This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] trojandownloader:win32/renos.IO

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think I got this while on Pirates Bay torrent site. My Firefox had been acting up so I went on IE 8…Oh well, here are the logs:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:17:18.80 on Sun 07/19/2009
Internet Explorer: 8.0.6001.18783 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3006.1841 [GMT -4:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\DNA\btdna.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Users\Apostate\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\School\LIT451\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig?hl=en
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\apostate\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [PSDiagnosticM] "c:\program files\linksys wireless-g print server\PSDiagnosticM.exe"
mRun: []
mRun: [HPUsageTracking] "c:\program files\hp\hp ut\bin\hppusg.exe" "c:\program files\hp\HP UT"
mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
mRun: [PrnStatusMX] c:\program files\hewlett-packard\prnstatusmx\PrnStatusMX.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
LSP: bmnet.dll
Trusted Zone: navy.mil
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5471/mcfscan.cab
TCP: NameServer = 85.255.112.168,85.255.112.146
TCP: {0C884745-7C02-4B88-B0E9-E6D62C852DA5} = 85.255.112.168,85.255.112.146
TCP: {879A08F0-5235-4DAC-B437-13FDD3ED1FFA} = [removed],[removed]
TCP: {D506B85D-476D-461D-8154-B2B8F25424F9} = 85.255.112.168,85.255.112.146

================= FIREFOX ===================

FF - ProfilePath - c:\users\apostate\appdata\roaming\mozilla\firefox\profiles\2btyf4cw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\apostate\appdata\local\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-19 130936]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-19 348752]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2008-8-16 13824]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2008-8-16 35840]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2009-5-19 121344]
S3 CAATT;AT&T Con App Svc;c:\program files\at&t\communication manager\ConAppsSvc.exe [2009-5-19 125440]
S3 LiveTurbineMessageService;Turbine Message Service - Live;c:\program files\turbine\turbine download manager\TurbineMessageService.exe [2009-4-3 255472]
S3 LiveTurbineNetworkService;Turbine Network Service - Live;c:\program files\turbine\turbine download manager\TurbineNetworkService.exe [2009-4-3 218608]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2009-4-8 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-4-8 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2009-4-8 23680]

=============== Created Last 30 ================

2009-07-19 18:02 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-07-19 18:02 130,936 a——- c:\windows\system32\drivers\PCTCore.sys
2009-07-19 18:02 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-19 18:02 a-d—– c:\programdata\TEMP
2009-07-19 18:02 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-07-19 18:02 –d—– c:\program files\common files\PC Tools
2009-07-19 18:02 –d—– c:\users\apostate\appdata\roaming\PC Tools
2009-07-19 18:02 –d—– c:\programdata\PC Tools
2009-07-19 18:02 –d—– c:\program files\Spyware Doctor
2009-07-19 18:02 –d—– c:\progra~2\PC Tools
2009-07-19 15:50 48,989 a——- c:\program files\Uninstall.exe
2009-07-15 16:48 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-15 16:48 156,672 a——- c:\windows\system32\t2embed.dll
2009-07-15 16:48 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-15 16:48 10,240 a——- c:\windows\system32\dciman32.dll
2009-06-27 18:56 97,800 a——- c:\windows\system32\infocardapi.dll
2009-06-27 18:56 622,080 a——- c:\windows\system32\icardagt.exe
2009-06-27 18:56 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-27 18:56 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-06-27 18:56 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-06-27 18:56 11,264 a——- c:\windows\system32\icardres.dll
2009-06-27 18:56 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-06-27 18:56 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-06-27 18:51 96,760 a——- c:\windows\system32\dfshim.dll
2009-06-27 18:51 282,112 a——- c:\windows\system32\mscoree.dll
2009-06-27 18:51 41,984 a——- c:\windows\system32\netfxperf.dll
2009-06-27 18:51 158,720 a——- c:\windows\system32\mscorier.dll
2009-06-27 18:51 83,968 a——- c:\windows\system32\mscories.dll
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motport_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2009-06-23 18:56 0 a—h— c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-06-23 18:46 –d—– c:\users\apostate\appdata\roaming\Bytemobile
2009-06-23 18:45 –d—– c:\users\apostate\appdata\roaming\Sierra Wireless
2009-06-23 18:43 26,496 a——- c:\windows\system32\drivers\RimSerial.sys
2009-06-23 18:43 –d—– c:\program files\common files\Motorola Shared
2009-06-23 18:42 –d—– c:\program files\common files\PctelEapPeer Authentication
2009-06-23 18:42 –d—– C:\Research in Motion
2009-06-23 18:42 –d—– c:\program files\common files\Research in Motion
2009-06-23 18:42 –d—– c:\programdata\AT&T
2009-06-23 18:42 –d—– c:\program files\Sierra Wireless Inc
2009-06-23 18:42 –d—– c:\program files\AT&T
2009-06-23 18:42 –d—– c:\progra~2\AT&T
2009-06-23 18:39 –d—– c:\program files\Option
2009-06-22 12:07 156 a——- c:\windows\Twunk001.MTX
2009-06-22 12:07 3 a——- c:\windows\Twain001.Mtx
2009-06-22 12:07 0 a——- c:\windows\Twunk002.MTX

==================== Find3M ====================

2009-07-19 18:16 68,276 a——- c:\programdata\nvModes.dat
2009-07-19 18:16 68,276 a——- c:\progra~2\nvModes.dat
2009-06-23 18:45 143,360 a——- c:\windows\inf\infstrng.dat
2009-06-23 18:45 143,360 a——- c:\windows\inf\infstor.dat
2009-06-23 18:45 86,016 a——- c:\windows\inf\infpub.dat
2009-05-19 14:51 719,360 a——- c:\windows\system32\bmutil.dll
2009-05-19 14:51 475,136 a——- c:\windows\system32\bmnet.dll
2009-05-19 14:51 118,784 a——- c:\windows\system32\bmwebcfg.exe
2009-05-19 14:51 8,464 a——- c:\windows\system32\SpOrder.Dll
2009-05-19 14:51 126,976 a——- c:\windows\system32\bmdumpd.bin
2009-05-19 14:50 137,752 a——- c:\windows\system32\PCTIN50.dll
2009-05-19 14:50 32,408 a——- c:\windows\system32\PCTINDIS5.sys
2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-05-01 17:02 90,112 a——- c:\windows\system32\dpl100.dll
2009-05-01 17:02 823,296 a——- c:\windows\system32\divx_xx0c.dll
2009-05-01 17:02 823,296 a——- c:\windows\system32\divx_xx07.dll
2009-05-01 17:02 815,104 a——- c:\windows\system32\divx_xx0a.dll
2009-05-01 17:02 811,008 a——- c:\windows\system32\divx_xx16.dll
2009-05-01 17:02 802,816 a——- c:\windows\system32\divx_xx11.dll
2009-05-01 17:02 685,056 a——- c:\windows\system32\DivX.dll
2009-04-30 08:37 293,376 a——- c:\windows\system32\psisdecd.dll
2009-04-30 08:37 428,544 a——- c:\windows\system32\EncDec.dll
2009-04-23 08:43 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 08:42 636,928 a——- c:\windows\system32\localspl.dll
2009-04-21 07:55 2,033,152 a——- c:\windows\system32\win32k.sys
2009-01-25 15:08 102,364 a——- c:\users\apostate\appdata\roaming\nvModes.dat
2008-06-12 09:08 665,600 a——- c:\windows\inf\drvindex.dat
2008-06-03 01:19 0 a——- c:\users\apostate\appdata\roaming\wklnhst.dat
2008-01-20 22:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2008-07-25 16:32 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-07-25 16:32 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-07-25 16:32 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat

============= FINISH: 19:17:46.32 ===============

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-19 19:24:38
Windows 6.0.6001 Service Pack 1


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x80789282]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x80789474]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x80788F32]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8078967C]

Code 877B0318 ZwEnumerateKey
Code 87846250 ZwFlushInstructionCache
Code 8779F225 IofCallDriver
Code 8743E2BE IofCompleteRequest
Code 8779FBFD ZwSaveKey
Code 877E7485 ZwSaveKeyEx

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!IofCompleteRequest 81E74FE2 5 Bytes JMP 8743E2C3
.text ntkrnlpa.exe!ZwSaveKey 81E91664 5 Bytes JMP 8779FC02
.text ntkrnlpa.exe!ZwSaveKeyEx 81E91678 5 Bytes JMP 877E748A
.text ntkrnlpa.exe!KeSetTimerEx + 43C 81EF3A00 8 Bytes [82, 92, 78, 80, 74, 94, 78, …]
.text ntkrnlpa.exe!KeSetTimerEx + 854 81EF3E18 4 Bytes [32, 8F, 78, 80]
.text ntkrnlpa.exe!KeSetTimerEx + 918 81EF3EDC 4 Bytes [7C, 96, 78, 80] {JL 0xffffffffffffff98; JS 0xffffffffffffff84}
.text ntkrnlpa.exe!IofCallDriver 81EF6F6F 5 Bytes JMP 8779F22A

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\svchost.exe[200] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[200] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[200] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[556] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[556] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[556] KERNEL32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[608] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[608] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\wininit.exe[608] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[620] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[620] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[620] KERNEL32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[652] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[652] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\services.exe[652] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[672] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\lsass.exe[672] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lsm.exe[680] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[680] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\lsm.exe[680] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\winlogon.exe[724] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[724] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\winlogon.exe[724] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[860] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[860] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[860] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[992] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[992] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[992] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1016] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1016] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1016] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\nvvsvc.exe[1056] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1072] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1072] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1072] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1140] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1140] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1156] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1156] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1236] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1236] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1236] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1268] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1268] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] kernel32.dll!CreateThread + 1A 778946E2 4 Bytes CALL 0044AD11 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Windows\System32\spoolsv.exe[1620] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1620] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\spoolsv.exe[1620] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1644] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1644] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1644] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1864] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1864] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[2060] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[2060] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[2060] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\taskeng.exe[2368] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[2368] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\taskeng.exe[2368] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\rundll32.exe[2580] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\rundll32.exe[2580] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\rundll32.exe[2580] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[4036] kernel32.dll!CreateThread + 1A 778946E2 4 Bytes CALL 0044AB89 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!SetWindowsHookExW 761D7B69 5 Bytes JMP 6DAC9271 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!CallNextHookEx 761D8C33 5 Bytes JMP 6DABC8B9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!UnhookWindowsHookEx 762008BE 5 Bytes JMP 6DA34284 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] ole32.dll!CoCreateInstance 760AE188 5 Bytes JMP 6DACD330 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!SetWindowsHookExW 761D7B69 5 Bytes JMP 6DAC9271 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!CallNextHookEx 761D8C33 5 Bytes JMP 6DABC8B9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!UnhookWindowsHookEx 762008BE 5 Bytes JMP 6DA34284 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] ole32.dll!CoCreateInstance 760AE188 5 Bytes JMP 6DACD330 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044AE68] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044AE68] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[4036] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044ACE0] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[4036] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044ACE0] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)

Device \Driver\BTHUSB \Device\00000076 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000078 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-

Attachments:

Hi,

please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Catbyte, thanks for the quick response. I downloaded Combofix, and shut off spyware doctor, but when I tried to load Combofix I received a windows error dialog. I rebooted, tried again and got the same error. Please advise.
The first dialog says Combofix has stopped working. Windows is looking for a solution to the problem. Then it stops and a new dialog opens that says A problem caused Combofix to stop working correctly. Windows is shutting the program down.
Hi,

Please delete the copy you have from your desktop then down load a fresh copy - renaming it before you save it - then run it in safe mode.


Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Ok, that was an experience. Here's the log. Thanks again.

ComboFix 09-07-19.04 - Apostate 07/19/2009 22:25.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3006.2072 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1032403844-1656704120-3049521593-500
c:\$recycle.bin\S-1-5-21-3107584610-53593523-1019121096-500
c:\users\Apostate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Uninstall.lnk
c:\windows\Installer\10da925.msi
c:\windows\Installer\40648.msi
c:\windows\Installer\WMEncoder.msi
c:\windows\system32\drivers\ESQULpmtappcemiudfernpqrsejbhjxxvcvcb.sys
c:\windows\System32\ESQULijcptfqtagmeipoqtspmtutiijiyqwkd.dll
c:\windows\system32\ESQULtclaowdbownhmhuexfcbsrdnjnidwske.dll
c:\windows\system32\KBL.LOG

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_ESQULserv.sys
——-\Service_ESQULserv.sys


((((((((((((((((((((((((( Files Created from 2009-06-20 to 2009-07-20 )))))))))))))))))))))))))))))))
.

2009-07-20 02:34 . 2009-07-20 02:38 ——– d—–w- c:\users\Apostate\AppData\Local\temp
2009-07-19 22:02 . 2008-12-11 12:38 159600 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-07-19 22:02 . 2009-04-03 15:18 130936 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-07-19 22:02 . 2008-12-18 16:16 73840 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-19 22:02 . 2009-07-19 22:02 ——– d—–w- c:\program files\Common Files\PC Tools
2009-07-19 22:02 . 2008-12-10 15:36 64392 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-07-19 22:02 . 2009-07-19 22:03 ——– d—–w- c:\program files\Spyware Doctor
2009-07-19 22:02 . 2009-07-19 22:02 ——– d—–w- c:\users\Apostate\AppData\Roaming\PC Tools
2009-07-19 22:02 . 2009-07-19 22:02 ——– d—–w- c:\progra~2\PC Tools
2009-07-19 19:50 . 2009-07-19 19:50 48989 —-a-w- c:\program files\Uninstall.exe
2009-07-15 20:48 . 2009-06-15 15:24 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-07-15 20:48 . 2009-06-15 15:20 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-07-15 20:48 . 2009-06-15 15:20 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-07-15 20:48 . 2009-06-15 12:52 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-06-27 22:56 . 2008-06-20 01:14 97800 —-a-w- c:\windows\system32\infocardapi.dll
2009-06-27 22:56 . 2008-06-20 01:14 43544 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2009-06-27 22:56 . 2008-06-20 01:14 105016 —-a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-27 22:56 . 2008-06-20 01:14 11264 —-a-w- c:\windows\system32\icardres.dll
2009-06-27 22:56 . 2008-06-20 01:14 622080 —-a-w- c:\windows\system32\icardagt.exe
2009-06-27 22:56 . 2008-06-20 01:14 781344 —-a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-06-27 22:56 . 2008-06-20 01:14 326160 —-a-w- c:\windows\system32\PresentationHost.exe
2009-06-27 22:51 . 2008-07-27 18:03 96760 —-a-w- c:\windows\system32\dfshim.dll
2009-06-27 22:51 . 2008-07-27 18:03 282112 —-a-w- c:\windows\system32\mscoree.dll
2009-06-27 22:51 . 2008-07-27 18:03 41984 —-a-w- c:\windows\system32\netfxperf.dll
2009-06-27 22:51 . 2008-07-27 18:03 158720 —-a-w- c:\windows\system32\mscorier.dll
2009-06-27 22:51 . 2008-07-27 18:03 83968 —-a-w- c:\windows\system32\mscories.dll
2009-06-27 22:50 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-06-27 22:50 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-23 22:46 . 2009-06-23 22:46 ——– d—–w- c:\users\Apostate\AppData\Roaming\Bytemobile
2009-06-23 22:46 . 2009-06-23 22:46 ——– d—–w- c:\users\Apostate\AppData\Local\DBUpdater
2009-06-23 22:46 . 2009-06-23 22:46 ——– d—–w- c:\users\Apostate\AppData\Local\AT&T;
2009-06-23 22:45 . 2009-06-23 22:45 ——– d—–w- c:\users\Apostate\AppData\Roaming\Sierra Wireless
2009-06-23 22:43 . 2007-01-18 14:24 26496 —-a-w- c:\windows\system32\drivers\RimSerial.sys
2009-06-23 22:43 . 2009-06-23 22:43 ——– d—–w- c:\program files\Common Files\Motorola Shared
2009-06-23 22:42 . 2009-06-23 22:42 ——– d—–w- c:\program files\Common Files\PctelEapPeer Authentication
2009-06-23 22:42 . 2009-06-23 22:42 ——– d—–w- C:\Research in Motion
2009-06-23 22:42 . 2009-06-23 22:42 ——– d—–w- c:\program files\Common Files\Research in Motion
2009-06-23 22:42 . 2009-06-23 22:42 ——– d—–w- c:\program files\Sierra Wireless Inc
2009-06-23 22:42 . 2009-06-23 22:42 ——– d—–w- c:\program files\AT&T;
2009-06-23 22:42 . 2009-06-23 22:42 ——– d—–w- c:\progra~2\AT&T;
2009-06-23 22:39 . 2009-06-23 22:39 ——– d—–w- c:\program files\Option
2009-06-22 16:07 . 2009-06-22 16:07 ——– d—–w- c:\users\Apostate\AppData\Local\HP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-20 02:38 . 2009-02-16 13:08 68276 —-a-w- c:\progra~2\nvModes.dat
2009-07-20 02:37 . 2009-03-14 14:30 ——– d—–w- c:\users\Apostate\AppData\Roaming\DNA
2009-07-20 02:37 . 2009-03-14 14:30 ——– d—–w- c:\program files\DNA
2009-07-20 02:35 . 2008-03-18 03:19 12 —-a-w- c:\windows\bthservsdp.dat
2009-07-20 02:06 . 2009-06-11 21:43 1 —-a-w- c:\users\Apostate\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-19 19:55 . 2009-03-14 14:30 ——– d—–w- c:\users\Apostate\AppData\Roaming\BitTorrent
2009-07-16 07:02 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-06-23 23:25 . 2009-06-23 23:25 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motport_01005.Wdf
2009-06-23 23:25 . 2009-06-23 23:25 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-06-23 23:25 . 2009-06-23 23:25 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2009-06-23 23:25 . 2009-06-23 23:25 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2009-06-23 22:56 . 2009-06-23 22:56 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-06-23 21:49 . 2008-07-16 13:47 6944 —-a-w- c:\users\Apostate\AppData\Local\d3d9caps.dat
2009-06-13 12:49 . 2008-03-10 18:15 ——– d—–w- c:\program files\Microsoft Works
2009-06-13 12:40 . 2008-06-02 13:48 89856 —-a-w- c:\users\Apostate\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-11 21:42 . 2009-06-11 21:42 ——– d—–w- c:\users\Apostate\AppData\Roaming\OpenOffice.org
2009-06-11 21:38 . 2009-06-11 21:38 ——– d—–w- c:\program files\JRE
2009-06-11 21:38 . 2009-06-11 21:38 ——– d—–w- c:\program files\OpenOffice.org 3
2009-06-11 21:38 . 2008-06-29 20:00 ——– d—–w- c:\program files\OpenOffice.org 2.4
2009-06-11 21:32 . 2008-06-29 20:11 ——– d—–w- c:\users\Apostate\AppData\Roaming\OpenOffice.org2
2009-06-11 21:15 . 2008-06-29 20:12 1 —-a-w- c:\users\Apostate\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-06-09 01:21 . 2009-06-09 01:21 ——– d—–w- c:\users\Apostate\AppData\Roaming\DivX
2009-06-09 01:20 . 2009-06-09 01:07 ——– d—–w- c:\users\Apostate\AppData\Roaming\PeaZip
2009-06-09 01:19 . 2009-06-09 01:19 ——– d—–w- c:\program files\DivX
2009-06-09 01:19 . 2009-06-09 01:19 ——– d—–w- c:\program files\Common Files\PX Storage Engine
2009-06-09 01:19 . 2009-06-09 01:19 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-06-09 01:07 . 2009-06-09 01:07 ——– d—–w- c:\program files\PeaZip
2009-06-09 00:56 . 2009-06-09 00:48 ——– d—–w- c:\users\Apostate\AppData\Roaming\vlc
2009-06-09 00:47 . 2009-06-09 00:47 ——– d—–w- c:\program files\VideoLAN
2009-06-07 23:12 . 2009-06-07 23:12 ——– d—–w- c:\program files\Microsoft Silverlight
2009-05-22 20:22 . 2008-03-10 18:54 ——– d—–w- c:\progra~2\Hewlett-Packard
2009-05-22 20:22 . 2009-05-22 20:22 ——– d—–w- c:\users\Apostate\AppData\Roaming\Marvell
2009-05-19 18:51 . 2009-05-19 18:51 8464 —-a-w- c:\windows\system32\SpOrder.Dll
2009-05-19 18:51 . 2009-05-19 18:51 75576 —-a-w- c:\windows\Fonts\ClvATT-Light Ital.otf
2009-05-19 18:51 . 2009-05-19 18:51 72744 —-a-w- c:\windows\Fonts\ClvATT-Bold Ital.otf
2009-05-19 18:51 . 2009-05-19 18:51 72592 —-a-w- c:\windows\Fonts\ClvATT-Light.otf
2009-05-19 18:51 . 2009-05-19 18:51 72420 —-a-w- c:\windows\Fonts\ClvATT-Book Ital.otf
2009-05-19 18:51 . 2009-05-19 18:51 72336 —-a-w- c:\windows\Fonts\ClvATT-Bold.otf
2009-05-19 18:51 . 2009-05-19 18:51 719360 —-a-w- c:\windows\system32\bmutil.dll
2009-05-19 18:51 . 2009-05-19 18:51 57888 —-a-w- c:\windows\Fonts\ClvATT-Book.otf
2009-05-19 18:51 . 2009-05-19 18:51 475136 —-a-w- c:\windows\system32\bmnet.dll
2009-05-19 18:51 . 2009-05-19 18:51 18816 —-a-w- c:\windows\system32\drivers\tcpipBM.sys
2009-05-19 18:51 . 2009-05-19 18:51 118784 —-a-w- c:\windows\system32\bmwebcfg.exe
2009-05-19 18:51 . 2009-05-19 18:51 126976 —-a-w- c:\windows\system32\bmdumpd.bin
2009-05-19 18:50 . 2009-05-19 18:50 32408 —-a-w- c:\windows\system32\PCTINDIS5.sys
2009-05-19 18:50 . 2009-05-19 18:50 137752 —-a-w- c:\windows\system32\PCTIN50.dll
2009-05-01 21:02 . 2009-05-01 21:02 90112 —-a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 —-a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 —-a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 —-a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 —-a-w- c:\windows\system32\DivX.dll
2009-04-30 12:37 . 2009-06-13 19:21 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-13 19:21 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-04-23 12:43 . 2009-06-11 21:36 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-11 21:36 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-11 21:36 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-07-10 21:15 . 2008-12-20 16:16 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-24 455968]
"Google Update"="c:\users\Apostate\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-14 321344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-20 468264]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"PSDiagnosticM"="c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-09-04 315392]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2007-11-02 36864]
"hpbdfawep"="c:\program files\HP\Dfawep\bin\hpbdfawep.exe" [2007-04-25 954368]
"PrnStatusMX"="c:\program files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe" [2007-07-13 1077248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-06 177472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AT&T; Communication Manager"="c:\program files\AT&T;\Communication Manager\ATTCM.exe" [2009-05-19 33280]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9EF89A66-9698-4353-959C-C3313B2EC120}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{2FFE2449-05F4-431E-B5AA-DAF630828DF1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{F55BC89E-745A-4208-88C6-B6558614481F}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{05D3FAA0-F2DC-432F-AA2B-6F565814D674}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{FCE21A2C-A02C-4786-A723-919B1FD4DB2F}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{EBD79006-D140-4DD3-8BA5-44078780CFEE}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{0429329E-0464-4D91-A359-809821A0E16F}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B576D741-6854-4188-9EEF-727EC31E27C1}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{77403D5F-6275-4BF9-850C-91F062BD4BCB}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3E86B356-8DF0-4207-A31D-036D1A8C0AE8}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{6C34F732-289D-4582-B087-693B59B91A53}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"TCP Query User{43E4361F-5071-4257-8602-DD2FCB87E2A2}c:\\users\\apostate\\appdata\\local\\temp\\electronicarts_patcher_000.exe"= UDP:c:\users\apostate\appdata\local\temp\electronicarts_patcher_000.exe:electronicarts_patcher_000.exe
"UDP Query User{27B98597-C215-4573-B361-5B030C296ED2}c:\\users\\apostate\\appdata\\local\\temp\\electronicarts_patcher_000.exe"= TCP:c:\users\apostate\appdata\local\temp\electronicarts_patcher_000.exe:electronicarts_patcher_000.exe
"TCP Query User{8C74AE3B-1461-41E1-A94A-889BB4E03493}c:\\users\\apostate\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\fol6msrq\\wotlk_intro_en.avi-downloader[1].exe"= UDP:c:\users\apostate\appdata\local\microsoft\windows\temporary internet files\content.ie5\fol6msrq\wotlk_intro_en.avi-downloader[1].exe:wotlk_intro_en.avi-downloader[1].exe
"UDP Query User{2CB54A51-0AA0-4CC8-B0EB-84D0BB3DD91A}c:\\users\\apostate\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\fol6msrq\\wotlk_intro_en.avi-downloader[1].exe"= TCP:c:\users\apostate\appdata\local\microsoft\windows\temporary internet files\content.ie5\fol6msrq\wotlk_intro_en.avi-downloader[1].exe:wotlk_intro_en.avi-downloader[1].exe
"{F69B73C7-5D26-4CA5-948D-5094DAA54630}"= UDP:c:\world of warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{B31E29F3-EDAE-41CC-AAE6-48E80F258E02}"= TCP:c:\world of warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{E4554F74-6B01-4778-85B2-E7C1ECFAFD26}"= UDP:3724:Blizzard Downloader: 3724
"{096D4FC1-C54D-4736-94E1-6F7D1A6A968B}"= UDP:c:\world of warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{69E88674-7D4B-4A9C-BBB2-CAF169BB31B5}"= TCP:c:\world of warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{04F2880A-11AE-43E0-9014-1DE6F9FF58A6}"= UDP:3724:Blizzard Downloader: 3724
"{AE059500-4042-4620-9444-77F936E59C30}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{D3F12B64-4EA3-4F84-8665-7527A6593EB1}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"TCP Query User{AC783D76-71EA-4FCB-B265-CC5CCCF3175B}c:\\users\\apostate\\appdata\\local\\temp\\blizzard launcher temporary - 2362a290\\launcher.exe"= UDP:c:\users\apostate\appdata\local\temp\blizzard launcher temporary - 2362a290\launcher.exe:launcher.exe
"UDP Query User{2143CFEE-D25F-4C25-890D-C24FDC65B953}c:\\users\\apostate\\appdata\\local\\temp\\blizzard launcher temporary - 2362a290\\launcher.exe"= TCP:c:\users\apostate\appdata\local\temp\blizzard launcher temporary - 2362a290\launcher.exe:launcher.exe
"TCP Query User{5F51CB01-4373-4C9E-BE30-2215D430C4B1}c:\\users\\apostate\\appdata\\local\\temp\\blizzard launcher temporary - 117fa510\\launcher.exe"= UDP:c:\users\apostate\appdata\local\temp\blizzard launcher temporary - 117fa510\launcher.exe:launcher.exe
"UDP Query User{72FB770F-3CF3-4035-894A-5D03984E062A}c:\\users\\apostate\\appdata\\local\\temp\\blizzard launcher temporary - 117fa510\\launcher.exe"= TCP:c:\users\apostate\appdata\local\temp\blizzard launcher temporary - 117fa510\launcher.exe:launcher.exe
"{6EAD62C3-37CA-48BB-8E55-25B8985773B1}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{62E287D2-6456-4018-859F-7D73B3AA1146}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C791888E-07FE-4737-BCB6-7A70CD448076}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{86A59300-9B67-4CC6-8DD5-0DE5108EB268}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{A5D70A43-9CB5-464E-A8BB-EB44FEA0A805}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{A5CB181B-5EE1-47C8-B092-52C45C8539F0}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{B9EC223A-4C88-4D63-B1A6-14D5271027BB}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (TCP-In)
"{E76B3ADE-D1DE-4E69-9CC8-8056E79AD6DF}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (UDP-In)
"TCP Query User{1AFDE757-3FA6-4A28-8CF1-1B9A18D178EA}c:\\program files\\dna\\btdna.exe"= UDP:c:\program files\dna\btdna.exe:DNA
"UDP Query User{30696F3D-870D-40FB-879A-B9642F549A3E}c:\\program files\\dna\\btdna.exe"= TCP:c:\program files\dna\btdna.exe:DNA
"{653B8416-E2D6-4E19-9565-625E8335E772}"= UDP:c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"{2F5B48A0-E4D2-4E51-983B-1BA78C67D1E6}"= TCP:c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"TCP Query User{032D40EA-6865-4658-BC30-F7EA5E3BBAC7}c:\\program files\\turbine\\the lord of the rings online\\lotroclient.exe"= UDP:c:\program files\turbine\the lord of the rings online\lotroclient.exe:lotroclient
"UDP Query User{D4D3DD69-454F-472D-A2AC-73346E63BA77}c:\\program files\\turbine\\the lord of the rings online\\lotroclient.exe"= TCP:c:\program files\turbine\the lord of the rings online\lotroclient.exe:lotroclient
"{C177ABBB-138E-45B9-8B34-11AADEA09AB4}"= UDP:c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{77F006CE-6747-4BC4-8A74-4B375F4C19B4}"= TCP:c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"TCP Query User{9CA85854-57AB-4837-9CAC-00D410960CD1}c:\\program files\\turbine\\the lord of the rings online\\lotroclient.exe"= UDP:c:\program files\turbine\the lord of the rings online\lotroclient.exe:lotroclient
"UDP Query User{5F6F801C-84C4-4DCF-9B04-816D2D30F395}c:\\program files\\turbine\\the lord of the rings online\\lotroclient.exe"= TCP:c:\program files\turbine\the lord of the rings online\lotroclient.exe:lotroclient
"{41D53B82-D641-4910-A533-6E3133347BF6}"= UDP:c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"{34987E9D-D6C0-46BB-84DF-99CDB689DAF1}"= TCP:c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"{761A65E2-F6F4-492C-BAF0-D353477FF905}"= UDP:c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{6E843320-9F3F-40CF-9814-3B5E4F381E65}"= TCP:c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"TCP Query User{9BD7F415-C2A0-48EB-ADE0-D3D4FA5DBDAB}c:\\world of warcraft\\launcher.exe"= UDP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{35FF7EC8-3450-41B5-A4AD-832625A689A7}c:\\world of warcraft\\launcher.exe"= TCP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"{5CAA5113-91CE-4C38-B6A6-F42F8025C2D7}"= UDP:990:LocalSubnet:LocalSubnet|IF={309F5F1B-A092-48A8-808C-D75A07414EDB}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{86A7821C-28D1-4C53-815A-E032E7D7A3BD}"= UDP:c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe:WPSM54G PSUtility
"{A034BB29-27C4-44B9-831D-1DB0260C3BDC}"= TCP:c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe:WPSM54G PSUtility
"{0D5C6043-A5AC-41AC-8A90-2455181288EB}"= UDP:c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe:WPSM54G PSUtility
"{229F1232-2308-4AC7-AAAE-4037A96DAEAE}"= TCP:c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe:WPSM54G PSUtility

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [7/19/2009 6:02 PM 130936]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\System32\drivers\lknuhst.sys [8/16/2008 3:11 PM 13824]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\System32\drivers\lknuhub.sys [8/16/2008 3:11 PM 35840]
S3 ATTRcAppSvc;AT&T; RcAppSvc;c:\program files\AT&T;\Communication Manager\RcAppSvc.exe [5/19/2009 2:57 PM 121344]
S3 CAATT;AT&T; Con App Svc;c:\program files\AT&T;\Communication Manager\ConAppsSvc.exe [5/19/2009 2:57 PM 125440]
S3 LiveTurbineMessageService;Turbine Message Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe [4/3/2009 6:59 PM 255472]
S3 LiveTurbineNetworkService;Turbine Network Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe [4/3/2009 6:59 PM 218608]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [4/8/2009 5:27 PM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [4/8/2009 5:27 PM 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\System32\drivers\motport.sys [4/8/2009 5:27 PM 23680]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/19/2009 6:02 PM 348752]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=81&bd;=Pavilion&pf;=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: bmnet.dll
Trusted Zone: navy.mil
FF - ProfilePath - c:\users\Apostate\AppData\Roaming\Mozilla\Firefox\Profiles\2btyf4cw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\Apostate\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-19 22:36
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3107584610-53593523-1019121096-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5e,cd,8a,48,9b,69,4d,a7,80,73,d5,8c,86,94,8f,3e,45,b7,4f,8a,6b,13,1c,
03,29,44,7e,45,c7,38,4d,4d,5d,36,e2,54,21,17,e0,3c,66,fc,2d,6f,1f,04,88,ec,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(688)
c:\windows\system32\bmnet.dll

- - - - - - - > 'Explorer.exe'(3384)
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\users\Apostate\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Completion time: 2009-07-20 22:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-20 02:44

Pre-Run: 17,720,950,784 bytes free
Post-Run: 17,798,754,304 bytes free

397 — E O F — 2009-07-17 08:57

Attachments:

Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Hi,

You are clean, just some housekeeping to do now.

Please do the following:

P2P - I see you have P2P software BitTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 13 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.

The go to Start > Control Panel > Add/Remove programs
a list of installed programs will populate
Remove the following programs:

Java™ 6 Update 2
Java™ 6 Update 4
Java™ 6 Update 5
Java™ 6 Update 7


(Be sure to leave Java™ 6 Update 14 installed as it is the latest version)

NEXT

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI