WiredWX Hobby Weather ToolsLog in

 


"You may not have the appropriate permission to access this item."

2 posters

description"You may not have the appropriate permission to access this item." Empty"You may not have the appropriate permission to access this item."

more_horiz
While trying to download the newest update for Ventrilo, I get this message that pops up telling me no basically. I logged on also as admin, but nothing changed and got the same message. I play internet games and am not able to play much without Ventrilo. I hope I can fix this soon.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
Hello.

Download OTL by OldTimer to your Desktop.

  • Close all windows and double click OTL.exe
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
  • You may need to use two posts to get it all.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
OTL logfile created on: 6/28/2010 2:21:43 PM - Run 3
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Brent\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.28 Gb Total Space | 2.17 Gb Free Space | 5.68% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 465.76 Gb Total Space | 437.94 Gb Free Space | 94.03% Space Free | Partition Type: NTFS

Computer Name: STADTS
Current User Name: Brent
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/28 14:14:04 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Brent\Desktop\OTL.exe
PRC - [2010/06/02 18:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/05/07 18:47:32 | 000,162,648 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2010/03/19 09:49:20 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/10/03 16:06:15 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\DNA\btdna.exe
PRC - [2009/09/09 15:33:06 | 000,065,536 | ---- | M] (New Boundary Technologies, Inc.) -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/04/19 20:29:56 | 000,149,024 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
PRC - [2007/04/19 20:29:44 | 000,411,168 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
PRC - [2004/08/02 10:50:36 | 000,806,912 | ---- | M] (U.S. Robotics) -- C:\U.S.R.TurboGWLAN\USRWLANG.exe


========== Modules (SafeList) ==========

MOD - [2010/06/28 14:14:04 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Brent\Desktop\OTL.exe
MOD - [2008/04/14 04:40:22 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (JavaQuickStarterService)
SRV - File not found [On_Demand | Stopped] -- -- (gusvc)
SRV - [2010/05/07 18:47:32 | 000,162,648 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2010/03/19 09:49:20 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/09/09 15:33:06 | 000,065,536 | ---- | M] (New Boundary Technologies, Inc.) [Auto | Running] -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -- (PrismXL)
SRV - [2009/05/25 04:26:40 | 000,303,376 | ---- | M] (Kaspersky Lab) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe -- (AVP)
SRV - [2007/04/19 20:29:44 | 000,411,168 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2004/12/23 19:19:40 | 000,202,448 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2004/12/10 18:02:34 | 000,243,312 | ---- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV - [2004/12/10 18:02:32 | 000,087,664 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc)


========== Driver Services (SafeList) ==========

DRV - [2010/05/14 16:04:20 | 000,023,904 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2010/05/14 16:04:02 | 006,842,592 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 250(UVC)
DRV - [2010/05/14 16:02:26 | 000,276,448 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2010/05/14 16:02:14 | 000,114,784 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvpopflt.sys -- (lvpopflt)
DRV - [2010/05/07 18:43:30 | 000,025,824 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2010/04/18 22:30:44 | 000,296,976 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2010/04/18 22:30:44 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (kl1)
DRV - [2009/05/16 19:59:44 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009/05/13 16:46:52 | 000,031,760 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2008/12/15 19:41:32 | 000,033,808 | ---- | M] (Kaspersky Lab) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\klbg.sys -- (klbg)
DRV - [2008/09/24 09:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2008/08/20 22:52:41 | 003,299,840 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2008/05/24 16:51:23 | 000,392,320 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2008/05/24 16:51:23 | 000,032,768 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2008/05/24 16:51:13 | 000,120,992 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\snapman.sys -- (snapman)
DRV - [2008/05/22 06:16:40 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008/04/14 00:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 23:10:32 | 000,096,512 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\atapi.sys -- (atapi)
DRV - [2008/04/13 10:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/07/20 17:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006/12/28 11:44:44 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdAud.sys -- (HdAudAddService)
DRV - [2006/05/10 10:27:00 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006/02/10 17:55:36 | 000,034,688 | ---- | M] (Dolphin, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\samfilt.sys -- (SAMFILT)
DRV - [2005/11/10 12:54:56 | 000,402,944 | R--- | M] (Belkin Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLKWGU.sys -- (BLKWGU(Belkin)) Belkin Wireless G USB Network Adapter(Belkin)
DRV - [2005/09/29 22:52:22 | 000,013,056 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/09/29 22:52:20 | 000,034,048 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005/08/18 02:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2004/08/12 20:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004/06/28 13:58:50 | 000,387,072 | ---- | M] (U.S. Robotics) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USR11G.SYS -- (USR11G)
DRV - [2004/03/11 20:16:32 | 000,062,865 | ---- | M] (Funk Software, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\odysseyIM3.sys -- (odysseyIM3)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
IE - HKCU\..\URLSearchHook: {5E72625C-99E3-4644-BFF0-315AA91294FA} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "bboy.org"
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.459
FF - prefs.js..extensions.enabledItems: {C3945711-14EC-489D-BF2A-08E97087AF20}:1.0
FF - prefs.js..keyword.URL: "http://tmq.bingstart.com/s/?src=FF-Address&site=Bing&cfg=2-168-0-1j2rR&q="
FF - prefs.js..network.proxy.no_proxies_on: "127.0.0.1, local.swarmcast.net"

FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Documents and Settings\Brent\Desktop\eMusic Download Manager\xulrunner\components
FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Documents and Settings\Brent\Desktop\eMusic Download Manager\xulrunner\plugins
FF - HKLM\software\mozilla\Firefox\Extensions\\{C3945711-14EC-489D-BF2A-08E97087AF20}: C:\Documents and Settings\Brent\Local Settings\Application Data\{C3945711-14EC-489D-BF2A-08E97087AF20} [2008/12/21 02:54:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: I:\Java\lib\deploy\jqs\ff
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/24 20:26:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/24 20:26:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010/04/18 22:17:40 | 000,000,000 | ---D | M]

[2009/10/14 08:58:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brent\Application Data\Mozilla\Extensions
[2009/10/14 08:58:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brent\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/06/19 09:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brent\Application Data\Mozilla\Firefox\Profiles\vbripgx3.default\extensions
[2009/07/23 09:12:54 | 000,000,681 | ---- | M] () -- C:\Documents and Settings\Brent\Application Data\Mozilla\Firefox\Profiles\vbripgx3.default\searchplugins\ask.xml
[2009/10/09 03:55:07 | 000,002,255 | ---- | M] () -- C:\Documents and Settings\Brent\Application Data\Mozilla\Firefox\Profiles\vbripgx3.default\searchplugins\askcom.xml
[2010/06/07 02:56:47 | 000,001,949 | ---- | M] () -- C:\Documents and Settings\Brent\Application Data\Mozilla\Firefox\Profiles\vbripgx3.default\searchplugins\bing-zugo.xml
[2009/12/01 12:50:20 | 000,002,160 | ---- | M] () -- C:\Documents and Settings\Brent\Application Data\Mozilla\Firefox\Profiles\vbripgx3.default\searchplugins\MySpace.xml
[2010/06/28 01:33:36 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/18 22:18:26 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru

O1 HOSTS File: ([2009/11/09 22:30:05 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (no name) - {5E72625B-99E3-4644-BFF0-315AA91294FA} - No CLSID value found.
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (no name) - {BBD14491-A5A0-4809-9C5A-C9FC6DF0ACB0} - No CLSID value found.
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (no name) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [PrinTray] C:\WINDOWS\system32\spool\drivers\w32x86\2\printray.exe (Lexmark)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] I:\Java\bin\jusched.exe File not found
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe File not found
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files\Logitech\Vid\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [Logitech Vid HD] C:\Program Files\Logitech\Vid\vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe ()
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\U.S. Robotics 802.11g Wireless Network Utility.lnk = C:\U.S.R.TurboGWLAN\USRWLANG.exe (U.S. Robotics)
O4 - Startup: C:\Documents and Settings\Brent\Start Menu\Programs\Startup\Logitech . Product Registration.lnk = C:\Program Files\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonscripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffscripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonscriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupscriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupscripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonscripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffscripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonscriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupscriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupscripts = 0
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1181071085625 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\winlogon32.exe) - C:\WINDOWS\system32\winlogon32.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Documents and Settings\Brent\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Brent\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/05 23:57:43 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/28 14:14:04 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Brent\Desktop\OTL.exe
[2010/06/27 01:04:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brent\Local Settings\Application Data\VS Revo Group
[2010/06/24 14:05:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brent\My Documents\SightSpeed Recordings
[2010/06/23 16:10:57 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Brent\IETldCache
[2010/06/23 16:04:25 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/06/12 16:48:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\logishrd
[2010/06/12 16:47:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LWS
[2010/06/12 16:47:15 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2010/06/12 16:00:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech
[2010/06/12 06:13:13 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\GTek
[2010/06/12 06:01:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brent\Application Data\Help
[2010/06/12 05:59:03 | 000,048,640 | ---- | C] (Lexmark) -- C:\WINDOWS\System32\Lexunst1.exe
[2010/06/12 05:59:02 | 000,201,728 | ---- | C] (Lexmark International, Inc.) -- C:\WINDOWS\System32\Lexp2p32.dll
[2010/06/12 05:59:02 | 000,190,976 | ---- | C] (Lexmark International, Inc.) -- C:\WINDOWS\System32\lexlmpm.dll
[2010/06/12 05:59:02 | 000,177,152 | ---- | C] (Lexmark International, Inc.) -- C:\WINDOWS\System32\lex2kusb.dll
[2010/06/12 05:59:02 | 000,135,168 | ---- | C] (Lexmark International, Inc.) -- C:\WINDOWS\System32\LexBce.dll
[2010/06/12 05:59:02 | 000,041,472 | ---- | C] (Lexmark International, Inc.) -- C:\WINDOWS\System32\ldeei.dll
[2010/06/12 05:58:23 | 000,299,520 | ---- | C] (InstallShield Corporation, Inc.) -- C:\WINDOWS\uninst.exe
[2010/06/12 05:58:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brent\WINDOWS
[2010/06/10 21:52:39 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/06/10 21:52:39 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/06/10 21:52:39 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2010/06/10 21:52:39 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/06/10 21:52:38 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2010/06/10 21:52:38 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/06/09 17:25:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LogiShrd
[2010/06/09 16:21:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brent\Local Settings\Application Data\LogiShrd
[2010/06/07 03:01:02 | 000,000,000 | ---D | C] -- C:\Program Files\QuizulousBar
[2010/06/07 02:56:40 | 000,000,000 | ---D | C] -- C:\Program Files\Mind Quiz
[2010/06/06 21:10:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brent\Application Data\Leadertech
[2010/06/06 21:08:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\LogiShrd
[2010/06/06 21:05:11 | 000,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010/06/06 21:05:11 | 000,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/06/06 21:05:00 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vfwwdm32.dll
[2010/06/06 21:05:00 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2010/06/06 21:05:00 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dshowext.ax
[2010/06/06 21:05:00 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dshowext.ax
[2010/05/31 09:45:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SpeedBit
[48 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/28 14:14:04 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Brent\Desktop\OTL.exe
[2010/06/28 14:08:25 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2010/06/28 14:07:34 | 000,000,587 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\World of Warcraft.lnk
[2010/06/28 13:48:17 | 000,020,712 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/06/28 13:47:31 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/06/28 13:47:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/06/28 13:47:28 | 000,044,964 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
[2010/06/28 13:47:09 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/06/28 13:47:07 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2010/06/28 02:36:43 | 005,242,880 | ---- | M] () -- C:\Documents and Settings\Brent\ntuser.dat
[2010/06/28 02:36:43 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Brent\ntuser.ini
[2010/06/27 17:12:08 | 003,196,328 | ---- | M] () -- C:\Documents and Settings\Brent\Desktop\ventrilo-3.0.5-Windows-i386.exe
[2010/06/26 09:20:09 | 004,844,566 | -H-- | M] () -- C:\Documents and Settings\Brent\Local Settings\Application Data\IconCache.db
[2010/06/24 01:21:27 | 000,005,120 | ---- | M] () -- C:\Documents and Settings\Brent\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/23 16:10:56 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Brent\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/06/19 11:23:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/19 06:49:39 | 000,125,184 | ---- | M] () -- C:\Documents and Settings\Brent\Desktop\Schedule.June.12th.19th.and.26th.rev.3.61510.pdf
[2010/06/15 13:59:20 | 000,000,749 | ---- | M] () -- C:\Documents and Settings\Brent\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2010/06/12 16:47:15 | 000,001,261 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Logitech Webcam Software .lnk
[2010/06/12 16:17:25 | 000,019,920 | ---- | M] () -- C:\Documents and Settings\Brent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/12 05:59:12 | 000,002,409 | ---- | M] () -- C:\WINDOWS\System32\Lexmark Z42-Z43 Series ColorFine.AD2
[2010/06/11 10:52:12 | 000,118,952 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/10 22:36:57 | 000,443,384 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/10 22:36:57 | 000,397,060 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/10 22:36:57 | 000,059,532 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/09 02:09:31 | 000,000,760 | ---- | M] () -- C:\Documents and Settings\Brent\Application Data\setup_ldm.iss
[2010/06/08 18:24:35 | 000,044,208 | ---- | M] () -- C:\Documents and Settings\Brent\My Documents\Picture 24.jpg
[2010/06/08 00:10:48 | 000,001,469 | ---- | M] () -- C:\Documents and Settings\Brent\Desktop\DivX Movies.lnk
[2010/06/08 00:10:13 | 000,000,777 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\DivX Plus Player.lnk
[2010/06/08 00:09:28 | 000,000,817 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\DivX Plus Converter.lnk
[48 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/27 17:12:10 | 003,196,328 | ---- | C] () -- C:\Documents and Settings\Brent\Desktop\ventrilo-3.0.5-Windows-i386.exe
[2010/06/27 01:17:00 | 005,242,880 | ---- | C] () -- C:\Documents and Settings\Brent\ntuser.dat
[2010/06/23 16:30:29 | 000,000,587 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\World of Warcraft.lnk
[2010/06/19 06:48:32 | 000,125,184 | ---- | C] () -- C:\Documents and Settings\Brent\Desktop\Schedule.June.12th.19th.and.26th.rev.3.61510.pdf
[2010/06/15 13:59:20 | 000,000,749 | ---- | C] () -- C:\Documents and Settings\Brent\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2010/06/12 17:45:57 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Brent\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/12 16:47:15 | 000,001,261 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Logitech Webcam Software .lnk
[2010/06/12 05:59:03 | 000,000,643 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2010/06/12 05:59:02 | 000,079,872 | ---- | C] () -- C:\WINDOWS\System32\lex_psu.exe
[2010/06/12 05:58:35 | 000,002,409 | ---- | C] () -- C:\WINDOWS\System32\Lexmark Z42-Z43 Series ColorFine.AD2
[2010/06/10 15:57:47 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/06/10 15:55:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2010/06/09 02:09:31 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\Brent\Application Data\setup_ldm.iss
[2010/06/08 18:26:15 | 000,044,208 | ---- | C] () -- C:\Documents and Settings\Brent\My Documents\Picture 24.jpg
[2010/06/08 00:10:13 | 000,000,777 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\DivX Plus Player.lnk
[2010/06/08 00:09:28 | 000,000,817 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\DivX Plus Converter.lnk
[2010/05/14 15:56:06 | 010,830,680 | ---- | C] () -- C:\WINDOWS\System32\LogiDPP.dll
[2010/05/14 15:55:58 | 000,290,648 | ---- | C] () -- C:\WINDOWS\System32\DevManagerCore.dll
[2010/05/14 15:47:00 | 000,090,071 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/05/07 18:46:36 | 000,014,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2010/05/07 18:43:30 | 000,025,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/11/15 09:40:07 | 000,000,000 | -HS- | C] () -- C:\WINDOWS\System32\calc.dll
[2009/10/15 16:58:05 | 000,081,332 | ---- | C] () -- C:\WINDOWS\System32\BASS.DLL
[2009/09/15 16:03:50 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2009/09/09 15:30:55 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009/05/03 21:26:09 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008/11/12 03:02:32 | 000,000,206 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/05/16 13:00:46 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2007/06/19 07:59:36 | 000,070,400 | ---- | C] () -- C:\WINDOWS\System32\PhysXLoader.dll
[2007/06/03 15:45:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2007/04/26 18:54:59 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2007/04/26 09:33:56 | 000,000,087 | ---- | C] () -- C:\WINDOWS\usrwiz.ini
[2007/04/26 09:05:38 | 000,020,256 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2007/04/26 09:05:37 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/04/26 09:05:30 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/04/20 06:57:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/04/20 06:57:28 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/04/20 06:57:28 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/04/20 06:57:28 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/04/20 06:57:28 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/04/20 06:57:28 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/04/20 06:57:28 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/04/20 06:57:28 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/04/20 06:57:28 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2002/10/24 14:59:48 | 000,096,512 | ---- | C] () -- C:\WINDOWS\System32\drivers\atapi.sys
[2002/07/05 08:12:06 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\authdvd.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:010ADD2C
< End of report >
However, it didn't creat an extras.txt to open and paste here.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
Hello.

  • Download combofix from here
    Link 1
    Link 2

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:

    "You may not have the appropriate permission to access this item." CF_download_FF

    "You may not have the appropriate permission to access this item." CF_download_rename

    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See HERE for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    "You may not have the appropriate permission to access this item." Cf410

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes

    "You may not have the appropriate permission to access this item." Cf510

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
ComboFix 10-06-27.06 - Brent 06/28/2010 20:07:32.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1505 [GMT -6:00]
Running from: c:\documents and settings\Brent\Desktop\ventrilo-3.0.5-Windows-i386.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Brent\Local Settings\Application Data\{C3945711-14EC-489D-BF2A-08E97087AF20}
c:\documents and settings\Brent\Local Settings\Application Data\{C3945711-14EC-489D-BF2A-08E97087AF20}\chrome.manifest
c:\documents and settings\Brent\Local Settings\Application Data\{C3945711-14EC-489D-BF2A-08E97087AF20}\chrome\content\_cfg.js
c:\documents and settings\Brent\Local Settings\Application Data\{C3945711-14EC-489D-BF2A-08E97087AF20}\chrome\content\c.js
c:\documents and settings\Brent\Local Settings\Application Data\{C3945711-14EC-489D-BF2A-08E97087AF20}\chrome\content\overlay.xul
c:\documents and settings\Brent\Local Settings\Application Data\{C3945711-14EC-489D-BF2A-08E97087AF20}\install.rdf
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\windows\system32\api.dat
c:\windows\system32\calc.dll
c:\windows\system32\tmp.reg
c:\windows\system32\winlogon32.exe

.
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))))
.

2010-06-29 01:49 . 2010-06-29 01:49 -------- d-----w- c:\documents and settings\Brent\Application Data\Logitech
2010-06-27 07:31 . 2010-06-27 07:31 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-27 07:04 . 2010-06-27 07:04 -------- d-----w- c:\documents and settings\Brent\Local Settings\Application Data\VS Revo Group
2010-06-23 22:25 . 2010-06-23 22:25 -------- d-sh--w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
2010-06-23 22:10 . 2010-06-23 22:10 -------- d-sh--w- c:\documents and settings\Brent\IETldCache
2010-06-23 22:04 . 2010-06-23 22:06 -------- dc-h--w- c:\windows\ie8
2010-06-19 13:04 . 2010-06-19 13:04 -------- d-----w- c:\documents and settings\Default User.WINDOWS\Local Settings\Application Data\Adobe
2010-06-12 22:48 . 2010-06-29 02:21 -------- d-----w- c:\windows\system32\logishrd
2010-06-12 22:47 . 2010-06-12 22:47 -------- d-----w- c:\program files\Common Files\LWS
2010-06-12 22:47 . 2010-06-12 22:51 -------- d-----w- c:\program files\Logitech
2010-06-12 22:17 . 2010-06-12 22:17 19920 ----a-w- c:\documents and settings\Brent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-12 22:00 . 2010-06-12 22:48 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech
2010-06-12 12:13 . 2010-06-13 05:12 -------- d--ha-w- c:\documents and settings\All Users.WINDOWS\Application Data\GTek
2010-06-12 11:59 . 2001-04-03 00:04 58880 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LXATPP.DLL
2010-06-12 11:59 . 2001-03-27 10:12 48640 ----a-w- c:\windows\system32\Lexunst1.exe
2010-06-12 11:59 . 2001-03-30 15:42 190976 ----a-w- c:\windows\system32\lexlmpm.dll
2010-06-12 11:59 . 2001-03-30 15:41 177152 ----a-w- c:\windows\system32\lex2kusb.dll
2010-06-12 11:59 . 2001-03-30 15:40 201728 ----a-w- c:\windows\system32\Lexp2p32.dll
2010-06-12 11:59 . 2001-03-27 08:56 311296 ----a-w- c:\windows\system32\LexBceS.exe
2010-06-12 11:59 . 2001-03-27 08:54 135168 ----a-w- c:\windows\system32\LexBce.dll
2010-06-12 11:59 . 2001-03-27 08:50 170496 ----a-w- c:\windows\system32\Lexpps.exe
2010-06-12 11:59 . 1997-10-09 19:08 79872 ----a-w- c:\windows\system32\lex_psu.exe
2010-06-12 11:59 . 1997-07-29 21:13 41472 ----a-w- c:\windows\system32\ldeei.dll
2010-06-12 11:58 . 1997-04-09 02:08 299520 ----a-w- c:\windows\uninst.exe
2010-06-12 11:58 . 2010-06-12 11:58 -------- d-----w- c:\documents and settings\Brent\WINDOWS
2010-06-11 03:53 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-06-11 03:52 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-06-11 03:52 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-06-11 03:52 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-06-11 03:52 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-06-11 03:52 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-06-11 03:52 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-06-11 03:52 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-06-11 03:52 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-06-09 23:25 . 2010-06-12 22:49 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-06-09 22:21 . 2010-06-09 22:21 -------- d-----w- c:\documents and settings\Brent\Local Settings\Application Data\LogiShrd
2010-06-07 09:01 . 2010-06-07 09:01 -------- d-----w- c:\program files\QuizulousBar
2010-06-07 08:56 . 2010-06-07 08:56 -------- d-----w- c:\program files\Mind Quiz
2010-06-07 03:10 . 2010-06-07 03:10 -------- d-----w- c:\documents and settings\Brent\Application Data\Leadertech
2010-06-07 03:08 . 2010-06-12 22:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\LogiShrd
2010-06-07 03:05 . 2008-04-14 06:15 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-06-07 03:05 . 2008-04-14 06:15 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-06-07 03:05 . 2008-04-14 11:42 53760 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-06-07 03:05 . 2008-04-14 11:42 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2010-05-31 15:45 . 2010-05-31 16:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-29 02:21 . 2008-08-14 09:46 -------- d-----w- c:\program files\DNA
2010-06-29 02:21 . 2008-08-14 09:46 -------- d-----w- c:\documents and settings\Brent\Application Data\DNA
2010-06-29 02:20 . 2010-06-10 21:57 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-06-29 02:20 . 2010-06-10 21:55 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-06-29 01:43 . 2010-04-19 04:16 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2010-06-27 06:42 . 2009-02-26 02:28 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-06-26 02:12 . 2010-04-02 19:41 -------- d-----w- c:\documents and settings\Brent\Application Data\BitTorrent
2010-06-23 23:27 . 2007-01-22 18:45 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-06-22 18:02 . 2009-09-15 22:28 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Blizzard Entertainment
2010-06-19 13:31 . 2009-09-17 21:21 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS
2010-06-19 13:02 . 2005-09-16 03:08 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-19 13:00 . 2010-04-24 17:09 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-19 12:59 . 2010-06-19 13:00 53632 ----a-w- c:\documents and settings\Brent\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-19 12:59 . 2010-04-24 17:09 53632 ----a-w- c:\documents and settings\Default User.WINDOWS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-15 12:20 . 2010-06-15 12:20 129552 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\mmpprtc.dll
2010-06-15 12:20 . 2010-06-15 12:20 129624 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mmpprtc.dll
2010-06-12 22:50 . 2010-06-12 22:50 53248 ----a-r- c:\documents and settings\Brent\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-06-12 12:15 . 2010-06-12 12:15 45056 ----a-r- c:\documents and settings\Brent\Application Data\Microsoft\Installer\{6815FCDD-401D-481E-BA88-31B4754C2B46}\ARPPRODUCTICON.exe
2010-06-10 02:04 . 2007-08-17 15:11 -------- d-----w- c:\documents and settings\Brent\Application Data\DivX
2010-06-09 03:02 . 2005-12-12 02:46 -------- d-----w- c:\program files\Ventrilo
2010-06-08 06:12 . 2010-05-07 04:47 57344 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-08 06:12 . 2010-05-07 04:43 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX
2010-06-08 06:10 . 2010-01-08 03:23 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-06-08 06:10 . 2007-08-17 15:07 -------- d-----w- c:\program files\DivX
2010-06-08 06:10 . 2010-06-08 06:10 56765 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-06-08 06:10 . 2010-06-08 06:10 56997 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-08 06:10 . 2010-06-08 06:10 53600 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Update\Uninstaller.exe
2010-06-08 06:10 . 2010-06-08 06:10 57715 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Player\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 84062 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 57054 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54166 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 57532 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 56458 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54174 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54153 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54128 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Converter\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54644 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54101 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 56969 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-06-08 06:04 . 2010-05-07 04:47 1062184 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Setup\Resource.dll
2010-06-08 06:04 . 2010-05-07 04:47 895256 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Setup\DivXSetup.exe
2010-05-31 16:07 . 2008-05-16 19:32 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2010-05-14 22:04 . 2010-05-14 22:04 23904 ----a-w- c:\windows\system32\drivers\lvuvcflt.sys
2010-05-14 22:04 . 2010-05-14 22:04 6842592 ----a-w- c:\windows\system32\drivers\lvuvc.sys
2010-05-14 22:03 . 2010-05-14 22:03 539232 ----a-w- c:\windows\system32\LVUI2RC.dll
2010-05-14 22:03 . 2010-05-14 22:03 543328 ----a-w- c:\windows\system32\LVUI2.dll
2010-05-14 22:02 . 2010-05-14 22:02 276448 ----a-w- c:\windows\system32\drivers\lvrs.sys
2010-05-14 22:02 . 2010-05-14 22:02 114784 ----a-w- c:\windows\system32\drivers\lvpopflt.sys
2010-05-14 21:59 . 2010-05-14 21:59 203360 ----a-w- c:\windows\system32\lvci1301783.dll
2010-05-14 21:59 . 2010-05-14 21:59 416352 ----a-w- c:\windows\system32\lvcodec2.dll
2010-05-14 21:56 . 2010-05-14 21:56 10830680 ----a-w- c:\windows\system32\LogiDPP.dll
2010-05-14 21:56 . 2010-05-14 21:56 102744 ----a-w- c:\windows\system32\LogiDPPApp.exe
2010-05-14 21:55 . 2010-05-14 21:55 290648 ----a-w- c:\windows\system32\DevManagerCore.dll
2010-05-14 21:47 . 2010-05-14 21:47 266828 ----a-w- c:\windows\system32\drivers\LVAFT.cfg
2010-05-14 21:46 . 2010-05-14 21:46 37518 ----a-w- c:\windows\system32\Repository.reg
2010-05-12 20:42 . 2010-05-12 20:42 46904 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech\LWS\PrivacyShades\LWS_PrivacyShade_Uninstall.exe
2010-05-08 06:54 . 2010-05-08 06:54 -------- d-----w- c:\documents and settings\Brent\Application Data\eMusic
2010-05-08 00:50 . 2010-05-08 00:50 299352 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech\LWS\Filters\VMSEF.dll
2010-05-08 00:48 . 2010-05-08 00:48 6915416 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech\LWS\Filters\MMSEF.dll
2010-05-08 00:46 . 2010-05-08 00:46 14168 ----a-w- c:\windows\system32\drivers\iKeyLFT2.dll
2010-05-08 00:43 . 2010-05-08 00:43 25824 ----a-w- c:\windows\system32\drivers\LVPr2Mon.sys
2010-05-08 00:30 . 2010-05-08 00:30 85302 ----a-w- c:\windows\system32\drivers\LVFeL102.cfg
2010-05-08 00:30 . 2010-05-08 00:30 227172 ----a-w- c:\windows\system32\drivers\LVFeL100.cfg
2010-05-08 00:30 . 2010-05-08 00:30 146680 ----a-w- c:\windows\system32\drivers\LVFeL101.cfg
2010-05-08 00:29 . 2010-05-08 00:29 69592 ----a-w- c:\windows\system32\drivers\LVFaL100.cfg
2010-05-07 04:47 . 2010-05-07 04:47 57409 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-07 04:47 . 2010-05-07 04:47 52963 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-07 04:46 . 2010-05-07 04:46 54073 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-06 02:57 . 2010-04-19 04:18 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-05-06 02:57 . 2010-04-19 04:18 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-04-27 18:40 . 2007-10-26 22:31 45648 ------w- c:\windows\system32\drivers\PxHelp20.sys
2010-04-27 18:40 . 2007-10-26 22:31 133616 ------w- c:\windows\system32\pxafs.dll
2010-04-27 18:40 . 2007-10-26 22:31 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-04-27 18:40 . 2007-10-26 22:31 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-04-24 16:47 . 2010-04-24 16:47 86016 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS\Adobe_Downloads\arh.exe
2010-04-19 04:31 . 2010-04-19 04:31 932368 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2010-04-19 04:31 . 2010-04-19 04:31 678416 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2010-04-19 04:31 . 2010-04-19 04:31 604688 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2010-04-19 04:31 . 2010-04-19 04:31 522768 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2010-04-19 04:31 . 2010-04-19 04:31 1096208 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2010-04-19 04:30 . 2009-05-24 20:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2010-04-19 04:30 . 2010-04-19 04:30 59920 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd.dll
2010-04-19 04:30 . 2010-04-19 04:30 264720 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\klwtbbho.dll
2010-04-19 04:30 . 2010-04-19 04:30 109072 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd3.dll
2010-04-19 04:30 . 2010-04-19 04:30 296976 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\sys\i386\5.1\klif.sys
2010-04-19 04:30 . 2010-04-19 04:30 128016 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\sys\i386\kl1.sys
2010-04-19 04:20 . 2010-04-19 04:20 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2010-04-11 05:03 . 2010-04-11 05:03 73000 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-03-21 01:29 . 2010-03-21 02:34 83010552 ----a-w- c:\program files\avg_free_stf_en_90_790a2730.exe
2004-07-22 15:51 . 2004-07-22 15:51 3432656 -c--a-w- c:\program files\ManagedDX.CAB
2004-07-20 03:58 . 2004-07-20 03:58 1156363 -c--a-w- c:\program files\BDANT.cab
2004-07-20 03:53 . 2004-07-20 03:53 976020 -c--a-w- c:\program files\BDAXP.cab
2004-07-09 19:17 . 2004-07-09 19:17 13265040 -c--a-w- c:\program files\dxnt.cab
2004-07-09 14:13 . 2004-07-09 14:13 15493481 -c--a-w- c:\program files\DirectX.cab
2004-07-09 14:13 . 2004-07-09 14:13 703080 -c--a-w- c:\program files\BDA.cab
2004-07-09 09:08 . 2004-07-09 09:08 472576 -c--a-w- c:\program files\dxsetup.exe
2004-07-09 09:08 . 2004-07-09 09:08 2242560 -c--a-w- c:\program files\dsetup32.dll
2004-07-09 08:03 . 2004-07-09 08:03 62976 -c--a-w- c:\program files\DSETUP.dll
.

------- Sigcheck -------

[7] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-14 05:10 . 0BDE3245BB788D6263B798646242D596 . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2002-10-24 . F1D915C3870E741D83B5142F3B358761 . 87040 . . [5.1.2600.1135] . . c:\windows\$NtServicePackUninstall$\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2009-12-01 6373376]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-10-03 323392]
"Logitech Vid HD"="c:\program files\Logitech\Vid\vid.exe" [2010-05-11 6061400]
"Logitech Vid"="c:\program files\Logitech\Vid\Vid.exe" [2010-05-11 6061400]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-20 149024]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"PrinTray"="c:\windows\System32\spool\DRIVERS\W32X86\2\printray.exe" [2001-03-27 36864]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-08 165208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-05-25 303376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2009-12-01 6373376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2003-03-31 40960]

c:\documents and settings\Brent\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Logitech\Ereg\eReg.exe [2009-11-16 517384]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
U.S. Robotics 802.11g Wireless Network Utility.lnk - c:\u.s.r.turbogwlan\USRWLANG.exe [2008-6-27 806912]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Tag28.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\freecell.exe"=
"c:\\WINDOWS\\system32\\mshearts.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Seagate\\Schedule2\\schedhlp.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"i:\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\Brent\\My Documents\\Torrent Music\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"i:\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\Logitech\\Vid\\Vid.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundRouterRequest"= 0 (0x0)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [12/15/2008 7:41 PM 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/13/2009 4:46 PM 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [5/16/2009 7:59 PM 19472]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/22/2008 6:16 AM 717296]
S0 Tag28;Tag28;c:\windows\system32\Drivers\Tag28.sys --> c:\windows\system32\Drivers\Tag28.sys [?]
S2 ioecqencsrz;ioecqencsrz;\??\c:\windows\system32\drivers\nmlkwols.sys --> c:\windows\system32\drivers\nmlkwols.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-06-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Brent\Application Data\Mozilla\Firefox\Profiles\vbripgx3.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - bboy.org
FF - prefs.js: keyword.URL - hxxp://tmq.bingstart.com/s/?src=FF-Address&site=Bing&cfg=2-168-0-1j2rR&q=
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{5E72625C-99E3-4644-BFF0-315AA91294FA} - (no file)
BHO-{5E72625B-99E3-4644-BFF0-315AA91294FA} - (no file)
BHO-{BBD14491-A5A0-4809-9C5A-C9FC6DF0ACB0} - (no file)
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKLM-Run-SunJavaUpdateSched - i:\java\bin\jusched.exe
SafeBoot-biN17.sys
SafeBoot-ipV28.sys
SafeBoot-jpV62.sys
SafeBoot-jpV73.sys
SafeBoot-msY73.sys
SafeBoot-msY74.sys
SafeBoot-ubH38.sys
AddRemove-9E140F48C9836B9B78539C08FB2B17146BDB3F65 - c:\progra~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe
AddRemove-eMusic Download Manager - c:\documents and settings\Brent\Desktop\eMusic Download Manager\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-28 20:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1752)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(7600)
c:\windows\system32\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Seagate\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-06-28 20:40:03 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-29 02:39
ComboFix2.txt 2008-06-04 19:12
ComboFix3.txt 2008-05-22 12:57

Pre-Run: 2,298,667,008 bytes free
Post-Run: 2,289,168,384 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(1)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /usepmtimer /NoExecute=OptIn

Current=9 Default=9 Failed=6 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
- - End Of File - - 1A824103222DE07ED416D266DD4EC8BB

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
Also, after ComboFix got done making it's run, a few new peoblems came up. First, I now can bootup in Recovery Console mode and does so very quickly if I don't beat my system to it. And second, now my computer is contantly at 100% usage. After disabling Kaspersky to let ComboFix run, I'm guessing a virus or trojan got on my computer. Even typing this and getting to this page took well over 10 minutes. Just an update.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
Logged on today, and both problems solved. Smile... Now just waitin to take care of vent.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
Hello.
Not done yet.

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    Code:


    KILLALL::

    FCopy::
    c:\windows\ServicePackFiles\i386\atapi.sys | c:\windows\system32\drivers\atapi.sys

    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Tag28.sys]

    Driver::
    Tag28
    ioecqencsrz

    Reboot::

  4. Save this as CFScript.txt, in the same location as ComboFix.exe

    "You may not have the appropriate permission to access this item." Cfscriptb4i

  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
ComboFix 10-06-29.04 - Brent 06/30/2010 12:05:02.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1450 [GMT -6:00]
Running from: c:\documents and settings\Brent\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Brent\Desktop\CFScript.txt
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\ServicePackFiles\i386\atapi.sys --> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_IOECQENCSRZ
-------\Legacy_TAG28
-------\Service_ioecqencsrz
-------\Service_Tag28


((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-30 )))))))))))))))))))))))))))))))
.

2010-06-29 01:49 . 2010-06-29 01:49 -------- d-----w- c:\documents and settings\Brent\Application Data\Logitech
2010-06-27 07:31 . 2010-06-27 07:31 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-27 07:04 . 2010-06-27 07:04 -------- d-----w- c:\documents and settings\Brent\Local Settings\Application Data\VS Revo Group
2010-06-23 22:25 . 2010-06-23 22:25 -------- d-sh--w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
2010-06-23 22:10 . 2010-06-23 22:10 -------- d-sh--w- c:\documents and settings\Brent\IETldCache
2010-06-23 22:04 . 2010-06-23 22:06 -------- dc-h--w- c:\windows\ie8
2010-06-19 13:04 . 2010-06-19 13:04 -------- d-----w- c:\documents and settings\Default User.WINDOWS\Local Settings\Application Data\Adobe
2010-06-12 22:48 . 2010-06-30 18:14 -------- d-----w- c:\windows\system32\logishrd
2010-06-12 22:47 . 2010-06-12 22:47 -------- d-----w- c:\program files\Common Files\LWS
2010-06-12 22:47 . 2010-06-12 22:51 -------- d-----w- c:\program files\Logitech
2010-06-12 22:17 . 2010-06-12 22:17 19920 ----a-w- c:\documents and settings\Brent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-12 22:00 . 2010-06-12 22:48 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech
2010-06-12 12:13 . 2010-06-13 05:12 -------- d--ha-w- c:\documents and settings\All Users.WINDOWS\Application Data\GTek
2010-06-12 11:59 . 2001-04-03 00:04 58880 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LXATPP.DLL
2010-06-12 11:59 . 2001-03-27 10:12 48640 ----a-w- c:\windows\system32\Lexunst1.exe
2010-06-12 11:59 . 2001-03-30 15:42 190976 ----a-w- c:\windows\system32\lexlmpm.dll
2010-06-12 11:59 . 2001-03-30 15:41 177152 ----a-w- c:\windows\system32\lex2kusb.dll
2010-06-12 11:59 . 2001-03-30 15:40 201728 ----a-w- c:\windows\system32\Lexp2p32.dll
2010-06-12 11:59 . 2001-03-27 08:56 311296 ----a-w- c:\windows\system32\LexBceS.exe
2010-06-12 11:59 . 2001-03-27 08:54 135168 ----a-w- c:\windows\system32\LexBce.dll
2010-06-12 11:59 . 2001-03-27 08:50 170496 ----a-w- c:\windows\system32\Lexpps.exe
2010-06-12 11:59 . 1997-10-09 19:08 79872 ----a-w- c:\windows\system32\lex_psu.exe
2010-06-12 11:59 . 1997-07-29 21:13 41472 ----a-w- c:\windows\system32\ldeei.dll
2010-06-12 11:58 . 1997-04-09 02:08 299520 ----a-w- c:\windows\uninst.exe
2010-06-12 11:58 . 2010-06-12 11:58 -------- d-----w- c:\documents and settings\Brent\WINDOWS
2010-06-11 03:53 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-06-11 03:52 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-06-11 03:52 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-06-11 03:52 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-06-11 03:52 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-06-11 03:52 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-06-11 03:52 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-06-11 03:52 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-06-11 03:52 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-06-09 23:25 . 2010-06-12 22:49 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-06-09 22:21 . 2010-06-09 22:21 -------- d-----w- c:\documents and settings\Brent\Local Settings\Application Data\LogiShrd
2010-06-07 09:01 . 2010-06-07 09:01 -------- d-----w- c:\program files\QuizulousBar
2010-06-07 08:56 . 2010-06-07 08:56 -------- d-----w- c:\program files\Mind Quiz
2010-06-07 03:10 . 2010-06-07 03:10 -------- d-----w- c:\documents and settings\Brent\Application Data\Leadertech
2010-06-07 03:08 . 2010-06-12 22:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\LogiShrd
2010-06-07 03:05 . 2008-04-14 06:15 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-06-07 03:05 . 2008-04-14 06:15 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-06-07 03:05 . 2008-04-14 11:42 53760 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-06-07 03:05 . 2008-04-14 11:42 53760 ----a-w- c:\windows\system32\vfwwdm32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-30 18:14 . 2008-08-14 09:46 -------- d-----w- c:\program files\DNA
2010-06-30 18:14 . 2008-08-14 09:46 -------- d-----w- c:\documents and settings\Brent\Application Data\DNA
2010-06-30 18:13 . 2010-06-10 21:57 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-06-30 18:13 . 2010-06-10 21:55 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-06-30 17:40 . 2010-04-19 04:16 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2010-06-27 06:42 . 2009-02-26 02:28 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-06-26 02:12 . 2010-04-02 19:41 -------- d-----w- c:\documents and settings\Brent\Application Data\BitTorrent
2010-06-23 23:27 . 2007-01-22 18:45 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-06-22 18:02 . 2009-09-15 22:28 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Blizzard Entertainment
2010-06-19 13:31 . 2009-09-17 21:21 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS
2010-06-19 13:02 . 2005-09-16 03:08 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-19 13:00 . 2010-04-24 17:09 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-19 12:59 . 2010-06-19 13:00 53632 ----a-w- c:\documents and settings\Brent\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-19 12:59 . 2010-04-24 17:09 53632 ----a-w- c:\documents and settings\Default User.WINDOWS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-15 12:20 . 2010-06-15 12:20 129552 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\mmpprtc.dll
2010-06-15 12:20 . 2010-06-15 12:20 129624 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mmpprtc.dll
2010-06-12 22:50 . 2010-06-12 22:50 53248 ----a-r- c:\documents and settings\Brent\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-06-12 12:15 . 2010-06-12 12:15 45056 ----a-r- c:\documents and settings\Brent\Application Data\Microsoft\Installer\{6815FCDD-401D-481E-BA88-31B4754C2B46}\ARPPRODUCTICON.exe
2010-06-10 02:04 . 2007-08-17 15:11 -------- d-----w- c:\documents and settings\Brent\Application Data\DivX
2010-06-09 03:02 . 2005-12-12 02:46 -------- d-----w- c:\program files\Ventrilo
2010-06-08 06:12 . 2010-05-07 04:47 57344 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-08 06:12 . 2010-05-07 04:43 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX
2010-06-08 06:10 . 2010-01-08 03:23 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-06-08 06:10 . 2007-08-17 15:07 -------- d-----w- c:\program files\DivX
2010-06-08 06:10 . 2010-06-08 06:10 56765 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-06-08 06:10 . 2010-06-08 06:10 56997 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-08 06:10 . 2010-06-08 06:10 53600 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Update\Uninstaller.exe
2010-06-08 06:10 . 2010-06-08 06:10 57715 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Player\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 84062 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 57054 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54166 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 57532 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 56458 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54174 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54153 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54128 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Converter\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54644 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 54101 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-08 06:09 . 2010-06-08 06:09 56969 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-06-08 06:04 . 2010-05-07 04:47 1062184 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Setup\Resource.dll
2010-06-08 06:04 . 2010-05-07 04:47 895256 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Setup\DivXSetup.exe
2010-05-31 16:15 . 2010-05-31 15:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit
2010-05-31 16:07 . 2008-05-16 19:32 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2010-05-14 22:04 . 2010-05-14 22:04 23904 ----a-w- c:\windows\system32\drivers\lvuvcflt.sys
2010-05-14 22:04 . 2010-05-14 22:04 6842592 ----a-w- c:\windows\system32\drivers\lvuvc.sys
2010-05-14 22:03 . 2010-05-14 22:03 539232 ----a-w- c:\windows\system32\LVUI2RC.dll
2010-05-14 22:03 . 2010-05-14 22:03 543328 ----a-w- c:\windows\system32\LVUI2.dll
2010-05-14 22:02 . 2010-05-14 22:02 276448 ----a-w- c:\windows\system32\drivers\lvrs.sys
2010-05-14 22:02 . 2010-05-14 22:02 114784 ----a-w- c:\windows\system32\drivers\lvpopflt.sys
2010-05-14 21:59 . 2010-05-14 21:59 203360 ----a-w- c:\windows\system32\lvci1301783.dll
2010-05-14 21:59 . 2010-05-14 21:59 416352 ----a-w- c:\windows\system32\lvcodec2.dll
2010-05-14 21:56 . 2010-05-14 21:56 10830680 ----a-w- c:\windows\system32\LogiDPP.dll
2010-05-14 21:56 . 2010-05-14 21:56 102744 ----a-w- c:\windows\system32\LogiDPPApp.exe
2010-05-14 21:55 . 2010-05-14 21:55 290648 ----a-w- c:\windows\system32\DevManagerCore.dll
2010-05-14 21:47 . 2010-05-14 21:47 266828 ----a-w- c:\windows\system32\drivers\LVAFT.cfg
2010-05-14 21:46 . 2010-05-14 21:46 37518 ----a-w- c:\windows\system32\Repository.reg
2010-05-12 20:42 . 2010-05-12 20:42 46904 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech\LWS\PrivacyShades\LWS_PrivacyShade_Uninstall.exe
2010-05-08 06:54 . 2010-05-08 06:54 -------- d-----w- c:\documents and settings\Brent\Application Data\eMusic
2010-05-08 00:50 . 2010-05-08 00:50 299352 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech\LWS\Filters\VMSEF.dll
2010-05-08 00:48 . 2010-05-08 00:48 6915416 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech\LWS\Filters\MMSEF.dll
2010-05-08 00:46 . 2010-05-08 00:46 14168 ----a-w- c:\windows\system32\drivers\iKeyLFT2.dll
2010-05-08 00:43 . 2010-05-08 00:43 25824 ----a-w- c:\windows\system32\drivers\LVPr2Mon.sys
2010-05-08 00:30 . 2010-05-08 00:30 85302 ----a-w- c:\windows\system32\drivers\LVFeL102.cfg
2010-05-08 00:30 . 2010-05-08 00:30 227172 ----a-w- c:\windows\system32\drivers\LVFeL100.cfg
2010-05-08 00:30 . 2010-05-08 00:30 146680 ----a-w- c:\windows\system32\drivers\LVFeL101.cfg
2010-05-08 00:29 . 2010-05-08 00:29 69592 ----a-w- c:\windows\system32\drivers\LVFaL100.cfg
2010-05-07 04:47 . 2010-05-07 04:47 57409 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-07 04:47 . 2010-05-07 04:47 52963 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-07 04:46 . 2010-05-07 04:46 54073 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-06 02:57 . 2010-04-19 04:18 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-05-06 02:57 . 2010-04-19 04:18 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-04-27 18:40 . 2007-10-26 22:31 45648 ------w- c:\windows\system32\drivers\PxHelp20.sys
2010-04-27 18:40 . 2007-10-26 22:31 133616 ------w- c:\windows\system32\pxafs.dll
2010-04-27 18:40 . 2007-10-26 22:31 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-04-27 18:40 . 2007-10-26 22:31 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-04-24 16:47 . 2010-04-24 16:47 86016 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS\Adobe_Downloads\arh.exe
2010-04-19 04:31 . 2010-04-19 04:31 932368 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2010-04-19 04:31 . 2010-04-19 04:31 678416 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2010-04-19 04:31 . 2010-04-19 04:31 604688 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2010-04-19 04:31 . 2010-04-19 04:31 522768 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2010-04-19 04:31 . 2010-04-19 04:31 1096208 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2010-04-19 04:30 . 2009-05-24 20:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2010-04-19 04:30 . 2010-04-19 04:30 59920 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd.dll
2010-04-19 04:30 . 2010-04-19 04:30 264720 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\klwtbbho.dll
2010-04-19 04:30 . 2010-04-19 04:30 109072 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd3.dll
2010-04-19 04:30 . 2010-04-19 04:30 296976 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\sys\i386\5.1\klif.sys
2010-04-19 04:30 . 2010-04-19 04:30 128016 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\sys\i386\kl1.sys
2010-04-19 04:20 . 2010-04-19 04:20 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2010-04-11 05:03 . 2010-04-11 05:03 73000 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-03-21 01:29 . 2010-03-21 02:34 83010552 ----a-w- c:\program files\avg_free_stf_en_90_790a2730.exe
2004-07-22 15:51 . 2004-07-22 15:51 3432656 -c--a-w- c:\program files\ManagedDX.CAB
2004-07-20 03:58 . 2004-07-20 03:58 1156363 -c--a-w- c:\program files\BDANT.cab
2004-07-20 03:53 . 2004-07-20 03:53 976020 -c--a-w- c:\program files\BDAXP.cab
2004-07-09 19:17 . 2004-07-09 19:17 13265040 -c--a-w- c:\program files\dxnt.cab
2004-07-09 14:13 . 2004-07-09 14:13 15493481 -c--a-w- c:\program files\DirectX.cab
2004-07-09 14:13 . 2004-07-09 14:13 703080 -c--a-w- c:\program files\BDA.cab
2004-07-09 09:08 . 2004-07-09 09:08 472576 -c--a-w- c:\program files\dxsetup.exe
2004-07-09 09:08 . 2004-07-09 09:08 2242560 -c--a-w- c:\program files\dsetup32.dll
2004-07-09 08:03 . 2004-07-09 08:03 62976 -c--a-w- c:\program files\DSETUP.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2009-12-01 6373376]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-10-03 323392]
"Logitech Vid HD"="c:\program files\Logitech\Vid\vid.exe" [2010-05-11 6061400]
"Logitech Vid"="c:\program files\Logitech\Vid\Vid.exe" [2010-05-11 6061400]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-20 149024]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"PrinTray"="c:\windows\System32\spool\DRIVERS\W32X86\2\printray.exe" [2001-03-27 36864]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-08 165208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-05-25 303376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2009-12-01 6373376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2003-03-31 40960]

c:\documents and settings\Brent\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Logitech\Ereg\eReg.exe [2009-11-16 517384]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
U.S. Robotics 802.11g Wireless Network Utility.lnk - c:\u.s.r.turbogwlan\USRWLANG.exe [2008-6-27 806912]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\freecell.exe"=
"c:\\WINDOWS\\system32\\mshearts.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Seagate\\Schedule2\\schedhlp.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"i:\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\Brent\\My Documents\\Torrent Music\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"i:\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\Logitech\\Vid\\Vid.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundRouterRequest"= 0 (0x0)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [12/15/2008 7:41 PM 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/13/2009 4:46 PM 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [5/16/2009 7:59 PM 19472]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/22/2008 6:16 AM 717296]
.
Contents of the 'Scheduled Tasks' folder

2010-06-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Brent\Application Data\Mozilla\Firefox\Profiles\vbripgx3.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - bboy.org
FF - prefs.js: keyword.URL - hxxp://tmq.bingstart.com/s/?src=FF-Address&site=Bing&cfg=2-168-0-1j2rR&q=
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-30 12:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1752)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(4144)
c:\windows\system32\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Seagate\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-06-30 12:24:35 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-30 18:24
ComboFix2.txt 2010-06-29 02:40
ComboFix3.txt 2008-06-04 19:12
ComboFix4.txt 2008-05-22 12:57

Pre-Run: 2,207,137,792 bytes free
Post-Run: 2,265,051,136 bytes free

Current=9 Default=9 Failed=6 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
- - End Of File - - F5710F50224DDBCA870AAE7C09AF0184

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
Hello.

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

Run ESET Online Scan
Please do an online scan with ESET Online Scanner. Please use Internet Explorer as it uses ActiveX.

  • Check (tick) this box: YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • When prompted to run ActiveX. click Yes.
  • You will be asked to install an ActiveX. Click Install.
  • Once installed, the scanner will be initialized.
  • After the scanner is initialized, click Start.
  • Check (tick) Remove found threats box.
  • Check (tick) Scan unwanted applications.
  • Click on Scan.
  • It will start scanning. Please be patient.
  • Once the scan is done, the log will be saved here: C:\Program Files\esetonlinescanner\log.txt.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=5090b00ac01c7b4f911f27887949613c
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-06-30 09:51:26
# local_time=2010-06-30 03:51:26 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1280 16777175 100 0 5359755 5359755 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=72650
# found=0
# cleaned=0
# scan_time=2716

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
How is the machine running now?

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
It's running just fine now, but ventrilo client still tells me I can't access the item.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
Hello.

Please download LockSearch.

  • A window will pop up, Press 2 and then Enter. A scan will start, let it run uninterrupted. It should only take a few minutes.
  • A log will appear when it is finished, it will also be saved in the same location as LockSearch, which should be on your desktop.
  • Post the contents of the log in your reply.

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
LockSearch by jpshortstuff (05.11.09.1)
Log created at 14:45 on 01/07/2010 (Brent)
Scanning C:\


C:\pagefile.sys
-------------------------

-=E.O.F=-

description"You may not have the appropriate permission to access this item." EmptyRe: "You may not have the appropriate permission to access this item."

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum