This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] uacinit.dll Will Not Go Away

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello and :welcome:

My name is Perplexus and I will be helping you fix your computer problem.

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate, so stay with me until given the 'all clear' even if symptoms diminish. Lack of symptoms does not always mean the job is complete.

Before we proceed to clean your computer from malware there are some points you should consider that will make the process go smoother:
  • To make sure that you receive an email when this topic is updated, please click here and check that this topic is listed under Malware Removal and Spyware Removal.
  • Before beginning the fix, read this post completely. If there's anything that you do not understand, please ask your questions before proceeding as you may temporarily be disconnected from the internet. No question is considered dumb here. It's better to be safe than sorry!
  • Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.
  • It is IMPORTANT that you do not miss a step & perform everything in the correct order/sequence.
  • Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested, as it can be very dangerous and cause harm to your system.
  • When posting logs, please ensure Wordwrap is turned off in Notepad (to check, open Notepad in the menubar click on Format and make sure that Word Wrap is unchecked)
———————————————————————————————

Download Combofix from any of the links below and save it to your desktop. You must rename it to Combo-Fix.exe before saving it.

Link 1
Link 2

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using FireFox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to Always ask me where to Save the files
  • During the download, rename it to Combo-Fix.exe as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important to rename it during the download and not after.
  • Please do not rename it to something other than what was indicated.
  • Make sure to do the following:
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause unpredictable results
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • Warning: ComboFix will disconnect your machine from the internet as soon as it starts.
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  • Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt log so we can continue cleaning the system.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Downloaded the ComboFix. Renamed to properly, however receiving an error that says: This application has failed to start because C:\WINDOWS\system32\wxvault.dll was not found. Re-Installing the application may fix this problem.
Ok, let's try this.

——————
Step 1:
——————

Download RootRepeal from one of the following locations: Unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
    • Shadow SSDT
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

——————
Step 2:
——————

  • Download OTL by OldTimer to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

——————
Step 3:
——————

Please post back with the following:
  • How your machine is running
  • RootRepeal.txt
  • OTL.txt
  • Extras.txt
yes it is. Since the last post, I made a copy of the file wxvault.dll.vir and named it wxvault.dll combofix is running on the infected machine as I am typing.
ComboFix 09-08-27.A3 - matt-f 08/28/2009 16:08.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1441 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
The following files were disabled during the run:
c:\windows\system32\wxvault.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\emMON.exe
c:\windows\Fonts\C39324L4.TTF
c:\windows\Fonts\C39336L4.TTF
c:\windows\Fonts\C39354L4.TTF
c:\windows\Fonts\C39372L4.TTF
c:\windows\Fonts\C39390L4.TTF
c:\windows\Fonts\C39424L4.TTF
c:\windows\Fonts\C39436L4.TTF
c:\windows\Fonts\C39472L4.TTF
c:\windows\Fonts\C39490L4.TTF
c:\windows\Fonts\C39H12L4.TTF
c:\windows\Fonts\C39H24L4.TTF
c:\windows\Fonts\C39H36L4.TTF
c:\windows\Fonts\C39H54L4.TTF
c:\windows\Fonts\C39H72L4.TTF
c:\windows\Fonts\C39L36L4.TTF
c:\windows\Fonts\C39L54L4.TTF
c:\windows\Fonts\C39L72L4.TTF
c:\windows\Fonts\C39L90L4.TTF
c:\windows\Fonts\C39M24L4.TTF
c:\windows\Fonts\C39M36L4.TTF
c:\windows\Fonts\C39M54L4.TTF
c:\windows\Fonts\C39M72L4.TTF
c:\windows\Fonts\C39M90L4.TTF
c:\windows\Fonts\FRE3OF9X.TTF
c:\windows\Fonts\FREE3OF9.TTF
c:\windows\Installer\559ab9e.msi
c:\windows\Installer\a3f99be.msi
c:\windows\patchw32.dll
c:\windows\pw32a.dll
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\UAChxdaopbpfm.sys
c:\windows\system32\nisuyiko.dll
c:\windows\system32\otapaluj.ini
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjeclwdikkl.dll
c:\windows\system32\UACmpfqqjlqgi.dll
c:\windows\system32\UACvithltowuy.dat
c:\windows\system32\UACyapmykspkf.dll
c:\windows\system32\wxvault.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-28 )))))))))))))))))))))))))))))))
.

2009-08-27 17:20 . 2009-08-27 17:20 13191944 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-25 20:40 . 2009-08-22 05:34 1323568 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\NAVEX15.SYS
2009-08-25 20:40 . 2009-08-22 05:34 84912 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\NAVENG.SYS
2009-08-25 20:40 . 2009-08-22 05:33 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\NAVEX32A.DLL
2009-08-25 20:40 . 2009-08-22 05:33 177520 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\NAVENG32.DLL
2009-08-25 20:40 . 2009-08-25 08:00 259440 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\ECMSVR32.DLL
2009-08-25 20:40 . 2009-02-18 19:41 2414128 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\CCERASER.DLL
2009-08-25 20:40 . 2009-02-06 19:26 101936 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\ERASER.SYS
2009-08-25 20:40 . 2009-02-06 19:26 371248 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\EECTRL.SYS
2009-08-25 19:41 . 2009-08-25 19:41 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\Sanford,_L.P
2009-08-25 17:20 . 2009-08-25 17:21 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\DYMO
2009-08-25 17:19 . 2009-08-25 17:19 ——– d—–w- c:\program files\DYMO
2009-08-25 17:19 . 2009-08-25 17:19 ——– d—–w- c:\documents and settings\All Users\Application Data\DYMO
2009-08-17 17:38 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-17 17:38 . 2009-08-17 18:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-17 17:38 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-17 17:04 . 2009-08-17 17:04 ——– d—–w- c:\documents and settings\test\Local Settings\Application Data\Symantec
2009-08-17 17:01 . 2009-08-17 17:01 ——– d-sh–w- c:\documents and settings\test\IETldCache
2009-08-17 11:50 . 2009-08-17 11:50 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-12 12:54 . 2009-08-12 12:54 ——– d—–w- c:\program files\AutoIt3
2009-08-12 04:31 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 18:55 . 2009-08-10 19:06 256 —-a-w- c:\windows\pool.bin
2009-08-05 09:01 . 2009-08-05 09:01 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 01:50 . 2009-08-04 01:50 34 —-a-w- c:\windows\system32\BD2170W.DAT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-28 20:17 . 2009-05-18 13:28 ——– d—–w- c:\program files\Symantec AntiVirus
2009-08-28 15:22 . 2008-04-18 16:38 ——– d—–w- c:\program files\Rainlendar2
2009-08-28 15:22 . 2007-08-10 16:47 ——– d—–w- c:\program files\Sling Media
2009-08-28 12:54 . 2008-11-21 17:24 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\SolidWorks
2009-08-28 12:31 . 2008-01-25 23:09 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-08-27 14:34 . 2009-05-18 18:46 32 —-a-w- c:\windows\system32\drivers\mshdmd.sys.
2009-08-27 14:34 . 2009-05-18 18:46 1326080 —-a-w- c:\windows\system32\drivers\XLHASP.sys
2009-08-25 17:20 . 2009-08-25 17:19 8759 –sh–r- c:\program files\uninstall.log
2009-08-21 12:51 . 2008-11-21 17:25 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\gtk-2.0
2009-08-17 13:50 . 2008-11-21 17:24 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\TextPad
2009-08-16 01:55 . 2007-03-15 21:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-15 13:02 . 2008-07-25 19:46 256 —-a-w- c:\windows\system32\pool.bin
2009-08-11 13:49 . 2008-11-21 17:43 124200 —-a-w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2004-08-11 23:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 11:24 . 2008-02-23 19:54 ——– d—–w- c:\program files\Brother
2009-07-28 14:32 . 2008-02-23 20:03 ——– d—–w- c:\program files\Brownie
2009-07-28 14:20 . 2009-07-27 20:06 ——– d—–w- c:\program files\Common Files\SupportSoft
2009-07-28 14:20 . 2009-07-28 11:10 ——– d—–w- c:\documents and settings\All Users\Application Data\SupportSoft
2009-07-28 14:15 . 2009-03-04 19:22 ——– d—–w- c:\program files\mozilla.org
2009-07-27 20:52 . 2009-07-27 20:06 ——– d—–w- c:\program files\support.com
2009-07-23 14:09 . 2008-11-21 17:24 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\Wave Systems Corp
2009-07-17 19:01 . 2004-08-11 23:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-17 16:02 . 2007-03-15 21:56 ——– d—–w- c:\program files\MSBuild
2009-07-17 16:02 . 2009-07-17 16:02 ——– d—–w- c:\program files\Reference Assemblies
2009-07-17 15:45 . 2007-03-15 21:56 ——– d—–w- c:\program files\Microsoft Works
2009-07-17 14:06 . 2008-11-21 17:24 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\OpenOffice.org2
2009-07-16 21:33 . 2007-03-09 04:48 ——– d—–w- c:\program files\Google
2009-07-14 17:29 . 2009-07-14 17:29 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\GetRightToGo
2009-07-14 03:43 . 2004-08-11 23:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 21:04 . 2007-03-09 04:50 123032 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-08 17:06 . 2009-07-08 17:06 ——– d–h–w- c:\documents and settings\All Users\Application Data\{93CD8CC6-0881-4D18-A826-DAA73A031A46}
2009-07-08 17:05 . 2009-07-08 17:05 ——– d—–w- c:\program files\Fargo
2009-07-03 17:09 . 2004-08-11 23:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-07-01 19:28 . 2007-03-16 21:57 ——– d—–w- c:\program files\Microsoft SQL Server
2009-06-30 02:04 . 2007-03-16 21:23 ——– d—–w- c:\program files\SolidWorks
2009-06-25 08:25 . 2004-08-11 23:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-11 23:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-11 23:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-11 23:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-11 23:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-11 23:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-11 23:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-19 16:35 . 2009-05-18 18:47 9532 —-a-w- c:\windows\system32\drivers\57ADA456.bin
2009-06-19 15:22 . 2009-06-19 15:22 6656 —-a-w- c:\windows\system32\haspvdd.dll
2009-06-19 15:22 . 2009-06-19 15:22 47616 —-a-w- c:\windows\system32\drivers\Haspnt.sys
2009-06-19 15:22 . 2009-06-19 15:22 383 —-a-w- c:\windows\system32\haspdos.sys
2009-06-19 15:22 . 2009-06-19 15:22 304640 —-a-w- c:\windows\system32\hlvdd.dll
2009-06-18 12:35 . 2007-03-09 04:26 128795 —-a-w- c:\windows\system32\nvModes.dat
2009-06-16 14:36 . 2004-08-11 23:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-11 23:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 20:34 . 2008-11-21 17:25 1 —-a-w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-06-12 12:31 . 2004-08-11 23:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-11 23:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-11 23:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2004-08-11 23:11 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-11 23:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-03 19:09 . 2004-08-11 23:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-02 19:08 . 2009-06-02 19:08 75040 —-a-w- c:\documents and settings\All Users\Application Data\Pervasive Software\PSQL\rcp\configuration\org.eclipse.osgi\bundles\9\1\.cp\pvjdbc2.dll
2009-07-16 21:33 . 2009-07-16 21:33 122880 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-12 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-19 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2009-05-18 100056]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2005-04-17 85184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-19 7401472]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-07-16 30192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"DLSService"="c:\program files\DYMO\DYMO Label Software\DLSService.exe" [2009-06-24 55808]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]
"Seagull Drivers"="ssdal_nc.exe" - c:\windows\ssdal_nc.exe [2008-11-19 69632]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^matt-f.BTECSOLUTIONS.000^Start Menu^Programs^Startup^FileOpenAPI.exe.lnk]
path=c:\documents and settings\matt-f.BTECSOLUTIONS.000\Start Menu\Programs\Startup\FileOpenAPI.exe.lnk
backup=c:\windows\pss\FileOpenAPI.exe.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^matt-f.BTECSOLUTIONS.000^Start Menu^Programs^Startup^jConnect 4.4.lnk]
path=c:\documents and settings\matt-f.BTECSOLUTIONS.000\Start Menu\Programs\Startup\jConnect 4.4.lnk
backup=c:\windows\pss\jConnect 4.4.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^matt-f.BTECSOLUTIONS.000^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\matt-f.BTECSOLUTIONS.000\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\BitTorrent\\btdownloadgui.exe"=
"c:\\Program Files\\EFTP\\EFTP3Server.exe"=
"c:\\Program Files\\EFTP\\EFTP3Client.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Cisco Systems\\ASDM\\asdm-launcher.exe"=
"c:\\Program Files\\AT&T\\Communication Manager\\SwiApiMux.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)
"AllowInboundMaskRequest"= 0 (0x0)

R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [10/24/2008 3:30 PM 86552]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [4/17/2005 12:30 PM 124608]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/11/2004 7:00 PM 5120]
R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [8/25/2009 4:40 PM 101936]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [12/20/2007 6:13 PM 1558000]
S2 aqjclsy;aqjclsy;c:\windows\system32\drivers\balday.sys –> c:\windows\system32\drivers\balday.sys [?]
S2 gurio;gurio;c:\windows\system32\drivers\uedvyri.sys –> c:\windows\system32\drivers\uedvyri.sys [?]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [9/18/2007 6:56 AM 109080]
S3 GoogleDesktopManager-060409-093314;Google Desktop Manager 5.9.906.4286;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [7/16/2009 5:33 PM 30192]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/17/2009 1:38 PM 38160]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [10/24/2008 3:29 PM 24876]
S3 SWNC8U56;Sierra Wireless MUX NDIS Driver (UMTS56);c:\windows\system32\drivers\swnc8u56.sys [6/27/2007 10:41 AM 101248]
S3 SWUMX56;Sierra Wireless USB MUX Driver (UMTS56);c:\windows\system32\drivers\swumx56.sys [6/27/2007 10:42 AM 73856]
S3 XLHASP;XLHASP;c:\windows\system32\drivers\XLHASP.sys [5/18/2009 2:46 PM 1326080]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:42]

2009-08-28 c:\windows\Tasks\User_Feed_Synchronization-{91145BBF-DD3A-44D8-B24E-C488F6A059FF}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]

2009-08-28 c:\windows\Tasks\Vantage_Important.job
- c:\windows\system32\ntbackup.exe [2004-08-11 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.npr.org/
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: bmnet.dll
TCP: {2763CA86-AB1C-463E-BB7B-A7D635010CD3} = 192.168.1.2,192.168.1.13
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {DAF7E6E7-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
FF - ProfilePath - c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\Mozilla\Firefox\Profiles\hwytzh3q.default\
FF - prefs.js: browser.startup.homepage - npr.org
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-28 16:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Pervasive Software\PSQL]
@Denied: ) (Everyone)
@=""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(284)
c:\windows\system32\bmnet.dll

- - - - - - - > 'lsass.exe'(356)
c:\windows\system32\bmnet.dll
c:\program files\Bonjour\mdnsNSP.dll

- - - - - - - > 'explorer.exe'(2772)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\bmnet.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\BRSS01A.EXE
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\bmwebcfg.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Wave Systems Corp\Common\DataServer.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\msdtc.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2009-08-28 16:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-28 20:20

Pre-Run: 262,825,119,744 bytes free
Post-Run: 267,852,156,928 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
325 — E O F — 2009-08-27 17:20
Great job! :thumbup: Let's continue on…

——————
Step 1:
——————

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

File::
c:\windows\system32\drivers\balday.sys
c:\windows\system32\drivers\uedvyri.sys

Driver::
aqjclsy
gurio

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

——————
Step 2:
——————

  • Download OTL by OldTimer to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

——————
Step 3:
——————

Please post back with the following:
  • How your machine is running
  • ComboFix.txt
  • OTL.txt
Ok finally ran combo with script and OTL.
See Combo log:

ComboFix 09-08-28.01 - matt-f 08/28/2009 17:39.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1428 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\matt-f.BTECSOLUTIONS.000\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

FILE ::
"c:\windows\system32\drivers\balday.sys"
"c:\windows\system32\drivers\uedvyri.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_AQJCLSY
——-\Legacy_GURIO
——-\Service_aqjclsy
——-\Service_gurio


((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-28 )))))))))))))))))))))))))))))))
.

2009-08-27 17:20 . 2009-08-27 17:20 13191944 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-25 20:40 . 2009-08-22 05:34 1323568 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\NAVEX15.SYS
2009-08-25 20:40 . 2009-08-22 05:34 84912 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\NAVENG.SYS
2009-08-25 20:40 . 2009-08-22 05:33 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\NAVEX32A.DLL
2009-08-25 20:40 . 2009-08-22 05:33 177520 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\NAVENG32.DLL
2009-08-25 20:40 . 2009-08-25 08:00 259440 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\ECMSVR32.DLL
2009-08-25 20:40 . 2009-02-18 19:41 2414128 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\CCERASER.DLL
2009-08-25 20:40 . 2009-02-06 19:26 101936 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\ERASER.SYS
2009-08-25 20:40 . 2009-02-06 19:26 371248 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2e3204.vdb\EECTRL.SYS
2009-08-25 19:41 . 2009-08-25 19:41 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\Sanford,_L.P
2009-08-25 17:20 . 2009-08-25 17:21 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\DYMO
2009-08-25 17:19 . 2009-08-25 17:19 ——– d—–w- c:\program files\DYMO
2009-08-25 17:19 . 2009-08-25 17:19 ——– d—–w- c:\documents and settings\All Users\Application Data\DYMO
2009-08-17 17:38 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-17 17:38 . 2009-08-17 18:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-17 17:38 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-17 17:04 . 2009-08-17 17:04 ——– d—–w- c:\documents and settings\test\Local Settings\Application Data\Symantec
2009-08-17 17:01 . 2009-08-17 17:01 ——– d-sh–w- c:\documents and settings\test\IETldCache
2009-08-17 11:50 . 2009-08-17 11:50 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-12 12:54 . 2009-08-12 12:54 ——– d—–w- c:\program files\AutoIt3
2009-08-12 04:31 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 18:55 . 2009-08-10 19:06 256 —-a-w- c:\windows\pool.bin
2009-08-05 09:01 . 2009-08-05 09:01 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 01:50 . 2009-08-04 01:50 34 —-a-w- c:\windows\system32\BD2170W.DAT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-28 21:47 . 2009-05-18 13:28 ——– d—–w- c:\program files\Symantec AntiVirus
2009-08-28 21:27 . 2008-01-25 23:09 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-08-28 15:22 . 2008-04-18 16:38 ——– d—–w- c:\program files\Rainlendar2
2009-08-28 15:22 . 2007-08-10 16:47 ——– d—–w- c:\program files\Sling Media
2009-08-28 13:30 . 2008-11-21 17:24 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\Wave Systems Corp
2009-08-28 12:54 . 2008-11-21 17:24 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\SolidWorks
2009-08-27 14:34 . 2009-05-18 18:46 32 —-a-w- c:\windows\system32\drivers\mshdmd.sys.
2009-08-27 14:34 . 2009-05-18 18:46 1326080 —-a-w- c:\windows\system32\drivers\XLHASP.sys
2009-08-25 17:20 . 2009-08-25 17:19 8759 –sh–r- c:\program files\uninstall.log
2009-08-21 12:51 . 2008-11-21 17:25 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\gtk-2.0
2009-08-17 13:50 . 2008-11-21 17:24 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\TextPad
2009-08-16 01:55 . 2007-03-15 21:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-15 13:02 . 2008-07-25 19:46 256 —-a-w- c:\windows\system32\pool.bin
2009-08-11 13:49 . 2008-11-21 17:43 124200 —-a-w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2004-08-11 23:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 11:24 . 2008-02-23 19:54 ——– d—–w- c:\program files\Brother
2009-07-28 14:32 . 2008-02-23 20:03 ——– d—–w- c:\program files\Brownie
2009-07-28 14:20 . 2009-07-27 20:06 ——– d—–w- c:\program files\Common Files\SupportSoft
2009-07-28 14:20 . 2009-07-28 11:10 ——– d—–w- c:\documents and settings\All Users\Application Data\SupportSoft
2009-07-28 14:15 . 2009-03-04 19:22 ——– d—–w- c:\program files\mozilla.org
2009-07-27 20:52 . 2009-07-27 20:06 ——– d—–w- c:\program files\support.com
2009-07-17 19:01 . 2004-08-11 23:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-17 16:02 . 2007-03-15 21:56 ——– d—–w- c:\program files\MSBuild
2009-07-17 16:02 . 2009-07-17 16:02 ——– d—–w- c:\program files\Reference Assemblies
2009-07-17 15:45 . 2007-03-15 21:56 ——– d—–w- c:\program files\Microsoft Works
2009-07-17 14:06 . 2008-11-21 17:24 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\OpenOffice.org2
2009-07-16 21:33 . 2007-03-09 04:48 ——– d—–w- c:\program files\Google
2009-07-14 17:29 . 2009-07-14 17:29 ——– d—–w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\GetRightToGo
2009-07-14 03:43 . 2004-08-11 23:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 21:04 . 2007-03-09 04:50 123032 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-08 17:06 . 2009-07-08 17:06 ——– d–h–w- c:\documents and settings\All Users\Application Data\{93CD8CC6-0881-4D18-A826-DAA73A031A46}
2009-07-08 17:05 . 2009-07-08 17:05 ——– d—–w- c:\program files\Fargo
2009-07-03 17:09 . 2004-08-11 23:00 915456 ——w- c:\windows\system32\wininet.dll
2009-07-01 19:28 . 2007-03-16 21:57 ——– d—–w- c:\program files\Microsoft SQL Server
2009-06-30 02:04 . 2007-03-16 21:23 ——– d—–w- c:\program files\SolidWorks
2009-06-25 08:25 . 2004-08-11 23:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-11 23:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-11 23:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-11 23:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-11 23:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-11 23:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-11 23:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-19 16:35 . 2009-05-18 18:47 9532 —-a-w- c:\windows\system32\drivers\57ADA456.bin
2009-06-19 15:22 . 2009-06-19 15:22 6656 —-a-w- c:\windows\system32\haspvdd.dll
2009-06-19 15:22 . 2009-06-19 15:22 47616 —-a-w- c:\windows\system32\drivers\Haspnt.sys
2009-06-19 15:22 . 2009-06-19 15:22 383 —-a-w- c:\windows\system32\haspdos.sys
2009-06-19 15:22 . 2009-06-19 15:22 304640 —-a-w- c:\windows\system32\hlvdd.dll
2009-06-18 12:35 . 2007-03-09 04:26 128795 —-a-w- c:\windows\system32\nvModes.dat
2009-06-16 14:36 . 2004-08-11 23:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-11 23:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 20:34 . 2008-11-21 17:25 1 —-a-w- c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-06-12 12:31 . 2004-08-11 23:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-11 23:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-11 23:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2004-08-11 23:11 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-11 23:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-03 19:09 . 2004-08-11 23:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-02 19:08 . 2009-06-02 19:08 75040 —-a-w- c:\documents and settings\All Users\Application Data\Pervasive Software\PSQL\rcp\configuration\org.eclipse.osgi\bundles\9\1\.cp\pvjdbc2.dll
2009-07-16 21:33 . 2009-07-16 21:33 122880 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-28_20.16.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-28 21:46 . 2009-08-28 21:46 16384 c:\windows\Temp\Perflib_Perfdata_cb4.dat
+ 2009-08-28 21:44 . 2009-08-28 21:44 16384 c:\windows\Temp\Perflib_Perfdata_6ec.dat
+ 2009-08-28 21:39 . 2009-08-28 21:39 16384 c:\windows\Temp\Perflib_Perfdata_33c.dat
+ 2009-08-28 21:44 . 2009-08-28 21:44 16384 c:\windows\Temp\Perflib_Perfdata_19c.dat
+ 2006-09-08 14:32 . 2006-09-08 14:32 286720 c:\windows\system32\wxvault.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-12 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-19 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2009-05-18 100056]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2005-04-17 85184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-19 7401472]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-07-16 30192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"DLSService"="c:\program files\DYMO\DYMO Label Software\DLSService.exe" [2009-06-24 55808]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]
"Seagull Drivers"="ssdal_nc.exe" - c:\windows\ssdal_nc.exe [2008-11-19 69632]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^matt-f.BTECSOLUTIONS.000^Start Menu^Programs^Startup^FileOpenAPI.exe.lnk]
path=c:\documents and settings\matt-f.BTECSOLUTIONS.000\Start Menu\Programs\Startup\FileOpenAPI.exe.lnk
backup=c:\windows\pss\FileOpenAPI.exe.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^matt-f.BTECSOLUTIONS.000^Start Menu^Programs^Startup^jConnect 4.4.lnk]
path=c:\documents and settings\matt-f.BTECSOLUTIONS.000\Start Menu\Programs\Startup\jConnect 4.4.lnk
backup=c:\windows\pss\jConnect 4.4.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^matt-f.BTECSOLUTIONS.000^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\matt-f.BTECSOLUTIONS.000\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\BitTorrent\\btdownloadgui.exe"=
"c:\\Program Files\\EFTP\\EFTP3Server.exe"=
"c:\\Program Files\\EFTP\\EFTP3Client.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Cisco Systems\\ASDM\\asdm-launcher.exe"=
"c:\\Program Files\\AT&T\\Communication Manager\\SwiApiMux.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)
"AllowInboundMaskRequest"= 0 (0x0)

R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [10/24/2008 3:30 PM 86552]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [4/17/2005 12:30 PM 124608]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/11/2004 7:00 PM 5120]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [12/20/2007 6:13 PM 1558000]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [9/18/2007 6:56 AM 109080]
S3 GoogleDesktopManager-060409-093314;Google Desktop Manager 5.9.906.4286;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [7/16/2009 5:33 PM 30192]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/17/2009 1:38 PM 38160]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [10/24/2008 3:29 PM 24876]
S3 SWNC8U56;Sierra Wireless MUX NDIS Driver (UMTS56);c:\windows\system32\drivers\swnc8u56.sys [6/27/2007 10:41 AM 101248]
S3 SWUMX56;Sierra Wireless USB MUX Driver (UMTS56);c:\windows\system32\drivers\swumx56.sys [6/27/2007 10:42 AM 73856]
S3 XLHASP;XLHASP;c:\windows\system32\drivers\XLHASP.sys [5/18/2009 2:46 PM 1326080]

— Other Services/Drivers In Memory —

*Deregistered* - EraserUtilDrv10910

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:42]

2009-08-28 c:\windows\Tasks\User_Feed_Synchronization-{91145BBF-DD3A-44D8-B24E-C488F6A059FF}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]

2009-08-28 c:\windows\Tasks\Vantage_Important.job
- c:\windows\system32\ntbackup.exe [2004-08-11 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.npr.org/
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: bmnet.dll
TCP: {2763CA86-AB1C-463E-BB7B-A7D635010CD3} = 192.168.1.2,192.168.1.13
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {DAF7E6E7-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
FF - ProfilePath - c:\documents and settings\matt-f.BTECSOLUTIONS.000\Application Data\Mozilla\Firefox\Profiles\hwytzh3q.default\
FF - prefs.js: browser.startup.homepage - npr.org
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-28 17:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\docume~1\MATT-F~1.000\LOCALS~1\Temp\00005049.exe 1003624 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Pervasive Software\PSQL]
@Denied: ) (Everyone)
@=""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1500)
c:\windows\system32\CLBCATQ.DLL

- - - - - - - > 'lsass.exe'(1556)
c:\windows\system32\bmnet.dll

- - - - - - - > 'explorer.exe'(5852)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\bmnet.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\BRSS01A.EXE
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\bmwebcfg.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Wave Systems Corp\Common\DataServer.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\msdtc.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Symantec AntiVirus\DoScan.exe
.
**************************************************************************
.
Completion time: 2009-08-28 17:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-28 21:52
ComboFix2.txt 2009-08-28 20:20

Pre-Run: 267,838,566,400 bytes free
Post-Run: 267,796,598,784 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
291 — E O F — 2009-08-27 17:20



Below is the OTL Log



OTL logfile created on: 8/28/2009 5:55:40 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 63.72% Memory free
3.85 Gb Paging File | 3.33 Gb Available in Paging File | 86.68% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.04 Gb Total Space | 249.44 Gb Free Space | 83.69% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MFISHER-LAPTOP
Current User Name: matt-f
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\System32\brss01a.exe (brother Industries Ltd)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\bmwebcfg.exe (Bytemobile, Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Wave Systems Corp\Common\DataServer.exe (Wave Systems Corp.)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe (Dell Inc.)
PRC - C:\Program Files\Norton Ghost\Agent\VProSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe ()
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe (Symantec)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\DYMO\DYMO Label Software\DLSService.exe (Sanford, L.P.)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Symantec AntiVirus\DoScan.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (ATTRcAppSvc [On_Demand | Stopped]) – C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe (PCTEL)
SRV - (bmwebcfg [Auto | Running]) – C:\WINDOWS\System32\bmwebcfg.exe (Bytemobile, Inc.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (Brother XP spl Service [Auto | Stopped]) – C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CVPND [Auto | Running]) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (DataSvr2 [Auto | Running]) – C:\Program Files\Wave Systems Corp\Common\DataServer.exe (Wave Systems Corp.)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-060409-093314 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Irmon [Auto | Running]) – C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe (Dell Inc.)
SRV - (Norton Ghost [Auto | Running]) – C:\Program Files\Norton Ghost\Agent\VProSvc.exe (Symantec Corporation)
SRV - (NVSvc [On_Demand | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RampartSvc [On_Demand | Stopped]) – C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe (SonicWALL, Inc.)
SRV - (RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (Roxio UPnP Renderer 9 [On_Demand | Stopped]) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe (Sonic Solutions)
SRV - (Roxio Upnp Server 9 [Auto | Stopped]) – C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe (Sonic Solutions)
SRV - (RoxLiveShare9 [Auto | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (Sonic Solutions)
SRV - (RoxMediaDB9 [On_Demand | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch9 [Auto | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (SavRoam [Auto | Running]) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (stllssvr [On_Demand | Stopped]) – File not found
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SymSnapService [On_Demand | Running]) – C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe (Symantec)
SRV - (tcsd_win32.exe [Auto | Running]) – C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe ()
SRV - (WLANKEEPER [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe (Intel® Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AegisP [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (BrPar [Auto | Stopped]) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (catchme [On_Demand | Running]) – File not found
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (CVirtA [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (CVPNDRVA [Auto | Running]) – C:\WINDOWS\System32\Drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DNE [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (Hardlock [Auto | Running]) – C:\WINDOWS\System32\drivers\hardlock.sys (Aladdin Knowledge Systems)
DRV - (Haspnt [Auto | Running]) – C:\WINDOWS\System32\drivers\Haspnt.sys (Aladdin Knowledge Systems)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (MBAMSwissArmy [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MPE [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090825.004\naveng.sys (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090825.004\navex15.sys (Symantec Corporation)
DRV - (NETw3x32 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\NETw3x32.sys (Intel® Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (PBADRV [Boot | Running]) – C:\WINDOWS\system32\drivers\pbadrv.sys (Dell Inc)
DRV - (PCASp50 [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\PCASp50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (PCTINDIS5 [On_Demand | Stopped]) – C:\WINDOWS\System32\PCTINDIS5.SYS (PCTEL Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RCFOX [System | Running]) – C:\WINDOWS\System32\Drivers\RCFOX.sys (SonicWALL, Inc.)
DRV - (rcvpn [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\rcvpn.sys (SonicWALL, Inc.)
DRV - (RimUsb [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RimUsb.sys (Research In Motion Limited)
DRV - (RimVSerPort [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\s24trans.sys (Intel Corporation)
DRV - (SAVRT [System | Running]) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SMCIRDA [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\smcirda.sys (SMC)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\System32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (swmsflt [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (SWNC8U56 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\swnc8u56.sys (Sierra Wireless Inc.)
DRV - (SWUMX56 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\swumx56.sys (Sierra Wireless Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (symsnap [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symsnap.sys (StorageCraft)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (tcpipBM [System | Running]) – C:\WINDOWS\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (USB28xxBGA [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\emOEM.sys (eMPIA Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (USBCCID [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\usbccid.sys (Microsoft Corporation)
DRV - (v2imount [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\v2imount.sys (Symantec Corporation)
DRV - (VProEventMonitor [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\vproeventmonitor.sys (Symantec Corporation)
DRV - (WimFltr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wimfltr.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XLHASP [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\XLHASP.sys ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070308
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070308

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.npr.org/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = actsvr.comcastonline.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = actsvr.comcastonline.com:8100

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "npr.org"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:6.0.04
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - prefs.js..network.proxy.backup.ftp: "192.168.1.6"
FF - prefs.js..network.proxy.backup.ftp_port: 1082
FF - prefs.js..network.proxy.backup.gopher: "192.168.1.6"
FF - prefs.js..network.proxy.backup.gopher_port: 1082
FF - prefs.js..network.proxy.backup.socks: "192.168.1.6"
FF - prefs.js..network.proxy.backup.socks_port: 1082
FF - prefs.js..network.proxy.backup.ssl: "192.168.1.6"
FF - prefs.js..network.proxy.backup.ssl_port: 1082
FF - prefs.js..network.proxy.ftp: "192.168.1.6"
FF - prefs.js..network.proxy.ftp_port: 1082
FF - prefs.js..network.proxy.gopher: "192.168.1.6"
FF - prefs.js..network.proxy.gopher_port: 1082
FF - prefs.js..network.proxy.http: "192.168.1.6"
FF - prefs.js..network.proxy.http_port: 1082
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "192.168.1.6"
FF - prefs.js..network.proxy.socks_port: 1082
FF - prefs.js..network.proxy.ssl: "192.168.1.6"
FF - prefs.js..network.proxy.ssl_port: 1082

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/01/26 16:51:21 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/17 12:03:52 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/07 15:08:48 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/28 10:11:24 | 00,000,000 | —D | M]

[2008/09/05 12:34:29 | 00,000,000 | —D | M] – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Application Data\mozilla\Extensions
[2008/09/05 12:34:29 | 00,000,000 | —D | M] – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/28 10:12:04 | 00,000,000 | —D | M] – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Application Data\mozilla\Firefox\Profiles\hwytzh3q.default\extensions
[2008/03/16 13:08:51 | 00,000,000 | —D | M] – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Application Data\mozilla\Firefox\Profiles\hwytzh3q.default\extensions\{3DD07E5D-2ADF-42ea-972E-2998FA5CE45A}
[2007/06/27 16:22:28 | 00,001,057 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Application Data\Mozilla\FireFox\Profiles\hwytzh3q.default\searchplugins\verizonsearch.xml
[2009/08/28 10:12:04 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/07 15:08:48 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/06/03 18:51:09 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2007/07/24 07:56:24 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2008/06/09 17:02:50 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
[2009/01/26 11:12:21 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/01/26 16:51:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/08/07 15:08:43 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/07 15:08:43 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/16 17:33:08 | 00,122,880 | —- | M] (Google) – C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll
[2009/01/26 16:51:19 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2007/11/20 15:37:22 | 01,334,576 | —- | M] (DivX,Inc.) – C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2007/10/19 20:54:50 | 00,098,304 | —- | M] (DivX, Inc) – C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2009/08/07 15:08:45 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/10/14 22:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/08/28 10:11:24 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/08/28 10:11:24 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/08/28 10:11:24 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/08/28 10:11:24 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/08/28 10:11:24 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/08/28 10:11:24 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/08/28 10:11:24 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/06/05 21:06:39 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/06/05 21:06:39 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/05 21:06:39 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/05 21:06:39 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/06/05 21:06:39 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/05 21:06:39 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/06/05 21:06:39 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DLSService] C:\Program Files\DYMO\DYMO Label Software\DLSService.exe (Sanford, L.P.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [Seagull Drivers] C:\WINDOWS\ssdal_nc.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [Symantec NetDriver Monitor] C:\Program Files\SymNetDrv\SNDMon.exe (Symantec Corporation)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DAF7E6E7-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab (AxLoaderPassword Class)
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} https://unmcnotes02.unmc.edu/dwa7W.cab (Domino Web Access 7 Control)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.btecsolutions.com
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\System32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 19:15:00 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[73 C:\WINDOWS\*.tmp files]
File not found – C:\WINDOWS\System32\drivers\mshdmd.sys.
[2009/08/28 16:19:33 | 01,614,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/08/28 16:19:33 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/08/28 16:19:33 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/08/28 16:19:33 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/08/28 16:19:33 | 00,574,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntfs.sys
[2009/08/28 16:19:33 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/08/28 16:19:33 | 00,409,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\qmgr.dll
[2009/08/28 16:19:33 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netlogon.dll
[2009/08/28 16:19:33 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/08/28 16:19:33 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\es.dll
[2009/08/28 16:19:33 | 00,249,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tapisrv.dll
[2009/08/28 16:19:33 | 00,245,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mswsock.dll
[2009/08/28 16:19:33 | 00,198,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netman.dll
[2009/08/28 16:19:33 | 00,192,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\schedsvc.dll
[2009/08/28 16:19:33 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\upnphost.dll
[2009/08/28 16:19:33 | 00,181,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\scecli.dll
[2009/08/28 16:19:33 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\srsvc.dll
[2009/08/28 16:19:33 | 00,142,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\aec.sys
[2009/08/28 16:19:33 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\shsvcs.dll
[2009/08/28 16:19:33 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\xmlprov.dll
[2009/08/28 16:19:33 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/08/28 16:19:33 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\browser.dll
[2009/08/28 16:19:33 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ssdpsrv.dll
[2009/08/28 16:19:33 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\cryptsvc.dll
[2009/08/28 16:19:33 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\regsvc.dll
[2009/08/28 16:19:33 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\eventlog.dll
[2009/08/28 16:19:33 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/08/28 16:19:33 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mspmsnsv.dll
[2009/08/28 16:19:33 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/08/28 16:19:33 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/08/28 16:19:33 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\linkinfo.dll
[2009/08/28 16:19:33 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\asyncmac.sys
[2009/08/28 16:19:33 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wscntfy.exe
[2009/08/28 16:19:33 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/08/28 16:19:33 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/08/28 16:19:33 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/08/28 16:19:33 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/08/28 16:19:32 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mshtml.dll
[2009/08/28 16:19:32 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/08/28 16:19:32 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/08/28 16:19:32 | 01,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/08/28 16:19:32 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/08/28 16:19:32 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/08/28 16:19:32 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/08/28 16:19:32 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/08/28 16:19:32 | 00,361,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/08/28 16:19:32 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/08/28 16:19:32 | 00,182,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/08/28 16:19:32 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/08/28 16:19:32 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/08/28 16:19:32 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/08/28 16:19:32 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/08/28 16:19:32 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/08/28 16:19:32 | 00,036,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/08/28 16:19:32 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/08/28 16:19:32 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/08/28 16:19:32 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/08/28 16:19:32 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/08/28 16:19:32 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/08/28 16:19:32 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/08/28 16:06:20 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/08/28 16:06:17 | 00,260,272 | —- | C] () – C:\cmldr
[2009/08/28 16:06:17 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/08/28 15:58:46 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/28 15:58:45 | 00,229,376 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/28 15:58:45 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/28 15:58:45 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/28 15:58:44 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/28 15:58:44 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/28 15:58:44 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/28 15:58:44 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/28 15:34:22 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\OTL.exe
[2009/08/28 15:33:23 | 00,472,064 | —- | C] ( ) – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\RootRepeal.exe
[2009/08/28 15:33:07 | 00,464,491 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\RootRepeal.zip
[2009/08/28 14:07:18 | 03,187,537 | R— | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Combo-Fix.exe
[2009/08/28 14:00:41 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/28 14:00:28 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/28 07:37:51 | 00,456,068 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\101788594 REV A D00332706[1].x_t
[2009/08/27 15:45:32 | 21,455,09376 | -HS- | C] () – C:\hiberfil.sys
[2009/08/25 15:41:57 | 00,000,000 | —D | C] – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\Sanford,_L.P
[2009/08/25 13:20:48 | 00,000,000 | —D | C] – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\DYMO Label
[2009/08/25 13:20:47 | 00,000,000 | —D | C] – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\DYMO
[2009/08/25 13:20:30 | 00,000,037 | —- | C] () – C:\WINDOWS\iltwain.ini
[2009/08/25 13:19:51 | 00,000,000 | —D | C] – C:\Program Files\DYMO
[2009/08/25 13:19:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DYMO
[2009/08/25 10:34:58 | 00,125,952 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Interim Ppap Worksheet.doc
[2009/08/25 07:51:12 | 00,023,040 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Copy of AUG-END.xls
[2009/08/23 11:43:37 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/08/17 13:38:39 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/17 13:38:38 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/17 13:38:38 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/15 21:54:26 | 00,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/08/12 09:05:33 | 01,065,536 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\AutoItImage2.jpg
[2009/08/12 09:05:32 | 01,090,064 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\AutoItImage.jpg
[2009/08/12 09:04:56 | 05,292,054 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\AutoItImage2.bmp
[2009/08/12 09:04:56 | 05,292,054 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\AutoItImage.bmp
[2009/08/12 08:54:41 | 00,000,000 | —D | C] – C:\Program Files\AutoIt3
[2009/08/12 00:31:47 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/08/12 00:31:31 | 01,315,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msoe.dll
[2009/08/10 14:55:29 | 00,000,256 | —- | C] () – C:\WINDOWS\pool.bin
[2009/08/10 12:41:32 | 00,000,000 | —D | C] – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Pics
[2009/08/05 05:01:48 | 00,204,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/03 21:50:26 | 00,000,034 | —- | C] () – C:\WINDOWS\System32\BD2170W.DAT
[2009/08/03 21:49:03 | 01,027,072 | —- | C] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\2100-2KXP2003VISTA-32-0107-US.EXE
[2009/07/08 16:54:12 | 00,000,035 | —- | C] () – C:\WINDOWS\C30eTbo.INI
[2009/06/19 11:22:03 | 00,000,383 | —- | C] () – C:\WINDOWS\System32\haspdos.sys
[2009/05/18 14:46:07 | 01,326,080 | —- | C] () – C:\WINDOWS\System32\drivers\XLHASP.sys
[2009/05/11 10:45:55 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/02/24 14:22:00 | 00,000,043 | —- | C] () – C:\WINDOWS\gswin32.ini
[2009/01/30 11:59:35 | 00,346,112 | —- | C] () – C:\WINDOWS\System32\Prosql32.dll
[2009/01/30 11:57:32 | 00,000,304 | —- | C] () – C:\WINDOWS\ISLV.INI
[2008/11/18 11:24:04 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\AdapterId.dll
[2008/11/18 11:24:03 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\support.dll
[2008/07/07 10:14:29 | 00,025,736 | —- | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2008/06/09 13:26:26 | 00,000,443 | —- | C] () – C:\WINDOWS\avpr.ini
[2008/06/06 14:53:26 | 00,000,392 | —- | C] () – C:\WINDOWS\System32\BTRDRVR.SYS
[2008/04/18 10:26:27 | 00,000,281 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/02/23 16:18:40 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2008/02/23 16:18:40 | 00,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2008/02/23 16:18:39 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2008/02/23 16:04:26 | 00,000,012 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2008/02/23 16:04:26 | 00,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2008/02/23 16:03:36 | 00,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2008/02/23 15:51:44 | 00,000,269 | —- | C] () – C:\WINDOWS\Brownie.ini
[2008/02/04 18:23:10 | 00,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/12/06 11:53:30 | 00,294,080 | —- | C] () – C:\WINDOWS\System32\FargoPrinterSDK13.dll
[2007/11/05 21:09:37 | 00,019,152 | —- | C] () – C:\WINDOWS\avwin.ini
[2007/10/19 20:56:16 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/19 20:54:28 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2007/10/19 20:54:28 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2007/10/18 05:02:34 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/10/16 14:24:48 | 00,000,011 | —- | C] () – C:\WINDOWS\avx.ini
[2007/09/16 13:11:50 | 00,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/09/12 14:14:20 | 00,685,816 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2007/09/10 21:44:40 | 00,029,752 | —- | C] () – C:\WINDOWS\System32\InstHelper.dll
[2007/09/10 21:44:18 | 00,197,680 | —- | C] () – C:\WINDOWS\System32\vpnapi.dll
[2007/09/10 21:44:16 | 00,193,584 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2007/09/04 15:30:58 | 00,299,008 | —- | C] () – C:\WINDOWS\System32\ivutl14.dll
[2007/09/04 15:30:56 | 00,434,176 | —- | C] () – C:\WINDOWS\System32\procli92.dll
[2007/05/22 12:09:19 | 00,057,344 | R— | C] () – C:\WINDOWS\System32\DYMOCFG.DLL
[2007/05/17 12:47:28 | 00,000,632 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/04/19 13:58:51 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2007/03/21 18:02:21 | 00,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2007/03/09 00:50:35 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/03/09 00:45:47 | 00,143,360 | —- | C] () – C:\WINDOWS\System32\bioapi_mds300.dll
[2007/03/09 00:45:47 | 00,106,496 | —- | C] () – C:\WINDOWS\System32\bioapi100.dll
[2007/03/09 00:23:08 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/03/09 00:23:08 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/03/09 00:23:07 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/03/09 00:23:07 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/03/09 00:23:05 | 00,106,496 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2007/03/09 00:22:06 | 00,000,390 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/09/12 14:07:36 | 00,184,320 | —- | C] () – C:\WINDOWS\System32\AmRes_en.dll
[2006/09/12 14:01:48 | 00,196,608 | —- | C] () – C:\WINDOWS\System32\AmRes_es.dll
[2006/09/12 14:01:42 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\AmRes_ko.dll
[2006/09/12 14:01:34 | 00,196,608 | —- | C] () – C:\WINDOWS\System32\AmRes_de.dll
[2006/09/12 14:01:28 | 00,184,320 | —- | C] () – C:\WINDOWS\System32\AmRes_pt-BR.dll
[2006/09/12 14:01:20 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\AmRes_fr.dll
[2006/09/12 14:01:12 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\AmRes_ja.dll
[2006/09/12 14:01:06 | 00,208,896 | —- | C] () – C:\WINDOWS\System32\AmRes_ru.dll
[2006/09/12 14:00:58 | 00,196,608 | —- | C] () – C:\WINDOWS\System32\AmRes_it.dll
[2006/09/12 14:00:52 | 00,176,128 | —- | C] () – C:\WINDOWS\System32\AmRes_zh-CHS.dll
[2006/09/12 14:00:44 | 00,172,032 | —- | C] () – C:\WINDOWS\System32\AmRes_zh-CHT.dll
[2006/09/08 10:32:02 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\wxvault.dll
[2006/09/08 10:30:44 | 00,004,096 | —- | C] () – C:\WINDOWS\System32\detoured.dll
[2006/09/05 12:05:32 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\Internationalization_en.dll
[2006/09/05 11:26:06 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\Internationalization_pt.dll
[2006/09/05 11:25:54 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\Internationalization_zh-CHT.dll
[2006/09/05 11:25:42 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\Internationalization_ko.dll
[2006/09/05 11:25:32 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\Internationalization_es.dll
[2006/09/05 11:25:20 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\Internationalization_ru.dll
[2006/09/05 11:25:10 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\Internationalization_ja.dll
[2006/09/05 11:24:58 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\Internationalization_it.dll
[2006/09/05 11:24:48 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\Internationalization_de.dll
[2006/09/05 11:24:36 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\Internationalization_fr.dll
[2006/09/05 11:24:26 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\Internationalization_zh-CHS.dll
[2006/06/12 12:01:18 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\TspPopup_RUS.dll
[2006/06/12 12:01:18 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\TspPopup_ITA.dll
[2006/06/12 12:01:18 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\TspPopup_FRA.dll
[2006/06/12 12:01:18 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\TspPopup_ESN.dll
[2006/06/12 12:01:18 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\TspPopup_ENU.dll
[2006/06/12 12:01:18 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\TspPopup_DEU.dll
[2006/06/12 12:01:18 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\TspPopup_CHS.dll
[2006/06/12 12:01:16 | 00,348,160 | —- | C] () – C:\WINDOWS\System32\Tsp.dll
[2005/12/01 16:41:20 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\pbadrvdll.dll
[2005/09/20 15:36:06 | 00,798,720 | —- | C] () – C:\WINDOWS\System32\DemoLicense.dll
[2004/08/11 19:24:19 | 00,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 19:11:31 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 19:00:37 | 00,001,140 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/11 19:00:35 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2004/07/21 17:03:14 | 00,917,504 | —- | C] () – C:\WINDOWS\System32\lmgr10.dll
[2004/07/20 16:27:52 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\ADsSecurity.dll
[2004/03/18 20:01:20 | 00,072,192 | —- | C] () – C:\WINDOWS\System32\xltZlib.dll
[2003/06/11 18:39:12 | 06,270,976 | —- | C] () – C:\WINDOWS\System32\cricu19.dll
[2002/02/27 10:41:28 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\nsldappr32v50.dll
[2002/02/27 10:41:26 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\nsldap32v50.dll
[2002/02/27 10:41:26 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\nsldapssl32v50.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[73 C:\WINDOWS\*.tmp files]
File not found – C:\WINDOWS\System32\drivers\mshdmd.sys.
[2009/08/28 18:00:02 | 00,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{91145BBF-DD3A-44D8-B24E-C488F6A059FF}.job
[2009/08/28 17:47:12 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/08/28 17:47:08 | 00,061,150 | —- | M] () – C:\WINDOWS\System32\nvwsapps.xml
[2009/08/28 17:47:07 | 00,128,795 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2009/08/28 17:46:25 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/08/28 17:46:04 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/08/28 17:44:33 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/28 17:44:28 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/28 17:44:19 | 21,455,09376 | -HS- | M] () – C:\hiberfil.sys
[2009/08/28 17:37:31 | 03,187,537 | R— | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Combo-Fix.exe
[2009/08/28 17:27:34 | 00,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/08/28 16:06:20 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/08/28 15:34:22 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\OTL.exe
[2009/08/28 15:33:08 | 00,464,491 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\RootRepeal.zip
[2009/08/28 13:07:32 | 00,001,732 | -H– | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\Default.rdp
[2009/08/28 13:06:46 | 00,000,938 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Time-Clock.lnk
[2009/08/28 12:10:19 | 00,000,906 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Global Shop Session 020.lnk
[2009/08/28 07:37:51 | 00,456,068 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\101788594 REV A D00332706[1].x_t
[2009/08/27 23:31:09 | 00,001,008 | —- | M] () – C:\WINDOWS\tasks\Vantage_Important.job
[2009/08/27 13:20:17 | 00,019,152 | —- | M] () – C:\WINDOWS\avwin.ini
[2009/08/27 13:20:10 | 03,707,610 | -H– | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\IconCache.db
[2009/08/27 13:14:33 | 00,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2009/08/27 10:34:00 | 01,326,080 | —- | M] () – C:\WINDOWS\System32\drivers\XLHASP.sys
[2009/08/25 13:20:30 | 00,000,037 | —- | M] () – C:\WINDOWS\iltwain.ini
[2009/08/25 12:30:53 | 00,125,952 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Interim Ppap Worksheet.doc
[2009/08/25 07:51:13 | 00,023,040 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\Copy of AUG-END.xls
[2009/08/23 11:43:38 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/08/23 10:11:21 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/23 03:09:13 | 00,229,376 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/15 21:54:26 | 00,000,118 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[2009/08/15 09:02:28 | 00,000,256 | —- | M] () – C:\WINDOWS\System32\pool.bin
[2009/08/15 08:58:33 | 00,411,880 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/13 11:14:18 | 00,472,064 | —- | M] ( ) – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Desktop\RootRepeal.exe
[2009/08/12 09:05:33 | 01,090,064 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\AutoItImage.jpg
[2009/08/12 09:05:33 | 01,065,536 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\AutoItImage2.jpg
[2009/08/12 09:05:32 | 00,028,672 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/12 09:04:56 | 05,292,054 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\AutoItImage2.bmp
[2009/08/12 09:04:56 | 05,292,054 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\AutoItImage.bmp
[2009/08/11 11:08:13 | 00,022,355 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Application Data\Comma Separated Values (Windows).ADR
[2009/08/11 09:49:07 | 00,124,200 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/10 15:06:11 | 00,000,256 | —- | M] () – C:\WINDOWS\pool.bin
[2009/08/10 15:02:56 | 00,001,140 | —- | M] () – C:\WINDOWS\win.ini
[2009/08/06 13:22:05 | 00,000,632 | —- | M] () – C:\WINDOWS\ODBC.INI
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mswebdvd.dll
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/03 21:50:26 | 00,000,034 | —- | M] () – C:\WINDOWS\System32\BD2170W.DAT
[2009/08/03 21:49:03 | 01,027,072 | —- | M] () – C:\Documents and Settings\matt-f.BTECSOLUTIONS.000\My Documents\2100-2KXP2003VISTA-32-0107-US.EXE
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/29 20:49:14 | 24,281,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
< End of report >
Ok, do these scans and tell me how your machine is running now :)

——————
Step 1:
——————

[external image: Posted Image]Run Malwarebytes' Anti-Malware
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

——————
Step 2:
——————

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

——————
Step 3:
——————

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply

——————
Step 4:
——————

Please post back with the following:
  • How your machine is running
  • MBAM log
  • KasReport.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI