replaced Norton/Symantec with Avast.  Since the Norton software included a firewall, please go to Control Panel\Security and activate the Windows Vista firewall or download and install one of the following firewall programs which are free for personal use.

Online Armor Free
Agnitum Outpost Firewall

3.  A strong word of caution:  P2P programs form a direct conduit on to your computer. They have always been a target of malware writers and are increasingly so of late. P2P security measures are easily circumvented and if your P2P program is not configured correctly, you may be sharing more files than you realize. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program. Use of P2P programs can result in Identity Theft.  A more recent article:  P2P Dangers Have Not Gone Away

There are remnants of BitComet not removed during an apparent uninstall process that we'll take care of.  However, you have two other P2P programs installed, which I encourage you to uninstall: 

µTorrent-->"C:\Program Files\uTorrent\uninstall.exe"
eMule-->"C:\Program Files\eMule\Uninstall.exe"


4.  You have an outdated/vulnerable version of Adobe Reader installed.  Please do the following:

a.  Go to add/remove programs and uninstall Adobe Reader
b.  Install the latest version of Adobe Reader from http://www.adobe.com/products/reader/
or
c.  Switch to an alternate PDF reader.  There are a number of open source readers available from http://pdfreaders.org/.

5.  Custom CFScript

Note: The following instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


  • Please open Notepad (Click Start -> Run -> type notepad in the Open field -> OK).  Copy/Paste all of the text present inside the code box below:
Code: [Select]
File::
c:\users\Aoife\AppData\Roaming\BitCometLite

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
  • Save this as CFScript.txt and place it on your desktop.
  • Close any open browsers.
  • Close/disable all antivirus and anti-malware programs so they do not interfere with the running of ComboFix.




  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.  Do not run ComboFix a second time.



CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.