This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Google search fails

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I type in a search subject into google. The google page disappears and I am left with my desktop. Once when I hit the search button - a timer appeared "DCOM servicer process launcher" I can access the internet via the address box by typing in the web site or via "Favourites" Can you help. Billdave
Please do the following:


STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.


Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
Couldnt get past step1 - google could find the site, clicked on google suggestion and got the answer below Google Error Not Found The requested URL /dds.pif was not found on this server.
Try this one instead,

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Dont know if you received my reply so I will send again. The computer still cannot find a site via google but will go straight to a site if I click on a site via "favourites"

OTListIt Extras logfile created on: 15/05/2009 12:52:35 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = E:\
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

479.48 Mb Total Physical Memory | 143.47 Mb Available Physical Memory | 29.92% Memory free
1.10 Gb Paging File | 0.82 Gb Available in Paging File | 74.40% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 99.48 Gb Free Space | 88.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 3.73 Gb Total Space | 3.73 Gb Free Space | 99.99% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVE
Current User Name: Anyuser
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Media Player Classic\mplayerc.exe:*:Disabled:Media Player Classic (Gabest)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{08498FF9-6C9B-4FC2-8DE1-BD98C89CC220}" = SiSRaidPackage
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A4FFB84-D070-4DA5-AB7B-D41D87FD8D19}" = Norton Security Scan
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{78CC3BAB-DE2A-4FB4-8FBB-E4DADDC26747}" = Ad-Aware SE Personal
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B5C209B1-8DDB-4642-A573-375B951514CB}" = Apple Mobile Device Support
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{F3759A9F-7AFA-4FB4-8DF1-53F26B979DEE}" = Belkin 54Mbps Wireless Network Adapter
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Google Updater" = Google Updater
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"KLiteCodecPack_is1" = K-Lite Codec Pack 2.71 Full
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OfficeScanNT" = Trend Micro OfficeScan Client
"PowerDVD" = PowerDVD
"QuicktimeAlt_is1" = QuickTime Alternative 1.69
"RealAlt_is1" = Real Alternative 1.48
"RealVNC_is1" = VNC Free Edition 4.1.2
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SiS VGA Driver" = SiS VGA Utilities
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 08/09/2008 04:33:40 | Computer Name = DAVE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 16/09/2008 10:35:27 | Computer Name = DAVE | Source = Microsoft Office 11 | ID = 2000
Description =

Error - 29/10/2008 05:29:50 | Computer Name = DAVE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072ee2, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 03/11/2008 05:05:27 | Computer Name = DAVE | Source = ESENT | ID = 490
Description = wuauclt (2312) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 05/01/2009 05:34:43 | Computer Name = DAVE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072efd, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 16/01/2009 11:33:43 | Computer Name = DAVE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240016, P2 begininstall, P3 install, P4
1.1.1593.0, P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL,
P10 NIL.

Error - 27/03/2009 06:25:11 | Computer Name = DAVE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240016, P2 begininstall, P3 install, P4
1.1.1593.0, P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL,
P10 NIL.

Error - 17/04/2009 05:14:14 | Computer Name = DAVE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 23/04/2009 04:40:15 | Computer Name = DAVE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 29/04/2009 04:22:21 | Computer Name = DAVE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 14/05/2009 04:11:22 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058

Error - 14/05/2009 04:15:26 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058

Error - 14/05/2009 04:15:26 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058

Error - 14/05/2009 04:15:26 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058

Error - 15/05/2009 04:10:42 | Computer Name = DAVE | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.124 for the Network Card with network
address 001CDFA0C043 has been denied by the DHCP server 192.168.1.254 (The DHCP
Server sent a DHCPNACK message).

Error - 15/05/2009 04:14:35 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058

Error - 15/05/2009 04:14:35 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058

Error - 15/05/2009 04:14:35 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058

Error - 15/05/2009 07:23:50 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058

Error - 15/05/2009 07:23:50 | Computer Name = DAVE | Source = Service Control Manager | ID = 7000
Description = The Common Firewall Driver service failed to start due to the following
error: %%1058


< End of report >
OTListIt logfile created on: 15/05/2009 12:52:35 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = E:\
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

479.48 Mb Total Physical Memory | 143.47 Mb Available Physical Memory | 29.92% Memory free
1.10 Gb Paging File | 0.82 Gb Available in Paging File | 74.40% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 99.48 Gb Free Space | 88.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 3.73 Gb Total Space | 3.73 Gb Free Space | 99.99% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVE
Current User Name: Anyuser
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe (Belkin)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)
PRC - C:\WINDOWS\TEMP\RS8754.EXE ()
PRC - C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe (Trend Micro Inc.)
PRC - E:\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (AppleImapiService [Auto | Stopped]) – File not found
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aspnet_stateAlerter [Auto | Stopped]) – File not found
SRV - (aspnet_stateNla [Auto | Stopped]) – File not found
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (COMSysAppEventlog [Auto | Stopped]) – File not found
SRV - (dmadminwuauserv [Auto | Stopped]) – File not found
SRV - (dmserverWmi [Auto | Stopped]) – File not found
SRV - (ERSvcAppMgmt [Auto | Stopped]) – File not found
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (helpsvcShellHWDetection [Auto | Stopped]) – File not found
SRV - (mnmsrvcNetDDEdsdmWZCSVC [Auto | Stopped]) – File not found
SRV - (MSDTCBrowser [Auto | Stopped]) – File not found
SRV - (NetDDECOMSysApp [Auto | Stopped]) – File not found
SRV - (NetDDEdsdmWZCSVC [Auto | Stopped]) – File not found
SRV - (ntrtscan [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe (Trend Micro Inc.)
SRV - (OfcPfwSvc [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe (Trend Micro Inc.)
SRV - (OfcPfwSvcdmserverWmi [Auto | Stopped]) – File not found
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (oseCOMSysAppEventlog [Auto | Stopped]) – File not found
SRV - (ProtectedStorageALG [Auto | Stopped]) – File not found
SRV - (RasManThemes [Auto | Stopped]) – File not found
SRV - (RemoteAccessThemes [Auto | Stopped]) – File not found
SRV - (Spoolerclr_optimization_v2.0.50727_32 [Auto | Stopped]) – File not found
SRV - (TapiSrvVSS [Auto | Stopped]) – File not found
SRV - (Themesaspnet_stateAlerter [Auto | Stopped]) – File not found
SRV - (tmlisten [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe (Trend Micro Inc.)
SRV - (tmlistenNetDDEdsdmWZCSVC [Auto | Stopped]) – File not found
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (upnphosthelpsvcShellHWDetection [Auto | Stopped]) – File not found
SRV - (UPSNetlogon [Auto | Stopped]) – File not found
SRV - (UPSNetlogonThemes [Auto | Stopped]) – File not found
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT73 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rt73.sys (Ralink Technology, Corp.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys ()
DRV - (SiS315 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SiSide [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\siside.sys (Silicon Integrated Systems Corp.)
DRV - (sisidex [Boot | Running]) – C:\WINDOWS\system32\drivers\sisidex.sys (Windows ® 2000 DDK provider)
DRV - (SiSkp [System | Running]) – C:\WINDOWS\system32\DRIVERS\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SISNIC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\sisnic.sys (SiS Corporation)
DRV - (sisperf [Boot | Running]) – C:\WINDOWS\system32\drivers\sisperf.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SiSRaid.sys (Silicon Integrated Systems)
DRV - (TmFilter [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys (Trend Micro Inc.)
DRV - (TmPreFilter [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys (Trend Micro Inc.)
DRV - (VSApiNt [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys (Trend Micro Inc.)
DRV - (GTNDIS5 [On_Demand | Running]) – C:\Program Files\Belkin\F5D7050v3\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (TM_CFW [Auto | Stopped]) – C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys (Trend Micro Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========



[2008/09/02 17:09:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\mozilla\Firefox\Profiles\4zjyngih.default\extensions

O1 HOSTS File: (942 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mozilla.com
O1 - Hosts: 127.0.0.1 www.mozilla.com
O1 - Hosts: 127.0.0.1 firefox.com
O1 - Hosts: 127.0.0.1 www.firefox.com
O1 - Hosts: 127.0.0.1 www.firefox2.com
O1 - Hosts: 127.0.0.1 firefox2.com
O1 - Hosts: 127.0.0.1 ftp.saix.net
O1 - Hosts: 127.0.0.1 download.mozilla.com
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [\VIE1.exe] C:\Windows\System32\VIE1.exe File not found
O4 - HKLM..\Run: [\VIE10.exe] C:\Windows\System32\VIE10.exe File not found
O4 - HKLM..\Run: [\VIE12.exe] C:\Windows\System32\VIE12.exe File not found
O4 - HKLM..\Run: [\VIE13.exe] C:\Windows\System32\VIE13.exe File not found
O4 - HKLM..\Run: [\VIE2.exe] C:\Windows\System32\VIE2.exe File not found
O4 - HKLM..\Run: [\VIE3.exe] C:\Windows\System32\VIE3.exe File not found
O4 - HKLM..\Run: [\VIE4.exe] C:\Windows\System32\VIE4.exe File not found
O4 - HKLM..\Run: [\VIE47.exe] C:\Windows\System32\VIE47.exe File not found
O4 - HKLM..\Run: [\VIE5.exe] C:\Windows\System32\VIE5.exe File not found
O4 - HKLM..\Run: [\VIE6.exe] C:\Windows\System32\VIE6.exe File not found
O4 - HKLM..\Run: [\VIE8.exe] C:\Windows\System32\VIE8.exe File not found
O4 - HKLM..\Run: [\VIE83.exe] C:\Windows\System32\VIE83.exe File not found
O4 - HKLM..\Run: [\VIE84.exe] C:\Windows\System32\VIE84.exe File not found
O4 - HKLM..\Run: [\VIEA.exe] C:\Windows\System32\VIEA.exe File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [F5D7050v3] C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe (Belkin)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow (Trend Micro Inc.)
O4 - HKLM..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [\VIE1.exe] C:\Windows\System32\VIE1.exe File not found
O4 - HKCU..\Run: [\VIE10.exe] C:\Windows\System32\VIE10.exe File not found
O4 - HKCU..\Run: [\VIE12.exe] C:\Windows\System32\VIE12.exe File not found
O4 - HKCU..\Run: [\VIE13.exe] C:\Windows\System32\VIE13.exe File not found
O4 - HKCU..\Run: [\VIE2.exe] C:\Windows\System32\VIE2.exe File not found
O4 - HKCU..\Run: [\VIE3.exe] C:\Windows\System32\VIE3.exe File not found
O4 - HKCU..\Run: [\VIE4.exe] C:\Windows\System32\VIE4.exe File not found
O4 - HKCU..\Run: [\VIE47.exe] C:\Windows\System32\VIE47.exe File not found
O4 - HKCU..\Run: [\VIE5.exe] C:\Windows\System32\VIE5.exe File not found
O4 - HKCU..\Run: [\VIE6.exe] C:\Windows\System32\VIE6.exe File not found
O4 - HKCU..\Run: [\VIE8.exe] C:\Windows\System32\VIE8.exe File not found
O4 - HKCU..\Run: [\VIE83.exe] C:\Windows\System32\VIE83.exe File not found
O4 - HKCU..\Run: [\VIE84.exe] C:\Windows\System32\VIE84.exe File not found
O4 - HKCU..\Run: [\VIEA.exe] C:\Windows\System32\VIEA.exe File not found
O4 - HKCU..\Run: [AntispywareBot] C:\Program Files\AntispywareBot\AntispywareBot.exe -boot File not found
O4 - HKCU..\Run: [enactcom] C:\WINDOWS\system32\lyhmnmbk.exe File not found
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 77 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Ranges: Range40 ([http] in Trusted sites)
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} http://192.168.1.2:8080/officescan/console…ll/WinNTChk.cab (ObjWinNTCheck Class)
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} http://192.168.1.2:8080/officescan/console…ll/setupini.cab (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class)
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} http://192.168.1.2:8080/officescan/console…stall/setup.cab (OfficeScan Corp Edition Web-Deployment SetupCtrl Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab (YInstStarter Class)
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} http://192.168.1.2:8080/officescan/console/html/AtxEnc.cab (Encrypt Class)
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} http://192.168.1.2:8080/officescan/console…/RemoveCtrl.cab (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} http://192.168.1.2:8080/officescan/console/html/AtxPie.cab (PieChart Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{88B89865-21E5-4439-A69C-57402BC99643}\\NameServer = 192.168.1.1,194.72.6.57
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\twext.exe) - C:\WINDOWS\system32\twext.exe [FILE handle not seen by OS]
O21 - SSODL: websh - {4C8D4D4C-5A93-CBEF-FCBE-00E952C5B4AD} - C:\Program Files\bwxjlgb\websh.dll File not found
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/25 13:17:41 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{5708ad83-ebee-11da-83a1-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{5708ad83-ebee-11da-83a1-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5708ad83-ebee-11da-83a1-806d6172696f}\Shell\AutoRun\command - "" = D:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/05/15 12:51:36 | 00,000,286 | —- | C] () – C:\Documents and Settings\Anyuser\Desktop\Shortcut to OTListIt2.lnk
[2009/05/15 10:17:28 | 00,034,304 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\Tweed Homes Ltd sales report may 09.doc
[2009/05/14 11:54:01 | 00,025,088 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\jan rankin.doc
[2009/05/14 10:00:04 | 00,017,920 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\Fabric of the Land cash book.xls
[2009/05/08 16:52:00 | 03,541,126 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\Tweed_Homes_Sprouston_Dean_Road_001.pdf
[2009/05/08 16:52:00 | 03,541,126 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\Sprouston Tweed
[2009/05/05 09:49:31 | 00,000,602 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\Shortcut to Backup of APL Flexi time.lnk
[2009/04/29 09:42:24 | 00,069,632 | RHS- | C] (Lvdjgjy Coscogjpdaj) – C:\WINDOWS\System32\1xwt.exe
[2009/04/28 10:59:49 | 00,069,632 | RHS- | C] (Lvdjgjy Coscogjpdaj) – C:\WINDOWS\System32\12520850e.exe
[2009/04/27 09:09:40 | 00,069,632 | RHS- | C] (Lvdjgjy Coscogjpdaj) – C:\WINDOWS\System32\accessdv.exe
[2009/04/20 10:01:45 | 00,056,320 | RHS- | C] (Microsoft Corporation) – C:\WINDOWS\System32\1042b.exe
[2009/04/17 16:17:54 | 00,014,848 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\riveroak os invoice summary.xls
[2009/04/17 15:27:36 | 00,056,320 | RHS- | C] (Microsoft Corporation) – C:\WINDOWS\System32\1031ak.exe
[2009/04/17 14:38:55 | 00,056,320 | RHS- | C] (Microsoft Corporation) – C:\WINDOWS\System32\1054r.exe
[2009/04/17 14:15:27 | 00,451,968 | —- | C] (Ralink Technology, Corp.) – C:\WINDOWS\System32\drivers\rt73.sys
[2009/04/17 14:15:26 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\UpdateDriver.exe
[2009/04/17 14:15:26 | 00,001,684 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Belkin Wireless Networking Utility.lnk
[2009/04/17 14:15:25 | 00,005,224 | —- | C] () – C:\WINDOWS\System32\ucuiinfo.ini
[2009/04/17 14:15:20 | 00,000,000 | —D | C] – C:\Program Files\Belkin
[2009/04/17 14:15:01 | 00,000,000 | —D | C] – C:\Documents and Settings\Anyuser\Application Data\InstallShield
[2009/04/17 13:09:10 | 00,053,248 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\Riveroak new invoices.doc
[2009/04/17 12:34:11 | 00,029,696 | —- | C] () – C:\Documents and Settings\Anyuser\My Documents\Clydesdale Bank loans april 09.doc
[2008/08/15 12:32:23 | 00,004,096 | —- | C] () – C:\WINDOWS\System32\regm64.dll
[2008/08/15 12:32:23 | 00,004,096 | —- | C] () – C:\WINDOWS\System32\hoproxy.dll
[2008/08/15 12:32:23 | 00,004,096 | —- | C] () – C:\WINDOWS\System32\h@tkeysh@@k.dll
[2008/08/15 12:32:23 | 00,004,096 | —- | C] () – C:\WINDOWS\System32\awtoolb.dll
[2008/08/15 12:32:23 | 00,004,096 | —- | C] () – C:\WINDOWS\System32\anticipator.dll
[2006/06/23 16:54:46 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/06/14 13:45:52 | 00,007,699 | —- | C] () – C:\WINDOWS\cfgall.ini
[2006/05/25 15:14:57 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/25 14:13:29 | 00,000,478 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/25 13:27:38 | 00,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2006/05/25 13:26:40 | 00,076,270 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2006/05/25 13:25:49 | 00,075,045 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2006/05/25 13:25:43 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\IDEproperty.dll
[2006/05/25 13:25:14 | 00,157,696 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/05/25 13:25:10 | 00,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/05/25 13:25:10 | 00,540,178 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2006/05/25 13:25:10 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/05/25 13:25:08 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2006/05/25 13:25:04 | 00,006,144 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2006/05/25 13:25:02 | 00,135,168 | —- | C] () – C:\WINDOWS\System32\property.dll
[2006/05/25 13:25:02 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2004/08/04 13:00:00 | 00,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/04 13:00:00 | 00,000,573 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 13:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/05/15 12:51:36 | 00,000,286 | —- | M] () – C:\Documents and Settings\Anyuser\Desktop\Shortcut to OTListIt2.lnk
[2009/05/15 12:42:35 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/05/15 12:22:36 | 00,002,521 | —- | M] () – C:\Documents and Settings\Anyuser\Desktop\Microsoft Office Outlook 2003.lnk
[2009/05/15 12:22:31 | 00,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/15 12:22:16 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/05/15 12:22:11 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Anyuser\Local Settings\desktop.ini
[2009/05/15 12:22:05 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/15 12:22:03 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/15 10:17:29 | 00,034,304 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\Tweed Homes Ltd sales report may 09.doc
[2009/05/15 09:22:06 | 00,002,497 | —- | M] () – C:\Documents and Settings\Anyuser\Desktop\Microsoft Office Word 2003.lnk
[2009/05/14 12:07:28 | 00,017,920 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\Fabric of the Land cash book.xls
[2009/05/14 12:00:38 | 00,002,495 | —- | M] () – C:\Documents and Settings\Anyuser\Desktop\Microsoft Office Excel 2003.lnk
[2009/05/14 11:54:02 | 00,025,088 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\jan rankin.doc
[2009/05/13 09:50:05 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/05/12 16:19:52 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/11 11:40:29 | 00,022,528 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\Clubhouse Running Pricing Mar 09.xls
[2009/05/08 16:52:00 | 03,541,126 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\Tweed_Homes_Sprouston_Dean_Road_001.pdf
[2009/05/08 16:52:00 | 03,541,126 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\Sprouston Tweed
[2009/05/08 15:00:01 | 00,000,410 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan.job
[2009/05/05 09:49:31 | 00,000,602 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\Shortcut to Backup of APL Flexi time.lnk
[2009/04/29 09:43:37 | 00,000,142 | –S- | M] () – C:\WINDOWS\System32\1699084608.dat
[2009/04/29 09:42:22 | 00,069,632 | RHS- | M] (Lvdjgjy Coscogjpdaj) – C:\WINDOWS\System32\1xwt.exe
[2009/04/28 10:59:49 | 00,069,632 | RHS- | M] (Lvdjgjy Coscogjpdaj) – C:\WINDOWS\System32\12520850e.exe
[2009/04/27 09:09:39 | 00,069,632 | RHS- | M] (Lvdjgjy Coscogjpdaj) – C:\WINDOWS\System32\accessdv.exe
[2009/04/20 10:01:44 | 00,056,320 | RHS- | M] (Microsoft Corporation) – C:\WINDOWS\System32\1042b.exe
[2009/04/20 09:44:59 | 00,462,168 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/20 09:44:59 | 00,395,530 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/20 09:44:59 | 00,059,644 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/17 17:33:58 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/17 16:17:54 | 00,014,848 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\riveroak os invoice summary.xls
[2009/04/17 16:07:38 | 00,053,248 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\Riveroak new invoices.doc
[2009/04/17 15:27:36 | 00,056,320 | RHS- | M] (Microsoft Corporation) – C:\WINDOWS\System32\1031ak.exe
[2009/04/17 14:38:55 | 00,056,320 | RHS- | M] (Microsoft Corporation) – C:\WINDOWS\System32\1054r.exe
[2009/04/17 14:15:26 | 00,001,684 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Belkin Wireless Networking Utility.lnk
[2009/04/17 12:34:12 | 00,029,696 | —- | M] () – C:\Documents and Settings\Anyuser\My Documents\Clydesdale Bank loans april 09.doc

========== LOP Check ==========

[2008/09/11 14:40:56 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/09/11 14:42:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/11/16 10:39:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/11/23 11:06:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/12 14:40:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/05/14 12:04:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2009/04/17 14:17:08 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/05/25 13:25:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Real
[2007/06/12 16:50:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/12 14:39:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/06/12 09:40:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/09/04 11:21:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\zknorozi
[2009/04/17 14:15:01 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Anyuser\Application Data
[2008/05/12 15:41:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Adobe
[2009/01/09 17:40:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\AntispywareBot
[2007/11/16 10:42:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Apple Computer
[2006/12/28 17:37:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Google
[2006/12/15 17:06:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Help
[2006/05/25 13:23:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Identities
[2009/04/17 14:15:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\InstallShield
[2006/05/25 14:03:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Lavasoft
[2006/06/28 16:41:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Macromedia
[2006/09/22 09:16:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Media Player Classic
[2008/01/08 13:20:39 | 00,000,000 | –SD | M] – C:\Documents and Settings\Anyuser\Application Data\Microsoft
[2008/09/02 17:09:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Mozilla
[2006/05/25 13:25:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Real
[2006/06/16 10:12:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Sun
[2008/09/02 17:16:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Anyuser\Application Data\Talkback
[2009/01/09 17:44:24 | 00,000,524 | —- | M] () – C:\WINDOWS\Tasks\AntispywareBot Scheduled Scan.job
[2009/05/13 09:50:05 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/15 12:22:16 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/05/15 12:42:35 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/05/08 15:00:01 | 00,000,410 | —- | M] () – C:\WINDOWS\Tasks\Norton Security Scan.job
[2009/05/15 12:22:05 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-18 12:27:37
Windows 5.1.2600 Service Pack 2


—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\ctfmon.exe[164] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\ctfmon.exe[164] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\System32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\System32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\Explorer.EXE[628] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\Explorer.EXE[628] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\winlogon.exe[716] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\winlogon.exe[716] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\services.exe[760] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\services.exe[760] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\lsass.exe[772] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\lsass.exe[772] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\svchost.exe[964] c:\windows\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\svchost.exe[964] c:\windows\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\svchost.exe[1012] c:\windows\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\svchost.exe[1012] c:\windows\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1052] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Windows Defender\MsMpEng.exe[1052] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\System32\svchost.exe[1092] c:\windows\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\System32\svchost.exe[1092] c:\windows\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\svchost.exe[1216] c:\windows\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\svchost.exe[1216] c:\windows\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\svchost.exe[1260] c:\windows\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\svchost.exe[1260] c:\windows\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\SOUNDMAN.EXE[1368] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\SOUNDMAN.EXE[1368] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe[1388] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe[1388] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Windows Defender\MSASCui.exe[1432] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Windows Defender\MSASCui.exe[1432] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\spoolsv.exe[1564] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\spoolsv.exe[1564] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\svchost.exe[1644] c:\windows\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\svchost.exe[1644] c:\windows\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1676] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1676] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe[1780] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe[1780] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[1824] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[1824] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe[1832] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe[1832] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe[1848] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe[1848] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Messenger\msmsgs.exe[1884] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Messenger\msmsgs.exe[1884] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\wdfmgr.exe[1900] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\wdfmgr.exe[1900] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe[1944] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe[1944] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\sistray.exe[2140] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\sistray.exe[2140] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\TEMP\EF10E6.EXE[2148] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\TEMP\EF10E6.EXE[2148] C:\WINDOWS\system32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\System32\alg.exe[2400] C:\WINDOWS\System32\WS2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\System32\alg.exe[2400] C:\WINDOWS\System32\WS2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\wuauclt.exe[2628] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\wuauclt.exe[2628] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]
.text C:\WINDOWS\system32\wuauclt.exe[3364] C:\WINDOWS\system32\ws2_32.dll section is writeable [0x71AB1000, 0x12133, 0xE0000040]
.data C:\WINDOWS\system32\wuauclt.exe[3364] C:\WINDOWS\system32\ws2_32.dll entry point in ".data" section [0x71AC4179]

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00405297
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00405229
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 004051EB
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 004051B8
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 004055A9
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 0040588A
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 0040588A
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 004055A9
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 0040588A
IAT C:\WINDOWS\System32\svchost.exe[440] @ C:\WINDOWS\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00405297
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\Explorer.EXE [USER32.dll!TranslateMessage] 017D588A
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 017D5297
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 017D5229
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 017D51EB
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 017D51B8
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 017D588A
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 017D588A
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 017D55A9
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 017D55A9
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 017D588A
IAT C:\WINDOWS\Explorer.EXE[628] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 017D5297
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\services.exe [ntdll.dll!NtQueryDirectoryFile] 00EE5297
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00EE5297
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00EE5229
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00EE51EB
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00EE51B8
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00EE55A9
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00EE588A
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00EE588A
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00EE55A9
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00EE588A
IAT C:\WINDOWS\system32\services.exe[760] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00EE5297
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00B15297
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00B15229
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00B151EB
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00B151B8
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\LSASRV.dll [ntdll.dll!LdrLoadDll] 00B15229
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00B15297
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrLoadDll] 00B15229
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrGetProcedureAddress] 00B151EB
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00B155A9
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00B1588A
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00B1588A
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00B155A9
IAT C:\WINDOWS\system32\lsass.exe[772] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00B1588A
IAT C:\WINDOWS\system32\svchost.exe[964] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 007B51B8
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00915297
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00915229
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 009151EB
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 009151B8
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 009155A9
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 0091588A
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 0091588A
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 009155A9
IAT C:\WINDOWS\system32\svchost.exe[1012] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 0091588A
IAT C:\WINDOWS\system32\svchost.exe[1012] @ c:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00915297
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00A55297
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00A55229
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00A551EB
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00A551B8
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00A5588A
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00A555A9
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00A5588A
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00A555A9
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00A5588A
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1052] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00A55297
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 021F5297
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 021F5229
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 021F51EB
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 021F51B8
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 021F55A9
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 021F588A
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 021F588A
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 021F55A9
IAT C:\WINDOWS\System32\svchost.exe[1092] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 021F588A
IAT C:\WINDOWS\System32\svchost.exe[1092] @ c:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 021F5297
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00135297
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00135229
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 001351EB
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 001351B8
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 0013588A
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 001355A9
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 0013588A
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00135297
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 001355A9
IAT C:\DOCUME~1\Anyuser\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[1320] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 0013588A
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00FD5297
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00FD5229
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00FD51EB
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00FD51B8
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00FD588A
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00FD55A9
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00FD588A
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00FD55A9
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00FD588A
IAT C:\Program Files\Windows Defender\MSASCui.exe[1432] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00FD5297
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00135297
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00135229
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 001351EB
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 001351B8
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 0013588A
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 001355A9
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 0013588A
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00135297
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 001355A9
IAT C:\WINDOWS\system32\sistray.exe[2140] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 0013588A
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00405297
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00405229
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 004051EB
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 004051B8
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 004055A9
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 0040588A
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00405297
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 0040588A
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 004055A9
IAT C:\WINDOWS\System32\alg.exe[2400] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 0040588A
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00085297
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00085229
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 000851EB
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 000851B8
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 000855A9
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 0008588A
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 0008588A
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 0008588A
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 000855A9
IAT C:\WINDOWS\system32\wuauclt.exe[2628] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00085297
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00085297
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00085229
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 000851EB
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 000851B8
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 000855A9
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 0008588A
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 0008588A
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 0008588A
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 000855A9
IAT C:\WINDOWS\system32\wuauclt.exe[3364] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00085297

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (FileSpy Filter Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs TmPreFlt.sys (Pre-Filter For XP/Trend Micro Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat sisidex.sys (FileSpy Filter Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Fastfat \Fat TmPreFlt.sys (Pre-Filter For XP/Trend Micro Inc.)

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\twain_32 0 bytes
File C:\WINDOWS\system32\twain_32\local.ds 0 bytes
File C:\WINDOWS\system32\twain_32\user.ds 198805 bytes
File C:\WINDOWS\system32\twext.exe 478720 bytes executable

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Computer acting the same as before. Scan result below
Billdave

ComboFix 09-05-17.05 - Anyuser 18/05/2009 14:49.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.479.174 [GMT 1:00]

Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe

FW: Trend Micro OfficeScan Enterprise Client Firewall *disabled* {F548C6D7-DBB9-4BBC-981A-A76EABD796D4}

* Created a new restore point

.



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.



c:\documents and settings\Anyuser\Application Data\AntispywareBot

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Log\2009 Jan 09 - 04_40_03 PM_765.log

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Log\2009 Jan 09 - 04_44_20 PM_359.log

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Log\2009 Jan 09 - 04_45_28 PM_296.log

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Log\2009 Jan 09 - 04_45_33 PM_843.log

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Log\2009 Jan 09 - 04_45_36 PM_296.log

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Log\2009 Jan 09 - 04_46_11 PM_000.log

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Log\2009 Jan 09 - 04_46_59 PM_171.log

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Log\2009 Jan 09 - 04_48_27 PM_515.log

c:\documents and settings\Anyuser\Application Data\AntispywareBot\rs.dat

c:\documents and settings\Anyuser\Application Data\AntispywareBot\Settings\ScanResults.pie

c:\documents and settings\LocalService\Application Data\twain_32

c:\documents and settings\LocalService\Application Data\twain_32\user.ds

c:\windows\a.bat

c:\windows\bdn.com

c:\windows\iTunesMusic.exe

c:\windows\mslagent

c:\windows\mssecu.exe

c:\windows\system32\1.ico

c:\windows\system32\2.ico

c:\windows\system32\akttzn.exe

c:\windows\system32\anticipator.dll

c:\windows\system32\awtoolb.dll

c:\windows\system32\bdn.com

c:\windows\system32\dpcproxy.exe

c:\windows\system32\dumphive.exe

c:\windows\system32\hoproxy.dll

c:\windows\system32\hxiwlgpm.dat

c:\windows\system32\hxiwlgpm.exe

c:\windows\system32\msgp.exe

c:\windows\system32\mssecu.exe

c:\windows\system32\mtr2.exe

c:\windows\system32\mwin32.exe

c:\windows\system32\netode.exe

c:\windows\system32\newsd32.exe

c:\windows\system32\ps1.exe

c:\windows\system32\psoft1.exe

c:\windows\system32\regm64.dll

c:\windows\system32\Rundl1.exe

c:\windows\system32\smp

c:\windows\system32\smp\msrc.exe

c:\windows\system32\SrchSTS.exe

c:\windows\system32\ssvchost.exe

c:\windows\system32\sysreq.exe

c:\windows\system32\taack.dat

c:\windows\system32\taack.exe

c:\windows\system32\temp#01.exe

c:\windows\system32\tmp.reg

c:\windows\system32\twain_32

c:\windows\system32\twain_32\local.ds

c:\windows\system32\twain_32\user.ds

c:\windows\system32\twext.exe

c:\windows\system32\VBIEWER.OCX

c:\windows\system32\winlogonpc.exe

c:\windows\system32\winsystem.exe

c:\windows\system32\WINWGPX.EXE

c:\windows\Tasks.\AntiSpywareBot Scheduled Scan.job



.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.



——-\Legacy_ASPNET_STATEALERTER

——-\Legacy_COMSYSAPPEVENTLOG

——-\Legacy_DMADMINWUAUSERV

——-\Legacy_DMSERVERWMI

——-\Legacy_ERSVCAPPMGMT

——-\Legacy_HELPSVCSHELLHWDETECTION

——-\Legacy_MNMSRVCNETDDEDSDMWZCSVC

——-\Legacy_MSDTCBROWSER

——-\Legacy_NETDDECOMSYSAPP

——-\Legacy_NETDDEDSDMWZCSVC

——-\Legacy_OFCPFWSVCDMSERVERWMI

——-\Legacy_OSECOMSYSAPPEVENTLOG

——-\Legacy_PROTECTEDSTORAGEALG

——-\Legacy_RASMANTHEMES

——-\Legacy_REMOTEACCESSTHEMES

——-\Legacy_SPOOLERCLR_OPTIMIZATION_V2.0.50727_32

——-\Legacy_TAPISRVVSS

——-\Legacy_THEMESASPNET_STATEALERTER

——-\Legacy_TMLISTENNETDDEDSDMWZCSVC

——-\Legacy_UPNPHOSTHELPSVCSHELLHWDETECTION

——-\Legacy_UPSNETLOGON

——-\Service_aspnet_stateAlerter

——-\Service_COMSysAppEventlog

——-\Service_dmadminwuauserv

——-\Service_dmserverWmi

——-\Service_ERSvcAppMgmt

——-\Service_helpsvcShellHWDetection

——-\Service_mnmsrvcNetDDEdsdmWZCSVC

——-\Service_MSDTCBrowser

——-\Service_NetDDECOMSysApp

——-\Service_NetDDEdsdmWZCSVC

——-\Service_OfcPfwSvcdmserverWmi

——-\Service_oseCOMSysAppEventlog

——-\Service_ProtectedStorageALG

——-\Service_RasManThemes

——-\Service_RemoteAccessThemes

——-\Service_Spoolerclr_optimization_v2.0.50727_32

——-\Service_TapiSrvVSS

——-\Service_Themesaspnet_stateAlerter

——-\Service_tmlistenNetDDEdsdmWZCSVC

——-\Service_upnphosthelpsvcShellHWDetection

——-\Service_UPSNetlogon





((((((((((((((((((((((((( Files Created from 2009-04-18 to 2009-05-18 )))))))))))))))))))))))))))))))

.



2009-04-29 08:42 . 2009-04-29 08:42 69632 –sh–r c:\windows\system32\1xwt.exe

2009-04-28 09:59 . 2009-04-28 09:59 69632 –sh–r c:\windows\system32\12520850e.exe

2009-04-27 08:09 . 2009-04-27 08:09 69632 –sh–r c:\windows\system32\accessdv.exe

2009-04-20 09:01 . 2009-04-20 09:01 56320 –sh–r c:\windows\system32\1042b.exe



.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-05-12 12:17 . 2007-04-13 14:00 ——– d—–w c:\program files\Common Files\Symantec Shared

2009-05-12 12:16 . 2008-09-10 10:25 ——– d—–w c:\program files\Norton Security Scan

2009-04-29 08:43 . 2009-04-14 07:56 142 –s-a-w c:\windows\system32\1699084608.dat

2009-04-17 14:27 . 2009-04-17 14:27 56320 –sh–r c:\windows\system32\1031ak.exe

2009-04-17 13:38 . 2009-04-17 13:38 56320 –sh–r c:\windows\system32\1054r.exe

2009-04-17 13:15 . 2009-04-17 13:15 20747 —-a-w c:\windows\system32\drivers\AegisP.sys

2009-04-17 13:15 . 2006-05-25 12:26 ——– d–h–w c:\program files\InstallShield Installation Information

2009-04-17 13:15 . 2009-04-17 13:15 ——– d—–w c:\program files\Belkin

2009-04-14 10:35 . 2009-04-14 10:35 56320 –sh–r c:\windows\system32\acctresr.exe

2009-04-14 07:55 . 2009-04-14 07:55 56320 –sh–r c:\windows\system32\acledith.exe

2009-04-06 08:45 . 2009-04-06 08:45 56320 –sh–r c:\windows\system32\3076l.exe

2009-04-02 09:05 . 2009-04-02 09:05 36864 –sh–r c:\windows\system32\1xw.exe

2009-04-01 09:08 . 2009-04-01 09:08 36864 –sh–r c:\windows\system32\actmoviekqh.exe

2009-03-30 09:20 . 2009-03-30 09:20 36864 –sh–r c:\windows\system32\actmoviekq.exe

2009-03-30 08:20 . 2009-03-30 08:20 36864 –sh–r c:\windows\system32\1037zz.exe

2009-03-26 14:23 . 2009-03-26 14:23 36864 –sh–r c:\windows\system32\accessdp.exe

2009-03-25 09:30 . 2009-03-25 09:30 36864 –sh–r c:\windows\system32\3ivxu.exe

2009-03-23 10:54 . 2009-03-23 10:54 36864 –sh–r c:\windows\system32\1x.exe

2009-03-23 08:54 . 2009-03-23 08:54 36864 –sh–r c:\windows\system32\accwizf.exe

2009-03-20 13:33 . 2009-03-20 13:33 36864 –sh–r c:\windows\system32\adsmsextd.exe

2009-03-18 09:19 . 2009-03-18 09:19 36864 –sh–r c:\windows\system32\12520437z.exe

2009-03-17 11:11 . 2009-03-17 11:11 36864 –sh–r c:\windows\system32\1031a.exe

2009-03-16 12:01 . 2009-03-16 12:01 36864 –sh–r c:\windows\system32\actmoviek.exe

2009-03-16 10:01 . 2009-03-16 10:01 36864 –sh–r c:\windows\system32\3ivxv.exe

2009-03-12 14:21 . 2009-03-12 14:21 36864 –sh–r c:\windows\system32\accessd.exe

2009-03-10 11:50 . 2009-03-10 11:51 56320 –sh–r c:\windows\system32\accessh.exe

2009-03-06 14:44 . 2004-08-04 12:00 283648 —-a-w c:\windows\system32\pdh.dll

2009-03-03 00:18 . 2004-08-04 12:00 826368 —-a-w c:\windows\system32\wininet.dll

2009-02-20 18:09 . 2004-08-04 12:00 78336 —-a-w c:\windows\system32\ieencode.dll

.



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4



[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-21 68856]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 356352]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-30 1654784]

"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-11-10 49152]

"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-01-11 577536]



[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]



c:\documents and settings\All Users\Start Menu\Programs\Startup\

Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]

Utility Tray.lnk - c:\windows\system32\sistray.exe [2006-5-25 262144]



[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001



[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]

"DisableMonitoring"=dword:00000001



[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)



[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Media Player Classic\\mplayerc.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=



R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\TmXPFlt.sys [09/11/2005 20:34 205328]

R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [09/11/2005 20:34 36368]

R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]

S2 AppleImapiService;Apple Mobile Device AppleImapiService;c:\windows\TEMP\A5.tmp srv –> c:\windows\TEMP\A5.tmp srv [?]

S2 aspnet_stateNla;ASP.NET State Service aspnet_stateNla;c:\windows\TEMP\6D.tmp srv –> c:\windows\TEMP\6D.tmp srv [?]

S2 UPSNetlogonThemes;Uninterruptible Power Supply UPSNetlogon UPSNetlogonThemes;c:\windows\TEMP\7.tmp srv –> c:\windows\TEMP\7.tmp srv [?]



— Other Services/Drivers In Memory —



*NewlyCreated* - GTNDIS5

.

Contents of the 'Scheduled Tasks' folder



2009-05-13 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]



2009-05-18 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-12 09:21]



2009-05-18 c:\windows\Tasks\MP Scheduled Scan.job

- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]



2009-05-15 c:\windows\Tasks\Norton Security Scan.job

- c:\program files\Norton Security Scan\Nss.exe [2007-09-18 22:42]

.

- - - - ORPHANS REMOVED - - - -



HKCU-Run-enactcom - c:\windows\system32\lyhmnmbk.exe

HKCU-Run-\VIE2.exe - c:\windows\System32\VIE2.exe

HKCU-Run-\VIE3.exe - c:\windows\System32\VIE3.exe

HKCU-Run-\VIE4.exe - c:\windows\System32\VIE4.exe

HKCU-Run-\VIE8.exe - c:\windows\System32\VIE8.exe

HKCU-Run-\VIE1.exe - c:\windows\System32\VIE1.exe

HKCU-Run-\VIE5.exe - c:\windows\System32\VIE5.exe

HKCU-Run-\VIE47.exe - c:\windows\System32\VIE47.exe

HKCU-Run-\VIE6.exe - c:\windows\System32\VIE6.exe

HKCU-Run-\VIE10.exe - c:\windows\System32\VIE10.exe

HKCU-Run-\VIE12.exe - c:\windows\System32\VIE12.exe

HKCU-Run-\VIE13.exe - c:\windows\System32\VIE13.exe

HKCU-Run-\VIEA.exe - c:\windows\System32\VIEA.exe

HKCU-Run-\VIE83.exe - c:\windows\System32\VIE83.exe

HKCU-Run-\VIE84.exe - c:\windows\System32\VIE84.exe

HKLM-Run-\VIE2.exe - c:\windows\System32\VIE2.exe

HKLM-Run-\VIE3.exe - c:\windows\System32\VIE3.exe

HKLM-Run-\VIE4.exe - c:\windows\System32\VIE4.exe

HKLM-Run-\VIE8.exe - c:\windows\System32\VIE8.exe

HKLM-Run-\VIE1.exe - c:\windows\System32\VIE1.exe

HKLM-Run-\VIE5.exe - c:\windows\System32\VIE5.exe

HKLM-Run-\VIE47.exe - c:\windows\System32\VIE47.exe

HKLM-Run-\VIE6.exe - c:\windows\System32\VIE6.exe

HKLM-Run-\VIE10.exe - c:\windows\System32\VIE10.exe

HKLM-Run-\VIE12.exe - c:\windows\System32\VIE12.exe

HKLM-Run-\VIE13.exe - c:\windows\System32\VIE13.exe

HKLM-Run-\VIEA.exe - c:\windows\System32\VIEA.exe

HKLM-Run-\VIE83.exe - c:\windows\System32\VIE83.exe

HKLM-Run-\VIE84.exe - c:\windows\System32\VIE84.exe

SSODL-websh-{4C8D4D4C-5A93-CBEF-FCBE-00E952C5B4AD} - c:\program files\bwxjlgb\websh.dll





.

——- Supplementary Scan ——-

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: {88B89865-21E5-4439-A69C-57402BC99643} = 192.168.1.1,194.72.6.57

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} - hxxp://192.168.1.2:8080/officescan/console/html/AtxEnc.cab

DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} - hxxp://192.168.1.2:8080/officescan/console/html/AtxPie.cab

.



**************************************************************************



catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-05-18 14:56

Windows 5.1.2600 Service Pack 2 NTFS



scanning hidden processes …



scanning hidden autostart entries …



scanning hidden files …



scan completed successfully

hidden files: 0



**************************************************************************



[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppleImapiService]

"ImagePath"="c:\windows\TEMP\A5.tmp srv"



[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aspnet_stateNla]

"ImagePath"="c:\windows\TEMP\6D.tmp srv"



[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UPSNetlogonThemes]

"ImagePath"="c:\windows\TEMP\7.tmp srv"

.

———————— Other Running Processes ————————

.

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Trend Micro\OfficeScan Client\NTRtScan.exe

c:\program files\Trend Micro\OfficeScan Client\TmListen.exe

c:\windows\system32\wdfmgr.exe

c:\program files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe

c:\windows\temp\NM8A47.EXE

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2009-05-18 14:59 - machine was rebooted

ComboFix-quarantined-files.txt 2009-05-18 13:59



Pre-Run: 107,194,122,240 bytes free

Post-Run: 107,242,020,864 bytes free



WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect



283 — E O F — 2009-05-15 08:16
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Google_search_fails_t102968.html&view=findpost&p=559723#entry559723

Collect::
c:\windows\system32\1xwt.exe
c:\windows\system32\12520850e.exe
c:\windows\system32\accessdv.exe
c:\windows\system32\1042b.exe
c:\windows\system32\1031ak.exe
c:\windows\system32\1054r.exe
c:\windows\system32\3076l.exe
c:\windows\system32\1xw.exe
c:\windows\system32\actmoviekqh.exe
c:\windows\system32\actmoviekq.exe
c:\windows\system32\acctresr.exe
c:\windows\system32\acledith.exe
c:\windows\system32\1037zz.exe
c:\windows\system32\accessdp.exe
c:\windows\system32\3ivxu.exe
c:\windows\system32\1x.exe
c:\windows\system32\accwizf.exe
c:\windows\system32\adsmsextd.exe
c:\windows\system32\12520437z.exe
c:\windows\system32\1031a.exe
c:\windows\system32\actmoviek.exe
c:\windows\system32\3ivxv.exe
c:\windows\system32\accessd.exe
c:\windows\system32\accessh.exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 09-05-17.05 - Anyuser 18/05/2009 17:18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.479.144 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Anyuser\Desktop\CFScript
FW: Trend Micro OfficeScan Enterprise Client Firewall *disabled* {F548C6D7-DBB9-4BBC-981A-A76EABD796D4}


file zipped: c:\windows\system32\1031a.exe
file zipped: c:\windows\system32\1031ak.exe
file zipped: c:\windows\system32\1037zz.exe
file zipped: c:\windows\system32\1042b.exe
file zipped: c:\windows\system32\1054r.exe
file zipped: c:\windows\system32\12520437z.exe
file zipped: c:\windows\system32\12520850e.exe
file zipped: c:\windows\system32\1x.exe
file zipped: c:\windows\system32\1xw.exe
file zipped: c:\windows\system32\1xwt.exe
file zipped: c:\windows\system32\3076l.exe
file zipped: c:\windows\system32\3ivxu.exe
file zipped: c:\windows\system32\3ivxv.exe
file zipped: c:\windows\system32\accessd.exe
file zipped: c:\windows\system32\accessdp.exe
file zipped: c:\windows\system32\accessdv.exe
file zipped: c:\windows\system32\accessh.exe
file zipped: c:\windows\system32\acctresr.exe
file zipped: c:\windows\system32\accwizf.exe
file zipped: c:\windows\system32\acledith.exe
file zipped: c:\windows\system32\actmoviek.exe
file zipped: c:\windows\system32\actmoviekq.exe
file zipped: c:\windows\system32\actmoviekqh.exe
file zipped: c:\windows\system32\adsmsextd.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\1031a.exe
c:\windows\system32\1031ak.exe
c:\windows\system32\1037zz.exe
c:\windows\system32\1042b.exe
c:\windows\system32\1054r.exe
c:\windows\system32\12520437z.exe
c:\windows\system32\12520850e.exe
c:\windows\system32\1x.exe
c:\windows\system32\1xw.exe
c:\windows\system32\1xwt.exe
c:\windows\system32\3076l.exe
c:\windows\system32\3ivxu.exe
c:\windows\system32\3ivxv.exe
c:\windows\system32\accessd.exe
c:\windows\system32\accessdp.exe
c:\windows\system32\accessdv.exe
c:\windows\system32\accessh.exe
c:\windows\system32\acctresr.exe
c:\windows\system32\accwizf.exe
c:\windows\system32\acledith.exe
c:\windows\system32\actmoviek.exe
c:\windows\system32\actmoviekq.exe
c:\windows\system32\actmoviekqh.exe
c:\windows\system32\adsmsextd.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_ASPNET_STATENLA
——-\Service_aspnet_stateNla

((((((((((((((((((((((((( Files Created from 2009-04-18 to 2009-05-18 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-18 16:00 . 2008-09-10 10:25 ——– d—–w c:\program files\Norton Security Scan
2009-05-12 12:17 . 2007-04-13 14:00 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-29 08:43 . 2009-04-14 07:56 142 –s-a-w c:\windows\system32\1699084608.dat
2009-04-17 13:15 . 2009-04-17 13:15 20747 —-a-w c:\windows\system32\drivers\AegisP.sys
2009-04-17 13:15 . 2006-05-25 12:26 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-17 13:15 . 2009-04-17 13:15 ——– d—–w c:\program files\Belkin
2009-03-06 14:44 . 2004-08-04 12:00 283648 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-04 12:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 12:00 78336 —-a-w c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-18_13.57.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-18 16:21 . 2006-02-07 15:10 172099 c:\windows\temp\IZB2B0.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-21 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 356352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-30 1654784]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-11-10 49152]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-01-11 577536]


[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2006-5-25 262144]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Media Player Classic\\mplayerc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\TmXPFlt.sys [09/11/2005 20:34 205328]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [09/11/2005 20:34 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S2 AppleImapiService;Apple Mobile Device AppleImapiService;c:\windows\TEMP\A5.tmp srv –> c:\windows\TEMP\A5.tmp srv [?]
S2 UPSNetlogonThemes;Uninterruptible Power Supply UPSNetlogon UPSNetlogonThemes;c:\windows\TEMP\7.tmp srv –> c:\windows\TEMP\7.tmp srv [?]
.
Contents of the 'Scheduled Tasks' folder

2009-05-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

2009-05-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-12 09:21]

2009-05-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

2009-05-15 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2007-09-18 22:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {88B89865-21E5-4439-A69C-57402BC99643} = 192.168.1.1,194.72.6.57
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} - hxxp://192.168.1.2:8080/officescan/console/html/AtxEnc.cab
DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} - hxxp://192.168.1.2:8080/officescan/console/html/AtxPie.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-18 17:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppleImapiService]
"ImagePath"="c:\windows\TEMP\A5.tmp srv"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UPSNetlogonThemes]
"ImagePath"="c:\windows\TEMP\7.tmp srv"

.
———————— Other Running Processes ————————
.

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Trend Micro\OfficeScan Client\NTRtScan.exe
c:\program files\Trend Micro\OfficeScan Client\TmListen.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
c:\windows\temp\IZB2B0.EXE
c:\windows\system32\wscntfy.exe
c:\program files\Trend Micro\OfficeScan Client\PccNTUpd.exe
.
**************************************************************************
.
Completion time: 2009-05-18 17:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-18 16:26
ComboFix2.txt 2009-05-18 13:59

Pre-Run: 107,246,792,704 bytes free
Post-Run: 107,235,106,816 bytes free

174 — E O F — 2009-05-15 08:16

I am away until the 27th. Will continue then - many thanks
Hi,

Please do the following:

Please download ATF Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
    • If you use Firefox browser
    • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.

NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT

Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include
  • MBAM Log
  • Kaspersky report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI