This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Warning! The contents of this web site can harm your

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have tried everything the different web sites and forums say to do to remove this. I have tried Malwarebytes,AVG,Symantec,SpyDr. and nothing. I have tried Gmer and DDS. Here are the logs of all..Please help
rocker44


MALWAREBYTES LOG:

Malwarebytes' Anti-Malware 1.40
Database version: 2628
Windows 5.1.2600 Service Pack 2

8/15/2009 6:36:17 AM
mbam-log-2009-08-15 (06-36-09).txt

Scan type: Quick Scan
Objects scanned: 101613
Time elapsed: 7 minute(s), 24 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 13

Memory Processes Infected:
C:\Program Files\Ascentive\Performance Center\ApcMain.exe (Adware.Ascentive) -> No action taken.
C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe (Rogue.PCSpeedScan) -> No action taken.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{10b3a0d2-3960-4d38-8158-d828a30f8db1} (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Adware.Ascentive) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe (Adware.DoubleD) -> No action taken.
HKEY_CLASSES_ROOT\aquaplay (Trojan.DNSChanger) -> No action taken.
HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\DoubleD (Adware.DoubleD) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760 (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760\bin (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Data (Adware.DoubleD) -> No action taken.

Files Infected:
C:\Program Files\Ascentive\Performance Center\ApcMain.exe (Adware.Ascentive) -> No action taken.
C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe (Rogue.PCSpeedScan) -> No action taken.
C:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760\bin\stbup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\bg.jpg (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\CurrentVersion.xml (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\icon.ico (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\productinfo.dll (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Setup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\stbup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\tdf.dat (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Data\ProductInfo.mx (Adware.DoubleD) -> No action taken.
C:\Program Files\SFX Machine LT.dll (Spyware.OnlineGames) -> No action taken.


DDS LOG:
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 13:01:06.95 on Sat 08/15/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2045.1360 [GMT -4:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
D:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
D:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\emaudsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\allen\Desktop\dds.pif

============== Pseudo HJT Report ===============

uDefault_Page_URL = hxxp://www.msn.com
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Performance Center] c:\program files\ascentive\performance center\ApcMain.exe -m
uRun: [E-MU USB Audio Control Panel] "c:\program files\creative professional\e-mu usb audio\e-mu usb audio\EmuUsbAudioCP.exe"
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
uRun: [UniblueSpeedUpMyPC] c:\program files\uniblue\speedupmypc\Launcher.exe -minimize
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Lexmark X74-X75] "c:\program files\lexmark x74-x75\lxbbbmgr.exe"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [H2O] c:\program files\syncrosoft\pos\h2o\cledx.exe
mRun: [VerizonServicepoint.exe] "c:\program files\verizon\vsp\VerizonServicepoint.exe" /AUTORUN
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\allen\startm~1\programs\startup\openof~1.lnk - d:\program files\openoffice.org 2.4\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,77,65,62,5c,72,65,6c-,61,74,65,64,2e,68,74,6d,00
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07}
LSP: c:\windows\system32\dcsource.dll
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248703385718
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: NavLogon - c:\windows\system32\NavLogon.dll
AppInit_DLLs: c:\progra~1\google\google~4\GOEC62~1.DLL

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-21 130936]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\codemeter\runtime\bin\CodeMeter.exe [2009-4-3 1680704]
R2 emaudsv;E-MU Audio Service;c:\windows\system32\emaudsv.exe [2006-11-20 10240]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-10-24 1813184]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2009-8-1 33792]
R3 emusba10;E-MU USB-Audio 1.0 Driver;c:\windows\system32\drivers\emusba10.sys [2006-11-20 142208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-12 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090814.004\naveng.sys [2009-8-14 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090814.004\navex15.sys [2009-8-14 875728]
S0 bhpftp;bhpftp;c:\windows\system32\drivers\hkztnm.sys –> c:\windows\system32\drivers\hkztnm.sys [?]
S2 gupdate1ca0a71a4770151;Google Update Service (gupdate1ca0a71a4770151);c:\program files\google\update\GoogleUpdate.exe [2009-7-21 133104]
S3 EraserUtilDrv10910;EraserUtilDrv10910;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv10910.sys –> c:\program files\common files\symantec shared\eengine\EraserUtilDrv10910.sys [?]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-6-24 30192]
S3 Radialpoint Security Services;Verizon PC Security Checkup Service;c:\program files\verizon\pc security checkup\RpsSecurityAwareR.exe [2009-8-14 170736]
S3 Rpcsvrvca_pr;Rpcsvrvca_pr;c:\windows\system32\drivers\amdk6.sys [2004-8-3 36992]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-10-24 116416]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-21 348752]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-7-21 1095560]

=============== Created Last 30 ================

2009-08-15 07:47 –d—– c:\program files\Trend Micro
2009-08-14 23:50 –d—– c:\docume~1\allen\applic~1\Malwarebytes
2009-08-14 23:49 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-14 23:49 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-14 23:49 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-14 23:49 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-14 14:35 –d—– c:\program files\Radialpoint
2009-08-14 12:09 73,728 a——- c:\windows\system32\rmpHTML.dll
2009-08-14 12:09 45,056 a——- c:\windows\system32\AxrmpHTML.dll
2009-08-14 12:09 868,352 a——- c:\windows\system32\rmpHTML.ocx
2009-08-14 12:09 249 a——- c:\windows\system32\windefht.bin
2009-08-14 12:09 –d—– C:\Abdio
2009-08-14 12:00 -cd-h— c:\docume~1\alluse~1\applic~1\{D9010FDD-3EED-44D9-9863-33B2D7362EC5}
2009-08-14 11:33 186,624 a——- c:\windows\system32\dcsource.dll
2009-08-14 11:32 –d—– c:\program files\BestAddress HTML Editor 2009 Professional
2009-08-14 11:24 –d—– c:\program files\qxyeed
2009-08-13 14:14 286,720 a——- c:\windows\iun507.exe
2009-08-13 14:14 –d—– c:\program files\PersonalWebKit3
2009-08-12 20:29 –d—– c:\documents and settings\allen\ErrorLogs
2009-08-12 19:57 –d—– c:\program files\Uniblue
2009-08-12 19:57 -cd-h— c:\docume~1\alluse~1\applic~1\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-08-12 12:42 0 a——- c:\windows\VPC32.INI
2009-08-12 12:40 109,744 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-08-12 12:40 48,816 a——- c:\windows\system32\S32EVNT1.DLL
2009-08-12 12:38 –d—– c:\program files\Symantec
2009-08-12 12:38 –d—– c:\program files\Symantec AntiVirus
2009-08-12 12:38 –d—– c:\docume~1\alluse~1\applic~1\Symantec
2009-08-12 12:33 –d—– C:\Symantec10.1.5
2009-08-10 22:28 –d—– c:\program files\common files\xing shared
2009-08-10 17:43 –d—– c:\docume~1\allen\applic~1\Forexyard
2009-08-10 17:42 –d—– C:\Forexyard
2009-08-08 22:53 –d—– c:\docume~1\allen\applic~1\Uniblue
2009-08-08 22:41 –d—– c:\docume~1\alluse~1\applic~1\Cakewalk
2009-08-08 22:29 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2009-08-08 22:29 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-08 22:29 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-08 22:29 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-08 21:43 –d—– c:\program files\MSXML 6.0
2009-08-08 21:41 –d—– c:\docume~1\allen\applic~1\Verizon
2009-08-08 21:41 –d—– c:\program files\Verizon
2009-08-08 21:41 –d—– c:\docume~1\alluse~1\applic~1\Verizon
2009-08-08 15:54 13 a——- c:\windows\system32\MSVC60SVV.DLL
2009-08-08 15:54 13 a——- c:\windows\MSOCREG.DAT
2009-08-04 13:16 57,344 a——- c:\windows\system32\Wnaspint.dll
2009-08-04 13:16 –d—– c:\program files\Acoustica Shared Effects
2009-08-04 13:16 –d—– c:\program files\Acoustica Mixcraft 3
2009-08-04 09:50 –d—– c:\docume~1\allen\applic~1\Digital Support
2009-08-04 09:49 –d—– c:\program files\Digital Support
2009-08-03 14:30 606,293 a——- c:\windows\system32\wbocx.ocx
2009-08-03 14:30 50,688 a——- c:\windows\system32\wbhelp2.dll
2009-08-03 14:30 –d—– c:\program files\Ipswitch
2009-08-03 13:41 319,488 a——- c:\windows\system32\PolarZIPLight.dll
2009-08-03 13:35 –d—– c:\docume~1\allen\applic~1\CoreFTP
2009-08-03 13:34 –d—– c:\program files\CoreFTP
2009-08-03 13:18 –d—– c:\docume~1\allen\applic~1\CoffeeCup Software
2009-08-02 11:32 189 a——- c:\windows\system32\.MySCMServerInfo
2009-08-02 11:32 –d—– c:\program files\DigiDesign
2009-08-01 22:23 –d—– c:\docume~1\alluse~1\applic~1\Steinberg
2009-08-01 22:12 –d—– c:\program files\common files\Steinberg
2009-08-01 19:01 87,040 a——- c:\windows\system32\ra32sipr.dll
2009-08-01 19:01 72,704 a——- c:\windows\system32\ra3228_8.dll
2009-08-01 19:01 21,504 a——- c:\windows\system32\ra32dnet.dll
2009-08-01 19:01 487,936 a——- c:\windows\system32\rmbe3260.dll
2009-08-01 19:01 352,768 a——- c:\windows\system32\pngu3263.dll
2009-08-01 19:01 131,072 a——- c:\windows\system32\pneng50.dll
2009-08-01 19:01 130,560 a——- c:\windows\system32\pnc3250.dll
2009-08-01 19:01 85,504 a——- c:\windows\system32\encdnet.dll
2009-08-01 19:01 81,920 a——- c:\windows\system32\ra3214_4.dll
2009-08-01 19:01 61,952 a——- c:\windows\system32\decdnet.dll
2009-08-01 18:59 33,792 a——- c:\windows\system32\drivers\cledx.sys
2009-08-01 18:59 147,425 a——- c:\windows\system32\SYNSOACC-Aide.chm
2009-08-01 18:59 120,468 a——- c:\windows\system32\SYNSOACC-Hilfe.chm
2009-08-01 18:59 114,279 a——- c:\windows\system32\SYNSOACC-Help.chm
2009-08-01 18:59 16,896 a——- c:\windows\system32\drivers\synasUSB.sys
2009-08-01 18:59 45,056 a——- c:\windows\system32\Synsopos.exe
2009-08-01 18:59 147,456 a——- c:\windows\system32\SynsoLChk.dll
2009-08-01 18:59 35,328 a——- c:\windows\system32\SYNSOACC.dll
2009-08-01 18:59 17,784 a——- c:\windows\system32\drivers\NSynas32.sys
2009-08-01 18:59 –d—– c:\program files\Syncrosoft
2009-08-01 14:45 –d—– c:\program files\Forex Strategy Builder
2009-07-30 14:01 416 a——- c:\windows\BeatBox.INI
2009-07-30 13:54 28 a——- c:\windows\Robota.INI
2009-07-30 11:17 1,294,336 a——- c:\windows\system32\vorbis.acm
2009-07-30 11:15 –d—– c:\program files\Image-Line
2009-07-30 10:20 0 a——- c:\windows\MusicStudio.INI
2009-07-30 10:19 –d—– c:\docume~1\alluse~1\applic~1\MAGIX
2009-07-30 10:19 –d—– c:\program files\common files\MAGIX Shared
2009-07-30 10:18 1,089,536 a——- c:\windows\system32\ROBOEX32.DLL
2009-07-30 10:18 49,152 a——- c:\windows\system32\INETWH32.dll
2009-07-30 10:18 –d—– c:\program files\MAGIX
2009-07-30 10:18 85,504 a——- c:\windows\system32\HtmlWH.dll
2009-07-30 10:18 663,552 a——- c:\windows\system32\mgxoschk.dll
2009-07-30 10:18 5,817 a——- c:\windows\mgxoschk.ini
2009-07-30 10:18 –d—– c:\windows\system32\MAGIX
2009-07-30 10:14 53,248 a——- c:\windows\system32\IKStompIO1API.dll
2009-07-30 10:06 –d—– c:\program files\common files\Acon Digital Media
2009-07-30 10:06 –d—– c:\program files\Acon Digital Media
2009-07-30 10:04 –d—– c:\docume~1\allen\applic~1\Thinstall
2009-07-30 00:58 –d—– c:\program files\EDIROL
2009-07-29 22:52 –d—– c:\docume~1\allen\applic~1\com.kewlshare.KewlManager.7FDCF29DEFD40899D06AD7AA1B082BD679DAC8B0.1
2009-07-29 01:20 594,432 -c—— c:\windows\system32\dllcache\msfeeds.dll
2009-07-29 01:20 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-28 14:44 73,728 a——- c:\windows\system32\javacpl.cpl
2009-07-27 10:55 -cd-h— c:\windows\ie8
2009-07-27 10:54 101,376 -c—— c:\windows\system32\dllcache\iecompat.dll
2009-07-27 10:54 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-07-27 10:54 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-07-27 10:54 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-07-27 10:54 11,067,392 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-07-27 10:10 –d—– c:\windows\system32\CatRoot_bak
2009-07-27 10:10 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2009-07-27 10:10 2,186,112 -c—— c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-27 10:10 2,142,720 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-27 10:10 2,062,976 -c—— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-07-27 10:10 2,020,864 -c—— c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-27 10:10 453,632 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2009-07-27 09:28 –d-h— c:\windows\msdownld.tmp
2009-07-27 01:13 19 a——- c:\documents and settings\allen\Settings.dat
2009-07-26 12:38 –d—– c:\program files\Steinberg
2009-07-26 12:38 –d—– c:\docume~1\allen\applic~1\Proteus VX
2009-07-26 12:37 1,706,800 ——– c:\windows\system32\gdiplus.dll
2009-07-25 18:25 –d—– c:\program files\Enigma Software Group
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresko.dll
2009-07-25 16:32 73,728 ac—— c:\windows\system32\dllcache\ehresja.dll
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresfr.dll
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresde.dll
2009-07-25 16:32 61,440 ac—— c:\windows\system32\dllcache\ehreschs.dll
2009-07-25 16:32 113,222 ac—— c:\windows\system32\dllcache\zoneclim.dll
2009-07-25 16:32 41,029 ac—— c:\windows\system32\dllcache\zcorem.dll
2009-07-25 16:32 36,937 ac—— c:\windows\system32\dllcache\zclientm.exe
2009-07-25 16:32 29,760 ac—— c:\windows\system32\dllcache\znetm.dll
2009-07-25 16:32 13,894 ac—— c:\windows\system32\dllcache\zonelibm.dll
2009-07-25 16:32 4,677 ac—— c:\windows\system32\dllcache\zeeverm.dll
2009-07-25 16:31 5,632 ac—— c:\windows\system32\dllcache\write.exe
2009-07-25 16:31 214,528 ac—— c:\windows\system32\dllcache\wordpad.exe
2009-07-25 16:31 221,184 ac—— c:\windows\system32\dllcache\wmpns.dll
2009-07-25 16:31 119,808 ac—— c:\windows\system32\dllcache\winmine.exe
2009-07-25 16:31 35,328 ac—— c:\windows\system32\dllcache\winchat.exe
2009-07-25 16:31 31,232 ac—— c:\windows\system32\dllcache\weitekp9.sys
2009-07-25 16:31 53,248 ac—— c:\windows\system32\dllcache\wamreg51.dll
2009-07-25 16:31 41,600 ac—— c:\windows\system32\dllcache\weitekp9.dll
2009-07-25 16:31 76,800 ac—— c:\windows\system32\dllcache\wam51.dll
2009-07-25 16:31 9,216 ac—— c:\windows\system32\dllcache\wamps51.dll
2009-07-25 16:31 363,520 ac—— c:\windows\system32\dllcache\w3svc.dll
2009-07-25 16:31 5,632 ac—— c:\windows\system32\dllcache\w3svapi.dll
2009-07-25 16:30 73,728 ac—— c:\windows\system32\dllcache\w3ext.dll
2009-07-25 16:30 48,256 ac—— c:\windows\system32\dllcache\w32.dll
2009-07-25 16:30 4,608 ac—— c:\windows\system32\dllcache\w3ctrs51.dll
2009-07-25 16:30 32,339 ac—— c:\windows\system32\dllcache\uniansi.dll
2009-07-25 16:30 103,424 ac—— c:\windows\system32\dllcache\uihelper.dll
2009-07-25 16:30 14,336 ac—— c:\windows\system32\dllcache\tsprof.exe
2009-07-25 16:30 31,232 ac—— c:\windows\system32\dllcache\tools.dll
2009-07-25 16:30 10,240 ac—— c:\windows\system32\dllcache\tmigrate.dll
2009-07-25 16:28 42,573 ac—— c:\windows\system32\dllcache\shvlzm.exe
2009-07-25 16:27 281,088 ac—— c:\windows\system32\dllcache\pinball.exe
2009-07-25 16:26 37,888 ac—— c:\windows\system32\dllcache\md5filt.dll
2009-07-25 16:25 6,144 ac—— c:\windows\system32\dllcache\kbdinpun.dll
2009-07-25 16:24 79,872 ac—— c:\windows\system32\dllcache\iislog51.dll
2009-07-25 16:24 60,928 ac—— c:\windows\system32\dllcache\iisclex4.dll
2009-07-25 16:24 19,456 ac—— c:\windows\system32\dllcache\iiscrmap.dll
2009-07-25 16:24 7,168 ac—— c:\windows\system32\dllcache\iisfecnv.dll
2009-07-25 16:24 6,656 ac—— c:\windows\system32\dllcache\iissync.exe
2009-07-25 16:24 3,584 ac—— c:\windows\system32\dllcache\iismui.dll
2009-07-25 16:24 145,408 ac—— c:\windows\system32\dllcache\iische51.dll
2009-07-25 16:24 25,088 ac—— c:\windows\system32\dllcache\iisadmin.dll
2009-07-25 16:23 10,096,640 ac—— c:\windows\system32\dllcache\hwxcht.dll
2009-07-25 16:23 61,440 ac—— c:\windows\system32\dllcache\httpod51.dll
2009-07-25 16:23 268,288 ac—— c:\windows\system32\dllcache\httpext.dll
2009-07-25 16:23 8,192 ac—— c:\windows\system32\dllcache\httpmb51.dll
2009-07-25 16:21 27,136 ac—— c:\windows\system32\dllcache\fxsdrv.dll
2009-07-25 16:20 33,792 ac—— c:\windows\system32\dllcache\controt.dll
2009-07-25 16:19 66,082 ac—— c:\windows\system32\dllcache\c_20284.nls
2009-07-25 16:18 19,456 ac—— c:\windows\system32\dllcache\agt040d.dll
2009-07-25 16:18 19,456 ac—— c:\windows\system32\dllcache\agt0401.dll
2009-07-25 16:18 49,664 ac—— c:\windows\system32\dllcache\adrot.dll
2009-07-25 16:18 5,632 ac—— c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-07-25 16:18 6,144 ac—— c:\windows\system32\dllcache\admxprox.dll
2009-07-25 16:18 29,696 ac—— c:\windows\system32\dllcache\admexs.dll
2009-07-25 16:18 183,808 ac—— c:\windows\system32\dllcache\accwiz.exe
2009-07-25 16:18 68,608 ac—— c:\windows\system32\dllcache\access.cpl
2009-07-25 16:18 10,240 ac—— c:\windows\system32\dllcache\npwmsdrm.dll
2009-07-25 16:16 20,541 ac—— c:\windows\system32\dllcache\fpexedll.dll
2009-07-25 16:15 188,480 ac—— c:\windows\system32\dllcache\cfgwiz.exe
2009-07-25 16:15 76,288 ac—— c:\windows\system32\dllcache\cnfgprts.ocx
2009-07-25 16:15 275,968 ac—— c:\windows\system32\dllcache\certwiz.ocx
2009-07-25 16:15 94,720 ac—— c:\windows\system32\dllcache\certmap.ocx
2009-07-25 16:15 290,816 ac—— c:\windows\system32\dllcache\adsiis51.dll
2009-07-25 16:15 20,540 ac—— c:\windows\system32\dllcache\author.dll
2009-07-25 16:15 16,439 ac—— c:\windows\system32\dllcache\author.exe
2009-07-25 16:15 43,520 ac—— c:\windows\system32\dllcache\admwprox.dll
2009-07-25 16:15 20,540 ac—— c:\windows\system32\dllcache\admin.dll
2009-07-25 16:15 16,439 ac—— c:\windows\system32\dllcache\admin.exe
2009-07-25 16:15 –d—– c:\program files\msn gaming zone
2009-07-25 16:10 488 a—hr– c:\windows\system32\logonui.exe.manifest
2009-07-25 16:10 749 a—hr– c:\windows\WindowsShell.Manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\wuaucpl.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\sapi.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\nwc.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\ncpa.cpl.manifest
2009-07-25 16:09 16,384 ac—— c:\windows\system32\dllcache\isignup.exe
2009-07-25 16:04 86,016 ac—— c:\windows\system32\dllcache\icwconn2.exe
2009-07-25 16:04 32,768 ac—— c:\windows\system32\dllcache\icwdl.dll
2009-07-25 16:04 20,480 ac—— c:\windows\system32\dllcache\inetwiz.exe
2009-07-25 16:03 214,528 ac—— c:\windows\system32\dllcache\icwconn1.exe
2009-07-25 15:44 24,661 ac—— c:\windows\system32\dllcache\spxcoins.dll
2009-07-25 15:44 13,312 ac—— c:\windows\system32\dllcache\irclass.dll
2009-07-25 15:44 24,661 a——- c:\windows\system32\spxcoins.dll
2009-07-25 15:44 13,312 a——- c:\windows\system32\irclass.dll
2009-07-23 14:32 –d—– c:\program files\Cakewalk
2009-07-23 14:32 –d—– C:\Cakewalk Projects
2009-07-22 15:53 138,752 ac—— c:\windows\system32\dllcache\sndvol32.exe
2009-07-22 15:53 138,752 a——- c:\windows\system32\sndvol32.exe
2009-07-22 13:49 –d—– c:\windows\system32\XPSViewer
2009-07-22 13:48 117,760 a——- c:\windows\system32\prntvpt.dll
2009-07-22 13:48 1,676,288 a——- c:\windows\system32\xpssvcs.dll
2009-07-22 13:48 575,488 a——- c:\windows\system32\xpsshhdr.dll
2009-07-21 22:16 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-07-21 22:16 130,936 a——- c:\windows\system32\drivers\PCTCore.sys
2009-07-21 22:16 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-21 22:16 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-07-21 22:16 –d—– c:\program files\common files\PC Tools
2009-07-21 22:16 –d—– c:\program files\Spyware Doctor
2009-07-21 22:16 –d—– c:\docume~1\alluse~1\applic~1\PC Tools
2009-07-21 22:16 –d—– c:\docume~1\allen\applic~1\PC Tools
2009-07-18 20:07 –d—– c:\program files\energyXT2
2009-07-17 16:14 –d—– c:\docume~1\allen\applic~1\CMplay
2009-07-17 12:13 –d—– c:\program files\REAPER

==================== Find3M ====================

2009-08-09 10:00 118,784 a——- c:\windows\dsdxirmv.exe
2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-28 14:44 410,984 a——- c:\windows\system32\deploytk.dll
2009-07-26 12:31 12,400 a——- c:\windows\system32\drivers\secdrv.sys
2009-07-25 16:01 34,284 a——- c:\windows\system32\emptyregdb.dat
2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-04 12:51 2,771,968 ——– c:\windows\system32\ReWire.dll
2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll
2009-06-27 21:11 87,747 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-25 14:36 661,504 a——- c:\windows\system32\mqqm.dll
2009-06-25 14:36 517,120 a——- c:\windows\system32\mqsnap.dll
2009-06-25 14:36 471,552 a——- c:\windows\system32\mqutil.dll
2009-06-25 14:36 225,280 a——- c:\windows\system32\mqoa.dll
2009-06-25 14:36 186,880 a——- c:\windows\system32\mqtrig.dll
2009-06-25 14:36 177,152 a——- c:\windows\system32\mqrt.dll
2009-06-25 14:36 138,240 a——- c:\windows\system32\mqad.dll
2009-06-25 14:36 123,392 a——- c:\windows\system32\mqrtdep.dll
2009-06-25 14:36 95,744 a——- c:\windows\system32\mqsec.dll
2009-06-25 14:36 48,640 a——- c:\windows\system32\mqupgrd.dll
2009-06-25 14:36 47,104 a——- c:\windows\system32\mqdscli.dll
2009-06-25 14:36 16,896 a——- c:\windows\system32\mqise.dll
2009-06-24 15:51 118,784 a——- c:\windows\SeaMonkeyUninstall.exe
2009-06-24 15:51 8,653 a——- c:\windows\mozver.dat
2009-06-24 15:51 118,784 a——- c:\windows\GREUninstall.exe
2009-06-22 07:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 07:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-22 07:48 91,776 a——- c:\windows\system32\drivers\mqac.sys
2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-14 15:43 24 a——- C:\DUKE3D.BAT
2009-06-12 07:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-10 10:21 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 02:32 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-06 21:23 43,520 a——- c:\windows\system32\CmdLineExt03.dll
2009-06-06 12:22 17,233 a——- c:\windows\unins000.dat
2009-06-06 12:21 678,746 a——- c:\windows\unins000.exe
2009-06-05 03:42 655,872 a——- c:\windows\system32\mstscax.dll
2009-06-03 15:27 1,290,752 a——- c:\windows\system32\quartz.dll
2009-05-30 14:08 737,280 a——- c:\windows\iun6002.exe
2009-05-25 00:34 13 —-h— c:\docume~1\alluse~1\applic~1\ÐÝÃÄ›.sys
2009-05-23 16:28 33,256 a—h— c:\windows\system32\mlfcache.dat
2009-05-21 19:22 27,136 a——- c:\windows\system32\pubdlg.dll
2009-05-21 19:22 12,288 a——- c:\windows\system32\picstore.dll
2009-05-21 19:22 161,552 a——- c:\windows\system32\asycpict.dll
2007-04-24 15:15 458,752 a——- c:\program files\common files\AmpliTubeJimiHendrix.dpm
2007-03-07 12:07 286 a——- c:\program files\common files\AmpliTubeJimiHendrix.dpm.rsr
2003-11-05 22:37 11,838 a——- c:\program files\SFX Machine LT Read Me.rtf
2002-07-31 19:55 106 —sh— c:\windows\WSYS049.SYS

============= FINISH: 13:01:57.06 ===============

GMER LOG:

GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-15 16:05:32
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

SSDT 89B8BB90 ZwAlertResumeThread
SSDT 89BC2808 ZwAlertThread
SSDT 89A9DC28 ZwAllocateVirtualMemory
SSDT 89A9E5E0 ZwConnectPort
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xBA6AF514]
SSDT 89B8C910 ZwCreateMutant
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xBA69E282]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xBA69E474]
SSDT 899C38C8 ZwCreateThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xBA6AFD00]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xBA6AFFB8]
SSDT 89BD6910 ZwFreeVirtualMemory
SSDT 89B8C720 ZwImpersonateAnonymousToken
SSDT 89B8BD30 ZwImpersonateThread
SSDT 89D1A890 ZwMapViewOfSection
SSDT 89B8CA98 ZwOpenEvent
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xBA6AE3FA]
SSDT 89BD67C8 ZwOpenProcessToken
SSDT 89ADA718 ZwOpenThreadToken
SSDT 89B8C7F0 ZwQueryValueKey
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xBA6B0422]
SSDT 89ABCAE0 ZwResumeThread
SSDT 89AEE728 ZwSetContextThread
SSDT 89BDB890 ZwSetInformationProcess
SSDT 89AEE760 ZwSetInformationThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xBA6AF7D8]
SSDT 89B8DC50 ZwSuspendProcess
SSDT 89BC2730 ZwSuspendThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xBA69DF32]
SSDT 89AEE8E0 ZwTerminateThread
SSDT 89AB9730 ZwUnmapViewOfSection
SSDT 89710368 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \FileSystem\Fastfat \Fat AFA54C8A

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

—- EOF - GMER 1.0.15 —-
Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
I did the ComboFix and so far everything seems OK. Thank You so Much.
Here is the Log:
ComboFix 09-08-10.06 - allen 08/16/2009 20:08.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2045.1429 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Search Settings
c:\program files\Search Settings\kb128\SearchSettings.dll
c:\program files\Search Settings\kb128\SearchSettingsRes409.dll
c:\program files\Search Settings\SearchSettings.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\Data
c:\windows\system32\dcsource.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\MSVC60SVV.DLL
c:\windows\system32\msvcsv60.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\slibjte.dll
c:\windows\system32\slibpopp.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\sslibjye.dll
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\system32\xpsys.dll

.
((((((((((((((((((((((((( Files Created from 2009-07-17 to 2009-08-17 )))))))))))))))))))))))))))))))
.

2009-08-16 23:35 . 2009-08-16 23:35 ——– d—–w- c:\documents and settings\allen\Application Data\GlarySoft
2009-08-16 23:32 . 2009-08-16 23:32 ——– d—–w- c:\program files\AskBarDis
2009-08-16 23:32 . 2009-08-16 23:32 ——– d—–w- c:\program files\Glary Utilities
2009-08-16 19:12 . 2009-08-16 19:12 ——– d—–w- c:\documents and settings\All Users\Application Data\SimCity Societies
2009-08-16 19:11 . 2009-08-16 19:11 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-08-16 18:28 . 2009-08-16 18:50 ——– d—–w- c:\program files\Electronic Arts
2009-08-16 18:15 . 2009-08-16 18:15 541 —-a-w- c:\windows\eReg.dat
2009-08-16 18:15 . 2009-08-16 18:15 ——– d—–w- c:\program files\Maxis
2009-08-16 04:26 . 2008-07-08 18:54 148496 —-a-w- c:\windows\system32\drivers\17189738.sys
2009-08-16 04:22 . 2009-08-17 00:18 34267168 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-16 04:11 . 2009-08-16 04:11 152576 —-a-w- c:\documents and settings\allen\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-16 03:57 . 2009-08-16 03:57 ——– d—–w- c:\documents and settings\All Users\Application Data\RegCure
2009-08-16 03:57 . 2009-08-16 03:57 ——– d—–w- c:\program files\RegCure
2009-08-16 02:30 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-08-16 02:14 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-16 02:13 . 2009-08-16 02:13 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-16 02:13 . 2009-07-08 17:28 2920112 -c–a-w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-08-16 02:13 . 2009-08-16 02:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-16 02:13 . 2009-08-16 02:13 ——– d—–w- c:\program files\Lavasoft
2009-08-15 11:47 . 2009-08-15 11:47 ——– d—–w- c:\program files\Trend Micro
2009-08-15 03:50 . 2009-08-15 03:50 ——– d—–w- c:\documents and settings\allen\Application Data\Malwarebytes
2009-08-15 03:49 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 03:49 . 2009-08-15 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-15 03:49 . 2009-08-15 16:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-15 03:49 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-14 18:35 . 2009-08-14 18:35 ——– d—–w- c:\program files\Radialpoint
2009-08-14 16:49 . 2009-08-14 16:49 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec
2009-08-14 16:47 . 2009-08-14 16:47 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-08-14 16:09 . 2006-10-17 02:57 45056 —-a-w- c:\windows\system32\AxrmpHTML.dll
2009-08-14 16:09 . 2006-10-17 02:57 73728 —-a-w- c:\windows\system32\rmpHTML.dll
2009-08-14 16:09 . 2009-08-14 16:09 ——– d—–w- C:\Abdio
2009-08-14 16:09 . 2007-06-14 22:00 249 —-a-w- c:\windows\system32\windefht.bin
2009-08-14 15:32 . 2009-08-14 15:59 ——– d—–w- c:\program files\BestAddress HTML Editor 2009 Professional
2009-08-14 15:24 . 2009-08-14 15:24 ——– d—–w- c:\program files\qxyeed
2009-08-13 18:14 . 2009-08-13 18:14 286720 —-a-w- c:\windows\iun507.exe
2009-08-13 18:14 . 2009-08-13 18:33 ——– d—–w- c:\program files\PersonalWebKit3
2009-08-13 00:29 . 2009-08-13 00:29 ——– d—–w- c:\documents and settings\allen\ErrorLogs
2009-08-12 23:57 . 2009-08-12 23:57 ——– d—–w- c:\program files\Uniblue
2009-08-12 16:51 . 2009-08-12 16:51 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2009-08-12 16:51 . 2009-08-12 16:51 ——– d-sh–w- c:\documents and settings\LocalService\IECompatCache
2009-08-12 16:40 . 2009-08-12 16:40 ——– d—–w- c:\documents and settings\allen\Local Settings\Application Data\Symantec
2009-08-12 16:40 . 2006-09-18 21:55 48816 —-a-w- c:\windows\system32\S32EVNT1.DLL
2009-08-12 16:40 . 2006-09-18 21:55 109744 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-08-12 16:38 . 2009-08-12 16:40 ——– d—–w- c:\program files\Symantec
2009-08-12 16:38 . 2009-08-17 00:15 ——– d—–w- c:\program files\Symantec AntiVirus
2009-08-12 16:38 . 2009-08-12 16:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-12 16:33 . 2009-08-12 16:33 ——– d—–w- C:\Symantec10.1.5
2009-08-11 02:28 . 2009-08-11 02:28 ——– d—–w- c:\program files\Common Files\xing shared
2009-08-10 21:43 . 2009-07-31 12:49 1662464 —-a-w- c:\documents and settings\allen\Application Data\Forexyard\APP#00E561EC\Fx_Client.exe
2009-08-10 21:43 . 2009-08-10 21:43 ——– d—–w- c:\documents and settings\allen\Application Data\Forexyard
2009-08-10 21:42 . 2009-08-10 21:45 ——– d—–w- C:\Forexyard
2009-08-09 02:53 . 2009-08-12 23:57 ——– d—–w- c:\documents and settings\allen\Application Data\Uniblue
2009-08-09 02:41 . 2009-08-09 17:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Cakewalk
2009-08-09 02:30 . 2009-08-16 02:14 103912 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-09 02:29 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-09 02:29 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-09 02:29 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-09 02:29 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-09 01:43 . 2009-08-09 01:43 ——– d—–w- c:\program files\MSXML 6.0
2009-08-09 01:41 . 2009-08-09 01:41 ——– d—–w- c:\documents and settings\allen\Application Data\Verizon
2009-08-09 01:41 . 2009-08-14 18:35 ——– d—–w- c:\program files\Verizon
2009-08-09 01:41 . 2009-08-14 18:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Verizon
2009-08-08 19:54 . 2009-08-09 14:43 13 —-a-w- c:\windows\MSOCREG.DAT
2009-08-04 17:16 . 2007-08-07 15:32 57344 —-a-w- c:\windows\system32\Wnaspint.dll
2009-08-04 17:16 . 2009-08-04 17:16 ——– d—–w- c:\program files\Acoustica Shared Effects
2009-08-04 17:16 . 2009-08-04 17:16 ——– d—–w- c:\program files\Acoustica Mixcraft 3
2009-08-04 13:50 . 2009-08-04 13:51 ——– d—–w- c:\documents and settings\allen\Application Data\Digital Support
2009-08-04 13:49 . 2009-08-04 13:50 ——– d—–w- c:\program files\Digital Support
2009-08-03 18:30 . 2009-08-03 18:30 ——– d—–w- c:\documents and settings\allen\Application Data\Ipswitch
2009-08-03 18:30 . 2009-08-03 18:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Ipswitch
2009-08-03 18:30 . 2009-05-13 14:32 50688 —-a-w- c:\windows\system32\wbhelp2.dll
2009-08-03 18:30 . 2009-08-03 18:30 ——– d—–w- c:\program files\Ipswitch
2009-08-03 17:41 . 2004-08-24 15:06 319488 —-a-w- c:\windows\system32\PolarZIPLight.dll
2009-08-03 17:35 . 2009-08-06 15:33 ——– d—–w- c:\documents and settings\allen\Application Data\CoreFTP
2009-08-03 17:34 . 2009-08-11 15:15 ——– d—–w- c:\program files\CoreFTP
2009-08-03 17:18 . 2009-08-14 02:16 ——– d—–w- c:\documents and settings\allen\Application Data\CoffeeCup Software
2009-08-02 15:32 . 2009-08-02 15:32 ——– d—–w- c:\program files\DigiDesign
2009-08-02 02:23 . 2009-08-02 02:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Steinberg
2009-08-02 02:12 . 2009-08-02 17:38 ——– d—–w- c:\program files\Common Files\Steinberg
2009-08-01 23:01 . 2005-06-04 13:09 72704 —-a-w- c:\windows\system32\ra3228_8.dll
2009-08-01 23:01 . 2005-06-04 13:09 21504 —-a-w- c:\windows\system32\ra32dnet.dll
2009-08-01 23:01 . 2005-06-04 13:08 87040 —-a-w- c:\windows\system32\ra32sipr.dll
2009-08-01 23:01 . 2005-06-04 13:11 85504 —-a-w- c:\windows\system32\encdnet.dll
2009-08-01 23:01 . 2005-06-04 13:09 61952 —-a-w- c:\windows\system32\decdnet.dll
2009-08-01 23:01 . 2005-06-04 13:09 130560 —-a-w- c:\windows\system32\pnc3250.dll
2009-08-01 23:01 . 2005-06-04 13:09 131072 —-a-w- c:\windows\system32\pneng50.dll
2009-08-01 23:01 . 2005-06-04 13:09 352768 —-a-w- c:\windows\system32\pngu3263.dll
2009-08-01 23:01 . 2005-06-04 13:09 81920 —-a-w- c:\windows\system32\ra3214_4.dll
2009-08-01 23:01 . 2005-06-04 13:08 487936 —-a-w- c:\windows\system32\rmbe3260.dll
2009-08-01 22:59 . 2005-05-10 00:08 33792 —-a-w- c:\windows\system32\drivers\cledx.sys
2009-08-01 22:59 . 2002-11-25 18:46 16896 —-a-w- c:\windows\system32\drivers\synasUSB.sys
2009-08-01 22:59 . 2002-11-25 21:36 45056 —-a-w- c:\windows\system32\Synsopos.exe
2009-08-01 22:59 . 2009-08-01 22:59 ——– d—–w- c:\program files\Syncrosoft
2009-08-01 22:59 . 2007-12-31 03:01 35328 —-a-w- c:\windows\system32\SYNSOACC.dll
2009-08-01 22:59 . 2004-05-11 04:58 147456 —-a-w- c:\windows\system32\SynsoLChk.dll
2009-08-01 22:59 . 2001-04-09 18:03 17784 —-a-w- c:\windows\system32\drivers\NSynas32.sys
2009-08-01 18:45 . 2009-08-01 18:45 ——– d—–w- c:\program files\Forex Strategy Builder
2009-07-30 15:15 . 2009-07-30 18:08 ——– d—–w- c:\program files\Image-Line
2009-07-30 14:18 . 2009-07-30 14:18 ——– d—–w- c:\program files\MAGIX
2009-07-30 14:18 . 2002-09-21 03:33 1089536 —-a-w- c:\windows\system32\ROBOEX32.DLL
2009-07-30 14:18 . 1999-01-28 17:44 49152 —-a-w- c:\windows\system32\INETWH32.dll
2009-07-30 14:18 . 1998-10-15 20:28 85504 —-a-w- c:\windows\system32\HtmlWH.dll
2009-07-30 14:18 . 2009-07-30 14:19 ——– d—–w- c:\windows\system32\MAGIX
2009-07-30 14:18 . 2007-02-07 14:53 663552 —-a-w- c:\windows\system32\mgxoschk.dll
2009-07-30 14:14 . 2008-01-17 16:00 53248 —-a-w- c:\windows\system32\IKStompIO1API.dll
2009-07-30 14:06 . 2009-08-02 17:50 ——– d—–w- c:\program files\Common Files\Acon Digital Media
2009-07-30 14:06 . 2009-07-30 14:06 ——– d—–w- c:\program files\Acon Digital Media
2009-07-30 14:04 . 2009-07-30 14:04 ——– d—–w- c:\documents and settings\allen\Local Settings\Application Data\Thinstall
2009-07-30 14:04 . 2009-07-30 14:04 ——– d—–w- c:\documents and settings\allen\Application Data\Thinstall
2009-07-30 04:58 . 2009-07-30 04:58 ——– d—–w- c:\program files\EDIROL
2009-07-30 02:52 . 2009-07-30 02:52 172 —-a-w- c:\documents and settings\allen\Application Data\com.kewlshare.KewlManager.7FDCF29DEFD40899D06AD7AA1B082BD679DAC8B0.1\Local Store\Kewlshare.user.dll
2009-07-30 02:52 . 2009-07-30 02:52 ——– d—–w- c:\documents and settings\allen\Application Data\com.kewlshare.KewlManager.7FDCF29DEFD40899D06AD7AA1B082BD679DAC8B0.1
2009-07-30 02:52 . 2009-07-30 02:52 38208 —-a-w- c:\documents and settings\allen\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-07-30 02:52 . 2009-07-30 02:52 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-07-29 05:20 . 2009-07-03 17:09 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-29 05:20 . 2009-07-03 17:09 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-28 18:44 . 2009-08-16 04:13 ——– d—–w- c:\program files\Java
2009-07-28 18:43 . 2009-07-28 18:43 152576 —-a-w- c:\documents and settings\allen\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-27 14:55 . 2009-07-27 14:56 ——– dc-h–w- c:\windows\ie8
2009-07-27 14:54 . 2009-07-01 07:08 101376 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-07-27 14:54 . 2009-07-03 17:09 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-07-27 14:54 . 2009-07-03 17:09 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-07-27 14:54 . 2009-07-03 17:09 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-27 14:54 . 2009-07-19 22:48 11067392 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-07-27 14:10 . 2009-07-27 14:21 ——– d—–w- c:\windows\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-17 00:18 . 2009-01-13 13:17 ——– d—–w- c:\documents and settings\allen\Application Data\OpenOffice.org2
2009-08-17 00:15 . 2009-08-16 04:22 403052 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-16 18:50 . 2008-12-21 22:42 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-16 17:38 . 2009-05-22 18:57 ——– d—–w- c:\program files\CoffeeCup Software
2009-08-15 11:12 . 2009-01-02 02:25 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-15 10:46 . 2009-01-24 18:15 ——– d—–w- c:\program files\Ascentive
2009-08-14 16:00 . 2009-08-14 16:00 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{D9010FDD-3EED-44D9-9863-33B2D7362EC5}
2009-08-13 18:35 . 2009-05-22 18:58 ——– d—–w- c:\program files\PageBreeze
2009-08-12 16:41 . 2009-03-01 01:42 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-11 02:28 . 2008-12-22 14:46 ——– d—–w- c:\program files\Common Files\Real
2009-08-09 17:23 . 2008-12-22 01:23 96 —-a-w- c:\windows\msocreg32.dat
2009-08-09 14:06 . 2008-12-21 23:20 ——– d—–w- c:\documents and settings\allen\Application Data\Cakewalk
2009-08-09 14:00 . 2008-12-21 23:00 118784 —-a-w- c:\windows\dsdxirmv.exe
2009-08-09 02:49 . 2008-12-21 17:51 39224 —-a-w- c:\documents and settings\allen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-08 18:04 . 2008-12-21 22:58 ——– d—–w- c:\program files\IK Multimedia
2009-08-08 18:03 . 2008-12-26 16:56 ——– d—–w- c:\documents and settings\All Users\Application Data\IK Multimedia
2009-08-05 09:11 . 2004-08-10 11:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 17:46 . 2009-07-17 16:13 ——– d—–w- c:\program files\REAPER
2009-08-02 17:44 . 2008-12-23 23:45 ——– d—–w- c:\documents and settings\allen\Application Data\REAPER
2009-08-02 02:31 . 2009-03-21 16:45 ——– d—–w- c:\documents and settings\allen\Application Data\Steinberg
2009-07-31 02:56 . 2009-06-07 11:10 ——– d—–w- c:\program files\ASIO4ALL v2
2009-07-30 17:40 . 2009-01-29 21:59 895 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap1.scr
2009-07-30 17:40 . 2009-01-29 21:59 17 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap5.scr
2009-07-30 17:40 . 2009-01-29 21:59 17 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap4.scr
2009-07-30 17:40 . 2009-01-29 21:59 17 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap3.scr
2009-07-30 17:40 . 2009-01-29 21:59 17 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap2.scr
2009-07-30 17:40 . 2009-01-29 21:59 0 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\FavPlugins.scr
2009-07-30 14:19 . 2009-07-30 14:19 ——– d—–w- c:\documents and settings\All Users\Application Data\MAGIX
2009-07-30 14:19 . 2009-07-30 14:19 ——– d—–w- c:\program files\Common Files\MAGIX Shared
2009-07-28 23:42 . 2009-06-03 18:37 ——– d—–w- c:\program files\FxPulp Trade station
2009-07-26 16:37 . 2008-12-21 22:49 ——– d—–w- c:\program files\Creative Professional
2009-07-26 16:31 . 2004-08-10 11:00 12400 —-a-w- c:\windows\system32\drivers\secdrv.sys
2009-07-25 20:01 . 2008-12-21 16:22 34284 —-a-w- c:\windows\system32\emptyregdb.dat
2009-07-25 17:28 . 2009-07-10 01:14 ——– d—–w- c:\program files\FXDD1 - MetaTrader 4
2009-07-25 17:28 . 2009-06-03 18:41 ——– d—–w- c:\program files\N2trader 4
2009-07-25 17:28 . 2009-05-31 22:30 ——– d—–w- c:\program files\Forex4you
2009-07-25 17:28 . 2009-05-31 20:48 ——– d—–w- c:\program files\MetaTrader - SigmaForex
2009-07-25 17:28 . 2009-02-22 22:32 ——– d—–w- c:\program files\MetaTrader - FXOpen
2009-07-25 17:28 . 2009-01-21 22:29 ——– d—–w- c:\program files\FXDD - MetaTrader 4
2009-07-25 17:28 . 2008-12-29 17:59 ——– d—–w- c:\program files\FXCM Trader 4
2009-07-25 09:23 . 2008-12-23 00:44 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-22 02:38 . 2009-01-19 21:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-22 02:17 . 2008-12-22 14:45 ——– d—–w- c:\program files\Google
2009-07-17 20:14 . 2009-07-17 20:14 ——– d—–w- c:\documents and settings\allen\Application Data\CMplay
2009-07-17 19:46 . 2008-12-21 22:58 ——– d—–w- c:\program files\VstPlugIns
2009-07-17 18:55 . 2004-08-10 11:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-16 23:37 . 2009-03-30 19:49 ——– d—–w- c:\documents and settings\allen\Application Data\Skype
2009-07-13 14:08 . 2004-08-10 11:00 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 22:03 . 2009-07-10 22:03 10710528 —-a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\L6TWXY.DLL
2009-07-10 22:03 . 2009-07-10 22:03 1534464 —-a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\data\twx\L6TWX.DLL
2009-07-10 22:02 . 2009-07-10 22:02 8192 —-a-r- c:\documents and settings\allen\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-07-10 22:02 . 2009-07-10 22:02 30208 —-a-r- c:\documents and settings\allen\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-07-10 22:02 . 2009-07-10 22:02 14848 —-a-r- c:\documents and settings\allen\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe
2009-07-10 22:02 . 2009-07-10 22:02 ——– d—–w- c:\program files\CodeMeter
2009-07-10 22:02 . 2009-07-04 16:43 ——– d—–w- c:\program files\Propellerhead
2009-07-09 20:34 . 2009-07-09 20:34 ——– d—–w- c:\documents and settings\allen\Application Data\Line 6
2009-07-09 20:34 . 2009-07-09 20:34 ——– d—–w- c:\program files\Line6
2009-07-09 20:18 . 2009-07-09 20:18 ——– d—–w- c:\program files\Pinnacle
2009-07-09 20:16 . 2009-07-09 20:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Pinnacle
2009-07-05 13:52 . 2009-05-02 16:38 ——– d—–w- c:\documents and settings\allen\Application Data\ScanSpyware
2009-07-04 16:51 . 2009-07-04 16:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Line 6
2009-07-04 16:51 . 2009-07-04 16:51 2771968 ——w- c:\windows\system32\ReWire.dll
2009-07-04 16:50 . 2008-12-23 23:52 ——– d—–w- c:\documents and settings\allen\Application Data\Propellerhead Software
2009-07-03 17:09 . 2006-03-04 03:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-28 01:11 . 2008-12-21 16:47 87747 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-25 18:36 . 2004-08-10 11:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-10 11:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-10 11:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-10 11:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-10 11:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-10 11:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-10 11:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-10 11:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-10 11:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-10 11:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-10 11:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2004-08-10 11:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-24 19:51 . 2009-06-20 22:36 335 —-a-w- c:\windows\nsreg.dat
2009-06-24 19:51 . 2009-06-24 19:51 118784 —-a-w- c:\windows\SeaMonkeyUninstall.exe
2009-06-24 19:51 . 2009-06-24 19:50 8653 —-a-w- c:\windows\mozver.dat
2009-06-24 19:51 . 2009-06-24 19:51 118784 —-a-w- c:\windows\GREUninstall.exe
2009-06-24 19:50 . 2009-06-24 19:50 ——– d—–w- c:\program files\mozilla.org
2009-06-24 19:15 . 2009-06-21 04:44 293 —-a-w- c:\windows\FTJ40MTI.DAT
2009-06-24 04:00 . 2009-05-17 14:33 ——– d—–w- c:\documents and settings\allen\Application Data\RomeCasino
2009-06-24 03:40 . 2009-05-17 14:33 ——– d—–w- c:\program files\RomeCasino
2009-06-23 00:52 . 2009-06-19 23:55 ——– d—–w- c:\program files\Hidden Expedition - Amazon
2009-06-22 11:49 . 2004-08-10 11:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-10 11:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2004-08-10 11:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2004-08-10 11:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-21 04:59 . 2009-06-21 04:58 ——– d—–w- c:\program files\MTI Client Services Inc
2009-06-21 04:58 . 2009-06-21 04:58 ——– d—–w- c:\documents and settings\allen\Application Data\MTI Client Services Inc
2009-06-20 09:48 . 2009-01-02 02:24 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-06-19 23:53 . 2009-01-02 02:24 ——– d—–w- c:\program files\bfgclient
2009-06-16 14:55 . 2004-08-10 11:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-10 11:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-14 19:43 . 2009-06-14 19:33 24 —-a-w- C:\DUKE3D.BAT
2009-06-12 11:50 . 2004-08-10 11:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 2004-08-10 11:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 2004-08-10 11:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-24 20:00 . 2009-06-24 20:00 122880 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2002-07-31 23:55 . 2009-05-24 00:08 106 –sh–w- c:\windows\WSYS049.SYS
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 21:20 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-31 68856]
"E-MU USB Audio Control Panel"="c:\program files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe" [2006-11-18 274432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-06-24 30192]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-09-13 7696384]
"Lexmark X74-X75"="c:\program files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-05-11 200069]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2009-03-12 2303216]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-10-24 125120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-27 282624]

c:\documents and settings\allen\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - d:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-7-31 393216]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi3"=xgusb.cpl

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Radialpoint Security Services]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\microsoft frontpage\\bin\\fpexplor.exe"=
"c:\\FrontPage Webs\\Server\\vhttpd32.exe"=
"f:\\Program Files\\prism3d.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Ipswitch\\WS_FTP 12\\UpWiz.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/15/2009 10:14 PM 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/21/2009 10:16 PM 130936]
R1 is-6UQDUdrv;is-6UQDUdrv;c:\windows\system32\drivers\17189738.sys [8/16/2009 12:26 AM 148496]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [4/3/2009 4:01 AM 1680704]
R2 emaudsv;E-MU Audio Service;c:\windows\system32\emaudsv.exe [11/20/2006 5:29 AM 10240]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 AM 1029456]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [8/1/2009 6:59 PM 33792]
R3 emusba10;E-MU USB-Audio 1.0 Driver;c:\windows\system32\drivers\emusba10.sys [11/20/2006 5:29 AM 142208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/12/2009 12:41 PM 101936]
S0 bhpftp;bhpftp;c:\windows\system32\drivers\hkztnm.sys –> c:\windows\system32\drivers\hkztnm.sys [?]
S2 gupdate1ca0a71a4770151;Google Update Service (gupdate1ca0a71a4770151);c:\program files\Google\Update\GoogleUpdate.exe [7/21/2009 10:10 PM 133104]
S3 EraserUtilDrv10910;EraserUtilDrv10910;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [?]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [6/24/2009 4:00 PM 30192]
S3 Radialpoint Security Services;Verizon PC Security Checkup Service;c:\program files\Verizon\PC Security Checkup\RpsSecurityAwareR.exe [8/14/2009 2:35 PM 170736]
S3 Rpcsvrvca_pr;Rpcsvrvca_pr;c:\windows\system32\drivers\amdk6.sys [8/3/2004 6:59 PM 36992]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/24/2006 7:32 PM 116416]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/21/2009 10:16 PM 348752]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-16 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-08-17 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-08-16 14:30]

2009-08-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-23 20:00]

2009-08-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-22 02:10]

2009-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-22 02:10]

2009-08-17 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-08-17 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-08-16 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]
.
- - - - ORPHANS REMOVED - - - -

BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)


.
——- Supplementary Scan ——-
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,77,65,62,5c,72,65,6c-,61,74,65,64,2e,68,74,6d,00
FF - ProfilePath - c:\documents and settings\allen\Application Data\Mozilla\Firefox\Profiles\s9swjhl4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - plugin: c:\program files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Verizon\VSP\nprpspa.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-

FF - user.js: browser.download.manager.showAlertOnComplete - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-16 20:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2872)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark X74-X75\lxbbbmon.exe
d:\program files\OpenOffice.org 2.4\program\soffice.exe
d:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2009-08-17 20:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-17 00:28

Pre-Run: 6,287,585,280 bytes free
Post-Run: 6,162,034,688 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /fastdetect /noexecute=optin

Current=3 Default=3 Failed=0 LastKnownGood=4 Sets=1,2,3,4
435 — E O F — 2009-08-15 03:15

Again Thank You so Much
Allen
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Warning_contents_web_site_can_harm_your_computer_t106161.html&view=findpost&p=588229#entry588229

KillAll::

Collect::
c:\windows\system32\drivers\17189738.sys

Folder::
c:\program files\qxyeed

Driver::
is-6UQDUdrv

DDS::
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,77,65,62,5c,72,65,6c-,61,74,65,64,2e,68,74,6d,00

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.



NEXT


  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\windows\system32\drivers\hkztnm.sys

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Hello again
I redid the combofix like you asked and the log is below. When I tried to do the Vir Scan I could not paste "c:\windows\system32\drivers\hkztnm.sys "
into the suspicious file blank space. I could nopt type it in nor did the file show up when I did a "browse".
Anyway here is the Combofix log:

ComboFix 09-08-10.06 - allen 08/17/2009 22:21.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2045.1556 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\allen\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

file zipped: c:\windows\system32\drivers\17189738.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\qxyeed
c:\program files\qxyeed\fngdsysguard.exe
c:\windows\system32\drivers\17189738.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IS-6UQDUDRV
——-\Service_is-6UQDUdrv


((((((((((((((((((((((((( Files Created from 2009-07-18 to 2009-08-18 )))))))))))))))))))))))))))))))
.

2009-08-16 23:35 . 2009-08-16 23:35 ——– d—–w- c:\documents and settings\allen\Application Data\GlarySoft
2009-08-16 23:32 . 2009-08-17 03:37 ——– d—–w- c:\program files\AskBarDis
2009-08-16 23:32 . 2009-08-16 23:32 ——– d—–w- c:\program files\Glary Utilities
2009-08-16 19:12 . 2009-08-16 19:12 ——– d—–w- c:\documents and settings\All Users\Application Data\SimCity Societies
2009-08-16 19:11 . 2009-08-16 19:11 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-08-16 18:28 . 2009-08-16 18:50 ——– d—–w- c:\program files\Electronic Arts
2009-08-16 18:15 . 2009-08-16 18:15 541 —-a-w- c:\windows\eReg.dat
2009-08-16 18:15 . 2009-08-16 18:15 ——– d—–w- c:\program files\Maxis
2009-08-16 04:22 . 2009-08-18 02:31 54960160 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-16 04:11 . 2009-08-16 04:11 152576 —-a-w- c:\documents and settings\allen\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-16 03:57 . 2009-08-16 03:57 ——– d—–w- c:\documents and settings\All Users\Application Data\RegCure
2009-08-16 03:57 . 2009-08-16 03:57 ——– d—–w- c:\program files\RegCure
2009-08-16 02:30 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-08-16 02:14 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-16 02:13 . 2009-08-16 02:13 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-16 02:13 . 2009-07-08 17:28 2920112 -c–a-w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-08-16 02:13 . 2009-08-16 02:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-16 02:13 . 2009-08-16 02:13 ——– d—–w- c:\program files\Lavasoft
2009-08-15 11:47 . 2009-08-15 11:47 ——– d—–w- c:\program files\Trend Micro
2009-08-15 03:50 . 2009-08-15 03:50 ——– d—–w- c:\documents and settings\allen\Application Data\Malwarebytes
2009-08-15 03:49 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 03:49 . 2009-08-15 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-15 03:49 . 2009-08-15 16:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-15 03:49 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-14 18:35 . 2009-08-14 18:35 ——– d—–w- c:\program files\Radialpoint
2009-08-14 16:49 . 2009-08-14 16:49 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec
2009-08-14 16:47 . 2009-08-14 16:47 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-08-14 16:09 . 2006-10-17 02:57 45056 —-a-w- c:\windows\system32\AxrmpHTML.dll
2009-08-14 16:09 . 2006-10-17 02:57 73728 —-a-w- c:\windows\system32\rmpHTML.dll
2009-08-14 16:09 . 2009-08-14 16:09 ——– d—–w- C:\Abdio
2009-08-14 16:09 . 2007-06-14 22:00 249 —-a-w- c:\windows\system32\windefht.bin
2009-08-14 15:32 . 2009-08-14 15:59 ——– d—–w- c:\program files\BestAddress HTML Editor 2009 Professional
2009-08-13 18:14 . 2009-08-13 18:14 286720 —-a-w- c:\windows\iun507.exe
2009-08-13 18:14 . 2009-08-13 18:33 ——– d—–w- c:\program files\PersonalWebKit3
2009-08-13 00:29 . 2009-08-13 00:29 ——– d—–w- c:\documents and settings\allen\ErrorLogs
2009-08-12 23:57 . 2009-08-12 23:57 ——– d—–w- c:\program files\Uniblue
2009-08-12 16:51 . 2009-08-12 16:51 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2009-08-12 16:51 . 2009-08-12 16:51 ——– d-sh–w- c:\documents and settings\LocalService\IECompatCache
2009-08-12 16:40 . 2009-08-12 16:40 ——– d—–w- c:\documents and settings\allen\Local Settings\Application Data\Symantec
2009-08-12 16:40 . 2006-09-18 21:55 48816 —-a-w- c:\windows\system32\S32EVNT1.DLL
2009-08-12 16:40 . 2006-09-18 21:55 109744 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-08-12 16:38 . 2009-08-12 16:40 ——– d—–w- c:\program files\Symantec
2009-08-12 16:38 . 2009-08-18 02:31 ——– d—–w- c:\program files\Symantec AntiVirus
2009-08-12 16:38 . 2009-08-12 16:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-12 16:33 . 2009-08-12 16:33 ——– d—–w- C:\Symantec10.1.5
2009-08-11 02:28 . 2009-08-11 02:28 ——– d—–w- c:\program files\Common Files\xing shared
2009-08-10 21:43 . 2009-07-31 12:49 1662464 —-a-w- c:\documents and settings\allen\Application Data\Forexyard\APP#00E561EC\Fx_Client.exe
2009-08-10 21:43 . 2009-08-10 21:43 ——– d—–w- c:\documents and settings\allen\Application Data\Forexyard
2009-08-10 21:42 . 2009-08-10 21:45 ——– d—–w- C:\Forexyard
2009-08-09 02:53 . 2009-08-12 23:57 ——– d—–w- c:\documents and settings\allen\Application Data\Uniblue
2009-08-09 02:41 . 2009-08-09 17:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Cakewalk
2009-08-09 02:30 . 2009-08-16 02:14 103912 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-09 02:29 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-09 02:29 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-09 02:29 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-09 02:29 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-09 01:43 . 2009-08-09 01:43 ——– d—–w- c:\program files\MSXML 6.0
2009-08-09 01:41 . 2009-08-09 01:41 ——– d—–w- c:\documents and settings\allen\Application Data\Verizon
2009-08-09 01:41 . 2009-08-14 18:35 ——– d—–w- c:\program files\Verizon
2009-08-09 01:41 . 2009-08-14 18:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Verizon
2009-08-08 19:54 . 2009-08-09 14:43 13 —-a-w- c:\windows\MSOCREG.DAT
2009-08-04 17:16 . 2007-08-07 15:32 57344 —-a-w- c:\windows\system32\Wnaspint.dll
2009-08-04 17:16 . 2009-08-04 17:16 ——– d—–w- c:\program files\Acoustica Shared Effects
2009-08-04 17:16 . 2009-08-04 17:16 ——– d—–w- c:\program files\Acoustica Mixcraft 3
2009-08-04 13:50 . 2009-08-04 13:51 ——– d—–w- c:\documents and settings\allen\Application Data\Digital Support
2009-08-04 13:49 . 2009-08-04 13:50 ——– d—–w- c:\program files\Digital Support
2009-08-03 18:30 . 2009-08-03 18:30 ——– d—–w- c:\documents and settings\allen\Application Data\Ipswitch
2009-08-03 18:30 . 2009-08-03 18:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Ipswitch
2009-08-03 18:30 . 2009-05-13 14:32 50688 —-a-w- c:\windows\system32\wbhelp2.dll
2009-08-03 18:30 . 2009-08-03 18:30 ——– d—–w- c:\program files\Ipswitch
2009-08-03 17:41 . 2004-08-24 15:06 319488 —-a-w- c:\windows\system32\PolarZIPLight.dll
2009-08-03 17:35 . 2009-08-06 15:33 ——– d—–w- c:\documents and settings\allen\Application Data\CoreFTP
2009-08-03 17:34 . 2009-08-11 15:15 ——– d—–w- c:\program files\CoreFTP
2009-08-03 17:18 . 2009-08-14 02:16 ——– d—–w- c:\documents and settings\allen\Application Data\CoffeeCup Software
2009-08-02 15:32 . 2009-08-02 15:32 ——– d—–w- c:\program files\DigiDesign
2009-08-02 02:23 . 2009-08-02 02:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Steinberg
2009-08-02 02:12 . 2009-08-02 17:38 ——– d—–w- c:\program files\Common Files\Steinberg
2009-08-01 23:01 . 2005-06-04 13:09 72704 —-a-w- c:\windows\system32\ra3228_8.dll
2009-08-01 23:01 . 2005-06-04 13:09 21504 —-a-w- c:\windows\system32\ra32dnet.dll
2009-08-01 23:01 . 2005-06-04 13:08 87040 —-a-w- c:\windows\system32\ra32sipr.dll
2009-08-01 23:01 . 2005-06-04 13:11 85504 —-a-w- c:\windows\system32\encdnet.dll
2009-08-01 23:01 . 2005-06-04 13:09 61952 —-a-w- c:\windows\system32\decdnet.dll
2009-08-01 23:01 . 2005-06-04 13:09 130560 —-a-w- c:\windows\system32\pnc3250.dll
2009-08-01 23:01 . 2005-06-04 13:09 131072 —-a-w- c:\windows\system32\pneng50.dll
2009-08-01 23:01 . 2005-06-04 13:09 352768 —-a-w- c:\windows\system32\pngu3263.dll
2009-08-01 23:01 . 2005-06-04 13:09 81920 —-a-w- c:\windows\system32\ra3214_4.dll
2009-08-01 23:01 . 2005-06-04 13:08 487936 —-a-w- c:\windows\system32\rmbe3260.dll
2009-08-01 22:59 . 2005-05-10 00:08 33792 —-a-w- c:\windows\system32\drivers\cledx.sys
2009-08-01 22:59 . 2002-11-25 18:46 16896 —-a-w- c:\windows\system32\drivers\synasUSB.sys
2009-08-01 22:59 . 2002-11-25 21:36 45056 —-a-w- c:\windows\system32\Synsopos.exe
2009-08-01 22:59 . 2009-08-01 22:59 ——– d—–w- c:\program files\Syncrosoft
2009-08-01 22:59 . 2007-12-31 03:01 35328 —-a-w- c:\windows\system32\SYNSOACC.dll
2009-08-01 22:59 . 2004-05-11 04:58 147456 —-a-w- c:\windows\system32\SynsoLChk.dll
2009-08-01 22:59 . 2001-04-09 18:03 17784 —-a-w- c:\windows\system32\drivers\NSynas32.sys
2009-08-01 18:45 . 2009-08-01 18:45 ——– d—–w- c:\program files\Forex Strategy Builder
2009-07-30 15:15 . 2009-07-30 18:08 ——– d—–w- c:\program files\Image-Line
2009-07-30 14:18 . 2009-07-30 14:18 ——– d—–w- c:\program files\MAGIX
2009-07-30 14:18 . 2002-09-21 03:33 1089536 —-a-w- c:\windows\system32\ROBOEX32.DLL
2009-07-30 14:18 . 1999-01-28 17:44 49152 —-a-w- c:\windows\system32\INETWH32.dll
2009-07-30 14:18 . 1998-10-15 20:28 85504 —-a-w- c:\windows\system32\HtmlWH.dll
2009-07-30 14:18 . 2009-07-30 14:19 ——– d—–w- c:\windows\system32\MAGIX
2009-07-30 14:18 . 2007-02-07 14:53 663552 —-a-w- c:\windows\system32\mgxoschk.dll
2009-07-30 14:14 . 2008-01-17 16:00 53248 —-a-w- c:\windows\system32\IKStompIO1API.dll
2009-07-30 14:06 . 2009-08-02 17:50 ——– d—–w- c:\program files\Common Files\Acon Digital Media
2009-07-30 14:06 . 2009-07-30 14:06 ——– d—–w- c:\program files\Acon Digital Media
2009-07-30 14:04 . 2009-07-30 14:04 ——– d—–w- c:\documents and settings\allen\Local Settings\Application Data\Thinstall
2009-07-30 14:04 . 2009-07-30 14:04 ——– d—–w- c:\documents and settings\allen\Application Data\Thinstall
2009-07-30 04:58 . 2009-07-30 04:58 ——– d—–w- c:\program files\EDIROL
2009-07-30 02:52 . 2009-07-30 02:52 172 —-a-w- c:\documents and settings\allen\Application Data\com.kewlshare.KewlManager.7FDCF29DEFD40899D06AD7AA1B082BD679DAC8B0.1\Local Store\Kewlshare.user.dll
2009-07-30 02:52 . 2009-07-30 02:52 ——– d—–w- c:\documents and settings\allen\Application Data\com.kewlshare.KewlManager.7FDCF29DEFD40899D06AD7AA1B082BD679DAC8B0.1
2009-07-30 02:52 . 2009-07-30 02:52 38208 —-a-w- c:\documents and settings\allen\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-07-30 02:52 . 2009-07-30 02:52 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-07-29 05:20 . 2009-07-03 17:09 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-29 05:20 . 2009-07-03 17:09 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-28 18:44 . 2009-08-16 04:13 ——– d—–w- c:\program files\Java
2009-07-28 18:43 . 2009-07-28 18:43 152576 —-a-w- c:\documents and settings\allen\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-27 14:55 . 2009-07-27 14:56 ——– dc-h–w- c:\windows\ie8
2009-07-27 14:54 . 2009-07-01 07:08 101376 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-07-27 14:54 . 2009-07-03 17:09 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-07-27 14:54 . 2009-07-03 17:09 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-07-27 14:54 . 2009-07-03 17:09 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-27 14:54 . 2009-07-19 22:48 11067392 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-07-27 14:10 . 2009-07-27 14:21 ——– d—–w- c:\windows\system32\CatRoot_bak
2009-07-27 14:10 . 2008-06-13 13:10 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-07-27 14:10 . 2009-02-06 10:32 2186112 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-18 02:35 . 2009-01-13 13:17 ——– d—–w- c:\documents and settings\allen\Application Data\OpenOffice.org2
2009-08-18 02:31 . 2009-08-16 04:22 647228 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-16 18:50 . 2008-12-21 22:42 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-16 17:38 . 2009-05-22 18:57 ——– d—–w- c:\program files\CoffeeCup Software
2009-08-15 11:12 . 2009-01-02 02:25 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-15 10:46 . 2009-01-24 18:15 ——– d—–w- c:\program files\Ascentive
2009-08-14 16:00 . 2009-08-14 16:00 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{D9010FDD-3EED-44D9-9863-33B2D7362EC5}
2009-08-13 18:35 . 2009-05-22 18:58 ——– d—–w- c:\program files\PageBreeze
2009-08-12 16:41 . 2009-03-01 01:42 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-11 02:28 . 2008-12-22 14:46 ——– d—–w- c:\program files\Common Files\Real
2009-08-09 17:23 . 2008-12-22 01:23 96 —-a-w- c:\windows\msocreg32.dat
2009-08-09 14:06 . 2008-12-21 23:20 ——– d—–w- c:\documents and settings\allen\Application Data\Cakewalk
2009-08-09 14:00 . 2008-12-21 23:00 118784 —-a-w- c:\windows\dsdxirmv.exe
2009-08-09 02:49 . 2008-12-21 17:51 39224 —-a-w- c:\documents and settings\allen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-08 18:04 . 2008-12-21 22:58 ——– d—–w- c:\program files\IK Multimedia
2009-08-08 18:03 . 2008-12-26 16:56 ——– d—–w- c:\documents and settings\All Users\Application Data\IK Multimedia
2009-08-05 09:11 . 2004-08-10 11:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 17:46 . 2009-07-17 16:13 ——– d—–w- c:\program files\REAPER
2009-08-02 17:44 . 2008-12-23 23:45 ——– d—–w- c:\documents and settings\allen\Application Data\REAPER
2009-08-02 02:31 . 2009-03-21 16:45 ——– d—–w- c:\documents and settings\allen\Application Data\Steinberg
2009-07-31 02:56 . 2009-06-07 11:10 ——– d—–w- c:\program files\ASIO4ALL v2
2009-07-30 17:40 . 2009-01-29 21:59 895 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap1.scr
2009-07-30 17:40 . 2009-01-29 21:59 17 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap5.scr
2009-07-30 17:40 . 2009-01-29 21:59 17 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap4.scr
2009-07-30 17:40 . 2009-01-29 21:59 17 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap3.scr
2009-07-30 17:40 . 2009-01-29 21:59 17 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\Browser\Snap2.scr
2009-07-30 17:40 . 2009-01-29 21:59 0 —-a-w- c:\documents and settings\allen\Application Data\Thinstall\FL\%ProgramFilesDir%\FL Studio 7\System\Config\FavPlugins.scr
2009-07-30 14:19 . 2009-07-30 14:19 ——– d—–w- c:\documents and settings\All Users\Application Data\MAGIX
2009-07-30 14:19 . 2009-07-30 14:19 ——– d—–w- c:\program files\Common Files\MAGIX Shared
2009-07-28 23:42 . 2009-06-03 18:37 ——– d—–w- c:\program files\FxPulp Trade station
2009-07-26 16:37 . 2008-12-21 22:49 ——– d—–w- c:\program files\Creative Professional
2009-07-26 16:31 . 2004-08-10 11:00 12400 —-a-w- c:\windows\system32\drivers\secdrv.sys
2009-07-25 20:01 . 2008-12-21 16:22 34284 —-a-w- c:\windows\system32\emptyregdb.dat
2009-07-25 17:28 . 2009-07-10 01:14 ——– d—–w- c:\program files\FXDD1 - MetaTrader 4
2009-07-25 17:28 . 2009-06-03 18:41 ——– d—–w- c:\program files\N2trader 4
2009-07-25 17:28 . 2009-05-31 22:30 ——– d—–w- c:\program files\Forex4you
2009-07-25 17:28 . 2009-05-31 20:48 ——– d—–w- c:\program files\MetaTrader - SigmaForex
2009-07-25 17:28 . 2009-02-22 22:32 ——– d—–w- c:\program files\MetaTrader - FXOpen
2009-07-25 17:28 . 2009-01-21 22:29 ——– d—–w- c:\program files\FXDD - MetaTrader 4
2009-07-25 17:28 . 2008-12-29 17:59 ——– d—–w- c:\program files\FXCM Trader 4
2009-07-25 09:23 . 2008-12-23 00:44 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-22 02:38 . 2009-01-19 21:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-22 02:17 . 2008-12-22 14:45 ——– d—–w- c:\program files\Google
2009-07-20 09:50 . 2009-07-19 00:07 ——– d—–w- c:\program files\energyXT2
2009-07-17 20:14 . 2009-07-17 20:14 ——– d—–w- c:\documents and settings\allen\Application Data\CMplay
2009-07-17 19:46 . 2008-12-21 22:58 ——– d—–w- c:\program files\VstPlugIns
2009-07-17 18:55 . 2004-08-10 11:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-16 23:37 . 2009-03-30 19:49 ——– d—–w- c:\documents and settings\allen\Application Data\Skype
2009-07-13 14:08 . 2004-08-10 11:00 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 22:03 . 2009-07-10 22:03 10710528 —-a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\L6TWXY.DLL
2009-07-10 22:03 . 2009-07-10 22:03 1534464 —-a-w- c:\documents and settings\All Users\Application Data\Line 6\L6TWXY\data\twx\L6TWX.DLL
2009-07-10 22:02 . 2009-07-10 22:02 8192 —-a-r- c:\documents and settings\allen\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-07-10 22:02 . 2009-07-10 22:02 30208 —-a-r- c:\documents and settings\allen\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-07-10 22:02 . 2009-07-10 22:02 14848 —-a-r- c:\documents and settings\allen\Application Data\Microsoft\Installer\{26B46206-DF80-4DA2-AEAB-FF146320C344}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe
2009-07-10 22:02 . 2009-07-10 22:02 ——– d—–w- c:\program files\CodeMeter
2009-07-10 22:02 . 2009-07-04 16:43 ——– d—–w- c:\program files\Propellerhead
2009-07-09 20:34 . 2009-07-09 20:34 ——– d—–w- c:\documents and settings\allen\Application Data\Line 6
2009-07-09 20:34 . 2009-07-09 20:34 ——– d—–w- c:\program files\Line6
2009-07-09 20:18 . 2009-07-09 20:18 ——– d—–w- c:\program files\Pinnacle
2009-07-09 20:16 . 2009-07-09 20:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Pinnacle
2009-07-05 13:52 . 2009-05-02 16:38 ——– d—–w- c:\documents and settings\allen\Application Data\ScanSpyware
2009-07-04 16:51 . 2009-07-04 16:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Line 6
2009-07-04 16:51 . 2009-07-04 16:51 2771968 ——w- c:\windows\system32\ReWire.dll
2009-07-04 16:50 . 2008-12-23 23:52 ——– d—–w- c:\documents and settings\allen\Application Data\Propellerhead Software
2009-07-03 17:09 . 2006-03-04 03:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-28 01:11 . 2008-12-21 16:47 87747 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-25 18:36 . 2004-08-10 11:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-10 11:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-10 11:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-10 11:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-10 11:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-10 11:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-10 11:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-10 11:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-10 11:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-10 11:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-10 11:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2004-08-10 11:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-24 19:51 . 2009-06-20 22:36 335 —-a-w- c:\windows\nsreg.dat
2009-06-24 19:51 . 2009-06-24 19:51 118784 —-a-w- c:\windows\SeaMonkeyUninstall.exe
2009-06-24 19:51 . 2009-06-24 19:50 8653 —-a-w- c:\windows\mozver.dat
2009-06-24 19:51 . 2009-06-24 19:51 118784 —-a-w- c:\windows\GREUninstall.exe
2009-06-24 19:50 . 2009-06-24 19:50 ——– d—–w- c:\program files\mozilla.org
2009-06-24 19:15 . 2009-06-21 04:44 293 —-a-w- c:\windows\FTJ40MTI.DAT
2009-06-24 04:00 . 2009-05-17 14:33 ——– d—–w- c:\documents and settings\allen\Application Data\RomeCasino
2009-06-24 03:40 . 2009-05-17 14:33 ——– d—–w- c:\program files\RomeCasino
2009-06-23 00:52 . 2009-06-19 23:55 ——– d—–w- c:\program files\Hidden Expedition - Amazon
2009-06-22 11:49 . 2004-08-10 11:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-10 11:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2004-08-10 11:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2004-08-10 11:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-21 04:59 . 2009-06-21 04:58 ——– d—–w- c:\program files\MTI Client Services Inc
2009-06-21 04:58 . 2009-06-21 04:58 ——– d—–w- c:\documents and settings\allen\Application Data\MTI Client Services Inc
2009-06-20 09:48 . 2009-01-02 02:24 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-06-19 23:53 . 2009-01-02 02:24 ——– d—–w- c:\program files\bfgclient
2009-06-16 14:55 . 2004-08-10 11:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-10 11:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-14 19:43 . 2009-06-14 19:33 24 —-a-w- C:\DUKE3D.BAT
2009-06-12 11:50 . 2004-08-10 11:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 2004-08-10 11:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-24 20:00 . 2009-06-24 20:00 122880 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2002-07-31 23:55 . 2009-05-24 00:08 106 –sh–w- c:\windows\WSYS049.SYS
.

((((((((((((((((((((((((((((( SnapShot@2009-08-17_00.18.16 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-08-17 00:16 . 2009-08-17 00:16 40960 c:\windows\Temp\rtdrvmon.exe
+ 2009-08-18 02:32 . 2009-08-18 02:32 40960 c:\windows\temp\rtdrvmon.exe
+ 2009-08-18 02:32 . 2009-08-18 02:32 16384 c:\windows\temp\Perflib_Perfdata_46c.dat
- 2009-08-17 00:15 . 2009-08-17 00:15 8192 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
+ 2009-08-18 02:30 . 2009-08-18 02:30 8192 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
+ 2009-08-18 02:30 . 2009-08-18 02:30 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
- 2009-08-17 00:15 . 2009-08-17 00:15 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
+ 2009-08-18 02:30 . 2009-08-18 02:30 233472 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
- 2009-08-17 00:15 . 2009-08-17 00:15 233472 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
- 2009-08-17 00:15 . 2009-08-17 00:15 520192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-18 02:30 . 2009-08-18 02:30 520192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
- 2009-08-17 00:15 . 2009-08-17 00:15 233472 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
+ 2009-08-18 02:30 . 2009-08-18 02:30 233472 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
+ 2009-08-18 02:30 . 2009-08-18 02:30 14307328 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 21:20 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-31 68856]
"E-MU USB Audio Control Panel"="c:\program files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe" [2006-11-18 274432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-06-24 30192]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-09-13 7696384]
"Lexmark X74-X75"="c:\program files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-05-11 200069]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2009-03-12 2303216]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-10-24 125120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-11 198160]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-27 282624]

c:\documents and settings\allen\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - d:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-7-31 393216]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi3"=xgusb.cpl

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Radialpoint Security Services]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\microsoft frontpage\\bin\\fpexplor.exe"=
"c:\\FrontPage Webs\\Server\\vhttpd32.exe"=
"f:\\Program Files\\prism3d.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Ipswitch\\WS_FTP 12\\UpWiz.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/15/2009 10:14 PM 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/21/2009 10:16 PM 130936]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [4/3/2009 4:01 AM 1680704]
R2 emaudsv;E-MU Audio Service;c:\windows\system32\emaudsv.exe [11/20/2006 5:29 AM 10240]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 AM 1029456]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [8/1/2009 6:59 PM 33792]
R3 emusba10;E-MU USB-Audio 1.0 Driver;c:\windows\system32\drivers\emusba10.sys [11/20/2006 5:29 AM 142208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/12/2009 12:41 PM 101936]
S0 bhpftp;bhpftp;c:\windows\system32\drivers\hkztnm.sys –> c:\windows\system32\drivers\hkztnm.sys [?]
S2 gupdate1ca0a71a4770151;Google Update Service (gupdate1ca0a71a4770151);c:\program files\Google\Update\GoogleUpdate.exe [7/21/2009 10:10 PM 133104]
S3 EraserUtilDrv10910;EraserUtilDrv10910;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [?]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [6/24/2009 4:00 PM 30192]
S3 Radialpoint Security Services;Verizon PC Security Checkup Service;c:\program files\Verizon\PC Security Checkup\RpsSecurityAwareR.exe [8/14/2009 2:35 PM 170736]
S3 Rpcsvrvca_pr;Rpcsvrvca_pr;c:\windows\system32\drivers\amdk6.sys [8/3/2004 6:59 PM 36992]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/24/2006 7:32 PM 116416]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/21/2009 10:16 PM 348752]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-08-18 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-08-16 14:30]

2009-08-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-23 20:00]

2009-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-22 02:10]

2009-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-22 02:10]

2009-08-18 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-08-18 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-08-16 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]
.
.
——- Supplementary Scan ——-
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,77,65,62,5c,72,65,6c-,61,74,65,64,2e,68,74,6d,00
FF - ProfilePath - c:\documents and settings\allen\Application Data\Mozilla\Firefox\Profiles\s9swjhl4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - plugin: c:\program files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Verizon\VSP\nprpspa.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-

FF - user.js: browser.download.manager.showAlertOnComplete - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-17 22:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3212)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark X74-X75\lxbbbmon.exe
d:\program files\OpenOffice.org 2.4\program\soffice.exe
d:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2009-08-18 22:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-18 02:44
ComboFix2.txt 2009-08-17 00:29

Pre-Run: 5,955,416,064 bytes free
Post-Run: 6,022,795,264 bytes free

Current=3 Default=3 Failed=0 LastKnownGood=4 Sets=1,2,3,4
426 — E O F — 2009-08-15 03:15


I have not gotten the anti virus warning yet so it seems to be working fine. But since you had me redo combo fix you must have seen something.
Thanks for all your help.
rocker44
Hi,

Please do the following:

Open your MalwareBytes AntiMalware program
  • Click on the Update tab, If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.





NEXT

It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course:

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:

1. Click Accept, when prompted to download and install the program files and database of malware definitions.


2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan

3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI