This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Search engine is redirected

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I am a total newbie when it comes to removing/fixing viruses. My computer has been infected and giving me the following symptoms.
1) Search engines are redirected to random sites
2) Windows Media Player cannot find my burner
3) My disc drive spins hard even when the computer is closed
4) The computer will often get the "blue screen of death".

Here is my log. Thanks for any help!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:22:59 PM, on 8/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\1186906696\ee\AOLSoftware.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\common files\aol\1186906696\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1186906696\EE\aolsoftware.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 68.44.244.240 idenupdate.motorola.com
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /installquiet /nodetect
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\CHDAudPropShortcut.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QlbCtrl] "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [Cpqset] "C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe"
O4 - HKLM\..\Run: [RecGuard] "C:\Windows\SMINST\RecGuard.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ehTray] "C:\WINDOWS\ehome\ehtray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1186906696\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] "C:\PROGRA~1\McAfee\MHN\McENUI.exe" /hide
O4 - HKLM\..\Run: [KernelFaultCheck] "C:\WINDOWS\system32\dumprep.exe" 0 -k
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI8CBC~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=presario&pf=laptop
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.putfile.com/includes/ImageUploader4-5.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter hijack: text/html - {2e25b3ae-c15f-4a6a-85b7-2f8d43cf68a4} - C:\WINDOWS\system32\msziptools.dll
O20 - AppInit_DLLs: cru629.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: khfdaya - khfdaya.dll (file missing)
O20 - Winlogon Notify: urqPfDVO - urqPfDVO.dll (file missing)
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 12670 bytes
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Note: You may need to run these scans in safe mode if they will not run in normal mode
Thank you for your assistance CatByte. I have both the DDS and the Attach txt files, but when I did the rootkit scan (following the instructions you posted) it keeps freezing the computer. Any idea?
Hi,

Try running GMER in safe mode.

If it still will not run, try this program instead

Please download Sysprot Antirootkit from >>>HERE<<<

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select ALL ITEMS
  • Look near the bottom left, and Check Hidden Objects Only
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.
Here is the the Attach txt


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/10/2007 11:37:28 PM
System Uptime: 8/7/2009 8:14:19 PM (16 hours ago)

Motherboard: Quanta | | 30B7
Processor: AMD Turion™ 64 X2 Mobile Technology TL-50 | Socket S1 | 1607/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 81 GiB total, 23.292 GiB free.
D: is FIXED (FAT32) - 11 GiB total, 1.227 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP252: 7/9/2009 10:08:57 PM - System Checkpoint
RP253: 7/9/2009 10:08:57 PM - System Checkpoint
RP254: 7/9/2009 10:08:57 PM - System Checkpoint
RP255: 7/9/2009 10:08:58 PM - Software Distribution Service 3.0
RP256: 7/9/2009 10:08:58 PM - System Checkpoint
RP257: 7/9/2009 10:08:58 PM - System Checkpoint
RP258: 7/9/2009 10:08:59 PM - System Checkpoint
RP259: 7/9/2009 10:08:59 PM - Installed QuickTime
RP260: 7/9/2009 10:08:59 PM - System Checkpoint
RP261: 7/9/2009 10:08:59 PM - System Checkpoint
RP262: 7/9/2009 10:09:00 PM - System Checkpoint
RP263: 7/9/2009 10:09:00 PM - System Checkpoint
RP264: 7/9/2009 10:09:00 PM - System Checkpoint
RP265: 7/9/2009 10:09:01 PM - System Checkpoint
RP266: 7/9/2009 10:09:01 PM - System Checkpoint
RP267: 7/9/2009 10:09:01 PM - System Checkpoint
RP268: 7/9/2009 10:09:01 PM - System Checkpoint
RP269: 7/9/2009 10:09:02 PM - System Checkpoint
RP270: 7/9/2009 10:09:02 PM - System Checkpoint
RP271: 7/9/2009 10:09:02 PM - System Checkpoint
RP272: 7/9/2009 10:09:02 PM - Software Distribution Service 3.0
RP273: 7/9/2009 10:09:02 PM - System Checkpoint
RP274: 7/9/2009 10:09:03 PM - System Checkpoint
RP275: 7/9/2009 10:09:03 PM - System Checkpoint
RP276: 7/9/2009 10:09:03 PM - System Checkpoint
RP277: 7/9/2009 10:09:03 PM - System Checkpoint
RP278: 7/9/2009 10:09:03 PM - System Checkpoint
RP279: 7/9/2009 10:09:04 PM - System Checkpoint
RP280: 7/9/2009 10:09:04 PM - System Checkpoint
RP281: 7/9/2009 10:09:04 PM - System Checkpoint
RP282: 7/9/2009 10:09:04 PM - System Checkpoint
RP283: 7/9/2009 10:09:04 PM - System Checkpoint
RP284: 7/9/2009 10:09:05 PM - System Checkpoint
RP285: 7/9/2009 10:09:05 PM - System Checkpoint
RP286: 7/9/2009 10:09:05 PM - System Checkpoint
RP287: 7/9/2009 10:09:06 PM - System Checkpoint
RP288: 7/9/2009 10:09:06 PM - System Checkpoint
RP289: 7/9/2009 10:09:06 PM - System Checkpoint
RP290: 7/9/2009 10:09:07 PM - System Checkpoint
RP291: 7/9/2009 10:09:07 PM - Software Distribution Service 3.0
RP292: 7/9/2009 10:09:07 PM - Software Distribution Service 3.0
RP293: 7/9/2009 10:09:08 PM - System Checkpoint
RP294: 7/9/2009 10:09:08 PM - System Checkpoint
RP295: 7/9/2009 10:09:08 PM - System Checkpoint
RP296: 7/9/2009 10:09:08 PM - System Checkpoint
RP297: 7/9/2009 10:09:09 PM - System Checkpoint
RP298: 7/9/2009 10:09:09 PM - System Checkpoint
RP299: 7/9/2009 10:09:09 PM - System Checkpoint
RP300: 7/9/2009 10:09:10 PM - System Checkpoint
RP301: 7/9/2009 10:09:10 PM - System Checkpoint
RP302: 7/9/2009 10:09:10 PM - System Checkpoint
RP303: 7/9/2009 10:09:10 PM - System Checkpoint
RP304: 7/9/2009 10:09:11 PM - System Checkpoint
RP305: 7/9/2009 10:09:11 PM - System Checkpoint
RP306: 7/9/2009 10:09:11 PM - System Checkpoint
RP307: 7/9/2009 10:09:11 PM - System Checkpoint
RP308: 7/9/2009 10:09:11 PM - System Checkpoint

==== Installed Programs ======================


5 Card Slingo from Hewlett-Packard Laptops (remove only)
Adobe Flash Player 10 ActiveX
Adobe Photoshop 7.0
Adobe Reader 7.0.5
Adobe Shockwave Player 11
Amazing Slow Downer (remove only)
America Online (Choose which version to remove)
AOL Coach Version 2.0(Build:20041026.5 en)
AOL Toolbar for Firefox
AOL Toolbar for Internet Explorer
AOL Uninstaller
AOL You've Got Pictures Screensaver
Apple Mobile Device Support
Apple Software Update
Audacity 1.2.6
AutoUpdate
Azureus Vuze
Bejeweled 2 Deluxe from Hewlett-Packard Laptops (remove only)
Big Kahuna Reef from Hewlett-Packard Laptops (remove only)
BlackBerry Desktop Software 4.3
BlackBerry Device Software v4.5.0 for the BlackBerry 8330 smartphone
Blackhawk Striker 2 from Hewlett-Packard Laptops (remove only)
Blasterball 2 from Hewlett-Packard Laptops (remove only)
Boggle Supreme from Hewlett-Packard Laptops (remove only)
Bonjour
Bookworm Deluxe from Hewlett-Packard Laptops (remove only)
Bounce Symphony from Hewlett-Packard Laptops (remove only)
BufferChm
Chuzzle Deluxe from Hewlett-Packard Laptops (remove only)
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
Critical Update for Windows Media Player 11 (KB959772)
Crystal Maze from Hewlett-Packard Laptops (remove only)
CueTour
Customer Experience Enhancement
Destinations
Dev-C++ 5 beta 9 release (4.9.9.2)
DeviceManagementQFolder
DivX
DivX Content Uploader
Download Updater (AOL LLC)
Easy Internet Sign-up
ESPNMotion
Family Feud™
FATE from Hewlett-Packard Laptops (remove only)
Final Drive Nitro from Hewlett-Packard Laptops (remove only)
Flip Words from Hewlett-Packard Laptops (remove only)
Free M4a to MP3 Converter 6.0
FullDPAppQFolder
Garmin Communicator Plugin
GemMaster Mystic
GoodOk Video Converter Gold 5.0
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
HP Game Console and games
HP Help and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Quick Launch Buttons 6.10 A2
HP QuickPlay 2.3
HP Rhapsody
HP Update
HP User Guides 0031
HP Wireless Assistant 2.00 G2
HpSdpAppCoreApp
Insaniquarium Deluxe from Hewlett-Packard Laptops (remove only)
InstantShareDevices
iTunes
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.0_02
Java 2 SDK, SE v1.4.0_02
Java™ 6 Update 11
Java™ 6 Update 7
Jewel Quest from Hewlett-Packard Laptops (remove only)
KeepV Flash Converter
Lemonade Tycoon 2 from Hewlett-Packard Laptops (remove only)
Lexibox Deluxe from Hewlett-Packard Laptops (remove only)
Lexmark Z700-P700 Series
LightScribe 1.4.97.1
LimeWire 4.18.8
LiveUpdate (Symantec Corporation)
Logitech Gaming Software
Macromedia Flash Player 8
Macromedia Shockwave Player
Mah Jong Quest from Hewlett-Packard Laptops (remove only)
McAfee SecurityCenter
McAfee Virtual Technician
Media Downloader
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2006
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Premium
Microsoft Office Standard Edition 2003
Microsoft Office XP Professional with FrontPage
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (2.0.0.20)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
muvee autoProducer 5.0
Netscape Browser (remove only)
NetWaiting
Norton Security Scan
NVIDIA Drivers
Oasis from Hewlett-Packard Laptops (remove only)
Office 2003 Trial Assistant
OptionalContentQFolder
Otto
PhotoGallery
pluginCreativity textArt
Polar Bowler from Hewlett-Packard Laptops (remove only)
Polar Golfer from Hewlett-Packard Laptops (remove only)
Project64 1.6
PSP Video 9 2.25
Puzzle Express from Hewlett-Packard Laptops (remove only)
Quicken 2006
QuickTime
RandMap
RealArcade
RealPlayer
Roxio Media Manager
SCRABBLE from Hewlett-Packard Laptops (remove only)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
SkinsHP1
Slingo Deluxe from Hewlett-Packard Laptops (remove only)
SlowGold
Slyder from Hewlett-Packard Laptops (remove only)
Snowboard SuperJam
Soft Data Fax Modem with SmartCP
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic Foundry ACID 4.0
Sonic MyDVD Plus
Sonic Update Manager
Sonic_PrimoSDK
SonicAC3Encoder
SonicMPEGEncoder
Sony ACID Music Studio 5.0
Sony ACID Music Studio 7.0
Spy Sweeper
Spy Sweeper Core
SqrSoft® Advanced Crossfading (remove only)
Super Granny from Hewlett-Packard Laptops (remove only)
SUPERAntiSpyware Free Edition
Synaptics Pointing Device Driver
TourSetup
Tradewinds from Hewlett-Packard Laptops (remove only)
Unload
Unreal Tournament
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player
Vongo
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Media Center Edition 2005 KB925766
Windows XP Service Pack 3
WinZip 12.0
Wireless Home Network Setup
Yahoo! Toolbar
Yahoo! Toolbar for Internet Explorer
Zuma Deluxe from Hewlett-Packard Laptops (remove only)

==== Event Viewer Messages From Past Week ========

8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The LexBce Server service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Automatic LiveUpdate Scheduler service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The AOL TopSpeed Monitor service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
8/7/2009 11:58:31 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the mcmscsvc service.
8/7/2009 11:15:18 AM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
8/7/2009 11:13:04 AM, error: System Error [1003] - Error code 100000d1, parameter1 e1f51000, parameter2 00000002, parameter3 00000000, parameter4 ed8a2125.
8/6/2009 6:54:38 AM, error: ACPIEC [1] - \Device\ACPIEC: The embedded controller (EC) hardware didn't respond within the timeout period. This may indicate an error in the EC hardware or firmware, or possibly a poorly designed BIOS which accesses the EC in an unsafe manner. The EC driver will retry the failed transaction if possible.
8/6/2009 10:11:23 AM, error: System Error [1003] - Error code 100000d1, parameter1 e1f49000, parameter2 00000002, parameter3 00000000, parameter4 ed807125.
8/6/2009 10:10:50 AM, error: System Error [1003] - Error code 100000d1, parameter1 e1f4d000, parameter2 00000002, parameter3 00000000, parameter4 ed8ac125.
8/5/2009 10:55:09 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
8/4/2009 12:50:30 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service hpqwmiex with arguments "-Service" in order to run the server: {F5539356-2F02-40D4-999E-FA61F45FE12E}
8/3/2009 5:41:27 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Bonjour Service service.
8/3/2009 4:25:03 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
8/3/2009 2:06:43 PM, error: LDMS [3023] - The Logical Disk Manager Service failed while registering for device handle notifications on device \\?\ide#cdromhl-dt-st_dvdram_gsa-4084n_______________kq09____#304b363253383446323520392020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}. Win32 Error: 1381.
8/3/2009 2:05:54 PM, error: Dhcp [1002] - The IP address lease 192.168.0.11 for the Network Card with network address 001A735C089F has been denied by the DHCP server 10.34.36.20 (The DHCP Server sent a DHCPNACK message).
8/1/2009 4:46:49 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\twunk_32.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 1.7.1.0.
8/1/2009 4:46:49 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\twunk_16.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.1.7.
8/1/2009 4:46:49 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\twain_32.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 1.7.1.1.
8/1/2009 4:46:29 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file twunk_32.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 1.7.1.0.
8/1/2009 4:46:29 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file twunk_16.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.1.7.
8/1/2009 4:46:29 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file twain_32.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 1.7.1.1.
8/1/2009 4:46:29 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file twain.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.1.7.

==== End Of File ===========================












Here is the DDS txt


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 12:27:37.42 on Sat 08/08/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.351 [GMT -4:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\1186906696\ee\AOLSoftware.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\common files\aol\1186906696\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1186906696\EE\aolsoftware.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Documents and Settings\YM\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.aol.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
uURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol toolbar\aoltb.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler
uRun: [AOL Fast Start] "c:\program files\america online 9.0a\AOL.EXE" -b
uRun: [SUPERAntiSpyware] "c:\program files\superantispyware\SUPERAntiSpyware.exe"
uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe"
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nwiz] "c:\windows\system32\nwiz.exe" /installquiet /nodetect
mRun: [High Definition Audio Property Page Shortcut] "c:\windows\system32\CHDAudPropShortcut.exe"
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [QlbCtrl] "c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe" /Start
mRun: [Cpqset] "c:\program files\hewlett-packard\default settings\cpqset.exe"
mRun: [RecGuard] "c:\windows\sminst\RecGuard.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [ehTray] "c:\windows\ehome\ehtray.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HostManager] "c:\program files\common files\aol\1186906696\ee\AOLSoftware.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] "c:\progra~1\mcafee\mhn\McENUI.exe" /hide
mRun: [KernelFaultCheck] "c:\windows\system32\dumprep.exe" 0 -k
mRun: [SpySweeper] "c:\program files\webroot\spy sweeper\SpySweeperUI.exe" /startintray
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: &AOL Toolbar Search - c:\documents and settings\all users\application data\aol\ietoolbar\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi8cbc~1\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: cmgsccc.com\forums
Trusted Zone: cmgsccc.com\www
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: microsoft.com\www
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} - hxxp://www.putfile.com/includes/ImageUploader4-5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_0_02-win.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Filter: text/html - {2e25b3ae-c15f-4a6a-85b7-2f8d43cf68a4} -
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: khfdaya - khfdaya.dll
Notify: urqPfDVO - urqPfDVO.dll
AppInit_DLLs: cru629.dat
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29808]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-13 214024]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-7-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-7-28 74480]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-7-30 210216]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-7-30 359952]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-6 99328]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-7-30 144704]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2008-8-9 3585384]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-7-30 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-7-30 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-7-30 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-7-30 40552]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-7-28 7408]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-7-30 34248]

=============== Created Last 30 ================

2009-08-07 12:22 –d—– c:\program files\Trend Micro
2009-08-07 11:52 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-07 11:51 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-07 11:51 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-01 17:13 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-08-01 17:13 –d—– c:\program files\SUPERAntiSpyware
2009-08-01 17:13 –d—– c:\docume~1\ym\applic~1\SUPERAntiSpyware.com
2009-08-01 17:13 –d—– c:\program files\common files\Wise Installation Wizard
2009-07-31 03:41 4,224 a——- c:\windows\system32\drivers\beep.sys
2009-07-31 03:41 4,224 a——- c:\windows\system32\dllcache\beep.sys
2009-07-31 00:06 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2009-07-30 22:56 –d—– c:\docume~1\ym\applic~1\McAfee
2009-07-30 22:44 10,947 a——- c:\windows\system32\Config.MPF
2009-07-30 22:40 120,136 a——- c:\windows\system32\drivers\Mpfp.sys
2009-07-30 22:39 –d—– c:\program files\common files\McAfee
2009-07-30 22:39 –d—– c:\program files\McAfee.com
2009-07-30 22:39 –d—– c:\program files\McAfee
2009-07-30 21:44 17,245 a——- c:\windows\abus.inf
2009-07-30 21:44 15,937 a——- c:\windows\resesifuqa._dl
2009-07-30 21:44 14,597 a——- c:\windows\naby.dll
2009-07-30 21:44 14,293 a——- c:\windows\yrofogajo.inf
2009-07-30 21:44 12,772 a——- c:\windows\system32\toram._sy
2009-07-30 21:44 10,847 a——- c:\windows\wubagocut.com
2009-07-30 21:44 18,143 a——- c:\docume~1\ym\applic~1\nynugy.dll
2009-07-30 21:44 17,914 a——- c:\windows\system32\icesix.pif
2009-07-30 21:44 10,538 a——- c:\windows\rixyrene.bin
2009-07-30 21:44 13,279 a——- c:\docume~1\alluse~1\applic~1\omijovivit.scr
2009-07-30 21:44 11,565 a——- c:\program files\common files\ehut.bat
2009-07-30 20:55 –d—– c:\program files\SiteAdvisor
2009-07-30 20:50 79,816 a——- c:\windows\system32\drivers\mfeavfk.sys
2009-07-30 20:50 40,552 a——- c:\windows\system32\drivers\mfesmfk.sys
2009-07-30 20:50 35,272 a——- c:\windows\system32\drivers\mfebopk.sys
2009-07-30 20:43 34,248 a——- c:\windows\system32\drivers\mferkdk.sys
2009-07-30 17:42 13,701 a——- c:\windows\esan.dl
2009-07-30 17:42 18,985 a——- c:\docume~1\ym\applic~1\gimu.vbs
2009-07-30 17:42 16,369 a——- c:\docume~1\alluse~1\applic~1\ewipexipyn.dat
2009-07-30 17:42 12,963 a——- c:\windows\agysa._dl
2009-07-30 17:42 12,314 a——- c:\windows\system32\odihovem.dl
2009-07-30 17:42 10,464 a——- c:\windows\lutapuwuv.com
2009-07-30 14:21 –d—– c:\windows\system32\XPSViewer
2009-07-30 14:20 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-30 14:20 117,760 ——– c:\windows\system32\prntvpt.dll
2009-07-30 14:20 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-30 14:20 –d—– C:\cafb9a9195d6889cb52c42
2009-07-30 14:20 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-07-30 14:20 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-07-30 14:20 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-07-30 14:20 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-07-23 22:13 –d—– C:\55f0d3035756f0da675d54e340ab
2009-07-23 22:13 –d—– C:\1e96c55cfa17680f76a495e58a0580
2009-07-23 22:12 –d—– C:\54bfe5b8bcb610cab098a8e9f5
2009-07-23 22:11 –d—– C:\3423bcd4be0e6c711d2c310b0c
2009-07-16 03:15 –d—– c:\program files\Shared

==================== Find3M ====================

2009-07-30 21:44 11,814 a——- c:\program files\common files\zulifibo._dl
2009-07-30 21:44 19,752 a——- c:\program files\common files\tyco.ban
2009-07-30 21:44 16,602 a——- c:\program files\common files\ucolyjupad.inf
2009-07-30 21:44 10,998 a——- c:\program files\common files\yxejygiko._sy
2009-07-30 17:42 12,972 a——- c:\program files\common files\ygib._dl
2009-07-30 17:42 15,933 a——- c:\program files\common files\canus.dl
2009-07-19 09:33 3,597,824 ——– c:\windows\system32\dllcache\mshtml.dll
2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll
2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 04:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe
2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat
2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-16 10:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 10:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll
2009-03-19 23:29 85,912 a——- c:\docume~1\ym\applic~1\GDIPFONTCACHEV1.DAT
2009-02-28 00:57 256 a——- c:\docume~1\ym\applic~1\wklnhst.dat
2009-02-21 19:08 256 a——- c:\documents and settings\ym\pool.bin
2007-08-16 13:32 439,296 a——- c:\documents and settings\ym\GoToAssist_phone__317_en.exe
2007-12-27 20:18 266,652 a–sh— c:\windows\system32\ybeeg.ini2
2008-12-10 18:57 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121020081211\index.dat

============= FINISH: 12:30:29.09 ===============








Ok here is the SysProt log:

SysProt AntiRootkit v1.0.1.0
by swatkat

********************************************************************************
**********
********************************************************************************
**********

No Hidden Processes found

********************************************************************************
**********
********************************************************************************
**********
Kernel Modules:
Module Name: \systemroot\system32\drivers\hjgruixkneyydp.sys
Service Name: hjgruikjvmhcac
Module Base: —
Module End: —
Hidden: Yes

Module Name: spfc.sys
Service Name: —
Module Base: F7286000
Module End: F7386000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\argkd36k.SYS
Service Name: —
Module Base: F5EEC000
Module End: F5F23000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_nvata.sys
Service Name: —
Module Base: EC1DF000
Module End: EC1F8000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: —
Module Base: F79E1000
Module End: F79E3000
Hidden: Yes

********************************************************************************
**********
********************************************************************************
**********
No SSDT Hooks found

********************************************************************************
**********
********************************************************************************
**********
Kernel Hooks:
Hooked Function: ZwYieldExecution
At Address: 80504AE8
Jump To: EC235518
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwUnmapViewOfSection
At Address: 805B2E14
Jump To: EC235544
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwUnloadKey
At Address: 80622060
Jump To: EC23564C
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwTerminateProcess
At Address: 805D29AA
Jump To: EC23555D
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwSetValueKey
At Address: 80621D36
Jump To: EC2355DB
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwSetInformationProcess
At Address: 805CDE52
Jump To: EC2354C6
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwSetContextThread
At Address: 805D1702
Jump To: EC2354DA
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwRestoreKey
At Address: 80625168
Jump To: EC235676
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwReplaceKey
At Address: 8062585C
Jump To: EC23568A
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwRenameKey
At Address: 806231D2
Jump To: EC2355AF
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwQueryValueKey
At Address: 806219E8
Jump To: EC2355F1
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwQueryMultipleValueKey
At Address: 806228FE
Jump To: EC235607
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwQueryKey
At Address: 80624EA8
Jump To: EC23569E
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwProtectVirtualMemory
At Address: 805B83E6
Jump To: EC235502
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwOpenThread
At Address: 805CB694
Jump To: EC235488
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwOpenProcess
At Address: 805CB408
Jump To: EC235474
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwOpenKey
At Address: 80624B82
Jump To: EC235571
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwNotifyChangeKey
At Address: 80625976
Jump To: EC235662
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwMapViewOfSection
At Address: 805B2006
Jump To: EC23552E
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwFlushInstructionCache
At Address: 805B6812
Jump To: 85FDB384
Module Name: _unknown_

Hooked Function: ZwEnumerateValueKey
At Address: 8062425A
Jump To: EC23561D
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwEnumerateKey
At Address: 80623FF0
Jump To: EC235638
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwDeleteValueKey
At Address: 80623E10
Jump To: EC2355C5
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwDeleteKey
At Address: 80623C40
Jump To: EC235599
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwCreateProcessEx
At Address: 805D1142
Jump To: EC2354B0
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwCreateProcess
At Address: 805D11F8
Jump To: EC23549C
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwCreateKey
At Address: 806237B0
Jump To: EC235585
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: ZwCreateFile
At Address: 80579084
Jump To: EC2354EE
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: PsCreateSystemThread
At Address: 805D1142
Jump To: EC2354B0
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: PsCreateSystemProcess
At Address: 805D11F8
Jump To: EC23549C
Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

Hooked Function: IofCompleteRequest
At Address: 804EF236
Jump To: 8614FC6B
Module Name: _unknown_

Hooked Function: IofCallDriver
At Address: 804EF1A6
Jump To: 86149E7B
Module Name: _unknown_

********************************************************************************
**********
********************************************************************************
**********
IRP Hooks:
Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_READ
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_SET_EA
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\nvata.sys
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: 864481F8
Hooking Module: _unknown_

Hooked Module: \SystemRoot\System32\Drivers\argkd36k.SYS
Hooked IRP: IRP_MJ_CREATE
Jump To: 862211F8
Hooking Module: _unknown_

Hooked Module: \SystemRoot\System32\Drivers\argkd36k.SYS
Hooked IRP: IRP_MJ_CLOSE
Jump To: 862211F8
Hooking Module: _unknown_

Hooked Module: \SystemRoot\System32\Drivers\argkd36k.SYS
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 862211F8
Hooking Module: _unknown_

Hooked Module: \SystemRoot\System32\Drivers\argkd36k.SYS
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 862211F8
Hooking Module: _unknown_

Hooked Module: \SystemRoot\System32\Drivers\argkd36k.SYS
Hooked IRP: IRP_MJ_POWER
Jump To: 862211F8
Hooking Module: _unknown_

Hooked Module: \SystemRoot\System32\Drivers\argkd36k.SYS
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 862211F8
Hooking Module: _unknown_

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CLOSE
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_READ
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_WRITE
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_EA
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CLEANUP
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_POWER
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: F7287000
Hooking Module: spfc.sys

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_READ
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 864491F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbohci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 84CF41F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbohci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 84CF41F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbohci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 84CF41F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbohci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 84CF41F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbohci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 84CF41F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbohci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 84CF41F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_READ
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 863D91F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 856301F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 856301F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 856301F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 856301F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 856301F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_READ
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 862F51F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 85FB0E00
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: 8615F348
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8615C428
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_READ
Jump To: 8615BBB8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 8615B200
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: 8615B448
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: 85FB0670
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: 86155B90
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_SET_EA
Jump To: 861551A0
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 86154500
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: 86153C90
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: 86241A28
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: 8615C968
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: 85E9D238
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 85FC51C0
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 85F220A8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 861866E0
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: 85FD2520
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 85D836F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: 85E9B2E8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: 85ACB2F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: 85F2F730
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 8623D2F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8623D280
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: 862B9BB8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: 862B9B40
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: 85E65278
Hooking Module: _unknown_

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_CREATE
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_CLOSE
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_READ
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_WRITE
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_SET_EA
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_CLEANUP
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_POWER
Jump To: F728EE1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: F72A3514
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: \Driver\PCI_PNP8788
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: F72CAB1C
Hooking Module: spfc.sys

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 84C041F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 84C041F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 84C041F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 84C041F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 84C041F8
Hooking Module: _unknown_

Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 84C041F8
Hooking Module: _unknown_

********************************************************************************
**********
********************************************************************************
**********
Ports:
Local Address: YM.HOME:1106
Remote Address: PROXY-MTC-F.PROXY.AOL.COM:5192
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: ESTABLISHED

Local Address: YM.HOME:1095
Remote Address: 205.188.7.230:5190
Type: TCP
Process: C:\Program Files\America Online 9.0a\waol.exe
State: ESTABLISHED

Local Address: YM.HOME:1090
Remote Address: PROXY-MTC-F.PROXY.AOL.COM:5192
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: ESTABLISHED

Local Address: YM.HOME:1082
Remote Address: ATS-MCC.DIAL.AOL.COM:5190
Type: TCP
Process: C:\Program Files\America Online 9.0a\waol.exe
State: ESTABLISHED

Local Address: YM.HOME:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: YM:27015
Remote Address: LOCALHOST:1026
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED

Local Address: YM:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING

Local Address: YM:11533
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:11532
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:11531
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:11530
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:11529
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:11528
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:11527
Remote Address: LOCALHOST:1312
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1311
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1309
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1308
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1307
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1306
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1305
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1304
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1303
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1302
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1301
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1300
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: LOCALHOST:1296
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11527
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:11526
Remote Address: LOCALHOST:1316
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11526
Remote Address: LOCALHOST:1314
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11526
Remote Address: LOCALHOST:1313
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11526
Remote Address: LOCALHOST:1310
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT

Local Address: YM:11526
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:11500
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
State: LISTENING

Local Address: YM:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING

Local Address: YM:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING

Local Address: YM:1049
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\alg.exe
State: LISTENING

Local Address: YM:1026
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED

Local Address: YM:6646
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
State: LISTENING

Local Address: YM:2869
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING

Local Address: YM:2107
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\mqsvc.exe
State: LISTENING

Local Address: YM:2105
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\mqsvc.exe
State: LISTENING

Local Address: YM:2103
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\mqsvc.exe
State: LISTENING

Local Address: YM:1801
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\mqsvc.exe
State: LISTENING

Local Address: YM:1037
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\mqsvc.exe
State: LISTENING

Local Address: YM:1025
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\LEXPPS.EXE
State: LISTENING

Local Address: YM:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: YM:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING

Local Address: YM.HOME:6646
Remote Address: NA
Type: UDP
Process: C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
State: NA

Local Address: YM.HOME:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: YM.HOME:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: YM.HOME:138
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: YM.HOME:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: YM.HOME:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: YM:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: YM:1096
Remote Address: NA
Type: UDP
Process: C:\Program Files\America Online 9.0a\waol.exe
State: NA

Local Address: YM:1083
Remote Address: NA
Type: UDP
Process: C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
State: NA

Local Address: YM:1062
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: YM:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: YM:51235
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: YM:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA

Local Address: YM:3776
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\ehome\mcrdsvc.exe
State: NA

Local Address: YM:3527
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\mqsvc.exe
State: NA

Local Address: YM:1036
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\mqsvc.exe
State: NA

Local Address: YM:1028
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: YM:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA

Local Address: YM:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA

********************************************************************************
**********
********************************************************************************
**********
Hidden files/folders:
Object: C:\959b454a5694eac5f353a33843f5\update\update.exe
Status: Access denied

Object: C:\Documents and Settings\YM\Local Settings\Temp\Temporary Internet Files\Content.IE5\0P2N81YF\%3D402036343%26cat%3D3%26ged%3D0%3A0%3Amzjhnweyyjqwyji3ymvlywz-qe2ux5l5k4x68p7i9-nek6awxsw8lb9fovywvd-ohbxx58v8fggzr1b0uvjnzf2dhkru8m57jd574j3tlhabxgzsonbye9crs
Status: Hidden

Object: C:\Documents and Settings\YM\Local Settings\Temp\Temporary Internet Files\Content.IE5\894XQB4D\main_6;sz=480x70;!c=6;kvid=BC_PtGb0v-o;kpu=universalmusicgroup;kar=3;kgender=m;ko=p;kpid=6;kr=F;k1=hip%20hop;u=BC_PtGb0v-o_6_042FCFB466F4BFEA;kt=U;kage=19;tile=
Status: Hidden

Object: C:\Documents and Settings\YM\Local Settings\Temp\Temporary Internet Files\Content.IE5\ERKPAB8V\CA7DAV1I.com%2Fbentley%2Fforums%2F&lmt=1205189450&dt=1195789851234&cc=243&u_h=800&u_w=1280&u_ah=766&u_aw=1280&u_cd=32&u_tz=-480&u_his=1&u_java=true&u_nplug=0&u_
Status: Hidden

Object: C:\Documents and Settings\YM\Local Settings\Temp\Temporary Internet Files\Content.IE5\F7TJZXOO\dref=http%253A%252F%252Fsubtracts.userplane[1].html%253FdomainID%253Dnone%2526app%253Dwc%2526zoneID%253D156%2526clickID%253Da716e68b%2526js_refresh%253D11960457
Status: Hidden

Object: C:\Documents and Settings\YM\Local Settings\Temp\Temporary Internet Files\Content.IE5\F7TJZXOO\main_6;sz=480x70;!c=6;kvid=mK3rVKcQbiM;kpu=universalmusicgroup;kar=3;kgender=m;ko=p;kpid=6;kr=
F;u=mK3rVKcQbiM_6_98ADEB54A7106E23;kt=U;kage=19;tile=1;dcopt=ist;o
Status: Hidden

Object: C:\Documents and Settings\YM\Local Settings\Temp\Temporary Internet Files\Content.IE5\SBJBUW9D\main_6;sz=300x250;!c=6;kvid=BC_PtGb0v-o;kpu=universalmusicgroup;kar=3;kgender=m;ko=p;kpid=6;kr=F;k1=hip%20hop;u=BC_PtGb0v-o_6_042FCFB466F4BFEA;kt=U;kage=19;tile
Status: Hidden

Object: C:\Documents and Settings\YM\Local Settings\Temp\Temporary Internet Files\Content.IE5\SBJBUW9D\main_6;sz=300x250;!c=6;kvid=mK3rVKcQbiM;kpu=universalmusicgroup;kar=3;kgender=m;ko=p;kpid=6;kr=
F;u=mK3rVKcQbiM_6_98ADEB54A7106E23;kt=U;kage=19;tile=1;dcopt=ist;
Status: Hidden

Object: C:\Documents and Settings\YM\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMRO52V\CAHSAFPK.com%2Fbentley%2Fforums%2F&lmt=1205189450&dt=1195789851890&cc=99&u_h=800&u_w=1280&u_ah=766&u_aw=1280&u_cd=32&u_tz=-480&u_his=1&u_java=true&u_nplug=0&u_n
Status: Hidden

Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied

Object: C:\System Volume Information\tracking.log
Status: Access denied

Object: C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}
Status: Access denied

Object: C:\WINDOWS\system32\drivers\hjgruixkneyydp.sys
Status: Hidden

Object: C:\WINDOWS\system32\hjgruimrfohwad.dat
Status: Hidden

Object: C:\WINDOWS\system32\hjgruiqppcixfn.dat
Status: Hidden

Object: C:\WINDOWS\system32\hjgruiqvnlkaat.dll
Status: Hidden

Object: C:\WINDOWS\system32\hjgruiyfgphouk.dll
Status: Hidden

Object: C:\WINDOWS\temp\hjgruikricxmlkai.tmp
Status: Hidden

Object: C:\WINDOWS\temp\hjgruiowpslultcb.tmp
Status: Hidden

Object: C:\WINDOWS\temp\hjgruisxdaulssjx.tmp
Status: Hidden

Object: C:\WINDOWS\temp\hjgruiukpavxukel.tmp
Status: Hidden

Object: C:\WINDOWS\temp\hjgruiwusikqlnxi.tmp
Status: Hidden

Object: C:\WINDOWS\temp\hjgruiymxxqpyrax.tmp
Status: Hidden
Hi,

You have a nasty rootkit infection on board.

This type of infection allows hackers to remotely control your computer, steal critical system information and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?


Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Here is the Combo-Fix text

ComboFix 09-08-07.09 - YM 08/08/2009 16:29.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.543 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\YM\Temporary Internet Files\jyfygeguwy.bat
c:\documents and settings\YM\Temporary Internet Files\udejoxuhe._dl
c:\documents and settings\YM\Temporary Internet Files\yruvakawu.dll
c:\program files\Common
c:\program files\Common\_helper.sig
c:\program files\Common\helper.sig
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\bkR11
c:\temp\bkR11\ftCa.log
c:\windows\010112010146118114.dat
c:\windows\0101120101465349.dat
c:\windows\0101120101465749.dat
c:\windows\b4657.dat
c:\windows\jmmark2.dat
c:\windows\kb913800.exe
c:\windows\system32\drivers\hjgruixkneyydp.sys
c:\windows\system32\hjgruimrfohwad.dat
c:\windows\system32\hjgruiqppcixfn.dat
c:\windows\system32\hjgruiqvnlkaat.dll
c:\windows\system32\hjgruiyfgphouk.dll
c:\windows\system32\rev1
c:\windows\system32\t21
c:\windows\system32\v2
c:\windows\system32\ybeeg.ini
c:\windows\system32\ybeeg.ini2
D:\Autorun.inf

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\system volume information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP301\A0193502.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_hjgruikjvmhcac
——-\Legacy_hjgruikjvmhcac


((((((((((((((((((((((((( Files Created from 2009-07-08 to 2009-08-08 )))))))))))))))))))))))))))))))
.

2009-08-08 21:15 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2009-08-08 21:15 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\dllcache\proquota.exe
2009-08-08 18:58 . 2009-08-08 18:58 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Webroot
2009-08-07 16:22 . 2009-08-07 16:22 ——– d—–w- c:\program files\Trend Micro
2009-08-07 15:52 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-07 15:51 . 2009-08-07 15:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 15:51 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 21:15 . 2009-08-08 19:06 117760 —-a-w- c:\documents and settings\YM\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-01 21:13 . 2009-08-01 21:13 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-01 21:13 . 2009-08-01 21:13 65024 —-a-r- c:\documents and settings\YM\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2009-08-01 21:13 . 2009-08-01 21:13 18944 —-a-r- c:\documents and settings\YM\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2009-08-01 21:13 . 2009-08-07 15:15 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-08-01 21:13 . 2009-08-01 21:13 ——– d—–w- c:\documents and settings\YM\Application Data\SUPERAntiSpyware.com
2009-08-01 21:13 . 2009-08-01 21:13 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-01 14:32 . 2009-08-01 14:32 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\SACore
2009-08-01 05:01 . 2009-08-01 05:01 ——– d—–w- c:\documents and settings\NetworkService\Application Data\SACore
2009-07-31 14:59 . 2009-07-31 14:59 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-07-31 13:04 . 2009-07-13 05:42 286880 —-a-r- c:\documents and settings\YM\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2009-07-31 07:41 . 2006-03-15 20:00 4224 —-a-w- c:\windows\system32\drivers\beep.sys
2009-07-31 07:41 . 2006-03-15 20:00 4224 —-a-w- c:\windows\system32\dllcache\beep.sys
2009-07-31 02:56 . 2009-07-31 02:56 ——– d—–w- c:\documents and settings\YM\Application Data\McAfee
2009-07-31 02:56 . 2009-07-31 02:56 49152 —-a-r- c:\documents and settings\YM\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA1.exe
2009-07-31 02:56 . 2009-07-31 02:56 49152 —-a-r- c:\documents and settings\YM\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA.exe
2009-07-31 02:40 . 2009-04-09 18:23 120136 —-a-w- c:\windows\system32\drivers\Mpfp.sys
2009-07-31 02:39 . 2009-07-31 02:40 ——– d—–w- c:\program files\Common Files\McAfee
2009-07-31 02:39 . 2009-07-31 02:40 ——– d—–w- c:\program files\McAfee.com
2009-07-31 02:39 . 2009-08-01 13:16 ——– d—–w- c:\program files\McAfee
2009-07-31 01:44 . 2009-07-31 01:44 14597 —-a-w- c:\windows\naby.dll
2009-07-31 01:44 . 2009-07-31 01:44 10847 —-a-w- c:\windows\wubagocut.com
2009-07-31 01:44 . 2009-07-31 01:44 18143 —-a-w- c:\documents and settings\YM\Application Data\nynugy.dll
2009-07-31 01:44 . 2009-07-31 01:44 17914 —-a-w- c:\windows\system32\icesix.pif
2009-07-31 01:44 . 2009-07-31 01:44 10538 —-a-w- c:\windows\rixyrene.bin
2009-07-31 01:44 . 2009-07-31 01:44 16088 —-a-w- c:\documents and settings\YM\Local Settings\Application Data\secizud.scr
2009-07-31 01:44 . 2009-07-31 01:44 13279 —-a-w- c:\documents and settings\All Users\Application Data\omijovivit.scr
2009-07-31 01:44 . 2009-07-31 01:44 11565 —-a-w- c:\program files\Common Files\ehut.bat
2009-07-31 00:56 . 2009-07-31 00:56 ——– d-sh–w- c:\documents and settings\LocalService\History
2009-07-31 00:56 . 2009-07-31 00:56 ——– d-sh–w- c:\documents and settings\LocalService\Temporary Internet Files
2009-07-31 00:55 . 2009-07-31 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-07-31 00:55 . 2009-07-31 01:34 ——– d—–w- c:\program files\SiteAdvisor
2009-07-31 00:50 . 2009-05-14 03:25 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-07-31 00:50 . 2009-05-14 03:25 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-07-31 00:50 . 2009-05-14 03:25 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-07-31 00:43 . 2009-05-14 03:24 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-07-31 00:32 . 2009-07-31 02:55 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-07-30 21:42 . 2009-07-30 21:42 13949 —-a-w- c:\documents and settings\YM\Local Settings\Application Data\yfix.vbs
2009-07-30 21:42 . 2009-07-30 21:42 17450 —-a-w- c:\documents and settings\YM\Local Settings\Application Data\egaqakyk.sys
2009-07-30 21:42 . 2009-07-30 21:42 10464 —-a-w- c:\windows\lutapuwuv.com
2009-07-30 18:21 . 2009-07-30 18:21 ——– d—–w- c:\windows\system32\XPSViewer
2009-07-30 18:21 . 2009-07-30 18:21 ——– d—–w- c:\program files\MSBuild
2009-07-30 18:21 . 2009-07-30 18:21 ——– d—–w- c:\program files\Reference Assemblies
2009-07-30 18:20 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-30 18:20 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-07-30 18:20 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-30 18:20 . 2009-07-30 18:21 ——– d—–w- C:\cafb9a9195d6889cb52c42
2009-07-30 18:20 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-07-30 18:20 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-07-30 18:20 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-07-30 18:20 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-07-24 02:13 . 2009-07-24 02:14 ——– d—–w- C:\55f0d3035756f0da675d54e340ab
2009-07-24 02:13 . 2009-07-24 02:13 ——– d—–w- C:\1e96c55cfa17680f76a495e58a0580
2009-07-24 02:12 . 2009-07-24 02:13 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-07-24 02:12 . 2009-07-24 02:12 ——– d—–w- C:\54bfe5b8bcb610cab098a8e9f5
2009-07-24 02:11 . 2009-07-24 02:12 ——– d—–w- C:\3423bcd4be0e6c711d2c310b0c
2009-07-16 07:15 . 2009-07-30 21:11 ——– d—–w- c:\program files\Shared
2009-07-11 21:43 . 2009-07-11 21:43 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Apple Computer
2009-07-11 21:43 . 2009-07-11 21:43 ——– d—–w- c:\documents and settings\User\Application Data\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-03 03:03 . 2007-10-22 09:01 ——– d—–w- c:\documents and settings\YM\Application Data\Azureus
2009-08-02 15:21 . 2007-08-14 11:14 ——– d—–w- c:\documents and settings\YM\Application Data\LimeWire
2009-08-01 16:09 . 2007-10-22 09:00 ——– d—–w- c:\program files\Azureus
2009-07-31 01:44 . 2009-07-31 01:44 11814 —-a-w- c:\program files\Common Files\zulifibo._dl
2009-07-31 01:44 . 2009-07-31 01:44 19752 —-a-w- c:\program files\Common Files\tyco.ban
2009-07-31 01:44 . 2009-07-31 01:44 16602 —-a-w- c:\program files\Common Files\ucolyjupad.inf
2009-07-31 01:44 . 2009-07-31 01:44 10998 —-a-w- c:\program files\Common Files\yxejygiko._sy
2009-07-31 00:13 . 2006-09-21 05:30 85912 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-30 21:42 . 2009-07-30 21:42 12972 —-a-w- c:\program files\Common Files\ygib._dl
2009-07-30 21:42 . 2009-07-30 21:42 18985 —-a-w- c:\documents and settings\YM\Application Data\gimu.vbs
2009-07-30 21:42 . 2009-07-30 21:42 16369 —-a-w- c:\documents and settings\All Users\Application Data\ewipexipyn.dat
2009-07-30 21:42 . 2009-07-30 21:42 15933 —-a-w- c:\program files\Common Files\canus.dl
2009-07-27 22:39 . 2007-10-16 11:30 ——– d—–w- c:\documents and settings\YM\Application Data\U3
2009-07-24 02:14 . 2006-09-21 06:20 ——– d—–w- c:\program files\Windows Media Connect 2
2009-07-11 21:44 . 2007-08-12 08:19 ——– d—–w- c:\documents and settings\User\Application Data\AOL
2009-07-02 16:24 . 2009-07-02 16:24 390664 —-a-w- c:\documents and settings\YM\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-29 16:12 . 2006-03-16 04:00 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2006-03-16 04:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2006-03-16 04:00 17408 ——w- c:\windows\system32\corpol.dll
2009-06-23 17:49 . 2009-06-23 17:49 ——– d—–w- c:\program files\Microsoft Silverlight
2009-06-16 14:36 . 2005-10-18 05:14 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2005-10-18 05:14 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2005-08-30 12:13 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-14 03:25 . 2009-05-14 03:25 214024 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-03-17 03:58 . 2007-10-16 20:27 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-03-17 03:58 . 2007-10-16 20:27 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-03-17 03:58 . 2007-10-16 20:27 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-03-17 03:58 . 2007-10-16 20:27 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-03-17 03:58 . 2007-10-16 20:27 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
"AOL Fast Start"="c:\program files\America Online 9.0a\AOL.EXE" [2005-07-28 50776]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-07 1830128]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"nwiz"="c:\windows\system32\nwiz.exe" [2006-08-18 1617920]
"High Definition Audio Property Page Shortcut"="c:\windows\system32\CHDAudPropShortcut.exe" [2006-06-02 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-31 136600]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"HostManager"="c:\program files\Common Files\AOL\1186906696\ee\AOLSoftware.exe" [2008-06-24 41824]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-22 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-05-01 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-04-09 1176808]
"KernelFaultCheck"="c:\windows\system32\dumprep.exe" [2008-04-14 10752]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-08-09 5418864]

c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-5-9 73728]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-5-9 73728]

c:\documents and settings\User\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-5-9 73728]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^YM^Start Menu^Programs^StartUp^Vongo Tray.lnk]
path=c:\documents and settings\YM\Start Menu\Programs\StartUp\Vongo Tray.lnk
backup=c:\windows\pss\Vongo Tray.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Vongo Service"=2 (0x2)
"ose"=3 (0x3)
"hpqwmiex"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1186906696\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Common Files\\AOL\\1186906696\\EE\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\mmc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"35373:TCP"= 35373:TCP:PORT_35373
"29341:TCP"= 29341:TCP:PORT_29341
"63075:TCP"= 63075:TCP:PORT_63075
"10285:TCP"= 10285:TCP:PORT_10285
"9548:TCP"= 9548:TCP:PORT_9548
"32099:TCP"= 32099:TCP:PORT_32099
"12510:TCP"= 12510:TCP:PORT_12510
"25375:TCP"= 25375:TCP:PORT_25375
"62888:TCP"= 62888:TCP:PORT_62888
"29546:TCP"= 29546:TCP:PORT_29546
"44933:TCP"= 44933:TCP:PORT_44933
"17621:TCP"= 17621:TCP:PORT_17621
"37837:TCP"= 37837:TCP:PORT_37837
"25316:TCP"= 25316:TCP:PORT_25316
"26719:TCP"= 26719:TCP:PORT_26719
"24369:TCP"= 24369:TCP:PORT_24369
"38583:TCP"= 38583:TCP:PORT_38583
"52423:TCP"= 52423:TCP:PORT_52423
"7817:TCP"= 7817:TCP:PORT_7817
"14173:TCP"= 14173:TCP:PORT_14173
"54981:TCP"= 54981:TCP:PORT_54981
"6352:TCP"= 6352:TCP:PORT_6352
"45243:TCP"= 45243:TCP:PORT_45243
"44796:TCP"= 44796:TCP:PORT_44796
"60633:TCP"= 60633:TCP:PORT_60633

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [8/9/2008 5:42 PM 29808]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/28/2009 10:53 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/28/2009 10:53 AM 74480]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [7/30/2009 10:43 PM 210216]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [7/28/2009 10:53 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-07-31 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-07-31 12:57]

2009-08-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-07-31 12:57]

2009-08-07 c:\windows\Tasks\wrSpySweeperFullSweep.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-09-14 23:04]

2009-08-07 c:\windows\Tasks\wrSpySweeperFullSweep.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-09-14 23:04]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
HKLM-Run- - (no file)
Notify-khfdaya - khfdaya.dll
Notify-urqPfDVO - urqPfDVO.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
mSearchAssistant = hxxp://www.google.com
IE: &AOL; Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MI8CBC~1\Office10\EXCEL.EXE/3000
Trusted Zone: cmgsccc.com\forums
Trusted Zone: cmgsccc.com\www
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: microsoft.com\www
FF - ProfilePath - c:\documents and settings\YM\Application Data\Mozilla\Firefox\Profiles\pgvddi93.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopie7&query;=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopab&query;=
FF - component: c:\documents and settings\YM\Application Data\Mozilla\Firefox\Profiles\pgvddi93.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-08 17:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2046495708-2985619692-3374508912-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(960)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2009-08-08 17:38
ComboFix-quarantined-files.txt 2009-08-08 21:38

Pre-Run: 24,965,767,168 bytes free
Post-Run: 29,567,549,440 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
353 — E O F — 2009-07-31 07:04
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Search_engine_redirected_t105916.html&view=findpost&p=585828#entry585828

Collect::
c:\windows\naby.dll
c:\windows\wubagocut.com
c:\documents and settings\YM\Application Data\nynugy.dll
c:\windows\system32\icesix.pif
c:\windows\rixyrene.bin
c:\documents and settings\YM\Local Settings\Application Data\secizud.scr
c:\documents and settings\All Users\Application Data\omijovivit.scr
c:\program files\Common Files\ehut.bat
c:\documents and settings\YM\Local Settings\Application Data\yfix.vbs
c:\documents and settings\YM\Local Settings\Application Data\egaqakyk.sys
c:\windows\lutapuwuv.com
c:\program files\Common Files\zulifibo._dl
c:\program files\Common Files\tyco.ban
c:\program files\Common Files\ucolyjupad.inf
c:\program files\Common Files\yxejygiko._sy
c:\program files\Common Files\ygib._dl
c:\documents and settings\YM\Application Data\gimu.vbs
c:\documents and settings\All Users\Application Data\ewipexipyn.dat
c:\program files\Common Files\canus.dl

DirLook::
C:\cafb9a9195d6889cb52c42
C:\55f0d3035756f0da675d54e340ab
C:\1e96c55cfa17680f76a495e58a0580
C:\54bfe5b8bcb610cab098a8e9f5
C:\3423bcd4be0e6c711d2c310b0c

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Here is the next log


ComboFix 09-08-07.09 - YM 08/09/2009 10:29.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.514 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\YM\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point

file zipped: c:\documents and settings\All Users\Application Data\ewipexipyn.dat
file zipped: c:\documents and settings\All Users\Application Data\omijovivit.scr
file zipped: c:\documents and settings\YM\Application Data\gimu.vbs
file zipped: c:\documents and settings\YM\Application Data\nynugy.dll
file zipped: c:\documents and settings\YM\Local Settings\Application Data\egaqakyk.sys
file zipped: c:\documents and settings\YM\Local Settings\Application Data\secizud.scr
file zipped: c:\documents and settings\YM\Local Settings\Application Data\yfix.vbs
file zipped: c:\program files\Common Files\canus.dl
file zipped: c:\program files\Common Files\ehut.bat
file zipped: c:\program files\Common Files\tyco.ban
file zipped: c:\program files\Common Files\ucolyjupad.inf
file zipped: c:\program files\Common Files\ygib._dl
file zipped: c:\program files\Common Files\yxejygiko._sy
file zipped: c:\program files\Common Files\zulifibo._dl
file zipped: c:\windows\lutapuwuv.com
file zipped: c:\windows\naby.dll
file zipped: c:\windows\rixyrene.bin
file zipped: c:\windows\system32\icesix.pif
file zipped: c:\windows\wubagocut.com
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\ewipexipyn.dat
c:\documents and settings\All Users\Application Data\omijovivit.scr
c:\documents and settings\YM\Application Data\gimu.vbs
c:\documents and settings\YM\Application Data\nynugy.dll
c:\documents and settings\YM\Local Settings\Application Data\egaqakyk.sys
c:\documents and settings\YM\Local Settings\Application Data\secizud.scr
c:\documents and settings\YM\Local Settings\Application Data\yfix.vbs
c:\program files\Common Files\canus.dl
c:\program files\Common Files\ehut.bat
c:\program files\Common Files\tyco.ban
c:\program files\Common Files\ucolyjupad.inf
c:\program files\Common Files\ygib._dl
c:\program files\Common Files\yxejygiko._sy
c:\program files\Common Files\zulifibo._dl
c:\windows\lutapuwuv.com
c:\windows\naby.dll
c:\windows\rixyrene.bin
c:\windows\system32\icesix.pif
c:\windows\wubagocut.com

.
((((((((((((((((((((((((( Files Created from 2009-07-09 to 2009-08-09 )))))))))))))))))))))))))))))))
.

2009-08-08 21:15 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2009-08-08 21:15 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\dllcache\proquota.exe
2009-08-08 18:58 . 2009-08-08 18:58 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Webroot
2009-08-07 16:22 . 2009-08-07 16:22 ——– d—–w- c:\program files\Trend Micro
2009-08-07 15:52 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-07 15:51 . 2009-08-07 15:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 15:51 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 21:15 . 2009-08-08 19:06 117760 —-a-w- c:\documents and settings\YM\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-01 21:13 . 2009-08-01 21:13 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-01 21:13 . 2009-08-01 21:13 65024 —-a-r- c:\documents and settings\YM\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2009-08-01 21:13 . 2009-08-01 21:13 18944 —-a-r- c:\documents and settings\YM\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2009-08-01 21:13 . 2009-08-07 15:15 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-08-01 21:13 . 2009-08-01 21:13 ——– d—–w- c:\documents and settings\YM\Application Data\SUPERAntiSpyware.com
2009-08-01 21:13 . 2009-08-01 21:13 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-01 14:32 . 2009-08-01 14:32 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\SACore
2009-08-01 05:01 . 2009-08-01 05:01 ——– d—–w- c:\documents and settings\NetworkService\Application Data\SACore
2009-07-31 14:59 . 2009-07-31 14:59 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-07-31 13:04 . 2009-07-13 05:42 286880 —-a-r- c:\documents and settings\YM\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2009-07-31 07:41 . 2006-03-15 20:00 4224 —-a-w- c:\windows\system32\drivers\beep.sys
2009-07-31 07:41 . 2006-03-15 20:00 4224 —-a-w- c:\windows\system32\dllcache\beep.sys
2009-07-31 02:56 . 2009-07-31 02:56 ——– d—–w- c:\documents and settings\YM\Application Data\McAfee
2009-07-31 02:56 . 2009-07-31 02:56 49152 —-a-r- c:\documents and settings\YM\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA1.exe
2009-07-31 02:56 . 2009-07-31 02:56 49152 —-a-r- c:\documents and settings\YM\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA.exe
2009-07-31 02:40 . 2009-04-09 18:23 120136 —-a-w- c:\windows\system32\drivers\Mpfp.sys
2009-07-31 02:39 . 2009-07-31 02:40 ——– d—–w- c:\program files\Common Files\McAfee
2009-07-31 02:39 . 2009-07-31 02:40 ——– d—–w- c:\program files\McAfee.com
2009-07-31 02:39 . 2009-08-01 13:16 ——– d—–w- c:\program files\McAfee
2009-07-31 00:56 . 2009-07-31 00:56 ——– d-sh–w- c:\documents and settings\LocalService\History
2009-07-31 00:56 . 2009-07-31 00:56 ——– d-sh–w- c:\documents and settings\LocalService\Temporary Internet Files
2009-07-31 00:55 . 2009-07-31 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-07-31 00:55 . 2009-07-31 01:34 ——– d—–w- c:\program files\SiteAdvisor
2009-07-31 00:50 . 2009-05-14 03:25 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-07-31 00:50 . 2009-05-14 03:25 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-07-31 00:50 . 2009-05-14 03:25 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-07-31 00:43 . 2009-05-14 03:24 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-07-31 00:32 . 2009-07-31 02:55 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-07-30 18:21 . 2009-07-30 18:21 ——– d—–w- c:\windows\system32\XPSViewer
2009-07-30 18:21 . 2009-07-30 18:21 ——– d—–w- c:\program files\MSBuild
2009-07-30 18:21 . 2009-07-30 18:21 ——– d—–w- c:\program files\Reference Assemblies
2009-07-30 18:20 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-30 18:20 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-07-30 18:20 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-30 18:20 . 2009-07-30 18:21 ——– d—–w- C:\cafb9a9195d6889cb52c42
2009-07-30 18:20 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-07-30 18:20 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-07-30 18:20 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-07-30 18:20 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-07-24 02:13 . 2009-07-24 02:14 ——– d—–w- C:\55f0d3035756f0da675d54e340ab
2009-07-24 02:13 . 2009-07-24 02:13 ——– d—–w- C:\1e96c55cfa17680f76a495e58a0580
2009-07-24 02:12 . 2009-07-24 02:13 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-07-24 02:12 . 2009-07-24 02:12 ——– d—–w- C:\54bfe5b8bcb610cab098a8e9f5
2009-07-24 02:11 . 2009-07-24 02:12 ——– d—–w- C:\3423bcd4be0e6c711d2c310b0c
2009-07-16 07:15 . 2009-07-30 21:11 ——– d—–w- c:\program files\Shared
2009-07-11 21:43 . 2009-07-11 21:43 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Apple Computer
2009-07-11 21:43 . 2009-07-11 21:43 ——– d—–w- c:\documents and settings\User\Application Data\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-03 03:03 . 2007-10-22 09:01 ——– d—–w- c:\documents and settings\YM\Application Data\Azureus
2009-08-02 15:21 . 2007-08-14 11:14 ——– d—–w- c:\documents and settings\YM\Application Data\LimeWire
2009-08-01 16:09 . 2007-10-22 09:00 ——– d—–w- c:\program files\Azureus
2009-07-31 00:13 . 2006-09-21 05:30 85912 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-27 22:39 . 2007-10-16 11:30 ——– d—–w- c:\documents and settings\YM\Application Data\U3
2009-07-24 02:14 . 2006-09-21 06:20 ——– d—–w- c:\program files\Windows Media Connect 2
2009-07-11 21:44 . 2007-08-12 08:19 ——– d—–w- c:\documents and settings\User\Application Data\AOL
2009-07-02 16:24 . 2009-07-02 16:24 390664 —-a-w- c:\documents and settings\YM\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-29 16:12 . 2006-03-16 04:00 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2006-03-16 04:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2006-03-16 04:00 17408 ——w- c:\windows\system32\corpol.dll
2009-06-23 17:49 . 2009-06-23 17:49 ——– d—–w- c:\program files\Microsoft Silverlight
2009-06-16 14:36 . 2005-10-18 05:14 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2005-10-18 05:14 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2005-08-30 12:13 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-14 03:25 . 2009-05-14 03:25 214024 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-03-17 03:58 . 2007-10-16 20:27 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-03-17 03:58 . 2007-10-16 20:27 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-03-17 03:58 . 2007-10-16 20:27 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-03-17 03:58 . 2007-10-16 20:27 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-03-17 03:58 . 2007-10-16 20:27 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\1e96c55cfa17680f76a495e58a0580 —-

2006-11-02 15:46 . 2006-11-02 15:46 13312 —-a-w- c:\1e96c55cfa17680f76a495e58a0580\update\wpdinstallutil.dll
2006-05-16 22:11 . 2006-05-16 22:11 716000 —-a-w- c:\1e96c55cfa17680f76a495e58a0580\update\update.exe
2006-05-16 22:11 . 2006-05-16 22:11 371424 —-a-w- c:\1e96c55cfa17680f76a495e58a0580\update\updspapi.dll

—- Directory of C:\3423bcd4be0e6c711d2c310b0c —-

2005-10-13 17:22 . 2005-10-13 17:22 716000 —-a-w- c:\3423bcd4be0e6c711d2c310b0c\update\update.exe

—- Directory of C:\54bfe5b8bcb610cab098a8e9f5 —-

2006-09-28 23:01 . 2006-09-28 23:01 58368 —-a-w- c:\54bfe5b8bcb610cab098a8e9f5\update\wudfcustom.dll
2006-09-16 05:05 . 2006-09-16 05:05 742192 —-a-w- c:\54bfe5b8bcb610cab098a8e9f5\update\update.exe
2006-09-16 05:05 . 2006-09-16 05:05 379184 —-a-w- c:\54bfe5b8bcb610cab098a8e9f5\update\updspapi.dll

—- Directory of C:\55f0d3035756f0da675d54e340ab —-

2006-05-16 22:11 . 2006-05-16 22:11 716000 —-a-w- c:\55f0d3035756f0da675d54e340ab\update\update.exe
2006-05-16 22:11 . 2006-05-16 22:11 371424 —-a-w- c:\55f0d3035756f0da675d54e340ab\update\updspapi.dll

—- Directory of C:\cafb9a9195d6889cb52c42 —-

2009-07-30 18:20 . 2008-06-19 05:33 72 ——w- c:\cafb9a9195d6889cb52c42\amd64\msxpsinc.ppd
2009-07-30 18:20 . 2008-06-19 05:33 2204 ——w- c:\cafb9a9195d6889cb52c42\i386\msxpsdrv.inf
2009-07-30 18:20 . 2008-06-19 15:03 73 ——w- c:\cafb9a9195d6889cb52c42\i386\msxpsinc.gpd
2009-07-30 18:20 . 2008-06-19 05:33 72 ——w- c:\cafb9a9195d6889cb52c42\i386\msxpsinc.ppd
2009-07-30 18:20 . 2008-06-19 05:33 2204 ——w- c:\cafb9a9195d6889cb52c42\amd64\msxpsdrv.inf
2009-07-30 18:20 . 2008-07-06 12:06 10929 ——w- c:\cafb9a9195d6889cb52c42\amd64\msxpsdrv.cat
2009-07-30 18:20 . 2008-07-06 12:06 10929 ——w- c:\cafb9a9195d6889cb52c42\i386\msxpsdrv.cat
2009-07-30 18:20 . 2008-07-06 12:06 147456 ——w- c:\cafb9a9195d6889cb52c42\amd64\filterpipelineprintproc.dll
2009-07-30 18:20 . 2008-07-06 12:06 89088 ——w- c:\cafb9a9195d6889cb52c42\i386\filterpipelineprintproc.dll
2009-07-30 18:20 . 2008-07-06 12:06 765440 ——w- c:\cafb9a9195d6889cb52c42\i386\mxdwdrv.dll
2009-07-30 18:20 . 2008-07-06 12:06 1676288 ——w- c:\cafb9a9195d6889cb52c42\i386\xpssvcs.dll
2009-07-30 18:20 . 2008-07-06 12:06 748032 ——w- c:\cafb9a9195d6889cb52c42\amd64\mxdwdrv.dll
2008-07-06 21:36 . 2008-07-06 21:36 2936832 ——w- c:\cafb9a9195d6889cb52c42\amd64\xpssvcs.dll
2008-06-19 15:03 . 2008-06-19 15:03 73 ——w- c:\cafb9a9195d6889cb52c42\amd64\msxpsinc.gpd


((((((((((((((((((((((((((((( SnapShot@2009-08-08_21.19.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-09-21 05:38 . 2009-08-09 11:47 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-09-21 05:38 . 2009-08-08 20:29 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-09-21 05:38 . 2009-08-08 20:29 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-09-21 05:38 . 2009-08-09 11:47 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-09-21 05:38 . 2009-08-09 11:47 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-09-21 05:38 . 2009-08-08 20:29 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
"AOL Fast Start"="c:\program files\America Online 9.0a\AOL.EXE" [2005-07-28 50776]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-07 1830128]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"nwiz"="c:\windows\system32\nwiz.exe" [2006-08-18 1617920]
"High Definition Audio Property Page Shortcut"="c:\windows\system32\CHDAudPropShortcut.exe" [2006-06-02 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-31 136600]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"HostManager"="c:\program files\Common Files\AOL\1186906696\ee\AOLSoftware.exe" [2008-06-24 41824]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-22 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-05-01 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-04-09 1176808]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-08-09 5418864]

c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-5-9 73728]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-5-9 73728]

c:\documents and settings\User\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-5-9 73728]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^YM^Start Menu^Programs^StartUp^Vongo Tray.lnk]
path=c:\documents and settings\YM\Start Menu\Programs\StartUp\Vongo Tray.lnk
backup=c:\windows\pss\Vongo Tray.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Vongo Service"=2 (0x2)
"ose"=3 (0x3)
"hpqwmiex"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1186906696\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Common Files\\AOL\\1186906696\\EE\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\mmc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"35373:TCP"= 35373:TCP:PORT_35373
"29341:TCP"= 29341:TCP:PORT_29341
"63075:TCP"= 63075:TCP:PORT_63075
"10285:TCP"= 10285:TCP:PORT_10285
"9548:TCP"= 9548:TCP:PORT_9548
"32099:TCP"= 32099:TCP:PORT_32099
"12510:TCP"= 12510:TCP:PORT_12510
"25375:TCP"= 25375:TCP:PORT_25375
"62888:TCP"= 62888:TCP:PORT_62888
"29546:TCP"= 29546:TCP:PORT_29546
"44933:TCP"= 44933:TCP:PORT_44933
"17621:TCP"= 17621:TCP:PORT_17621
"37837:TCP"= 37837:TCP:PORT_37837
"25316:TCP"= 25316:TCP:PORT_25316
"26719:TCP"= 26719:TCP:PORT_26719
"24369:TCP"= 24369:TCP:PORT_24369
"38583:TCP"= 38583:TCP:PORT_38583
"52423:TCP"= 52423:TCP:PORT_52423
"7817:TCP"= 7817:TCP:PORT_7817
"14173:TCP"= 14173:TCP:PORT_14173
"54981:TCP"= 54981:TCP:PORT_54981
"6352:TCP"= 6352:TCP:PORT_6352
"45243:TCP"= 45243:TCP:PORT_45243
"44796:TCP"= 44796:TCP:PORT_44796
"60633:TCP"= 60633:TCP:PORT_60633

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [8/9/2008 5:42 PM 29808]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/28/2009 10:53 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/28/2009 10:53 AM 74480]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [7/30/2009 10:43 PM 210216]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [7/28/2009 10:53 AM 7408]

— Other Services/Drivers In Memory —

*Deregistered* - ATWPKT2
.
Contents of the 'Scheduled Tasks' folder

2009-07-31 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-07-31 12:57]

2009-08-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-07-31 12:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: &AOL; Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MI8CBC~1\Office10\EXCEL.EXE/3000
Trusted Zone: cmgsccc.com\forums
Trusted Zone: cmgsccc.com\www
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: microsoft.com\www
FF - ProfilePath - c:\documents and settings\YM\Application Data\Mozilla\Firefox\Profiles\pgvddi93.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopie7&query;=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopab&query;=
FF - component: c:\documents and settings\YM\Application Data\Mozilla\Firefox\Profiles\pgvddi93.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-09 11:03
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2046495708-2985619692-3374508912-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(960)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2009-08-09 11:16
ComboFix-quarantined-files.txt 2009-08-09 15:16
ComboFix2.txt 2009-08-08 21:39

Pre-Run: 29,567,205,376 bytes free
Post-Run: 29,524,140,032 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
368 — E O F — 2009-07-31 07:04
Upload was successful
Hi,

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
I have the MBAM log, however I couldnt get a log from the Kaspersky Scanner. When I ran the scan the first time, for some reason my computer froze and now when I try to run the scanner again I get an error message saying the key has expired. I even downloaded the Antivirus trial version from Kaspersky but it wouldnt let me finish the install because it showed a list of incompatible McAfee programs I needed to remove first (I couldnt find any of these programs). Any other alternative scanner?
Yes, Kaspersky can be finicky sometimes,

Try this scanner instead:

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Okay after three hours of scanning, I have both logs lol.

Here is the MBAM log

Malwarebytes' Anti-Malware 1.40
Database version: 2586
Windows 5.1.2600 Service Pack 3

8/9/2009 2:21:08 PM
mbam-log-2009-08-09 (14-21-08).txt

Scan type: Quick Scan
Objects scanned: 112101
Time elapsed: 8 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\MSINET.oca (Rogue.Trace) -> Quarantined and deleted successfully.











Here is the ESET Scanner log

ESETSmartInstaller@High as downloader log:
all ok
# version=6
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.5889
# api_version=3.0.2
# EOSSerial=a7b9b3c0b2adc84fbcc1b18bd3e0ec29
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2009-08-09 11:46:00
# local_time=2009-08-09 07:46:00 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5121 37 100 88 75881884218750
# scanned=16554
# found=0
# cleaned=0
# scan_time=2677
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=6
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.5889
# api_version=3.0.2
# EOSSerial=a7b9b3c0b2adc84fbcc1b18bd3e0ec29
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2009-08-10 03:50:23
# local_time=2009-08-09 11:50:23 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5121 37 100 88 76028512343750
# scanned=138602
# found=9
# cleaned=0
# scan_time=14492
C:\Documents and Settings\YM\My Documents\Azureus Downloads\[PC] Test Drive Unlimited [PROPER] [RIP] [dopeman]\TDU.7z probably a variant of Win32/Genetik trojan 00000000000000000000000000000000 I
C:\Documents and Settings\YM\My Documents\Computer Games\TDU\TestDriveUnlimited.exe probably a variant of Win32/Genetik trojan 00000000000000000000000000000000 I
C:\Documents and Settings\YM\My Documents\Incomplete\T-5905209-micheal jackson- human nature - bonus track.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan 00000000000000000000000000000000 I
C:\Documents and Settings\YM\My Documents\Shared2\i love music ahmad jamal.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\hjgruiyfgphouk.dll.vir Win32/Olmarik.JU trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\ybeeg.ini.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\ybeeg.ini2.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP302\A0193509.exe Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP308\A0216541.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=6
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.5889
# api_version=3.0.2
# EOSSerial=a7b9b3c0b2adc84fbcc1b18bd3e0ec29
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2009-08-10 09:24:05
# local_time=2009-08-10 05:24:05 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5121 37 100 88 76228739218750
# scanned=138717
# found=9
# cleaned=0
# scan_time=11111
C:\Documents and Settings\YM\My Documents\Azureus Downloads\[PC] Test Drive Unlimited [PROPER] [RIP] [dopeman]\TDU.7z probably a variant of Win32/Genetik trojan 00000000000000000000000000000000 I
C:\Documents and Settings\YM\My Documents\Computer Games\TDU\TestDriveUnlimited.exe probably a variant of Win32/Genetik trojan 00000000000000000000000000000000 I
C:\Documents and Settings\YM\My Documents\Incomplete\T-5905209-micheal jackson- human nature - bonus track.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan 00000000000000000000000000000000 I
C:\Documents and Settings\YM\My Documents\Shared2\i love music ahmad jamal.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\hjgruiyfgphouk.dll.vir Win32/Olmarik.JU trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\ybeeg.ini.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\ybeeg.ini2.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP302\A0193509.exe Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP308\A0216541.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I
Hi,

Please do the following:

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Files
C:\Documents and Settings\YM\My Documents\Azureus Downloads\[PC] Test Drive Unlimited [PROPER] [RIP] [dopeman]\TDU.7z 
C:\Documents and Settings\YM\My Documents\Computer Games\TDU\TestDriveUnlimited.exe 
C:\Documents and Settings\YM\My Documents\Incomplete\T-5905209-micheal jackson- human nature - bonus track.mp3 
C:\Documents and Settings\YM\My Documents\Shared2\i love music ahmad jamal.mp3 

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


NEXT

Please post a fresh DDS log and Attach.txt and advise how your computer is running now and if there are any outstanding issues
Here is the new DDS text



DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 10:53:23.14 on Mon 08/10/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.437 [GMT -4:00]

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
svchost.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1186906696\ee\AOLSoftware.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
c:\program files\aol toolbar\AolTbServer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\America Online 9.0a\shellmon.exe
c:\program files\common files\aol\1186906696\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1186906696\EE\aolsoftware.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\YM\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.aol.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
uURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol toolbar\aoltb.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler
uRun: [AOL Fast Start] "c:\program files\america online 9.0a\AOL.EXE" -b
uRun: [SUPERAntiSpyware] "c:\program files\superantispyware\SUPERAntiSpyware.exe"
uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nwiz] "c:\windows\system32\nwiz.exe" /installquiet /nodetect
mRun: [High Definition Audio Property Page Shortcut] "c:\windows\system32\CHDAudPropShortcut.exe"
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [QlbCtrl] "c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe" /Start
mRun: [Cpqset] "c:\program files\hewlett-packard\default settings\cpqset.exe"
mRun: [RecGuard] "c:\windows\sminst\RecGuard.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [ehTray] "c:\windows\ehome\ehtray.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HostManager] "c:\program files\common files\aol\1186906696\ee\AOLSoftware.exe"
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] "c:\progra~1\mcafee\mhn\McENUI.exe" /hide
mRun: [SpySweeper] "c:\program files\webroot\spy sweeper\SpySweeperUI.exe" /startintray
IE: &AOL Toolbar Search - c:\documents and settings\all users\application data\aol\ietoolbar\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi8cbc~1\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: cmgsccc.com\forums
Trusted Zone: cmgsccc.com\www
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: microsoft.com\www
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} - hxxp://www.putfile.com/includes/ImageUploader4-5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_0_02-win.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ym\applic~1\mozilla\firefox\profiles\pgvddi93.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopie7&query=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopab&query=
FF - component: c:\documents and settings\ym\application data\mozilla\firefox\profiles\pgvddi93.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\real\realplayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29808]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-13 214024]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-7-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-7-28 74480]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-7-30 210216]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-7-30 359952]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-6 99328]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-7-30 144704]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2008-8-9 3585384]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-7-30 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-7-30 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-7-30 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-7-30 40552]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-7-28 7408]
S0 ouclhh;ouclhh;c:\windows\system32\drivers\dviiqci.sys –> c:\windows\system32\drivers\dviiqci.sys [?]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-7-30 34248]

=============== Created Last 30 ================

2009-08-10 10:33 –d—– C:\_OTM
2009-08-09 18:51 –d—– c:\program files\ESET
2009-08-09 17:53 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-08-08 17:22 –d—– c:\windows\system32\dllcache\cache
2009-08-08 17:15 50,176 a——- c:\windows\system32\proquota.exe
2009-08-08 17:15 50,176 a——- c:\windows\system32\dllcache\proquota.exe
2009-08-08 16:11 –d—– C:\cmdcons
2009-08-08 16:01 216,064 a——- c:\windows\PEV.exe
2009-08-08 16:01 161,792 a——- c:\windows\SWREG.exe
2009-08-08 16:01 98,816 a——- c:\windows\sed.exe
2009-08-07 12:22 –d—– c:\program files\Trend Micro
2009-08-07 11:52 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-07 11:51 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-07 11:51 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-01 17:13 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-08-01 17:13 –d—– c:\program files\SUPERAntiSpyware
2009-08-01 17:13 –d—– c:\docume~1\ym\applic~1\SUPERAntiSpyware.com
2009-08-01 17:13 –d—– c:\program files\common files\Wise Installation Wizard
2009-07-31 03:41 4,224 a——- c:\windows\system32\drivers\beep.sys
2009-07-31 03:41 4,224 a——- c:\windows\system32\dllcache\beep.sys
2009-07-31 00:06 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2009-07-30 22:56 –d—– c:\docume~1\ym\applic~1\McAfee
2009-07-30 22:44 11,219 a——- c:\windows\system32\Config.MPF
2009-07-30 22:40 120,136 a——- c:\windows\system32\drivers\Mpfp.sys
2009-07-30 22:39 –d—– c:\program files\common files\McAfee
2009-07-30 22:39 –d—– c:\program files\McAfee.com
2009-07-30 22:39 –d—– c:\program files\McAfee
2009-07-30 21:44 17,245 a——- c:\windows\abus.inf
2009-07-30 21:44 15,937 a——- c:\windows\resesifuqa._dl
2009-07-30 21:44 14,293 a——- c:\windows\yrofogajo.inf
2009-07-30 21:44 12,772 a——- c:\windows\system32\toram._sy
2009-07-30 20:55 –d—– c:\program files\SiteAdvisor
2009-07-30 20:50 79,816 a——- c:\windows\system32\drivers\mfeavfk.sys
2009-07-30 20:50 40,552 a——- c:\windows\system32\drivers\mfesmfk.sys
2009-07-30 20:50 35,272 a——- c:\windows\system32\drivers\mfebopk.sys
2009-07-30 20:43 34,248 a——- c:\windows\system32\drivers\mferkdk.sys
2009-07-30 17:42 13,701 a——- c:\windows\esan.dl
2009-07-30 17:42 12,963 a——- c:\windows\agysa._dl
2009-07-30 17:42 12,314 a——- c:\windows\system32\odihovem.dl
2009-07-30 14:21 –d—– c:\windows\system32\XPSViewer
2009-07-30 14:20 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-30 14:20 117,760 ——– c:\windows\system32\prntvpt.dll
2009-07-30 14:20 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-30 14:20 –d—– C:\cafb9a9195d6889cb52c42
2009-07-30 14:20 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-07-30 14:20 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-07-30 14:20 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-07-30 14:20 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-07-23 22:13 –d—– C:\55f0d3035756f0da675d54e340ab
2009-07-23 22:13 –d—– C:\1e96c55cfa17680f76a495e58a0580
2009-07-23 22:12 –d—– C:\54bfe5b8bcb610cab098a8e9f5
2009-07-23 22:11 –d—– C:\3423bcd4be0e6c711d2c310b0c
2009-07-16 03:15 –d—– c:\program files\Shared

==================== Find3M ====================

2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\cache\mshtml.dll
2009-07-19 09:33 3,597,824 ——– c:\windows\system32\dllcache\mshtml.dll
2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll
2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 04:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe
2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat
2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-16 10:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 10:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll
2009-03-19 23:29 85,912 a——- c:\docume~1\ym\applic~1\GDIPFONTCACHEV1.DAT
2009-02-28 00:57 256 a——- c:\docume~1\ym\applic~1\wklnhst.dat
2009-02-21 19:08 256 a——- c:\documents and settings\ym\pool.bin
2007-08-16 13:32 439,296 a——- c:\documents and settings\ym\GoToAssist_phone__317_en.exe
2008-12-10 18:57 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121020081211\index.dat

============= FINISH: 11:00:37.21 ===============







Here is the new Attach txt



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/10/2007 11:37:28 PM
System Uptime: 8/10/2009 10:36:21 AM (1 hours ago)

Motherboard: Quanta | | 30B7
Processor: AMD Turion™ 64 X2 Mobile Technology TL-50 | Socket S1 | 1607/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 81 GiB total, 27.488 GiB free.
D: is FIXED (FAT32) - 11 GiB total, 1.227 GiB free.
E: is CDROM ()
F: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP252: 7/9/2009 10:08:57 PM - System Checkpoint
RP253: 7/9/2009 10:08:57 PM - System Checkpoint
RP254: 7/9/2009 10:08:57 PM - System Checkpoint
RP255: 7/9/2009 10:08:58 PM - Software Distribution Service 3.0
RP256: 7/9/2009 10:08:58 PM - System Checkpoint
RP257: 7/9/2009 10:08:58 PM - System Checkpoint
RP258: 7/9/2009 10:08:59 PM - System Checkpoint
RP259: 7/9/2009 10:08:59 PM - Installed QuickTime
RP260: 7/9/2009 10:08:59 PM - System Checkpoint
RP261: 7/9/2009 10:08:59 PM - System Checkpoint
RP262: 7/9/2009 10:09:00 PM - System Checkpoint
RP263: 7/9/2009 10:09:00 PM - System Checkpoint
RP264: 7/9/2009 10:09:00 PM - System Checkpoint
RP265: 7/9/2009 10:09:01 PM - System Checkpoint
RP266: 7/9/2009 10:09:01 PM - System Checkpoint
RP267: 7/9/2009 10:09:01 PM - System Checkpoint
RP268: 7/9/2009 10:09:01 PM - System Checkpoint
RP269: 7/9/2009 10:09:02 PM - System Checkpoint
RP270: 7/9/2009 10:09:02 PM - System Checkpoint
RP271: 7/9/2009 10:09:02 PM - System Checkpoint
RP272: 7/9/2009 10:09:02 PM - Software Distribution Service 3.0
RP273: 7/9/2009 10:09:02 PM - System Checkpoint
RP274: 7/9/2009 10:09:03 PM - System Checkpoint
RP275: 7/9/2009 10:09:03 PM - System Checkpoint
RP276: 7/9/2009 10:09:03 PM - System Checkpoint
RP277: 7/9/2009 10:09:03 PM - System Checkpoint
RP278: 7/9/2009 10:09:03 PM - System Checkpoint
RP279: 7/9/2009 10:09:04 PM - System Checkpoint
RP280: 7/9/2009 10:09:04 PM - System Checkpoint
RP281: 7/9/2009 10:09:04 PM - System Checkpoint
RP282: 7/9/2009 10:09:04 PM - System Checkpoint
RP283: 7/9/2009 10:09:04 PM - System Checkpoint
RP284: 7/9/2009 10:09:05 PM - System Checkpoint
RP285: 7/9/2009 10:09:05 PM - System Checkpoint
RP286: 7/9/2009 10:09:05 PM - System Checkpoint
RP287: 7/9/2009 10:09:06 PM - System Checkpoint
RP288: 7/9/2009 10:09:06 PM - System Checkpoint
RP289: 7/9/2009 10:09:06 PM - System Checkpoint
RP290: 7/9/2009 10:09:07 PM - System Checkpoint
RP291: 7/9/2009 10:09:07 PM - Software Distribution Service 3.0
RP292: 7/9/2009 10:09:07 PM - Software Distribution Service 3.0
RP293: 7/9/2009 10:09:08 PM - System Checkpoint
RP294: 7/9/2009 10:09:08 PM - System Checkpoint
RP295: 7/9/2009 10:09:08 PM - System Checkpoint
RP296: 7/9/2009 10:09:08 PM - System Checkpoint
RP297: 7/9/2009 10:09:09 PM - System Checkpoint
RP298: 7/9/2009 10:09:09 PM - System Checkpoint
RP299: 7/9/2009 10:09:09 PM - System Checkpoint
RP300: 7/9/2009 10:09:10 PM - System Checkpoint
RP301: 7/9/2009 10:09:10 PM - System Checkpoint
RP302: 7/9/2009 10:09:10 PM - System Checkpoint
RP303: 7/9/2009 10:09:10 PM - System Checkpoint
RP304: 7/9/2009 10:09:11 PM - System Checkpoint
RP305: 7/9/2009 10:09:11 PM - System Checkpoint
RP306: 7/9/2009 10:09:11 PM - System Checkpoint
RP307: 7/9/2009 10:09:11 PM - System Checkpoint
RP308: 7/9/2009 10:09:11 PM - System Checkpoint
RP309: 8/9/2009 10:23:31 AM - ComboFix created restore point

==== Installed Programs ======================


5 Card Slingo from Hewlett-Packard Laptops (remove only)
Adobe Flash Player 10 ActiveX
Adobe Reader 7.0.5
Adobe Shockwave Player 11
Amazing Slow Downer (remove only)
America Online (Choose which version to remove)
AOL Coach Version 2.0(Build:20041026.5 en)
AOL Toolbar for Firefox
AOL Toolbar for Internet Explorer
AOL Uninstaller
AOL You've Got Pictures Screensaver
Apple Mobile Device Support
Apple Software Update
Audacity 1.2.6
AutoUpdate
Azureus Vuze
Bejeweled 2 Deluxe from Hewlett-Packard Laptops (remove only)
Big Kahuna Reef from Hewlett-Packard Laptops (remove only)
BlackBerry Desktop Software 4.3
BlackBerry Device Software v4.5.0 for the BlackBerry 8330 smartphone
Blackhawk Striker 2 from Hewlett-Packard Laptops (remove only)
Blasterball 2 from Hewlett-Packard Laptops (remove only)
Boggle Supreme from Hewlett-Packard Laptops (remove only)
Bonjour
Bookworm Deluxe from Hewlett-Packard Laptops (remove only)
Bounce Symphony from Hewlett-Packard Laptops (remove only)
BufferChm
Chuzzle Deluxe from Hewlett-Packard Laptops (remove only)
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
Critical Update for Windows Media Player 11 (KB959772)
Crystal Maze from Hewlett-Packard Laptops (remove only)
CueTour
Customer Experience Enhancement
Destinations
Dev-C++ 5 beta 9 release (4.9.9.2)
DeviceManagementQFolder
DivX
DivX Content Uploader
Download Updater (AOL LLC)
Easy Internet Sign-up
ESET Online Scanner v3
ESPNMotion
Family Feud™
FATE from Hewlett-Packard Laptops (remove only)
Final Drive Nitro from Hewlett-Packard Laptops (remove only)
Flip Words from Hewlett-Packard Laptops (remove only)
Free M4a to MP3 Converter 6.0
FullDPAppQFolder
Garmin Communicator Plugin
GemMaster Mystic
GoodOk Video Converter Gold 5.0
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
HP Game Console and games
HP Help and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Quick Launch Buttons 6.10 A2
HP QuickPlay 2.3
HP Rhapsody
HP Update
HP User Guides 0031
HP Wireless Assistant 2.00 G2
HpSdpAppCoreApp
Insaniquarium Deluxe from Hewlett-Packard Laptops (remove only)
InstantShareDevices
iTunes
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.0_02
Java 2 SDK, SE v1.4.0_02
Java™ 6 Update 11
Java™ 6 Update 7
Jewel Quest from Hewlett-Packard Laptops (remove only)
KeepV Flash Converter
Lemonade Tycoon 2 from Hewlett-Packard Laptops (remove only)
Lexibox Deluxe from Hewlett-Packard Laptops (remove only)
Lexmark Z700-P700 Series
LightScribe 1.4.97.1
LimeWire 4.18.8
LiveUpdate (Symantec Corporation)
Logitech Gaming Software
Macromedia Flash Player 8
Macromedia Shockwave Player
Mah Jong Quest from Hewlett-Packard Laptops (remove only)
Malwarebytes' Anti-Malware
McAfee SecurityCenter
McAfee Virtual Technician
Media Downloader
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2006
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Premium
Microsoft Office Standard Edition 2003
Microsoft Office XP Professional with FrontPage
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (2.0.0.20)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
muvee autoProducer 5.0
Netscape Browser (remove only)
NetWaiting
Norton Security Scan
NVIDIA Drivers
Oasis from Hewlett-Packard Laptops (remove only)
Office 2003 Trial Assistant
OptionalContentQFolder
Otto
PhotoGallery
pluginCreativity textArt
Polar Bowler from Hewlett-Packard Laptops (remove only)
Polar Golfer from Hewlett-Packard Laptops (remove only)
Project64 1.6
PSP Video 9 2.25
Puzzle Express from Hewlett-Packard Laptops (remove only)
Quicken 2006
QuickTime
RandMap
RealArcade
RealPlayer
Roxio Media Manager
SCRABBLE from Hewlett-Packard Laptops (remove only)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
SkinsHP1
Slingo Deluxe from Hewlett-Packard Laptops (remove only)
SlowGold
Slyder from Hewlett-Packard Laptops (remove only)
Snowboard SuperJam
Soft Data Fax Modem with SmartCP
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic Foundry ACID 4.0
Sonic MyDVD Plus
Sonic Update Manager
Sonic_PrimoSDK
SonicAC3Encoder
SonicMPEGEncoder
Sony ACID Music Studio 5.0
Sony ACID Music Studio 7.0
Spy Sweeper
Spy Sweeper Core
Super Granny from Hewlett-Packard Laptops (remove only)
SUPERAntiSpyware Free Edition
Synaptics Pointing Device Driver
TourSetup
Tradewinds from Hewlett-Packard Laptops (remove only)
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player
Vongo
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Media Center Edition 2005 KB925766
Windows XP Service Pack 3
WinZip 12.0
Wireless Home Network Setup
Yahoo! Toolbar
Yahoo! Toolbar for Internet Explorer
Zuma Deluxe from Hewlett-Packard Laptops (remove only)

==== Event Viewer Messages From Past Week ========

8/9/2009 10:44:42 AM, error: Service Control Manager [7031] - The McAfee SystemGuards service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/8/2009 4:46:58 PM, error: Service Control Manager [7031] - The McAfee SystemGuards service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/8/2009 4:24:51 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
8/8/2009 4:16:26 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
8/8/2009 4:06:22 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
8/8/2009 12:45:47 PM, error: System Error [1003] - Error code 100000d1, parameter1 e1f46000, parameter2 00000002, parameter3 00000000, parameter4 ed807125.
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The LexBce Server service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7034] - The Automatic LiveUpdate Scheduler service terminated unexpectedly. It has done this 1 time(s).
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/7/2009 9:04:30 AM, error: Service Control Manager [7031] - The AOL TopSpeed Monitor service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
8/7/2009 11:58:31 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the mcmscsvc service.
8/7/2009 11:15:18 AM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
8/7/2009 11:13:04 AM, error: System Error [1003] - Error code 100000d1, parameter1 e1f51000, parameter2 00000002, parameter3 00000000, parameter4 ed8a2125.
8/6/2009 6:54:38 AM, error: ACPIEC [1] - \Device\ACPIEC: The embedded controller (EC) hardware didn't respond within the timeout period. This may indicate an error in the EC hardware or firmware, or possibly a poorly designed BIOS which accesses the EC in an unsafe manner. The EC driver will retry the failed transaction if possible.
8/6/2009 10:11:23 AM, error: System Error [1003] - Error code 100000d1, parameter1 e1f49000, parameter2 00000002, parameter3 00000000, parameter4 ed807125.
8/6/2009 10:10:50 AM, error: System Error [1003] - Error code 100000d1, parameter1 e1f4d000, parameter2 00000002, parameter3 00000000, parameter4 ed8ac125.
8/5/2009 10:55:09 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
8/3/2009 5:41:27 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Bonjour Service service.
8/3/2009 4:25:03 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
8/3/2009 4:18:04 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service hpqwmiex with arguments "-Service" in order to run the server: {F5539356-2F02-40D4-999E-FA61F45FE12E}
8/3/2009 2:06:43 PM, error: LDMS [3023] - The Logical Disk Manager Service failed while registering for device handle notifications on device \\?\ide#cdromhl-dt-st_dvdram_gsa-4084n_______________kq09____#304b363253383446323520392020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}. Win32 Error: 1381.
8/3/2009 2:05:54 PM, error: Dhcp [1002] - The IP address lease 192.168.0.11 for the Network Card with network address 001A735C089F has been denied by the DHCP server 10.34.36.20 (The DHCP Server sent a DHCPNACK message).
8/10/2009 10:33:14 AM, error: Service Control Manager [7034] - The Message Queuing Triggers service terminated unexpectedly. It has done this 1 time(s).
8/10/2009 10:33:14 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
8/10/2009 10:33:13 AM, error: Service Control Manager [7034] - The Message Queuing service terminated unexpectedly. It has done this 1 time(s).
8/10/2009 10:33:12 AM, error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
8/10/2009 10:33:12 AM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.

==== End Of File ===========================










Here is the OTM log

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
C:\Documents and Settings\YM\My Documents\Azureus Downloads\[PC] Test Drive Unlimited [PROPER] [RIP] [dopeman]\TDU.7z moved successfully.
C:\Documents and Settings\YM\My Documents\Computer Games\TDU\TestDriveUnlimited.exe moved successfully.
C:\Documents and Settings\YM\My Documents\Incomplete\T-5905209-micheal jackson- human nature - bonus track.mp3 moved successfully.
C:\Documents and Settings\YM\My Documents\Shared2\i love music ahmad jamal.mp3 moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 16786 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 16786 bytes

User: User
->Temp folder emptied: 2784160 bytes
->Temporary Internet Files folder emptied: 78991 bytes
->FireFox cache emptied: 2911552 bytes

User: YM
->Temp folder emptied: 1285433214 bytes
File delete failed. C:\Documents and Settings\YM\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 111160670 bytes
->Java cache emptied: 52517941 bytes
->FireFox cache emptied: 55422540 bytes

%systemdrive% .tmp files removed: 0 bytes
C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP folder deleted successfully.
%systemroot% .tmp files removed: 61154 bytes
%systemroot%\System32 .tmp files removed: 4965905 bytes
File delete failed. C:\WINDOWS\temp\mcmsc_kvxAWWRsY1xaKGt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_LP2Y6zlgGhchUty scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_LQNrtDgx094aD7w scheduled to be deleted on reboot.
Windows Temp folder emptied: 46080 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1445.21 mb


OTM by OldTimer - Version 3.0.0.6 log created on 08102009_103302

Files moved on Reboot…
File C:\WINDOWS\temp\mcmsc_kvxAWWRsY1xaKGt not found!
File C:\WINDOWS\temp\mcmsc_LP2Y6zlgGhchUty not found!
File C:\WINDOWS\temp\mcmsc_LQNrtDgx094aD7w not found!

Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI