This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Leftover infections from Total Security virus that won'

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings, I caught the Total Security virus, and I think that I got rid of the program successfully after stopping the .exe and then running Malwarebytes. However, it looks like there's some things left behind that keep reappearing after I restart my computer (I pasted the Malwarebytes log file at the very bottom that contains the malware that keeps appearing after I 'remove selected' and restart). The virus seems to make it more difficult for me to browse the web. About 80% of the time, a link will take me where it's supposed to and another 20% of the time I am redirected to irrelevant ads. It's nowhere near as bad as the original Total Security virus, but I'd still like to remove it if possible. Anyways, I've pasted the DDS and RootRepeal logfiles here along with the attachment as specified in the 'Welcome New Members' topic. I've also downloaded HijackThis, but I haven't used it yet because I don't want to destroy anything important. Please let me know if there's anything else I can do to get rid of this virus. Thanks, - Orod DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 15:41:19.14 on Mon 08/31/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1341 [GMT -4:00] ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\Ati2evxx.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Digital Media Reader\shwiconem.exe C:\WINDOWS\zHotkey.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\WiFiConnector\NintendoWFCReg.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe svchost.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Megaupload\Mega Manager\MegaManager.exe C:\Program Files\Java\jre6\bin\java.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Bar = hxxp://www.google.com/ie uStart Page = hxxp://www.google.com/ mSearchAssistant = hxxp://www.google.com/ie BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 52\axcmd.exe" /automount mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe mRun: [] mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [CHotkey] zHotkey.exe mRun: [ShowWnd] ShowWnd.exe mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe mRun: [Mixersel] c:\program files\realtek\installshield\mixersel.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [AlcWzrd] ALCWZRD.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe mRunOnce: [FolderProtection] regsvr32 ShellvRTF.dll /s StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe IE: Download Link Using Mega Manager… - c:\program files\megaupload\mega manager\mm_file.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} - hxxp://support.gateway.com/support/serialharvest/gwCID.CAB DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs: ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\if50ndrw.default\ FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - HiddenExtension: XUL Cache: {D76C49C9-5A37-4F2B-A820-6A12C19E9335} - c:\documents and settings\owner\local settings\application data\{d76c49c9-5a37-4f2b-a820-6a12c19e9335}\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064] =============== Created Last 30 ================ 2009-08-29 13:59 –d—– c:\program files\WinPcap 2009-08-29 13:36 84,096 a——- c:\windows\system32\drivers\b106ac19.sys 2009-08-28 14:27 –d—– c:\program files\Trend Micro 2009-08-25 01:48 –d—– c:\program files\EcoleSoftware 2009-08-25 01:41 –d—– c:\program files\Alcohol Soft 2009-08-25 01:03 –d—– c:\program files\DAEMON Tools Pro 2009-08-25 01:03 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Pro 2009-08-25 01:00 722,416 a——- c:\windows\system32\drivers\sptd.sys 2009-08-25 01:00 –d—– c:\docume~1\owner\applic~1\DAEMON Tools Pro 2009-08-24 23:52 50 a——- c:\windows\MegaManager.INI 2009-08-24 23:49 –d—– c:\docume~1\owner\applic~1\Megaupload 2009-08-24 23:46 –d—– c:\program files\Megaupload 2009-08-22 04:43 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-22 04:43 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-22 04:43 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-22 04:29 –d—– c:\program files\gbmgtn 2009-08-14 21:03 54,156 a—h— c:\windows\QTFont.qfn 2009-08-14 21:03 1,409 a——- c:\windows\QTFont.for 2009-08-05 23:15 –d—– c:\program files\Belarc 2009-08-05 01:07 –d—– c:\docume~1\owner\applic~1\Malwarebytes 2009-08-05 01:06 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-05 00:35 –d—– c:\program files\raogih ==================== Find3M ==================== 2009-08-03 23:10 85,504 a–sh— c:\windows\system32\vobulofo.dll 2009-08-03 23:10 38,400 a–sh— c:\windows\system32\kofelifu.dll 2009-08-03 11:10 83,968 a–sh— c:\windows\system32\zutovogi.dll 2009-08-03 11:10 38,400 a–sh— c:\windows\system32\dadatefe.dll 2009-08-02 23:10 83,968 a–sh— c:\windows\system32\kerobuvi.dll 2009-08-02 23:10 38,400 a–sh— c:\windows\system32\lukuduni.dll 2009-07-25 12:15 410,984 a——- c:\windows\system32\deploytk.dll 2009-07-19 00:51 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-07-18 19:26 8,552 a——- c:\windows\system32\drivers\asctrm.sys 2009-07-18 17:41 73,728 a——- c:\windows\ALCFDRTM.EXE 2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 15:09 1,291,264 ——– c:\windows\system32\quartz.dll ============= FINISH: 15:41:36.31 =============== ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/31 15:45 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP3 ================================================== Drivers ——————- Name: b106ac19.sys Image Path: C:\WINDOWS\System32\drivers\b106ac19.sys Address: 0xAAE0B000 Size: 84096 File Visible: No Signed: - Status: - Name: blarnaj.sys Image Path: blarnaj.sys Address: 0xBA0A8000 Size: 61440 File Visible: No Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xAAD7F000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xBA5F4000 Size: 8192 File Visible: No Signed: - Status: - Name: PCI_PNP0834 Image Path: \Driver\PCI_PNP0834 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA7967000 Size: 49152 File Visible: No Signed: - Status: - Name: spde.sys Image Path: spde.sys Address: 0xB9EA6000 Size: 1052672 File Visible: No Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - SSDT ——————- #: 035 Function Name: NtCreateEvent Status: Hooked by "C:\WINDOWS\System32\drivers\b106ac19.sys" at address 0xaae11815 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\System32\drivers\b106ac19.sys" at address 0xaae0f805 #: 071 Function Name: NtEnumerateKey Status: Hooked by "spde.sys" at address 0xb9ec5da4 #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "spde.sys" at address 0xb9ec6132 #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\System32\drivers\b106ac19.sys" at address 0xaae0f8c5 #: 160 Function Name: NtQueryKey Status: Hooked by "spde.sys" at address 0xb9ec620a #: 177 Function Name: NtQueryValueKey Status: Hooked by "spde.sys" at address 0xb9ec608a #: 247 Function Name: NtSetValueKey Status: Hooked by "spde.sys" at address 0xb9ec629c Hidden Services ——————- Service Name: b106ac19 Image Path: C:\WINDOWS\System32\drivers\b106ac19.sys Service Name: kbiwkmlsxmgejt Image Path: C:\WINDOWS\system32\drivers\kbiwkmkdxqqkuo.sys Service Name: mbamswissarmy Image Path: C:\WINDOWS\system32\drivers\mbamswissarmy.sys ==EOF== Malwarebytes' Anti-Malware 1.40 Database version: 2722 Windows 5.1.2600 Service Pack 3 8/31/2009 4:06:29 PM mbam-log-2009-08-31 (16-06-25).txt Scan type: Quick Scan Objects scanned: 102356 Time elapsed: 5 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kbiwkmlsxmgejt (Rootkit.TDSS) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Attachments:

Hi Orod , welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back witht the combofix log. How is the computer now?

Thanks
Thank you oldman,

I just ran ComboFix, so I'll let you know if anything changes throughout use today. So far so good. I haven't noticed any ad redirects yet from visiting a quick series of websites.

I included the ComboFix.txt file to this reply. Please let me know if you see anything else I need to do to clean my computer.

- Orod

ComboFix 09-08-31.04 - Owner 09/01/2009 13:07.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1612 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Local Settings\Application Data\{D76C49C9-5A37-4F2B-A820-6A12C19E9335}
c:\documents and settings\Owner\Local Settings\Application Data\{D76C49C9-5A37-4F2B-A820-6A12C19E9335}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{D76C49C9-5A37-4F2B-A820-6A12C19E9335}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{D76C49C9-5A37-4F2B-A820-6A12C19E9335}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{D76C49C9-5A37-4F2B-A820-6A12C19E9335}\install.rdf
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\recycler\S-1-5-21-3854199597-1568727750-447480215-500
c:\windows\system32\dadatefe.dll
c:\windows\system32\drivers\b106ac19.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\kerobuvi.dll
c:\windows\system32\kofelifu.dll
c:\windows\system32\lukuduni.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\zutovogi.dll
E:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_kbiwkmlsxmgejt
——-\Legacy_npf
——-\Service_kbiwkmlsxmgejt
——-\Service_npf
——-\Service_b106ac19


((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
.

2009-08-31 19:37 . 2009-08-31 19:37 ——– d—–w- c:\program files\ERUNT
2009-08-31 19:09 . 2009-08-31 19:09 ——– d—–w- c:\documents and settings\Owner\Application Data\SampleView
2009-08-29 17:35 . 2009-08-29 17:35 ——– d—–w- c:\windows\Sun
2009-08-29 03:53 . 2009-08-29 03:53 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Identities
2009-08-28 18:27 . 2009-08-28 18:27 ——– d—–w- c:\program files\Trend Micro
2009-08-26 19:21 . 2009-08-26 19:21 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-26 04:11 . 2009-08-26 04:11 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-08-25 05:48 . 2009-08-25 05:48 ——– d—–w- c:\program files\EcoleSoftware
2009-08-25 05:41 . 2009-08-25 05:41 ——– d—–w- c:\program files\Alcohol Soft
2009-08-25 05:03 . 2009-08-25 05:38 ——– d—–w- c:\program files\DAEMON Tools Pro
2009-08-25 05:03 . 2009-08-25 05:03 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-08-25 05:00 . 2009-08-25 05:00 722416 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-08-25 05:00 . 2009-08-25 05:00 ——– d—–w- c:\documents and settings\Owner\Application Data\DAEMON Tools Pro
2009-08-25 03:49 . 2009-08-25 03:49 ——– d—–w- c:\documents and settings\Owner\Application Data\Megaupload
2009-08-25 03:46 . 2009-08-25 03:46 ——– d—–w- c:\program files\Megaupload
2009-08-22 08:43 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 08:43 . 2009-08-22 08:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 08:43 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 08:29 . 2009-08-22 08:58 ——– d—–w- c:\program files\gbmgtn
2009-08-15 00:55 . 2009-08-15 00:55 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-08-06 03:15 . 2009-08-06 03:15 ——– d—–w- c:\program files\Belarc
2009-08-05 05:07 . 2009-08-05 05:07 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-05 05:06 . 2009-08-05 05:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-05 04:35 . 2009-08-05 05:18 ——– d—–w- c:\program files\raogih
2009-08-03 03:04 . 2009-08-03 03:04 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 16:51 . 2009-07-20 04:34 ——– d—–w- c:\documents and settings\Owner\Application Data\Azureus
2009-08-27 05:27 . 2009-07-19 05:45 ——– d—–w- c:\program files\Trillian
2009-08-25 03:46 . 2009-07-18 23:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-04 03:10 . 2009-05-04 03:10 85504 –sha-w- c:\windows\system32\vobulofo.dll
2009-07-30 04:16 . 2009-07-20 04:34 65000 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-30 04:16 . 2009-07-30 04:16 ——– d—–w- c:\documents and settings\Owner\Application Data\ATI
2009-07-30 04:16 . 2009-07-30 04:16 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI
2009-07-30 04:03 . 2009-07-30 03:37 ——– d—–w- c:\program files\ATI Technologies
2009-07-30 03:41 . 2009-07-30 03:41 0 —-a-w- c:\windows\ativpsrm.bin
2009-07-29 22:29 . 2009-07-24 16:00 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-07-28 18:11 . 2009-07-28 18:11 ——– d—–w- c:\documents and settings\Owner\Application Data\InstallShield
2009-07-28 09:01 . 2009-07-28 09:01 ——– d—–w- c:\program files\Firaxis Games
2009-07-28 07:59 . 2009-07-28 07:59 ——– d—–w- c:\program files\Gateway
2009-07-28 06:57 . 2009-07-28 06:57 ——– d—–w- c:\documents and settings\Owner\Application Data\My Games
2009-07-26 04:09 . 2009-07-26 04:09 ——– d—–w- c:\program files\WiFiConnector
2009-07-25 16:15 . 2009-07-25 16:16 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-07-25 16:15 . 2005-04-13 17:41 ——– d—–w- c:\program files\Java
2009-07-25 16:15 . 2009-07-25 16:15 152576 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-24 16:00 . 2009-07-24 16:00 10684866 —-a-w- c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\mplayer.exe
2009-07-20 04:34 . 2009-07-20 04:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Azureus
2009-07-20 04:34 . 2009-07-20 04:33 ——– d—–w- c:\program files\Vuze
2009-07-20 03:24 . 2009-07-20 03:24 ——– d—–w- c:\documents and settings\Owner\Application Data\Media Player Classic
2009-07-19 06:00 . 2009-07-18 23:13 ——– d—–w- c:\program files\Symantec
2009-07-19 05:43 . 2009-07-19 05:43 ——– d—–w- c:\program files\K-Lite Codec Pack
2009-07-19 05:25 . 2009-07-18 23:13 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-07-19 05:19 . 2009-07-18 23:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-19 05:16 . 2009-07-18 23:30 ——– d—–w- c:\program files\Google
2009-07-19 04:58 . 2009-07-18 23:28 ——– d—–w- c:\program files\Pure Networks
2009-07-19 04:51 . 2005-04-13 17:18 86811 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-19 04:39 . 2009-07-18 23:23 ——– d—–w- c:\program files\Common Files\AOL
2009-07-19 04:39 . 2009-07-18 23:26 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-07-18 23:32 . 2009-07-18 23:32 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-07-18 23:32 . 2009-07-18 23:32 ——– d—–w- c:\program files\Microsoft.NET
2009-07-18 23:30 . 2009-07-18 23:30 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-07-18 23:30 . 2009-07-18 23:30 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\McAfee
2009-07-18 23:30 . 2009-07-18 23:30 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-07-18 23:29 . 2009-07-18 23:29 ——– d—–w- c:\program files\Ahead
2009-07-18 23:29 . 2009-07-18 23:29 ——– d—–w- c:\program files\Common Files\Ahead
2009-07-18 23:29 . 2009-07-18 23:26 ——– d—–w- c:\program files\QuickTime
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\program files\Viewpoint
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\program files\Learn2.com
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-07-18 23:26 . 2009-07-18 23:26 ——– d—–w- c:\program files\Common Files\Nullsoft
2009-07-18 21:41 . 2009-07-18 21:41 73728 —-a-w- c:\windows\ALCFDRTM.EXE
2009-07-18 21:36 . 2009-07-18 23:29 ——– d—–w- c:\program files\BigFix
2009-07-18 20:35 . 2009-07-18 20:35 49152 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\NewShortcut3_15377C3E9655400FB441E69F0A6BEAFE.EXE
2009-07-18 20:35 . 2009-07-18 20:35 45056 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\NewShortcut2_15377C3E9655400FB441E69F0A6BEAFE.EXE
2009-07-18 20:35 . 2009-07-18 20:35 45056 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\NewShortcut1_15377C3E9655400FB441E69F0A6BEAFE.exe
2009-07-18 20:35 . 2009-07-18 20:35 10134 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\ARPPRODUCTICON.exe
2009-07-18 20:35 . 2009-07-18 20:35 ——– d—–w- c:\program files\Napster
2009-07-18 20:35 . 2009-07-18 20:35 ——– d—–w- c:\program files\Common Files\Roxio Shared
2009-07-18 20:35 . 2009-07-18 20:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Napster
2009-07-18 20:35 . 2009-07-18 23:21 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-03 17:09 . 2005-04-13 16:56 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-16 14:36 . 2005-04-13 16:56 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-04-13 16:55 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:09 . 2005-04-13 16:55 1291264 ——w- c:\windows\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-19 39408]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 52\axcmd.exe" [2009-04-24 203416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 148888]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-07-18 98304]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Mixersel"="c:\program files\Realtek\InstallShield\mixersel.exe" [2003-11-11 369664]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-19 122368]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-28 61440]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-03-09 966656]
"CHotkey"="zHotkey.exe" - c:\windows\zHotkey.exe [2004-05-18 543232]
"ShowWnd"="ShowWnd.exe" - c:\windows\ShowWnd.exe [2003-09-19 36864]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-08-13 61952]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-10-21 77824]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2004-10-22 2744832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2009-7-26 1073152]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\if50ndrw.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-01 13:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3956)
c:\windows\system32\WININET.dll
c:\program files\Google\Quick Search Box\bin\1.2.1137.3514\qsb.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-01 13:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-01 17:19

Pre-Run: 96,271,294,464 bytes free
Post-Run: 96,356,065,280 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

232 — E O F — 2009-07-29 07:00

Attachments:

Hi Orod,

Please do not attach the logs unless asked to. It's easier to read them on the forum.

Vuze
You have Vuze, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. It's not the programs themselves but what can be downloaded with them that is the problem. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. You'll be doing yourself a favor by removing them.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554

I would recommend that you uninstall Vuze, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Still have a bit to do.

We will be using Combofix again.

Please read through these instructions to familarize yourself with what to expect when this tool runs

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/Leftover_infections_Total_Security_virus_won_t_disappear_t106618.html

KillAll::

Collect::[4]
c:\windows\system32\vobulofo.dll

File::
c:\windows\ativpsrm.bin

DirLook::
c:\program files\raogih
c:\program files\gbmgtn

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

  • Please post back with the combofix log.

    Thanks
Thanks oldman. I have not noticed any unusual behavior of my PC since running ComboFix for the first time. I will make sure not to run Vuze anymore until until this process is complete. I only have one question: If ComboFix asks me if it's alright to update itself, should I answer "Yes"?

Here is the most recent ComboFix log:


ComboFix 09-08-31.04 - Owner 09/02/2009 13:41.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1624 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt

FILE ::
"c:\windows\ativpsrm.bin"

file zipped: c:\windows\system32\vobulofo.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\ativpsrm.bin
c:\windows\system32\vobulofo.dll

.
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.

2009-09-01 23:56 . 2009-09-01 23:56 10628032 —-a-w- c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU183862168671922861.tmp\Vuze_4.2.0.8b_win32.exe
2009-08-31 19:37 . 2009-08-31 19:37 ——– d—–w- c:\program files\ERUNT
2009-08-31 19:09 . 2009-08-31 19:09 ——– d—–w- c:\documents and settings\Owner\Application Data\SampleView
2009-08-29 17:35 . 2009-08-29 17:35 ——– d—–w- c:\windows\Sun
2009-08-29 03:53 . 2009-08-29 03:53 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Identities
2009-08-28 18:27 . 2009-08-28 18:27 ——– d—–w- c:\program files\Trend Micro
2009-08-26 19:21 . 2009-08-26 19:21 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-26 04:11 . 2009-08-26 04:11 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-08-25 05:48 . 2009-08-25 05:48 ——– d—–w- c:\program files\EcoleSoftware
2009-08-25 05:41 . 2009-08-25 05:41 ——– d—–w- c:\program files\Alcohol Soft
2009-08-25 05:03 . 2009-08-25 05:38 ——– d—–w- c:\program files\DAEMON Tools Pro
2009-08-25 05:03 . 2009-08-25 05:03 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-08-25 05:00 . 2009-08-25 05:00 722416 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-08-25 05:00 . 2009-08-25 05:00 ——– d—–w- c:\documents and settings\Owner\Application Data\DAEMON Tools Pro
2009-08-25 03:49 . 2009-08-25 03:49 ——– d—–w- c:\documents and settings\Owner\Application Data\Megaupload
2009-08-25 03:46 . 2009-08-25 03:46 ——– d—–w- c:\program files\Megaupload
2009-08-22 08:43 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 08:43 . 2009-08-22 08:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 08:43 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 08:29 . 2009-08-22 08:58 ——– d—–w- c:\program files\gbmgtn
2009-08-15 00:55 . 2009-08-15 00:55 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-08-06 03:15 . 2009-08-06 03:15 ——– d—–w- c:\program files\Belarc
2009-08-05 05:07 . 2009-08-05 05:07 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-05 05:06 . 2009-08-05 05:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-05 04:35 . 2009-08-05 05:18 ——– d—–w- c:\program files\raogih

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 08:00 . 2009-07-20 04:34 ——– d—–w- c:\documents and settings\Owner\Application Data\Azureus
2009-08-27 05:27 . 2009-07-19 05:45 ——– d—–w- c:\program files\Trillian
2009-08-25 03:46 . 2009-07-18 23:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-30 04:16 . 2009-07-20 04:34 65000 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-30 04:16 . 2009-07-30 04:16 ——– d—–w- c:\documents and settings\Owner\Application Data\ATI
2009-07-30 04:16 . 2009-07-30 04:16 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI
2009-07-30 04:03 . 2009-07-30 03:37 ——– d—–w- c:\program files\ATI Technologies
2009-07-29 22:29 . 2009-07-24 16:00 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-07-28 18:11 . 2009-07-28 18:11 ——– d—–w- c:\documents and settings\Owner\Application Data\InstallShield
2009-07-28 09:01 . 2009-07-28 09:01 ——– d—–w- c:\program files\Firaxis Games
2009-07-28 07:59 . 2009-07-28 07:59 ——– d—–w- c:\program files\Gateway
2009-07-28 06:57 . 2009-07-28 06:57 ——– d—–w- c:\documents and settings\Owner\Application Data\My Games
2009-07-26 04:09 . 2009-07-26 04:09 ——– d—–w- c:\program files\WiFiConnector
2009-07-25 16:15 . 2009-07-25 16:16 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-07-25 16:15 . 2005-04-13 17:41 ——– d—–w- c:\program files\Java
2009-07-25 16:15 . 2009-07-25 16:15 152576 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-24 16:00 . 2009-07-24 16:00 10684866 —-a-w- c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\mplayer.exe
2009-07-20 04:34 . 2009-07-20 04:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Azureus
2009-07-20 04:34 . 2009-07-20 04:33 ——– d—–w- c:\program files\Vuze
2009-07-20 03:24 . 2009-07-20 03:24 ——– d—–w- c:\documents and settings\Owner\Application Data\Media Player Classic
2009-07-19 06:00 . 2009-07-18 23:13 ——– d—–w- c:\program files\Symantec
2009-07-19 05:43 . 2009-07-19 05:43 ——– d—–w- c:\program files\K-Lite Codec Pack
2009-07-19 05:25 . 2009-07-18 23:13 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-07-19 05:19 . 2009-07-18 23:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-19 05:16 . 2009-07-18 23:30 ——– d—–w- c:\program files\Google
2009-07-19 04:58 . 2009-07-18 23:28 ——– d—–w- c:\program files\Pure Networks
2009-07-19 04:51 . 2005-04-13 17:18 86811 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-19 04:39 . 2009-07-18 23:23 ——– d—–w- c:\program files\Common Files\AOL
2009-07-19 04:39 . 2009-07-18 23:26 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-07-18 23:32 . 2009-07-18 23:32 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-07-18 23:32 . 2009-07-18 23:32 ——– d—–w- c:\program files\Microsoft.NET
2009-07-18 23:30 . 2009-07-18 23:30 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-07-18 23:30 . 2009-07-18 23:30 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\McAfee
2009-07-18 23:30 . 2009-07-18 23:30 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-07-18 23:29 . 2009-07-18 23:29 ——– d—–w- c:\program files\Ahead
2009-07-18 23:29 . 2009-07-18 23:29 ——– d—–w- c:\program files\Common Files\Ahead
2009-07-18 23:29 . 2009-07-18 23:26 ——– d—–w- c:\program files\QuickTime
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\program files\Viewpoint
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\program files\Learn2.com
2009-07-18 23:28 . 2009-07-18 23:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-07-18 23:26 . 2009-07-18 23:26 ——– d—–w- c:\program files\Common Files\Nullsoft
2009-07-18 21:41 . 2009-07-18 21:41 73728 —-a-w- c:\windows\ALCFDRTM.EXE
2009-07-18 21:36 . 2009-07-18 23:29 ——– d—–w- c:\program files\BigFix
2009-07-18 20:35 . 2009-07-18 20:35 49152 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\NewShortcut3_15377C3E9655400FB441E69F0A6BEAFE.EXE
2009-07-18 20:35 . 2009-07-18 20:35 45056 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\NewShortcut2_15377C3E9655400FB441E69F0A6BEAFE.EXE
2009-07-18 20:35 . 2009-07-18 20:35 45056 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\NewShortcut1_15377C3E9655400FB441E69F0A6BEAFE.exe
2009-07-18 20:35 . 2009-07-18 20:35 10134 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\ARPPRODUCTICON.exe
2009-07-18 20:35 . 2009-07-18 20:35 ——– d—–w- c:\program files\Napster
2009-07-18 20:35 . 2009-07-18 20:35 ——– d—–w- c:\program files\Common Files\Roxio Shared
2009-07-18 20:35 . 2009-07-18 20:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Napster
2009-07-18 20:35 . 2009-07-18 23:21 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-03 17:09 . 2005-04-13 16:56 915456 ——w- c:\windows\system32\wininet.dll
2009-06-16 14:36 . 2005-04-13 16:56 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-04-13 16:55 81920 —-a-w- c:\windows\system32\fontsub.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\program files\gbmgtn —-


—- Directory of c:\program files\raogih —-



((((((((((((((((((((((((((((( SnapShot@2009-09-01_17.13.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-02 17:48 . 2009-09-02 17:49 16384 c:\windows\temp\Perflib_Perfdata_fc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-19 39408]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 52\axcmd.exe" [2009-04-24 203416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 148888]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-07-18 98304]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Mixersel"="c:\program files\Realtek\InstallShield\mixersel.exe" [2003-11-11 369664]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-19 122368]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-28 61440]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-03-09 966656]
"CHotkey"="zHotkey.exe" - c:\windows\zHotkey.exe [2004-05-18 543232]
"ShowWnd"="ShowWnd.exe" - c:\windows\ShowWnd.exe [2003-09-19 36864]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-08-13 61952]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-10-21 77824]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2004-10-22 2744832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2009-7-26 1073152]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\if50ndrw.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-02 13:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2828)
c:\windows\system32\WININET.dll
c:\program files\Google\Quick Search Box\bin\1.2.1137.3514\qsb.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-09-02 13:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-02 17:54
ComboFix2.txt 2009-09-01 17:19

Pre-Run: 96,009,400,320 bytes free
Post-Run: 95,935,930,368 bytes free

208 — E O F — 2009-07-29 07:00
Hi Orod,

If ComboFix asks me if it's alright to update itself, should I answer "Yes"?

Yes. If we use it again we'll get a new copy first.

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



I'd like to have a look with a different scanner.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop

Please post back with
  • MBAM log
  • GMER log
  • new DDS log taken after all other steps

Thanks
Looks like MalwareBytes didn't detect anything this time. I also haven't noticed anymore strange behavior from my web browser. Here are all of the reports:


Malwarebytes' Anti-Malware 1.40
Database version: 2735
Windows 5.1.2600 Service Pack 3

9/3/2009 12:43:06 PM
mbam-log-2009-09-03 (12-43-06).txt

Scan type: Quick Scan
Objects scanned: 97866
Time elapsed: 4 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



GMER 1.0.15.15077 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-09-03 16:43:13
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT spnx.sys ZwCreateKey [0xB9EA70E0]
SSDT spnx.sys ZwEnumerateKey [0xB9EC5DA4]
SSDT spnx.sys ZwEnumerateValueKey [0xB9EC6132]
SSDT spnx.sys ZwOpenKey [0xB9EA70C0]
SSDT spnx.sys ZwQueryKey [0xB9EC620A]
SSDT spnx.sys ZwQueryValueKey [0xB9EC608A]
SSDT spnx.sys ZwSetValueKey [0xB9EC629C]

INT 0x62 ? 8A0D9BF8
INT 0x63 ? 89E9CBF8
INT 0x83 ? 89E9CBF8
INT 0xA4 ? 89E9CBF8
INT 0xB4 ? 8A0D9BF8
INT 0xB4 ? 8A0D9BF8
INT 0xB4 ? 89E9CBF8
INT 0xB4 ? 8A0D9BF8

—- Kernel code sections - GMER 1.0.15 —-

? spnx.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B900C8AC 5 Bytes JMP 89E9C1D8
.text amzstjjt.SYS B8D61386 35 Bytes [00, 00, 00, 00, 00, 00, 20, …]
.text amzstjjt.SYS B8D613AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text amzstjjt.SYS B8D613C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text amzstjjt.SYS B8D613C9 1 Byte [2E]
.text amzstjjt.SYS B8D613C9 11 Bytes [2E, 00, 00, 00, 5A, 02, 00, …]
.text …

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EA8042] spnx.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EA813E] spnx.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EA80C0] spnx.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EA8800] spnx.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EA86D6] spnx.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EB7E9C] spnx.sys
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!KfAcquireSpinLock] CCCCCCC3
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!READ_PORT_UCHAR] CCCCCCCC
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!KeGetCurrentIrql] CCCCCCCC
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!KfRaiseIrql] CCCCCCCC
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!KfLowerIrql] 8BEC8B55
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!HalGetInterruptVector] 00C73445
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!HalTranslateBusAddress] 00000000
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!KeStallExecutionProcessor] 830C458B
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!KfReleaseSpinLock] C0840CEC
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 053C0D74
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!READ_PORT_USHORT] 57B80974
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 8B000000
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[HAL.dll!WRITE_PORT_UCHAR] 56C35DE5
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[WMILIB.SYS!WmiSystemControl] 8D51FC4D
IAT \SystemRoot\System32\Drivers\amzstjjt.SYS[WMILIB.SYS!WmiCompleteRequest] 8D52FD55

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8A05A1F8
Device \FileSystem\Fastfat \FatCdrom 8905A500
Device \Driver\sptd \Device\3119188924 spnx.sys
Device \Driver\usbuhci \Device\USBPDO-0 89D5A1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A0DA1F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A0DA1F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A0DA1F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A0DA1F8
Device \Driver\usbuhci \Device\USBPDO-1 89D5A1F8
Device \Driver\usbuhci \Device\USBPDO-2 89D5A1F8
Device \Driver\usbuhci \Device\USBPDO-3 89D5A1F8
Device \Driver\usbehci \Device\USBPDO-4 89E861F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A06C1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FA35A0C4-9094-4AD6-B4B7-DF5E341BE331} 891881F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A06C1F8
Device \Driver\Cdrom \Device\CdRom0 89D271F8
Device \Driver\Cdrom \Device\CdRom1 89D271F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 8A06C1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{12DB622A-E1B1-4A98-B8CB-9089D2A9DE17} 891881F8
Device \Driver\PCI_PNP8924 \Device\00000069 spnx.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export 891881F8
Device \Driver\USBSTOR \Device\00000091 891661F8
Device \Driver\NetBT \Device\NetbiosSmb 891881F8
Device \Driver\USBSTOR \Device\00000094 891661F8
Device \Driver\USBSTOR \Device\00000095 891661F8
Device \Driver\USBSTOR \Device\00000096 891661F8
Device \Driver\USBSTOR \Device\00000097 891661F8
Device \Driver\usbuhci \Device\USBFDO-0 89D5A1F8
Device \Driver\usbuhci \Device\USBFDO-1 89D5A1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 891771F8
Device \Driver\usbuhci \Device\USBFDO-2 89D5A1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 891771F8
Device \Driver\usbuhci \Device\USBFDO-3 89D5A1F8
Device \Driver\usbehci \Device\USBFDO-4 89E861F8
Device \Driver\Ftdisk \Device\FtControl 8A06C1F8
Device \Driver\amzstjjt \Device\Scsi\amzstjjt1Port3Path0Target0Lun0 89D2B1F8
Device \Driver\amzstjjt \Device\Scsi\amzstjjt1 89D2B1F8
Device \FileSystem\Fastfat \Fat 8905A500
Device \FileSystem\Cdfs \Cdfs 89E7D500

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCA 0xC8 0xD2 0xEE …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0E 0x4E 0x01 0x35 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1E 0x63 0x16 0x8B …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCA 0xC8 0xD2 0xEE …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0E 0x4E 0x01 0x35 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1E 0x63 0x16 0x8B …

—- EOF - GMER 1.0.15 —-


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:47:26.10 on Thu 09/03/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1492 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 52\axcmd.exe" /automount
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [CHotkey] zHotkey.exe
mRun: [ShowWnd] ShowWnd.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
mRun: [Mixersel] c:\program files\realtek\installshield\mixersel.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
IE: Download Link Using Mega Manager… - c:\program files\megaupload\mega manager\mm_file.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} - hxxp://support.gateway.com/support/serialharvest/gwCID.CAB
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\if50ndrw.default\
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-09-03 12:30 0 a——- c:\windows\ativpsrm.bin
2009-09-03 03:06 –d—– c:\windows\system32\XPSViewer
2009-09-03 03:05 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2009-09-03 03:05 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-09-03 03:05 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2009-09-03 03:05 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-09-03 03:05 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-09-03 03:05 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-09-03 03:05 117,760 ——– c:\windows\system32\prntvpt.dll
2009-09-02 13:57 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx
2009-09-02 13:57 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll
2009-09-01 13:17 -cd—– c:\windows\system32\dllcache\cache
2009-09-01 13:04 a-dshr– C:\cmdcons
2009-09-01 13:02 229,376 a——- c:\windows\PEV.exe
2009-09-01 13:02 161,792 a——- c:\windows\SWREG.exe
2009-09-01 13:02 98,816 a——- c:\windows\sed.exe
2009-08-28 14:27 –d—– c:\program files\Trend Micro
2009-08-25 01:48 –d—– c:\program files\EcoleSoftware
2009-08-25 01:41 –d—– c:\program files\Alcohol Soft
2009-08-25 01:03 –d—– c:\program files\DAEMON Tools Pro
2009-08-25 01:03 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Pro
2009-08-25 01:00 722,416 a——- c:\windows\system32\drivers\sptd.sys
2009-08-25 01:00 –d—– c:\docume~1\owner\applic~1\DAEMON Tools Pro
2009-08-24 23:52 50 a——- c:\windows\MegaManager.INI
2009-08-24 23:49 –d—– c:\docume~1\owner\applic~1\Megaupload
2009-08-24 23:46 –d—– c:\program files\Megaupload
2009-08-22 04:43 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 04:43 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-22 04:43 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-22 04:29 –d—– c:\program files\gbmgtn
2009-08-14 21:03 54,156 a—h— c:\windows\QTFont.qfn
2009-08-14 21:03 1,409 a——- c:\windows\QTFont.for
2009-08-05 23:15 –d—– c:\program files\Belarc
2009-08-05 05:01 204,800 -c—— c:\windows\system32\dllcache\mswebdvd.dll
2009-08-05 01:07 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2009-08-05 01:06 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-05 00:35 –d—– c:\program files\raogih

==================== Find3M ====================

2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-25 12:15 410,984 a——- c:\windows\system32\deploytk.dll
2009-07-19 00:51 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-18 19:26 8,552 a——- c:\windows\system32\drivers\asctrm.sys
2009-07-18 17:41 73,728 a——- c:\windows\ALCFDRTM.EXE
2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-03 13:09 915,456 ——– c:\windows\system32\wininet.dll
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll

============= FINISH: 16:47:36.89 ===============
Hi Orod,

That's good.

It's imperative you install a resident antivirus program now. Without one we will be battling uphill. MBAM is not an antivirus pogram.

You can get a free one from any one of these vendors. Choose only one.

Avast
Help and support can be found here Avast Forum
AVG
Help and support can be found here AVG Forum
Antivir PersonalEditionClassic
Help and support can be found here Avira Personal Support Forum



For some reason, the service/driver section is not showing in your logs. It's important we see what's in this section of your computer. We have a couple of folders to remove so we'll use another tool to see if the sections will show in it.


Any problem such as a blank page in ADD/remove Programs or a blank page if you

Click the start button, open Help and Support Center

or

click Start, open Control Panel, double click User Accounts

Next

Download OTListIt2 to your desktop.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Files
c:\program files\gbmgtn
c:\program files\raogih

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer

After your computer has restarted,
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the Extra Registry section, change the setting to None
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window. OTL.Txt

Please post back with
  • OTL fix log
  • OTL.txt

Thanks
I decided to go with AVG.

Here is the output you asked for:


All processes killed
========== FILES ==========
c:\program files\gbmgtn moved successfully.
c:\program files\raogih moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49286 bytes

User: LocalService
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Owner
->Temp folder emptied: 172429473 bytes
->Temporary Internet Files folder emptied: 2986594 bytes
->Java cache emptied: 25742903 bytes
->FireFox cache emptied: 103713384 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 14944088 bytes
RecycleBin emptied: 10184 bytes

Total Files Cleaned = 305.20 mb


OTL by OldTimer - Version 3.0.10.7 log created on 09042009_002357

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


OTL logfile created on: 9/4/2009 12:33:08 AM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 75.23% Memory free
3.84 Gb Paging File | 3.43 Gb Available in Paging File | 89.11% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.64 Gb Total Space | 88.93 Gb Free Space | 38.90% Space Free | Partition Type: NTFS
Drive D: | 232.88 Gb Total Space | 232.14 Gb Free Space | 99.68% Space Free | Partition Type: NTFS
Drive E: | 4.23 Gb Total Space | 0.99 Gb Free Space | 23.33% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LOWRIDER
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Media Reader\shwiconem.exe (Alcor Micro, Corp.)
PRC - C:\WINDOWS\zHotkey.exe ()
PRC - C:\WINDOWS\eHome\ehmsas.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\WiFiConnector\NintendoWFCReg.exe ()
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe (ATI Technologies Inc.)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PrismXL [Auto | Running]) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (UMWdf [On_Demand | Stopped]) – C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ATIAVPCI [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\atinavxx.sys (ATI Technologies Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Cdr4_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k [System | Running]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (CmdIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (HdAudAddService [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\HdAudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\System32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MPE [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (mraid35x [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (mxnic [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\mxnic.sys (Macronix International Co., Ltd. )
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RT25USBAP [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\rt25usbap.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SunkFilt [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\sunkfilt.sys (Alcor Micro Corp.)
DRV - (symc810 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {40a1f5d7-afc2-498f-b264-02668d616ff6}:1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: avg@igeared:2.507.024.001
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p="


FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/25 12:15:51 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/09/04 00:14:23 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/09/04 00:14:38 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/05 01:25:17 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/05 01:25:16 | 00,000,000 | —D | M]

[2009/07/19 01:29:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2009/07/19 01:29:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/09/02 01:32:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\if50ndrw.default\extensions
[2009/08/24 23:50:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\if50ndrw.default\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}
[2009/09/03 23:58:48 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/05 01:25:09 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/25 12:16:03 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/09/03 23:58:48 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/08/05 01:25:09 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/05 01:25:09 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/25 05:23:01 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/08/05 01:25:14 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/09/10 15:56:44 | 00,144,960 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2008/09/10 15:37:54 | 00,094,208 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2009/07/15 14:10:00 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/15 14:10:00 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/09/04 00:18:35 | 00,001,497 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg_igeared.xml
[2009/07/15 14:10:00 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/15 14:10:00 | 00,002,344 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/07/15 14:10:00 | 00,002,371 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/15 14:10:00 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Mixersel] C:\Program Files\Realtek\InstallShield\mixersel.exe ()
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [ShowWnd] C:\WINDOWS\ShowWnd.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe (Alcor Micro, Corp.)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/13 13:20:25 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/06/15 10:18:59 | 00,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/09/04 00:31:01 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\first
[2009/09/04 00:28:40 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2009/09/04 00:23:57 | 00,000,000 | —D | C] – C:\_OTL
[2009/09/04 00:18:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\AVG Security Toolbar
[2009/09/04 00:15:04 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/09/04 00:15:04 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/09/04 00:15:04 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/09/04 00:14:58 | 00,335,240 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/09/04 00:14:57 | 00,027,784 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/09/04 00:14:44 | 40,589,153 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/09/04 00:14:42 | 00,076,683 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/09/04 00:14:41 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/09/04 00:14:39 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/09/04 00:14:39 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/09/04 00:14:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/09/04 00:14:23 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/09/04 00:14:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/09/04 00:04:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG8
[2009/09/04 00:03:40 | 00,848,712 | —- | C] (AVG Technologies) – C:\Documents and Settings\Owner\Desktop\avg_free_stb_all_8_32_cnet.exe
[2009/09/03 23:58:47 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/09/03 23:58:47 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/09/03 23:58:47 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/09/03 23:58:33 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/09/03 16:46:27 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/09/03 12:49:56 | 00,288,768 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2009/09/03 12:46:42 | 00,280,282 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2009/09/03 12:30:10 | 00,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2009/09/03 03:05:44 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/09/03 03:05:44 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/09/03 03:05:44 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/09/03 03:05:44 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/09/03 03:05:44 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/09/03 03:05:44 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/09/03 03:05:44 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/09/03 03:00:41 | 24,281,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/09/02 13:57:44 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/09/02 13:57:36 | 01,315,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msoe.dll
[2009/09/02 13:47:18 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/09/01 13:17:55 | 01,614,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/09/01 13:17:55 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/09/01 13:17:55 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/09/01 13:17:55 | 00,574,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntfs.sys
[2009/09/01 13:17:55 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/09/01 13:17:55 | 00,409,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\qmgr.dll
[2009/09/01 13:17:55 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netlogon.dll
[2009/09/01 13:17:55 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/09/01 13:17:55 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\es.dll
[2009/09/01 13:17:55 | 00,249,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tapisrv.dll
[2009/09/01 13:17:55 | 00,245,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mswsock.dll
[2009/09/01 13:17:55 | 00,198,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netman.dll
[2009/09/01 13:17:55 | 00,192,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\schedsvc.dll
[2009/09/01 13:17:55 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\upnphost.dll
[2009/09/01 13:17:55 | 00,181,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\scecli.dll
[2009/09/01 13:17:55 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\srsvc.dll
[2009/09/01 13:17:55 | 00,167,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\appmgmts.dll
[2009/09/01 13:17:55 | 00,142,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\aec.sys
[2009/09/01 13:17:55 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\shsvcs.dll
[2009/09/01 13:17:55 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\xmlprov.dll
[2009/09/01 13:17:55 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/09/01 13:17:55 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\browser.dll
[2009/09/01 13:17:55 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ssdpsrv.dll
[2009/09/01 13:17:55 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\cryptsvc.dll
[2009/09/01 13:17:55 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\regsvc.dll
[2009/09/01 13:17:55 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\eventlog.dll
[2009/09/01 13:17:55 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/09/01 13:17:55 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mspmsnsv.dll
[2009/09/01 13:17:55 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/09/01 13:17:55 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\linkinfo.dll
[2009/09/01 13:17:55 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\asyncmac.sys
[2009/09/01 13:17:55 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wscntfy.exe
[2009/09/01 13:17:55 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/09/01 13:17:55 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/09/01 13:17:55 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/09/01 13:17:55 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/09/01 13:17:54 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mshtml.dll
[2009/09/01 13:17:54 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/09/01 13:17:54 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/09/01 13:17:54 | 01,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/09/01 13:17:54 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/09/01 13:17:54 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/09/01 13:17:54 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/09/01 13:17:54 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/09/01 13:17:54 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/09/01 13:17:54 | 00,361,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/09/01 13:17:54 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/09/01 13:17:54 | 00,182,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/09/01 13:17:54 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/09/01 13:17:54 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/09/01 13:17:54 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/09/01 13:17:54 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/09/01 13:17:54 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/09/01 13:17:54 | 00,036,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/09/01 13:17:54 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/09/01 13:17:54 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/09/01 13:17:54 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/09/01 13:17:54 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/09/01 13:17:54 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/09/01 13:17:54 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/09/01 13:17:54 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/09/01 13:04:45 | 00,000,209 | —- | C] () – C:\Boot.bak
[2009/09/01 13:04:40 | 00,260,272 | —- | C] () – C:\cmldr
[2009/09/01 13:04:34 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/09/01 13:02:31 | 00,229,376 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/09/01 13:02:31 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/09/01 13:02:31 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/09/01 13:02:31 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/09/01 13:02:31 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/09/01 13:02:31 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/09/01 13:02:31 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/09/01 13:02:31 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/09/01 13:02:19 | 00,000,000 | —D | C] – C:\Qoobox
[2009/09/01 12:55:49 | 03,189,102 | R— | C] () – C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe
[2009/08/31 15:45:04 | 00,000,000 | —- | C] () – C:\Documents and Settings\Owner\Desktop\settings.dat
[2009/08/31 15:38:39 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/31 15:37:05 | 00,000,611 | —- | C] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2009/08/31 15:37:05 | 00,000,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2009/08/31 15:37:04 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/08/31 15:31:40 | 00,472,064 | —- | C] ( ) – C:\Documents and Settings\Owner\Desktop\rootrepeal.exe
[2009/08/31 15:31:17 | 00,359,929 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2009/08/31 15:29:54 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2009/08/31 15:09:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SampleView
[2009/08/31 13:29:08 | 26,171,928 | —- | C] (PC Tools ) – C:\Documents and Settings\Owner\Desktop\sdsetup.exe
[2009/08/29 13:45:35 | 03,550,592 | —- | C] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\Owner\Desktop\procexp.exe
[2009/08/29 13:35:56 | 00,000,000 | —D | C] – C:\WINDOWS\Sun
[2009/08/28 23:53:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Identities
[2009/08/28 14:27:45 | 00,001,734 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/08/28 14:27:45 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/08/28 14:25:45 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HJTInstall.exe
[2009/08/25 18:23:39 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Downloads
[2009/08/25 17:19:28 | 00,001,027 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Perfect Cherry Blossom.lnk
[2009/08/25 17:05:53 | 00,001,221 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Phantasmagoria of Flower View.lnk
[2009/08/25 16:48:11 | 00,001,059 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Imperishable Night.lnk
[2009/08/25 16:22:59 | 00,000,979 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Glove on Fight.lnk
[2009/08/25 16:06:24 | 00,001,311 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Queen of Heart 2001 - Party's Breaker.lnk
[2009/08/25 15:40:14 | 00,001,391 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Embodiment of Scarlet Devil.lnk
[2009/08/25 15:31:43 | 00,000,803 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Doukutsu Monogatari.lnk
[2009/08/25 15:18:34 | 00,001,140 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Valkyrie Fight Tag.lnk
[2009/08/25 14:58:46 | 00,000,719 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Melty Blood Act Cadenza Version B.lnk
[2009/08/25 01:48:29 | 00,000,000 | —D | C] – C:\Program Files\EcoleSoftware
[2009/08/25 01:41:05 | 00,000,826 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Alcohol 52%.lnk
[2009/08/25 01:41:04 | 00,000,000 | —D | C] – C:\Program Files\Alcohol Soft
[2009/08/25 01:03:58 | 00,000,000 | —D | C] – C:\Program Files\DAEMON Tools Pro
[2009/08/25 01:03:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2009/08/25 01:00:35 | 00,722,416 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/08/25 01:00:25 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\DAEMON Tools Pro
[2009/08/25 00:38:38 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\WinRAR
[2009/08/25 00:37:54 | 00,000,000 | —D | C] – C:\Program Files\WinRAR
[2009/08/25 00:23:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\My Downloads
[2009/08/24 23:52:20 | 00,000,050 | —- | C] () – C:\WINDOWS\MegaManager.INI
[2009/08/24 23:49:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Megaupload
[2009/08/24 23:47:31 | 00,001,668 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mega Manager.lnk
[2009/08/24 23:46:08 | 00,000,000 | —D | C] – C:\Program Files\Megaupload
[2009/08/22 04:43:11 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/22 04:43:09 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/22 04:43:07 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/22 04:43:07 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/20 02:02:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Roms
[2009/08/14 21:03:45 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/08/14 21:03:45 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/08/14 20:55:58 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2009/08/08 00:31:07 | 00,002,007 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Fall from Heaven 2.lnk
[2009/08/05 23:15:08 | 00,000,000 | —D | C] – C:\Program Files\Belarc
[2009/08/05 05:01:48 | 00,204,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/05 01:07:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/08/05 01:06:47 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/07/29 23:56:29 | 00,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2009/07/20 23:37:39 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/07/19 01:43:59 | 00,168,448 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/07/19 01:43:59 | 00,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/07/19 01:43:57 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/07/19 01:43:57 | 02,402,304 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2009/07/19 01:43:57 | 00,881,664 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/07/19 01:43:57 | 00,205,824 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/07/19 01:43:55 | 00,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/07/19 01:43:55 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/07/19 00:39:13 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/07/18 19:33:01 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/07/18 19:29:05 | 00,198,144 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/07/18 19:03:09 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2009/07/18 16:37:29 | 00,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2009/07/18 16:35:20 | 00,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2009/07/18 16:35:20 | 00,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2005/04/13 15:02:03 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/04/13 12:57:05 | 00,001,218 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/04/13 12:57:05 | 00,000,468 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2005/04/13 12:56:11 | 00,000,598 | —- | C] () – C:\WINDOWS\win.ini
[2005/04/13 12:56:08 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/01/07 18:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Files - Modified Within 30 Days ==========

[2009/09/04 00:26:26 | 00,000,431 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/09/04 00:25:53 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/09/04 00:25:49 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/09/04 00:25:44 | 21,452,14464 | -HS- | M] () – C:\hiberfil.sys
[2009/09/04 00:15:04 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/09/04 00:15:04 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/09/04 00:15:04 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/09/04 00:14:58 | 00,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/09/04 00:14:57 | 40,589,153 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/09/04 00:14:57 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/09/04 00:14:44 | 00,076,683 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/09/04 00:14:42 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/09/04 00:14:41 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/09/04 00:03:40 | 00,848,712 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner\Desktop\avg_free_stb_all_8_32_cnet.exe
[2009/09/03 23:58:34 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/09/03 12:46:44 | 00,280,282 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2009/09/03 12:30:10 | 00,000,000 | —- | M] () – C:\WINDOWS\ativpsrm.bin
[2009/09/03 03:05:04 | 00,456,194 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/09/03 03:05:04 | 00,405,828 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/09/03 03:05:04 | 00,063,280 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/09/03 03:02:19 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/09/02 13:49:13 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/09/02 13:48:46 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/09/02 00:04:03 | 00,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/09/01 17:59:39 | 00,001,391 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Embodiment of Scarlet Devil.lnk
[2009/09/01 13:04:45 | 00,000,279 | RHS- | M] () – C:\boot.ini
[2009/09/01 12:56:03 | 03,189,102 | R— | M] () – C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe
[2009/09/01 12:55:38 | 00,000,050 | —- | M] () – C:\WINDOWS\MegaManager.INI
[2009/08/31 15:45:04 | 00,000,000 | —- | M] () – C:\Documents and Settings\Owner\Desktop\settings.dat
[2009/08/31 15:37:05 | 00,000,611 | —- | M] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2009/08/31 15:37:05 | 00,000,592 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2009/08/31 15:31:42 | 00,472,064 | —- | M] ( ) – C:\Documents and Settings\Owner\Desktop\rootrepeal.exe
[2009/08/31 15:31:17 | 00,359,929 | —- | M] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2009/08/31 15:29:58 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2009/08/31 13:30:46 | 26,171,928 | —- | M] (PC Tools ) – C:\Documents and Settings\Owner\Desktop\sdsetup.exe
[2009/08/30 02:52:11 | 00,016,384 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/29 13:45:45 | 03,550,592 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\Owner\Desktop\procexp.exe
[2009/08/28 14:27:45 | 00,001,734 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/08/28 14:25:46 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HJTInstall.exe
[2009/08/27 00:39:58 | 00,001,622 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Trillian.lnk
[2009/08/26 04:51:20 | 02,651,270 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/08/25 17:19:28 | 00,001,027 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Perfect Cherry Blossom.lnk
[2009/08/25 17:05:53 | 00,001,221 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Phantasmagoria of Flower View.lnk
[2009/08/25 16:48:11 | 00,001,059 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Imperishable Night.lnk
[2009/08/25 16:43:36 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/25 16:22:59 | 00,000,979 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Glove on Fight.lnk
[2009/08/25 16:06:24 | 00,001,311 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Queen of Heart 2001 - Party's Breaker.lnk
[2009/08/25 15:31:43 | 00,000,803 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Doukutsu Monogatari.lnk
[2009/08/25 15:18:34 | 00,001,140 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Valkyrie Fight Tag.lnk
[2009/08/25 14:58:46 | 00,000,719 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Melty Blood Act Cadenza Version B.lnk
[2009/08/25 01:41:05 | 00,000,826 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Alcohol 52%.lnk
[2009/08/25 01:00:36 | 00,722,416 | —- | M] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/08/24 23:47:31 | 00,001,668 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mega Manager.lnk
[2009/08/23 03:09:13 | 00,229,376 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/22 04:43:11 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/21 00:57:07 | 00,073,728 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\ALCFDRTM.VER
[2009/08/17 10:36:30 | 00,288,768 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2009/08/14 21:03:45 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/08/08 00:33:48 | 00,002,007 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Fall from Heaven 2.lnk
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mswebdvd.dll
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/05 01:17:24 | 00,011,168 | -H– | M] () – C:\WINDOWS\System32\deniwefe

========== LOP Check ==========

[2009/09/04 00:14:38 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/07/30 00:16:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI
[2009/09/04 00:17:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/07/20 00:34:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/08/25 01:03:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2009/07/18 16:35:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/07/18 19:18:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prism Deploy
[2009/07/18 19:28:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2009/07/18 19:28:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/04 00:04:54 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2009/07/30 00:16:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ATI
[2009/09/02 04:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2009/08/25 01:00:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DAEMON Tools Pro
[2009/08/24 23:49:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Megaupload
[2009/07/28 02:57:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\My Games
[2009/08/31 15:09:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2004/08/10 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/09/04 00:25:53 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


< End of report >
Hi Orod,

I decided to go with AVG.

:thumbup:

Looks better all the time. One more scan just to be sure nothing is lurking in the background.

First we'll remove some old vulnerable java.

Open Control Panel > Add/Remove Programs and uninstall

J2SE Runtime Environment 5.0 Update 2

Do not uninstall Java TM 6 Update 13 if found! :yeah:



Next, open Control panel again.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.


Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK


    *Note
    It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
    Please don't go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



    Please go to Kaspersky website and perform an online antivirus scan.
    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions.
    • You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
      • Spyware, Adware, Dialers, and other potentially dangerous programs
      • Archives
      • Mail databases
    • Click on My Computerr under Scan.
    • Once the scan is complete, it will display the results. Click on View Scan Report.
    • You will see a list of infected items there. Click on Save Report As….
    • Change the Files of type to Text file (.txt)
    • Set the Save In to Desktop
    • click the Save button.
    • Please post this log in your next reply along with a new DDS log.
    Thanks
Hi oldman, I was able to complete the Kaspersky scan. However, after I clicked on the button to save the log file, the window for me to save the file never popped up and the button could not be pressed again. I scanned again and was still unable to save the log file to my desktop. I deactivated AVG, followed all the instructions, and didn't use my computer for anything else while it scanned so I'm not sure what the problem was. I also waited about ten minutes after I hit the save button to make sure that it wasn't just taking a long time to generate a log file I could save. I was using Firefox. Should I try to scan with Kaspersky using a different browser? The scan appeared to come out clean though; no infections were found. Here is the most recent DDS output: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:08:16.35 on Fri 09/04/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1476 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\Ati2evxx.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Digital Media Reader\shwiconem.exe C:\WINDOWS\zHotkey.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\WiFiConnector\NintendoWFCReg.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 52\axcmd.exe" /automount uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [CHotkey] zHotkey.exe mRun: [ShowWnd] ShowWnd.exe mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe mRun: [Mixersel] c:\program files\realtek\installshield\mixersel.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [AlcWzrd] ALCWZRD.EXE mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe IE: Download Link Using Mega Manager… - c:\program files\megaupload\mega manager\mm_file.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} - hxxp://support.gateway.com/support/serialharvest/gwCID.CAB DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\if50ndrw.default\ FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p= FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-9-4 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-9-4 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-9-4 108552] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-9-4 297752] =============== Created Last 30 ================ 2009-09-04 06:07 –d-h— C:\$AVG8.VAULT$ 2009-09-04 02:23 –d—– c:\windows\system32\XPSViewer 2009-09-04 00:23 –d—– C:\_OTL 2009-09-04 00:15 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-09-04 00:15 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-09-04 00:14 335,240 a——- c:\windows\system32\drivers\avgldx86.sys 2009-09-04 00:14 –d—– c:\windows\system32\drivers\Avg 2009-09-04 00:14 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar 2009-09-04 00:14 –d—– c:\program files\AVG 2009-09-04 00:14 –d—– c:\docume~1\alluse~1\applic~1\avg8 2009-09-04 00:04 –d—– c:\docume~1\owner\applic~1\AVG8 2009-09-03 12:30 0 a——- c:\windows\ativpsrm.bin 2009-09-03 03:05 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-09-03 03:05 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-09-03 03:05 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-09-03 03:05 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-09-03 03:05 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-09-03 03:05 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-09-03 03:05 117,760 ——– c:\windows\system32\prntvpt.dll 2009-09-02 13:57 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx 2009-09-02 13:57 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll 2009-09-01 13:17 -cd—– c:\windows\system32\dllcache\cache 2009-09-01 13:04 a-dshr– C:\cmdcons 2009-09-01 13:02 229,376 a——- c:\windows\PEV.exe 2009-09-01 13:02 161,792 a——- c:\windows\SWREG.exe 2009-09-01 13:02 98,816 a——- c:\windows\sed.exe 2009-08-28 14:27 –d—– c:\program files\Trend Micro 2009-08-25 01:48 –d—– c:\program files\EcoleSoftware 2009-08-25 01:41 –d—– c:\program files\Alcohol Soft 2009-08-25 01:03 –d—– c:\program files\DAEMON Tools Pro 2009-08-25 01:03 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Pro 2009-08-25 01:00 722,416 a——- c:\windows\system32\drivers\sptd.sys 2009-08-25 01:00 –d—– c:\docume~1\owner\applic~1\DAEMON Tools Pro 2009-08-24 23:52 50 a——- c:\windows\MegaManager.INI 2009-08-24 23:49 –d—– c:\docume~1\owner\applic~1\Megaupload 2009-08-24 23:46 –d—– c:\program files\Megaupload 2009-08-22 04:43 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-22 04:43 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-22 04:43 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-14 21:03 54,156 a—h— c:\windows\QTFont.qfn 2009-08-14 21:03 1,409 a——- c:\windows\QTFont.for 2009-08-05 23:15 –d—– c:\program files\Belarc ==================== Find3M ==================== 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll 2009-07-19 00:51 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-07-18 19:26 8,552 a——- c:\windows\system32\drivers\asctrm.sys 2009-07-18 17:41 73,728 a——- c:\windows\ALCFDRTM.EXE 2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll 2009-07-03 13:09 915,456 ——– c:\windows\system32\wininet.dll 2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-12 08:31 80,896 a——- c:\windows\system32\tlntsess.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll ============= FINISH: 19:08:57.65 ===============
Hi Orod,

no infections were found.

If you are certain that the Kaspersky log was clean then there isn't any need to repeat it. The DDS log looks good.

Any problems? If not we can clean up the tools we used.

From your desktop, please delete
  • any notepads/logs that we created
  • gmer.exe
  • gmer.zip
  • DDS.scr

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u

Open OTListIt2 then click the Clean Up button. You may get prompted by your firewall that OTListIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep MBAM updated and use it regularly.

Updates and upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.0 first. Be sure to move any PDF documents to another folder first though.

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have a antivrus program and an on demand antispyware program (MBAM).

I recommend you use an antispyware program with resident (real time) scanning. I suggest

Winpatrol
OR
Windows Defender


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI