This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help! It started with Windows Antivirus Pro...

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

We had a nasty version of Windows Antivirus Pro attack our system yesterday.

We tried to run our Malwarebytes program, but it wouldn't even start. We downloaded another malware program…same problem.

We tried running at least 5 different scans from different places. No luck–the malware stops the scans before they can delete the trojans. My dh went in and manually deleted Windows Antivirus Pro where ever he could find it. That slowed down the pop ups.

Last night we got smart and ran our antivirus (AVG) in smart mode and set it to delete trojans as it found them. The scan still stopped before it was done, but today we have not had one pop up from WAP.

However…we are still have a great deal of problems with our computer and internet. Very slow, shutting down programs, and receiving error codes like this one:

Microsoft Visual C++Runtime Library
Program: C:\WINDOWS\explorer.exe
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.

Oh…and Malwarebytes still won't open. :pullhair:

Soooo…I'm assuming that we still have the nasty running around in our system. My friend said this was the place to get help–so here I am. :notworthy:


Our operating system is Windows XP, we use the latest version of Firefox for our browser (my dh occasionally uses Explorer, but I'm not sure which version), and we use the free version of AVG for antivirus protection.







Thank you for any help you can offer!
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay, but I will do my best to keep it as short as possible.

I will be back to you shortly with instructions. :)
New message tonight: SVChost.exe - Application Error The instruction at "0x71aa1704" referenced memory at "0x71aa1704". The memory could not be "written". Click on OK to terminate the program. Click on CANCEL to debug the program. Thanks for taking the time to help us.
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

1) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

2) GMER
Please download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Rename GMER.exe to REMG.exe
  • Double click REMG.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and put it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


3) What You Will Need To Post:
  • DDS logs
  • GMER log
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:42:25.32 on Wed 07/29/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1236 [GMT -7:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\sopidkc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\My Computer\Desktop\games\Steam\Steam.exe
C:\WINDOWS\system32\wiwow64.exe
C:\old harddrive (G)\old program files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\My Computer\Desktop\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uWindows: load=c:\windows\system32\msobksri.exe
uWindows: run=c:\windows\system32\msqwc.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Mininova-Vuze Toolbar: {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - c:\program files\mininova-vuze\tbMin0.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Mininova-Vuze Toolbar: {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - c:\program files\mininova-vuze\tbMin0.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [IntelAudioStudio] "c:\program files\intel audio studio\IntelAudioStudio.exe" TRAY
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop elements 5.0\apdproxy.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [MyWebSearch Plugin] rundll32 c:\progra~1\mywebs~1\bar\1.bin\M3PLUGIN.DLL,UPF
mRun: [My Web Search Bar] rundll32 c:\progra~1\mywebs~1\bar\1.bin\MWSBAR.DLL,S
mRun: [SetDefPrt] c:\program files\brother\brmfl04a\BrStDvPt.exe
mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [MSxmlHpr] RUNDLL32.EXE c:\windows\system32\msxm192z.dll,w
mRun: [Jgovixejower] rundll32.exe "c:\windows\umeqinoqoyejamiy.dll",e
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mExplorerRun: [exec] c:\windows\system32\mseib.exe
StartupFolder: c:\documents and settings\my computer\start menu\programs\startup\PowerReg Scheduler V3.exe
StartupFolder: c:\documents and settings\my computer\start menu\programs\startup\PowerReg Scheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imagem~1.lnk - c:\program files\pixela\imagemixer 3 se for sd\CameraMonitor.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\status~1.lnk - c:\program files\brother\brmfcmon\BrMfcWnd.exe
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {722FE9B2-6895-42D9-9984-F4CB26616023} - {722FE9B2-6895-42D9-9984-F4CB26616023} - c:\program files\cosmi\perfect pdf creator\pdfshell.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\hesahesu.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 nwprovau
LSA: Notification Packages = scecli c:\windows\system32\hesahesu.dll intcmob.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mycomp~1\applic~1\mozilla\firefox\profiles\uor6kyr0.default\
FF - prefs.js: browser.startup.homepage - hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\my computer\application data\mozilla\firefox\profiles\uor6kyr0.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\old harddrive (g)\old program files\mozilla firefox\plugins\NPcol305.dll
FF - plugin: c:\old harddrive (g)\old program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\old harddrive (g)\old program files\mozilla firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\program files\virtools\3d life player\npvirtools.dll
FF - HiddenExtension: XUL Cache: {AF00CE25-C84A-4B91-95A8-107F77DCF9EE} - c:\documents and settings\my computer\local settings\application data\{AF00CE25-C84A-4B91-95A8-107F77DCF9EE}
FF - HiddenExtension: Java Console: No Registry Reference - c:\old harddrive (g)\old program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\old harddrive (g)\old program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\old harddrive (g)\old program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-9-19 335752]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-9-19 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-9-19 108552]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-9-19 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-9-19 298776]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 msncache;msncache;c:\windows\system32\svchost.exe -k netsvcs [2008-9-19 14336]
R2 sopidkc;sopidkc Service;c:\windows\system32\sopidkc.exe [2004-8-10 96768]
S2 Ias;Network Security;c:\windows\system32\svchost.exe -k netsvcs [2008-9-19 14336]
S2 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe –> c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe [?]
S3 gAGP440p;gAGP440p;\??\c:\docume~1\mycomp~1\locals~1\temp\gagp440p.sys –> c:\docume~1\mycomp~1\locals~1\temp\gAGP440p.sys [?]
S3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\drivers\MOSUMAC.SYS [2008-9-19 40448]
S3 WPEServ;soft Xpansion Print2Document;c:\program files\common files\wpe\wpeserv.exe [2008-9-19 323584]

=============== Created Last 30 ================

2009-07-29 00:03 3,293 a——- c:\windows\afiyacik.dll
2009-07-28 23:50 3,293 a——- c:\windows\ohajijohapuh.dll
2009-07-28 23:30 3,301 a——- c:\windows\owiquqis.dll
2009-07-28 23:10 3,285 a——- c:\windows\axipilid.dll
2009-07-28 22:20 3,269 a——- c:\windows\iwekudat.dll
2009-07-28 21:36 3,309 a——- c:\windows\ogadopumamajux.dll
2009-07-28 21:20 3,285 a——- c:\windows\oridojodoh.dll
2009-07-28 20:56 3,261 a——- c:\windows\ihofiwupuc.dll
2009-07-28 20:26 3,285 a——- c:\windows\ixibizebuf.dll
2009-07-28 17:47 3,269 a——- c:\windows\ededibotaxar.dll
2009-07-28 17:37 3,277 a——- c:\windows\uqugafekute.dll
2009-07-28 16:56 3,285 a——- c:\windows\otamuyosamav.dll
2009-07-28 16:06 3,301 a——- c:\windows\abewaruyumogavim.dll
2009-07-28 15:22 3,261 a——- c:\windows\imecuxiq.dll
2009-07-28 14:43 3,293 a——- c:\windows\awufuwejatazaleb.dll
2009-07-28 12:37 3,293 a——- c:\windows\edibufisawanulam.dll
2009-07-28 11:33 3,269 a——- c:\windows\exovadazaderirif.dll
2009-07-28 09:27 3,285 a——- c:\windows\upisavadebib.dll
2009-07-28 08:37 3,293 a——- c:\windows\obaferab.dll
2009-07-28 00:01 3,309 a——- c:\windows\ojozehobiq.dll
2009-07-27 23:43 3,269 a——- c:\windows\ahobimon.dll
2009-07-27 22:52 3,277 a——- c:\windows\ohibopitucigenog.dll
2009-07-27 22:29 –d—– C:\_OTM
2009-07-27 22:16 3,277 a——- c:\windows\exacikotadoq.dll
2009-07-27 21:55 3,261 a——- c:\windows\ocubicitaqun.dll
2009-07-27 20:04 3,285 a——- c:\windows\esumobelisuz.dll
2009-07-27 18:57 102,664 a——- c:\windows\system32\drivers\tmcomm.sys
2009-07-27 18:55 –d—– c:\documents and settings\my computer\.housecall6.6
2009-07-27 18:52 3,301 a——- c:\windows\exeqobacagayus.dll
2009-07-27 18:37 3,293 a——- c:\windows\uwohinal.dll
2009-07-27 18:32 92,208 a——- c:\windows\system32\Wing.dll
2009-07-27 18:32 12,800 a——- c:\windows\system\Wing32.dll
2009-07-27 18:31 –d—– c:\program files\Enigma Software Group
2009-07-27 18:27 3,269 a——- c:\windows\ojibexuyiru.dll
2009-07-27 17:56 3,293 a——- c:\windows\uforatiqefa.dll
2009-07-27 17:40 4,224 a——- c:\windows\system32\tmp.reg
2009-07-27 17:22 3,269 a——- c:\windows\inugohewat.dll
2009-07-27 16:41 552 a——- c:\windows\system32\d3d8caps.dat
2009-07-27 16:28 –d—– C:\VundoFix Backups
2009-07-27 16:10 3,293 a——- c:\windows\izabevaxitig.dll
2009-07-27 15:50 3,285 a——- c:\windows\ufugohew.dll
2009-07-27 15:21 3,285 a——- c:\windows\eraducenafidaco.dll
2009-07-27 14:39 4 a——- c:\windows\system32\bincd32.dat
2009-07-27 14:22 120 a——- c:\windows\Ctuwihuvuwox.dat
2009-07-27 14:18 31,232 a——- c:\windows\system32\wingenocx.dll
2009-07-27 14:16 1,382 a——- c:\windows\system32\onhelp.htm
2009-07-27 14:03 257,536 a——- c:\windows\system32\resdll.dll
2009-07-27 14:03 –d—– c:\docume~1\alluse~1\applic~1\14357344
2009-07-27 14:03 134,656 a——- c:\windows\system32\mobsyn.exe
2009-07-27 14:03 10 a——- c:\windows\system32\comsa32.sys
2009-07-27 14:03 9 a——- c:\windows\system32\bennuar.old
2009-07-27 14:03 94 a——- c:\windows\system32\sonhelp.htm
2009-07-27 14:03 64 a——- c:\windows\ppp4.dat
2009-07-27 14:03 36 a——- c:\windows\system32\sysnet.dat
2009-07-27 14:03 3 a——- c:\windows\ppp3.dat
2009-07-27 14:03 45,056 a——- C:\uynrr.exe
2009-07-27 14:02 53,248 a——- C:\uigxpmv.exe
2009-07-27 14:02 2 a——- C:\411558708
2009-07-27 06:44 10,240 a——- c:\windows\codec.exe
2009-07-26 17:48 –d—– c:\docume~1\mycomp~1\applic~1\Jane s Hotel
2009-07-26 17:48 –d—– c:\program files\Realore
2009-07-23 17:30 1,409 a——- c:\windows\system32\tmpD5E92.FOT
2009-07-23 17:30 1,409 a——- c:\windows\system32\tmp91F92.FOT
2009-07-23 17:30 1,409 a——- c:\windows\system32\tmp84F92.FOT
2009-07-17 00:14 –d—– c:\program files\MSECache
2009-07-01 22:56 –d—– c:\program files\XCOM Terror from the Deep
2009-07-01 22:55 51 a——- C:\AUTOEXEC.CW
2009-07-01 22:55 –d—– C:\CWE
2009-07-01 22:45 –d—– c:\docume~1\mycomp~1\applic~1\GetRightToGo
2009-06-29 10:52 297 a——- c:\windows\EReg072.dat
2009-06-29 10:51 –d—– c:\program files\Firaxis Games

==================== Find3M ====================

2009-07-28 21:50 4 —-h— c:\windows\fonts\mlog
2009-07-26 09:02 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-07-13 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-01 22:20 43,520 a——- c:\windows\system32\CmdLineExt03.dll
2009-06-16 07:36 119,808 ——– c:\windows\system32\t2embed.dll
2009-06-16 07:36 81,920 ——– c:\windows\system32\fontsub.dll
2009-06-03 12:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-19 10:03 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-05-07 08:32 345,600 ——– c:\windows\system32\localspl.dll

============= FINISH: 0:43:38.90 ===============







UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 9/19/2008 11:03:06 AM
System Uptime: 7/28/2009 9:23:22 PM (3 hours ago)

Motherboard: Intel Corporation | | D945GCZ
Processor: Intel® Pentium® D CPU 2.80GHz | | 2799/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 224 GiB total, 155.763 GiB free.
E: is CDROM (CDFS)
F: is CDROM ()
G: is Removable
I: is Removable
J: is Removable
K: is Removable
L: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\198C41D902700
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\198C41D902700
Service: NIC1394

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Ethernet Controller
Device ID: PCI\VEN_8086&DEV_27DC&SUBSYS_5049107B&REV_01\4&1E46F438&0&40F0
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_8086&DEV_27DC&SUBSYS_5049107B&REV_01\4&1E46F438&0&40F0
Service:

==== System Restore Points ===================

RP255: 7/27/2009 2:03:10 PM - System Checkpoint
RP256: 7/27/2009 2:03:10 PM - System Checkpoint
RP257: 7/27/2009 2:03:10 PM - System Checkpoint
RP258: 7/27/2009 2:03:10 PM - System Checkpoint
RP259: 7/27/2009 2:03:10 PM - System Checkpoint
RP260: 7/27/2009 2:03:10 PM - System Checkpoint
RP261: 7/27/2009 2:03:10 PM - System Checkpoint
RP262: 7/27/2009 2:03:10 PM - System Checkpoint
RP263: 7/27/2009 2:03:10 PM - System Checkpoint
RP264: 7/27/2009 2:03:11 PM - System Checkpoint
RP265: 7/27/2009 2:03:11 PM - System Checkpoint
RP266: 7/27/2009 2:03:11 PM - System Checkpoint
RP267: 7/27/2009 2:03:11 PM - System Checkpoint
RP268: 7/27/2009 2:03:11 PM - System Checkpoint
RP269: 7/27/2009 2:03:11 PM - Software Distribution Service 3.0
RP270: 7/27/2009 2:03:11 PM - System Checkpoint
RP271: 7/27/2009 2:03:11 PM - System Checkpoint
RP272: 7/27/2009 2:03:12 PM - System Checkpoint
RP273: 7/27/2009 2:03:12 PM - System Checkpoint
RP274: 7/27/2009 2:03:12 PM - System Checkpoint
RP275: 7/27/2009 2:03:12 PM - System Checkpoint
RP276: 7/27/2009 2:03:12 PM - Avg8 Update
RP277: 7/27/2009 2:03:12 PM - Avg8 Update
RP278: 7/27/2009 2:03:12 PM - System Checkpoint
RP279: 7/27/2009 2:03:13 PM - System Checkpoint
RP280: 7/27/2009 2:03:13 PM - System Checkpoint
RP281: 7/27/2009 2:03:13 PM - System Checkpoint
RP282: 7/27/2009 2:03:13 PM - System Checkpoint
RP283: 7/27/2009 2:03:13 PM - System Checkpoint
RP284: 7/27/2009 2:03:13 PM - System Checkpoint
RP285: 7/27/2009 2:03:13 PM - System Checkpoint
RP286: 7/27/2009 2:03:13 PM - System Checkpoint
RP287: 7/27/2009 2:03:14 PM - System Checkpoint
RP288: 7/27/2009 2:03:14 PM - System Checkpoint
RP289: 7/27/2009 2:03:14 PM - Installed ImageMixer 3 SE for SD
RP290: 7/27/2009 2:03:14 PM - Installed Windows Media Player 10
RP291: 7/27/2009 2:03:14 PM - Software Distribution Service 3.0
RP292: 7/27/2009 2:03:14 PM - Installed ImageMixer 3 SE for SD
RP293: 7/27/2009 2:03:14 PM - Installed ImageMixer 3 SE for SD
RP294: 7/27/2009 2:03:15 PM - System Checkpoint
RP295: 7/27/2009 2:03:15 PM - Software Distribution Service 3.0
RP296: 7/27/2009 2:03:15 PM - System Checkpoint
RP297: 7/27/2009 2:03:15 PM - System Checkpoint
RP298: 7/27/2009 2:03:15 PM - System Checkpoint
RP299: 7/27/2009 2:03:15 PM - System Checkpoint
RP300: 7/27/2009 2:03:15 PM - Installed Windows NLSDownlevelMapping.
RP301: 7/27/2009 2:03:16 PM - Installed Windows IDNMitigationAPIs.
RP302: 7/27/2009 2:03:16 PM - Installed Windows Internet Explorer 7.
RP303: 7/27/2009 2:03:16 PM - Software Distribution Service 3.0
RP304: 7/27/2009 2:03:16 PM - Installed Windows NLSDownlevelMapping.
RP305: 7/27/2009 2:03:16 PM - Installed Windows IDNMitigationAPIs.
RP306: 7/27/2009 2:03:17 PM - Installed Windows Internet Explorer 7.
RP307: 7/27/2009 2:03:17 PM - Installed Windows NLSDownlevelMapping.
RP308: 7/27/2009 2:03:17 PM - Software Distribution Service 3.0
RP309: 7/27/2009 2:03:17 PM - Software Distribution Service 3.0
RP310: 7/27/2009 2:03:17 PM - System Checkpoint
RP311: 7/27/2009 2:03:17 PM - System Checkpoint
RP312: 7/27/2009 2:03:17 PM - System Checkpoint
RP313: 7/27/2009 2:03:18 PM - Software Distribution Service 3.0
RP314: 7/27/2009 2:03:18 PM - Avg8 Update
RP315: 7/27/2009 2:03:18 PM - Avg8 Update
RP316: 7/27/2009 2:03:18 PM - System Checkpoint
RP317: 7/27/2009 2:03:18 PM - System Checkpoint
RP318: 7/27/2009 2:03:18 PM - System Checkpoint
RP319: 7/27/2009 2:03:19 PM - Configured Peachtree Accounting 2009
RP320: 7/27/2009 2:03:19 PM - System Checkpoint
RP321: 7/27/2009 2:03:19 PM - System Checkpoint
RP322: 7/27/2009 2:03:19 PM - Avg8 Update
RP323: 7/27/2009 2:03:19 PM - Avg8 Update
RP324: 7/27/2009 2:03:19 PM - System Checkpoint
RP325: 7/27/2009 2:03:20 PM - System Checkpoint
RP326: 7/27/2009 2:03:20 PM - System Checkpoint
RP327: 7/27/2009 2:03:20 PM - System Checkpoint
RP328: 7/27/2009 2:03:20 PM - System Checkpoint
RP329: 7/27/2009 2:03:21 PM - System Checkpoint
RP330: 7/27/2009 2:03:21 PM - System Checkpoint
RP331: 7/27/2009 2:03:21 PM - System Checkpoint
RP332: 7/27/2009 2:03:21 PM - Software Distribution Service 3.0
RP333: 7/27/2009 2:03:24 PM - Software Distribution Service 3.0
RP334: 7/27/2009 2:03:25 PM - Software Distribution Service 3.0
RP335: 7/27/2009 2:03:25 PM - System Checkpoint
RP336: 7/27/2009 2:03:26 PM - Installed Sid Meier's Alpha Centauri 2000/XP Compatibility Updat
RP337: 7/27/2009 2:03:26 PM - Removed Sid Meier's Alpha Centauri 2000/XP Compatibility Update
RP338: 7/27/2009 2:03:26 PM - Avg8 Update
RP339: 7/27/2009 2:03:26 PM - System Checkpoint
RP340: 7/27/2009 2:03:26 PM - System Checkpoint
RP341: 7/27/2009 2:03:26 PM - System Checkpoint
RP342: 7/27/2009 2:03:26 PM - System Checkpoint
RP343: 7/27/2009 2:03:27 PM - System Checkpoint
RP344: 7/27/2009 2:03:27 PM - System Checkpoint
RP345: 7/27/2009 2:03:27 PM - Installed Microsoft Works 6-9 Converter
RP346: 7/27/2009 2:03:27 PM - Software Distribution Service 3.0
RP347: 7/27/2009 2:03:27 PM - System Checkpoint
RP348: 7/27/2009 2:03:27 PM - System Checkpoint
RP349: 7/27/2009 2:03:27 PM - System Checkpoint
RP350: 7/27/2009 2:03:27 PM - Installed InstallShield Restore Point
RP351: 7/27/2009 2:03:28 PM - System Checkpoint
RP352: 7/27/2009 2:03:28 PM - System Checkpoint
RP353: 7/27/2009 2:03:28 PM - Software Distribution Service 3.0
RP354: 7/27/2009 2:03:28 PM - System Checkpoint
RP355: 7/27/2009 2:03:28 PM - Software Distribution Service 3.0
RP356: 7/27/2009 2:03:28 PM - Installed Compatibility Pack for the 2007 Office system
RP357: 7/27/2009 2:03:28 PM - System Checkpoint
RP358: 7/27/2009 2:03:29 PM - System Checkpoint
RP359: 7/27/2009 2:03:29 PM - System Checkpoint
RP360: 7/27/2009 2:03:29 PM - System Checkpoint
RP361: 7/27/2009 2:03:29 PM - Software Distribution Service 3.0
RP362: 7/27/2009 2:03:29 PM - System Checkpoint
RP363: 7/27/2009 2:03:29 PM - System Checkpoint
RP364: 7/27/2009 2:03:29 PM - System Checkpoint
RP365: 7/27/2009 2:03:29 PM - Avg8 Update
RP366: 7/27/2009 2:03:30 PM - Avg8 Update
RP367: 7/27/2009 2:03:30 PM - System Checkpoint
RP368: 7/27/2009 10:35:38 PM - Software Distribution Service 3.0

==== Installed Programs ======================

3DVIA player 4.1
7-Zip 4.57
Acrobat.com
Ad-Aware
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 2.1
Adobe Photoshop Elements 5.0
Adobe Reader 7.0.8
Adobe Shockwave Player 11.5
Age of Mythology
Age of Mythology - The Titans Expansion
Apple Mobile Device Support
Apple Software Update
AVG Free 8.5
Bonjour
Brother MFL-Pro Suite
BVHE-Beauty and the Beast Magical Ballroom
Canon Camera Access Library
Canon Camera Support Core Library
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture DC
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Catz (remove only)
Cinderella's Dollhouse
Civ II : Test Of Time
Civilization II Multiplayer Gold Edition
Civilization III
Civilization III Play the World
Colossus
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
Critical Update for Windows Media Player 11 (KB959772)
Crystal Reports 2008 Runtime
dBpoweramp Music Converter
DivX Codec
DivX Version Checker
Dreamship Tales
Easy Bake Kitchen
Empires in Arms
Encyclopaedia Britannica Homework Essentials Plus 2004 CD-ROM
Family Restaurant
GamesBar [removed]
GameSpy Comrade
Hearts of Iron
High Definition Audio Driver Package - KB888111
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hoyle Board Games 2005
Hoyle Card Games 2005
Hoyle Puzzle Games 2005
ImageMixer 3 SE for SD
Intel Audio Studio
Intel® Graphics Media Accelerator Driver
iTunes
Jane's Hotel
Java™ 6 Update 13
Jimmy Neutron Invention Revenge
JumpStart Numbers
Kitty Luv v1.8
Malwarebytes' Anti-Malware
Mango Plumo's Earth Adventure
Math Attack
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 6-9 Converter
Mininova-Vuze Toolbar
Mozilla Firefox (3.5.1)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
MSXML4 Parser
Nero 7 Essentials
neroxml
Netscape (7.1)
OpenOffice.org Installer 1.0
PaperPort
Perfect PDF Creator
Pony Luv v1.5
PowerDVD
Puppy Luv
QuickTime
Reader Rabbit Learn To Read With Phonics
Rhapsody
Rhapsody Player Engine
Rollercoaster Rush
Sanctum Revolutions
Scooby-Doo™, Case File #2 The Scary Stone Dragon
Scooby-Doo™, Jinx At The Sphinx™
Scooby-Doo™, Showdown in Ghost Town™
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
Sid Meier's Alpha Centauri
Sid Meier's Alpha Centauri 2000/XP Compatibility Update
Sid Meier's Civilization 4 - Beyond the Sword
Sid Meier's Civilization 4 Gold
SigmaTel Audio
Sonic Encoders
SpongeBob SquarePants 3-D
SpongeBob SquarePants Obstacle Odyssey
SpongeBob SquarePants Obstacle Odyssey 2
Tax Forms Helper 2008 8.5
Temple of Elemental Evil
The Game Of Life
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 2 for Windows XP Media Center Edition 2005
USB-Ethernet Adapter Device
Viewpoint Media Player (Remove Only)
Vuze
Walmart MP3 Music Downloads
Warlords Battlecry II
Warlords Battlecry III
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Media Center Edition 2005 KB925766
Windows XP Service Pack 3
Wizard101
World Dance
XCOM: Terror from the Deep (remove only)
Zatikon

==== Event Viewer Messages From Past Week ========

7/29/2009 12:42:27 AM, error: Service Control Manager [7016] - The BrSplService service has reported an invalid current state 0.
7/27/2009 9:35:14 PM, error: Service Control Manager [7000] - The AntipyPro_12 service failed to start due to the following error: The system cannot find the file specified.
7/27/2009 4:53:11 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
7/27/2009 4:27:51 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
7/27/2009 4:27:20 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
7/27/2009 4:27:20 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 4:27:20 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 4:27:20 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 4:27:20 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 4:27:20 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 4:27:20 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 4:26:53 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
7/27/2009 4:26:45 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
7/27/2009 3:34:30 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 3:27:32 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
7/27/2009 3:10:35 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the sopidkc Service service to connect.
7/27/2009 3:10:35 PM, error: Service Control Manager [7000] - The sopidkc Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/27/2009 3:00:43 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect.
7/27/2009 3:00:43 PM, error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/27/2009 2:59:43 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 21 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:58:43 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 20 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:57:42 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 19 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:56:42 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 18 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:55:41 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 17 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:54:41 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 16 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:53:40 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 15 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:52:40 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 14 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:51:39 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 13 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:50:39 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 12 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:49:38 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 11 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:48:38 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 10 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:47:37 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 9 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:46:37 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 8 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:45:36 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 7 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:44:36 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 6 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:43:41 PM, error: Service Control Manager [7034] - The AntipyPro_12 service terminated unexpectedly. It has done this 4 time(s).
7/27/2009 2:43:35 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 5 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:42:35 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:42:15 PM, error: Service Control Manager [7034] - The AntipyPro_12 service terminated unexpectedly. It has done this 3 time(s).
7/27/2009 2:42:00 PM, error: Service Control Manager [7034] - The AntipyPro_12 service terminated unexpectedly. It has done this 2 time(s).
7/27/2009 2:41:34 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:40:58 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Media Center Receiver Service service to connect.
7/27/2009 2:40:43 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Media Center Extender Service service to connect.
7/27/2009 2:40:43 PM, error: Service Control Manager [7000] - The Media Center Extender Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/27/2009 2:40:36 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 12 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:34 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:40:30 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 11 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:25 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 10 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7034] - The NMIndexingService service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:40:19 PM, error: Service Control Manager [7034] - The COM+ System Application service terminated unexpectedly. It has done this 3 time(s).
7/27/2009 2:40:19 PM, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:40:19 PM, error: Service Control Manager [7034] - The AVG8 E-mail Scanner service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 9 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 8 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 7 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 6 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 5 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
7/27/2009 2:40:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
7/27/2009 2:40:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG8 WatchDog service to connect.
7/27/2009 2:40:19 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/27/2009 2:40:19 PM, error: Service Control Manager [7000] - The AVG8 WatchDog service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/27/2009 2:37:41 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the AVG8 WatchDog service, but this action failed with the following error: An instance of the service is already running.
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The sopidkc Service service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The PrismXL service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The Fax service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The BrSplService service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The Brother Popup Suspend service for Resource manager service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The AntipyPro_12 service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7034] - The Adobe Active File Monitor V5 service terminated unexpectedly. It has done this 1 time(s).
7/27/2009 2:37:38 PM, error: Service Control Manager [7031] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:37:38 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
7/27/2009 2:37:38 PM, error: Service Control Manager [7031] - The AVG8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
7/27/2009 2:37:38 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/27/2009 2:37:38 PM, error: Service Control Manager [7022] - The Fax service hung on starting.
7/27/2009 2:34:30 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Canon Camera Access Library 8 service to connect.
7/27/2009 2:34:30 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG8 E-mail Scanner service to connect.
7/27/2009 2:34:30 PM, error: Service Control Manager [7000] - The Canon Camera Access Library 8 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/27/2009 2:34:30 PM, error: Service Control Manager [7000] - The AVG8 E-mail Scanner service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/27/2009 2:31:13 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
7/25/2009 7:14:18 AM, error: Service Control Manager [7000] - The My Web Search Service service failed to start due to the following error: The system cannot find the path specified.
7/22/2009 6:00:39 PM, error: Service Control Manager [7000] - The MCSTRM service failed to start due to the following error: The system cannot find the file specified.

==== End Of File ===========================



GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-29 00:55:44
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

Code 8A6B7E78 ZwEnumerateKey
Code 8A6B7A30 ZwFlushInstructionCache
Code 8A6B6306 IofCallDriver
Code 8A6B6E36 IofCompleteRequest
Code 8A5EA00D ZwSaveKey
Code 8A6827FD ZwSaveKeyEx

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-
1) mbr.exe
Please download MBR.EXE by GMER. Save it to your desktop.
  • Double click on mbr.exe to execute.
    If you recieve the "Publisher could not be verified" security warning, please press Run.
  • A black CMD prompt window will open and close quickly, this is expected and normal.
    Upon completion, a file will be created on your desktop named "mbr.log"
  • Double click the "mbr.log" file and Notepad should open.
  • Copy and paste the contents of the files mbr.log in your next reply.

2) What You Will Need To Post:
  • mbr.log contents
Evidently in the course of the day today…we got a update from Windows. The internet is running faster (still very slow), but now the computer is freezing and it takes anywhere between 3 and 5 reboots to even get to the desktop. Do we need to run another log because of the update? :smack:
There are no more major updates for your system, so it may just be a smaller update conflicting with the malware that you have. We'll try and get you cleaned up first, then deal with that issue if it's still around.

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.
You must rename it before saving it. Save it as Combo-Fix.exe.

[external image: Posted Image]

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on Combo-Fix.exe & follow the prompts. Close all browsers/windows first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
The first link doesn't allow me to re-name the download or save it to desktop. The second link leads me to a spyware forum in Spanish. ????
LOL…I was just coming back to say that when we tried to run as Combo-Fix.exe a pop came on saying that we couldn't rename ComboFix to Combo-Fix. I then tried to run the link you just provided and it said we were not authorized users.
:P

Delete the current copy you have (Right click->Delete), download ComboFix again, but save it as CombFix.exe on your desktop. Hopefully this will get us there, otherwise we'll just move on to something else.
ComboFix 09-07-29.04 - My Computer 07/30/2009 22:50.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1594 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\CombFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-906280836-2277474917-2120796318-500
C:\uigxpmv.exe
c:\windows\codec.exe
c:\windows\FONTS\cooecp.tlb
c:\windows\FONTS\logcde.dll
c:\windows\Fonts\mlog
c:\windows\Fonts\services.exe
c:\windows\FONTS\windef.dll
c:\windows\FONTS\windef.Log
c:\windows\FONTS\winpaged.ocx
c:\windows\Install.txt
c:\windows\intcmob.dll
c:\windows\kb913800.exe
c:\windows\system32\6to4v32.dll
c:\windows\system32\certstore.dat
c:\windows\system32\comsa32.sys
c:\windows\system32\drivers\UACdqlpbovoyb.sys
c:\windows\system32\FInstall.sys
c:\windows\system32\Iasv32.dll
c:\windows\system32\mobsyn.exe
c:\windows\system32\msassnz.exe
c:\windows\system32\msbtym.exe
c:\windows\system32\mscdiy.exe
c:\windows\system32\mscdtrwx.exe
c:\windows\system32\mscdymv.exe
c:\windows\system32\mscew.exe
c:\windows\system32\mscfu.exe
c:\windows\system32\mscgra.exe
c:\windows\system32\mscgwc.exe
c:\windows\system32\mschl.exe
c:\windows\system32\mscino.exe
c:\windows\system32\mscit.exe
c:\windows\system32\mscjm.exe
c:\windows\system32\mscmhyen.exe
c:\windows\system32\mscmsqx.exe
c:\windows\system32\mscoc.exe
c:\windows\system32\mscoihqz.exe
c:\windows\system32\mscojdco.exe
c:\windows\system32\mscoxtqc.exe
c:\windows\system32\mscpeh.exe
c:\windows\system32\mscpntuf.exe
c:\windows\system32\mscpz.exe
c:\windows\system32\mscqbkox.exe
c:\windows\system32\mscrv.exe
c:\windows\system32\mscslt.exe
c:\windows\system32\mscsonuj.exe
c:\windows\system32\msctavd.exe
c:\windows\system32\msctcz.exe
c:\windows\system32\msctixl.exe
c:\windows\system32\mscuc.exe
c:\windows\system32\mscvgn.exe
c:\windows\system32\mscwelok.exe
c:\windows\system32\mscwm.exe
c:\windows\system32\mscxlnx.exe
c:\windows\system32\mscymjfk.exe
c:\windows\system32\msczol.exe
c:\windows\system32\msczyr.exe
c:\windows\system32\msdanf.exe
c:\windows\system32\msddpiv.exe
c:\windows\system32\msdep.exe
c:\windows\system32\msdgbbc.exe
c:\windows\system32\msdgf.exe
c:\windows\system32\msdgvhu.exe
c:\windows\system32\msdifsvv.exe
c:\windows\system32\msdjapi.exe
c:\windows\system32\msdjido.exe
c:\windows\system32\msdkpge.exe
c:\windows\system32\msdkz.exe
c:\windows\system32\msdltte.exe
c:\windows\system32\msdlz.exe
c:\windows\system32\msdnn.exe
c:\windows\system32\msdnqy.exe
c:\windows\system32\msdowhlk.exe
c:\windows\system32\msdsavc.exe
c:\windows\system32\msdtfbz.exe
c:\windows\system32\msduhfzj.exe
c:\windows\system32\msdwuv.exe
c:\windows\system32\msdxapzp.exe
c:\windows\system32\msdxyfs.exe
c:\windows\system32\msdznlw.exe
c:\windows\system32\mseasxv.exe
c:\windows\system32\mseaud.exe
c:\windows\system32\msebpg.exe
c:\windows\system32\msecwhq.exe
c:\windows\system32\mseddg.exe
c:\windows\system32\msefjefl.exe
c:\windows\system32\msefjh.exe
c:\windows\system32\msegj.exe
c:\windows\system32\msegt.exe
c:\windows\system32\msehvccs.exe
c:\windows\system32\mseib.exe
c:\windows\system32\msejw.exe
c:\windows\system32\msejyab.exe
c:\windows\system32\msejyqdy.exe
c:\windows\system32\msekx.exe
c:\windows\system32\msekzn.exe
c:\windows\system32\mselecb.exe
c:\windows\system32\mselp.exe
c:\windows\system32\mselu.exe
c:\windows\system32\msembsh.exe
c:\windows\system32\msemmgn.exe
c:\windows\system32\msenrxn.exe
c:\windows\system32\msenwlsc.exe
c:\windows\system32\mseozh.exe
c:\windows\system32\msepu.exe
c:\windows\system32\mserdn.exe
c:\windows\system32\mserf.exe
c:\windows\system32\mserwpdg.exe
c:\windows\system32\mseugo.exe
c:\windows\system32\mseuh.exe
c:\windows\system32\mseunemx.exe
c:\windows\system32\msevflkk.exe
c:\windows\system32\msevgdkp.exe
c:\windows\system32\msevrpty.exe
c:\windows\system32\msevxnms.exe
c:\windows\system32\msewkygl.exe
c:\windows\system32\msexugat.exe
c:\windows\system32\msezfg.exe
c:\windows\system32\msfaqiep.exe
c:\windows\system32\msfbh.exe
c:\windows\system32\msfblqg.exe
c:\windows\system32\msfccugy.exe
c:\windows\system32\msfcf.exe
c:\windows\system32\msfcg.exe
c:\windows\system32\msfcxr.exe
c:\windows\system32\msfdu.exe
c:\windows\system32\msfeddlj.exe
c:\windows\system32\msfej.exe
c:\windows\system32\msfgbq.exe
c:\windows\system32\msfgesrd.exe
c:\windows\system32\msfgxqo.exe
c:\windows\system32\msfhf.exe
c:\windows\system32\msfhq.exe
c:\windows\system32\msfhz.exe
c:\windows\system32\msfin.exe
c:\windows\system32\msfipab.exe
c:\windows\system32\msfjb.exe
c:\windows\system32\msfjch.exe
c:\windows\system32\msfjuh.exe
c:\windows\system32\msfmss.exe
c:\windows\system32\msfmw.exe
c:\windows\system32\msfne.exe
c:\windows\system32\msfnoe.exe
c:\windows\system32\msfouh.exe
c:\windows\system32\msfpgkmw.exe
c:\windows\system32\msfqsd.exe
c:\windows\system32\msfrkpug.exe
c:\windows\system32\msfsktr.exe
c:\windows\system32\msfuab.exe
c:\windows\system32\msfukeu.exe
c:\windows\system32\msfunqk.exe
c:\windows\system32\msfvz.exe
c:\windows\system32\msfwwlqg.exe
c:\windows\system32\msfxcjbv.exe
c:\windows\system32\msfxiehb.exe
c:\windows\system32\msfxjwjs.exe
c:\windows\system32\msfzhbgb.exe
c:\windows\system32\msfzxckb.exe
c:\windows\system32\msfzyvqc.exe
c:\windows\system32\msgaasjy.exe
c:\windows\system32\msgae.exe
c:\windows\system32\msgafk.exe
c:\windows\system32\msgdke.exe
c:\windows\system32\msgecr.exe
c:\windows\system32\msgenjq.exe
c:\windows\system32\msgex.exe
c:\windows\system32\msgfdp.exe
c:\windows\system32\msgff.exe
c:\windows\system32\msggo.exe
c:\windows\system32\msggwx.exe
c:\windows\system32\msghr.exe
c:\windows\system32\msgjkovz.exe
c:\windows\system32\msgkbc.exe
c:\windows\system32\msgkc.exe
c:\windows\system32\msgkra.exe
c:\windows\system32\msglf.exe
c:\windows\system32\msglo.exe
c:\windows\system32\msgno.exe
c:\windows\system32\msgobvqz.exe
c:\windows\system32\msgpuvna.exe
c:\windows\system32\msgqtz.exe
c:\windows\system32\msgrnhd.exe
c:\windows\system32\msgvpo.exe
c:\windows\system32\msgvx.exe
c:\windows\system32\msgwbcd.exe
c:\windows\system32\msgxmg.exe
c:\windows\system32\msgxuhha.exe
c:\windows\system32\msgyg.exe
c:\windows\system32\msgylhb.exe
c:\windows\system32\mshafykz.exe
c:\windows\system32\mshcmr.exe
c:\windows\system32\mshcni.exe
c:\windows\system32\mshgixuk.exe
c:\windows\system32\mshgkcv.exe
c:\windows\system32\mshgw.exe
c:\windows\system32\mshhqdw.exe
c:\windows\system32\mshhra.exe
c:\windows\system32\mshhzk.exe
c:\windows\system32\mshiyr.exe
c:\windows\system32\mshizxr.exe
c:\windows\system32\mshjzf.exe
c:\windows\system32\mshll.exe
c:\windows\system32\mshlnsj.exe
c:\windows\system32\mshmhn.exe
c:\windows\system32\mshmyer.exe
c:\windows\system32\mshoe.exe
c:\windows\system32\mshpkrpo.exe
c:\windows\system32\mshrxzjz.exe
c:\windows\system32\mshsdgjn.exe
c:\windows\system32\mshshe.exe
c:\windows\system32\mshssec.exe
c:\windows\system32\mshtgy.exe
c:\windows\system32\mshtkem.exe
c:\windows\system32\mshtuyq.exe
c:\windows\system32\mshudl.exe
c:\windows\system32\mshufyvc.exe
c:\windows\system32\mshvyfg.exe
c:\windows\system32\mshwkd.exe
c:\windows\system32\mshwm.exe
c:\windows\system32\mshxo.exe
c:\windows\system32\mshxytjt.exe
c:\windows\system32\mshydepn.exe
c:\windows\system32\mshzbfnm.exe
c:\windows\system32\mshzct.exe
c:\windows\system32\msiaeon.exe
c:\windows\system32\msicijlj.exe
c:\windows\system32\msiffxrc.exe
c:\windows\system32\msifix.exe
c:\windows\system32\msifwk.exe
c:\windows\system32\msifzde.exe
c:\windows\system32\msiirdh.exe
c:\windows\system32\msikdw.exe
c:\windows\system32\msikgjiw.exe
c:\windows\system32\msils.exe
c:\windows\system32\msiltvbu.exe
c:\windows\system32\msimdc.exe
c:\windows\system32\msimjvm.exe
c:\windows\system32\msimwqmy.exe
c:\windows\system32\msinld.exe
c:\windows\system32\msinnmzs.exe
c:\windows\system32\msipewji.exe
c:\windows\system32\msiplhfz.exe
c:\windows\system32\msiprtfn.exe
c:\windows\system32\msipyizc.exe
c:\windows\system32\msipz.exe
c:\windows\system32\msiqzuu.exe
c:\windows\system32\msird.exe
c:\windows\system32\msiseyjk.exe
c:\windows\system32\msisj.exe
c:\windows\system32\msitng.exe
c:\windows\system32\msivb.exe
c:\windows\system32\msivxws.exe
c:\windows\system32\msiwbwi.exe
c:\windows\system32\msiwugf.exe
c:\windows\system32\msixc.exe
c:\windows\system32\msixfx.exe
c:\windows\system32\msizuv.exe
c:\windows\system32\msjawit.exe
c:\windows\system32\msjbrmk.exe
c:\windows\system32\msjbyxgt.exe
c:\windows\system32\msjcoiv.exe
c:\windows\system32\msjdiuv.exe
c:\windows\system32\msjdq.exe
c:\windows\system32\msjdye.exe
c:\windows\system32\msjek.exe
c:\windows\system32\msjfgyf.exe
c:\windows\system32\msjgev.exe
c:\windows\system32\msjgyjg.exe
c:\windows\system32\msjicsau.exe
c:\windows\system32\msjilqhy.exe
c:\windows\system32\msjinzw.exe
c:\windows\system32\msjivg.exe
c:\windows\system32\msjivgq.exe
c:\windows\system32\msjjn.exe
c:\windows\system32\msjlrzm.exe
c:\windows\system32\msjmizj.exe
c:\windows\system32\msjmle.exe
c:\windows\system32\msjnc.exe
c:\windows\system32\msjnvjsh.exe
c:\windows\system32\msjolh.exe
c:\windows\system32\msjpg.exe
c:\windows\system32\msjps.exe
c:\windows\system32\msjrxu.exe
c:\windows\system32\msjskmm.exe
c:\windows\system32\msjvhwf.exe
c:\windows\system32\msjvlsqd.exe
c:\windows\system32\msjwdtht.exe
c:\windows\system32\msjxaech.exe
c:\windows\system32\msjytrht.exe
c:\windows\system32\msjzj.exe
c:\windows\system32\msjzwnhy.exe
c:\windows\system32\mskbp.exe
c:\windows\system32\mskdgst.exe
c:\windows\system32\mskdlfcf.exe
c:\windows\system32\mskfxkzc.exe
c:\windows\system32\mskgp.exe
c:\windows\system32\mskhgc.exe
c:\windows\system32\mskijpcr.exe
c:\windows\system32\mskjlq.exe
c:\windows\system32\mskjrdml.exe
c:\windows\system32\mskkhvx.exe
c:\windows\system32\mskkjlhv.exe
c:\windows\system32\mskkq.exe
c:\windows\system32\msklgxm.exe
c:\windows\system32\msklua.exe
c:\windows\system32\msklusy.exe
c:\windows\system32\mskma.exe
c:\windows\system32\mskncwm.exe
c:\windows\system32\mskpg.exe
c:\windows\system32\mskpkain.exe
c:\windows\system32\mskqlh.exe
c:\windows\system32\msktmvdf.exe
c:\windows\system32\msktr.exe
c:\windows\system32\mskts.exe
c:\windows\system32\mskttiba.exe
c:\windows\system32\mskuco.exe
c:\windows\system32\mskumbvq.exe
c:\windows\system32\mskwdlim.exe
c:\windows\system32\mskwoc.exe
c:\windows\system32\mskwuy.exe
c:\windows\system32\mskww.exe
c:\windows\system32\mskxhit.exe
c:\windows\system32\mskxlf.exe
c:\windows\system32\mskxlk.exe
c:\windows\system32\mskxtcsh.exe
c:\windows\system32\mskzaj.exe
c:\windows\system32\mskzemqd.exe
c:\windows\system32\mskzpwbb.exe
c:\windows\system32\mslcag.exe
c:\windows\system32\mslcy.exe
c:\windows\system32\msldvd.exe
c:\windows\system32\msletg.exe
c:\windows\system32\mslfdj.exe
c:\windows\system32\mslfj.exe
c:\windows\system32\mslhw.exe
c:\windows\system32\mslhww.exe
c:\windows\system32\mslio.exe
c:\windows\system32\msljc.exe
c:\windows\system32\mslkan.exe
c:\windows\system32\mslmmx.exe
c:\windows\system32\mslmmyg.exe
c:\windows\system32\mslmp.exe
c:\windows\system32\mslns.exe
c:\windows\system32\mslodta.exe
c:\windows\system32\msloj.exe
c:\windows\system32\mslpbgr.exe
c:\windows\system32\mslraeo.exe
c:\windows\system32\mslrgfcc.exe
c:\windows\system32\mslrne.exe
c:\windows\system32\mslrp.exe
c:\windows\system32\mslrxe.exe
c:\windows\system32\mslucqe.exe
c:\windows\system32\msluqn.exe
c:\windows\system32\msluuk.exe
c:\windows\system32\mslvdi.exe
c:\windows\system32\mslxdhd.exe
c:\windows\system32\mslzg.exe
c:\windows\system32\msmacoah.exe
c:\windows\system32\msmagio.exe
c:\windows\system32\msmagnu.exe
c:\windows\system32\msmbea.exe
c:\windows\system32\msmbvqra.exe
c:\windows\system32\msmckv.exe
c:\windows\system32\msmcoqs.exe
c:\windows\system32\msmcq.exe
c:\windows\system32\msmcu.exe
c:\windows\system32\msmedyfq.exe
c:\windows\system32\msmemut.exe
c:\windows\system32\msmftoz.exe
c:\windows\system32\msmhaa.exe
c:\windows\system32\msmhk.exe
c:\windows\system32\msminxd.exe
c:\windows\system32\msmjxznq.exe
c:\windows\system32\msmktixr.exe
c:\windows\system32\msmkxew.exe
c:\windows\system32\msmlwzj.exe
c:\windows\system32\msmlz.exe
c:\windows\system32\msmovruh.exe
c:\windows\system32\msmprznq.exe
c:\windows\system32\msmqjgln.exe
c:\windows\system32\msmru.exe
c:\windows\system32\msmsa.exe
c:\windows\system32\msmscehe.exe
c:\windows\system32\msmsdm.exe
c:\windows\system32\msmskcr.exe
c:\windows\system32\msmtquf.exe
c:\windows\system32\msmuwb.exe
c:\windows\system32\msmwdpk.exe
c:\windows\system32\msmwhh.exe
c:\windows\system32\msmwwdrf.exe
c:\windows\system32\msmxoeab.exe
c:\windows\system32\msmxw.exe
c:\windows\system32\msmxy.exe
c:\windows\system32\msmynr.exe
c:\windows\system32\msmzqwm.exe
c:\windows\system32\msnaq.exe
c:\windows\system32\msnaud.exe
c:\windows\system32\msnbewet.exe
c:\windows\system32\msnbu.exe
c:\windows\system32\msncache.dll
c:\windows\system32\msncjccs.exe
c:\windows\system32\msnczdj.exe
c:\windows\system32\msndloui.exe
c:\windows\system32\msndrui.exe
c:\windows\system32\msnej.exe
c:\windows\system32\msnet.exe
c:\windows\system32\msnfm.exe
c:\windows\system32\msngovql.exe
c:\windows\system32\msnhbds.exe
c:\windows\system32\msniaebo.exe
c:\windows\system32\msnjoiv.exe
c:\windows\system32\msnkf.exe
c:\windows\system32\msnkzjyc.exe
c:\windows\system32\msnmb.exe
c:\windows\system32\msnmzc.exe
c:\windows\system32\msnnsmc.exe
c:\windows\system32\msnogi.exe
c:\windows\system32\msnokwr.exe
c:\windows\system32\msnom.exe
c:\windows\system32\msnopm.exe
c:\windows\system32\msnphd.exe
c:\windows\system32\msnplgqk.exe
c:\windows\system32\msnpqbx.exe
c:\windows\system32\msnqhhf.exe
c:\windows\system32\msnrfa.exe
c:\windows\system32\msnrmlan.exe
c:\windows\system32\msnrmn.exe
c:\windows\system32\msnrsq.exe
c:\windows\system32\msnrxtq.exe
c:\windows\system32\msnrxz.exe
c:\windows\system32\msntrirl.exe
c:\windows\system32\msnua.exe
c:\windows\system32\msnvbss.exe
c:\windows\system32\msnvp.exe
c:\windows\system32\msnvriv.exe
c:\windows\system32\msnvva.exe
c:\windows\system32\msnvvu.exe
c:\windows\system32\msnwc.exe
c:\windows\system32\msnwv.exe
c:\windows\system32\msnykimk.exe
c:\windows\system32\msoawz.exe
c:\windows\system32\msobaia.exe
c:\windows\system32\msobksri.exe
c:\windows\system32\msodiigs.exe
c:\windows\system32\msoeqxc.exe
c:\windows\system32\msofjmn.exe
c:\windows\system32\msohsoxu.exe
c:\windows\system32\msojb.exe
c:\windows\system32\msolces.exe
c:\windows\system32\msoleqn.exe
c:\windows\system32\msolg.exe
c:\windows\system32\msomy.exe
c:\windows\system32\msonmq.exe
c:\windows\system32\msoohqy.exe
c:\windows\system32\msopawz.exe
c:\windows\system32\msopxmhi.exe
c:\windows\system32\msopz.exe
c:\windows\system32\msorm.exe
c:\windows\system32\msose.exe
c:\windows\system32\msoss.exe
c:\windows\system32\msotimvc.exe
c:\windows\system32\msovjwj.exe
c:\windows\system32\msown.exe
c:\windows\system32\msoxbw.exe
c:\windows\system32\msoyqzvw.exe
c:\windows\system32\msozakca.exe
c:\windows\system32\msozba.exe
c:\windows\system32\msozmv.exe
c:\windows\system32\msozr.exe
c:\windows\system32\mspak.exe
c:\windows\system32\mspbwo.exe
c:\windows\system32\mspcmi.exe
c:\windows\system32\mspct.exe
c:\windows\system32\mspczldp.exe
c:\windows\system32\mspdamu.exe
c:\windows\system32\mspfw.exe
c:\windows\system32\mspgznok.exe
c:\windows\system32\msphavs.exe
c:\windows\system32\msphd.exe
c:\windows\system32\msphh.exe
c:\windows\system32\msphjubk.exe
c:\windows\system32\msphk.exe
c:\windows\system32\msphlj.exe
c:\windows\system32\msphlq.exe
c:\windows\system32\msphojyk.exe
c:\windows\system32\msphufs.exe
c:\windows\system32\mspjkuc.exe
c:\windows\system32\mspjuhsa.exe
c:\windows\system32\mspkb.exe
c:\windows\system32\mspkr.exe
c:\windows\system32\mspku.exe
c:\windows\system32\mspky.exe
c:\windows\system32\mspmf.exe
c:\windows\system32\mspmmx.exe
c:\windows\system32\mspnanwi.exe
c:\windows\system32\mspozs.exe
c:\windows\system32\msppdjhd.exe
c:\windows\system32\msppm.exe
c:\windows\system32\msppqgzc.exe
c:\windows\system32\mspprc.exe
c:\windows\system32\msppruf.exe
c:\windows\system32\msppxb.exe
c:\windows\system32\mspqhu.exe
c:\windows\system32\mspqiux.exe
c:\windows\system32\mspqlthg.exe
c:\windows\system32\mspqn.exe
c:\windows\system32\msprb.exe
c:\windows\system32\msprex.exe
c:\windows\system32\mspribfe.exe
c:\windows\system32\mspsubu.exe
c:\windows\system32\mspsw.exe
c:\windows\system32\mspubk.exe
c:\windows\system32\mspuiep.exe
c:\windows\system32\mspuk.exe
c:\windows\system32\mspun.exe
c:\windows\system32\mspuwsax.exe
c:\windows\system32\mspvli.exe
c:\windows\system32\mspvmt.exe
c:\windows\system32\mspwc.exe
c:\windows\system32\mspwofky.exe
c:\windows\system32\mspxrw.exe
c:\windows\system32\mspxt.exe
c:\windows\system32\mspyl.exe
c:\windows\system32\mspynsju.exe
c:\windows\system32\mspyqhl.exe
c:\windows\system32\mspyr.exe
c:\windows\system32\mspytark.exe
c:\windows\system32\mspyxur.exe
c:\windows\system32\mspzbwkh.exe
c:\windows\system32\mspzc.exe
c:\windows\system32\mspzfz.exe
c:\windows\system32\mspzht.exe
c:\windows\system32\msqacyb.exe
c:\windows\system32\msqayn.exe
c:\windows\system32\msqaz.exe
c:\windows\system32\msqbfhqi.exe
c:\windows\system32\msqci.exe
c:\windows\system32\msqcnimq.exe
c:\windows\system32\msqcqkf.exe
c:\windows\system32\msqczv.exe
c:\windows\system32\msqdalit.exe
c:\windows\system32\msqdmlh.exe
c:\windows\system32\msqdwre.exe
c:\windows\system32\msqdxau.exe
c:\windows\system32\msqee.exe
c:\windows\system32\msqerrk.exe
c:\windows\system32\msqfjn.exe
c:\windows\system32\msqfn.exe
c:\windows\system32\msqfomd.exe
c:\windows\system32\msqfpa.exe
c:\windows\system32\msqfq.exe
c:\windows\system32\msqfrd.exe
c:\windows\system32\msqfrfh.exe
c:\windows\system32\msqgc.exe
c:\windows\system32\msqgfwlw.exe
c:\windows\system32\msqhpnbn.exe
c:\windows\system32\msqiq.exe
c:\windows\system32\msqizso.exe
c:\windows\system32\msqjqby.exe
c:\windows\system32\msqjxeu.exe
c:\windows\system32\msqkhjxz.exe
c:\windows\system32\msqkoi.exe
c:\windows\system32\msqkpao.exe
c:\windows\system32\msqlacl.exe
c:\windows\system32\msqlh.exe
c:\windows\system32\msqlj.exe
c:\windows\system32\msqlkb.exe
c:\windows\system32\msqmcqt.exe
c:\windows\system32\msqmwrjg.exe
c:\windows\system32\msqnuig.exe
c:\windows\system32\msqnuyo.exe
c:\windows\system32\msqonc.exe
c:\windows\system32\msqpdz.exe
c:\windows\system32\msqpete.exe
c:\windows\system32\msqpmdd.exe
c:\windows\system32\msqpo.exe
c:\windows\system32\msqpxfux.exe
c:\windows\system32\msqqaoy.exe
c:\windows\system32\msqqlfcs.exe
c:\windows\system32\msqqn.exe
c:\windows\system32\msqqrv.exe
c:\windows\system32\msqqzqr.exe
c:\windows\system32\msqrox.exe
c:\windows\system32\msqrsgc.exe
c:\windows\system32\msqrzi.exe
c:\windows\system32\msquav.exe
c:\windows\system32\msquf.exe
c:\windows\system32\msqufds.exe
c:\windows\system32\msqvqtq.exe
c:\windows\system32\msqvt.exe
c:\windows\system32\msqvtlcl.exe
c:\windows\system32\msqwc.exe
c:\windows\system32\msqwegg.exe
c:\windows\system32\msqwpc.exe
c:\windows\system32\msqysixh.exe
c:\windows\system32\msqzhmzb.exe
c:\windows\system32\msqzotjg.exe
c:\windows\system32\msrahxd.exe
c:\windows\system32\msrame.exe
c:\windows\system32\msraot.exe
c:\windows\system32\msrbpotw.exe
c:\windows\system32\msrbvyx.exe
c:\windows\system32\msrcgcpd.exe
c:\windows\system32\msrcrcj.exe
c:\windows\system32\msrcz.exe
c:\windows\system32\msrdqgym.exe
c:\windows\system32\msrenm.exe
c:\windows\system32\msrenoai.exe
c:\windows\system32\msrepxz.exe
c:\windows\system32\msrfjjek.exe
c:\windows\system32\msrfru.exe
c:\windows\system32\msrgb.exe
c:\windows\system32\msrgpc.exe
c:\windows\system32\msrgt.exe
c:\windows\system32\msrgwa.exe
c:\windows\system32\msrgzlk.exe
c:\windows\system32\msrha.exe
c:\windows\system32\msrhesfl.exe
c:\windows\system32\msrhubt.exe
c:\windows\system32\msrhvr.exe
c:\windows\system32\msriqte.exe
c:\windows\system32\msriusa.exe
c:\windows\system32\msrjesfs.exe
c:\windows\system32\msrjhcx.exe
c:\windows\system32\msrjp.exe
c:\windows\system32\msrjz.exe
c:\windows\system32\msrket.exe
c:\windows\system32\msrkhop.exe
c:\windows\system32\msrkhwkh.exe
c:\windows\system32\msrkvbg.exe
c:\windows\system32\msrkwph.exe
c:\windows\system32\msrky.exe
c:\windows\system32\msrlarfr.exe
c:\windows\system32\msrlnf.exe
c:\windows\system32\msrlod.exe
c:\windows\system32\msrmm.exe
c:\windows\system32\msrmq.exe
c:\windows\system32\msrnp.exe
c:\windows\system32\msroeit.exe
c:\windows\system32\msrondt.exe
c:\windows\system32\msrpebj.exe
c:\windows\system32\msrpv.exe
c:\windows\system32\msrqc.exe
c:\windows\system32\msrqfkwn.exe
c:\windows\system32\msrqilv.exe
c:\windows\system32\msrqz.exe
c:\windows\system32\msrrgle.exe
c:\windows\system32\msrrjzyt.exe
c:\windows\system32\msrrq.exe
c:\windows\system32\msrsmb.exe
c:\windows\system32\msrsqge.exe
c:\windows\system32\msrtcfk.exe
c:\windows\system32\msrtiyx.exe
c:\windows\system32\msrtsl.exe
c:\windows\system32\msrtyrpu.exe
c:\windows\system32\msruhrwo.exe
c:\windows\system32\msrut.exe
c:\windows\system32\msruwyww.exe
c:\windows\system32\msrvf.exe
c:\windows\system32\msrwmn.exe
c:\windows\system32\msrwq.exe
c:\windows\system32\msrxkci.exe
c:\windows\system32\msrxoirr.exe
c:\windows\system32\msrxuku.exe
c:\windows\system32\msrzyvdz.exe
c:\windows\system32\mssaizx.exe
c:\windows\system32\mssbqkxm.exe
c:\windows\system32\mssbrsud.exe
c:\windows\system32\mssbs.exe
c:\windows\system32\mssbscqx.exe
c:\windows\system32\mssbvsn.exe
c:\windows\system32\mssbxp.exe
c:\windows\system32\mssdhyk.exe
c:\windows\system32\mssdjajx.exe
c:\windows\system32\mssdn.exe
c:\windows\system32\mssehbj.exe
c:\windows\system32\mssetaez.exe
c:\windows\system32\mssfcc.exe
c:\windows\system32\mssffn.exe
c:\windows\system32\mssgp.exe
c:\windows\system32\mssgqdt.exe
c:\windows\system32\msshe.exe
c:\windows\system32\msshk.exe
c:\windows\system32\msshnmu.exe
c:\windows\system32\msshp.exe
c:\windows\system32\msshptlt.exe
c:\windows\system32\msshy.exe
c:\windows\system32\msshyv.exe
c:\windows\system32\mssifb.exe
c:\windows\system32\msskhkoo.exe
c:\windows\system32\msskrrc.exe
c:\windows\system32\msslntmb.exe
c:\windows\system32\mssls.exe
c:\windows\system32\mssmeyla.exe
c:\windows\system32\mssmg.exe
c:\windows\system32\mssnzdru.exe
c:\windows\system32\mssog.exe
c:\windows\system32\mssoukn.exe
c:\windows\system32\mssov.exe
c:\windows\system32\mssox.exe
c:\windows\system32\mssqj.exe
c:\windows\system32\mssqseix.exe
c:\windows\system32\mssqsxk.exe
c:\windows\system32\mssrko.exe
c:\windows\system32\msssgchx.exe
c:\windows\system32\msssyz.exe
c:\windows\system32\msstpws.exe
c:\windows\system32\mssua.exe
c:\windows\system32\mssvcgbh.exe
c:\windows\system32\msswk.exe
c:\windows\system32\msswq.exe
c:\windows\system32\msswxfuq.exe
c:\windows\system32\mssxss.exe
c:\windows\system32\mssyiv.exe
c:\windows\system32\mssyryr.exe
c:\windows\system32\msszk.exe
c:\windows\system32\msszsl.exe
c:\windows\system32\msszztwj.exe
c:\windows\system32\mstalmqq.exe
c:\windows\system32\mstaqc.exe
c:\windows\system32\mstaqg.exe
c:\windows\system32\mstaseqi.exe
c:\windows\system32\mstatqq.exe
c:\windows\system32\mstavhj.exe
c:\windows\system32\mstbel.exe
c:\windows\system32\mstdacm.exe
c:\windows\system32\mstdaqxr.exe
c:\windows\system32\mstdco.exe
c:\windows\system32\mstdczox.exe
c:\windows\system32\mstdjqgs.exe
c:\windows\system32\mstelun.exe
c:\windows\system32\mstemx.exe
c:\windows\system32\mstevfhb.exe
c:\windows\system32\mstfmlk.exe
c:\windows\system32\mstghsh.exe
c:\windows\system32\mstgij.exe
c:\windows\system32\msthiusg.exe
c:\windows\system32\msthnmdj.exe
c:\windows\system32\msthoko.exe
c:\windows\system32\mstipg.exe
c:\windows\system32\mstirvdl.exe
c:\windows\system32\mstissu.exe
c:\windows\system32\mstix.exe
c:\windows\system32\mstjaa.exe
c:\windows\system32\mstjh.exe
c:\windows\system32\mstjmxg.exe
c:\windows\system32\mstjmz.exe
c:\windows\system32\mstjmzcz.exe
c:\windows\system32\mstjo.exe
c:\windows\system32\mstjph.exe
c:\windows\system32\mstjwq.exe
c:\windows\system32\mstjwtsu.exe
c:\windows\system32\mstkgbo.exe
c:\windows\system32\mstkx.exe
c:\windows\system32\mstlc.exe
c:\windows\system32\mstlcr.exe
c:\windows\system32\mstleshv.exe
c:\windows\system32\mstlpir.exe
c:\windows\system32\mstmcqwu.exe
c:\windows\system32\mstmm.exe
c:\windows\system32\mstms.exe
c:\windows\system32\mstmv.exe
c:\windows\system32\mstmydy.exe
c:\windows\system32\mstnhmoo.exe
c:\windows\system32\mstno.exe
c:\windows\system32\mstnxhl.exe
c:\windows\system32\mstoo.exe
c:\windows\system32\mstpdxh.exe
c:\windows\system32\mstqah.exe
c:\windows\system32\mstqd.exe
c:\windows\system32\mstqmvtb.exe
c:\windows\system32\mstqpqyc.exe
c:\windows\system32\mstrn.exe
c:\windows\system32\mstsaqti.exe
c:\windows\system32\mstshz.exe
c:\windows\system32\mstsr.exe
c:\windows\system32\mststq.exe
c:\windows\system32\msttrsc.exe
c:\windows\system32\mstttfcl.exe
c:\windows\system32\mstudth.exe
c:\windows\system32\mstukw.exe
c:\windows\system32\mstwlmv.exe
c:\windows\system32\mstwpa.exe
c:\windows\system32\mstxeebz.exe
c:\windows\system32\mstxmi.exe
c:\windows\system32\mstxo.exe
c:\windows\system32\mstxu.exe
c:\windows\system32\mstyf.exe
c:\windows\system32\mstzau.exe
c:\windows\system32\mstzf.exe
c:\windows\system32\mstzj.exe
c:\windows\system32\mstzm.exe
c:\windows\system32\mstzxvq.exe
c:\windows\system32\mstzykui.exe
c:\windows\system32\msuaed.exe
c:\windows\system32\msuah.exe
c:\windows\system32\msuam.exe
c:\windows\system32\msuaz.exe
c:\windows\system32\msubj.exe
c:\windows\system32\msubwcz.exe
c:\windows\system32\msuby.exe
c:\windows\system32\msubzih.exe
c:\windows\system32\msubzuyk.exe
c:\windows\system32\msuchio.exe
c:\windows\system32\msudfaex.exe
c:\windows\system32\msuduk.exe
c:\windows\system32\msuema.exe
c:\windows\system32\msufc.exe
c:\windows\system32\msufka.exe
c:\windows\system32\msugnmdt.exe
c:\windows\system32\msugpd.exe
c:\windows\system32\msugyybe.exe
c:\windows\system32\msuhbzug.exe
c:\windows\system32\msuhe.exe
c:\windows\system32\msuhtdq.exe
c:\windows\system32\msuhubw.exe
c:\windows\system32\msuiakjb.exe
c:\windows\system32\msuidqep.exe
c:\windows\system32\msuietkd.exe
c:\windows\system32\msuih.exe
c:\windows\system32\msuijezy.exe
c:\windows\system32\msuirdwa.exe
c:\windows\system32\msuizuos.exe
c:\windows\system32\msukb.exe
c:\windows\system32\msukeib.exe
c:\windows\system32\msuky.exe
c:\windows\system32\msukzvia.exe
c:\windows\system32\msuma.exe
c:\windows\system32\msumpn.exe
c:\windows\system32\msumzwid.exe
c:\windows\system32\msunaaa.exe
c:\windows\system32\msunir.exe
c:\windows\system32\msuodmyf.exe
c:\windows\system32\msuoujr.exe
c:\windows\system32\msuoyz.exe
c:\windows\system32\msupft.exe
c:\windows\system32\msupw.exe
c:\windows\system32\msupxj.exe
c:\windows\system32\msupxqge.exe
c:\windows\system32\msupzrj.exe
c:\windows\system32\msuqj.exe
c:\windows\system32\msuqu.exe
c:\windows\system32\msuqx.exe
c:\windows\system32\msurqzs.exe
c:\windows\system32\msurxa.exe
c:\windows\system32\msusasz.exe
c:\windows\system32\msusibv.exe
c:\windows\system32\msutdti.exe
c:\windows\system32\msuuqrh.exe
c:\windows\system32\msuuxul.exe
c:\windows\system32\msuvjaoh.exe
c:\windows\system32\msuvr.exe
c:\windows\system32\msuvzge.exe
c:\windows\system32\msuwcraz.exe
c:\windows\system32\msuwtpl.exe
c:\windows\system32\msuxe.exe
c:\windows\system32\msuxfz.exe
c:\windows\system32\msuxjp.exe
c:\windows\system32\msuxwhw.exe
c:\windows\system32\msuya.exe
c:\windows\system32\msuyejgo.exe
c:\windows\system32\msuylti.exe
c:\windows\system32\msuyms.exe
c:\windows\system32\msuyv.exe
c:\windows\system32\msuzmt.exe
c:\windows\system32\msuzrlp.exe
c:\windows\system32\msuzzxh.exe
c:\windows\system32\msvacshw.exe
c:\windows\system32\msvae.exe
c:\windows\system32\msvai.exe
c:\windows\system32\msvamfe.exe
c:\windows\system32\msvba.exe
c:\windows\system32\msvbgmz.exe
c:\windows\system32\msvbnmwe.exe
c:\windows\system32\msvbx.exe
c:\windows\system32\msvcb.exe
c:\windows\system32\msvcn.exe
c:\windows\system32\msvdnoxr.exe
c:\windows\system32\msvdonq.exe
c:\windows\system32\msvdwf.exe
c:\windows\system32\msveqaln.exe
c:\windows\system32\msvexkx.exe
c:\windows\system32\msvfb.exe
c:\windows\system32\msvfeqh.exe
c:\windows\system32\msvgs.exe
c:\windows\system32\msvhkgwv.exe
c:\windows\system32\msvhldxo.exe
c:\windows\system32\msvhm.exe
c:\windows\system32\msvhqk.exe
c:\windows\system32\msvhtfz.exe
c:\windows\system32\msvib.exe
c:\windows\system32\msviopn.exe
c:\windows\system32\msvje.exe
c:\windows\system32\msvjhl.exe
c:\windows\system32\msvkk.exe
c:\windows\system32\msvkndiz.exe
c:\windows\system32\msvkzqbq.exe
c:\windows\system32\msvlpq.exe
c:\windows\system32\msvlxbx.exe
c:\windows\system32\msvlyn.exe
c:\windows\system32\msvmbnt.exe
c:\windows\system32\msvmco.exe
c:\windows\system32\msvmj.exe
c:\windows\system32\msvnns.exe
c:\windows\system32\msvntxww.exe
c:\windows\system32\msvnzwoc.exe
c:\windows\system32\msvoxwtp.exe
c:\windows\system32\msvpc.exe
c:\windows\system32\msvpf.exe
c:\windows\system32\msvpnh.exe
c:\windows\system32\msvpnyx.exe
c:\windows\system32\msvpocn.exe
c:\windows\system32\msvpr.exe
c:\windows\system32\msvpt.exe
c:\windows\system32\msvpwsa.exe
c:\windows\system32\msvqafnf.exe
c:\windows\system32\msvraz.exe
c:\windows\system32\msvrdo.exe
c:\windows\system32\msvreh.exe
c:\windows\system32\msvrlyv.exe
c:\windows\system32\msvrna.exe
c:\windows\system32\msvrysd.exe
c:\windows\system32\msvsd.exe
c:\windows\system32\msvseotu.exe
c:\windows\system32\msvss.exe
c:\windows\system32\msvstc.exe
c:\windows\system32\msvsw.exe
c:\windows\system32\msvswjp.exe
c:\windows\system32\msvtb.exe
c:\windows\system32\msvtqtie.exe
c:\windows\system32\msvubc.exe
c:\windows\system32\msvuhk.exe
c:\windows\system32\msvuvmb.exe
c:\windows\system32\msvwfv.exe
c:\windows\system32\msvwge.exe
c:\windows\system32\msvwzn.exe
c:\windows\system32\msvxvc.exe
c:\windows\system32\msvys.exe
c:\windows\system32\msvzht.exe
c:\windows\system32\msvzrcus.exe
c:\windows\system32\mswag.exe
c:\windows\system32\mswak.exe
c:\windows\system32\mswbpixb.exe
c:\windows\system32\mswcbcdl.exe
c:\windows\system32\mswcenwb.exe
c:\windows\system32\mswck.exe
c:\windows\system32\mswdef.exe
c:\windows\system32\mswdew.exe
c:\windows\system32\mswds.exe
c:\windows\system32\mswdw.exe
c:\windows\system32\mswemvh.exe
c:\windows\system32\mswerx.exe
c:\windows\system32\mswfs.exe
c:\windows\system32\mswgbxd.exe
c:\windows\system32\mswgkk.exe
c:\windows\system32\mswgs.exe
c:\windows\system32\mswhan.exe
c:\windows\system32\mswhr.exe
c:\windows\system32\mswhx.exe
c:\windows\system32\mswibd.exe
c:\windows\system32\mswimo.exe
c:\windows\system32\mswiymk.exe
c:\windows\system32\mswiyquk.exe
c:\windows\system32\mswjek.exe
c:\windows\system32\mswjkyr.exe
c:\windows\system32\mswjpbzh.exe
c:\windows\system32\mswjso.exe
c:\windows\system32\mswjug.exe
c:\windows\system32\mswjvy.exe
c:\windows\system32\mswkhb.exe
c:\windows\system32\mswkik.exe
c:\windows\system32\mswkl.exe
c:\windows\system32\mswlcsy.exe
c:\windows\system32\mswlhn.exe
c:\windows\system32\mswlioc.exe
c:\windows\system32\mswmt.exe
c:\windows\system32\mswmwxzc.exe
c:\windows\system32\mswngyi.exe
c:\windows\system32\mswnoe.exe
c:\windows\system32\mswnopd.exe
c:\windows\system32\mswnpi.exe
c:\windows\system32\mswnpokd.exe
c:\windows\system32\mswnro.exe
c:\windows\system32\mswnvsn.exe
c:\windows\system32\mswoclo.exe
c:\windows\system32\mswofgr.exe
c:\windows\system32\mswogu.exe
c:\windows\system32\mswox.exe
c:\windows\system32\mswozbd.exe
c:\windows\system32\mswpt.exe
c:\windows\system32\mswqduh.exe
c:\windows\system32\mswqp.exe
c:\windows\system32\mswquv.exe
c:\windows\system32\mswqw.exe
c:\windows\system32\mswrkwa.exe
c:\windows\system32\mswrq.exe
c:\windows\system32\mswsca.exe
c:\windows\system32\mswszgw.exe
c:\windows\system32\mswte.exe
c:\windows\system32\mswtmx.exe
c:\windows\system32\mswtngp.exe
c:\windows\system32\mswubwvi.exe
c:\windows\system32\mswuf.exe
c:\windows\system32\mswurb.exe
c:\windows\system32\mswvmbhq.exe
c:\windows\system32\mswwifq.exe
c:\windows\system32\mswwqvp.exe
c:\windows\system32\mswxe.exe
c:\windows\system32\mswxgmy.exe
c:\windows\system32\mswydr.exe
c:\windows\system32\mswyjw.exe
c:\windows\system32\mswyv.exe
c:\windows\system32\mswyxgnb.exe
c:\windows\system32\mswzywog.exe
c:\windows\system32\msxafut.exe
c:\windows\system32\msxbfovm.exe
c:\windows\system32\msxbgk.exe
c:\windows\system32\msxcoahy.exe
c:\windows\system32\msxct.exe
c:\windows\system32\msxdcj.exe
c:\windows\system32\msxdg.exe
c:\windows\system32\msxdk.exe
c:\windows\system32\msxdpa.exe
c:\windows\system32\msxdry.exe
c:\windows\system32\msxdy.exe
c:\windows\system32\msxega.exe
c:\windows\system32\msxej.exe
c:\windows\system32\msxepytu.exe
c:\windows\system32\msxfijs.exe
c:\windows\system32\msxggd.exe
c:\windows\system32\msxgnp.exe
c:\windows\system32\msxgui.exe
c:\windows\system32\msxgyh.exe
c:\windows\system32\msxhphk.exe
c:\windows\system32\msxhu.exe
c:\windows\system32\msxhzzz.exe
c:\windows\system32\msxia.exe
c:\windows\system32\msxitz.exe
c:\windows\system32\msxjgkkk.exe
c:\windows\system32\msxjjv.exe
c:\windows\system32\msxjqwoy.exe
c:\windows\system32\msxjvds.exe
c:\windows\system32\msxkajk.exe
c:\windows\system32\msxkxv.exe
c:\windows\system32\msxlczg.exe
c:\windows\system32\msxldgxp.exe
c:\windows\system32\msxln.exe
c:\windows\system32\msxltj.exe
c:\windows\system32\msxmkdbw.exe
c:\windows\system32\msxmx.exe
c:\windows\system32\msxnat.exe
c:\windows\system32\msxnh.exe
c:\windows\system32\msxnqgsv.exe
c:\windows\system32\msxnrq.exe
c:\windows\system32\msxny.exe
c:\windows\system32\msxobwpd.exe
c:\windows\system32\msxodqf.exe
c:\windows\system32\msxpb.exe
c:\windows\system32\msxpyi.exe
c:\windows\system32\msxpzxwa.exe
c:\windows\system32\msxrlq.exe
c:\windows\system32\msxsfxli.exe
c:\windows\system32\msxsz.exe
c:\windows\system32\msxtfh.exe
c:\windows\system32\msxur.exe
c:\windows\system32\msxusyy.exe
c:\windows\system32\msxvjph.exe
c:\windows\system32\msxvppuv.exe
c:\windows\system32\msxwgdjf.exe
c:\windows\system32\msxwlypm.exe
c:\windows\system32\msxwoc.exe
c:\windows\system32\msxwpez.exe
c:\windows\system32\msxxb.exe
c:\windows\system32\msxxu.exe
c:\windows\system32\msxyafoe.exe
c:\windows\system32\msxyi.exe
c:\windows\system32\msxyohmx.exe
c:\windows\system32\msxywucz.exe
c:\windows\system32\msxyzob.exe
c:\windows\system32\msxzsli.exe
c:\windows\system32\msxzxrj.exe
c:\windows\system32\msxzz.exe
c:\windows\system32\msxzzkcp.exe
c:\windows\system32\msyaabth.exe
c:\windows\system32\msyahlv.exe
c:\windows\system32\msybb.exe
c:\windows\system32\msyblh.exe
c:\windows\system32\msybm.exe
c:\windows\system32\msybmve.exe
c:\windows\system32\msybroox.exe
c:\windows\system32\msybutz.exe
c:\windows\system32\msyckand.exe
c:\windows\system32\msyclno.exe
c:\windows\system32\msyclnvq.exe
c:\windows\system32\msycoxn.exe
c:\windows\system32\msycpvvb.exe
c:\windows\system32\msycrm.exe
c:\windows\system32\msycypdl.exe
c:\windows\system32\msyddbo.exe
c:\windows\system32\msyde.exe
c:\windows\system32\msydrzay.exe
c:\windows\system32\msydxixs.exe
c:\windows\system32\msyebymg.exe
c:\windows\system32\msyedxd.exe
c:\windows\system32\msyfaj.exe
c:\windows\system32\msyfp.exe
c:\windows\system32\msyfqu.exe
c:\windows\system32\msyfvj.exe
c:\windows\system32\msygh.exe
c:\windows\system32\msyglu.exe
c:\windows\system32\msyha.exe
c:\windows\system32\msyharpq.exe
c:\windows\system32\msyhdj.exe
c:\windows\system32\msyhifez.exe
c:\windows\system32\msyiwahf.exe
c:\windows\system32\msyjoicv.exe
c:\windows\system32\msyjsum.exe
c:\windows\system32\msyjsymo.exe
c:\windows\system32\msyjvbf.exe
c:\windows\system32\msyjwr.exe
c:\windows\system32\msyllua.exe
c:\windows\system32\msymn.exe
c:\windows\system32\msynik.exe
c:\windows\system32\msyomifu.exe
c:\windows\system32\msyoskyv.exe
c:\windows\system32\msyotuvi.exe
c:\windows\system32\msypmych.exe
c:\windows\system32\msypozgp.exe
c:\windows\system32\msyppg.exe
c:\windows\system32\msyqgir.exe
c:\windows\system32\msyqi.exe
c:\windows\system32\msyqivz.exe
c:\windows\system32\msyqlel.exe
c:\windows\system32\msyrfi.exe
c:\windows\system32\msyrgi.exe
c:\windows\system32\msyspsn.exe
c:\windows\system32\msytkv.exe
c:\windows\system32\msyuhehw.exe
c:\windows\system32\msyuk.exe
c:\windows\system32\msyum.exe
c:\windows\system32\msyurzp.exe
c:\windows\system32\msyve.exe
c:\windows\system32\msyvg.exe
c:\windows\system32\msyvq.exe
c:\windows\system32\msyvw.exe
c:\windows\system32\msywalg.exe
c:\windows\system32\msywc.exe
c:\windows\system32\msywri.exe
c:\windows\system32\msyxaezo.exe
c:\windows\system32\msyxkzl.exe
c:\windows\system32\msyxpvnu.exe
c:\windows\system32\msyxt.exe
c:\windows\system32\msyxx.exe
c:\windows\system32\msyyf.exe
c:\windows\system32\msyzp.exe
c:\windows\system32\mszaf.exe
c:\windows\system32\mszap.exe
c:\windows\system32\mszbbzoy.exe
c:\windows\system32\mszcc.exe
c:\windows\system32\mszce.exe
c:\windows\system32\mszcm.exe
c:\windows\system32\mszct.exe
c:\windows\system32\mszdbud.exe
c:\windows\system32\mszdkuq.exe
c:\windows\system32\mszdun.exe
c:\windows\system32\mszepzb.exe
c:\windows\system32\mszes.exe
c:\windows\system32\mszetjhj.exe
c:\windows\system32\mszfnl.exe
c:\windows\system32\mszfqng.exe
c:\windows\system32\mszfs.exe
c:\windows\system32\mszgxs.exe
c:\windows\system32\mszhjujx.exe
c:\windows\system32\mszhx.exe
c:\windows\system32\mszhz.exe
c:\windows\system32\mszirrvn.exe
c:\windows\system32\msziuqgf.exe
c:\windows\system32\mszix.exe
c:\windows\system32\mszixxs.exe
c:\windows\system32\mszjhnmt.exe
c:\windows\system32\mszjqcoi.exe
c:\windows\system32\mszkfgwb.exe
c:\windows\system32\mszkie.exe
c:\windows\system32\mszkmcy.exe
c:\windows\system32\mszmeam.exe
c:\windows\system32\mszmvz.exe
c:\windows\system32\msznqpru.exe
c:\windows\system32\msznqq.exe
c:\windows\system32\mszohez.exe
c:\windows\system32\mszohnl.exe
c:\windows\system32\mszonk.exe
c:\windows\system32\mszpg.exe
c:\windows\system32\mszpj.exe
c:\windows\system32\mszpn.exe
c:\windows\system32\mszppavk.exe
c:\windows\system32\mszpsqlt.exe
c:\windows\system32\mszqb.exe
c:\windows\system32\mszqh.exe
c:\windows\system32\mszrovch.exe
c:\windows\system32\mszrpkdu.exe
c:\windows\system32\mszrtnxp.exe
c:\windows\system32\mszsalec.exe
c:\windows\system32\msztpa.exe
c:\windows\system32\mszuijje.exe
c:\windows\system32\mszvrgqp.exe
c:\windows\system32\mszwtds.exe
c:\windows\system32\mszxlq.exe
c:\windows\system32\mszxt.exe
c:\windows\system32\mszxzoe.exe
c:\windows\system32\mszybmu.exe
c:\windows\system32\mszyduxc.exe
c:\windows\system32\mszygi.exe
c:\windows\system32\mszyysv.exe
c:\windows\system32\mszzetp.exe
c:\windows\system32\mszzk.exe
c:\windows\system32\mszzvr.exe
c:\windows\system32\mszzxz.exe
c:\windows\system32\mszzzr.exe
c:\windows\system32\resdll.dll
c:\windows\system32\sopidkc.exe
c:\windows\system32\tmp.reg
c:\windows\system32\UACdmjucqomfi.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkvyvwnjucs.dll
c:\windows\system32\UACmorxukauiw.dat
c:\windows\system32\UACpadtkslwno.dll
c:\windows\system32\UACrdsmbvyyoi.dll
c:\windows\system32\UACrkrnstkvhp.dll
c:\windows\system32\wiawow32.sys
c:\windows\system32\wiwow64.exe
c:\windows\TEMP\mpj68825.dll
c:\windows\TEMP\mta54283.dll
c:\windows\umeqinoqoyejamiy.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_6TO4
——-\Legacy_IAS
——-\Legacy_MSNCACHE
——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_SOPIDKC
——-\Service_6to4
——-\Service_Ias
——-\Service_msncache
——-\Service_MyWebSearchService
——-\Service_sopidkc


((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.

2009-07-31 05:21 . 2009-07-31 05:21 3285 —-a-w- c:\windows\owexujesazuku.dll
2009-07-31 04:52 . 2009-07-31 04:53 ——– d-s—w- C:\Combo-Fix
2009-07-31 04:21 . 2009-07-31 04:21 3269 —-a-w- c:\windows\ijipahal.dll
2009-07-31 03:16 . 2009-07-31 03:16 3269 —-a-w- c:\windows\udegupiditem.dll
2009-07-31 01:10 . 2009-07-31 01:10 3285 —-a-w- c:\windows\ifatupekamos.dll
2009-07-30 23:04 . 2009-07-30 23:04 3277 —-a-w- c:\windows\izuhadajakucuraq.dll
2009-07-30 21:29 . 2009-07-30 21:29 3269 —-a-w- c:\windows\agodahig.dll
2009-07-30 21:01 . 2009-07-30 21:01 3277 —-a-w- c:\windows\eciwesoz.dll
2009-07-30 20:21 . 2009-07-30 20:21 3269 —-a-w- c:\windows\ojuvegubelix.dll
2009-07-30 18:13 . 2009-07-30 18:13 3285 —-a-w- c:\windows\efosaxoga.dll
2009-07-30 17:27 . 2009-07-30 17:27 3269 —-a-w- c:\windows\itomapesepe.dll
2009-07-30 17:04 . 2009-07-30 17:04 3277 —-a-w- c:\windows\eyobuhuwonez.dll
2009-07-30 16:21 . 2009-07-30 16:21 3277 —-a-w- c:\windows\ijoxovab.dll
2009-07-30 15:22 . 2009-07-30 15:22 3269 —-a-w- c:\windows\afayayiyohuyaga.dll
2009-07-30 06:39 . 2009-07-30 06:39 3277 —-a-w- c:\windows\oruxezoyipo.dll
2009-07-30 06:29 . 2009-07-30 06:29 3293 —-a-w- c:\windows\aluwuhuq.dll
2009-07-30 06:22 . 2009-07-30 06:22 3269 —-a-w- c:\windows\ugubojebuqagetey.dll
2009-07-30 04:16 . 2009-07-30 04:16 3285 —-a-w- c:\windows\uyefuheli.dll
2009-07-30 03:36 . 2009-07-30 03:36 3285 —-a-w- c:\windows\edayetas.dll
2009-07-29 22:15 . 2009-07-29 22:15 3277 —-a-w- c:\windows\ocopuveb.dll
2009-07-29 21:24 . 2009-07-29 21:24 3277 —-a-w- c:\windows\exasufol.dll
2009-07-29 20:44 . 2009-07-29 20:44 3293 —-a-w- c:\windows\etadohugili.dll
2009-07-29 18:06 . 2009-07-29 18:06 3277 —-a-w- c:\windows\icuqilaquvacax.dll
2009-07-29 17:31 . 2009-07-29 17:31 3165 —-a-w- c:\windows\ewowofehoc.dll
2009-07-29 17:01 . 2009-07-29 17:01 3293 —-a-w- c:\windows\obebebaguwimu.dll
2009-07-29 16:26 . 2009-07-29 16:26 3269 —-a-w- c:\windows\awawoluw.dll
2009-07-29 07:59 . 2009-07-29 07:59 3277 —-a-w- c:\windows\afiyodege.dll
2009-07-29 07:03 . 2009-07-29 07:03 3293 —-a-w- c:\windows\afiyacik.dll
2009-07-29 06:50 . 2009-07-29 06:50 3293 —-a-w- c:\windows\ohajijohapuh.dll
2009-07-29 06:30 . 2009-07-29 06:30 3301 —-a-w- c:\windows\owiquqis.dll
2009-07-29 06:10 . 2009-07-29 06:10 3285 —-a-w- c:\windows\axipilid.dll
2009-07-29 05:20 . 2009-07-29 05:20 3269 —-a-w- c:\windows\iwekudat.dll
2009-07-29 04:36 . 2009-07-29 04:36 3309 —-a-w- c:\windows\ogadopumamajux.dll
2009-07-29 04:20 . 2009-07-29 04:20 3285 —-a-w- c:\windows\oridojodoh.dll
2009-07-29 03:56 . 2009-07-29 03:56 3261 —-a-w- c:\windows\ihofiwupuc.dll
2009-07-29 03:26 . 2009-07-29 03:26 3285 —-a-w- c:\windows\ixibizebuf.dll
2009-07-29 00:47 . 2009-07-29 00:47 3269 —-a-w- c:\windows\ededibotaxar.dll
2009-07-29 00:37 . 2009-07-29 00:37 3277 —-a-w- c:\windows\uqugafekute.dll
2009-07-28 23:56 . 2009-07-28 23:56 3285 —-a-w- c:\windows\otamuyosamav.dll
2009-07-28 23:06 . 2009-07-28 23:06 3301 —-a-w- c:\windows\abewaruyumogavim.dll
2009-07-28 22:22 . 2009-07-28 22:22 3261 —-a-w- c:\windows\imecuxiq.dll
2009-07-28 21:43 . 2009-07-28 21:43 3293 —-a-w- c:\windows\awufuwejatazaleb.dll
2009-07-28 19:37 . 2009-07-28 19:37 3293 —-a-w- c:\windows\edibufisawanulam.dll
2009-07-28 18:33 . 2009-07-28 18:33 3269 —-a-w- c:\windows\exovadazaderirif.dll
2009-07-28 16:27 . 2009-07-28 16:27 3285 —-a-w- c:\windows\upisavadebib.dll
2009-07-28 15:37 . 2009-07-28 15:37 3293 —-a-w- c:\windows\obaferab.dll
2009-07-28 15:31 . 2009-07-28 15:31 152576 —-a-w- c:\documents and settings\My Computer\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-28 07:38 . 2009-07-28 07:38 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2009-07-28 07:38 . 2009-07-28 07:38 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2009-07-28 07:01 . 2009-07-28 07:01 3309 —-a-w- c:\windows\ojozehobiq.dll
2009-07-28 06:43 . 2009-07-28 06:43 3269 —-a-w- c:\windows\ahobimon.dll
2009-07-28 05:52 . 2009-07-28 05:52 3277 —-a-w- c:\windows\ohibopitucigenog.dll
2009-07-28 05:29 . 2009-07-28 05:29 ——– d—–w- C:\_OTM
2009-07-28 05:16 . 2009-07-28 05:16 3277 —-a-w- c:\windows\exacikotadoq.dll
2009-07-28 04:55 . 2009-07-28 04:55 3261 —-a-w- c:\windows\ocubicitaqun.dll
2009-07-28 03:04 . 2009-07-28 03:04 3285 —-a-w- c:\windows\esumobelisuz.dll
2009-07-28 01:57 . 2009-07-28 01:56 102664 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-07-28 01:55 . 2009-07-28 02:03 ——– d—–w- c:\documents and settings\My Computer\.housecall6.6
2009-07-28 01:52 . 2009-07-28 01:52 3301 —-a-w- c:\windows\exeqobacagayus.dll
2009-07-28 01:37 . 2009-07-28 01:37 3293 —-a-w- c:\windows\uwohinal.dll
2009-07-28 01:32 . 1998-03-26 23:25 12800 —-a-w- c:\windows\system\Wing32.dll
2009-07-28 01:32 . 1996-02-14 22:01 92208 —-a-w- c:\windows\system32\Wing.dll
2009-07-28 01:31 . 2009-07-28 01:31 ——– d—–w- c:\program files\Enigma Software Group
2009-07-28 01:27 . 2009-07-28 01:27 3269 —-a-w- c:\windows\ojibexuyiru.dll
2009-07-28 00:56 . 2009-07-28 00:56 3293 —-a-w- c:\windows\uforatiqefa.dll
2009-07-28 00:22 . 2009-07-28 00:22 3269 —-a-w- c:\windows\inugohewat.dll
2009-07-27 23:41 . 2009-07-27 23:41 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-07-27 23:28 . 2009-07-27 23:28 ——– d—–w- C:\VundoFix Backups
2009-07-27 23:10 . 2009-07-27 23:10 3293 —-a-w- c:\windows\izabevaxitig.dll
2009-07-27 22:50 . 2009-07-27 22:50 3285 —-a-w- c:\windows\ufugohew.dll
2009-07-27 22:21 . 2009-07-27 22:21 3285 —-a-w- c:\windows\eraducenafidaco.dll
2009-07-27 21:39 . 2009-07-28 05:28 4 —-a-w- c:\windows\system32\bincd32.dat
2009-07-27 21:22 . 2009-07-31 04:25 120 —-a-w- c:\windows\Ctuwihuvuwox.dat
2009-07-27 21:18 . 2009-07-27 21:18 31232 —-a-w- c:\windows\system32\wingenocx.dll
2009-07-27 21:15 . 2009-07-27 21:15 ——– d—–w- c:\documents and settings\My Computer\Local Settings\Application Data\{AF00CE25-C84A-4B91-95A8-107F77DCF9EE}
2009-07-27 21:03 . 2009-07-27 21:05 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\14357344
2009-07-27 21:03 . 2009-07-28 00:29 64 —-a-w- c:\windows\ppp4.dat
2009-07-27 21:03 . 2009-07-28 00:29 3 —-a-w- c:\windows\ppp3.dat
2009-07-27 21:03 . 2009-07-27 21:03 36 —-a-w- c:\windows\system32\sysnet.dat
2009-07-27 21:03 . 2009-07-27 21:03 45056 —-a-w- C:\uynrr.exe
2009-07-27 00:48 . 2009-07-27 00:48 ——– d—–w- c:\documents and settings\My Computer\Application Data\Jane s Hotel
2009-07-27 00:48 . 2009-07-27 00:48 ——– d—–w- c:\program files\Realore
2009-07-17 07:14 . 2009-07-17 07:14 ——– d—–w- c:\program files\MSECache
2009-07-02 05:56 . 2009-07-02 05:56 ——– d—–w- c:\program files\XCOM Terror from the Deep
2009-07-02 05:55 . 2009-07-02 05:55 ——– d—–w- C:\CWE
2009-07-02 05:45 . 2009-07-02 05:56 ——– d—–w- c:\documents and settings\My Computer\Application Data\GetRightToGo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 15:52 . 2009-03-24 04:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-28 15:32 . 2008-10-30 08:31 ——– d—–w- c:\program files\Java
2009-07-28 15:26 . 2008-09-19 21:10 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-07-27 04:00 . 2008-10-25 22:17 ——– d—a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-07-26 16:02 . 2008-09-19 21:10 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-24 00:33 . 2008-11-27 22:10 ——– d—–w- c:\documents and settings\My Computer\Application Data\Azureus
2009-07-24 00:30 . 2008-12-11 01:57 ——– d—–w- c:\program files\Mango Earth
2009-07-22 10:00 . 2009-06-27 05:18 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-20 06:11 . 2008-11-27 22:10 ——– d—–w- c:\program files\Mininova-Vuze
2009-07-17 23:20 . 2006-06-19 04:25 57328 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-17 06:59 . 2008-10-25 17:12 ——– d—–w- c:\program files\Microsoft Works
2009-07-16 22:57 . 2008-10-19 05:54 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-13 20:36 . 2009-03-24 04:15 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 20:36 . 2009-03-24 04:15 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 23:02 . 2008-09-19 19:31 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-12 23:02 . 2008-11-18 03:15 513 —-a-w- c:\windows\EReg515.dat
2009-07-12 23:01 . 2008-11-18 03:14 ——– d—–w- c:\program files\Disney Interactive
2009-07-11 22:13 . 2008-10-30 08:32 ——– d—–w- c:\program files\freecol
2009-07-09 23:19 . 2008-11-27 23:18 ——– d—–w- c:\program files\Puppy Luv
2009-07-02 05:20 . 2008-10-18 08:04 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll
2009-06-29 17:52 . 2009-06-29 17:52 297 —-a-w- c:\windows\EReg072.dat
2009-06-29 17:51 . 2009-06-29 17:51 ——– d—–w- c:\program files\Firaxis Games
2009-06-29 16:12 . 2006-06-17 09:23 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-09-19 17:42 78336 ——w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-09-19 17:42 17408 ——w- c:\windows\system32\corpol.dll
2009-06-27 17:48 . 2009-06-27 17:47 ——– d—–w- c:\program files\Canon
2009-06-27 17:46 . 2009-06-27 17:46 ——– d—–w- c:\program files\Common Files\Canon
2009-06-19 15:59 . 2008-09-19 21:10 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-18 23:11 . 2009-06-12 16:58 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\AVG Security Toolbar
2009-06-18 01:08 . 2008-11-07 17:45 ——– d—–w- c:\program files\The Learning Company
2009-06-16 14:36 . 2006-06-17 09:23 119808 ——w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2006-06-17 09:23 81920 ——w- c:\windows\system32\fontsub.dll
2009-06-13 03:37 . 2009-06-13 03:35 ——– d—–w- c:\documents and settings\My Computer\Application Data\Move Networks
2009-06-12 19:51 . 2009-06-12 19:51 ——– d—–w- c:\documents and settings\My Computer\Application Data\DivX
2009-06-12 19:50 . 2008-11-28 16:01 10684866 —-a-w- c:\documents and settings\My Computer\Application Data\Azureus\plugins\azump\mplayer.exe
2009-06-12 19:50 . 2009-06-12 19:50 ——– d—–w- c:\program files\DivX
2009-06-12 19:50 . 2009-06-12 19:49 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-06-12 19:48 . 2008-11-27 22:09 ——– d—–w- c:\program files\Vuze
2009-06-12 16:58 . 2009-06-12 16:58 ——– d—–w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-11 20:47 . 2009-06-11 20:47 ——– d—–w- c:\program files\Coupons
2009-06-07 06:22 . 2008-09-19 21:10 ——– d—–w- c:\documents and settings\My Computer\Application Data\AVGTOOLBAR
2009-06-07 06:16 . 2009-06-01 06:49 ——– d—–w- c:\program files\Windows Media Connect 2
2009-06-05 21:08 . 2008-10-26 23:03 ——– d—–w- c:\program files\Hasbro Interactive
2009-06-03 19:09 . 2006-06-17 09:23 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-01 16:01 . 2009-04-27 20:23 ——– d—–w- c:\documents and settings\My Computer\Application Data\ZoomBrowser EX
2009-06-01 15:56 . 2009-06-01 15:56 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\ZoomBrowser
2009-05-19 17:03 . 2008-09-19 21:10 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-19 17:03 . 2008-09-19 21:10 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-07 15:32 . 2008-09-19 17:43 345600 ——w- c:\windows\system32\localspl.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-26 17:36 1008896 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
2009-07-20 06:12 2215960 —-a-w- c:\program files\Mininova-Vuze\tbMin0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d51d388b-f5dc-471a-a1ce-5e2d671091c0}"= "c:\program files\Mininova-Vuze\tbMin0.dll" [2009-07-20 2215960]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]

[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D51D388B-F5DC-471A-A1CE-5E2D671091C0}"= "c:\program files\Mininova-Vuze\tbMin0.dll" [2009-07-20 2215960]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]

[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-25 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-25 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-25 114688]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-12-06 9138176]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-10 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-12-22 67752]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl04a\BrStDvPt.exe" [2004-05-25 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"MSxmlHpr"="c:\windows\system32\msxm192z.dll" [2004-08-18 28672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

c:\documents and settings\My Computer\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2009-1-10 225280]
PowerReg Scheduler.exe [2009-3-31 189952]

c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
ImageMixer 3 SE Camera Monitor for SD.lnk - c:\program files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe [2009-5-31 253952]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2008-10-30 815104]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-19 17:03 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Civilization4.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\old harddrive (G)\\old program files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Infogrames Interactive\\Civilization III\\CIV3PTW\\Civilization3X.exe"=
"c:\\Documents and Settings\\My Computer\\Desktop\\games\\Steam\\steamapps\\common\\spaceempiresv\\SE5\\SE5.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1583:TCP"= 1583:TCP:Pervasive DBEngine
"3351:TCP"= 3351:TCP:Pervasive DBEngine

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/19/2008 2:10 PM 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/19/2008 2:10 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/19/2008 2:15 PM 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/19/2008 2:15 PM 298776]
S3 gAGP440p;gAGP440p;\??\c:\docume~1\MYCOMP~1\LOCALS~1\Temp\gAGP440p.sys –> c:\docume~1\MYCOMP~1\LOCALS~1\Temp\gAGP440p.sys [?]
S3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\drivers\MOSUMAC.SYS [9/19/2008 12:16 PM 40448]
S3 WPEServ;soft Xpansion Print2Document;c:\program files\Common Files\WPE\wpeserv.exe [9/19/2008 2:06 PM 323584]
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-*{d51d388b-f5dc-471a-a1ce-5e2d671091c0} - (no file)
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
HKLM-Run-Jgovixejower - c:\windows\umeqinoqoyejamiy.dll
HKLM-Run-SigmatelSysTrayApp - sttray.exe


.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Search;
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{722FE9B2-6895-42D9-9984-F4CB26616023} - {722FE9B2-6895-42D9-9984-F4CB26616023} - c:\program files\Cosmi\Perfect PDF Creator\pdfshell.dll
FF - ProfilePath - c:\docume~1\MYCOMP~1\APPLIC~1\Mozilla\Firefox\Profiles\uor6kyr0.default\
FF - prefs.js: browser.startup.homepage - hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\My Computer\Application Data\Mozilla\Firefox\Profiles\uor6kyr0.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\old harddrive (g)\old program files\Mozilla Firefox\plugins\NPcol305.dll
FF - plugin: c:\old harddrive (g)\old program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\old harddrive (g)\old program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - HiddenExtension: XUL Cache: {AF00CE25-C84A-4B91-95A8-107F77DCF9EE} - c:\documents and settings\My Computer\Local Settings\Application Data\{AF00CE25-C84A-4B91-95A8-107F77DCF9EE}

—- FIREFOX POLICIES —-
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-30 23:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3628)
c:\windows\system32\WININET.dll
c:\windows\system32\msxm192z.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\brss01a.exe
c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Brmfrmps.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\ehome\mcrdsvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-07-31 23:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-31 06:21

Pre-Run: 166,902,882,304 bytes free
Post-Run: 166,891,724,800 bytes free

1612 — E O F — 2009-07-30 15:15
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/Help_started_Windows_Antivirus_Pro_t105628.html
    
    KillAll::
    
    Collect::
    c:\windows\owexujesazuku.dll
    c:\windows\ijipahal.dll
    c:\windows\udegupiditem.dll
    c:\windows\ifatupekamos.dll
    c:\windows\izuhadajakucuraq.dll
    c:\windows\agodahig.dll
    c:\windows\eciwesoz.dll
    c:\windows\ojuvegubelix.dll
    c:\windows\efosaxoga.dll
    c:\windows\itomapesepe.dll
    c:\windows\eyobuhuwonez.dll
    c:\windows\ijoxovab.dll
    c:\windows\afayayiyohuyaga.dll
    c:\windows\oruxezoyipo.dll
    c:\windows\aluwuhuq.dll
    c:\windows\ugubojebuqagetey.dll
    c:\windows\uyefuheli.dll
    c:\windows\edayetas.dll
    c:\windows\ocopuveb.dll
    c:\windows\exasufol.dll
    c:\windows\etadohugili.dll
    c:\windows\icuqilaquvacax.dll
    c:\windows\ewowofehoc.dll
    c:\windows\obebebaguwimu.dll
    c:\windows\awawoluw.dll
    c:\windows\afiyodege.dll
    c:\windows\afiyacik.dll
    c:\windows\ohajijohapuh.dll
    c:\windows\owiquqis.dll
    c:\windows\axipilid.dll
    c:\windows\iwekudat.dll
    c:\windows\ogadopumamajux.dll
    c:\windows\oridojodoh.dll
    c:\windows\ihofiwupuc.dll
    c:\windows\ixibizebuf.dll
    c:\windows\ededibotaxar.dll
    c:\windows\uqugafekute.dll
    c:\windows\otamuyosamav.dll
    c:\windows\abewaruyumogavim.dll
    c:\windows\imecuxiq.dll
    c:\windows\awufuwejatazaleb.dll
    c:\windows\edibufisawanulam.dll
    c:\windows\exovadazaderirif.dll
    c:\windows\upisavadebib.dll
    c:\windows\obaferab.dll
    c:\windows\ojozehobiq.dll
    c:\windows\ahobimon.dll
    c:\windows\ohibopitucigenog.dll
    c:\windows\exacikotadoq.dll
    c:\windows\ocubicitaqun.dll
    c:\windows\esumobelisuz.dll
    c:\windows\exeqobacagayus.dll
    c:\windows\uwohinal.dll
    c:\windows\ojibexuyiru.dll
    c:\windows\uforatiqefa.dll
    c:\windows\inugohewat.dll
    c:\windows\izabevaxitig.dll
    c:\windows\ufugohew.dll
    c:\windows\eraducenafidaco.dll
    c:\windows\system32\bincd32.dat
    c:\windows\Ctuwihuvuwox.dat
    c:\windows\system32\wingenocx.dll
    c:\windows\ppp4.dat
    c:\windows\ppp3.dat
    c:\windows\system32\sysnet.dat
    C:\uynrr.exe
    c:\windows\system32\msxm192z.dll
    
    Folder::
    c:\program files\Mininova-Vuze
    
    Driver:: 
    gAGP440p
    
    Registry:: 
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{d51d388b-f5dc-471a-a1ce-5e2d671091c0}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{D51D388B-F5DC-471A-A1CE-5E2D671091C0}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSxmlHpr"=-
    
    Firefox::
    FF - ProfilePath - c:\docume~1\MYCOMP~1\APPLIC~1\Mozilla\Firefox\Profiles\uor6kyr0.default\
    FF - HiddenExtension: XUL Cache: {AF00CE25-C84A-4B91-95A8-107F77DCF9EE} - c:\documents and settings\My Computer\Local Settings\Application Data\{AF00CE25-C84A-4B91-95A8-107F77DCF9EE}
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into CombFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI