0

My PC's been slow lately and a lot of programs wont stat, Insufficient system memory and some just wont run and ect help...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:08:16 PM, on 1/18/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:\WINDOWZ\System32\smss.exe
C:\WINDOWZ\system32\csrss.exe
C:\WINDOWZ\system32\winlogon.exe
C:\WINDOWZ\system32\services.exe
C:\WINDOWZ\system32\lsass.exe
C:\WINDOWZ\system32\nvsvc32.exe
C:\WINDOWZ\system32\svchost.exe
C:\WINDOWZ\system32\svchost.exe
C:\WINDOWZ\System32\svchost.exe
C:\WINDOWZ\system32\svchost.exe
C:\WINDOWZ\system32\svchost.exe
C:\WINDOWZ\system32\spoolsv.exe
C:\WINDOWZ\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\WINDOWZ\system32\dlcccoms.exe
C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\WINDOWZ\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWZ\system32\PnkBstrA.exe
C:\WINDOWZ\system32\PnkBstrB.exe
C:\PROGRA~1\DrWeb\spidernt.exe
C:\WINDOWZ\system32\svchost.exe
C:\WINDOWZ\Explorer.EXE
C:\WINDOWZ\system32\SearchIndexer.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWZ\System32\alg.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\Program Files\DrWeb\SpIDerAgent.exe
C:\Program Files\DrWeb\spiderml.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe
C:\WINDOWZ\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\D-Link\D-Link RangeBooster N DWA-142\wirelesscm.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Glary Utilities\Integrator.exe
C:\WINDOWZ\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWZ\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWZ\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://dealhrfind.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dealhrfind.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://dealhrfind.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWZ\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [BackgroundSwitcher] "C:\Program Files\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWZ\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link RangeBooster N DWA-142\wirelesscm.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWZ\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWZ\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} (Diagnostics ActiveX WebControl) - http://support.microsoft.com/mats/DiagWebControl.cab
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWZ\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWZ\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - D:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: dlcc_device - - C:\WINDOWZ\system32\dlcccoms.exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWZ\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWZ\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWZ\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWZ\system32\PnkBstrB.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 7982 bytes


And here is the malware bytes log


Malwarebytes' Anti-Malware 1.44
Database version: 3594
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

1/18/2010 6:49:30 PM
mbam-log-2010-01-18 (18-49-30).txt

Scan type: Quick Scan
Objects scanned: 177025
Time elapsed: 7 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Temp\Cfvh.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Temporary Internet Files\Content.IE5\QZN5MC04\z002103318801r0409J10000601R0143fdeeX02a9705eY49fa994fZ04f020530[1] (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWZ\system32\spool\prtprocs\w32x86\71.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.

Help!

2
Contributors
3
Replies
4
Views
7 Years
Discussion Span
Last Post by jellyman223
0

I've noticed that every time I restart my computer the viruses come back

0

Please do the following:
Please download ComboFix by sUBs from HERE or HERE

* You must download it to and run it from your Desktop
* Physically disconnect from the internet.
* Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
* Double click combofix.exe & follow the prompts.
* When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
* Re-enable all the programs that were disabled during the running of ComboFix..


Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Run Combofix ONCE only!!

0

ComboFix 10-01-19.01 - DeShawn Luu 01/19/2010 19:40:49.1.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1646 [GMT -5:00]
Running from: c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\My Documents\Downloads\ComboFix.exe
AV: Doctor Web Anti-Virus *On-access scanning enabled* (Updated) {3454C8F1-ECBC-4180-A6F4-04632FBA762B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\DESHAW~1.DES\LOCALS~1\Temp\swtlib-32\swt-gdip-win32-3550.dll
c:\docume~1\DESHAW~1.DES\LOCALS~1\Temp\swtlib-32\swt-win32-3550.dll
c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Desktopicon
c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Temp\swtlib-32\swt-gdip-win32-3550.dll
c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Temp\swtlib-32\swt-win32-3550.dll
c:\recycler\S-1-5-21-1123561945-1677128483-1417001333-500
c:\recycler\S-1-5-21-3710195049-1329442639-3207129273-1005
c:\recycler\S-1-5-21-3710195049-1329442639-3207129273-500
C:\System
c:\windowz\system32\plugin.dat

.
((((((((((((((((((((((((( Files Created from 2009-12-20 to 2010-01-20 )))))))))))))))))))))))))))))))
.

2010-01-19 20:05 . 2010-01-19 20:05 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Electronic Arts
2010-01-19 00:02 . 2010-01-19 00:05 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Norton
2010-01-19 00:02 . 2010-01-19 00:02 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Symantec
2010-01-19 00:02 . 2010-01-19 00:02 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\NortonInstaller
2010-01-18 20:34 . 2010-01-18 20:34 12862 ----a-r- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Microsoft\Installer\{0E2B767B-EA6A-489B-BF83-8083FE1DB661}\_1EEFFF72773535163E4216.exe
2010-01-18 04:49 . 2010-01-18 05:02 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\DoctorWeb
2010-01-18 04:49 . 2010-01-18 04:49 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Doctor Web
2010-01-18 04:21 . 2007-09-27 05:58 461952 ----a-w- c:\windowz\system32\drivers\MRVW245.sys
2010-01-17 18:18 . 2010-01-17 18:18 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\NeopleLauncherDFO
2010-01-16 23:41 . 2010-01-16 23:42 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Braid
2010-01-15 10:31 . 2010-01-20 00:34 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\GlarySoft
2010-01-15 05:45 . 2010-01-16 07:24 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Software Informer
2010-01-15 05:45 . 2010-01-15 05:45 -------- d-----w- c:\program files\Software Informer
2010-01-15 05:45 . 2010-01-15 05:45 -------- d-----w- c:\program files\Glary Utilities
2010-01-13 00:12 . 2009-11-21 15:51 471552 -c----w- c:\windowz\system32\dllcache\aclayers.dll
2010-01-12 20:46 . 2010-01-12 20:46 -------- d-----w- c:\windowz\vbSkinner
2010-01-12 20:45 . 2010-01-12 20:47 -------- d-----w- c:\program files\PFConfig
2010-01-11 00:44 . 2010-01-11 00:44 -------- d-----w- c:\windowz\A7E07C2B2220441587E3784D5814BC93.TMP
2010-01-10 16:31 . 2010-01-10 16:31 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\TortoiseSVN
2010-01-10 08:53 . 2010-01-10 08:53 -------- d-----w- c:\program files\TinkleBell
2010-01-10 07:29 . 2010-01-20 00:29 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\TSVNCache
2010-01-10 07:11 . 2010-01-10 07:11 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Subversion
2010-01-10 07:10 . 2010-01-10 07:10 -------- d-----w- c:\program files\Common Files\TortoiseOverlays
2010-01-10 07:10 . 2010-01-10 07:10 -------- d-----w- c:\program files\TortoiseSVN
2010-01-10 02:02 . 2010-01-10 02:03 -------- d-----w- c:\windowz\system32\NtmsData
2010-01-09 17:57 . 2010-01-09 17:57 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Threat Expert
2010-01-09 17:50 . 2009-12-02 13:19 64288 ----a-w- c:\windowz\system32\drivers\Lbd.sys
2010-01-09 17:47 . 2009-12-07 14:10 2953352 -c--a-w- c:\documents and settings\All Users.WINDOWZ\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
2010-01-09 17:46 . 2010-01-19 04:21 -------- dc-h--w- c:\documents and settings\All Users.WINDOWZ\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-09 17:43 . 2010-01-09 17:43 -------- d-----w- c:\program files\Lavasoft
2010-01-09 17:43 . 2010-01-19 04:20 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Lavasoft
2010-01-09 17:39 . 2010-01-09 17:39 54016 ----a-w- c:\windowz\system32\drivers\vvglki.sys
2010-01-06 20:53 . 2010-01-06 20:53 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Ubisoft
2010-01-06 20:53 . 2010-01-06 20:53 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Ubisoft
2010-01-04 02:54 . 2008-04-13 18:47 25856 -c--a-w- c:\windowz\system32\dllcache\usbprint.sys
2010-01-04 02:54 . 2008-04-13 18:47 25856 ----a-w- c:\windowz\system32\drivers\usbprint.sys
2010-01-04 02:52 . 2001-08-18 03:36 87040 -c--a-w- c:\windowz\system32\dllcache\wiafbdrv.dll
2010-01-04 02:52 . 2001-08-18 03:36 87040 ----a-w- c:\windowz\system32\wiafbdrv.dll
2010-01-04 02:51 . 2010-01-04 03:10 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Deployment
2010-01-04 01:41 . 2010-01-04 02:14 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Rosetta Stone
2010-01-04 01:41 . 2010-01-04 01:41 -------- d-----w- c:\program files\Rosetta Stone
2009-12-31 21:26 . 2010-01-01 01:29 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\yjhpgo
2009-12-31 21:24 . 2009-11-21 02:34 69632 ----a-w- c:\windowz\system32\OpenCL.dll
2009-12-31 21:24 . 2009-11-21 02:34 11374592 ----a-w- c:\windowz\system32\nvcompiler.dll
2009-12-31 19:35 . 2009-12-31 19:35 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Logitech
2009-12-31 19:35 . 2009-12-31 19:35 10134 ----a-r- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
2009-12-31 19:35 . 2007-01-23 20:45 34576 ----a-w- c:\windowz\system32\drivers\LHidFilt.Sys
2009-12-31 19:35 . 2007-01-23 20:45 33296 ----a-w- c:\windowz\system32\drivers\LMouFilt.Sys
2009-12-31 19:35 . 2007-01-23 20:45 1419024 ----a-w- c:\windowz\system32\WdfCoInstaller01005.dll
2009-12-31 19:35 . 2007-01-23 20:44 101136 ----a-w- c:\windowz\KHALMNPR.Exe
2009-12-31 19:34 . 2007-01-30 06:46 69632 ----a-w- c:\windowz\system32\KemXML.dll
2009-12-31 19:34 . 2007-01-30 06:46 163840 ----a-w- c:\windowz\system32\kemutb.dll
2009-12-31 19:34 . 2007-01-30 06:46 110592 ----a-w- c:\windowz\system32\KemWnd.dll
2009-12-31 19:34 . 2007-01-30 06:46 135168 ----a-w- c:\windowz\system32\KemUtil.dll
2009-12-31 19:34 . 2009-12-31 19:34 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Logitech
2009-12-31 19:34 . 2009-12-31 19:34 -------- d-----w- c:\program files\Logitech
2009-12-31 19:34 . 2009-12-31 19:34 10134 ----a-r- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Microsoft\Installer\{C89C8D86-4423-4A58-AA40-DD259ACE07C1}\ARPPRODUCTICON.exe
2009-12-31 19:34 . 2009-12-31 19:34 -------- d-----w- c:\program files\Common Files\Logitech
2009-12-29 19:20 . 2009-12-29 19:20 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Midway
2009-12-24 23:38 . 2009-12-21 03:32 394600 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\cd-rip@songbirdnest.com\lib\gwrks32.dll
2009-12-24 23:38 . 2009-12-21 03:32 3573096 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\cd-rip@songbirdnest.com\lib\gearaw32.dll
2009-12-24 23:38 . 2009-12-21 03:32 238952 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\cd-rip@songbirdnest.com\lib\gwlangen.dll
2009-12-24 23:38 . 2009-12-21 03:32 13312 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\cd-rip@songbirdnest.com\components\sbGearworksStub.dll
2009-12-24 23:38 . 2009-12-21 03:32 65536 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\cd-rip@songbirdnest.com\lib\sbGearworksCD.dll
2009-12-24 23:38 . 2009-12-21 03:31 561152 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\msc@songbirdnest.com\components\sbMSCDevice.dll
2009-12-24 23:38 . 2009-12-21 03:30 13312 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\gracenote@songbirdnest.com\components\sbGracenoteStub.dll
2009-12-24 23:38 . 2009-12-21 03:30 81408 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\gracenote@songbirdnest.com\lib\gnsdk_musicid_cd.dll
2009-12-24 23:38 . 2009-12-21 03:30 77824 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\gracenote@songbirdnest.com\lib\sbGracenote.dll
2009-12-24 23:38 . 2009-12-21 03:30 571904 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\gracenote@songbirdnest.com\lib\gnsdk_sdkmanager.dll
2009-12-24 23:38 . 2009-12-21 03:30 154624 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\gracenote@songbirdnest.com\lib\gnsdk_search.dll
2009-12-24 23:38 . 2009-12-21 03:30 114688 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\gracenote@songbirdnest.com\lib\gnsdk_link.dll
2009-12-24 23:37 . 2009-12-21 03:30 106496 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\quicktime@songbirdnest.com\platform\WINNT_x86-msvc\components\sbQuickTimeMediacore.dll
2009-12-24 23:37 . 2009-12-21 03:30 274432 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\windowsmedia@songbirdnest.com\platform\WINNT_x86-msvc\components\sbWindowsMediacore.dll
2009-12-24 23:37 . 2009-12-21 03:32 724992 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\mtp@songbirdnest.com\components\sbMTPWin32.dll
2009-12-24 23:37 . 2009-10-24 08:10 892928 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\ipod@songbirdnest.com\libraries\iconv.dll
2009-12-24 23:37 . 2009-10-24 08:10 45056 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\ipod@songbirdnest.com\libraries\intl.dll
2009-12-24 23:37 . 2009-10-24 08:10 438272 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\ipod@songbirdnest.com\libraries\sbIPDDevice.dll
2009-12-24 23:37 . 2009-10-24 08:10 417792 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\ipod@songbirdnest.com\libraries\libgpod.dll
2009-12-24 23:37 . 2009-10-24 08:10 292108 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\ipod@songbirdnest.com\libraries\libgobject-2.0-0.dll
2009-12-24 23:37 . 2009-10-24 08:10 1004081 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\ipod@songbirdnest.com\libraries\libglib-2.0-0.dll
2009-12-24 23:37 . 2009-10-24 08:10 8192 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2\Profiles\na7ym8m5.default\extensions\ipod@songbirdnest.com\components\ComponentLoader.dll
2009-12-24 23:36 . 2010-01-03 05:11 -------- d-----w- c:\program files\Songbird
2009-12-24 19:56 . 2009-12-24 19:56 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\ElevatedDiagnostics
2009-12-24 19:55 . 2009-12-24 19:55 -------- d-----w- c:\program files\Microsoft ATS
2009-12-23 07:21 . 2009-12-23 07:21 -------- d-----w- c:\program files\MSXML 6.0
2009-12-22 20:16 . 1999-12-17 13:13 86016 ----a-w- c:\windowz\unvise32.exe
2009-12-22 20:14 . 2009-12-22 20:20 -------- d-----w- c:\program files\Postal2
2009-12-22 09:32 . 2009-12-21 16:11 14336 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Mozilla\Firefox\Profiles\binmxplw.default\extensions\thepiratebay@toolbar\components\toolbarhomewmp.dll
2009-12-22 07:01 . 2009-12-22 07:01 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\johnsadventures.com
2009-12-22 07:00 . 2009-12-22 07:00 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\johnsadventures.com
2009-12-22 07:00 . 2009-12-22 07:00 -------- d-----w- c:\program files\johnsadventures.com
2009-12-21 23:40 . 2009-12-22 02:30 -------- d-----w- c:\program files\Microsoft Works
2009-12-21 23:39 . 2009-12-21 23:39 -------- d-----w- c:\program files\Microsoft.NET
2009-12-21 23:38 . 2009-12-21 23:38 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Microsoft Help
2009-12-21 23:38 . 2009-12-22 19:25 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Microsoft Help
2009-12-21 11:40 . 2001-08-23 11:00 838144 -c--a-w- c:\windowz\system32\dllcache\chtbrkr.dll
2009-12-21 02:51 . 2009-12-21 02:51 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\CAPCOM

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-19 20:13 . 2009-02-21 15:49 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\uTorrent
2010-01-19 11:50 . 2009-03-27 02:26 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Azureus
2010-01-19 03:35 . 2009-02-21 06:30 -------- d---a-w- c:\documents and settings\All Users.WINDOWZ\Application Data\TEMP
2010-01-19 03:30 . 2009-10-08 19:39 -------- d-----w- c:\program files\Vuze
2010-01-19 01:52 . 2009-11-01 23:07 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\vlc
2010-01-19 00:05 . 2008-10-11 19:46 -------- d-----w- c:\program files\Norton Security Scan
2010-01-18 23:56 . 2009-02-21 06:21 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Spybot - Search & Destroy
2010-01-18 04:21 . 2007-06-30 15:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-11 00:43 . 2009-01-19 00:49 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-10 08:38 . 2009-10-11 16:35 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\dvdcss
2010-01-09 23:03 . 2009-04-28 18:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-09 23:01 . 2009-01-18 23:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 23:00 . 2009-03-28 01:59 5115824 ----a-w- c:\documents and settings\All Users.WINDOWZ\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-09 05:23 . 2008-06-08 15:45 -------- d-----w- c:\program files\SpywareBlaster
2010-01-07 21:07 . 2009-02-21 04:48 38224 ----a-w- c:\windowz\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-02-21 04:48 19160 ----a-w- c:\windowz\system32\drivers\mbam.sys
2010-01-03 20:04 . 2009-03-01 23:20 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Songbird2
2009-12-31 21:26 . 2009-10-08 01:32 -------- d-----w- c:\program files\NVIDIA Corporation
2009-12-31 21:14 . 2009-02-23 10:41 633648 ----a-w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-31 19:35 . 2009-12-31 19:35 0 ---ha-w- c:\windowz\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-12-26 20:20 . 2009-03-02 22:11 138384 ----a-w- c:\windowz\system32\drivers\PnkBstrK.sys
2009-12-26 20:20 . 2009-03-02 22:11 215128 ----a-w- c:\windowz\system32\PnkBstrB.exe
2009-12-23 11:03 . 2009-02-21 15:47 15664 ----a-w- c:\windowz\system32\drivers\GEARAspiWDM.sys
2009-12-23 11:03 . 2009-02-21 15:47 109360 ----a-w- c:\windowz\system32\GEARAspi.dll
2009-12-22 06:41 . 2009-02-21 02:28 50024 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-21 23:26 . 2009-02-24 00:21 1 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-21 08:08 . 2009-03-28 20:55 444952 ----a-w- c:\windowz\system32\wrap_oal.dll
2009-12-21 08:08 . 2009-03-28 20:55 109080 ----a-w- c:\windowz\system32\OpenAL32.dll
2009-12-21 01:42 . 2009-09-30 19:23 107888 ----a-w- c:\windowz\system32\CmdLineExt.dll
2009-12-20 22:04 . 2009-12-20 22:04 1409 ----a-w- c:\windowz\Fonts\BIRDO___.FOT
2009-12-20 22:04 . 2009-12-20 22:04 1409 ----a-w- c:\windowz\Fonts\BIRDMAN_.FOT
2009-12-20 22:04 . 2009-12-20 22:04 1409 ----a-w- c:\windowz\Fonts\BIRDL___.FOT
2009-12-20 22:04 . 2009-12-20 22:04 1409 ----a-w- c:\windowz\Fonts\BIRDB___.FOT
2009-12-14 22:51 . 2008-08-25 18:49 -------- d-----w- c:\program files\Yahoo!
2009-12-12 22:08 . 2009-12-12 22:06 69 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\jagex_runescape_preferences2.dat
2009-12-12 22:07 . 2009-12-12 22:05 39 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\jagex_runescape_preferences.dat
2009-12-10 00:00 . 2009-12-10 00:00 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Divinity 2
2009-12-09 22:52 . 2009-12-09 22:52 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\InstallShield
2009-12-04 04:07 . 2009-10-11 05:24 -------- d-----w- c:\program files\Stardock
2009-12-01 20:42 . 2009-12-03 03:34 51200 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Mozilla\Firefox\Profiles\binmxplw.default\extensions\fotofox@mozilla.com\platform\WINNT_x86-msvc\components\mozFotofox.dll
2009-11-25 16:20 . 2009-02-21 15:44 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Any Video Converter
2009-11-25 15:56 . 2008-06-14 19:20 -------- d-----w- c:\program files\Any Video Converter
2009-11-25 15:49 . 2009-07-06 19:10 -------- d-----w- c:\program files\AviSynth 2.5
2009-11-25 15:46 . 2009-11-25 15:39 -------- d-----w- c:\program files\Common Files\Nero
2009-11-25 15:45 . 2009-11-25 15:39 -------- d-----w- c:\documents and settings\All Users.WINDOWZ\Application Data\Nero
2009-11-25 15:42 . 2009-11-25 15:42 -------- d-----w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Nero
2009-11-25 15:18 . 2009-11-25 15:18 -------- d-----w- c:\program files\XviD
2009-11-22 05:59 . 2009-11-22 05:59 -------- d-----w- c:\program files\Parallel Port Joystick
2009-11-21 18:40 . 2009-09-12 05:07 -------- d-----w- c:\program files\World of Warcraft
2009-11-21 15:51 . 2004-08-04 10:00 471552 ----a-w- c:\windowz\AppPatch\aclayers.dll
2009-11-21 02:34 . 2009-10-08 01:01 592488 ----a-w- c:\windowz\system32\nvudisp.exe
2009-11-21 02:34 . 2009-10-08 01:00 6282752 ----a-w- c:\windowz\system32\nv4_disp.dll
2009-11-21 02:34 . 2009-10-08 01:00 10235968 ----a-w- c:\windowz\system32\drivers\nv4_mini.sys
2009-11-21 02:34 . 2009-09-27 20:12 2293286 ----a-w- c:\windowz\system32\nvdata.bin
2009-11-21 02:34 . 2009-09-27 20:12 1989224 ----a-w- c:\windowz\system32\nvcuvenc.dll
2009-11-21 02:34 . 2009-02-18 18:44 4038656 ----a-w- c:\windowz\system32\nvcuda.dll
2009-11-21 02:34 . 2009-02-18 18:44 2259560 ----a-w- c:\windowz\system32\nvcuvid.dll
2009-11-21 02:34 . 2009-02-18 18:44 182888 ----a-w- c:\windowz\system32\nvcodins.dll
2009-11-21 02:34 . 2009-02-18 18:44 182888 ----a-w- c:\windowz\system32\nvcod.dll
2009-11-21 02:34 . 2009-02-18 18:44 13602816 ----a-w- c:\windowz\system32\nvoglnt.dll
2009-11-21 02:34 . 2009-02-18 18:44 1056768 ----a-w- c:\windowz\system32\nvapi.dll
2009-11-21 01:32 . 2009-11-21 01:32 278120 ----a-w- c:\windowz\system32\nvmccs.dll
2009-11-21 01:32 . 2009-11-21 01:32 154216 ----a-w- c:\windowz\system32\nvsvc32.exe
2009-11-21 01:32 . 2009-11-21 01:32 145000 ----a-w- c:\windowz\system32\nvcolor.exe
2009-11-21 01:32 . 2009-11-21 01:32 12669544 ----a-w- c:\windowz\system32\nvcpl.dll
2009-11-21 01:32 . 2009-11-21 01:32 110184 ----a-w- c:\windowz\system32\nvmctray.dll
2009-11-21 01:32 . 2009-11-21 01:32 81920 ----a-w- c:\windowz\system32\nvwddi.dll
2009-11-20 02:42 . 2009-10-08 01:00 592488 ----a-w- c:\windowz\system32\NVUNINST.EXE
2009-11-12 04:46 . 2009-11-12 04:46 138240 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll
2009-11-12 04:46 . 2009-11-12 04:46 138240 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll
2009-11-12 04:46 . 2009-11-12 04:46 138240 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll
2009-11-12 04:46 . 2009-11-12 04:46 138240 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll
2009-11-09 19:36 . 2009-11-09 19:36 15029880 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Raptr\raptr-0.3.6_20091105.exe
2009-11-09 18:00 . 2009-11-14 07:00 85504 ----a-w- c:\windowz\system32\ff_vfw.dll
2009-11-04 00:42 . 2009-05-19 02:25 691696 ----a-w- c:\windowz\system32\drivers\sptd.sys
2009-10-29 07:46 . 2006-03-04 03:33 832512 ----a-w- c:\windowz\system32\wininet.dll
2009-10-29 07:46 . 2004-08-04 10:00 78336 ----a-w- c:\windowz\system32\ieencode.dll
2009-10-29 07:46 . 2004-08-04 10:00 17408 ----a-w- c:\windowz\system32\corpol.dll
2009-10-28 20:37 . 2009-10-28 20:37 17280 ----a-w- c:\documents and settings\Guest.DESHAWN-D80E212\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-23 21:05 . 2010-01-19 03:31 38208 ----a-w- c:\documents and settings\Administrator.DESHAWN-D80E212\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-23 21:05 . 2009-08-13 20:59 38208 ----a-w- c:\documents and settings\Default User.WINDOWZ\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-23 21:05 . 2009-08-13 20:57 38208 ----a-w- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2006-05-03 09:06 . 2009-07-06 19:10 163328 --sh--r- c:\windowz\system32\flvDX.dll
2007-02-21 10:47 . 2009-07-06 19:10 31232 --sh--r- c:\windowz\system32\msfDX.dll
2008-03-16 12:30 . 2009-07-06 19:10 216064 --sh--r- c:\windowz\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackgroundSwitcher"="c:\program files\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe" [2009-11-28 119104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 734264]
"NvCplDaemon"="c:\windowz\system32\NvCpl.dll" [2009-11-21 12669544]

c:\documents and settings\All Users.WINDOWZ\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-12-31 688128]
Wireless Connection Manager.lnk - c:\program files\D-Link\D-Link RangeBooster N DWA-142\wirelesscm.exe [2010-1-17 20512768]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWZ^Start Menu^Programs^Startup^Run Registration Tool.lnk]
path=c:\documents and settings\All Users.WINDOWZ\Start Menu\Programs\Startup\Run Registration Tool.lnk
backup=c:\windowz\pss\Run Registration Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWZ^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windowz\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWZ^Start Menu^Programs^Startup^Wireless Connection Manager.lnk]
backup=c:\windowz\pss\Wireless Connection Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^DeShawn Luu.DESHAWN-D80E212^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
backup=c:\windowz\pss\OpenOffice.org 3.0.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^DeShawn Luu.DESHAWN-D80E212^Start Menu^Programs^Startup^Yahoo! Widgets.lnk]
backup=c:\windowz\pss\Yahoo! Widgets.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 16:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 08:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
2007-10-04 22:38 307200 ----a-w- c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ------w- c:\windowz\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CurseClient]
2009-06-08 14:51 1934336 ----a-w- c:\program files\Curse\CurseClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-21 04:31 133104 ----atw- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-21 20:36 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-11-21 01:32 12669544 ----a-w- c:\windowz\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
2008-04-01 01:54 507904 ----a-w- c:\program files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 05:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
2009-11-05 23:56 43960 ----a-w- c:\progra~1\Raptr\RaptrStub.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sbitunesagent]
2009-12-23 11:03 266240 ----a-w- c:\program files\Songbird\songbirditunesagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-03-20 20:00 282624 ----a-w- c:\windowz\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-08-20 08:44 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-08-20 08:41 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2009-05-19 23:26 3561720 ----a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"NvCplDaemon"=RUNDLL32.EXE c:\windowz\system32\NvCpl.dll,NvStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWZ\\system32\\PnkBstrA.exe"=
"c:\\WINDOWZ\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\WINDOWZ\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Raptr\\Raptr.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"d:\\Program Files\\Volition Inc\\Red Faction Guerrilla\\rfg.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\DeShawn Luu.DESHAWN-D80E212\\My Documents\\Downloads\\New Folder\\HentaiAtHome.jar"=
"c:\\Documents and Settings\\DeShawn Luu.DESHAWN-D80E212\\My Documents\\Downloads\\New Folder\\HentaiAtHomeGUI.jar"=
"c:\\Documents and Settings\\DeShawn Luu.DESHAWN-D80E212\\My Documents\\Downloads\\New Folder\\sqlitejdbc-v056.jar"=
"c:\\Documents and Settings\\DeShawn Luu.DESHAWN-D80E212\\My Documents\\Downloads\\New Folder\\autostartgui.bat"=
"c:\\Documents and Settings\\All Users.WINDOWZ\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\DFO\\DFO.exe"=
"d:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"d:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"d:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutParadise.exe"=
"c:\\WINDOWZ\\system32\\javaw.exe"=
"c:\\WINDOWZ\\system32\\dpnsvr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Steam\\steamapps\\jellyman223\\team fortress 2\\hl2.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\left 4 dead 2 demo\\left4dead2.exe"=
"d:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"d:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"d:\\Program Files\\Dragon Age\\bin_ship\\daorigins-enabledeveloperconsole.exe"=
"d:\\Program Files\\Steam\\steam.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"d:\\Program Files\\Steam\\steamapps\\jellyman223\\source sdk base 2007\\hl2.exe"=
"d:\\Program Files\\Steam\\steamapps\\jellyman223\\zombie panic! source\\hl2.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\Program Files\\Rune\\System\\Rune.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\unreal tournament 3\\Binaries\\UT3.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\splintercell chaos theory\\System\\splintercell3.exe"=
"d:\\Program Files\\Steam\\steamapps\\jellyman223\\counter-strike source\\hl2.exe"=
"d:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"d:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
"c:\\WINDOWZ\\system32\\dlcccoms.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\unreal tournament 2004\\System\\UT2004.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\stalker shadow of chernobyl\\bin\\XR_3DA.exe"=
"d:\\Program Files\\Steam\\steamapps\\jellyman223\\garrysmod\\hl2.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\prince of persia the warrior within\\PrinceOfPersia.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\prince of persia two thrones\\PrinceOfPersia.exe"=
"d:\\Program Files\\Dead Space\\Dead Space.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8395:TCP"= 8395:TCP:League of Legends Launcher
"8395:UDP"= 8395:UDP:League of Legends Launcher
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"8397:TCP"= 8397:TCP:League of Legends Launcher
"8397:UDP"= 8397:UDP:League of Legends Launcher
"8398:TCP"= 8398:TCP:League of Legends Launcher
"8398:UDP"= 8398:UDP:League of Legends Launcher
"8399:TCP"= 8399:TCP:League of Legends Launcher
"8399:UDP"= 8399:UDP:League of Legends Launcher
"24669:TCP"= 24669:TCP:League of Legends Launcher
"24669:UDP"= 24669:UDP:League of Legends Launcher
"57030:TCP"= 57030:TCP:Pando Media Booster
"57030:UDP"= 57030:UDP:Pando Media Booster
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"1112:TCP"= 1112:TCP:1112
"8888:TCP"= 8888:TCP:DSPad02

S0 gwwqqqb;gwwqqqb;c:\windowz\system32\drivers\gmfxrkjc.sys --> c:\windowz\system32\drivers\gmfxrkjc.sys [?]
S0 sptd;sptd;c:\windowz\system32\drivers\sptd.sys [5/18/2009 9:25 PM 691696]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [5/6/2009 5:53 PM 1220608]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12/24/2009 10:21 PM 25832]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [8/7/2008 10:10 AM 3276800]
S3 npggsvc;nProtect GameGuard Service;c:\windowz\system32\GameMon.des -service --> c:\windowz\system32\GameMon.des -service [?]
S3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windowz\system32\drivers\PPJoyBus.sys [8/8/2002 5:27 PM 11330]
S3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windowz\system32\drivers\WPRO_40_1340.sys --> c:\windowz\system32\drivers\WPRO_40_1340.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-01-07 c:\windowz\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]

2010-01-17 c:\windowz\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-117609710-839522115-1003Core.job
- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-21 04:31]

2010-01-19 c:\windowz\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-117609710-839522115-1003UA.job
- c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-21 04:31]
.
.
------- Supplementary Scan -------
.
uLocal Page = hxxp://dealhrfind.com
uStart Page = hxxp://dealhrfind.com
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
FF - ProfilePath - c:\documents and settings\DeShawn Luu.DESHAWN-D80E212\Application Data\Mozilla\Firefox\Profiles\binmxplw.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}\defaults\preferences\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windowz\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\npggsvc]
"ImagePath"="c:\windowz\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1229272821-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’e*’B*’ ’N*’9 ’x*’9 ]
"Order"=hex:08,00,00,00,02,00,00,00,b0,00,00,00,01,00,00,00,01,00,00,00,a4,00,
00,00,00,00,00,00,96,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,84,00,31,\

[HKEY_LOCAL_MACHINE\software\’t*’0 ’ ’X*’p*’ \’0 ’O*’i*’*’N*’o*’g*’9 ’I*’t*’0 ’C*’ ]
"Path"="d:\\Program Files\\RBO"

[HKEY_LOCAL_MACHINE\software\’t*’0 ’ ’X*’p*’ \’0 ’O*’i*’*’N*’o*’g*’9 ’I*’t*’0 ’C*’ Ç*0 Á*’V*’i*’`’I*1*]
"Path"="d:\\Program Files\\RBO\\ƒ‰ƒOƒiƒƒNƒoƒgƒ‹ƒIƒtƒ‰ƒCƒ“’ljÁƒVƒiƒŠƒI1"
DUMPHIVE0.003 (REGF)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(624)
c:\windowz\system32\Ati2evxx.dll
.
Completion time: 2010-01-19 19:46:51
ComboFix-quarantined-files.txt 2010-01-20 00:46

Pre-Run: 24,393,494,528 bytes free
Post-Run: 24,507,043,840 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWZ
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWZ="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noguiboot
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=5 Default=5 Failed=2 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 75D261E26376A11C839E28200480AC5C

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.