InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1351. |
Solve : Is this to much protection? |
|
Answer» Hello i was wondering if this is to much protection and if having all of these could give less protection |
|
| 1352. |
Solve : Microsoft's Free Anti Virus Suite Arriving Soon? |
| Answer» http://www.pcpro.co.uk/news/security/351739/microsofts-free-antivirus-suite-arriving-in-weeksI hope it works better than that crappy one care they made.Personally I'll stick with Kaspersky. While I know there are some fine free AV utilities, I've always FELT that VIRUS PROTECTION is not something to buy based on cost. | |
| 1353. |
Solve : AuthUpdater message...what is it?? |
|
Answer» I also had this pop up SAYING "AuthUpdater has encountered a problem and needs to CLOSE." It created an error report and happened approximately every 30 seconds or so. I DISCOVERED that it is a problem with Bigpond Security. You need to call 133 933 and they will talk you through uninstalling the software and REINSTALLING it again. You will need your Activation code, but don't worry if you don't have it anymore as they will read it back out to you. |
|
| 1354. |
Solve : an unhandled win32 exception occurred in svchost.exe? |
|
Answer» currently i m using XP professional OS version 2002 (SP2).
I can see some temp viruses. cat-bomb , you should not be giving advice you are not a malware expert karan_21584 , if you have 2 anti-virus in your pc please remove 1 of them i checked your logs and you seem to have a lot of threats BUT you need an expert to help youi have only one anti virus... NAV. i removed nav and processed. the same problem occur. again i installed avg ANTIVIRUS. again the same problem remains. while i m shut-down the machine "umdmgr.exe" is occuring many times. if i give "end now" then only the SYSTEM gettin shutdown or restart. is that major problem? help me plz. moreover if i click the any page link (mozilla browser) for 10-15 times, the page getting loaded (that too rare case). help mehttp://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039/ you must have had norton in your pc at one time use this to clean it out you will have to wait for an expert i can do a little to help but do not want to HARM your pc , harryHello Karan, My name is Superdave but you can just CALL me SD. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your replies. The first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the internet with your infected computer you will have to download and transfer any PROGRAMS to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please copy and paste any logs that you can generate.nice to see you on board superdave |
|
| 1355. |
Solve : What is proxy server? |
|
Answer» This poped up what is it and is it anything to worry about The proxy desktop is related to windows Explorer freezing. If you open Task Manager you should see multiple instances of Explorer.exe. Ending the processes in Task Manager should stop the error message. |
|
| 1356. |
Solve : malware and viruses? |
|
Answer» Yesterday my computer all of a sudden restarted and was then stuck in a restart loop. It went to the option to use safe mode so i selected the option to use the last known working settings which fixed the restart loop. After that i tried to scan for viruses/malware/spyware with spybot and malwarebytes neither of which will work. malwarebytes will start scan for about 2-5 seconds then closes and when i try to open it it tells me i dont have permissions. spybot tells me that spybotsd.exe is read only and wont install or run. i used combofix to create a log which is here:
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file). ---------- Also please try running this online scan: http://www.superantispyware.com/onlinescan.html Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log from it and post it in the next reply. ----- Next post please add:
|
|
| 1357. |
Solve : generic host process for win32 services has encountered a problem and needs to c? |
|
Answer» generic HOST process for win32 services has encountered a problem and needs to close, i ALWAYS recieve this message everytime i open my computer, when it accurs i will be disconnected to the network, and my audio also will be lost. |
|
| 1358. |
Solve : Amature in need of malware removal help? |
|
Answer» I have somehow downloaded a virus or malware and it keeps opening porn icons on my desktop I've tried to scan it with my trend MICRO INTERNET security it gets to 41% and the current target it stops at is, HKLM\SOFTWARE\Cla...539c680f,',1.1) then wont go no further. I tried the procedures under malware removal and the program starts the scan gets so far then stops with no log files. Then when i try to run the program again i get a message that says (Windows cannot access the specified device, path, or file. You may not have permission to access them.) Any help with my problem WOULD be much appreciated thank you.Try DOWNLOADING ubuntu and burning it to a CD on another computer. Then BOOT from the Ubuntu CD and use it as a live CD (don't install). When it boots put Avast or Malwarebytes on it and use it to scan your hard drive. |
|
| 1359. |
Solve : Can't download and run malwarebytes and explorer opens windows by itself.? |
|
Answer» I had malwarebytes' anti-malware on my computer before. After a trip to myspace my computer started running very slow and explorer opens by itself, even when i am running firefox. I have been back to the malwarebytes WEBSITE and tried to download it again and i get an error message: download the c batch file.I'm not sure what file you're talking about. Quote When I try to open up my taskmanager, i get the message that it has been disabled by my administrator!This is a sure sign of infection. If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate. |
|
| 1360. |
Solve : Search engines rerouting to different sites? |
|
Answer» I've read pretty much everything and done pretty much everything about this problem. I have Norton Antivirus 2009, and have used Avast! antivirus, I have and have used spybot search and destroy, and have used Malwarebytes, I have used hijack this and killbox and all that other crap but nothing works. I am using windows vista business, and now everytime i restart my computer, there is a blue screen which says "error_page_nonpage_area" or something along those lines, and will not restart until i put in the windows vista business install cd. The black "start windows normally, etc" screen says 1)put in the OS install cd, 2) select language and click next, 3) click "repair my computer." I have not done that YET, as the computer starts up when I put the cd into the drive. The reason I haven't done that yet is because I fear I will have to do it every time I attempt to get rid of this virus, SINCE nothing works. Go to the malware forum on this site and follow the instructions at the top of that forum.SAS log: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 12/26/2009 at 09:01 PM Application Version : 4.32.1000 Core Rules Database Version : 4412 Trace Rules Database Version: 2243 Scan type : Complete Scan Total Scan Time : 06:43:55 Memory items scanned : 745 Memory threats detected : 0 Registry items scanned : 7212 Registry threats detected : 9 File items scanned : 469292 File threats detected : 283 Rogue.AntiVirusPlus HKLM\Software\Classes\CLSID\{C2B5AAB8-2183-4be7-81A6-F11493C45872} HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2B5AAB8-2183-4be7-81A6-F11493C45872} HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2B5AAB8-2183-4BE7-81A6-F11493C45872} HKU\S-1-5-21-3593084958-1206254983-1428058218-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2B5AAB8-2183-4BE7-81A6-F11493C45872} HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2B5AAB8-2183-4BE7-81A6-F11493C45872} HKCR\CLSID\{C2B5AAB8-2183-4BE7-81A6-F11493C45872} HKCR\CLSID\{C2B5AAB8-2183-4BE7-81A6-F11493C45872}\InProcServer32 HKCR\CLSID\{C2B5AAB8-2183-4BE7-81A6-F11493C45872}\InProcServer32#ThreadingModel Adware.Tracking Cookie C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Cookies\pat[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Users\Patrick McMahon\Cookies\[email protected][2].txt C:\Users\Patrick McMahon\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected]rld[2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected]ultfriendfinder[1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected]questionmarket[1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt Trojan.Agent/Gen C:\Windows\system32\critical_warning.html C:\Windows\system32\winhelper86.dll Rogue.InternetSecurity2010 HKU\S-1-5-21-3593084958-1206254983-1428058218-1000\Software\IS2010 C:\Program Files\InternetSecurity2010 C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Start Menu\Internet Security 2010.lnk C:\Users\Patrick McMahon\Start Menu\Internet Security 2010.lnk Rogue.Agent/Gen-Nullo[DLL] C:\WINDOWS\SYSTEM32\BIBOSUYI.DLL C:\WINDOWS\SYSTEM32\BOFUJIDE.DLL C:\WINDOWS\SYSTEM32\DASULELO.DLL C:\WINDOWS\SYSTEM32\DUMOPIPE.DLL C:\WINDOWS\SYSTEM32\DURIBEGI.DLL C:\WINDOWS\SYSTEM32\FOSINOWA.DLL C:\WINDOWS\SYSTEM32\HEGUYAZO.DLL C:\WINDOWS\SYSTEM32\HIGEWOMU.DLL C:\WINDOWS\SYSTEM32\HOGUDARU.DLL C:\WINDOWS\SYSTEM32\HOVIVUYI.DLL C:\WINDOWS\SYSTEM32\HUVOMIFI.DLL C:\WINDOWS\SYSTEM32\JUBATEYA.DLL C:\WINDOWS\SYSTEM32\KANAGULE.DLL C:\WINDOWS\SYSTEM32\KUFOMAHI.DLL C:\WINDOWS\SYSTEM32\LABESUFI.DLL C:\WINDOWS\SYSTEM32\LIMOWUYU.DLL C:\WINDOWS\SYSTEM32\LIRUTOGA.DLL C:\WINDOWS\SYSTEM32\LITABIRU.DLL C:\WINDOWS\SYSTEM32\LIVIWEGU.DLL C:\WINDOWS\SYSTEM32\NAKUWIYI.DLL C:\WINDOWS\SYSTEM32\NAWEMONA.DLL C:\WINDOWS\SYSTEM32\PEFEPISA.DLL C:\WINDOWS\SYSTEM32\POHUNAZI.DLL C:\WINDOWS\SYSTEM32\RIYIGABU.DLL C:\WINDOWS\SYSTEM32\SAFIMUSI.DLL C:\WINDOWS\SYSTEM32\SANITUTU.DLL C:\WINDOWS\SYSTEM32\SULEKIPI.DLL C:\WINDOWS\SYSTEM32\TILAKIPU.DLL C:\WINDOWS\SYSTEM32\VAKAKAYU.DLL C:\WINDOWS\SYSTEM32\VETAGAMA.DLL C:\WINDOWS\SYSTEM32\VINOKUNI.DLL C:\WINDOWS\SYSTEM32\WELIMALA.DLL C:\WINDOWS\SYSTEM32\WIDUJUDA.DLL C:\WINDOWS\SYSTEM32\WUHELIDI.DLL C:\WINDOWS\SYSTEM32\YUZOKEWA.DLL C:\WINDOWS\SYSTEM32\ZOKEFAFO.DLL Rogue.Agent/Gen-Nullo[EXE] C:\WINDOWS\SYSTEM32\NULORAKU.EXE Mbam log: Malwarebytes' Anti-Malware 1.42 Database version: 3437 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 12/27/2009 12:34:02 AM mbam-log-2009-12-27 (00-34-02).txt Scan type: Quick Scan Objects scanned: 96898 Time elapsed: 6 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 3 Registry Data Items Infected: 5 Folders Infected: 0 Files Infected: 23 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\notepad (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\notepad (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Windows\System32\bazahabe.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\bikobaka.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\dobapoda.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\fimijole.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\giniduna.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\gitubazo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\jiyegine.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\mifuwape.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\nonituwo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\papororo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\pawehuhe.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\pinigati.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\winiyavi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\yewohosi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\System32\zujedafu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Windows\system32\Drivers\ucchpibq.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\Users\Patrick McMahon\AppData\Roaming\avp.ico (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully. C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Windows\System32\notepad.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\Temp\nsrbgxod.bak (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Windows\System32\AVR10.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Users\Patrick McMahon\ntload.dll (Trojan.Agent) -> Quarantined and deleted successfully. HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:47:15 AM, on 12/27/2009 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v7.00 (7.00.6002.18005) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Windows\OEM02Mon.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\System32\rundll32.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Steam\Steam.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe C:\Program Files\Uniblue\DriverScanner\DriverScanner.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HijackThis\Sniper.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O1 - Hosts: ::1 localhost127.0.0.1 thepiratebay.org O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {28134def-d748-436c-9fcb-e8af34670009} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O8 - Extra CONTEXT menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O13 - Gopher Prefix: O16 - DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345} (Symantec Configuration Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlcm.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll O20 - AppInit_DLLs: jegofoto.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe -- End of file - 7046 bytes do you need anymore information? So i'm screwed?Now I have to reformat my computer because no one here was nice enough to actually help me with my problem. I only have one day left until I NEED this problem fixed, BUT I didn't post logs in the first post (even though I had done all you had said to do earlier, and none of it worked), so you decided I was just another little retarded punk who didn't know what was going on...thank you so very much for your time. Quote from: vikingkid3 on December 28, 2009, 10:22:38 PM Now I have to reformat my computer because no one here was nice enough to actually help me with my problem. ... Please contact the accounts department. You are entitled to a full refund of your enrolment fee. However, did you read the instructions properly? If so, why have you bumped 3 times? (Over Christmas!) Like, duh! Quote We also request patience. The Experts here are Volunteers and are not here 24/7. This is not a live session either. If it takes a few hours or overnight for them to get back to you, trust me it is worth the wait. See here* why not to not bump your thread. Quote *WHEN YOU BUMP YOUR THREAD OR ADD UNNECESSARY POSTS YOU LENGTHEN THE TIME TO GET A RESPONSE!vikingkid3, I'm sorry for the delay. It's been a very busy couple of weeks. Do you still need help? |
|
| 1361. |
Solve : browser redirects? |
|
Answer» Dave - You really super. No redirects and computer SEEMS to be operating properly. Is there anything a lay person can do (besides just saying thank you) to insure that the INVALUABLE help that you and this website will carry on ? Thank you very much ! Is there anything a lay person can do (besides just saying thank you) to insure that the INVALUABLE help that you and this website will carry on ? Thank you very much !Thank you. The only thing you need to do is to spread the word about us and to help someone else in whatever way you can. If there are no other issues, we can do some cleanup. To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
**************************************************** To set a new Restore Point. Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard DISK, clear the check box next to the disk, and then click OK. Reboot to Normal Mode. Click the Start button , click Control Panel, click System and Maintenance, and then click System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK. This will give you a new, clean Restore Point. ******************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have SAVED all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ***************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ***************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything LISTED. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's EASY and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 1362. |
Solve : Laptop mouse not responding? |
|
Answer» The mouse on my laptop is not working at all. |
|
| 1363. |
Solve : potential malware? |
|
Answer» Quote I still need to reinstall antivirus, is there a preference between avast or avg?You can choose from this list below. I, myself, prefer MicroSoft Security Essentials. Very efficient, updates automatically and not a resource hog. Remember to only install one antivirus! 1) Avast! Home Edition 2) AVG Free Edition 3) Avira AntiVir Personal 4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download 4-a) Microsoft Security Essentials for Windows XP 5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one) 6) PC Tools AntiVirus Free Edition It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time. ******************************************** Please run Notepad (start > All Programs > Accessories > Notepad) and copy and paste the text in the CODE box into a new file: Code: [Select]echo off >Log1.txt ( ipconfig /all nslookup google.com nslookup yahoo.com ping -n 2 google.com ping -n 2 yahoo.com route print ) start Log1.txt del %0 •Go to the File menu at the top of the Notepad and select Save as. •Select save in: desktop •Fill in File name: test.bat •Save as type: All file types (*.*) •Click save. •Close the Notepad. •Locate and double-click test.bat on the desktop. •A notepad opens, copy and paste the content it (log1.txt) to your reply. Windows IP Configuration Host Name . . . . . . . . . . . . : cgeiger-PC Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : launchmodem.com Ethernet adapter LOCAL Area Connection: Connection-specific DNS Suffix . : launchmodem.com Description . . . . . . . . . . . : NVIDIA nForce Networking Controller Physical Address. . . . . . . . . : 00-1A-92-13-01-71 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::15b3:2ca9:7d55:787d%8(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.1.97(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : Saturday, April 02, 2011 2:44:05 PM Lease Expires . . . . . . . . . . : Sunday, April 03, 2011 2:44:05 PM Default Gateway . . . . . . . . . : 192.168.1.254 DHCP Server . . . . . . . . . . . : 192.168.1.254 DHCPv6 IAID . . . . . . . . . . . : 201332979 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-0D-21-C2-1C-00-1A-92-13-01-71 DNS Servers . . . . . . . . . . . : 192.168.1.254 192.168.1.254 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter Local Area Connection* 6: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : isatap.launchmodem.com Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Local Area Connection* 7: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 02-00-54-55-4E-01 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:8ac:730:3f57:fe9e(Preferred) Link-local IPv6 Address . . . . . : fe80::8ac:730:3f57:fe9e%9(Preferred) Default Gateway . . . . . . . . . : :: NetBIOS over Tcpip. . . . . . . . : Disabled Tunnel adapter Local Area Connection* 11: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : launchmodem.com Description . . . . . . . . . . . : isatap.launchmodem.com Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Server: launchmodem Address: 192.168.1.254 Name: google.com Addresses: 74.125.45.147 74.125.45.99 74.125.45.103 74.125.45.106 74.125.45.105 74.125.45.104 Server: launchmodem Address: 192.168.1.254 Name: yahoo.com Addresses: 69.147.125.65 72.30.2.43 98.137.149.56 209.191.122.70 67.195.160.76 Pinging google.com [74.125.45.147] with 32 bytes of data: Reply from 74.125.45.147: bytes=32 time=12ms TTL=52 Reply from 74.125.45.147: bytes=32 time=12ms TTL=52 Ping statistics for 74.125.45.147: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 12ms, Maximum = 12ms, Average = 12ms Pinging yahoo.com [209.191.122.70] with 32 bytes of data: Reply from 209.191.122.70: bytes=32 time=73ms TTL=49 Reply from 209.191.122.70: bytes=32 time=69ms TTL=49 Ping statistics for 209.191.122.70: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 69ms, Maximum = 73ms, Average = 71ms =========================================================================== Interface List 8 ...00 1a 92 13 01 71 ...... NVIDIA nForce Networking Controller 1 ........................... Software Loopback Interface 1 12 ...00 00 00 00 00 00 00 e0 isatap.launchmodem.com 9 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface 13 ...00 00 00 00 00 00 00 e0 isatap.launchmodem.com =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.97 20 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.1.0 255.255.255.0 On-link 192.168.1.97 276 192.168.1.97 255.255.255.255 On-link 192.168.1.97 276 192.168.1.255 255.255.255.255 On-link 192.168.1.97 276 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.1.97 276 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.1.97 276 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 9 18 ::/0 On-link 1 306 ::1/128 On-link 9 18 2001::/32 On-link 9 266 2001:0:4137:9e76:8ac:730:3f57:fe9e/128 On-link 8 276 fe80::/64 On-link 9 266 fe80::/64 On-link 9 266 fe80::8ac:730:3f57:fe9e/128 On-link 8 276 fe80::15b3:2ca9:7d55:787d/128 On-link 1 306 ff00::/8 On-link 9 266 ff00::/8 On-link 8 276 ff00::/8 On-link =========================================================================== Persistent Routes: None Sure do appreciate your help and patience! Will run the first essentials scan after I get this to you, would also like to know your thougths on upgrading to 7 after we fix allOk. We need to clear your DNS cache. Please navigate to Start>Run and type cmd in the window that pops up type ipconfig /flushdns Now try to see if IE works in Normal Mode. I could only do the flush in safe mode, so IE shut down after beginning to open in regular mode (the installer window continues to run as well, saying the network source is no longer available, for an .msi file) in regular mode it said it needed elevation?wow, I just did a reset of EI and now it is working in regular, still got the elevation notice and the REPETITIVE insstaller. Will intall WOT and and I think you recommended cc slim?, will wait for the other cleaning til I hear from you, thanks!During Comodo install the options to uncheck did not come up, there were 3 versions to choose from, think I chose the middle and the GEEK Buddy? Quote During Comodo install the options to uncheck did not come up, there were 3 versions to choose from, think I chose the middle and the Geek Buddy?Sorry, I'm not familiar with Comodo AV. Quote still got the elevation notice and the repetitive insstaller.I'm sure this is not malware related. Perhaps you could ask this question in the proper software forum. Please let me know when you're finished with the clean up so I can lock this thread.Sorry, it is the comodo firewall, not the AV Quote Sorry, it is the comodo firewall, not the AVIt shouldn't matter from where you downloaded it; they should all be the same. This link that I gave you is a old canned speech. They must have changed the program. I don't remember those options when I installed my Comodo Firewall. Clean up is done! Thanks SuperDave!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 1364. |
Solve : How to get rid of iMesh?? |
|
Answer» Howdy people, |
|
| 1365. |
Solve : Everytime I try to open a program, I'm prompted to "Open With"? |
|
Answer» So... I've looked at the criteria for posting and recieving help, and I've tried to download and run the programs necessary... but even when I try to do that, I still end up staring perplexed at the "Open With" window, and can't run the programs. Thank you so much! So it did work? Now it would be good to determine why this happened. Download TrendMicro HijackThis.exe (HJT) to the desktop. * Double-click on HJTInstall. * Click on the Install button. * It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. * Upon install, HijackThis should open for you. * Important! If using Windows Vista or Windows 7, close HijackThis. Now right-click HijackThis and Run As Administrator * Click on the Do a system scan and SAVE a log file button * HijackThis will scan and then a log will open in notepad. * Copy and then paste the entire contents of the log in your post. * Do not have HijackThis fix ANYTHING yet. Most of what it finds will be harmless or even required. |
|
| 1366. |
Solve : Trojan.Vundo-Variant/F C:\WINDOWS\SYSWOW64\DESW32DL.DLL? |
|
Answer» I have been using Microsoft Security Essentials which did not FIND this file with a complete SCAN. So I uninstalled MSE and INSTALLED AVG 2011 version10.0.1209. AVG did find the file (corrupted executable file) and it is now in the AGV 'virus vault'. Is it safe to keep this file as is - in the AVG virus vault - or is further action needed?It's safe in the vault or, if you WISH, you can empty the vault. Edited. |
|
| 1367. |
Solve : Spy/mal-ware infection on my vista desktop, unable to get on internet, etc.? |
|
Answer» I un-installed the AVG.Free 9.0. R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 netr7364;Linksys Compact Wireless-G USB Adapter Driver for Vista;c:\windows\system32\DRIVERS\WUSB54GCx64.sys R3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768] R4 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2009-06-23 109168] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2010-11-30 135336] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [2011-02-16 101048] S3 LVUVC64;Logitech Webcam 500(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\DRIVERS\WUSB54GCv3.sys . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-06 10:38] . 2011-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-06 10:38] . 2011-04-03 c:\windows\Tasks\User_Feed_Synchronization-{79662777-9144-4FDC-9878-A688B6B1948B}.job - c:\windows\system32\msfeedssync.exe [2011-02-14 04:47] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [X] "combofix"="c:\combofix\CF13003.cfxxe" [X] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.ca/ uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://www.yahoo.com/ mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://ca.search.yahoo.com/search?fr=mcafee&p=%s IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\769657z5.default\ FF - prefs.js: browser.search.selectedEngine - Secure Search FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b8497d4&v=6.103.018.001&i=23&tp=ab&iy=&ychte=ca&lng=en-GB&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files (x86)\McAfee\SiteAdvisor FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . - - - - ORPHANS REMOVED - - - - . Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) Wow6432Node-HKLM-Run-WindowsLiveDeviceIntegrator - c:\program files (x86)\Windows Live\Device Integrator\wldi.exe SafeBoot-mcmscsvc SafeBoot-MCODS WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - (no file) AddRemove-sp44626 - c:\hp\Softpaq\sp44626\sp44626.exe AddRemove-WindowsLiveDeviceIntegrator - c:\program files (x86)\Windows Live\Device Integrator\InstallDI.exe AddRemove-WinLiveSuite - c:\program files (x86)\Windows Live\Installer\wlarp.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] ="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] ="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] ="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] ="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] ="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] Denied: (A 2) (Everyone) ="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] ="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] Denied: (A 2) (Everyone) ="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] ="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\ACR0065\4&98671ce&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] DACL=(02 0000) . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\ACR0065\4&98671ce&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] DACL=(02 0000) . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\4&98671ce&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] DACL=(02 0000) . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\4&98671ce&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] DACL=(02 0000) . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26A8\4&98671ce&0&UID16843008\Device Parameters\MODES] DACL=(02 0000) . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26A8\4&98671ce&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] DACL=(02 0000) . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26A8\4&98671ce&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] DACL=(02 0000) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\windows\SysWOW64\rundll32.exe . ************************************************************************** . Completion time: 2011-04-03 22:09:37 - machine was rebooted ComboFix-quarantined-files.txt 2011-04-04 02:09 . Pre-Run: 376,976,920,576 bytes free Post-Run: 376,517,332,992 bytes free . - - End Of File - - 0F2952DAFA973D05741C739009A56F27 Please download the Sophos Anti-Rootkit Scanner and save it to your desktop. You will need to enter your name, e-mail address and location in order to access the download page.
Won't let me checkmark "Running Processes". [/url]Ok. Please try this: Please download Rooter and Save it to your desktop.
Won't work. That's weird. Please try this one to see if it will work. SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
I got that pop up and I put run under Administrator. So I'm not sure if the log showed everything. SysProt AntiRootkit v1.0.1.0 by swatkat ****************************************************************************************** ****************************************************************************************** No Hidden Processes found ****************************************************************************************** ****************************************************************************************** No Hidden Kernel Modules found ****************************************************************************************** ****************************************************************************************** No SSDT Hooks found ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** No hidden files/folders found I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt [email protected] as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK [email protected] as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6425 # api_version=3.0.2 # EOSSerial=161aeaa8969a0844a3567aa7a0e6a701 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-04-14 07:15:46 # local_time=2011-04-14 03:15:46 (-0500, Eastern Daylight Time) # country="Canada" # lang=4105 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=768 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777215 100 0 34903983 34903983 0 0 # compatibility_mode=1797 16775165 100 94 0 38396138 0 0 # compatibility_mode=5892 16776573 100 56 0 139401495 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=186383 # found=0 # cleaned=0 # scan_time=5757 How's your computer running now? Any other issues? |
|
| 1368. |
Solve : ROOT hacking? |
|
Answer» If someone were to hack your root, how would you make sure that you're rooted and what should you do to get it REMOVED? |
|
| 1369. |
Solve : How do you fix dll errors then? |
|
Answer» Want to know if you get a dll error what do you need to do to FIX it? Should you download the missing file? What if you cannot enter the internet then? Where do you copy the missing file to? Thanksi think this is in the wrong aria, this section os about PC viruses, you may need to POST this question somewere elce, SORRY for not beeing helpful. you can download the .dll FILES but they MIGHT not be the right vertion. |
|
| 1370. |
Solve : Need help...please? |
|
Answer» Quote Do I need to Delete the quarantined files? and also is this a program that I should uninstall or will I use it regularly from now on?You can wait about a week then empty the quarantine folder. Mp4 Player is supposed to be a safe application. How's your computer running now?Hey Dave, My computer seems pretty "normal". I can print fine now and the screen looks "normal" for a while it looked just odd. I have been using it and so far so good. I have not rebooted it for a day or so. It feels good to have it be "OK". Should I back it up now or wait a week to delete the quarantined files? Also, what do you suggest I as a virus protection. I use Malwarebytes every couple of weeks. Honestly I have never had any problems until this past week. Thanks. Quote Should I back it up now or wait a week to delete the quarantined files?If everything is running fine you can empty the quarantine folder. Quote Also, what do you suggest I as a virus protection. I use Malwarebytes every couple of weeks. Honestly I have never had any problems until this past week. First of all, you need a good, up-to-date Anti-Virus program and a third-party firewall. MBAM and SAS are good to run every so often. I will suggest some others when we are finished. One more scan, please. Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop. link # 1 Link # 2 If you are using Firefox, make sure that your download settings are as follows: * Tools->Options->Main tab * Set to "Always ask me where to Save the files". Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Right-click combofix.exe and select Run as Administrator and follow the prompts. When finished, ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete. Yeah, able to do both of those now ComboFix 11-04-15.06 - jjsangelandjan 04/16/2011 16:40:12.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3062.1786 [GMT -4:00] Running from: c:\users\jjsangelandjan\Desktop\ComboFix.exe SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\BSTIeprintctl1.dll c:\windows\system32\Packet.dll c:\windows\system32\pthreadVC.dll c:\windows\system32\WanPacket.dll c:\windows\system32\wpcap.dll . . ((((((((((((((((((((((((( Files Created from 2011-03-16 to 2011-04-16 ))))))))))))))))))))))))))))))) . . 2011-04-16 20:48 . 2011-04-16 20:49 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\Lisa Long\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\Hazel\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\Giving Works Today\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\Danielas Account\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\Bens Account\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\Roberts Account\AppData\Local\temp 2011-04-16 20:48 . 2011-04-16 20:48 -------- d-----w- c:\users\Administrator\AppData\Local\temp 2011-04-16 16:51 . 2011-04-16 16:51 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{26C05198-F838-40AB-82CC-5A7758DB2BE6} 2011-04-15 17:18 . 2011-02-22 13:24 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-04-15 16:50 . 2011-04-16 04:51 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{E23B81FE-69BB-4308-A2B8-5344BB8931C1} 2011-04-15 06:01 . 2011-03-15 04:05 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition UPDATES\{588CD8F9-C519-48D0-A67F-872FCB2670A1}\mpengine.dll 2011-04-14 21:58 . 2011-04-14 21:58 -------- d-----w- c:\program files\ESET 2011-04-13 02:10 . 2011-04-13 14:11 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{21B88FEE-85C9-4800-868D-B744E8938192} 2011-04-12 12:59 . 2011-04-12 12:59 -------- d-----w- c:\users\jjsangelandjan\AppData\Roaming\SUPERAntiSpyware.com 2011-04-12 12:59 . 2011-04-12 12:59 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2011-04-12 12:59 . 2011-04-12 12:59 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-04-11 01:47 . 2011-04-11 13:48 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{1BE5394E-D636-4DC3-B969-EBCA40A40D82} 2011-04-08 01:30 . 2011-04-10 13:32 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{93BDE59F-4BB9-4979-AA6E-86734974B9CA} 2011-04-06 10:04 . 2011-04-07 10:05 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{F742A92F-9581-4369-9336-D547166C376A} 2011-04-05 22:04 . 2011-04-05 22:04 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{33BDE833-9B1B-42C6-AE08-FCE7B62A873C} 2011-04-04 10:03 . 2011-04-05 10:03 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{3F64CE41-12A6-4ABB-8792-33437B8B4A00} 2011-04-03 22:00 . 2011-04-03 22:00 -------- d-----w- c:\users\Administrator\AppData\Roaming\HPAppData 2011-03-31 22:01 . 2011-04-03 22:03 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{8973526F-506B-44D8-B587-4EE36E0894D5} 2011-03-29 17:05 . 2011-03-31 05:06 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{38701BC8-0FE8-437A-9B11-DEA83A2E95E4} 2011-03-26 02:42 . 2011-03-26 02:42 -------- d-----w- c:\users\Public\summer_floral_48258 2011-03-25 23:48 . 2011-03-25 23:48 4284416 ----a-w- c:\windows\system32\GPhotos.scr 2011-03-23 12:56 . 2011-03-29 00:59 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{A4C4797D-0F19-4C78-B7C1-9A0AAE84986C} 2011-03-22 21:45 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-22 21:45 . 2011-02-22 13:33 1068544 ----a-w- c:\windows\system32\DWrite.dll 2011-03-22 21:45 . 2011-02-22 13:33 797696 ----a-w- c:\windows\system32\FntCache.dll 2011-03-21 09:30 . 2011-03-22 21:31 -------- d-----w- c:\users\jjsangelandjan\AppData\Local\{3AE8680E-5F41-4375-9506-FBBE49C8945B} . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-10 02:49 . 2010-06-24 16:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-02-02 22:11 . 2009-10-02 16:51 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-01-20 16:37 . 2011-02-09 04:29 638336 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2011-01-20 16:08 . 2011-02-09 04:29 478720 ----a-w- c:\windows\system32\dxgi.dll 2011-01-20 16:08 . 2011-02-09 04:29 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2011-01-20 16:08 . 2011-02-09 04:29 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2011-01-20 16:08 . 2011-02-09 04:29 1029120 ----a-w- c:\windows\system32\d3d10.dll 2011-01-20 16:08 . 2011-02-09 04:29 189952 ----a-w- c:\windows\system32\d3d10core.dll 2011-01-20 16:07 . 2011-02-09 04:29 37376 ----a-w- c:\windows\system32\cdd.dll 2011-01-20 16:07 . 2011-02-09 04:29 258048 ----a-w- c:\windows\system32\winspool.drv 2011-01-20 16:07 . 2011-02-09 04:29 586240 ----a-w- c:\windows\system32\stobject.dll 2011-01-20 16:06 . 2011-02-09 04:29 2873344 ----a-w- c:\windows\system32\mf.dll 2011-01-20 16:06 . 2011-02-09 04:29 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 16:04 . 2011-02-09 04:29 209920 ----a-w- c:\windows\system32\mfplat.dll 2011-01-20 16:04 . 2011-02-09 04:29 98816 ----a-w- c:\windows\system32\mfps.dll 2011-01-20 14:28 . 2011-02-09 04:29 1554432 ----a-w- c:\windows\system32\xpsservices.dll 2011-01-20 14:27 . 2011-02-09 04:29 876032 ----a-w- c:\windows\system32\XpsPrint.dll 2011-01-20 14:26 . 2011-02-09 04:29 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 14:25 . 2011-02-09 04:29 847360 ----a-w- c:\windows\system32\OpcServices.dll 2011-01-20 14:24 . 2011-02-09 04:29 135680 ----a-w- c:\windows\system32\XpsRasterService.dll 2011-01-20 14:15 . 2011-02-09 04:29 979456 ----a-w- c:\windows\system32\MFH264Dec.dll 2011-01-20 14:14 . 2011-02-09 04:29 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll 2011-01-20 14:14 . 2011-02-09 04:29 261632 ----a-w- c:\windows\system32\mfreadwrite.dll 2011-01-20 14:14 . 2011-02-09 04:29 302592 ----a-w- c:\windows\system32\mfmp4src.dll 2011-01-20 14:12 . 2011-02-09 04:29 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2011-01-20 14:11 . 2011-02-09 04:29 486400 ----a-w- c:\windows\system32\d3d10level9.dll 2011-01-20 13:47 . 2011-02-09 04:29 683008 ----a-w- c:\windows\system32\d2d1.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-05 1644088] "googletalk"="c:\users\jjsangelandjan\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-03-16 2423752] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536] "KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-10-24 107112] "osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2006-10-26 22696] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-04-19 151552] "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 133656] "QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2008-11-04 413696] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896] "iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-05 136600] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "Malwarebytes' Anti-Malware (reboot)"="e:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-25 44136] . c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216] . c:\users\Roberts Account\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216] . c:\users\Bens Account\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216] . c:\users\Hazel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216] . c:\users\Lisa Long\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216] . c:\users\jjsangelandjan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [2006-05-10 29696] R3 SoundMovieServer;SoundMovieServer;c:\windows\system32\snmvtsvc.exe [2008-06-04 184320] R3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648] R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20071204.001\IDSvix86.sys [2007-11-06 180272] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 208896] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2007-09-21 112688] S3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2006-11-22 336000] S3 MovRVDrv32;MovRVDrv32;c:\windows\system32\DRIVERS\MovRVDrv32.sys [2008-06-04 3768] S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2008-10-03 37936] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - COMHOST . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2011-04-16 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Lisa Long.job - c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2006-11-07 17:48] . 2011-04-15 c:\windows\Tasks\User_Feed_Synchronization-{FC857FE0-93F1-49AE-9D69-02E072DD5496}.job - c:\windows\system32\msfeedssync.exe [2011-04-15 04:43] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html FF - ProfilePath - c:\users\jjsangelandjan\AppData\Roaming\Mozilla\Firefox\Profiles\m8jvtigk.default\ FF - prefs.js: browser.startup.homepage - www.ipburger.com FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - ORPHANS REMOVED - - - - . WebBrowser-{D51D388B-F5DC-471A-A1CE-5E2D671091C0} - (no file) . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-04-16 16:49 Windows 6.0.6002 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Windows 6.0.6002 Disk: SAMSUNG_SP2504C rev.VT100-49 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-1 . device: opened successfully user: MBR read successfully kernel: MBR read successfully user != kernel MBR !!! sectors 488397166 (+255): user != kernel . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2011-04-16 16:52:43 ComboFix-quarantined-files.txt 2011-04-16 20:52 . Pre-Run: 98,973,835,264 bytes free Post-Run: 99,919,798,272 bytes free . - - End Of File - - CEA3191586138A204C013A4F60FF9073 here is the hijack log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:43:26 PM, on 4/16/2011 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.19048) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\hp\support\hpsysdrv.exe C:\WINDOWS\RtHDVCpl.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\igfxpers.exe E:\Program Files\QuickTime\QTTask.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe E:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\sdclt.exe C:\Windows\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe O4 - HKCU\..\Run: [googletalk] C:\Users\jjsangelandjan\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - E:\Program Files\SoundTaxi\YouTubeRipper.dll O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - E:\Program Files\SoundTaxi\YouTubeRipper.dll O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} (Auctiva Image Uploader Control) - http://www.auctiva.com/Aurigma/ImageUploader57.cab O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe O23 - Service: SoundMovieServer - SoundMovieServer - C:\Windows\system32\snmvtsvc.exe O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 11035 bytes The only thing I notice that is different now is the it seems to take FOREVER to boot up. I dont remember it ever taking so long. THANKS! Quote The only thing I notice that is different now is the it seems to take FOREVER to boot up. I dont remember it ever taking so long.I will include a program so you can look at and adjust what starts in startup. A couple of items to fix in HJT and we can do some cleanup. Open HijackThis and select Do a system scan only Place a check mark next to the following entries: (if there) O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ********************************************* StartupLite Download StartupLite by MalwareBytes to your Desktop. Doubleclick StartupLite.exe to launch the program. Ensure the Disable box is checked. Click Continue. A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer. Re-start your computer. **************************************** To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************* Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. **************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Hi Dave, I have done everything that you have suggested except the firewall. My vista fire wall is "ON" do you advise adding an additional firewall on top of that? My computer still takes a long time to boot up....it still seems longer than it used to but I have not used a couple of the clean up tools listed on the "SLOW computer" page that you suggested. I have used a program CALLED: "Clean up" by Steven Gould that seems to have worked well in the past....are you familiar with this? and if so is it adequate or would the "CCleaner" be better? I am planning to add another memory card here soon. Thanks again for your help and the clear easy to follow steps! Lisa Just a follow up...I updated my Spybot today and than ran a scan. It FOUND a trojan hiding as well. Is there anything else I should be running? Quote My computer still takes a long time to boot up....it still seems longer than it used to but I have not used a couple of the clean up tools listed on the "SLOW computer" page that you suggested.How much time are we talking about? Quote I have used a program called: "Clean up" by Steven Gould that seems to have worked well in the past....are you familiar with this? and if so is it adequate or would the "CCleaner" be better?Looks like a bit like CCleaner with a few more bells and whistles. Quote Is there anything else I should be running?You should keep SAS and MBAM. Update them and run them on a regular basis. Quote from: SuperDave on April 18, 2011, 12:04:57 PM How much time are we talking about? It takes it about 8 - 10 minutes to boot up, then another 5 - 6 minutes to open my main user up. I never timed it before but it seemed before to boot up in about 5 minutes and may be 3 - 4 minutes for the main user. Now, I have done all of the updates with the browsers and when it booted the last time, I wondered if this might have something to do with it....normally my computer is very fast. Otherwise other than getting used to the "new" look of the browsers things seem pretty fine. I used my system as NORMAL today Thanks!Did you find anything when you ran StartupLite? If there a lot of apps starting it can really slow things down.Yes, I removed about 8 things with the STARTUPLite! Here's a bunch of links concerning slow boot with Vista. I hope it helps.ok Great! You are a very valuable knowledgeable asset to this forum. Thanks for being willing to share that with all of us who struggle against these nasty virus'. No words to really express my gratitude! Take care You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 1371. |
Solve : Unable to open in safe mode due to virus? |
|
Answer» Can you tell me another way to get into safe mode? I am apparently under attack by worms,trojan, etc. I TRIED to open in safe mode to do the fix but it does not work. Any other way to get in? The screen stays black when I TRY to restart and hit F8.... |
|
| 1372. |
Solve : Virus in computer i think slowing computer right down :(? |
|
Answer» Still got some the Background on my screen is just black now no picture i have tried to put the 1 back on but will not let me also When you go into documents all the files have no picture of a file just a name but you have to click the invisible file Maybe be easier just to make back up disc of WINDOWS VISTA if can find the file of it put on disc then wipe computer not done that for over 2 years so might just need wiping clean GOOD CLEAN UP, Like still don't know what the TASK ENG.EXE running 3 times when i look at task manager it will not let me close it all them down when i close others it just starts up again few seconds later. Still got some the Background on my screen is just black now no picture i have tried to put the 1 back on but will not let me also When you go into documents all the files have no picture of a file just a name but you have to click the invisible fileThis sounds like a monitor or driver problem Can you give me screenshots of these two problems? How to post screenshots or images Quote Do you think we will be able to work out what the trouble is ??, Have you seen anything wrong so far in any of the logs that might be 1 of the problems if there is more than 1 i say they is.I haven't seen anything that would cause this sort of problems. Did you install anything new or make any changes to your computer prior to these problems beginning? Please run this even if you don't have the disk. 1/ Click the Start button. 2/ From the Start Menu, Click All programs followed by Accessories. 3/ In the Accessories menu, Right Click on the Command Prompt option. 4/ From the drop down menu that appears, Click on the Run as administrator option. 5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc. 6/ In the Command Prompt window, type: sfc /scannow and then press Enter. 7/ A message will appear stating that the system scan will begin. 8/ Be patient because the scan may take some time. 9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue. 10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations. 11/ After the scan has completed, Close the command prompt window. Sorry was not faster with replies computer acting up now,The question you asked about did I install anything before this happened well the online game i play called CONQUER ONLINE done a Auto Update and when it was done the MS REMOVAL TOOL CAME UP?? , I have been playing this game over 4yrs now and sometime there is just a problem with update but not a virus i have asked a few friends on the site as well if they got a virus from the update and all say no & none detected as well. IMAGES that you asked for. SCREEN SHOT : http://img151.imageshack.us/img151/558/blackscreen.jpg[/IMG] By jenzos FILE SHOT : http://img713.imageshack.us/img713/9783/justfilenames.jpg[/IMG] By jenzos The scan that you ask me to run i have done but it will not let me get the CBS logs from the Windows file just says ACCESS DENIED SORRY COULD NOT GET LOG FOR YOU THIS TIME . will try again when you might have way to get logs THANK YOU SuperDave for all the time that you have spared for helping me on this matter PURE LIFE SAVER SO FAR computer still going I know you will get it ALL WORKING AGAIN JENZO Thank you. Did you try adding some wallpaper to you desktop? As for the filenames, try clicking on view and choose a different setting such as thumbnails. Did you try to run SFC as described in Reply # 18? Please download the latest version of Kaspersky GetSystemInfo (GSI) from Kaspersky and save it to your Desktop. Note: please close all other applications running on your system. Double click GetSystemInfo.exe to open it. It will display an agreement. Click on I Agree to continue. Click the Settings button. Set the slider to Maximum. IMPORTANT! Then, click Customize - choose Driver / Ports tab and uncheck Scan Ports. On the General tab, make sure all of the boxes are checked. On the Misc tab, make sure all the checkboxes are checked. Then, click OK on the windows that you launched. Click Create Report to run it. It will begin scanning. It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop. It should automatically upload it to http://www.getsysteminfo.com. If it does not, then please SUBMIT it manually by going to the site and doing the upload process. It will redirect to a page, where it will provide a sharing URL for specialists. Copy and paste the url of the GSI Parser report in your next reply.. This is the Link for the scan you ask me to run. http://www.getsysteminfo.com/read.php?file=9611b27f6d736101e8a00701428f6410 Also i did run the SFC scan that you ask me to as i said in last report it would not let me get logs from CBS kept saying ACCESS DENIED. but did run the scan as you said just the logs could not get for you i found them no problem but would not let me open them. THANK YOU SuperDave JENZO Quote Also i did run the SFC scan that you ask me to as i said in last report it would not let me get logs from CBS kept saying ACCESS DENIED. but did run the scan as you said just the logs could not get for you i found them no problem but would not let me open them.I don't believe SFC will produce a log. If it finds a corrupt file it will replace it with one from the disk. If there is no disk, then it will ask for the disk. That's a tipoff that there's something amiss with the files. Did you try my suggestions for the black screen and the files? Download OTL to your Desktop
msconfig safebootminimal safebootnetwork activex drivers32 %SYSTEMDRIVE%\*.exe %systemroot%\*. /mp /s c:\$recycle.bin\*.* /s HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs /md5start eventlog.dll scecli.dll netlogon.dll cngaudit.dll sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys nvstor32.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll explorer.exe svchost.exe userinit.exe qmgr.dll ws2_32.dll proquota.exe imm32.dll kernel32.dll ndis.sys autochk.exe spoolsv.exe xmlprov.dll ntmssvc.dll mswsock.dll Beep.SYS ntfs.sys termsrv.dll sfcfiles.dll st3shark.sys ahcix86.sys srsvc.dll nvrd32.sys /md5stop %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles
LOG FOR OTL: OTL logfile created on: 20/04/2011 10:41:53 - Run 2 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Jenzo\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 40.00% Memory free 6.00 Gb Paging File | 5.00 Gb Available in Paging File | 73.00% Paging File free Paging file location(s): ?:\pagefile.sys %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 458.92 Gb Total Space | 195.68 Gb Free Space | 42.64% Space Free | Partition Type: NTFS Computer Name: MY | User Name: Jenzo | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011/04/20 10:41:16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Jenzo\Desktop\OTL.exe PRC - [2011/04/11 17:12:59 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2011/04/11 17:12:58 | 000,281,768 | ---- | M] (Avira GmbH) -- c:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2011/04/11 17:12:58 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2011/03/23 09:20:39 | 000,403,240 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe PRC - [2011/03/19 07:13:34 | 011,857,920 | ---- | M] (Electronic Arts) -- C:\Program Files\Electronic Arts\EADM\EADMUI\EADMUI.exe PRC - [2011/03/19 07:10:46 | 002,437,120 | ---- | M] (Electronic Arts) -- C:\Program Files\Electronic Arts\EADM\EADMUI\EADM.exe PRC - [2011/03/19 07:05:02 | 000,759,088 | ---- | M] (Electronic Arts) -- C:\Program Files\Electronic Arts\EADM\EADMUI\EACoreServer.exe PRC - [2011/03/18 18:57:02 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2011/02/22 14:57:34 | 000,378,128 | ---- | M] (PC Tools) -- C:\Program Files\ThreatFire\TFTray.exe PRC - [2011/01/07 22:06:12 | 000,803,432 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe PRC - [2011/01/07 20:48:56 | 000,378,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2010/12/14 13:34:57 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\steam.exe PRC - [2010/12/13 15:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe PRC - [2010/01/14 22:12:21 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2009/10/23 20:34:36 | 000,827,904 | ---- | M] () -- C:\Program Files\dvd43\DVD43_Tray.exe PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe ========== Modules (SafeList) ========== MOD - [2011/04/20 10:41:16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Jenzo\Desktop\OTL.exe MOD - [2010/08/31 16:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (ServiceLayer) SRV - [2011/04/11 17:12:59 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011/04/11 17:12:58 | 000,421,032 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService) SRV - [2011/04/11 17:12:58 | 000,339,624 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService) SRV - [2011/04/11 17:12:58 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011/03/23 09:20:39 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011/02/22 14:57:30 | 000,070,928 | ---- | M] (PC Tools) [Auto | Stopped] -- C:\Program Files\ThreatFire\TFService.exe -- (ThreatFire) SRV - [2011/01/07 20:48:56 | 000,378,984 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2010/12/13 15:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc) SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService) SRV - [2008/01/21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) ========== Driver Services (SafeList) ========== DRV - [2011/04/17 02:43:32 | 000,279,712 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2011/04/17 02:43:32 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2011/04/11 17:12:59 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2011/04/11 17:12:59 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011/02/23 08:27:00 | 010,468,360 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2011/02/22 14:57:52 | 000,069,392 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\TfSysMon.sys -- (TfSysMon) DRV - [2011/02/22 14:57:52 | 000,033,552 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\TfNetMon.sys -- (TfNetMon) DRV - [2011/02/22 14:57:50 | 000,051,984 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\TfFsMon.sys -- (TfFsMon) DRV - [2010/12/02 23:30:44 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nx6000.sys -- (MSHUSBVideo) DRV - [2010/08/16 08:50:16 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010/08/16 08:50:14 | 000,102,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avfwot.sys -- (avfwot) DRV - [2010/08/16 08:50:14 | 000,079,432 | ---- | M] (Avira GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avfwim.sys -- (avfwim) DRV - [2010/06/23 09:21:32 | 000,259,176 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2010/05/26 21:12:57 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL) DRV - [2010/02/17 11:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV) DRV - [2010/02/17 11:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM) DRV - [2009/09/16 10:22:48 | 000,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk) DRV - [2009/09/16 10:22:48 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk) DRV - [2009/09/16 10:22:48 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfesmfk.sys -- (mfesmfk) DRV - [2009/09/16 10:22:48 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk) DRV - [2009/09/16 10:22:14 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (mferkdk) DRV - [2009/02/03 16:36:58 | 000,059,000 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x) DRV - [2008/01/21 03:23:26 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\irsir.sys -- (irsir) DRV - [2007/06/02 15:59:42 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\PeerGuardian2\pgfilter.sys -- (pgfilter) DRV - [2007/03/20 11:33:26 | 000,028,672 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0) DRV - [2007/02/08 18:44:43 | 000,083,320 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x) DRV - [2006/07/10 17:19:58 | 000,027,032 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x) DRV - [2006/06/14 15:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/?ocid=OIE9HP IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE9ENGB/110 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B3 45 3A 13 17 56 CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.en gineName: "ZoneAlarm Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm" FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm" FF - prefs.js..browser.search.param.yahoo-type: "${8}" FF - prefs.js..browser.search.selectedEngine: "ZoneAlarm Customized Web Search" FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/" FF - prefs.js..extensions.enabledItems: [email protected]:1.19.1 FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3 FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: [email protected]:20110101 FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties" FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/24 11:13:52 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/24 11:13:51 | 000,000,000 | ---D | M] [2009/08/24 15:58:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Extensions [2011/04/10 06:04:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions [2010/04/27 08:48:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010/09/29 21:39:54 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}(12) [2011/03/25 08:44:07 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822} [2011/04/10 06:04:31 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\[email protected] [2010/12/17 16:14:25 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\[email protected] [2011/03/12 16:39:26 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\[email protected] [2010/06/08 23:00:34 | 000,000,921 | ---- | M] () -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\searchplugins\conduit.xml [2011/03/24 11:13:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2010/12/18 13:35:27 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2010/07/23 15:20:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010/08/08 15:14:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010/10/13 02:49:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011/01/16 19:03:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011/02/17 23:12:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} File not found (No name found) -- () (No name found) -- C:\USERS\JENZO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4W1NG7TY.DEFAULT\EXTENSIONS\{340C2BBC-CE74-4362-90B5-7C26312808EF}.XPI () (No name found) -- C:\USERS\JENZO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4W1NG7TY.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI () (No name found) -- C:\USERS\JENZO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4W1NG7TY.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI [2011/03/18 18:57:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll [2010/05/05 06:17:35 | 000,024,683 | ---- | M] (Ask.com) -- C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll [2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll [2010/01/01 09:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml [2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml [2010/01/01 09:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml [2010/01/01 09:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml [2010/01/01 09:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml O1 HOSTS File: ([2011/04/13 05:29:58 | 000,000,052 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe () O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation) O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools) O4 - HKCU..\Run: [EADM] C:\Program Files\Electronic Arts\EADM\EADMUI\EADMUI.exe (Electronic Arts) O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\rmtray.exe (PC Tools) O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation) O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10o_Plugin.exe (Adobe Systems, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\DisableRegistryTools: = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\DisableRegistryTools\ShowInfoTip: = 0 O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com) O24 - Desktop WallPaper: C:\Users\Jenzo\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg O24 - Desktop BackupWallPaper: C:\Users\Jenzo\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [ = comfile] -- "%1" %* O37 - HKLM\...exe [ = exefile] -- "%1" %* NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - File not found NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^Users^Jenzo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CNET TechTracker.lnk - Reg Error: Value error. - File not found MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) MsConfig - StartUpReg: Messenger (Yahoo!) - hkey= - key= - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.) MsConfig - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.) MsConfig - StartUpReg: Sidebar - hkey= - key= - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) MsConfig - StartUpReg: Windows Defender - hkey= - key= - File not found MsConfig - State: "startup" - 2 MsConfig - State: "services" - 2 SafeBootMin: AppMgmt - File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PEVSystemStart - Service SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: procexp90.Sys - Driver SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - File not found SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: MpfService - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PEVSystemStart - Service SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: procexp90.Sys - Driver SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vsmon - Service SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: WudfPf - Driver SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0 ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error. ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{0d6d480a-b17b-4aa2-9156-ce888156e8d2} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll () ========== Files/Folders - Created Within 30 Days ========== [2011/04/20 10:41:16 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Jenzo\Desktop\OTL.exe [2011/04/19 20:15:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2011/04/19 20:14:55 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2011/04/19 19:55:11 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2011/04/19 19:55:04 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2011/04/19 19:14:59 | 000,611,624 | ---- | C] (Kaspersky Lab) -- C:\Users\Jenzo\Desktop\GetSystemInfo.exe [2011/04/18 08:47:07 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{8B8FDA98-FB47-4CCE-AA3A-3F13D3197CFC} [2011/04/17 21:07:09 | 000,000,000 | ---D | C] -- C:\ProgramData\SpecialBit [2011/04/17 19:05:50 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{8D72AA64-1097-4593-8FB2-B6EA9F1B5658} [2011/04/17 02:43:46 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Games [2011/04/17 02:42:48 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallShield [2011/04/17 02:41:58 | 000,000,000 | ---D | C] -- C:\Windows\LastGood [2011/04/17 02:41:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\AGEIA [2011/04/17 02:41:50 | 000,000,000 | ---D | C] -- C:\Program Files\AGEIA Technologies [2011/04/17 02:41:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focus [2011/04/17 02:38:36 | 000,000,000 | ---D | C] -- C:\Program Files\Focus [2011/04/17 02:33:16 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{E3B986F9-998E-42C2-957C-8DCCEE57C0D2} [2011/04/16 16:43:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SpecialBit Games [2011/04/16 16:42:22 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunted Hotel II - Believe the Lies [2011/04/16 16:42:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haunted Hotel II - Believe the Lies [2011/04/16 16:42:22 | 000,000,000 | ---D | C] -- C:\Program Files\Haunted Hotel II - Believe the Lies [2011/04/16 16:41:44 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunted Hotel [2011/04/16 16:41:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haunted Hotel [2011/04/16 16:41:44 | 000,000,000 | ---D | C] -- C:\Program Files\Haunted Hotel [2011/04/16 16:41:31 | 000,000,000 | ---D | C] -- C:\Program Files\bfgclient [2011/04/16 16:41:25 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache [2011/04/16 13:16:34 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{A66A2B64-BA03-414A-933F-BCD41AE937C5} [2011/04/16 01:55:06 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Documents\Battlefield 2 [2011/04/16 01:48:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EasyInfo [2011/04/16 01:16:07 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{5A7887E3-D55B-4CD5-AF36-C827D7669E15} [2011/04/15 22:05:23 | 000,000,000 | ---D | C] -- C:\Qoobox [2011/04/15 11:13:09 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Desktop\Kew Association V Barnes [2011/04/15 08:22:44 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2011/04/15 02:09:15 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{5D0BABCF-8578-4EDB-81BE-C0B63D612E95} [2011/04/13 05:38:35 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{A17467E1-0301-4E81-A57F-109882E50878} [2011/04/13 05:38:25 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Windows Live Writer [2011/04/13 05:38:25 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\Windows Live Writer [2011/04/13 05:04:56 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{E25CE24C-2DDA-4EF2-BAB5-44F2D3321744} [2011/04/11 17:10:44 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Avira [2011/04/11 14:33:07 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Documents\Battlefield Play4Free [2011/04/10 16:06:21 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{CD71DF95-AEE1-46FB-9877-BA17845BEF77} [2011/04/10 04:05:54 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{5E4A142B-A8AC-42A6-91B9-0899EDDA128F} [2011/04/09 14:36:59 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{0BEE5CEB-D003-4DB2-96AD-558A1342BF4E} [2011/04/07 11:45:43 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\Macroplant,_LLC [2011/04/06 11:31:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2011/04/05 15:39:53 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{1355D98B-7E6E-4CD4-86CB-D61DF846BD8F} [2011/04/05 03:39:24 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{4F75B93E-DEE1-4CBF-A3F9-2AE5EA85919D} [2011/03/31 11:41:52 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Documents\SHIFT 2 UNLEASHED [2011/03/31 10:17:43 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{223F4ADE-FE60-40AF-858A-67E46B993228} [2011/03/28 11:41:41 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\Macroplant [2011/03/28 11:37:50 | 000,000,000 | ---D | C] -- C:\Program Files\iPhone Explorer [2011/03/27 05:40:28 | 000,043,520 | ---- | C] (http://libusb-win32.sourceforge.net) -- C:\Windows\System32\libusb0.dll [2011/03/27 05:40:28 | 000,028,672 | ---- | C] (http://libusb-win32.sourceforge.net) -- C:\Windows\System32\drivers\libusb0.sys [2011/03/27 03:32:49 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\.shsh [2011/03/25 15:14:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerGuardian 2 [2011/03/25 15:14:45 | 000,000,000 | ---D | C] -- C:\Program Files\PeerGuardian2 [2011/03/25 09:45:24 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan [2011/03/22 09:49:36 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Favorites [2010/10/04 12:01:30 | 000,726,384 | ---- | C] (Electronic Arts) -- C:\Program Files\AutoRun.exe [2009/08/26 13:26:35 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Jenzo\AppData\Roaming\pcouffin.sys [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [18 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011/04/20 10:41:16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Jenzo\Desktop\OTL.exe [2011/04/20 10:32:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011/04/19 20:41:45 | 000,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011/04/19 20:41:45 | 000,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011/04/19 20:29:31 | 000,000,799 | ---- | M] () -- C:\Users\Jenzo\Desktop\cleanup.bat [2011/04/19 20:18:06 | 329,933,934 | ---- | M] () -- C:\Users\Jenzo\Desktop\sn0wbreeze_iPhone 3G-4.2.1.ipsw [2011/04/19 20:15:52 | 000,001,669 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2011/04/19 19:23:27 | 000,292,565 | ---- | M] () -- C:\Users\Jenzo\Desktop\GetSystemInfo_MY_Jenzo_2011_04_19_19_19_22.zip [2011/04/19 19:14:59 | 000,611,624 | ---- | M] (Kaspersky Lab) -- C:\Users\Jenzo\Desktop\GetSystemInfo.exe [2011/04/19 13:16:33 | 001,116,318 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011/04/19 13:16:33 | 000,362,214 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011/04/17 22:40:20 | 000,002,305 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk [2011/04/17 22:26:37 | 338,579,762 | R--- | M] () -- C:\Users\Jenzo\Desktop\iPhone1,2_4.2.1_8C148_Restore.ipsw [2011/04/17 02:43:32 | 000,279,712 | ---- | M] () -- C:\Windows\System32\drivers\atksgt.sys [2011/04/17 02:43:32 | 000,025,888 | ---- | M] () -- C:\Windows\System32\drivers\lirsgt.sys [2011/04/17 02:41:02 | 000,002,181 | ---- | M] () -- C:\Users\Public\Desktop\Play Sherlock Holmes versus Jack the Ripper.lnk [2011/04/16 16:42:46 | 000,001,938 | ---- | M] () -- C:\Users\Public\Desktop\Play Haunted Hotel II - Believe the Lies.lnk [2011/04/16 16:41:59 | 000,001,740 | ---- | M] () -- C:\Users\Public\Desktop\Play Haunted Hotel.lnk [2011/04/16 16:41:31 | 000,001,729 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk [2011/04/16 16:41:31 | 000,001,705 | ---- | M] () -- C:\Users\Public\Desktop\Game Manager.lnk [2011/04/16 12:48:42 | 026,093,317 | ---- | M] () -- C:\Users\Jenzo\Documents\EA-Battlefield-Bad-Company-2.zip [2011/04/16 02:09:43 | 000,001,996 | ---- | M] () -- C:\Users\Public\Desktop\Play BF2 SF Online Now!.lnk [2011/04/16 02:09:43 | 000,001,974 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 2 Special Forces.lnk [2011/04/16 01:51:38 | 000,001,890 | ---- | M] () -- C:\Users\Public\Desktop\Play BF2 Online Now!.lnk [2011/04/16 01:51:38 | 000,001,868 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 2.lnk [2011/04/15 12:16:00 | 000,333,100 | ---- | M] () -- C:\Users\Jenzo\AppData\Roaming\vso_ts_preview.xml [2011/04/15 09:05:47 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk [2011/04/15 08:06:13 | 000,303,008 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011/04/15 02:01:16 | 000,000,574 | ---- | M] () -- C:\cleanup.bat [2011/04/13 21:20:41 | 000,138,264 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2011/04/13 21:20:10 | 000,234,768 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr [2011/04/13 20:48:50 | 000,000,104 | ---- | M] () -- C:\Users\Jenzo\Desktop\Recycle Bin - Shortcut.lnk [2011/04/13 20:16:24 | 000,000,809 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011/04/13 10:57:27 | 000,071,282 | ---- | M] () -- C:\Users\Jenzo\Documents\Great New Movies BY JENZO.XtoDVD [2011/04/13 05:29:58 | 000,000,052 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2011/04/11 17:12:59 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2011/04/11 17:12:59 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2011/04/10 06:23:37 | 000,138,056 | ---- | M] () -- C:\Users\Jenzo\AppData\Roaming\PnkBstrK.sys [2011/04/10 06:13:11 | 000,902,709 | ---- | M] () -- C:\Users\Jenzo\Documents\iTunes Diagnostics.spx [2011/04/10 06:13:11 | 000,003,916 | ---- | M] () -- C:\Users\Jenzo\Documents\iTunes Diagnostics.rtf [2011/04/10 04:22:15 | 000,015,699 | ---- | M] () -- C:\Users\Jenzo\AppData\Roaming\UserTile.png [2011/04/09 13:20:10 | 000,000,948 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/04/06 11:42:13 | 000,000,620 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\vlc-1.1.8-win32 - Shortcut.lnk [2011/04/06 11:30:59 | 020,586,196 | ---- | M] () -- C:\Users\Jenzo\Documents\vlc-1.1.8-win32.exe [2011/04/05 02:08:17 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat [2011/04/05 02:08:17 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat [2011/04/05 02:08:09 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2011/04/03 15:37:05 | 000,002,401 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk [2011/03/31 11:41:39 | 000,000,136 | ---- | M] () -- C:\Users\Jenzo\Desktop\SHIFT 2 UNLEASHED™.LNK [2011/03/29 18:10:46 | 000,001,356 | ---- | M] () -- C:\Users\Jenzo\AppData\Local\d3d9caps.dat [2011/03/29 17:05:40 | 000,000,080 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.umbrella [2011/03/29 15:09:10 | 000,604,499 | ---- | M] () -- C:\Users\Jenzo\Desktop\greenpois0n rc5.exe [2011/03/28 15:36:20 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2011/03/28 06:15:37 | 005,298,620 | ---- | M] () -- C:\Users\Jenzo\Desktop\greenpois0n rc6.exe [2011/03/27 23:04:48 | 000,000,799 | ---- | M] () -- C:\Windows\System32\cleanup.bat [2011/03/27 22:48:33 | 018,147,328 | ---- | M] (iH8sn0w) -- C:\Users\Jenzo\Desktop\sn0wbreeze-2.2.1.exe [2011/03/25 15:21:52 | 000,001,669 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk [2011/03/25 15:14:46 | 000,000,775 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\PeerGuardian.lnk [2011/03/25 15:14:46 | 000,000,751 | ---- | M] () -- C:\Users\Jenzo\Desktop\PeerGuardian.lnk [2011/03/25 05:59:56 | 000,000,136 | ---- | M] () -- C:\Users\Jenzo\Desktop\Crysis® 2 - Shortcut.lnk [2011/03/24 13:50:18 | 000,001,052 | ---- | M] () -- C:\Users\Public\Desktop\EA Download Manager.lnk [2011/03/24 11:13:54 | 000,000,875 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2011/03/24 11:13:54 | 000,000,851 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2011/03/23 09:09:25 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [18 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011/04/19 20:29:31 | 000,000,799 | ---- | C] () -- C:\Users\Jenzo\Desktop\cleanup.bat [2011/04/19 20:17:05 | 329,933,934 | ---- | C] () -- C:\Users\Jenzo\Desktop\sn0wbreeze_iPhone 3G-4.2.1.ipsw [2011/04/19 20:15:52 | 000,001,669 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2011/04/19 19:20:59 | 000,292,565 | ---- | C] () -- C:\Users\Jenzo\Desktop\GetSystemInfo_MY_Jenzo_2011_04_19_19_19_22.zip [2011/04/17 22:21:47 | 338,579,762 | R--- | C] () -- C:\Users\Jenzo\Desktop\iPhone1,2_4.2.1_8C148_Restore.ipsw [2011/04/17 02:41:15 | 000,279,712 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2011/04/17 02:41:14 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2011/04/17 02:41:02 | 000,002,181 | ---- | C] () -- C:\Users\Public\Desktop\Play Sherlock Holmes versus Jack the Ripper.lnk [2011/04/16 16:42:46 | 000,001,938 | ---- | C] () -- C:\Users\Public\Desktop\Play Haunted Hotel II - Believe the Lies.lnk [2011/04/16 16:41:59 | 000,001,740 | ---- | C] () -- C:\Users\Public\Desktop\Play Haunted Hotel.lnk [2011/04/16 16:41:31 | 000,001,729 | ---- | C] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk [2011/04/16 16:41:31 | 000,001,717 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Manager.lnk [2011/04/16 16:41:31 | 000,001,705 | ---- | C] () -- C:\Users\Public\Desktop\Game Manager.lnk [2011/04/16 12:47:08 | 026,093,317 | ---- | C] () -- C:\Users\Jenzo\Documents\EA-Battlefield-Bad-Company-2.zip [2011/04/16 02:09:43 | 000,001,996 | ---- | C] () -- C:\Users\Public\Desktop\Play BF2 SF Online Now!.lnk [2011/04/16 02:09:43 | 000,001,974 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 2 Special Forces.lnk [2011/04/16 01:51:38 | 000,001,890 | ---- | C] () -- C:\Users\Public\Desktop\Play BF2 Online Now!.lnk [2011/04/16 01:51:38 | 000,001,868 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 2.lnk [2011/04/15 02:01:16 | 000,000,574 | ---- | C] () -- C:\cleanup.bat [2011/04/13 10:57:27 | 000,071,282 | ---- | C] () -- C:\Users\Jenzo\Documents\Great New Movies BY JENZO.XtoDVD [2011/04/10 04:22:15 | 000,015,699 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\UserTile.png [2011/04/06 11:42:13 | 000,000,620 | ---- | C] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\vlc-1.1.8-win32 - Shortcut.lnk [2011/04/06 11:30:42 | 020,586,196 | ---- | C] () -- C:\Users\Jenzo\Documents\vlc-1.1.8-win32.exe [2011/04/05 02:08:09 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2011/03/31 11:41:39 | 000,000,136 | ---- | C] () -- C:\Users\Jenzo\Desktop\SHIFT 2 UNLEASHED™.LNK [2011/03/27 22:44:51 | 000,000,799 | ---- | C] () -- C:\Windows\System32\cleanup.bat [2011/03/27 02:24:25 | 000,902,709 | ---- | C] () -- C:\Users\Jenzo\Documents\iTunes Diagnostics.spx [2011/03/27 02:24:25 | 000,003,916 | ---- | C] () -- C:\Users\Jenzo\Documents\iTunes Diagnostics.rtf [2011/03/25 15:21:52 | 000,001,669 | ---- | C] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk [2011/03/25 15:14:46 | 000,000,775 | ---- | C] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\PeerGuardian.lnk [2011/03/25 15:14:46 | 000,000,751 | ---- | C] () -- C:\Users\Jenzo\Desktop\PeerGuardian.lnk [2011/03/25 05:59:56 | 000,000,136 | ---- | C] () -- C:\Users\Jenzo\Desktop\Crysis® 2 - Shortcut.lnk [2011/03/24 11:13:54 | 000,000,863 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2011/03/24 11:13:54 | 000,000,851 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2011/03/12 16:58:21 | 000,084,480 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2010/12/18 13:40:37 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010/12/16 15:25:49 | 000,682,280 | ---- | C] () -- C:\Windows\System32\pbsvc.exe [2010/12/03 06:42:02 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2010/10/14 02:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2010/10/04 12:01:30 | 000,000,157 | ---- | C] () -- C:\Program Files\autorun.inf [2010/10/04 12:01:28 | 009,822,208 | ---- | C] () -- C:\Program Files\autorun.dat [2010/10/04 12:01:28 | 000,000,185 | ---- | C] () -- C:\Program Files\p0.cab [2010/10/04 12:01:22 | 063,013,682 | ---- | C] () -- C:\Program Files\o0.cab [2010/10/04 11:59:28 | 1508,976,877 | ---- | C] () -- C:\Program Files\d0.cab [2010/10/04 11:59:28 | 006,866,468 | ---- | C] () -- C:\Program Files\c0.cab [2010/10/04 11:59:24 | 000,138,264 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2010/10/04 11:59:08 | 000,234,768 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2010/10/04 11:59:02 | 002,601,752 | ---- | C] () -- C:\Windows\System32\pbsvc_moh.exe [2010/10/04 11:59:02 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2010/07/30 17:41:14 | 000,001,184 | ---- | C] () -- C:\Windows\eReg.dat [2010/05/05 07:58:25 | 000,000,597 | ---- | C] () -- C:\Windows\wininit.ini [2010/04/08 16:44:47 | 000,001,356 | ---- | C] () -- C:\Users\Jenzo\AppData\Local\d3d9caps.dat [2010/03/19 19:47:58 | 000,138,056 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\PnkBstrK.sys [2009/12/03 09:27:30 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2009/10/07 12:38:38 | 000,069,632 | ---- | C] () -- C:\Windows\System32\xmltok.dll [2009/10/07 12:38:38 | 000,036,864 | ---- | C] () -- C:\Windows\System32\xmlparse.dll [2009/09/27 07:10:34 | 000,000,100 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\wklnhst.dat [2009/09/23 12:12:16 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009/09/23 12:12:16 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009/08/26 13:27:06 | 000,333,100 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\vso_ts_preview.xml [2009/08/26 13:26:35 | 000,007,887 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\pcouffin.cat [2009/08/26 13:26:35 | 000,001,144 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\pcouffin.inf [2009/08/26 13:17:37 | 000,007,680 | ---- | C] () -- C:\Users\Jenzo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll [2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe [2009/06/23 16:57:30 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll [2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll [2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll [2006/11/02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006/11/02 13:47:37 | 000,303,008 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 11:33:01 | 001,116,318 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 11:33:01 | 000,362,214 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat ========== LOP Check ========== [2011/04/19 18:55:54 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\BitTorrent [2010/03/26 20:30:01 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\CBS Interactive [2010/07/15 10:22:02 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\CheckPoint [2009/11/16 20:03:03 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2010/07/21 12:31:26 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\ESET [2010/11/17 00:00:58 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Flood Light Games [2010/11/16 23:30:49 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\FloodLightGames [2011/04/17 02:44:55 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Games [2010/12/03 06:46:20 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\MAGIX [2010/09/22 10:58:26 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Mount&Blade Warband [2010/09/09 12:02:02 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Need for Speed World [2010/02/03 22:10:07 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Nokia [2010/02/03 21:14:51 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\PC Suite [2010/10/13 00:38:54 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\ProtectDISC [2010/07/02 12:00:11 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Samsung [2010/05/27 13:38:11 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\SEGA Corporation [2010/06/05 21:22:26 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Sports Interactive [2011/04/16 12:44:18 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\SystemRequirementsLab [2009/09/27 07:12:06 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Template [2010/11/16 09:40:40 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Tropico 3 Demo [2010/03/27 21:45:26 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\TS3Client [2010/04/10 11:08:11 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Ubisoft [2011/04/15 12:16:01 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Vso [2011/04/13 05:38:25 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Windows Live Writer [2011/04/16 12:17:23 | 000,032,648 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > [2007/11/07 09:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe < %systemroot%\*. /mp /s > < c:\$recycle.bin\*.* /s > [2011/04/18 08:57:24 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$I1D7MMA.mp3 [2011/04/18 09:01:08 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$I9WYJ2Q.mp3 [2011/04/20 10:40:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$IFS6Z3O.html [2011/04/19 19:53:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$IKZU7Q2.ipa [2011/04/18 08:57:10 | 058,959,727 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R1D7MMA.mp3 [2011/04/18 08:53:09 | 031,099,986 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R9WYJ2Q.mp3 [2011/04/20 10:39:44 | 000,009,390 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RFS6Z3O.html [2011/03/12 22:24:23 | 021,372,799 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RKZU7Q2.ipa [2010/07/21 10:15:23 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\desktop.ini [2010/10/26 21:17:00 | 000,000,402 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R0HRNJ1\Favorites\desktop.ini [2010/04/09 06:58:44 | 000,000,080 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R0HRNJ1\Favorites\Links\desktop.ini [2009/10/19 12:32:19 | 000,000,382 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R2TESFY\desktop.ini [2009/05/15 23:23:34 | 000,000,317 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R2TESFY\Black Eyed Peas - Monkey Business (2005) - 320 KBPS by blondu4all\desktop.ini [2009/08/30 19:39:16 | 000,000,296 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R7NZS7O\desktop.ini [2009/10/10 11:56:18 | 000,000,391 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RAO8EEK\desktop.ini [2009/06/14 14:33:22 | 000,000,328 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RDFEJXC\desktop.ini [2010/03/22 07:21:50 | 000,000,362 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RHTRIBM\desktop.ini [2010/03/22 07:31:35 | 000,000,298 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RITT528\desktop.ini [2009/10/19 12:33:04 | 000,000,322 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RRX81K4\desktop.ini [2010/03/26 20:33:27 | 000,000,402 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RV620Y3\Favorites\desktop.ini [2010/10/26 21:27:00 | 000,000,402 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RX6G98Z\Favorites\desktop.ini [2010/11/06 21:31:31 | 000,000,080 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RX6G98Z\Favorites\Links\desktop.ini [2010/12/15 06:27:00 | 000,000,402 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RY566S7\Favorites\desktop.ini [2011/01/08 09:53:09 | 000,000,080 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RY566S7\Favorites\Links\desktop.ini [2009/11/10 14:48:49 | 000,000,391 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RZ6T9NS\desktop.ini < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-19 08:28:52 < MD5 for: AGP440.SYS > [2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\ERDNT\cache\AGP440.sys [2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys [2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys [2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys [2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys [2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys [2006/11/02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys < MD5 for: ATAPI.SYS > [2009/04/11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\ERDNT\cache\atapi.sys [2009/04/11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys [2009/04/11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys [2009/04/11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys [2008/01/21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys [2008/01/21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys [2006/11/02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) I was looking at ThreatFire under the ADVANCED TOOLS >> SYSTEM ACTIVITY MONITOR >> PROTECTED and i found a file by the name of 6ac3f99b-de48-4ea7-8e9d-9ab6f1df2286.exe I tried to look this file up on the start menu but nothing came up & asked for more info on this file but nothing , I have looked it up on goggle but nothing on there as well so just wondering if this was any good to you just in case might mean something to you. Hope this helps you in any way THANKS FOR ALL THE HELP SO FAR SuperDave JENZO I look in my ThreatFire but I can't find Protection in Advanced Tools. Neither can I find that exe file. It's been about one week since we started this cleaning. Other than the black background, is there anything else wrong with the computer? If Vista came install do you have the Recovery Console installed?With ThreatFire on the Advance Tools made a pic of the place to find it PROTECED is at the bottom on the left list on pic the program is not there now By jenzos at 2011-04-20 the computer is still slow the anti virus keeps closing down by itself then back on again. I know might have to wipe computer but 1 thing I HAVE NO RECOVERY DISC did not get 1 with computer when new it came installed with VISTA already is there a way to make RECOVERY DISC if so if you can tell me i do that & wipe computer start from new because you cannot find nothing so what ever it is attacking my computer is hiding well from you IF YOU CANNOT FIND IT SuperDave then i have no chance but to wipe it . If you can please tell me where to get main Vista file to make BACK UP DISC i do that will not take up more of your time you have tried your best for me you helped me out 2 times before & we cleaned up the computers but this 1 has got me THANK YOU FOR THE HELP SO FAR SuperDave sorry if wasted your time if i wipe computer JENZO JUST FOUND IN TREATFIRE Quarantine: FILE C:\CLEANUP.EXE Trojan.Zapchast!sd6 15/04/11 02:08:07 Computer just keeps freezing up when your typing or opening programs & as i said SECURITY system keeps shutting & opening up when it likes My version of ThreatFire doesn't have that tab. Quote I HAVE NO RECOVERY DISC did not get 1 with computer when new it came installed with VISTA already is there a way to make RECOVERY DISC if so if you can tell me i do that & wipe computer start from new because you cannot find nothing so what ever it is attacking my computer is hiding well from you IF YOU CANNOT FIND IT SuperDave then i have no chance but to wipe itIt either has the Recovery Console installed or you have the ability to create a RC disk. That's what I had to do with my laptop. Of course, that was a few years ago. I would imagine they all come with the RC installed. If it's there, you should see a separate partition on your C: drive Quote If you can please tell me where to get main Vista file to make BACK UP DISC i do that will not take up more of your time you have tried your best for me you helped me out 2 times before & we cleaned up the computers but this 1 has got meOn my laptop it has a Recovery Disk Creator. You probably should ask that question in the Vista forum Quote THANK YOU FOR THE HELP SO FAR SuperDave sorry if wasted your time if i wipe computerYou're welcome but I don't consider it a waste of time. We've run a lot of scans and really couldn't find anything serious.Thank you so much for all the time that you have spent helping me. i think i look into one of the courses that teach you how to look for & fix spyware & malaware would be good to help people give something back. will let you know how i get on i have to go away tomorrow so back in 2 weeks so will leave you a PM how i get on. Take Care mate all the best SuperDave JENZO Quote i think i look into one of the courses that teach you how to look for & fix spyware & malaware would be good to help people give something back.Great, I could use the help. Thanks. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 1373. |
Solve : broken digital signature? |
|
Answer» Hi |
|
| 1374. |
Solve : NO SOUND ON MY DELL VOSTRO 1520? |
|
Answer» Hi, |
|
| 1375. |
Solve : Got registry bugs........? |
|
Answer» Please uninstall Antivirus 2010. It is malware. As I mentioned earlier, 'Anti virus 2010' will not uninstall through control panel. If I could find the file, perhaps I could wipe it with DPwiper, but I don't know how to find it, and a search for 'anti virus 2010' comes up blank.Sorry. Let's try to get rid of it this way. Please run another Security Check after you've done this. * Open OTL * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window. Code: [Select]:OTL :folders Antivirus 2010 :Processes -- this is the command for killing processes. :COMMANDS [resethosts] [purity] [emptytemp] [start explorer] * Click Run Fix * OTLI2 may ask to reboot the machine. Please do so if asked. * Click OK * A report will open. Copy and Paste that report in your next reply. All processes killed ========== OTL ========== Error: Unable to interpret <:folders> in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret <:Processes -- this is the command for killing processes.> in the current context! ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Compaq_Owner ->Temp folder emptied: 2526 bytes ->Temporary Internet Files folder emptied: 1440836 bytes ->Java cache emptied: 2027 bytes ->FireFox cache emptied: 45779653 bytes ->Flash cache emptied: 456 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56466 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->FireFox cache emptied: 0 bytes User: misc pics User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: New Folder User: savanah pics %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 452 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 45.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04232011_172541 Files\Folders moved on Reboot... Registry entries deleted on Reboot... Please run Security Check again to see if it has been removed. Results of screen317's Security Check version 0.99.10 Windows XP Service Pack 3 (UAC is disabled!) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! Avira AntiVir Personal - Free Antivirus WWII: Normandy Antivirus 2010 PC Tools Firewall Plus 6.0 McAfee Security Scan Plus ZoneAlarm Spy Blocker Toolbar ZoneAlarm Avira successfully updated! ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware CCleaner Java(TM) 6 Update 25 Out of date Java installed! Adobe Flash Player 10.1.102.64 Adobe Reader X (10.0.1) Mozilla Thunderbird (3.1.9) ```````````````````````````````` Process Check: objlist.exe by Laurent Avira Antivir avgnt.exe Avira Antivir avguard.exe PC Tools Firewall Plus FWService.exe PC Tools Firewall Plus FirewallGUI.exe ``````````End of Log```````````` Please update and run MBAM in Normal mode and post the log.Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6435 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 4/24/2011 4:59:43 PM mbam-log-2011-04-24 (16-59-43).txt Scan type: Full scan (C:\|) Objects scanned: 221571 Time ELAPSED: 1 hour(s), 6 minute(s), 37 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the PAGE under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
by swatkat ************************************* *************************************** No Hidden Processes found *************************************************** *************************************************** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: --- Module Base: B4B05000 Module End: B4B1D000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: --- Module Base: BA5F4000 Module End: BA5F6000 Hidden: Yes ******************************************************** ******************************************************** SSDT: Function Name: ZwCreateFile Address: B278ED80 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwCreateKey Address: B27B3070 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwCreateThread Address: BA7D1AEC Driver Base: 0 Driver End: 0 Driver Name: _unknown_ Function Name: ZwDeleteFile Address: B278FC60 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwDeleteKey Address: B27B4780 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwDeleteValueKey Address: B27B4160 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwLoadKey Address: B27B5080 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwLoadKey2 Address: B27B52B0 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwOpenFile Address: B278F750 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwOpenProcess Address: BA7D1AD8 Driver Base: 0 Driver End: 0 Driver Name: _unknown_ Function Name: ZwOpenThread Address: BA7D1ADD Driver Base: 0 Driver End: 0 Driver Name: _unknown_ Function Name: ZwRenameKey Address: B27B6430 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwReplaceKey Address: B27B5A40 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwRestoreKey Address: B27B60D0 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwSetInformationFile Address: B2790080 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwSetSecurityObject Address: B27B68E0 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwSetValueKey Address: B27B3970 Driver Base: B2761000 Driver End: B27F1000 Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys Function Name: ZwTerminateProcess Address: BA7D1AE7 Driver Base: 0 Driver End: 0 Driver Name: _unknown_ ******************************************************** ******************************************************** No Kernel Hooks found ************************************************************* ************************************************************** Hidden files/folders: Object: C:\System Volume Information\MountPointManagerRemoteDatabase Status: Access denied Object: C:\System Volume Information\tracking.log Status: Access denied Object: C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6} Status: Access denied I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt |
|
| 1376. |
Solve : Loss of internet connection after spyware problem? |
|
Answer» Quote I use Firefox and also Internet explorer.And, neither one can connect to the internet? Please download the latest version of Kaspersky GetSystemInfo (GSI) from Kaspersky and save it to your Desktop. Note: please close all other applications running on your system. Double click GetSystemInfo.exe to open it. It will display an agreement. Click on I Agree to continue. Click the Settings button. Set the slider to Maximum. IMPORTANT! Then, click Customize - choose Driver / Ports tab and uncheck Scan Ports. On the General tab, make sure all of the boxes are checked. On the Misc tab, make sure all the checkboxes are checked. Then, click OK on the WINDOWS that you launched. Click Create Report to run it. It will begin scanning. It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop. It should automatically upload it to http://www.getsysteminfo.com. If it does not, then please submit it manually by going to the site and doing the upload process. It will redirect to a page, where it will provide a sharing URL for specialists. Copy and paste the url of the GSI Parser report in your next reply.. http://www.getsysteminfo.com/read.php?file=a761082afdd05f4f1cfb540a1406f389Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop. link # 1 Link # 2 If you are using Firefox, make sure that your download settings are as follows: * Tools->Options->Main tab * Set to "Always ask me where to Save the files". Close any open WEB browsers (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Right-click combofix.exe and select Run as Administrator and follow the prompts. When finished, ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.Here is the combo fix one - not sure if i sucessfully turned off norton thoug: ComboFix 11-04-17.03 - franki 18/04/2011 22:27:05.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.1014.276 [GMT 1:00] Running from: c:\users\franki\Desktop\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_usnjsvc . . ((((((((((((((((((((((((( Files Created from 2011-03-18 to 2011-04-18 ))))))))))))))))))))))))))))))) . . 2011-04-18 21:19 . 2011-04-18 21:20 -------- d-----w- C:\32788R22FWJFW 2011-04-11 20:10 . 2011-04-11 20:10 -------- d-----w- c:\users\franki\AppData\Roaming\SUPERAntiSpyware.com 2011-04-10 16:28 . 2011-04-10 16:30 -------- d-----w- c:\users\Administrator . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll 2009-03-31 21:47 . 2009-08-17 21:57 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-12-09 17:40 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}] 2010-09-07 06:23 585096 ----a-w- c:\progra~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}] 2009-11-20 17:34 87472 ----a-w- c:\progra~1\IMESHA~1\MediaBar\ToolBar\iMeshMediaBarDx.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192] "{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}"= "c:\progra~1\IMESHA~1\MediaBar\ToolBar\iMeshMediaBarDx.dll" [2009-11-20 87472] . [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] . [HKEY_CLASSES_ROOT\clsid\{abb49b3b-ab7d-4ed0-9135-93fd5aa4f69f}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192] . [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-10 1232896] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440] "kdx"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-01 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-31 131072] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-31 151552] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-31 126976] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-03-29 176128] "NapsterShell"="c:\program files\Napster\napster.exe" [2007-01-13 323216] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 50696] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-04-24 77824] "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328] "4oD"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048] "osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896] . c:\users\franki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Audible Download Manager.lnk - c:\program files\Audible\Bin\AudibleDownloadHelper.exe [2009-9-23 1791320] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\IMESHA~1\MediaBar\Datamngr\datamngr.dll c:\progra~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-02 135664] R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888] R3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2009-02-19 41008] S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2010-10-03 59240] S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080911.001\IDSvix86.sys [2008-08-08 261680] S1 RapportCerberus_19917;RapportCerberus_19917;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys [2010-10-03 34792] S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2010-10-03 169320] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352] S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2010-10-03 767208] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - COMHOST . Contents of the 'Scheduled Tasks' folder . 2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-02 21:40] . 2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-02 21:40] . 2011-04-18 c:\windows\Tasks\User_Feed_Synchronization-{1A1E9A67-A002-4FB0-9411-2BA1D61AA15B}.job - c:\windows\system32\msfeedssync.exe [2010-12-28 04:56] . . ------- Supplementary Scan ------- . mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=Pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20101221064513 FF - ProfilePath - c:\users\franki\AppData\Roaming\Mozilla\Firefox\Profiles\nqjfmbrz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - iMesh Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.imesh.com/ FF - prefs.js: keyword.URL - hxxp://search.imesh.com/web?src=ffb&systemid=1&q= FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\program files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: MediaBar: {28D35620-51D9-11DE-9D13-2DB156D89593} - %profile%\extensions\{28D35620-51D9-11DE-9D13-2DB156D89593} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . . ------- File Associations ------- . inifile=%SystemRoot%\System32\NOTEPAD.EXE %1" . - - - - ORPHANS REMOVED - - - - . HKLM-Run-QlbCtrl - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe HKLM-Run-hpWirelessAssistant - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe HKLM-Run-WAWifiMessage - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe SafeBoot-klmdb.sys . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-04-18 22:49 Windows 6.0.6000 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . . c:\windows\TEMP\TMP00000012CF9B031445299DCB 524288 bytes executable . scan completed successfully hidden files: 1 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'Explorer.exe'(3352) c:\program files\Trusteer\Rapport\bin\rooksbas.dll c:\windows\system32\imapi2.dll c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\windows\system32\lxdacoms.exe c:\windows\system32\DRIVERS\xaudio.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe c:\windows\system32\WUDFHost.exe c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe c:\windows\system32\DllHost.exe c:\windows\system32\vssvc.exe . ************************************************************************** . Completion time: 2011-04-18 22:57:33 - MACHINE was rebooted ComboFix-quarantined-files.txt 2011-04-18 21:57 . Pre-Run: 10,001,489,920 bytes free Post-Run: 8,793,120,768 bytes free . - - End Of File - - 4DA887D544D059E7895194C9DAB74592 Please go to Jotti's malware scan (If more than one file needs scanned they must be done separately and links posted for each one) * Copy the file path in the below Code box: Code: [Select]C:\Windows\System32\igfxCoIn_v1187.dll * At the upload site, click once inside the window next to Browse. * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. * Next click Submit file * Your file will possibly be entered into a queue which normally takes less than a minute to clear. * This will perform a scan across multiple different virus scanning engines. * Important: Wait for all of the scanning engines to complete. * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply. Something else to try: Make sure, your computer is set to obtain IP address automatically. 1. Go Start>Settings>Control Panel (Vista/7 users: Start>Control Panel) 2. Double click Network CONNECTIONS (Vista/7 users: Network and Sharing Center) 3. Vista/7 users - From the list of tasks on the left, click Manage network connections. 4. For a wired network connection, right-click Local Area Connection, and then select Properties. For a wireless network connection, right-click Wireless Network Connection, and then select Properties. 5. From the General tab (Vista/7 users: Networking tab), click Internet Protocol (TCP/IP), make sure it is checked, and then click Properties 6. Click Obtain an IP Address Automatically, and then click OK. Didn't find anything! http://virusscan.jotti.org/en-GB/scanresult/9148c0cb6a1cdaaa76848a7c21491d9ba25cad32Ok. Please try the IP fix I posted.Yep I tried that, the settings are all as they should be.Please run the ping test in Reply # 5. I want to see if anything has changed. Turn off computer. Disconnect router, and modem from power source for 1 minute. At the same time disconnect ethernet cable as well. Reconnect everything. Restart computer. Nothing seemed to be working so I had to wipe the disk and start again - internet now connects. Hopefully I won't get anything that bad again. thanks for your help!I'm sorry it had to come to that. Please make sure you have a good AV and a good firewall. I will post some links below. Remember to only install one antivirus! 1) Avast! Home Edition 2) AVG Free Edition 3) Avira AntiVir Personal 4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download 4-a) Microsoft Security Essentials for Windows XP 5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one) 6) PC Tools AntiVirus Free Edition It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. |
|
| 1377. |
Solve : Post-Antimalware Doctor Internet Problems? |
|
Answer» Dave, I hope I'm not speaking prematurely but that appears to have done it. I can access Microsoft Update, Google Chrome is working, the Windows theme is finally back to normal, this is great. I can't thank you enough. Only one thing, on your template (well, I'm assuming your instruction guides are templates) for the Recovery Console, the second and third pictures are inverted. It caused a second of minor confusion until I realized what it was supposed to look like. Very minor, I just thought I might let you know about that.Thanks for the feedback. I got that template from another malware fighter and I'll inform him about that. I would like you to run DDS as described in Reply # 16 and TDSSKiller as described in Reply # 7 Also, please run the Security Check below. Download Security Check by screen317 from one of the following links and save it to your desktop. LINK 1 Link 2 * Unzip SecurityCheck.zip and a folder named Security Check should appear. * Open the Security Check folder and double-click Security Check.bat * Follow the on-screen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.2011/04/24 16:00:17.0234 6040 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28 2011/04/24 16:00:17.0640 6040 ================================================================================ 2011/04/24 16:00:17.0640 6040 SystemInfo: 2011/04/24 16:00:17.0640 6040 2011/04/24 16:00:17.0640 6040 OS Version: 5.1.2600 ServicePack: 3.0 2011/04/24 16:00:17.0640 6040 Product type: Workstation 2011/04/24 16:00:17.0640 6040 ComputerName: TELKERNEW 2011/04/24 16:00:17.0640 6040 UserName: MATT 2011/04/24 16:00:17.0640 6040 Windows directory: C:\WINDOWS 2011/04/24 16:00:17.0640 6040 System windows directory: C:\WINDOWS 2011/04/24 16:00:17.0640 6040 Processor architecture: Intel x86 2011/04/24 16:00:17.0640 6040 Number of processors: 2 2011/04/24 16:00:17.0640 6040 Page size: 0x1000 2011/04/24 16:00:17.0640 6040 Boot type: Normal boot 2011/04/24 16:00:17.0640 6040 ================================================================================ 2011/04/24 16:00:17.0859 6040 INITIALIZE success 2011/04/24 16:02:01.0859 4912 ================================================================================ 2011/04/24 16:02:01.0859 4912 Scan started 2011/04/24 16:02:01.0859 4912 Mode: Manual; 2011/04/24 16:02:01.0859 4912 ================================================================================ 2011/04/24 16:02:02.0203 4912 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/04/24 16:02:02.0234 4912 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/04/24 16:02:02.0281 4912 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/04/24 16:02:02.0312 4912 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys 2011/04/24 16:02:02.0468 4912 Aken (66c6d13334efc090347c7f4f3e57034c) C:\Documents and Settings\Matt\Local Settings\Application Data\0 A.D. alpha\binaries\system\aken.sys 2011/04/24 16:02:02.0593 4912 Ambfilt (267fc636801edc5ab28e14036349e3be) C:\WINDOWS\system32\drivers\Ambfilt.sys 2011/04/24 16:02:02.0671 4912 amdide (6e58654cb25730b2579e45e1fd116a47) C:\WINDOWS\system32\DRIVERS\amdide.sys 2011/04/24 16:02:02.0718 4912 AmdPPM (033448d435e65c4bd72e70521fd05c76) C:\WINDOWS\system32\DRIVERS\AmdPPM.sys 2011/04/24 16:02:02.0812 4912 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/04/24 16:02:02.0828 4912 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/04/24 16:02:02.0953 4912 ati2mtag (eb0531822aabcf843a0940d4ca8a90a9) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/04/24 16:02:03.0015 4912 AtiHdmiService (b9bc23b57765c167806a1feb7a3d16a6) C:\WINDOWS\system32\drivers\AtiHdmi.sys 2011/04/24 16:02:03.0046 4912 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/04/24 16:02:03.0078 4912 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/04/24 16:02:03.0125 4912 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/04/24 16:02:03.0265 4912 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/04/24 16:02:03.0312 4912 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/04/24 16:02:03.0343 4912 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/04/24 16:02:03.0375 4912 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/04/24 16:02:03.0421 4912 Cdr4_xp (c3e76b0c05ebf7261abfb08d9e75822e) C:\WINDOWS\system32\drivers\Cdr4_xp.sys 2011/04/24 16:02:03.0437 4912 Cdralw2k (17590dfe29e02842a6e3a463e443d1b9) C:\WINDOWS\system32\drivers\Cdralw2k.sys 2011/04/24 16:02:03.0453 4912 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/04/24 16:02:03.0500 4912 cmderd (61b20ca85950870fa23587b26f3e4d7d) C:\WINDOWS\system32\DRIVERS\cmderd.sys 2011/04/24 16:02:03.0515 4912 cmdGuard (dd530ee7d9efbb0ec42aebe7226b8a93) C:\WINDOWS\system32\DRIVERS\cmdguard.sys 2011/04/24 16:02:03.0531 4912 cmdHlp (07cbbe993ed08a52dafac1e6cf27b6a5) C:\WINDOWS\system32\DRIVERS\cmdhlp.sys 2011/04/24 16:02:03.0609 4912 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/04/24 16:02:03.0640 4912 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/04/24 16:02:03.0656 4912 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys 2011/04/24 16:02:03.0671 4912 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/04/24 16:02:03.0703 4912 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/04/24 16:02:03.0781 4912 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/04/24 16:02:03.0796 4912 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/04/24 16:02:03.0828 4912 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/04/24 16:02:03.0843 4912 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/04/24 16:02:03.0843 4912 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/04/24 16:02:03.0875 4912 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/04/24 16:02:03.0921 4912 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/04/24 16:02:03.0953 4912 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/04/24 16:02:04.0000 4912 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 2011/04/24 16:02:04.0015 4912 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/04/24 16:02:04.0046 4912 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys 2011/04/24 16:02:04.0078 4912 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/04/24 16:02:04.0093 4912 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/04/24 16:02:04.0156 4912 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 2011/04/24 16:02:04.0203 4912 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 2011/04/24 16:02:04.0218 4912 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 2011/04/24 16:02:04.0250 4912 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/04/24 16:02:04.0281 4912 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/04/24 16:02:04.0343 4912 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/04/24 16:02:04.0421 4912 Inspect (8154a2c13b72b08db11157673c60c3eb) C:\WINDOWS\system32\DRIVERS\inspect.sys 2011/04/24 16:02:04.0578 4912 IntcAzAudAddService (262b0ab01671882e1c14ba8573583c32) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2011/04/24 16:02:04.0640 4912 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/04/24 16:02:04.0671 4912 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/04/24 16:02:04.0687 4912 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/04/24 16:02:04.0718 4912 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/04/24 16:02:04.0734 4912 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/04/24 16:02:04.0781 4912 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/04/24 16:02:04.0828 4912 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/04/24 16:02:04.0875 4912 ISODrive (2f03ceb28307983f3b36216d35ffa5aa) C:\Program Files\UltraISO\drivers\ISODrive.sys 2011/04/24 16:02:04.0890 4912 JGOGO (c995c0e8b4503fac38793bb0236ad246) C:\WINDOWS\system32\DRIVERS\JGOGO.sys 2011/04/24 16:02:04.0906 4912 JRAID (66a54519ed42ec2ccca592f47eb02c5d) C:\WINDOWS\system32\DRIVERS\jraid.sys 2011/04/24 16:02:04.0937 4912 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/04/24 16:02:04.0968 4912 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/04/24 16:02:05.0000 4912 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/04/24 16:02:05.0046 4912 LHidFlt2 (27bbea62dfafc495e956d3911ebc3045) C:\WINDOWS\system32\DRIVERS\LHidFlt2.sys 2011/04/24 16:02:05.0078 4912 LKbdFlt2 (bbc297ea4fc97fc7b85f70915345c80a) C:\WINDOWS\system32\DRIVERS\LKbdFlt2.sys 2011/04/24 16:02:05.0109 4912 LMouFlt2 (45df10f44f6a140a4f3dd377676603f2) C:\WINDOWS\system32\DRIVERS\LMouFlt2.sys 2011/04/24 16:02:05.0140 4912 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/04/24 16:02:05.0171 4912 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/04/24 16:02:05.0234 4912 Monfilt (c7d9f9717916b34c1b00dd4834af485c) C:\WINDOWS\system32\drivers\Monfilt.sys 2011/04/24 16:02:05.0265 4912 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/04/24 16:02:05.0296 4912 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/04/24 16:02:05.0328 4912 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/04/24 16:02:05.0359 4912 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/04/24 16:02:05.0390 4912 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/04/24 16:02:05.0421 4912 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/04/24 16:02:05.0453 4912 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/04/24 16:02:05.0468 4912 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/04/24 16:02:05.0484 4912 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/04/24 16:02:05.0531 4912 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/04/24 16:02:05.0562 4912 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/04/24 16:02:05.0578 4912 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/04/24 16:02:05.0640 4912 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/04/24 16:02:05.0671 4912 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/04/24 16:02:05.0703 4912 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/04/24 16:02:05.0734 4912 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/04/24 16:02:05.0750 4912 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/04/24 16:02:05.0765 4912 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/04/24 16:02:05.0812 4912 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/04/24 16:02:05.0859 4912 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/04/24 16:02:05.0875 4912 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/04/24 16:02:05.0906 4912 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/04/24 16:02:05.0921 4912 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/04/24 16:02:05.0984 4912 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/04/24 16:02:06.0031 4912 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/04/24 16:02:06.0046 4912 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/04/24 16:02:06.0093 4912 OVT511Plus (c5739be3a8eecdf951955a38e1741f45) C:\WINDOWS\system32\Drivers\omcamvid.sys 2011/04/24 16:02:06.0109 4912 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 2011/04/24 16:02:06.0125 4912 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/04/24 16:02:06.0171 4912 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/04/24 16:02:06.0187 4912 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/04/24 16:02:06.0218 4912 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\drivers\PCIIde.sys 2011/04/24 16:02:06.0250 4912 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/04/24 16:02:06.0390 4912 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/04/24 16:02:06.0406 4912 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 2011/04/24 16:02:06.0421 4912 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/04/24 16:02:06.0437 4912 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/04/24 16:02:06.0453 4912 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/04/24 16:02:06.0562 4912 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/04/24 16:02:06.0609 4912 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/04/24 16:02:06.0625 4912 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/04/24 16:02:06.0640 4912 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/04/24 16:02:06.0656 4912 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/04/24 16:02:06.0671 4912 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/04/24 16:02:06.0703 4912 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/04/24 16:02:06.0734 4912 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/04/24 16:02:06.0750 4912 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/04/24 16:02:06.0796 4912 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys 2011/04/24 16:02:06.0859 4912 RTLE8023xp (e511d68f1ba6170a7178b7c4267c26cb) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 2011/04/24 16:02:06.0937 4912 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/04/24 16:02:06.0968 4912 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/04/24 16:02:07.0015 4912 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/04/24 16:02:07.0062 4912 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 2011/04/24 16:02:07.0093 4912 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/04/24 16:02:07.0140 4912 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/04/24 16:02:07.0203 4912 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/04/24 16:02:07.0265 4912 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys 2011/04/24 16:02:07.0312 4912 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/04/24 16:02:07.0343 4912 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/04/24 16:02:07.0390 4912 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys 2011/04/24 16:02:07.0421 4912 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/04/24 16:02:07.0437 4912 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/04/24 16:02:07.0484 4912 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/04/24 16:02:07.0562 4912 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/04/24 16:02:07.0625 4912 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/04/24 16:02:07.0656 4912 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/04/24 16:02:07.0687 4912 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/04/24 16:02:07.0703 4912 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/04/24 16:02:07.0765 4912 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/04/24 16:02:07.0828 4912 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/04/24 16:02:07.0875 4912 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys 2011/04/24 16:02:07.0968 4912 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/04/24 16:02:07.0984 4912 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/04/24 16:02:08.0000 4912 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/04/24 16:02:08.0015 4912 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/04/24 16:02:08.0031 4912 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 2011/04/24 16:02:08.0078 4912 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/04/24 16:02:08.0093 4912 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/04/24 16:02:08.0125 4912 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/04/24 16:02:08.0140 4912 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/04/24 16:02:08.0218 4912 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/04/24 16:02:08.0250 4912 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/04/24 16:02:08.0281 4912 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys 2011/04/24 16:02:08.0328 4912 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys 2011/04/24 16:02:08.0406 4912 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/04/24 16:02:08.0468 4912 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 2011/04/24 16:02:08.0546 4912 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/04/24 16:02:08.0609 4912 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/04/24 16:02:08.0625 4912 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/04/24 16:02:08.0781 4912 ================================================================================ 2011/04/24 16:02:08.0781 4912 Scan finished 2011/04/24 16:02:08.0781 4912 ================================================================================ . DDS (Ver_11-03-05.01) - NTFSx86 Run by Matt at 16:03:43.34 on Sun 04/24/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2309 [GMT -4:00] . AV: COMODO Antivirus *Enabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B} FW: COMODO Firewall *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe C:\WINDOWS\Explorer.EXE C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Browny02\Brother\BrStMonW.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe svchost.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\DNA\btdna.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Hamachi\hamachi-2.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\wanmpsvc.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Browny02\BrYNSvc.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Documents and Settings\Matt\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\10.0.648.205\npchrome_frame.dll TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [RoxioEngineUtility] "c:\program files\common files\roxio shared\system\EngUtil.exe" mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe" mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe" mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini" mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe dRunOnce: [RunNarrator] Narrator.exe dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe StartupFolder: c:\docume~1\matt\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - /105 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1294469241906 DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab DPF: {7E1C8369-99C1-46BA-86C7-1BF331ADEB2B} - hxxps://www51.honeywell.com/checkbrowser/ax/CBSystemCheck.CAB DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} - hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.26.2.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: {D8B65097-3AB9-476E-83B5-699E51D7B4D8} = 156.154.70.22,156.154.71.22 Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\10.0.648.205\npchrome_frame.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs: c:\windows\system32\guard32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\matt\applic~1\mozilla\firefox\profiles\xcgcf8sm.default\ FF - plugin: c:\documents and settings\matt\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\documents and settings\matt\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: Java Quick Starter: [email protected] - c:\program files\java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Torbutton: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca} - %profile%\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca} FF - Ext: vShare: [email protected] - %profile%\extensions\[email protected] . ---- FIREFOX POLICIES ---- FF - user.js: network.protocol-handler.warn-external.dnupdate - false . ============= SERVICES / DRIVERS =============== . R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2010-6-1 15592] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 239368] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 27576] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2010-6-1 1803224] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\hamachi\hamachi-2.exe [2011-3-28 1242504] R3 BrYNSvc;BrYNSvc;c:\program files\browny02\BrYNSvc.exe [2011-2-13 245760] R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-29 135664] S3 Aken;Aken;c:\documents and settings\matt\local settings\application data\0 a.d. alpha\binaries\system\aken.sys [2007-6-17 3712] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-9-10 1691480] S3 icsak;icsak;\??\c:\program files\checkpoint\zaforcefield\ak\icsak.sys --> c:\program files\checkpoint\zaforcefield\ak\icsak.sys [?] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.1.121\McCHSvc.exe [2010-9-3 227232] S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\e3.tmp --> c:\windows\system32\E3.tmp [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-04-24 01:40:34 -------- d-sha-r- C:\cmdcons 2011-04-24 01:22:09 98816 ----a-w- c:\windows\sed.exe 2011-04-24 01:22:09 89088 ----a-w- c:\windows\MBR.exe 2011-04-24 01:22:09 256512 ----a-w- c:\windows\PEV.exe 2011-04-24 01:22:09 161792 ----a-w- c:\windows\SWREG.exe 2011-04-22 21:36:00 -------- d-----w- c:\program files\Sophos 2011-04-21 15:56:12 -------- d-----w- c:\docume~1\matt\applic~1\SUPERAntiSpyware.com 2011-04-21 15:56:12 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2011-04-21 15:55:53 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-04-21 15:29:09 -------- d-----w- c:\windows\system32\wbem\repository\FS 2011-04-21 15:29:09 -------- d-----w- c:\windows\system32\wbem\Repository 2011-04-21 05:05:11 -------- d-----w- c:\program files\common files\iS3 2011-04-21 05:05:10 -------- d-----w- c:\docume~1\alluse~1\applic~1\STOPzilla! 2011-03-29 13:56:20 -------- d-----w- c:\program files\Hamachi . ==================== Find3M ==================== . 2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys 2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll 2011-02-22 23:06:29 43520 ------w- c:\windows\system32\licmgr10.dll 2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-02-22 11:41:59 385024 ------w- c:\windows\system32\html.iec 2011-02-18 21:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll 2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll 2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll 2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll 2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll 2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll 2011-02-03 02:40:23 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-02-03 00:19:39 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll 2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe 2011-01-26 22:35:04 1112576 ----a-w- c:\windows\system32\ativvamv.dll . ============= FINISH: 16:06:44.89 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 1/8/2011 1:31:05 AM System Uptime: 4/24/2011 3:20:15 PM (1 hours ago) . Motherboard: ECS | | A780GM-A Ultra Processor: AMD Athlon(tm) II X2 240 Processor | CPU 1 | 2800/200mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 298 GiB total, 139.07 GiB free. D: is CDROM () E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP21: 1/21/2011 12:22:03 PM - System Checkpoint RP22: 1/22/2011 1:00:38 PM - System Checkpoint RP23: 1/23/2011 1:04:26 PM - System Checkpoint RP24: 1/23/2011 2:52:57 PM - Printer Driver EPSON Stylus Photo R280 Series Installed RP25: 1/25/2011 4:44:04 PM - System Checkpoint RP26: 1/26/2011 6:45:53 PM - System Checkpoint RP27: 1/27/2011 10:50:41 PM - System Checkpoint RP28: 1/28/2011 1:24:12 AM - DMX_DriverMax Driver Installation RP29: 1/28/2011 1:32:43 AM - DMX_DriverMax Driver Installation RP30: 1/29/2011 12:26:03 PM - System Checkpoint RP31: 1/29/2011 1:04:35 PM - DMX_DriverMax Driver Installation RP32: 1/29/2011 1:09:57 PM - DMX_DriverMax Driver Installation RP33: 2/2/2011 3:17:18 PM - System Checkpoint RP34: 2/4/2011 6:27:12 PM - System Checkpoint RP35: 2/6/2011 9:10:09 PM - System Checkpoint RP36: 2/8/2011 4:12:23 PM - System Checkpoint RP37: 2/9/2011 11:28:14 PM - Software Distribution Service 3.0 RP38: 2/12/2011 1:39:38 PM - Software Distribution Service 3.0 RP39: 2/13/2011 3:43:27 PM - System Checkpoint RP40: 2/13/2011 6:50:30 PM - Installed ScanSoft PaperPort 11 RP41: 2/13/2011 6:52:02 PM - Installed PaperPort Image Printer RP42: 2/13/2011 6:52:14 PM - Printer Driver Nuance Image Printer Driver Installed RP43: 2/13/2011 6:56:24 PM - Installed Brother Software Suite RP44: 2/13/2011 6:58:10 PM - Unsigned printer driver Brother PC-FAX v.2.1 installed. RP45: 2/14/2011 8:28:06 PM - System Checkpoint RP46: 2/16/2011 12:41:33 PM - System Checkpoint RP47: 2/27/2011 2:39:07 PM - System Checkpoint RP48: 2/28/2011 5:41:38 PM - System Checkpoint RP49: 3/1/2011 5:59:19 PM - System Checkpoint RP50: 3/3/2011 4:03:55 PM - System Checkpoint RP51: 3/4/2011 6:27:59 PM - System Checkpoint RP52: 3/5/2011 4:03:10 PM - Installed Java(TM) 6 Update 24 RP53: 3/5/2011 4:03:48 PM - Installed Java Runtime Environment RP54: 3/6/2011 6:50:11 PM - System Checkpoint RP55: 3/6/2011 11:33:49 PM - Installed Mobile Mouse Server. RP56: 3/7/2011 11:09:09 PM - Software Distribution Service 3.0 RP57: 3/8/2011 9:36:40 PM - Software Distribution Service 3.0 RP58: 3/8/2011 10:07:17 PM - Removed XBList RP59: 3/9/2011 6:22:42 PM - Removed ATI Catalyst Install Manager RP60: 3/10/2011 6:56:40 PM - System Checkpoint RP61: 3/10/2011 6:58:30 PM - Removed Network Magic RP62: 3/10/2011 6:59:07 PM - Removed Pure Networks Platform RP63: 3/10/2011 7:05:02 PM - Removed TortoiseSVN 1.6.7.18415 (32 bit) RP64: 3/11/2011 7:20:37 PM - System Checkpoint RP65: 3/12/2011 8:36:25 PM - System Checkpoint RP66: 3/15/2011 4:47:27 PM - System Checkpoint RP67: 3/16/2011 8:25:23 PM - System Checkpoint RP68: 3/17/2011 9:24:07 PM - System Checkpoint RP69: 3/19/2011 3:30:39 PM - System Checkpoint RP70: 3/20/2011 3:52:39 PM - System Checkpoint RP71: 3/21/2011 5:29:42 PM - System Checkpoint RP72: 3/22/2011 7:09:03 PM - System Checkpoint RP73: 3/23/2011 4:22:37 PM - Software Distribution Service 3.0 RP74: 3/24/2011 4:32:01 PM - System Checkpoint RP75: 3/25/2011 6:00:31 PM - System Checkpoint RP76: 3/27/2011 12:33:09 PM - System Checkpoint RP77: 3/28/2011 4:06:28 PM - System Checkpoint RP78: 3/29/2011 5:16:46 PM - System Checkpoint RP79: 3/30/2011 5:19:31 PM - System Checkpoint RP80: 3/31/2011 5:21:09 PM - System Checkpoint RP81: 4/1/2011 6:26:30 PM - System Checkpoint RP82: 4/2/2011 8:43:47 PM - System Checkpoint RP83: 4/4/2011 5:15:25 PM - System Checkpoint RP84: 4/5/2011 7:07:37 PM - System Checkpoint RP85: 4/7/2011 4:59:37 PM - System Checkpoint RP86: 4/8/2011 8:07:06 PM - System Checkpoint RP87: 4/10/2011 11:42:38 AM - System Checkpoint RP88: 4/11/2011 4:55:29 PM - System Checkpoint RP89: 4/12/2011 5:34:37 PM - System Checkpoint RP90: 4/13/2011 7:49:47 PM - System Checkpoint RP91: 4/14/2011 11:00:32 PM - Software Distribution Service 3.0 RP92: 4/16/2011 9:54:19 AM - System Checkpoint RP93: 4/17/2011 1:13:27 PM - System Checkpoint RP94: 4/18/2011 3:06:27 PM - System Checkpoint RP95: 4/19/2011 4:46:53 PM - System Checkpoint RP96: 4/20/2011 5:02:51 PM - System Checkpoint RP97: 4/21/2011 1:05:03 AM - Installed STOPzilla. Available with Windows Installer version 1.2 and later. RP98: 4/21/2011 1:30:10 AM - Removed STOPzilla. Available with Windows Installer version 1.2 and later. RP99: 4/21/2011 11:25:41 AM - Restore Operation RP100: 4/21/2011 11:28:15 AM - Restore Operation RP101: 4/24/2011 3:47:48 PM - System Checkpoint . ==== Installed Programs ====================== . µTorrent 0 A.D. 7-Zip 9.20 Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.4.3 Advertising Center Alien Swarm Alien Swarm - SDK AOL Uninstaller (Choose which Products to Remove) Apple Application Support Apple Mobile Device Support Apple Software Update ATI AVIVO Codecs ATI Catalyst Install Manager ATI Parental Control & Encoder ATI Problem Report Wizard ATI Stream SDK v2 Developer Battlefield 2(TM) Battlefield 2: Special Forces Battlefield Play4Free (Matt) Bonjour Brother MFL-Pro Suite MFC-J265W Call of Duty Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center HydraVision Full Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-preinstall ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CCleaner Chinese Traditional Fonts Support For Adobe Reader 9 COMODO Internet Security Compatibility Pack for the 2007 Office system Dedicated Server Definition update for Microsoft Office 2010 (KB982726) DivX Setup DNA DolbyFiles Download Updater (AOL LLC) DriverMax 5 Game Booster Garry's Mod Google Chrome Google Chrome Frame Google Earth Google Update Helper HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB973442) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB961118) HP Photo and Imaging 2.0 - All-in-One HP Photo and Imaging 2.0 - All-in-One Drivers hp psc 2200 series HyperCam 2 ImagXpress iPhone Configuration Utility iTunes Java Auto Updater Java(TM) 6 Update 24 JMicron JMB36X Driver Junk Mail filter update LAME v3.98.2 for Audacity LogMeIn Hamachi Malwarebytes' Anti-Malware McAfee Security Scan Plus Menu Templates - Starter Kit Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office Live Add-in 1.4 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Edition 2003 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 14 Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mobile Mouse Server MobileMe Control Panel Movie Templates - Starter Kit Mozilla Firefox (3.6.16) MSN MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NaturalMotion endorphin 2.7.1 Nero 8 Essentials Nero 9 Essentials Nero BurnRights Nero BurnRights Help Nero ControlCenter Nero CoverDesigner Nero CoverDesigner Help Nero DiscSpeed Nero DiscSpeed Help Nero DriveSpeed Nero DriveSpeed Help Nero Express Help Nero InfoTool Nero InfoTool Help Nero Installer Nero Online Upgrade Nero ShowTime Nero StartSmart Nero StartSmart Help Nero Vision Nero Vision Help NeroExpress neroxml NVIDIA PhysX OGA Notifier 2.0.0048.0 ooVoo OpenAL PaperPort Image Printer Polipo 1.0.4.1 Portal Project Reality 0909 Full - Part 1 of 2 Project Reality 0909 Full - Part 2 of 2 Project Reality 0917 Patch Project S PunkBuster Services QuickTime Readiris 7.5 Realtek High Definition Audio Driver Rootkit Unhooker LE 3.8 SR 2 Roxio PhotoSuite 5 Safari ScanSoft PaperPort 11 Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft Excel 2010 (KB2466146) Security Update for Microsoft Office 2010 (KB2289078) Security Update for Microsoft Office 2010 (KB2289161) Security Update for Microsoft PowerPoint 2010 (KB2519975) Security Update for Microsoft Publisher 2010 (KB2409055) Security Update for Microsoft Word 2010 (KB2345000) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2416400) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Segoe UI Sid Meier's Civilization 4 Snood 4 Sophos Anti-Rootkit 1.5.4 Source SDK Source SDK Base SpywareBlaster 4.2 SpywareGuard v2.2 Stay On Top Steam SUPERAntiSpyware System Requirements Lab System Requirements Lab CYRI Team Fortress 2 Team Fortress 2 Dedicated Server Tor 0.2.2.19-alpha Trader's Little Helper 2.6.0 UltraISO Premium V9.36 Uninstall AOL Emergency Connect Utility 1.0 Unity Web Player Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2010 (KB2202188) Update for Microsoft Office 2010 (KB2413186) Update for Microsoft OneNote 2010 (KB2493983) Update for Microsoft Outlook Social Connector (KB2441641) Update for Microsoft Windows (KB971513) Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC 9.0 Runtime VC80CRTRedist - 8.0.50727.4053 VCRedistSetup Vegas Movie Studio HD Platinum 10.0 Ventrilo Client Vidalia 0.2.10 Viewpoint Media Player Virus Guard - powered by BitDefender WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Mail Windows Live Messenger Windows Live Upload Tool Windows Management Framework Core Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinSCP 4.3.1 beta WolfQuest . ==== Event Viewer Messages From Past Week ======== . 90884761 AmdPPM cmdGuard Fips PCIIde SASDIFSV SASKUTIL setup_9.0.0.722_21.04.2011_20-58[1]drv sptd 4/23/2011 12:15:42 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect. 4/23/2011 12:15:42 PM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 4/23/2011 12:15:31 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE} 4/23/2011 10:33:12 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect. 4/23/2011 10:33:12 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 4/22/2011 8:22:31 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 4/22/2011 8:15:29 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 4/22/2011 8:08:36 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 4/22/2011 2:44:18 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 4/22/2011 2:40:19 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} 4/22/2011 12:12:41 PM, error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 4/22/2011 1:34:30 PM, error: WMPNetworkSvc [14344] - A new media server was not initialized because WMCreateDeviceRegistration() encountered error '0xc00d2711'. The Windows Media DRM components on your computer might be corrupted. Verify that protected files play correctly in Windows Media Player, and then restart the WMPNetworkSvc service. 4/22/2011 1:12:49 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 4/21/2011 5:26:58 PM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists. 4/21/2011 5:24:57 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde sptd 4/21/2011 5:22:19 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 4/21/2011 4:44:18 PM, error: Service Control Manager [7034] - The LogMeIn Hamachi 2.0 Tunneling Engine service terminated unexpectedly. It has done this 1 time(s). 4/21/2011 4:41:01 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: 4/20/2011 11:00:09 AM, error: WMPNetworkSvc [14344] - A new media server was not initialized because WMCreateDeviceRegistration() encountered error '0xc00d2721'. The Windows Media DRM components on your computer might be corrupted. Verify that protected files play correctly in Windows Media Player, and then restart the WMPNetworkSvc service. 4/20/2011 10:59:50 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: sptd 4/20/2011 10:59:28 AM, error: Service Control Manager [7000] - The Zune Bus Enumerator Driver service failed to start due to the following error: The system cannot find the file specified. 4/20/2011 10:58:57 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service NMIndexingService with arguments "" in order to run the server: {E8933C4B-2C90-4A04-A677-E958D9509F1A} 4/20/2011 10:58:46 AM, error: sptd [4] - Driver detected an internal error in its data structures for . . ==== End Of File =========================== It says there is an out of date Adobe Reader installed but I just updated it and it is current, to the best of my knowledge. Results of screen317's Security Check version 0.99.10 Windows XP Service Pack 3 Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! Virus Guard - powered by BitDefender McAfee Security Scan Plus Antivirus up to date! ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware CCleaner Java(TM) 6 Update 24 Adobe Flash Player 10.2.152.26 Adobe Reader 9.4.4 Chinese Traditional Fonts Support For Adobe Reader 9 Out of date Adobe Reader installed! Mozilla Firefox (x86 en-US..) ```````````````````````````````` Process Check: objlist.exe by Laurent Comodo Firewall cmdagent.exe Comodo Firewall cfp.exe ``````````End of Log```````````` The DDS log shows that you're running COMODO Antivirus but the Security check shows Virus Guard - powered by BitDefender and McAfee Security Scan Plus. You should only run on AV program. Please run RootKitUnhooker as suggested in Reply # 19.Wow that thing takes forever. 3 hours later it tells me I have possible rootkit activity. That's saddening. I attached the log due to its length. [recovering disk space - old attachment deleted by admin]I wouldn't worry about it. The other scans came back clean. It's going to take some time to go throught the log. In the meantime, please run this scan and post the log. I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Here's the ESET log. C:\System Volume Information\_restore{9B7DE55D-7ECA-4DF7-A547-785275B6B0CA}\RP100\A0060161.ini Win32/Adware.AntimalwareDoctor.AE.Gen application cleaned by deleting - quarantined C:\System Volume Information\_restore{9B7DE55D-7ECA-4DF7-A547-785275B6B0CA}\RP100\A0062295.exe Win32/TrojanDownloader.FakeAlert.BBT trojan cleaned by deleting - quarantined Ok. If there's nothing else let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ********************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ********************************************************* Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping SITES. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Okay, I should be all set. As I've said many times before, I truly can't thank you enough! Best wishes to you.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 1378. |
Solve : Possible Virus, otherwise Registry Issue? |
|
Answer» I removed SysProt and ESET. Is there SOMETHING I installed that replaces SAS and MBAM? I don't mind keeping them around as I've had them for years. Is there something I installed that replaces SAS and MBAM?Windows Defender should do just about the same thing but I LIKE to run them on a regular basis. Quote TFC, and Secunia. Should I delete CCleaner if I installed TFC?You can get rid of all three, if you wish. You can do the same thing by using "disk cleanup" Quote And the Avast situation...why isn't it coming on automatically anymore?If I were you, I would get rid of Avast and install MicroSoft SECURITY Essentials. No need to register it and it updates automatically. Microsoft Security Essentials for Windows XP |
|
| 1379. |
Solve : I have a trojan? |
|
Answer» That's GREAT news. PLEASE keep me updated.Sorry, I was PREMATURE in thinking that the PROBLEM was solved. I'm still LOOKING though. |
|
| 1380. |
Solve : Can't run pgms. I am trying to install ran Hijackthis posted log. Anyone?? |
|
Answer» Please run ESET again and this time, fix the infections and post the log.doneSo, how's your computer running now? Any other issues?Still unable run the pgm. Quote Still unable run the pgm.Please explain. Do you mean you can't run any programs? Do you get any error messages?Ok probably should have covered this question at the front end, but here we go 1. Bought a little pgm wouldn't run got error msg They eventually responded and said I needed the .net 4 framework. Net 4 said I needed a WIC file/pgm, whatever, found here http://www.microsoft.com/downloads/en/details.aspx?FamilyId=8E011506-6307-445B-B950-215DEF45DDD8&displaylang=en#AffinityDownloads When I saw this page and instructions at bottom didn't know which to download, sounded like there was suppose to be a download button for the whole package. So I downloaded the .esn one for English I'm guessing. Anyway was able to install .Net 4 . Now I get another error msg. Wondering do I need Net 2 or other or diff wic package? Very confusing. [recovering disk space - old attachment deleted by admin]I don't want to sound dense but what is a little pgm? Quote They eventually responded and said I needed the .net 4 framework.Who is They? I did a bit of checking about Net 4 network and there are a couple of sites where you can download it from MS. I'm sorry but I can't help you with that problem. You might have better luck posting that problem in the software forum. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, EXECUTION time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block OUTGOING connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security ADDON for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT WARNS you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 1381. |
Solve : Have virus. Need to copy information. Please help.? |
|
Answer» I have a virus that is preventing me from UPLOADING my files to a CD. I don't need help with the virus. Just with transferring my files. I just bought a mac and need to transfer the files. Is there a virtual website that I can TEMPORARILY store my files? Or, would I have better LUCK with a flash DRIVE? Many thanks. |
|
| 1382. |
Solve : Can someone help me please!!? |
|
Answer» http://virusscan.jotti.org/en-gb/scanresult/01b7612528486ee80756776c20e5be28dd792b5f http://virusscan.jotti.org/en-gb/scanresult/fc5eb0e11068590e5fbc6d3b16b706d3f8e4a611 http://virusscan.jotti.org/en-gb/scanresult/84391c69438966404bbdce4fc504ddcf4e87473f http://virusscan.jotti.org/en-gb/scanresult/9880348cf42936dbe2702d75b9841c5bebf7b9f7 Sorry i couldn't find the last link you listed.ComboFix 11-05-09.03 - Owner 10/05/2011 18:13:20.2.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1014.545 [GMT 1:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\bL28601CaIgA28601 c:\documents and settings\All Users\Application Data\bL28601CaIgA28601\bL28601CaIgA28601 c:\documents and settings\Owner\Application Data\xfgkxer1hbbxwfxokvojijtyebjdow3k2 . . ((((((((((((((((((((((((( Files Created from 2011-04-10 to 2011-05-10 ))))))))))))))))))))))))))))))) . . 2011-05-08 11:48 . 2011-05-09 16:33 -------- d-----w- c:\documents and settings\Owner\Application Data\Ulirmo 2011-05-05 21:25 . 2011-05-05 21:25 135680 ----a-w- c:\windows\system32\drivers\ethxylvf.sys 2011-05-05 21:22 . 2011-05-05 21:22 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-05-05 21:22 . 2011-05-05 21:22 -------- d-----w- c:\program files\Trend Micro 2011-05-05 21:20 . 2011-05-05 21:20 -------- d-----w- c:\program files\Common Files\Java 2011-05-05 20:44 . 2011-05-05 20:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2011-05-05 20:35 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-05 20:35 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-05-05 20:32 . 2011-05-05 20:32 -------- d-----w- c:\program files\CCleaner 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\rpcns4H.dll 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\logonuiv.dll 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\ialmuTHAU.dll 2011-05-05 18:41 . 2011-04-11 07:04 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C8C2A59-AC6B-4305-BF8F-AA42A1FBBBC0}\mpengine.dll 2011-04-29 12:34 . 2011-04-29 12:34 -------- d-----w- c:\windows\system32\wbem\Repository 2011-04-29 12:30 . 2011-04-29 12:33 -------- d-s---w- c:\documents and settings\Administrator 2011-04-29 06:43 . 2011-04-29 06:43 -------- d-----w- c:\documents and settings\Owner\Application Data\Sibelius Software 2011-04-28 23:18 . 2011-04-28 23:18 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes 2011-04-28 23:18 . 2011-04-28 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-04-28 23:18 . 2011-05-05 20:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-04-28 22:38 . 2011-04-28 22:38 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com 2011-04-28 22:38 . 2011-05-08 11:50 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-04-25 15:51 . 2011-04-25 15:51 -------- d-----w- c:\program files\iPod 2011-04-25 15:51 . 2011-04-25 15:53 -------- d-----w- c:\program files\iTunes 2011-04-25 15:46 . 2011-04-25 15:46 -------- d-----w- c:\program files\Bonjour 2011-04-25 14:07 . 2011-04-25 14:07 -------- d-----r- C:\MSOCache 2011-04-25 13:59 . 2011-04-25 13:59 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\SoftGrid Client 2011-04-25 13:59 . 2011-05-09 17:10 -------- d-----w- c:\documents and settings\Owner\Application Data\SoftGrid Client 2011-04-25 13:59 . 2011-04-25 13:59 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0062-0409-0000-0000000FF1CE} 2011-04-25 13:59 . 2011-05-09 17:10 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client 2011-04-25 13:57 . 2011-04-25 13:57 -------- d-----w- c:\documents and settings\All Users\Microsoft 2011-04-25 13:57 . 2011-04-29 12:38 -------- d-----w- c:\program files\Microsoft Application Virtualization Client 2011-04-25 13:56 . 2011-04-25 14:01 -------- d-----w- c:\documents and settings\Owner\Application Data\TP 2011-04-18 21:13 . 2011-04-18 21:13 -------- d-----w- c:\documents and settings\Owner\Application Data\Amazon 2011-04-18 21:12 . 2011-04-18 21:12 -------- d-----w- c:\program files\Amazon 2011-04-17 14:07 . 2011-04-17 14:07 -------- d-----w- c:\windows\Sun 2011-04-16 14:29 . 2011-04-16 14:29 -------- d-----w- c:\documents and settings\Owner\Application Data\OpenOffice.org 2011-04-16 14:26 . 2011-04-16 14:26 -------- d-----w- c:\program files\OpenOffice.org 3 2011-04-16 14:25 . 2011-04-14 04:07 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-04-16 14:25 . 2011-04-14 01:40 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-04-16 14:25 . 2011-05-05 21:20 -------- d-----w- c:\program files\Java . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSTITL.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSTEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSTMP.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSPEC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSCRP.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSREH_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSMET_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSCHOR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRS____.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSTEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSSE__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSS___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSROMC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSPC__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSP___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSO___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSNN__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSM___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFS__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFBE_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFB__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSCSC_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSCS__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSC___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUS____.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INKPEN2_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2TEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2SPEC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2SCRI.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2METR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2CHOR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELST___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSS___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSM___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSINKI.FOT 2011-04-11 07:04 . 2011-02-06 22:20 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-04-06 15:20 . 2011-04-06 15:20 91424 ----a-w- c:\windows\system32\dnssd.dll 2011-04-06 15:20 . 2011-04-06 15:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 15:20 . 2011-04-06 15:20 197920 ----a-w- c:\windows\system32\dnssdX.dll 2011-04-06 15:20 . 2011-04-06 15:20 107808 ----a-w- c:\windows\system32\dns-sd.exe 2011-03-07 05:33 . 2011-01-11 19:25 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:37 . 2004-08-04 10:00 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:21 . 2004-08-04 10:00 1857920 ----a-w- c:\windows\system32\win32k.sys 2011-02-22 23:06 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll 2011-02-22 23:06 . 2004-08-04 10:00 43520 ------w- c:\windows\system32\licmgr10.dll 2011-02-22 23:06 . 2004-08-04 10:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-02-22 11:41 . 2004-08-04 10:00 385024 ------w- c:\windows\system32\html.iec 2011-02-17 13:18 . 2004-08-04 10:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-17 13:18 . 2004-08-04 10:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys 2011-02-17 12:32 . 2011-01-19 20:06 5120 ----a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56 . 2004-08-04 10:00 290432 ----a-w- c:\windows\system32\atmfd.dll . . ((((((((((((((((((((((((((((( [email protected]_16.53.14 ))))))))))))))))))))))))))))))))))))))))) . + 2011-01-11 09:59 . 2011-01-11 09:59 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_214ee422\vcomp90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90rus.dll + 2011-01-11 09:59 . 2011-01-11 09:59 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90kor.dll + 2011-01-11 09:59 . 2011-01-11 09:59 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90jpn.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90ita.dll + 2011-01-11 09:59 . 2011-01-11 09:59 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90fra.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esp.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esn.dll + 2011-01-11 09:59 . 2011-01-11 09:59 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90enu.dll + 2011-01-11 09:59 . 2011-01-11 09:59 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90deu.dll + 2011-01-11 09:59 . 2011-01-11 09:59 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90cht.dll + 2011-01-11 09:59 . 2011-01-11 09:59 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90chs.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90u.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90.dll + 2011-05-10 17:19 . 2011-05-10 17:19 16384 c:\windows\temp\Perflib_Perfdata_798.dat + 2011-01-11 09:59 . 2011-01-11 09:59 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcm90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_65b7a93a\atl90.dll + 2011-05-09 17:10 . 2011-05-09 17:10 223232 c:\windows\Installer\186080.msi + 2011-01-11 09:59 . 2011-01-11 09:59 3780936 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90u.dll + 2011-01-11 09:59 . 2011-01-11 09:59 3766088 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-08 2424192] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\Default User\Start Menu\Programs\Startup\ ykitl.exe [2011-5-8 284160] . c:\documents and settings\Owner\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP DIGITAL Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] ="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] ="Service" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management . R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656] R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [22/02/2007 12:28 30864] R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664] R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688] R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344] R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432] R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584] R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280] R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768] S0 nwba;nwba;c:\windows\system32\drivers\fxufjr.sys --> c:\windows\system32\drivers\fxufjr.sys [?] S1 ethxylvf;ethxylvf;c:\windows\system32\drivers\ethxylvf.sys [05/05/2011 22:25 135680] S2 AMService;AMService;c:\windows\TEMP\kixd\setup.exe run --> c:\windows\TEMP\kixd\setup.exe run [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04/08/2004 11:00 14336] S3 WMZuneComm;Zune Windows Mobile Connectivity Service;f:\zune\WMZuneComm.exe --> f:\zune\WMZuneComm.exe [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WINRM REG_MULTI_SZ WINRM . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-05-10 18:20 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] ="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] Denied: (A 2) (Everyone) ="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(640) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . - - - - - - - > 'explorer.exe'(560) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\SearchIndexer.exe c:\windows\system32\wscntfy.exe c:\windows\stsystra.exe c:\program files\OpenOffice.org 3\program\soffice.exe c:\program files\OpenOffice.org 3\program\soffice.bin c:\program files\iPod\bin\iPodService.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Completion time: 2011-05-10 18:23:43 - machine was rebooted ComboFix-quarantined-files.txt 2011-05-10 17:23 ComboFix2.txt 2011-05-09 16:54 . Pre-Run: 488,152,834,048 bytes free Post-Run: 488,185,438,208 bytes free . - - End Of File - - 39F9F2BE1C45ACA3A07C972651ABE405Ok. Just a few more things to do. Any improvement in your computer? Re-running ComboFix to remove infections:
DOWNLOAD Security Check by screen317 from one of the following links and save it to your desktop. Link 1 Link 2 * Unzip SecurityCheck.zip and a folder named Security Check should appear. * Open the Security Check folder and double-click Security Check.bat * Follow the on-screen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so. Results of screen317's Security Check version 0.99.10 Windows XP Service Pack 3 Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! Microsoft Security Essentials ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware CCleaner Java(TM) 6 Update 25 Out of date Java installed! Adobe Flash Player ```````````````````````````````` Process Check: objlist.exe by Laurent Microsoft Security Essentials msseces.exe ``````````End of Log```````````` ComboFix 11-05-10.02 - Owner 11/05/2011 18:10:05.3.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1014.559 [GMT 1:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . FILE :: "c:\documents and settings\Default User\Start Menu\Programs\Startup\" "c:\windows\system32\drivers\ethxylvf.sys" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\drivers\ethxylvf.sys . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_ethxylvf . . ((((((((((((((((((((((((( Files Created from 2011-04-11 to 2011-05-11 ))))))))))))))))))))))))))))))) . . 2011-05-08 11:48 . 2011-05-09 16:33 -------- d-----w- c:\documents and settings\Owner\Application Data\Ulirmo 2011-05-05 21:22 . 2011-05-05 21:22 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-05-05 21:22 . 2011-05-05 21:22 -------- d-----w- c:\program files\Trend Micro 2011-05-05 21:20 . 2011-05-05 21:20 -------- d-----w- c:\program files\Common Files\Java 2011-05-05 20:44 . 2011-05-05 20:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2011-05-05 20:35 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-05 20:35 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-05-05 20:32 . 2011-05-05 20:32 -------- d-----w- c:\program files\CCleaner 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\rpcns4H.dll 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\logonuiv.dll 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\ialmuTHAU.dll 2011-05-05 18:41 . 2011-04-11 07:04 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C8C2A59-AC6B-4305-BF8F-AA42A1FBBBC0}\mpengine.dll 2011-04-29 12:34 . 2011-04-29 12:34 -------- d-----w- c:\windows\system32\wbem\Repository 2011-04-29 12:30 . 2011-04-29 12:33 -------- d-s---w- c:\documents and settings\Administrator 2011-04-29 06:43 . 2011-04-29 06:43 -------- d-----w- c:\documents and settings\Owner\Application Data\Sibelius Software 2011-04-28 23:18 . 2011-04-28 23:18 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes 2011-04-28 23:18 . 2011-04-28 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-04-28 23:18 . 2011-05-05 20:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-04-28 22:38 . 2011-04-28 22:38 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com 2011-04-28 22:38 . 2011-05-08 11:50 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-04-25 15:51 . 2011-04-25 15:51 -------- d-----w- c:\program files\iPod 2011-04-25 15:51 . 2011-04-25 15:53 -------- d-----w- c:\program files\iTunes 2011-04-25 15:46 . 2011-04-25 15:46 -------- d-----w- c:\program files\Bonjour 2011-04-25 14:07 . 2011-04-25 14:07 -------- d-----r- C:\MSOCache 2011-04-25 13:59 . 2011-04-25 13:59 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\SoftGrid Client 2011-04-25 13:59 . 2011-05-10 18:53 -------- d-----w- c:\documents and settings\Owner\Application Data\SoftGrid Client 2011-04-25 13:59 . 2011-04-25 13:59 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0062-0409-0000-0000000FF1CE} 2011-04-25 13:59 . 2011-05-10 18:53 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client 2011-04-25 13:57 . 2011-04-25 13:57 -------- d-----w- c:\documents and settings\All Users\Microsoft 2011-04-25 13:57 . 2011-04-29 12:38 -------- d-----w- c:\program files\Microsoft Application Virtualization Client 2011-04-25 13:56 . 2011-04-25 14:01 -------- d-----w- c:\documents and settings\Owner\Application Data\TP 2011-04-18 21:13 . 2011-04-18 21:13 -------- d-----w- c:\documents and settings\Owner\Application Data\Amazon 2011-04-18 21:12 . 2011-04-18 21:12 -------- d-----w- c:\program files\Amazon 2011-04-17 14:07 . 2011-04-17 14:07 -------- d-----w- c:\windows\Sun 2011-04-16 14:29 . 2011-04-16 14:29 -------- d-----w- c:\documents and settings\Owner\Application Data\OpenOffice.org 2011-04-16 14:26 . 2011-04-16 14:26 -------- d-----w- c:\program files\OpenOffice.org 3 2011-04-16 14:25 . 2011-04-14 04:07 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-04-16 14:25 . 2011-04-14 01:40 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-04-16 14:25 . 2011-05-05 21:20 -------- d-----w- c:\program files\Java . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSTITL.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSTEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSTMP.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSPEC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSCRP.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSREH_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSMET_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSCHOR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRS____.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSTEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSSE__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSS___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSROMC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSPC__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSP___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSO___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSNN__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSM___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFS__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFBE_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFB__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSCSC_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSCS__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSC___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUS____.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INKPEN2_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2TEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2SPEC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2SCRI.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2METR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2CHOR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELST___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSS___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSM___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSINKI.FOT 2011-04-11 07:04 . 2011-02-06 22:20 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-04-06 15:20 . 2011-04-06 15:20 91424 ----a-w- c:\windows\system32\dnssd.dll 2011-04-06 15:20 . 2011-04-06 15:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 15:20 . 2011-04-06 15:20 197920 ----a-w- c:\windows\system32\dnssdX.dll 2011-04-06 15:20 . 2011-04-06 15:20 107808 ----a-w- c:\windows\system32\dns-sd.exe 2011-03-07 05:33 . 2011-01-11 19:25 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:37 . 2004-08-04 10:00 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:21 . 2004-08-04 10:00 1857920 ----a-w- c:\windows\system32\win32k.sys 2011-02-22 23:06 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll 2011-02-22 23:06 . 2004-08-04 10:00 43520 ------w- c:\windows\system32\licmgr10.dll 2011-02-22 23:06 . 2004-08-04 10:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-02-22 11:41 . 2004-08-04 10:00 385024 ------w- c:\windows\system32\html.iec 2011-02-17 13:18 . 2004-08-04 10:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-17 13:18 . 2004-08-04 10:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys 2011-02-17 12:32 . 2011-01-19 20:06 5120 ----a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56 . 2004-08-04 10:00 290432 ----a-w- c:\windows\system32\atmfd.dll . . ((((((((((((((((((((((((((((( [email protected]_16.53.14 ))))))))))))))))))))))))))))))))))))))))) . + 2011-01-11 09:59 . 2011-01-11 09:59 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_214ee422\vcomp90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90rus.dll + 2011-01-11 09:59 . 2011-01-11 09:59 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90kor.dll + 2011-01-11 09:59 . 2011-01-11 09:59 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90jpn.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90ita.dll + 2011-01-11 09:59 . 2011-01-11 09:59 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90fra.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esp.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esn.dll + 2011-01-11 09:59 . 2011-01-11 09:59 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90enu.dll + 2011-01-11 09:59 . 2011-01-11 09:59 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90deu.dll + 2011-01-11 09:59 . 2011-01-11 09:59 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90cht.dll + 2011-01-11 09:59 . 2011-01-11 09:59 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90chs.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90u.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90.dll + 2011-05-11 17:15 . 2011-05-11 17:15 16384 c:\windows\temp\Perflib_Perfdata_660.dat + 2011-01-11 09:59 . 2011-01-11 09:59 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcm90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_65b7a93a\atl90.dll + 2011-05-09 17:10 . 2011-05-09 17:10 223232 c:\windows\Installer\186080.msi + 2011-01-11 09:59 . 2011-01-11 09:59 3780936 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90u.dll + 2011-01-11 09:59 . 2011-01-11 09:59 3766088 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-08 2424192] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\Default User\Start Menu\Programs\Startup\ ykitl.exe [2011-5-8 284160] . c:\documents and settings\Owner\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] ="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] ="Service" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management . R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656] R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [22/02/2007 12:28 30864] R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664] R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688] R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344] R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432] R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584] R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280] R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768] S0 nwba;nwba;c:\windows\system32\drivers\fxufjr.sys --> c:\windows\system32\drivers\fxufjr.sys [?] S2 AMService;AMService;c:\windows\TEMP\kixd\setup.exe run --> c:\windows\TEMP\kixd\setup.exe run [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04/08/2004 11:00 14336] S3 WMZuneComm;Zune Windows Mobile Connectivity Service;f:\zune\WMZuneComm.exe --> f:\zune\WMZuneComm.exe [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WINRM REG_MULTI_SZ WINRM . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-05-11 18:16 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] ="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] Denied: (A 2) (Everyone) ="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(620) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . - - - - - - - > 'explorer.exe'(3248) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\SearchIndexer.exe c:\windows\system32\wscntfy.exe c:\windows\stsystra.exe c:\program files\OpenOffice.org 3\program\soffice.exe c:\program files\OpenOffice.org 3\program\soffice.bin c:\program files\iPod\bin\iPodService.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Completion time: 2011-05-11 18:19:13 - machine was rebooted ComboFix-quarantined-files.txt 2011-05-11 17:19 ComboFix2.txt 2011-05-10 17:23 ComboFix3.txt 2011-05-09 16:54 . Pre-Run: 488,131,448,832 bytes free Post-Run: 488,109,334,528 bytes free . - - End Of File - - 3134006567461E2BA064FDD000367D38 SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
by swatkat ****************************************************************************************** ****************************************************************************************** No Hidden Processes found ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: --- Module Base: AA45C000 Module End: AA474000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: --- Module Base: F7B58000 Module End: F7B5A000 Hidden: Yes Module Name: C:\WINDOWS\system32\DRIVERS\WinUSB.sys Service Name: WinUSB Module Base: F7966000 Module End: F796E000 Hidden: Yes Module Name: C:\WINDOWS\system32\DRIVERS\wudfrd.sys Service Name: WudfRd Module Base: AA1CC000 Module End: AA1ED000 Hidden: Yes ****************************************************************************************** ****************************************************************************************** SSDT: Function Name: ZwTerminateProcess Address: AA567620 Driver Base: AA55D000 Driver End: AA57F000 Driver Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** Hidden files/folders: Object: C:\Qoobox\BackEnv\AppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cache.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cookies.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Desktop.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Favorites.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\History.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Music.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\NetHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Personal.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Pictures.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\PrintHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Programs.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Recent.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SendTo.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SetPath.bat Status: Access denied Object: C:\Qoobox\BackEnv\StartMenu.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\StartUp.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SysPath.dat Status: Access denied Object: C:\Qoobox\BackEnv\Templates.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\VikPev00 Status: Access denied Looking good. Let's try this scan. I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be PATIENT as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\37\4bb6a8a5-26d0d414 Java/TrojanDownloader.OpenStream.NBV trojan C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\31\3ba0d75f-12867f1f Java/TrojanDownloader.OpenStream.NBV trojan C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\6\27241306-4d955265 Java/TrojanDownloader.Agent.NCQ trojan Please run ESET again and this time, clean the infections. How's your computer working now? Any other issues?The first and last file i couldn't find but here are the results for the rest. http://virusscan.jotti.org/en-gb/scanresult/d6ffeee1d24a1531e91b17f4e2e35fe86b924006 http://virusscan.jotti.org/en-gb/scanresult/84391c69438966404bbdce4fc504ddcf4e87473f/66ee4b78e7f4dca13e54b43985109d4933be4897 http://virusscan.jotti.org/en-gb/scanresult/f1504c02d1a67e8a72aee63a14005f4f091f3c5dComboFix 11-05-14.01 - Owner 15/05/2011 10:25:44.4.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1014.331 [GMT 1:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . . ((((((((((((((((((((((((( Files Created from 2011-04-15 to 2011-05-15 ))))))))))))))))))))))))))))))) . . 2011-05-15 09:33 . 2011-05-15 09:33 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\MpKsld931e1f3.sys 2011-05-15 09:15 . 2011-05-15 09:15 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\MpKslca26fab0.sys 2011-05-15 09:14 . 2011-04-11 07:04 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\mpengine.dll 2011-05-15 09:06 . 2011-05-15 09:06 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-14 10:34 . 2011-05-14 10:34 -------- d-----w- c:\documents and settings\All Users\Application Data\VirtualizedApplications 2011-05-14 08:29 . 2011-05-14 08:29 -------- d-----w- c:\program files\ESET 2011-05-08 11:48 . 2011-05-09 16:33 -------- d-----w- c:\documents and settings\Owner\Application Data\Ulirmo 2011-05-05 21:22 . 2011-05-05 21:22 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-05-05 21:22 . 2011-05-05 21:22 -------- d-----w- c:\program files\Trend Micro 2011-05-05 21:20 . 2011-05-05 21:20 -------- d-----w- c:\program files\Common Files\Java 2011-05-05 20:44 . 2011-05-05 20:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2011-05-05 20:35 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-05 20:35 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-05-05 20:32 . 2011-05-05 20:32 -------- d-----w- c:\program files\CCleaner 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\rpcns4H.dll 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\logonuiv.dll 2011-05-05 18:46 . 2011-05-05 18:46 114176 --sha-r- c:\windows\system32\ialmuTHAU.dll 2011-04-29 12:34 . 2011-04-29 12:34 -------- d-----w- c:\windows\system32\wbem\Repository 2011-04-29 12:30 . 2011-04-29 12:33 -------- d-s---w- c:\documents and settings\Administrator 2011-04-29 06:43 . 2011-04-29 06:43 -------- d-----w- c:\documents and settings\Owner\Application Data\Sibelius Software 2011-04-28 23:18 . 2011-04-28 23:18 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes 2011-04-28 23:18 . 2011-04-28 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-04-28 23:18 . 2011-05-05 20:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-04-28 22:38 . 2011-04-28 22:38 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com 2011-04-28 22:38 . 2011-05-08 11:50 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-04-25 15:51 . 2011-04-25 15:51 -------- d-----w- c:\program files\iPod 2011-04-25 15:51 . 2011-04-25 15:53 -------- d-----w- c:\program files\iTunes 2011-04-25 15:46 . 2011-04-25 15:46 -------- d-----w- c:\program files\Bonjour 2011-04-25 14:07 . 2011-04-25 14:07 -------- d-----r- C:\MSOCache 2011-04-25 13:59 . 2011-04-25 13:59 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\SoftGrid Client 2011-04-25 13:59 . 2011-05-14 11:28 -------- d-----w- c:\documents and settings\Owner\Application Data\SoftGrid Client 2011-04-25 13:59 . 2011-04-25 13:59 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0062-0409-0000-0000000FF1CE} 2011-04-25 13:59 . 2011-05-14 11:28 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client 2011-04-25 13:57 . 2011-04-25 13:57 -------- d-----w- c:\documents and settings\All Users\Microsoft 2011-04-25 13:57 . 2011-04-29 12:38 -------- d-----w- c:\program files\Microsoft Application Virtualization Client 2011-04-25 13:56 . 2011-04-25 14:01 -------- d-----w- c:\documents and settings\Owner\Application Data\TP 2011-04-18 21:13 . 2011-04-18 21:13 -------- d-----w- c:\documents and settings\Owner\Application Data\Amazon 2011-04-18 21:12 . 2011-04-18 21:12 -------- d-----w- c:\program files\Amazon 2011-04-17 14:07 . 2011-04-17 14:07 -------- d-----w- c:\windows\Sun 2011-04-16 14:29 . 2011-04-16 14:29 -------- d-----w- c:\documents and settings\Owner\Application Data\OpenOffice.org 2011-04-16 14:26 . 2011-04-16 14:26 -------- d-----w- c:\program files\OpenOffice.org 3 2011-04-16 14:25 . 2011-04-14 04:07 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-04-16 14:25 . 2011-04-14 01:40 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-04-16 14:25 . 2011-05-05 21:20 -------- d-----w- c:\program files\Java . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSTITL.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSTEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSTMP.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSPEC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSSCRP.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSREH_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSMET_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRSCHOR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\RPRS____.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSTEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSSE__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSS___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSROMC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSPC__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSP___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSO___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSNN__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSM___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFS__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFBE_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSFB__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSCSC_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSCS__.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUSC___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\OPUS____.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INKPEN2_.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2TEXT.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2SPEC.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2SCRI.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2METR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\INK2CHOR.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELST___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSS___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSM___.FOT 2011-04-29 06:43 . 2011-04-29 06:43 1409 ----a-w- c:\windows\Fonts\HELSINKI.FOT 2011-04-11 07:04 . 2011-02-06 22:20 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-04-06 15:20 . 2011-04-06 15:20 91424 ----a-w- c:\windows\system32\dnssd.dll 2011-04-06 15:20 . 2011-04-06 15:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 15:20 . 2011-04-06 15:20 197920 ----a-w- c:\windows\system32\dnssdX.dll 2011-04-06 15:20 . 2011-04-06 15:20 107808 ----a-w- c:\windows\system32\dns-sd.exe 2011-03-07 05:33 . 2011-01-11 19:25 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:37 . 2004-08-04 10:00 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:21 . 2004-08-04 10:00 1857920 ----a-w- c:\windows\system32\win32k.sys 2011-02-22 23:06 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll 2011-02-22 23:06 . 2004-08-04 10:00 43520 ------w- c:\windows\system32\licmgr10.dll 2011-02-22 23:06 . 2004-08-04 10:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-02-22 11:41 . 2004-08-04 10:00 385024 ------w- c:\windows\system32\html.iec 2011-02-17 13:18 . 2004-08-04 10:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-17 13:18 . 2004-08-04 10:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys 2011-02-17 12:32 . 2011-01-19 20:06 5120 ----a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56 . 2004-08-04 10:00 290432 ----a-w- c:\windows\system32\atmfd.dll . . ((((((((((((((((((((((((((((( [email protected]_16.53.14 ))))))))))))))))))))))))))))))))))))))))) . + 2011-01-11 09:59 . 2011-01-11 09:59 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_214ee422\vcomp90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90rus.dll + 2011-01-11 09:59 . 2011-01-11 09:59 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90kor.dll + 2011-01-11 09:59 . 2011-01-11 09:59 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90jpn.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90ita.dll + 2011-01-11 09:59 . 2011-01-11 09:59 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90fra.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esp.dll + 2011-01-11 09:59 . 2011-01-11 09:59 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esn.dll + 2011-01-11 09:59 . 2011-01-11 09:59 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90enu.dll + 2011-01-11 09:59 . 2011-01-11 09:59 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90deu.dll + 2011-01-11 09:59 . 2011-01-11 09:59 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90cht.dll + 2011-01-11 09:59 . 2011-01-11 09:59 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90chs.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90u.dll + 2011-01-11 09:59 . 2011-01-11 09:59 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90.dll + 2011-05-15 09:33 . 2011-05-15 09:33 16384 c:\windows\temp\Perflib_Perfdata_74c.dat + 2011-01-11 09:59 . 2011-01-11 09:59 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcm90.dll + 2011-01-11 09:59 . 2011-01-11 09:59 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_65b7a93a\atl90.dll + 2011-05-15 09:06 . 2011-05-15 09:06 240288 c:\windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe + 2011-05-15 09:06 . 2011-05-15 09:06 321184 c:\windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.dll + 2011-05-09 17:10 . 2011-05-09 17:10 223232 c:\windows\Installer\186080.msi + 2011-01-11 09:59 . 2011-01-11 09:59 3780936 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90u.dll + 2011-01-11 09:59 . 2011-01-11 09:59 3766088 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90.dll + 2011-01-19 20:26 . 2011-05-11 17:41 42829768 c:\windows\system32\MRT.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-08 2424192] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\Owner\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] ="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] ="Service" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management . R1 MpKslca26fab0;MpKslca26fab0;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\MpKslca26fab0.sys [15/05/2011 10:15 28752] R1 MpKsld931e1f3;MpKsld931e1f3;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\MpKsld931e1f3.sys [15/05/2011 10:33 28752] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656] R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [22/02/2007 12:28 30864] R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664] R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688] R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344] R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432] R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584] R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280] R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768] S0 nwba;nwba;c:\windows\system32\drivers\fxufjr.sys --> c:\windows\system32\drivers\fxufjr.sys [?] S2 AMService;AMService;c:\windows\TEMP\kixd\setup.exe run --> c:\windows\TEMP\kixd\setup.exe run [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04/08/2004 11:00 14336] S3 WMZuneComm;Zune Windows Mobile Connectivity Service;f:\zune\WMZuneComm.exe [11/11/2010 14:57 268528] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - MPKSLD931E1F3 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WINRM REG_MULTI_SZ WINRM . Contents of the 'Scheduled Tasks' folder . 2011-05-15 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 12:26] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-05-15 10:35 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] ="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] Denied: (A 2) (Everyone) ="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(620) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . - - - - - - - > 'explorer.exe'(724) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe f:\zune\ZuneBusEnum.exe c:\windows\system32\SearchIndexer.exe c:\windows\stsystra.exe c:\program files\OpenOffice.org 3\program\soffice.exe c:\program files\OpenOffice.org 3\program\soffice.bin c:\program files\iPod\bin\iPodService.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Completion time: 2011-05-15 10:38:24 - machine was rebooted ComboFix-quarantined-files.txt 2011-05-15 09:38 ComboFix2.txt 2011-05-11 17:19 ComboFix3.txt 2011-05-10 17:23 ComboFix4.txt 2011-05-09 16:54 . Pre-Run: 487,744,663,552 bytes free Post-Run: 487,813,476,352 bytes free . - - End Of File - - 089C36B5AA4188206B2D13BE7F2779A3 SORRY! READ THE WRONG PAGE. DONT WORRY ABOUT THE PREVIOUS COUPLE OF POSTS!!I've scanned again and got rid of the infections. Touch wood, everything seems to be okay at the mo i think...That's great. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************* Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 1383. |
Solve : Thanks anyway? |
|
Answer» Hi, |
|
| 1384. |
Solve : Everything has disappeared? |
|
Answer» HP Pavilion dv9000 notebook |
|
| 1385. |
Solve : I Need To Know if This Trojan is Gone? |
|
Answer» I had a Trojan that I had to remove manually because no software could remove it completely nor could it detect it. However there are some files that I did not modify, delete, or restore because I wasn't sure how to. |
|
| 1386. |
Solve : Help! I'm infected with a Trojan Horse!? |
|
Answer» Hi Mr. & Mrs. HOPE! For about 2 weeks I've noticed major issues with my computer. At first I suspected my Verizon Security Suite was the gateway to these issues and despite removing it, ladies and gents, the damage has been already done! |
|
| 1387. |
Solve : nebiteda.dll and goradoja.dll? |
|
Answer» Hi. This is kind of STRANGE, but here goes. Whenever I boot up windows I receive the FOLLOWING error: RUNDLL I also get an error for "goradoja.dll". Problem is, the computer freezes soon after this happens. I can still move the mouse and all but no programs respond. Safe Mode WAS working for a little while, but now it just stops at "Mup.sys" when loading. Closest to a solution I've found: I have two user accounts on XP, one of which I never use. I get the same error when I log in, but for some reason it doesn't freeze unless I try to get rid of the RUNDLL error messages. I scanned for nebiteda.dll and deleted it. Then I WENT to the registry to delete all the keys that reference it, but since that user account doesn't have admin status I can't do anything. A FRIEND told me I could manually delete files with the Recovery Console, but... for some weird reason the console is way too big for my screen. i try to adjust my monitor, but all I can MAKE out is the right hand side of the screen. it's a bit strange! please help me out if you know a solutionHave you tried a registry cleaner? http://majorgeeks.com/Wise_Registry_Cleaner_d5437.html |
|
| 1388. |
Solve : Is it required to enable the antivirus software to run during the startup?? |
|
Answer» Is it required to enable the ANTIVIRUS software to run during the startup?Your AV software NEEDS to be active at all times. |
|
| 1389. |
Solve : wdmaud. sys (computer virus?)? |
|
Answer» Your online posting here so it isn't your service. |
|
| 1390. |
Solve : Malware Personal Antivirus? |
|
Answer» I had ADWARE, took laptop in and after $150 it worked and then a message popped up: CRITICAL warning.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. ---------- |
|
| 1391. |
Solve : is the virus still there?? |
|
Answer» Hi, |
|
| 1392. |
Solve : here are the 3 logs i was asked to post by evilfantasy...? |
|
Answer» Hi, my computer is acting weird and is getting worse every day. My homepage toolbar looks different, I dont have forward and backward keys, tabs dont work the same, some words are getting cut off, I have trouble navigating in some SITES, my email switched to Outlook by itself, some sites tell me I dont have Java or FLASH player installed, but I do, etc...I own a 3 year old e-machine T6528 with Widows XP Home. I have the free versions of AVG anti-virus and Comodo firewall and their scans come up clean..... HELP!!! |
|
| 1393. |
Solve : AVG 8.5 Resident Shield Quarentined two trojans? |
|
Answer» I can't find them, where did they go? |
|
| 1394. |
Solve : There is porn sites in my temp.files and history!? |
|
Answer» Quote from: squall_01 on May 05, 2009, 06:36:35 PM thats good but I ment that alot more depthful. But USUALLY you get this stuff when your on something your not supposed to be. But ad's can have them not sure so much anymore. Was that DIRECTED to me? Yeah i dont know, might been because we have watched "normal" movies online, and had to download like zango, divx etc.. to view them. Could be that he has looked at some porn site, but i dont honestly want to believe, that he has looked at that many sites while im at work in one day... Or the kind of porn there was on my temporary internet files. We'll see, after i get this problem solved and off my computer, i might just install a keylogger or something, to see if he is lying. Thanks for the help, i look forward to hearing more Quote from: squall_01 on May 06, 2009, 04:08:56 AM I ment how you get stuff. I was TOLD that any ad can contain stuff. Ment like once its there its hard to remove an requires alot of cleaning. Oh yeah, sounds possible. We get a lot of pop ups, when no one is on the internet. But this porn only shows up in the temp.files, and kanoodle links sometimes in the BROWSER history. Most of the sites also have the same ending, like trannysmile.com, teensmile, asiansmile.. etc.. etc... Its driving me mad. All considering most maleware scanners would pick that up then. The BEST thing would be to confront him. If you get what I mean??? Quote from: squall_01 on May 06, 2009, 04:38:03 AM All considering most maleware scanners would pick that up then. The best thing would be to confront him. If you get what I mean??? I have already, many times... He denies it every time & blames it on the virus..thats not what I ment use a bit of charm. Jesus Squall, this is a malware topic. I told you to stop. Malware Specialists look for topics with least number of posts first. You just bumped Mimmi to the bottom of the list. Mimmi, I suggest starting a new topic with a brief explanation of what is going on (virus problem). Don't forget to include the logs. Quote from: Carbon Dudeoxide on May 06, 2009, 05:07:26 AM Jesus Squall, this is a malware topic. I told you to stop. Oh i didnt get what he ment at first, im not a native english speaker! But that was not nice. Ok, i will start a new one. Thanks.Ok. I'll close this one then. Quote from: Carbon Dudeoxide on May 06, 2009, 05:07:26 AM Malware Specialists look for topics with least number of posts first. You just bumped Mimmi to the bottom of the list. Actually, we typically look for the oldest topics first, but you get the general idea. I'm sorry to see that Squall is still here causing problems... |
|
| 1395. |
Solve : virus won't let me access my computer!? |
|
Answer» nope, sorry....just tried. i can't get online....it says my router card is not plugged in...which it is...
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.Hi My apologies for the delay in getting back to you. After all this...I believe your thought on this not being a virus was correct. After looking around on the internet, I saw other people had the same kind of problem as I have, after deleting AdAware, which is something I did. I didn't mention it before, because I completely forgot actually. At any rate, I have surrendered. My computer has had nothing but problems since the day I bought it. It was used, cheap, and as I was to assume with time, most LIKELY stolen. The copy of Windows was not registered, so I could never get help from MS, couldn't download things I needed and so on. So, the time has come. I'm just wiping the thing clean, and starting over with a new install of Windows. That should just about take care of everything I hope. Thank you so much to everyone that helped me through this. I truly appreciate CH being here...you guys have been a great help to me time and again. As well as being teachers! If any good has come from two years of dinkin' around with this laptop from *censored*...I certainly have learned A LOT!!! Actually, I'm looking into some IT classes now...I actually love learning all this stuff! THANKS again to all Thanks for letting me know. |
|
| 1396. |
Solve : Re: HiJack Log? |
|
Answer» It is very simple to solve this problem. Note: USE WITH CAUTION! That's not very reassuring! |
|
| 1397. |
Solve : Windows update redirects to Google search page? |
|
Answer» Malwarebytes worked this time. Here are my logs.
. The above procedure will:
---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and GET all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and UNRELIABLE shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop CERTAIN COOKIES from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Everything seems to be working fine now. Thank You very much for your help!Your welcome. Safe surfing... |
|
| 1398. |
Solve : aviar scan could someone have a look please? |
|
Answer» COULD someone have a look at the scan the only problem i can see is below in red , harry its ok evil , i put this part below in it will do Starting the file scan: Begin scan in 'C:\' <CM99-G4> C:\hiberfil.sys [WARNING] The file could not be opened! [NOTE] This file is a Windows system file. [NOTE] This file cannot be opened for scanning. C:\pagefile.sys [WARNING] The file could not be opened! [NOTE] This file is a Windows system file. [NOTE] This file cannot be opened for scanning.C:\Documents and Settings\harold mullan\DoctorWeb\Quarantine\UninstallHelper.exe [DETECTION] Contains recognition pattern of the DR/Tool.PsKill.1101.46 dropper Beginning disinfection: C:\Documents and Settings\harold mullan\DoctorWeb\Quarantine\UninstallHelper.exe [DETECTION] Contains recognition pattern of the DR/Tool.PsKill.1101.46 dropper [NOTE] The file was moved to '4a742544.qua'! [attachment deleted by admin]I don't KNOW how to read Avira logs. It looks like WHATEVER was found has been taken care of though.ok evil , its just i thought that avira wanted to open the FILES or would that not be any problem for it to do that and what id , dr,tool / pskillLook at the file path. C:\Documents and Settings\harold mullan\DoctorWeb\Quarantine\UninstallHelper.exe That is in DoctorWebs Quarantine folder...ok now that you show me and i read it i understand , thank you as usual , harry |
|
| 1399. |
Solve : Indonesaian text at top of web browser & intermitten connection to website? |
|
Answer» have above problem and done the TrendMicro HijackThis scan here is the scanned log file.
---------- Download the Norton Removal Tool (SymNRT) to your Desktop. Once downloaded please close ALL open browsers, also save any work because this may require a restart.
---------- Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there)
Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Download Malwarebytes' Anti-Malware (MBAM) Alternate MBAM download link
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.Thanks for your advice :after follow your instruction, the "Indonesian text" disappeared. But I still facing problem in using "Internet Explorer " to get into any Website. Most of the time, I receive statement "Internet Explorer cannot display the Webpage ". Have to logout and log in Explorer many times. By chance, have to repaet several times before success. I though it was due to " Indonesian text visrus " . Now the text is gone, Internet Explorer log in problem still there . Please advice solution . Thanks in advance for your help . nb. As requested , here is the logfile after "Anti-Malware" scanned. Malwarebytes' Anti-Malware 1.36 Database version: 2069 Windows 6.0.6001 Service Pack 1 3/5/2009 7:44:32 PM mbam-log-2009-05-03 (19-44-32).txt Scan type: Quick Scan Objects scanned: 68595 Time elapsed: 4 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 5 Files Infected: 220 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Users\Acer\AppData\Roaming\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\Logs (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010 (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\Results (Rogue.RegTool) -> Quarantined and deleted successfully. Files Infected: C:\Users\Acer\AppData\Roaming\RegTool\Logs\2009-04-28 19-29-120.log (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-1.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-10.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-100.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-101.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-102.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-103.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-104.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-105.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-106.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-107.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-108.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-109.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-11.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-110.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-111.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-112.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-113.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-114.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-115.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-116.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-117.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-118.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-119.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-12.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-120.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-121.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-122.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-123.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-124.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-125.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-126.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-127.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-128.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-129.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-13.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-130.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-131.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-132.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-133.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-134.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-135.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-136.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-137.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-138.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-139.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-14.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-140.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-141.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-142.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-143.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-144.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-145.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-146.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-147.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-148.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-149.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-15.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-150.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-151.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-152.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-153.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-154.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-155.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-156.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-157.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-158.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-159.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-16.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-160.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-161.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-162.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-163.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-164.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-165.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-166.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-167.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-168.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-169.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-17.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-170.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-171.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-172.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-173.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-174.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-175.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-176.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-177.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-178.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-179.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-18.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-180.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-181.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-182.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-183.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-184.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-185.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-186.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-187.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-188.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-189.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-19.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-190.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-191.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-192.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-193.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-194.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-195.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-196.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-197.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-198.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-199.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-2.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-20.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-200.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-201.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-202.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-203.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-204.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-205.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-206.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-207.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-208.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-209.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-21.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-210.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-211.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-212.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-22.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-23.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-24.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-25.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-26.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-27.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-28.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-29.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-3.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-30.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-31.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-32.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-33.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-34.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-35.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-36.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-37.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-38.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-39.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-4.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-40.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-41.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-42.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-43.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-44.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-45.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-46.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-47.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-48.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-49.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-5.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-50.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-51.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-52.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-53.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-54.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-55.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-56.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-57.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-58.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-59.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-6.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-60.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-61.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-62.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-63.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-64.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-65.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-66.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-67.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-68.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-69.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-7.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-70.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-71.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-72.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-73.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-74.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-75.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-76.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-77.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-78.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-79.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-8.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-80.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-81.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-82.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-83.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-84.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-85.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-86.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-87.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-88.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-89.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-9.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-90.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-91.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-92.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-93.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-94.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-95.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-96.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-97.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-98.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-99.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\Results\Evidence.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\Results\Junk.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\Results\Registry.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Users\Acer\AppData\Roaming\RegTool\Results\Update.db (Rogue.RegTool) -> Quarantined and deleted successfully. C:\Windows\Tasks\RegTool Scan.job (Rogue.RegTool) -> Quarantined and deleted successfully. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFix Follow your instruction and here is the ComboFix log, please help to analyse . Thanks . -------------------------------------------------------------------------------------------------------------------- ComboFix 09-05-03.1 - Acer 04/05/2009 23:09.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2047.1290 [GMT 8:00] Running from: c:\users\Acer\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\x64 D:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2009-04-04 to 2009-05-04 ))))))))))))))))))))))))))))))) . 2009-05-03 10:34 . 2009-05-03 10:34 -------- d-----w c:\programdata\NortonInstaller 2009-05-03 10:34 . 2009-05-03 10:34 -------- d-----w c:\users\All Users\NortonInstaller 2009-05-02 03:37 . 2009-05-02 03:37 -------- d-----w c:\program files\Trend Micro 2009-04-27 16:35 . 2009-04-27 16:35 -------- d-----w c:\program files\RegCure 2009-04-27 14:21 . 2009-04-27 14:21 -------- d-----w c:\users\Acer\AppData\Roaming\Malwarebytes 2009-04-27 14:21 . 2009-04-06 07:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-04-27 14:21 . 2009-04-06 07:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-27 14:21 . 2009-04-27 14:21 -------- d-----w c:\programdata\Malwarebytes 2009-04-27 14:21 . 2009-04-27 14:21 -------- d-----w c:\users\All Users\Malwarebytes 2009-04-27 14:21 . 2009-05-03 11:38 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-04-25 09:17 . 2009-04-25 09:17 -------- d-----w c:\programdata\SiteAdvisor 2009-04-25 09:17 . 2009-04-25 09:17 -------- d-----w c:\users\All Users\SiteAdvisor 2009-04-25 09:17 . 2009-04-25 09:22 -------- d-----w c:\program files\SiteAdvisor 2009-04-25 09:14 . 2009-03-25 03:06 40552 ----a-w c:\windows\system32\drivers\mfesmfk.sys 2009-04-25 09:14 . 2009-03-25 03:06 35272 ----a-w c:\windows\system32\drivers\mfebopk.sys 2009-04-25 09:14 . 2009-03-25 03:06 79880 ----a-w c:\windows\system32\drivers\mfeavfk.sys 2009-04-25 09:14 . 2008-10-23 05:08 130424 ----a-w c:\windows\system32\drivers\Mpfp.sys 2009-04-25 09:14 . 2009-04-25 09:14 -------- d-----w c:\program files\Common Files\McAfee 2009-04-25 09:14 . 2009-04-25 09:14 -------- d-----w c:\program files\McAfee.com 2009-04-25 09:14 . 2009-04-27 14:18 -------- d-----w c:\program files\McAfee 2009-04-25 09:13 . 2009-03-25 03:05 34216 ----a-w c:\windows\system32\drivers\mferkdk.sys 2009-04-25 09:00 . 2009-04-25 09:18 -------- d-----w c:\programdata\McAfee 2009-04-25 09:00 . 2009-04-25 09:18 -------- d-----w c:\users\All Users\McAfee 2009-04-20 12:06 . 2009-04-25 08:39 81984 ----a-w c:\windows\system32\bdod.bin 2009-04-20 12:02 . 2009-04-20 12:02 -------- d-----w c:\program files\BitDefender 2009-04-20 11:54 . 2009-04-20 15:39 -------- d-----w c:\program files\Common Files\BitDefender 2009-04-19 00:58 . 2009-04-19 00:58 -------- d-----w C:\Sounds 2009-04-19 00:53 . 2008-09-03 22:27 24832 ----a-w c:\windows\system32\drivers\lgusbmodem.sys 2009-04-19 00:53 . 2008-09-03 22:28 19968 ----a-w c:\windows\system32\drivers\lgusbdiag.sys 2009-04-19 00:53 . 2008-09-03 22:27 13056 ----a-w c:\windows\system32\drivers\lgusbbus.sys 2009-04-19 00:53 . 2009-04-19 00:53 -------- d-----w c:\program files\LG Electronics 2009-04-19 00:51 . 2007-11-08 08:26 1164728 ----a-w c:\windows\system32\NMSDVDXU.dll 2009-04-19 00:51 . 2009-04-19 09:59 -------- d-----w c:\users\Acer\AppData\Roaming\LG Electronics 2009-04-19 00:51 . 2009-04-19 10:00 -------- d-----w c:\program files\LG PC Suite II . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-04 14:59 . 2009-03-24 11:17 420 ---ha-w c:\windows\Tasks\User_Feed_Synchronization-{FCED9B55-8DFE-46EE-B608-B7626366AB7D}.job 2009-05-04 14:43 . 2008-12-20 14:28 868 ----a-w c:\windows\Tasks\Google Software Updater.job 2009-05-04 14:38 . 2009-02-05 07:54 882 ----a-w c:\windows\Tasks\GoogleUpdateTaskMachine.job 2009-05-04 14:38 . 2009-04-28 11:29 352 ----a-w c:\windows\Tasks\RegTool Startup.job 2009-05-04 14:38 . 2009-04-27 16:35 436 ----a-w c:\windows\Tasks\RegCure Program Check.job 2009-05-04 14:38 . 2006-11-02 13:01 6 ---ha-w c:\windows\Tasks\SA.DAT 2009-05-03 10:35 . 2007-07-17 06:57 -------- d-----w c:\program files\Common Files\Symantec Shared 2009-04-28 10:52 . 2009-04-27 16:35 370 ----a-w c:\windows\Tasks\RegCure.job 2009-04-26 04:06 . 2009-04-25 09:14 338 ----a-w c:\windows\Tasks\McDefragTask.job 2009-04-26 04:06 . 2009-04-25 09:14 330 ----a-w c:\windows\Tasks\McQcTask.job 2009-04-19 00:56 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat 2009-04-19 00:56 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat 2009-04-19 00:56 . 2006-11-02 10:25 143360 ----a-w c:\windows\inf\infstrng.dat 2009-04-19 00:53 . 2007-07-17 06:18 -------- d--h--w c:\program files\InstallShield Installation Information 2009-04-19 00:50 . 2008-01-21 08:04 7376 ----a-w c:\users\Acer\AppData\Local\d3d9caps.dat 2009-04-17 12:42 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail 2009-04-01 13:02 . 2008-12-20 14:28 -------- d-----w c:\program files\Google 2009-03-25 03:06 . 2009-03-25 03:06 214024 ----a-w c:\windows\system32\drivers\mfehidk.sys 2009-03-17 03:38 . 2009-04-17 11:15 40960 ----a-w c:\windows\AppPatch\apihex86.dll 2009-03-17 03:38 . 2009-04-17 11:15 13824 ----a-w c:\windows\system32\apilogen.dll 2009-03-17 03:38 . 2009-04-17 11:15 24064 ----a-w c:\windows\system32\amxread.dll 2009-03-08 11:34 . 2009-03-24 11:06 914944 ----a-w c:\windows\system32\wininet.dll 2009-03-08 11:34 . 2009-03-24 11:06 43008 ----a-w c:\windows\system32\licmgr10.dll 2009-03-08 11:33 . 2009-03-24 11:06 18944 ----a-w c:\windows\system32\corpol.dll 2009-03-08 11:33 . 2009-03-24 11:06 109056 ----a-w c:\windows\system32\iesysprep.dll 2009-03-08 11:33 . 2009-03-24 11:06 109568 ----a-w c:\windows\system32\PDMSetup.exe 2009-03-08 11:33 . 2009-03-24 11:06 132608 ----a-w c:\windows\system32\ieUnatt.exe 2009-03-08 11:33 . 2009-03-24 11:06 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe 2009-03-08 11:33 . 2009-03-24 11:06 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe 2009-03-08 11:33 . 2009-03-24 11:06 103936 ----a-w c:\windows\system32\SetDepNx.exe 2009-03-08 11:33 . 2009-03-24 11:06 420352 ----a-w c:\windows\system32\vbscript.dll 2009-03-08 11:32 . 2009-03-24 11:06 72704 ----a-w c:\windows\system32\admparse.dll 2009-03-08 11:32 . 2009-03-24 11:06 71680 ----a-w c:\windows\system32\iesetup.dll 2009-03-08 11:32 . 2009-03-24 11:06 66560 ----a-w c:\windows\system32\wextract.exe 2009-03-08 11:32 . 2009-03-24 11:06 169472 ----a-w c:\windows\system32\iexpress.exe 2009-03-08 11:31 . 2009-03-24 11:06 34816 ----a-w c:\windows\system32\imgutil.dll 2009-03-08 11:31 . 2009-03-24 11:06 48128 ----a-w c:\windows\system32\mshtmler.dll 2009-03-08 11:31 . 2009-03-24 11:06 45568 ----a-w c:\windows\system32\mshta.exe 2009-03-08 11:22 . 2009-03-24 11:06 156160 ----a-w c:\windows\system32\msls31.dll 2009-03-08 06:33 . 2009-03-08 06:33 -------- d-----w c:\program files\Rationale 2 2009-03-03 04:46 . 2009-04-17 11:15 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe 2009-03-03 04:46 . 2009-04-17 11:15 3547632 ----a-w c:\windows\system32\ntoskrnl.exe 2009-03-03 04:39 . 2009-04-17 11:15 183296 ----a-w c:\windows\system32\sdohlp.dll 2009-03-03 04:39 . 2009-04-17 11:15 551424 ----a-w c:\windows\system32\rpcss.dll 2009-03-03 04:39 . 2009-04-17 11:15 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll 2009-03-03 04:37 . 2009-04-17 11:15 98304 ----a-w c:\windows\system32\iasrecst.dll 2009-03-03 04:37 . 2009-04-17 11:15 54784 ----a-w c:\windows\system32\iasads.dll 2009-03-03 04:37 . 2009-04-17 11:15 44032 ----a-w c:\windows\system32\iasdatastore.dll 2009-03-03 03:04 . 2009-04-17 11:15 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe 2009-03-03 02:38 . 2009-04-17 11:15 17408 ----a-w c:\windows\system32\iashost.exe 2009-02-13 08:49 . 2009-04-17 11:15 72704 ----a-w c:\windows\system32\secur32.dll 2009-02-13 08:49 . 2009-04-17 11:15 1255936 ----a-w c:\windows\system32\lsasrv.dll 2009-02-09 03:10 . 2009-03-11 10:12 2033152 ----a-w c:\windows\system32\win32k.sys 2008-08-31 14:39 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ALaunch"="c:\acer\ALaunch\AlaunchClient.exe" [2007-01-26 540672] "Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-06-15 326440] "PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2007-06-22 204908] "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 630784] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112] "PlayMovie"="c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe" [2007-07-14 178280] "Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-09 144784] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-03-25 645328] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-06-20 4493312] c:\users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440] WordWeb.lnk - c:\program files\WordWeb\wweb32.exe [2008-4-22 42168] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32 "wave2"= serwvdrv.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 "InternetSettingsDisableNotify"=dword:00000001 "AutoUpdateDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) "DefaultOutboundAction"= 0 (0x0) "DefaultInboundAction"= 1 (0x1) "DisableUnicastResponsesToMulticastBroad cast"= 0 (0x0) "DoNotAllowExceptions"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{CC798B78-DE13-4976-9DBA-0015A8CE56F8}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{81030BAF-357C-40FB-8793-B99ADE4212A8}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{4C0E0174-247F-4069-9F52-9AD19DC71D83}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live "{560429FD-BAD7-4E9A-857F-AA8C893A477F}"= c:\program files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician "{ED9E9E19-C630-464A-87A6-C20269418FC1}"= c:\program files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine "{492EC220-FB41-4472-8B20-E400B5B81034}"= c:\program files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia "{63C2B5ED-23AB-4CB2-AC71-1114E8E91419}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect "{9C8A4F83-9400-4816-BA61-125CC31F09BB}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service "{D174244A-0FBB-4C36-8948-020059CF029E}"= c:\program files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD "{7DDAC852-04CD-4EFE-8DE0-1361BE28FB87}"= c:\program files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician "{A737C415-9154-4556-87F7-B5F30470A416}"= c:\program files\Acer Arcade Live\Acer PlayMovie\PlayMovie.exe:Acer Play Movie "{5D969526-27C1-40B7-9F52-8278DA307BA0}"= c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe:Acer Play Movie Resident Program "{3C4ED021-08D7-40ED-B0AD-E27D445943AF}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{7675F91E-FBB7-4E0C-9628-6432ED104CA4}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0 "{50E32A91-4CD3-4573-90F9-B49D58FF0C3A}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0 "{D6C8BEFB-D7A5-43B3-AEC2-F1A90A04DF7D}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{89879D53-A003-402C-835D-7BFE787E063A}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{9C6250F4-9A47-482F-89D3-7CD7534C3986}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{E8376ABB-C3B1-4964-95E9-E750169D22B5}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{2B15D7A0-01B8-4442-B9F8-24F7164354DE}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player "{38BE90AF-D3C8-4C9E-94E6-E0A458035CB9}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player "{6B4DD4C0-2194-43F9-A598-60A6148EFAA6}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) "DefaultOutboundAction"= 0 (0x0) "DefaultInboundAction"= 1 (0x1) "DoNotAllowExceptions"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) "DefaultOutboundAction"= 0 (0x0) "DefaultInboundAction"= 1 (0x1) "DoNotAllowExceptions"= 0 (0x0) R2 gupdate1c9876777235ff;Google Update Service (gupdate1c9876777235ff);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104] R3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\DRIVERS\s816bus.sys [2007-06-18 81832] S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Live\Acer PlayMovie\000.fcl [2006-11-02 23:51 13560] S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-06-22 269448] S2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216] S3 netr73;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2008-02-26 493568] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L] \shell\AutoRun\command - L:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f3f3c6-b6f5-11dd-9a93-0019214a2749}] \shell\AutoRun\command - E:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1bccb4bb-ccfc-11dd-8560-0019214a2749}] \shell\AutoRun\command - K:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{678b971c-d966-11dc-b513-00120e82456d}] \shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe k4l0n62.sys.vbs [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-05-04 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-20 09:38] 2009-05-04 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 07:54] 2009-04-26 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 02:53] 2009-04-26 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 02:53] 2009-05-04 c:\windows\Tasks\RegCure Program Check.job - c:\program files\RegCure\RegCure.exe [2008-12-29 17:58] 2009-04-28 c:\windows\Tasks\RegCure.job - c:\program files\RegCure\RegCure.exe [2008-12-29 17:58] 2009-05-04 c:\windows\Tasks\User_Feed_Synchronization-{FCED9B55-8DFE-46EE-B608-B7626366AB7D}.job - c:\windows\system32\msfeedssync.exe [2009-03-24 11:31] . - - - - ORPHANS REMOVED - - - - HKCU-Run-Acer Tour Reminder - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.us.acer.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: &WordWeb... - c:\windows\wweb32.dll/lookup.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\rgir4l13.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-04 23:15 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101" [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation] "Enabled"=dword:00000001 [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32] ="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe" [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Shockwave Flash Object" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] ="0" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] ="ShockwaveFlash.ShockwaveFlash.10" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] ="1.0" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="ShockwaveFlash.ShockwaveFlash" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Macromedia Flash Factory Object" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] ="FlashFactory.FlashFactory.1" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] ="1.0" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="FlashFactory.FlashFactory" [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}] Denied: (A 2) (Everyone) ="IFlashBroker2" [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] Denied: (A 2) (Everyone) [HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] ="Shockwave Flash" [HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] Denied: (A 2) (Everyone) ="" [HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] ="FlashBroker" [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2009-05-04 23:17 ComboFix-quarantined-files.txt 2009-05-04 15:17 Pre-Run: 101,571,207,168 bytes free Post-Run: 102,403,452,928 bytes free 358 --- E O F --- 2009-05-03 08:57 Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and PRESSING Ctrl+C Code: [Select]KillAll:: FixCSet:: Folder:: c:\programdata\NortonInstaller c:\users\All Users\NortonInstaller [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezePerformed the activity as per instructed. It is noticed that there is a new "Internet Explorer " icon appear at the Desktop, and the old "Internet Explorer " icon still there . Which one shall I use or delete ? Here is the latest Combofix.txt logfile. Please advice the next cause of action . thanks. --------------------------------------- logfile -------------------------------------------------- ComboFix 09-05-03.1 - Acer 05/05/2009 20:23.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2047.1279 [GMT 8:00] Running from: c:\users\Acer\Desktop\ComboFix.exe Command switches used :: c:\users\Acer\Desktop\CFScript.txt . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\programdata\NortonInstaller c:\programdata\NortonInstaller\Logs\05-03-2009-18h34m01s\SymNRT-05-03-2009-18h34m01s.log c:\programdata\NortonInstaller\Logs\05-03-2009-18h34m01s\SymNRT.1.mft.7z c:\programdata\NortonInstaller\Settings\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}.7z c:\users\All Users\NortonInstaller\Logs\05-03-2009-18h34m01s\SymNRT-05-03-2009-18h34m01s.log c:\users\All Users\NortonInstaller\Logs\05-03-2009-18h34m01s\SymNRT.1.mft.7z c:\users\All Users\NortonInstaller\Settings\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}.7z . ((((((((((((((((((((((((( Files Created from 2009-04-05 to 2009-05-05 ))))))))))))))))))))))))))))))) . 2009-05-02 03:37 . 2009-05-02 03:37 -------- d-----w c:\program files\Trend Micro 2009-04-27 16:35 . 2009-04-27 16:35 -------- d-----w c:\program files\RegCure 2009-04-27 14:21 . 2009-04-27 14:21 -------- d-----w c:\users\Acer\AppData\Roaming\Malwarebytes 2009-04-27 14:21 . 2009-04-06 07:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-04-27 14:21 . 2009-04-06 07:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-27 14:21 . 2009-04-27 14:21 -------- d-----w c:\programdata\Malwarebytes 2009-04-27 14:21 . 2009-04-27 14:21 -------- d-----w c:\users\All Users\Malwarebytes 2009-04-27 14:21 . 2009-05-03 11:38 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-04-25 09:17 . 2009-04-25 09:17 -------- d-----w c:\programdata\SiteAdvisor 2009-04-25 09:17 . 2009-04-25 09:17 -------- d-----w c:\users\All Users\SiteAdvisor 2009-04-25 09:17 . 2009-04-25 09:22 -------- d-----w c:\program files\SiteAdvisor 2009-04-25 09:14 . 2009-03-25 03:06 40552 ----a-w c:\windows\system32\drivers\mfesmfk.sys 2009-04-25 09:14 . 2009-03-25 03:06 35272 ----a-w c:\windows\system32\drivers\mfebopk.sys 2009-04-25 09:14 . 2009-03-25 03:06 79880 ----a-w c:\windows\system32\drivers\mfeavfk.sys 2009-04-25 09:14 . 2008-10-23 05:08 130424 ----a-w c:\windows\system32\drivers\Mpfp.sys 2009-04-25 09:14 . 2009-04-25 09:14 -------- d-----w c:\program files\Common Files\McAfee 2009-04-25 09:14 . 2009-04-25 09:14 -------- d-----w c:\program files\McAfee.com 2009-04-25 09:14 . 2009-04-27 14:18 -------- d-----w c:\program files\McAfee 2009-04-25 09:13 . 2009-03-25 03:05 34216 ----a-w c:\windows\system32\drivers\mferkdk.sys 2009-04-25 09:00 . 2009-04-25 09:18 -------- d-----w c:\programdata\McAfee 2009-04-25 09:00 . 2009-04-25 09:18 -------- d-----w c:\users\All Users\McAfee 2009-04-20 12:06 . 2009-04-25 08:39 81984 ----a-w c:\windows\system32\bdod.bin 2009-04-20 12:02 . 2009-04-20 12:02 -------- d-----w c:\program files\BitDefender 2009-04-20 11:54 . 2009-04-20 15:39 -------- d-----w c:\program files\Common Files\BitDefender 2009-04-19 00:58 . 2009-04-19 00:58 -------- d-----w C:\Sounds 2009-04-19 00:53 . 2008-09-03 22:27 24832 ----a-w c:\windows\system32\drivers\lgusbmodem.sys 2009-04-19 00:53 . 2008-09-03 22:28 19968 ----a-w c:\windows\system32\drivers\lgusbdiag.sys 2009-04-19 00:53 . 2008-09-03 22:27 13056 ----a-w c:\windows\system32\drivers\lgusbbus.sys 2009-04-19 00:53 . 2009-04-19 00:53 -------- d-----w c:\program files\LG Electronics 2009-04-19 00:51 . 2007-11-08 08:26 1164728 ----a-w c:\windows\system32\NMSDVDXU.dll 2009-04-19 00:51 . 2009-04-19 09:59 -------- d-----w c:\users\Acer\AppData\Roaming\LG Electronics 2009-04-19 00:51 . 2009-04-19 10:00 -------- d-----w c:\program files\LG PC Suite II . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-05 12:26 . 2009-02-05 07:54 882 ----a-w c:\windows\Tasks\GoogleUpdateTaskMachine.job 2009-05-05 12:26 . 2009-04-28 11:29 352 ----a-w c:\windows\Tasks\RegTool Startup.job 2009-05-05 12:26 . 2009-04-27 16:35 436 ----a-w c:\windows\Tasks\RegCure Program Check.job 2009-05-05 12:26 . 2008-12-20 14:28 868 ----a-w c:\windows\Tasks\Google Software Updater.job 2009-05-05 12:26 . 2006-11-02 13:01 6 ---ha-w c:\windows\Tasks\SA.DAT 2009-05-04 14:59 . 2009-03-24 11:17 420 ---ha-w c:\windows\Tasks\User_Feed_Synchronization-{FCED9B55-8DFE-46EE-B608-B7626366AB7D}.job 2009-05-03 10:35 . 2007-07-17 06:57 -------- d-----w c:\program files\Common Files\Symantec Shared 2009-04-28 10:52 . 2009-04-27 16:35 370 ----a-w c:\windows\Tasks\RegCure.job 2009-04-26 04:06 . 2009-04-25 09:14 338 ----a-w c:\windows\Tasks\McDefragTask.job 2009-04-26 04:06 . 2009-04-25 09:14 330 ----a-w c:\windows\Tasks\McQcTask.job 2009-04-19 00:56 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat 2009-04-19 00:56 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat 2009-04-19 00:56 . 2006-11-02 10:25 143360 ----a-w c:\windows\inf\infstrng.dat 2009-04-19 00:53 . 2007-07-17 06:18 -------- d--h--w c:\program files\InstallShield Installation Information 2009-04-19 00:50 . 2008-01-21 08:04 7376 ----a-w c:\users\Acer\AppData\Local\d3d9caps.dat 2009-04-17 12:42 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail 2009-04-01 13:02 . 2008-12-20 14:28 -------- d-----w c:\program files\Google 2009-03-25 03:06 . 2009-03-25 03:06 214024 ----a-w c:\windows\system32\drivers\mfehidk.sys 2009-03-17 03:38 . 2009-04-17 11:15 40960 ----a-w c:\windows\AppPatch\apihex86.dll 2009-03-17 03:38 . 2009-04-17 11:15 13824 ----a-w c:\windows\system32\apilogen.dll 2009-03-17 03:38 . 2009-04-17 11:15 24064 ----a-w c:\windows\system32\amxread.dll 2009-03-08 11:34 . 2009-03-24 11:06 914944 ----a-w c:\windows\system32\wininet.dll 2009-03-08 11:34 . 2009-03-24 11:06 43008 ----a-w c:\windows\system32\licmgr10.dll 2009-03-08 11:33 . 2009-03-24 11:06 18944 ----a-w c:\windows\system32\corpol.dll 2009-03-08 11:33 . 2009-03-24 11:06 109056 ----a-w c:\windows\system32\iesysprep.dll 2009-03-08 11:33 . 2009-03-24 11:06 109568 ----a-w c:\windows\system32\PDMSetup.exe 2009-03-08 11:33 . 2009-03-24 11:06 132608 ----a-w c:\windows\system32\ieUnatt.exe 2009-03-08 11:33 . 2009-03-24 11:06 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe 2009-03-08 11:33 . 2009-03-24 11:06 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe 2009-03-08 11:33 . 2009-03-24 11:06 103936 ----a-w c:\windows\system32\SetDepNx.exe 2009-03-08 11:33 . 2009-03-24 11:06 420352 ----a-w c:\windows\system32\vbscript.dll 2009-03-08 11:32 . 2009-03-24 11:06 72704 ----a-w c:\windows\system32\admparse.dll 2009-03-08 11:32 . 2009-03-24 11:06 71680 ----a-w c:\windows\system32\iesetup.dll 2009-03-08 11:32 . 2009-03-24 11:06 66560 ----a-w c:\windows\system32\wextract.exe 2009-03-08 11:32 . 2009-03-24 11:06 169472 ----a-w c:\windows\system32\iexpress.exe 2009-03-08 11:31 . 2009-03-24 11:06 34816 ----a-w c:\windows\system32\imgutil.dll 2009-03-08 11:31 . 2009-03-24 11:06 48128 ----a-w c:\windows\system32\mshtmler.dll 2009-03-08 11:31 . 2009-03-24 11:06 45568 ----a-w c:\windows\system32\mshta.exe 2009-03-08 11:22 . 2009-03-24 11:06 156160 ----a-w c:\windows\system32\msls31.dll 2009-03-08 06:33 . 2009-03-08 06:33 -------- d-----w c:\program files\Rationale 2 2009-03-03 04:46 . 2009-04-17 11:15 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe 2009-03-03 04:46 . 2009-04-17 11:15 3547632 ----a-w c:\windows\system32\ntoskrnl.exe 2009-03-03 04:39 . 2009-04-17 11:15 183296 ----a-w c:\windows\system32\sdohlp.dll 2009-03-03 04:39 . 2009-04-17 11:15 551424 ----a-w c:\windows\system32\rpcss.dll 2009-03-03 04:39 . 2009-04-17 11:15 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll 2009-03-03 04:37 . 2009-04-17 11:15 98304 ----a-w c:\windows\system32\iasrecst.dll 2009-03-03 04:37 . 2009-04-17 11:15 54784 ----a-w c:\windows\system32\iasads.dll 2009-03-03 04:37 . 2009-04-17 11:15 44032 ----a-w c:\windows\system32\iasdatastore.dll 2009-03-03 03:04 . 2009-04-17 11:15 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe 2009-03-03 02:38 . 2009-04-17 11:15 17408 ----a-w c:\windows\system32\iashost.exe 2009-02-13 08:49 . 2009-04-17 11:15 72704 ----a-w c:\windows\system32\secur32.dll 2009-02-13 08:49 . 2009-04-17 11:15 1255936 ----a-w c:\windows\system32\lsasrv.dll 2009-02-09 03:10 . 2009-03-11 10:12 2033152 ----a-w c:\windows\system32\win32k.sys 2008-08-31 14:39 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini . ((((((((((((((((((((((((((((( [email protected]_15.15.22 ))))))))))))))))))))))))))))))))))))))))) . - 2007-07-17 06:24 . 2009-05-04 14:40 69044 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2007-07-17 06:24 . 2009-05-05 12:07 69044 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2006-11-02 13:05 . 2009-05-05 12:07 74370 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin - 2008-01-19 09:10 . 2009-05-04 14:40 18066 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-339563597-1808007692-2602482230-1000_UserData.bin + 2008-01-19 09:10 . 2009-05-05 12:07 18066 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-339563597-1808007692-2602482230-1000_UserData.bin + 2007-10-19 08:34 . 2009-05-05 12:27 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2007-10-19 08:34 . 2009-05-04 15:15 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2007-10-19 08:34 . 2009-05-05 12:27 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2007-10-19 08:34 . 2009-05-04 15:15 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-05-04 14:44 . 2009-05-04 14:44 5828 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\B855EB17AFD3537FD667244F8CB86F6C92AE4254\B855EB17AFD3537FD667244F8CB86F6C92AE4254\Data.dat + 2009-05-05 12:08 . 2009-05-05 12:08 5828 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\B855EB17AFD3537FD667244F8CB86F6C92AE4254\B855EB17AFD3537FD667244F8CB86F6C92AE4254\Data.dat + 2009-05-05 12:07 . 2009-05-05 12:07 5220 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\AFA0228517D559C72225EDC64521ED7E04459E89\AFA0228517D559C72225EDC64521ED7E04459E89\Data.dat - 2009-05-04 14:41 . 2009-05-04 14:41 5220 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\AFA0228517D559C72225EDC64521ED7E04459E89\AFA0228517D559C72225EDC64521ED7E04459E89\Data.dat + 2009-05-05 12:07 . 2009-05-05 12:07 7994 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\74A956292B9D7ED29866593C7E501FA45B187192\74A956292B9D7ED29866593C7E501FA45B187192\Data.dat + 2009-05-05 12:06 . 2009-05-05 12:06 6202 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\1D392462A204CC01DF4399DA2E6E264AAC23F1AA\1D392462A204CC01DF4399DA2E6E264AAC23F1AA\Data.dat - 2009-05-04 14:44 . 2009-05-04 14:44 6202 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\1D392462A204CC01DF4399DA2E6E264AAC23F1AA\1D392462A204CC01DF4399DA2E6E264AAC23F1AA\Data.dat - 2009-05-04 14:38 . 2009-05-04 14:38 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-05-05 12:26 . 2009-05-05 12:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2007-10-19 08:34 . 2009-05-05 12:27 131072 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2007-10-19 08:34 . 2009-05-04 15:15 131072 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] "Acer Tour Reminder"="" [BU] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ALaunch"="c:\acer\ALaunch\AlaunchClient.exe" [2007-01-26 540672] "Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-06-15 326440] "PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2007-06-22 204908] "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 630784] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112] "PlayMovie"="c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe" [2007-07-14 178280] "Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-09 144784] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-03-25 645328] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-06-20 4493312] c:\users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440] WordWeb.lnk - c:\program files\WordWeb\wweb32.exe [2008-4-22 42168] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32 "wave2"= serwvdrv.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 "InternetSettingsDisableNotify"=dword:00000001 "AutoUpdateDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) "DefaultOutboundAction"= 0 (0x0) "DefaultInboundAction"= 1 (0x1) "DisableUnicastResponsesToMulticastBroad cast"= 0 (0x0) "DoNotAllowExceptions"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{CC798B78-DE13-4976-9DBA-0015A8CE56F8}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{81030BAF-357C-40FB-8793-B99ADE4212A8}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{4C0E0174-247F-4069-9F52-9AD19DC71D83}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live "{560429FD-BAD7-4E9A-857F-AA8C893A477F}"= c:\program files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician "{ED9E9E19-C630-464A-87A6-C20269418FC1}"= c:\program files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine "{492EC220-FB41-4472-8B20-E400B5B81034}"= c:\program files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia "{63C2B5ED-23AB-4CB2-AC71-1114E8E91419}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect "{9C8A4F83-9400-4816-BA61-125CC31F09BB}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service "{D174244A-0FBB-4C36-8948-020059CF029E}"= c:\program files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD "{7DDAC852-04CD-4EFE-8DE0-1361BE28FB87}"= c:\program files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician "{A737C415-9154-4556-87F7-B5F30470A416}"= c:\program files\Acer Arcade Live\Acer PlayMovie\PlayMovie.exe:Acer Play Movie "{5D969526-27C1-40B7-9F52-8278DA307BA0}"= c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe:Acer Play Movie Resident Program "{3C4ED021-08D7-40ED-B0AD-E27D445943AF}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{7675F91E-FBB7-4E0C-9628-6432ED104CA4}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0 "{50E32A91-4CD3-4573-90F9-B49D58FF0C3A}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0 "{D6C8BEFB-D7A5-43B3-AEC2-F1A90A04DF7D}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{89879D53-A003-402C-835D-7BFE787E063A}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{9C6250F4-9A47-482F-89D3-7CD7534C3986}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{E8376ABB-C3B1-4964-95E9-E750169D22B5}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{2B15D7A0-01B8-4442-B9F8-24F7164354DE}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player "{38BE90AF-D3C8-4C9E-94E6-E0A458035CB9}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player "{6B4DD4C0-2194-43F9-A598-60A6148EFAA6}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) "DefaultOutboundAction"= 0 (0x0) "DefaultInboundAction"= 1 (0x1) "DoNotAllowExceptions"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) "DefaultOutboundAction"= 0 (0x0) "DefaultInboundAction"= 1 (0x1) "DoNotAllowExceptions"= 0 (0x0) R2 gupdate1c9876777235ff;Google Update Service (gupdate1c9876777235ff);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104] R3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\DRIVERS\s816bus.sys [2007-06-18 81832] S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Live\Acer PlayMovie\000.fcl [2006-11-02 23:51 13560] S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-06-22 269448] S2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216] S3 netr73;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2008-02-26 493568] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L] \shell\AutoRun\command - L:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f3f3c6-b6f5-11dd-9a93-0019214a2749}] \shell\AutoRun\command - E:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1bccb4bb-ccfc-11dd-8560-0019214a2749}] \shell\AutoRun\command - K:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{678b971c-d966-11dc-b513-00120e82456d}] \shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe k4l0n62.sys.vbs [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-05-05 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-20 09:38] 2009-05-05 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 07:54] 2009-04-26 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 02:53] 2009-04-26 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 02:53] 2009-05-05 c:\windows\Tasks\RegCure Program Check.job - c:\program files\RegCure\RegCure.exe [2008-12-29 17:58] 2009-04-28 c:\windows\Tasks\RegCure.job - c:\program files\RegCure\RegCure.exe [2008-12-29 17:58] 2009-05-04 c:\windows\Tasks\User_Feed_Synchronization-{FCED9B55-8DFE-46EE-B608-B7626366AB7D}.job - c:\windows\system32\msfeedssync.exe [2009-03-24 11:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.us.acer.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: &WordWeb... - c:\windows\wweb32.dll/lookup.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\rgir4l13.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-05 20:27 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101" [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation] "Enabled"=dword:00000001 [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32] ="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe" [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Shockwave Flash Object" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] ="0" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] ="ShockwaveFlash.ShockwaveFlash.10" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] ="1.0" [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="ShockwaveFlash.ShockwaveFlash" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Macromedia Flash Factory Object" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] ="FlashFactory.FlashFactory.1" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] ="1.0" [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="FlashFactory.FlashFactory" [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}] Denied: (A 2) (Everyone) ="IFlashBroker2" [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] Denied: (A 2) (Everyone) [HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] ="Shockwave Flash" [HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] Denied: (A 2) (Everyone) ="" [HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] ="FlashBroker" [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(2016) c:\program files\McAfee\SiteAdvisor\saHook.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\Ati2evxx.exe c:\windows\System32\audiodg.exe c:\windows\System32\Ati2evxx.exe c:\acer\Empowering Technology\ePerformance\MemCheck.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\acer\Empowering Technology\eDataSecurity\eDSService.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe c:\windows\System32\rundll32.exe c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe c:\program files\McAfee\MPF\MpfSrv.exe c:\program files\McAfee\MSK\msksrver.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\McAfee.com\Agent\mcagent.exe c:\windows\System32\conime.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\windows\ehome\ehmsas.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Completion time: 2009-05-05 20:32 - machine was rebooted ComboFix-quarantined-files.txt 2009-05-05 12:32 ComboFix2.txt 2009-05-04 15:17 Pre-Run: 102,314,172,416 bytes free Post-Run: 102,181,163,008 bytes free 419 --- E O F --- 2009-05-03 08:57 I have no idea where the new IE icon came from... Download GMER and save it your desktop. * Extract it to your desktop and double-click GMER.exe * Click the rootkit tab and then scan. * Don't check the Show All box while scanning in progress! * When scanning is finished click Copy. * This copies the log to clipboard * Post the log in your reply.Before doing GMER scan, computer seems get back to normal -> no more IE log in problem and faster log in . Nevertheless, still perform GMER-> rootkit-> scan as instructed . During scanning, counter problem and following statement appear : ---------------------------------------------------------------------------------- gmer.exe has stopped working A problem caused the program to stop working correctly. Window will close the program and notify you if solution is available ------------------------------------------------------------------------------------- After this, computer seems performing some work and never shut down . Waited for more than half an hour and finally I do a click the "shut down " commant at the right bottom of above statement and get out of the loop . What has gone wrong with GMER? Since no IE log in problem. Is there any more thing to be done ? Thanks . Download Rooter.exe to your desktop * Double click Rooter.exe to start the tool. * A DOS window will appear and show the scan progress. * Once complete a notepad file containing the report will open. * Copy & paste the results in your next reply. * Close notepad and Rooter will close. A log will also save at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have Windows installed).after double click Rooter.exe, following message came out on screen ( not in DOS window) : -------------------------------------------------------------------- Exception Processing message 0xc0000013 parameters 0x75D792A0 ox00000004 0x75D792A0 0x75D79A0 3x choices are given : stop, try again or continue ------------------------------------------------------------- Select " continue " , Dos window shows --------------------------------------------------- C:\windows\prefetch\webmediaplayer -------------------------------------------------- this statement stay in Dos window and no further progress, after 5 minutes, following message appear on screen ( not in DOS window ) : Find String (QGREP) utility has stopped working , click close program .... Please advice how to proceed ? thanks . ( NB. the computer seems working perfectly now, no problem to log in to IE ) .Right click it and choose 'Run as Administrator'Done ! same problem and message as before .* Download The Avenger by Swandog46 * Unzip/extract it to a folder on your desktop. * Right click on avenger.exe and choose 'Run as Administrator' * Click OK * Make sure that the box next to Scan for rootkits has a mark in it and that the box next to Automatically disable any rootkits found does not have a mark in it. * Click the Execute button. * You will be asked No script has been entered. Do you want to execute a rootkit scan only?. * Click Yes. * You will now be asked First step completed ... The Avenger has been successfully set up to run on next boot. Reboot now? * Click Yes * Your PC will now be rebooted. * After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%avenger.txt (typically C:avenger.txt). * Please post the Avenger log in your next reply.PLease see Avenger log file . Kindly advice next action. thanks Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows Vista ******************* Script file opened successfully. Script file read successfully. Backups DIRECTORY opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Completed script processing. ******************* Finished! Terminate. |
|
| 1400. |
Solve : removal question BIOS? |
|
Answer» If I got a VIRUS on my COMPUTER could I erase everything off my BIOS and reset it and would doing this get rid of the virus?A virus very rarely infects the bios. 99.9999999% of the time they STAY on the hard drive. A virus very rarely infects the bios. 99.9999999% of the time they stay on the hard drive. EXCELLENT advice!! Just to add, the rule of thumb with your BIOS is leave it alone unless you are 110% positive you know what you are doing! Quote from: evilfantasy on May 16, 2009, 06:39:04 PM Excellent advice!! This same good advice applies to the registry as well........... Quote from: evilfantasy on May 16, 2009, 06:39:04 PM ... unless you are 110% positive you know what you are doing!Not relevant. Does not apply to anybody here. |
|