This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Adware tracking cookie

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
Looks like some changes have been made in this forum. I could not find the hijackthis topic and I'm going to just post my thread here. I need some help to remove these two tough spyware: [removed][2].txt and other@atdmt[2].txt. I've tried on my own with everything–adaware, spybot, superantispyware, malwarebyte, avast…–I got and nothing works so far. those spyware just keep on coming back. Thanks very much again and here is the hijackthis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:26:07 AM, on 9/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\IcbcDaemon.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\reliz\akeys.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Startup Faster 2004\sfAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\pkext.dll
O2 - BHO: Öйú¹¤ÉÌÒøÐÐBHO - {BB4491A2-D11A-4c6b-91C0-B53246A3122B} - C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\Icbc_AntiPhishing.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: IncrediBar - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: AbsoluteShield - {EE9DD090-902D-4623-9360-FB7D8666202B} - C:\Program Files\SysShield Tools\Internet Eraser\AbsoluteBar.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [StartupFaster] "C:\Program Files\Startup Faster 2004\StrpFstCfg.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: StartupFaster
O4 - Global Startup: StartupFaster
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~2\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Answers… - file:C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Logoff - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComLogoff.html
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IncrediBar - {023FA804-DCE1-4817-94ED-6BA4200F9AF2} - C:\Program Files\IncrediBar\bin\IBTBar.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0D99625B-0619-4420-BB61-82DEE1B91D3A} (BlockHouse Class) - https://ebank.gdb.com.cn/perbank/js/CertKitAx.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://johnzheng2356.spaces.live.com//Phot…ad/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y…ctl_0_0_0_1.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222675051475
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/newperbank/…afeControls.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D81CA86B-EF63-42AF-BEE3-4502D9A03C2D} (MMRadioHostX Class) - http://wwws.musicmatch.com/graphics/WebPlayer/MMLRadio.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: mbox - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mboxflash - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICBC Daemon Service - Unknown owner - C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\IcbcDaemon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

–
End of file - 16357 bytes

Here is the up to date new log, just in case. Thanks again!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:52:15 PM, on 9/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\reliz\akeys.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Startup Faster 2004\sfAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\China Mobile\Fetion\FetionFX.exe
C:\Program Files\eMule0.49c\emule.exe
C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe
C:\Program Files\SlimBrowser\sbrowser.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\pkext.dll
O2 - BHO: Öйú¹¤ÉÌÒøÐÐBHO - {BB4491A2-D11A-4c6b-91C0-B53246A3122B} - C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\Icbc_AntiPhishing.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: IncrediBar - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: AbsoluteShield - {EE9DD090-902D-4623-9360-FB7D8666202B} - C:\Program Files\SysShield Tools\Internet Eraser\AbsoluteBar.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [StartupFaster] "C:\Program Files\Startup Faster 2004\StrpFstCfg.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: StartupFaster
O4 - Global Startup: StartupFaster
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~2\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Answers… - file:C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Logoff - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComLogoff.html
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IncrediBar - {023FA804-DCE1-4817-94ED-6BA4200F9AF2} - C:\Program Files\IncrediBar\bin\IBTBar.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0D99625B-0619-4420-BB61-82DEE1B91D3A} (BlockHouse Class) - https://ebank.gdb.com.cn/perbank/js/CertKitAx.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://johnzheng2356.spaces.live.com//Phot…ad/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y…ctl_0_0_0_1.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222675051475
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/newperbank/…afeControls.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D81CA86B-EF63-42AF-BEE3-4502D9A03C2D} (MMRadioHostX Class) - http://wwws.musicmatch.com/graphics/WebPlayer/MMLRadio.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: mbox - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mboxflash - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICBC Daemon Service - Unknown owner - C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\IcbcDaemon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

–
End of file - 16618 bytes
Hi Tom_q2356,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's get some deeper information:

  • Download DDS and save it to your desktop from
  • Here
  • here or
  • here.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click DDS icon to run the tool (may take up to 3 minutes to run)
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
  • We Need to check for Rootkits with RootRepeal
    • Download RootRepeal from one of the following locations and save it to your desktop.
    • Open [external image: Posted Image] on your desktop.
    • Click the [external image: Posted Image] tab.
    • Click the [external image: Posted Image] button.
    • In the Select Scan dialog, check
      [external image: Posted Image]
    • Push Ok
    • Check the box for your main system drive (Usually C:), and press Ok.
    • Allow RootRepeal to run a scan of your system. This may take some time.
    • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
  • Copy/paste the log (that you've previously saved to your desktop) from RootRepeal onto your post.

  • Copy/paste the DDS.txt log (that you've previously saved to your desktop) onto your post.

  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/18 22:43 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: 1394BUS.SYS Image Path: C:\WINDOWS\System32\DRIVERS\1394BUS.SYS Address: 0xF7801000 Size: 57344 File Visible: - Signed: - Status: - Name: Aavmker4.SYS Image Path: C:\WINDOWS\System32\Drivers\Aavmker4.SYS Address: 0xF7AF9000 Size: 19072 File Visible: - Signed: - Status: - Name: ACPI.sys Image Path: ACPI.sys Address: 0xF7792000 Size: 187776 File Visible: - Signed: - Status: - Name: ACPI_HAL Image Path: \Driver\ACPI_HAL Address: 0x804D7000 Size: 2189056 File Visible: - Signed: - Status: - Name: ACPIEC.sys Image Path: ACPIEC.sys Address: 0xF7BFD000 Size: 11648 File Visible: - Signed: - Status: - Name: AegisP.sys Image Path: C:\WINDOWS\system32\DRIVERS\AegisP.sys Address: 0xF7BD9000 Size: 19008 File Visible: - Signed: - Status: - Name: afd.sys Image Path: C:\WINDOWS\System32\drivers\afd.sys Address: 0xEDE3A000 Size: 138496 File Visible: - Signed: - Status: - Name: agp440.sys Image Path: agp440.sys Address: 0xF7871000 Size: 42368 File Visible: - Signed: - Status: - Name: arp1394.sys Image Path: C:\WINDOWS\System32\DRIVERS\arp1394.sys Address: 0xF79E1000 Size: 60800 File Visible: - Signed: - Status: - Name: aspi32.sys Image Path: C:\WINDOWS\System32\drivers\aspi32.sys Address: 0xED8CA000 Size: 15936 File Visible: - Signed: - Status: - Name: aswFsBlk.sys Image Path: C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys Address: 0xF7B91000 Size: 32768 File Visible: - Signed: - Status: - Name: aswMon2.SYS Image Path: C:\WINDOWS\System32\Drivers\aswMon2.SYS Address: 0xED97E000 Size: 87424 File Visible: - Signed: - Status: - Name: aswRdr.sys Image Path: C:\WINDOWS\system32\drivers\aswRdr.sys Address: 0xED028000 Size: 15136 File Visible: - Signed: - Status: - Name: aswSP.SYS Image Path: C:\WINDOWS\System32\Drivers\aswSP.SYS Address: 0xEDD59000 Size: 135168 File Visible: - Signed: - Status: - Name: aswTdi.SYS Image Path: C:\WINDOWS\System32\Drivers\aswTdi.SYS Address: 0xF79C1000 Size: 41664 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: atapi.sys Address: 0xF772C000 Size: 96512 File Visible: - Signed: - Status: - Name: ati2dvag.dll Image Path: C:\WINDOWS\System32\ati2dvag.dll Address: 0xBF9D5000 Size: 241664 File Visible: - Signed: - Status: - Name: ati2mtag.sys Image Path: C:\WINDOWS\System32\DRIVERS\ati2mtag.sys Address: 0xF751E000 Size: 539392 File Visible: - Signed: - Status: - Name: ati3d1ag.dll Image Path: C:\WINDOWS\System32\ati3d1ag.dll Address: 0xBFA10000 Size: 831488 File Visible: - Signed: - Status: - Name: ATMFD.DLL Image Path: C:\WINDOWS\System32\ATMFD.DLL Address: 0xBFFA0000 Size: 286720 File Visible: - Signed: - Status: - Name: Atusbcam.sys Image Path: C:\WINDOWS\system32\DRIVERS\Atusbcam.sys Address: 0xEE081000 Size: 117984 File Visible: - Signed: - Status: - Name: audstub.sys Image Path: C:\WINDOWS\System32\DRIVERS\audstub.sys Address: 0xF7EA4000 Size: 3072 File Visible: - Signed: - Status: - Name: BATTC.SYS Image Path: C:\WINDOWS\System32\DRIVERS\BATTC.SYS Address: 0xF7BF9000 Size: 16384 File Visible: - Signed: - Status: - Name: bcm4sbxp.sys Image Path: C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys Address: 0xF78A1000 Size: 42368 File Visible: - Signed: - Status: - Name: Beep.SYS Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS Address: 0xF7CFF000 Size: 4224 File Visible: - Signed: - Status: - Name: BOOTVID.dll Image Path: C:\WINDOWS\system32\BOOTVID.dll Address: 0xF7BF1000 Size: 12288 File Visible: - Signed: - Status: - Name: Cdfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS Address: 0xF7240000 Size: 63744 File Visible: - Signed: - Status: - Name: Cdr4_xp.SYS Image Path: C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS Address: 0xF7F10000 Size: 2432 File Visible: - Signed: - Status: - Name: Cdralw2k.SYS Image Path: C:\WINDOWS\System32\Drivers\Cdralw2k.SYS Address: 0xF7F12000 Size: 2560 File Visible: - Signed: - Status: - Name: cdrom.sys Image Path: C:\WINDOWS\System32\DRIVERS\cdrom.sys Address: 0xF78E1000 Size: 62976 File Visible: - Signed: - Status: - Name: CertClient.dat Image Path: C:\WINDOWS\system32\Drivers\CertClient.dat Address: 0xF7E18000 Size: 2624 File Visible: - Signed: - Status: - Name: CLASSPNP.SYS Image Path: C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS Address: 0xF7841000 Size: 53248 File Visible: - Signed: - Status: - Name: CmBatt.sys Image Path: C:\WINDOWS\System32\DRIVERS\CmBatt.sys Address: 0xF7C95000 Size: 13952 File Visible: - Signed: - Status: - Name: CMBProtector.dat Image Path: C:\WINDOWS\system32\Drivers\CMBProtector.dat Address: 0xF7E23000 Size: 3584 File Visible: - Signed: - Status: - Name: compbatt.sys Image Path: compbatt.sys Address: 0xF7BF5000 Size: 10240 File Visible: - Signed: - Status: - Name: DefragFS.SYS Image Path: C:\WINDOWS\System32\Drivers\DefragFS.SYS Address: 0xEDBEC000 Size: 86016 File Visible: - Signed: - Status: - Name: disk.sys Image Path: disk.sys Address: 0xF7831000 Size: 36352 File Visible: - Signed: - Status: - Name: drmk.sys Image Path: C:\WINDOWS\system32\drivers\drmk.sys Address: 0xF7901000 Size: 61440 File Visible: - Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xEDD19000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7D31000 Size: 8192 File Visible: No Signed: - Status: - Name: Dxapi.sys Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys Address: 0xF7C8D000 Size: 12288 File Visible: - Signed: - Status: - Name: dxg.sys Image Path: C:\WINDOWS\System32\drivers\dxg.sys Address: 0xBF9C3000 Size: 73728 File Visible: - Signed: - Status: - Name: dxgthk.sys Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys Address: 0xF7E31000 Size: 4096 File Visible: - Signed: - Status: - Name: Fips.SYS Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS Address: 0xF7A41000 Size: 44544 File Visible: - Signed: - Status: - Name: fltmgr.sys Image Path: fltmgr.sys Address: 0xF770C000 Size: 129792 File Visible: - Signed: - Status: - Name: Fs_Rec.SYS Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS Address: 0xF7CFB000 Size: 7936 File Visible: - Signed: - Status: - Name: ftdisk.sys Image Path: ftdisk.sys Address: 0xF7744000 Size: 125056 File Visible: - Signed: - Status: - Name: GEARAspiWDM.sys Image Path: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys Address: 0xF7CAD000 Size: 9472 File Visible: - Signed: - Status: - Name: giveio.sys Image Path: giveio.sys Address: 0xF7DAC000 Size: 1664 File Visible: No Signed: - Status: - Name: hal.dll Image Path: C:\WINDOWS\system32\hal.dll Address: 0x806EE000 Size: 81152 File Visible: - Signed: - Status: - Name: HSF_CNXT.sys Image Path: C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys Address: 0xF7260000 Size: 569088 File Visible: - Signed: - Status: - Name: HSF_DP.sys Image Path: C:\WINDOWS\System32\DRIVERS\HSF_DP.sys Address: 0xF72EB000 Size: 1091936 File Visible: - Signed: - Status: - Name: HSFHWICH.sys Image Path: C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys Address: 0xF73F6000 Size: 144832 File Visible: - Signed: - Status: - Name: HTTP.sys Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys Address: 0xECA3D000 Size: 264832 File Visible: - Signed: - Status: - Name: i2omgmt.SYS Image Path: C:\WINDOWS\System32\Drivers\i2omgmt.SYS Address: 0xF7C99000 Size: 8576 File Visible: - Signed: - Status: - Name: i8042prt.sys Image Path: C:\WINDOWS\System32\DRIVERS\i8042prt.sys Address: 0xF78C1000 Size: 52480 File Visible: - Signed: - Status: - Name: imapi.sys Image Path: C:\WINDOWS\System32\DRIVERS\imapi.sys Address: 0xF78D1000 Size: 42112 File Visible: - Signed: - Status: - Name: InCDfs.SYS Image Path: C:\WINDOWS\System32\Drivers\InCDfs.SYS Address: 0xEE09E000 Size: 80800 File Visible: - Signed: - Status: - Name: InCDPass.sys Image Path: C:\WINDOWS\System32\DRIVERS\InCDPass.sys Address: 0xF7AE9000 Size: 25504 File Visible: - Signed: - Status: - Name: InCDrec.SYS Image Path: C:\WINDOWS\System32\Drivers\InCDrec.SYS Address: 0xF7D0B000 Size: 4704 File Visible: - Signed: - Status: - Name: incdrm.SYS Image Path: C:\WINDOWS\System32\Drivers\incdrm.SYS Address: 0xF7AD9000 Size: 22848 File Visible: - Signed: - Status: - Name: intelide.sys Image Path: intelide.sys Address: 0xF7CE5000 Size: 5504 File Visible: - Signed: - Status: - Name: intelppm.sys Image Path: C:\WINDOWS\System32\DRIVERS\intelppm.sys Address: 0xF7891000 Size: 36352 File Visible: - Signed: - Status: - Name: ip6fw.sys Image Path: C:\WINDOWS\system32\drivers\ip6fw.sys Address: 0xF79F1000 Size: 36608 File Visible: - Signed: - Status: - Name: ipnat.sys Image Path: C:\WINDOWS\System32\DRIVERS\ipnat.sys Address: 0xEDFEF000 Size: 152832 File Visible: - Signed: - Status: - Name: ipsec.sys Image Path: C:\WINDOWS\System32\DRIVERS\ipsec.sys Address: 0xEE06E000 Size: 75264 File Visible: - Signed: - Status: - Name: isapnp.sys Image Path: isapnp.sys Address: 0xF77E1000 Size: 37248 File Visible: - Signed: - Status: - Name: kbdclass.sys Image Path: C:\WINDOWS\System32\DRIVERS\kbdclass.sys Address: 0xF7AB1000 Size: 24576 File Visible: - Signed: - Status: - Name: KDCOM.DLL Image Path: C:\WINDOWS\system32\KDCOM.DLL Address: 0xF7CE1000 Size: 8192 File Visible: - Signed: - Status: - Name: kmixer.sys Image Path: C:\WINDOWS\system32\drivers\kmixer.sys Address: 0xEC8D2000 Size: 172416 File Visible: - Signed: - Status: - Name: ks.sys Image Path: C:\WINDOWS\System32\DRIVERS\ks.sys Address: 0xF7496000 Size: 143360 File Visible: - Signed: - Status: - Name: KSecDD.sys Image Path: KSecDD.sys Address: 0xF76E3000 Size: 92928 File Visible: - Signed: - Status: - Name: Lbd.sys Image Path: Lbd.sys Address: 0xF7851000 Size: 57472 File Visible: - Signed: - Status: - Name: LMPC2.SYS Image Path: C:\WINDOWS\System32\Drivers\LMPC2.SYS Address: 0xF7CE9000 Size: 4224 File Visible: - Signed: - Status: - Name: mbam.sys Image Path: C:\WINDOWS\system32\drivers\mbam.sys Address: 0xEDC61000 Size: 12416 File Visible: - Signed: - Status: - Name: mdc8021x.sys Image Path: C:\WINDOWS\system32\DRIVERS\mdc8021x.sys Address: 0xEDBE8000 Size: 14176 File Visible: - Signed: - Status: - Name: mdmxsdk.sys Image Path: C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys Address: 0xED80A000 Size: 8768 File Visible: - Signed: - Status: - Name: mnmdd.SYS Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS Address: 0xF7D03000 Size: 4224 File Visible: - Signed: - Status: - Name: Modem.SYS Image Path: C:\WINDOWS\System32\Drivers\Modem.SYS Address: 0xF7B19000 Size: 30080 File Visible: - Signed: - Status: - Name: motovision.sys Image Path: C:\WINDOWS\system32\DRIVERS\motovision.sys Address: 0xF7B29000 Size: 29856 File Visible: - Signed: - Status: - Name: MotoVisionDP.sys Image Path: C:\WINDOWS\system32\DRIVERS\MotoVisionDP.sys Address: 0xF7CDD000 Size: 11232 File Visible: - Signed: - Status: - Name: mouclass.sys Image Path: C:\WINDOWS\System32\DRIVERS\mouclass.sys Address: 0xF7AC1000 Size: 23040 File Visible: - Signed: - Status: - Name: MountMgr.sys Image Path: MountMgr.sys Address: 0xF7811000 Size: 42368 File Visible: - Signed: - Status: - Name: mrxdav.sys Image Path: C:\WINDOWS\System32\DRIVERS\mrxdav.sys Address: 0xED7C1000 Size: 180608 File Visible: - Signed: - Status: - Name: mrxsmb.sys Image Path: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys Address: 0xEDD7A000 Size: 455296 File Visible: - Signed: - Status: - Name: Msfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS Address: 0xF7BC1000 Size: 19072 File Visible: - Signed: - Status: - Name: msgpc.sys Image Path: C:\WINDOWS\System32\DRIVERS\msgpc.sys Address: 0xF7951000 Size: 35072 File Visible: - Signed: - Status: - Name: mssmbios.sys Image Path: C:\WINDOWS\System32\DRIVERS\mssmbios.sys Address: 0xF7CD5000 Size: 15488 File Visible: - Signed: - Status: - Name: Mup.sys Image Path: Mup.sys Address: 0xF75FB000 Size: 105344 File Visible: - Signed: - Status: - Name: NDIS.sys Image Path: NDIS.sys Address: 0xF7629000 Size: 182656 File Visible: - Signed: - Status: - Name: ndistapi.sys Image Path: C:\WINDOWS\System32\DRIVERS\ndistapi.sys Address: 0xF7CC1000 Size: 10112 File Visible: - Signed: - Status: - Name: ndisuio.sys Image Path: C:\WINDOWS\System32\DRIVERS\ndisuio.sys Address: 0xEDBE0000 Size: 14592 File Visible: - Signed: - Status: - Name: ndiswan.sys Image Path: C:\WINDOWS\System32\DRIVERS\ndiswan.sys Address: 0xF71A9000 Size: 91520 File Visible: - Signed: - Status: - Name: NDProxy.SYS Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS Address: 0xF7981000 Size: 40576 File Visible: - Signed: - Status: - Name: netbios.sys Image Path: C:\WINDOWS\System32\DRIVERS\netbios.sys Address: 0xF7A01000 Size: 34688 File Visible: - Signed: - Status: - Name: netbt.sys Image Path: C:\WINDOWS\System32\DRIVERS\netbt.sys Address: 0xEDEC7000 Size: 162816 File Visible: - Signed: - Status: - Name: nic1394.sys Image Path: C:\WINDOWS\System32\DRIVERS\nic1394.sys Address: 0xF78B1000 Size: 61824 File Visible: - Signed: - Status: - Name: Npfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS Address: 0xF7BD1000 Size: 30848 File Visible: - Signed: - Status: - Name: Ntfs.sys Image Path: Ntfs.sys Address: 0xF7656000 Size: 574976 File Visible: - Signed: - Status: - Name: ntoskrnl.exe Image Path: C:\WINDOWS\system32\ntoskrnl.exe Address: 0x804D7000 Size: 2189056 File Visible: - Signed: - Status: - Name: Null.SYS Image Path: C:\WINDOWS\System32\Drivers\Null.SYS Address: 0xF7F18000 Size: 2944 File Visible: - Signed: - Status: - Name: ohci1394.sys Image Path: ohci1394.sys Address: 0xF77F1000 Size: 61696 File Visible: - Signed: - Status: - Name: omci.sys Image Path: C:\WINDOWS\System32\DRIVERS\omci.sys Address: 0xF7B89000 Size: 17152 File Visible: - Signed: - Status: - Name: OPRGHDLR.SYS Image Path: C:\WINDOWS\System32\DRIVERS\OPRGHDLR.SYS Address: 0xF7DAA000 Size: 4096 File Visible: - Signed: - Status: - Name: PartMgr.sys Image Path: PartMgr.sys Address: 0xF7A69000 Size: 19712 File Visible: - Signed: - Status: - Name: pci.sys Image Path: pci.sys Address: 0xF7781000 Size: 68224 File Visible: - Signed: - Status: - Name: pciide.sys Image Path: pciide.sys Address: 0xF7DA9000 Size: 3328 File Visible: - Signed: - Status: - Name: PCIIDEX.SYS Image Path: C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS Address: 0xF7A61000 Size: 28672 File Visible: - Signed: - Status: - Name: pcmcia.sys Image Path: pcmcia.sys Address: 0xF7763000 Size: 120192 File Visible: - Signed: - Status: - Name: pfc.sys Image Path: C:\WINDOWS\system32\drivers\pfc.sys Address: 0xF7CA1000 Size: 10368 File Visible: - Signed: - Status: - Name: PnpManager Image Path: \Driver\PnpManager Address: 0x804D7000 Size: 2189056 File Visible: - Signed: - Status: - Name: portcls.sys Image Path: C:\WINDOWS\system32\drivers\portcls.sys Address: 0xF741A000 Size: 147456 File Visible: - Signed: - Status: - Name: psched.sys Image Path: C:\WINDOWS\System32\DRIVERS\psched.sys Address: 0xF7198000 Size: 69120 File Visible: - Signed: - Status: - Name: ptilink.sys Image Path: C:\WINDOWS\System32\DRIVERS\ptilink.sys Address: 0xF7B61000 Size: 17792 File Visible: - Signed: - Status: - Name: PxHelp20.sys Image Path: PxHelp20.sys Address: 0xF7861000 Size: 36320 File Visible: - Signed: - Status: - Name: rasacd.sys Image Path: C:\WINDOWS\System32\DRIVERS\rasacd.sys Address: 0xF7CA5000 Size: 8832 File Visible: - Signed: - Status: - Name: rasl2tp.sys Image Path: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys Address: 0xF7921000 Size: 51328 File Visible: - Signed: - Status: - Name: raspppoe.sys Image Path: C:\WINDOWS\System32\DRIVERS\raspppoe.sys Address: 0xF7931000 Size: 41472 File Visible: - Signed: - Status: - Name: raspptp.sys Image Path: C:\WINDOWS\System32\DRIVERS\raspptp.sys Address: 0xF7941000 Size: 48384 File Visible: - Signed: - Status: - Name: raspti.sys Image Path: C:\WINDOWS\System32\DRIVERS\raspti.sys Address: 0xF7B71000 Size: 16512 File Visible: - Signed: - Status: - Name: RAW Image Path: \FileSystem\RAW Address: 0x804D7000 Size: 2189056 File Visible: - Signed: - Status: - Name: rdbss.sys Image Path: C:\WINDOWS\System32\DRIVERS\rdbss.sys Address: 0xEDDEA000 Size: 175744 File Visible: - Signed: - Status: - Name: RDPCDD.sys Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Address: 0xF7D07000 Size: 4224 File Visible: - Signed: - Status: - Name: redbook.sys Image Path: C:\WINDOWS\System32\DRIVERS\redbook.sys Address: 0xF78F1000 Size: 57600 File Visible: - Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xED164000 Size: 49152 File Visible: No Signed: - Status: - Name: SASDIFSV.SYS Image Path: C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS Address: 0xF7AC9000 Size: 24576 File Visible: - Signed: - Status: - Name: SASKUTIL.sys Image Path: C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys Address: 0xEDE15000 Size: 151552 File Visible: - Signed: - Status: - Name: speedfan.sys Image Path: speedfan.sys Address: 0xF7DAB000 Size: 4096 File Visible: No Signed: - Status: - Name: sr.sys Image Path: sr.sys Address: 0xF76FA000 Size: 73472 File Visible: - Signed: - Status: - Name: srescan.sys Image Path: srescan.sys Address: 0xF7615000 Size: 81920 File Visible: No Signed: - Status: - Name: srv.sys Image Path: C:\WINDOWS\System32\DRIVERS\srv.sys Address: 0xED477000 Size: 333952 File Visible: - Signed: - Status: - Name: STAC97.sys Image Path: C:\WINDOWS\system32\drivers\STAC97.sys Address: 0xF743E000 Size: 193568 File Visible: - Signed: - Status: - Name: STREAM.SYS Image Path: C:\WINDOWS\system32\DRIVERS\STREAM.SYS Address: 0xF7911000 Size: 53248 File Visible: - Signed: - Status: - Name: strmdisp.sys Image Path: C:\WINDOWS\System32\DRIVERS\strmdisp.sys Address: 0xF7B99000 Size: 21280 File Visible: - Signed: - Status: - Name: swenum.sys Image Path: C:\WINDOWS\System32\DRIVERS\swenum.sys Address: 0xF7CF3000 Size: 4352 File Visible: - Signed: - Status: - Name: SynTP.sys Image Path: C:\WINDOWS\System32\DRIVERS\SynTP.sys Address: 0xF74B9000 Size: 182688 File Visible: - Signed: - Status: - Name: sysaudio.sys Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys Address: 0xED5D9000 Size: 60800 File Visible: - Signed: - Status: - Name: tcpip.sys Image Path: C:\WINDOWS\System32\DRIVERS\tcpip.sys Address: 0xEE015000 Size: 361600 File Visible: - Signed: - Status: - Name: tcpip6.sys Image Path: C:\WINDOWS\system32\DRIVERS\tcpip6.sys Address: 0xEDEEF000 Size: 225856 File Visible: - Signed: - Status: - Name: TDI.SYS Image Path: C:\WINDOWS\System32\DRIVERS\TDI.SYS Address: 0xF7B51000 Size: 20480 File Visible: - Signed: - Status: - Name: termdd.sys Image Path: C:\WINDOWS\System32\DRIVERS\termdd.sys Address: 0xF7961000 Size: 40704 File Visible: - Signed: - Status: - Name: tunmp.sys Image Path: C:\WINDOWS\system32\DRIVERS\tunmp.sys Address: 0xF7C81000 Size: 12288 File Visible: - Signed: - Status: - Name: UniShieldXP.sys Image Path: C:\Program Files\Everstrike\Lock Folder XP 3.2\UniShieldXP.sys Address: 0xED846000 Size: 45952 File Visible: - Signed: - Status: - Name: update.sys Image Path: C:\WINDOWS\System32\DRIVERS\update.sys Address: 0xF713A000 Size: 384768 File Visible: - Signed: - Status: - Name: USBD.SYS Image Path: C:\WINDOWS\System32\DRIVERS\USBD.SYS Address: 0xF7CED000 Size: 8192 File Visible: - Signed: - Status: - Name: usbehci.sys Image Path: C:\WINDOWS\System32\DRIVERS\usbehci.sys Address: 0xF7A99000 Size: 30208 File Visible: - Signed: - Status: - Name: usbhub.sys Image Path: C:\WINDOWS\System32\DRIVERS\usbhub.sys Address: 0xF79B1000 Size: 59520 File Visible: - Signed: - Status: - Name: USBPORT.SYS Image Path: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS Address: 0xF74E6000 Size: 147456 File Visible: - Signed: - Status: - Name: usbuhci.sys Image Path: C:\WINDOWS\System32\DRIVERS\usbuhci.sys Address: 0xF7A91000 Size: 20608 File Visible: - Signed: - Status: - Name: Vcs.sys Image Path: C:\WINDOWS\system32\Drivers\Vcs.sys Address: 0xF7D17000 Size: 5184 File Visible: - Signed: - Status: - Name: vga.sys Image Path: C:\WINDOWS\System32\drivers\vga.sys Address: 0xF7BA9000 Size: 20992 File Visible: - Signed: - Status: - Name: VIDEOPRT.SYS Image Path: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS Address: 0xF750A000 Size: 81920 File Visible: - Signed: - Status: - Name: VolSnap.sys Image Path: VolSnap.sys Address: 0xF7821000 Size: 52352 File Visible: - Signed: - Status: - Name: vsdatant.sys Image Path: C:\WINDOWS\System32\vsdatant.sys Address: 0xEDE5C000 Size: 438272 File Visible: - Signed: - Status: - Name: wanarp.sys Image Path: C:\WINDOWS\System32\DRIVERS\wanarp.sys Address: 0xF79D1000 Size: 34560 File Visible: - Signed: - Status: - Name: watchdog.sys Image Path: C:\WINDOWS\System32\watchdog.sys Address: 0xF7B41000 Size: 20480 File Visible: - Signed: - Status: - Name: wdmaud.sys Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys Address: 0xED43A000 Size: 83072 File Visible: - Signed: - Status: - Name: Win32k Image Path: \Driver\Win32k Address: 0xBF800000 Size: 1847296 File Visible: - Signed: - Status: - Name: win32k.sys Image Path: C:\WINDOWS\System32\win32k.sys Address: 0xBF800000 Size: 1847296 File Visible: - Signed: - Status: - Name: WMILIB.SYS Image Path: C:\WINDOWS\System32\DRIVERS\WMILIB.SYS Address: 0xF7CE3000 Size: 8192 File Visible: - Signed: - Status: - Name: WMIxWDM Image Path: \Driver\WMIxWDM Address: 0x804D7000 Size: 2189056 File Visible: - Signed: - Status: -
In the RootRepeal, I can only follow steps "5A through 5D" and then jump to "5I" from your instuction, there wasn't option I can click on like you described. Anyhow, the result is what you see above.
DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 22:37:59.34 on Fri 09/18/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.512 [GMT 8:00] AV: avast! antivirus 4.8.1351 [VPS 090918-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\System32\Ati2evxx.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Common Files\Stardock\SDMCP.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\Explorer.EXE C:\Program Files\reliz\akeys.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\CursorXP\CursorXP.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\Program Files\Startup Faster 2004\sfAgent.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe C:\Documents and Settings\Others\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html mWinlogon: UIHost=c:\windows\system32\logonuiX.exe BHO: IE7Pro BHO: {00011268-e188-40df-a514-835fcd78b1bf} - c:\program files\iepro\iepro.dll BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 8\SnagItBHO.dll BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - c:\program files\getright\xx2gr.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: PopKiller Class: {9a23b8a4-c6c9-4a68-8fa6-5f905dc8ff80} - c:\program files\sysshield tools\internet eraser\pkext.dll BHO: ICBC Anti-Phishing class: {bb4491a2-d11a-4c6b-91c0-b53246a3122b} - c:\program files\icbcebanktools\icbcantiphishing\Icbc_AntiPhishing.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: IncrediBar: {d8073790-84c7-4602-bf77-c6acbf1612e4} - c:\program files\incredibar\bin\IBTBar.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: 1-Click Answers: {7754c418-f62e-44aa-b169-e719e718bcfd} - c:\progra~1\1-clic~1\ietoolbar\AnswersToolbarU.dll TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 8\SnagItIEAddin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn5\yt.dll TB: AbsoluteShield: {ee9dd090-902d-4623-9360-fb7d8666202b} - c:\program files\sysshield tools\internet eraser\AbsoluteBar.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - No File EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File EB: {8BCB5337-EC01-4E38-840C-A964F174255B} - No File mRun: [StartupFaster] "c:\program files\startup faster 2004\StrpFstCfg.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\others\startm~1\programs\startup\startu~1\amfdai~1.lnk - c:\program files\pim\amf.exe StartupFolder: c:\documents and settings\others\start menu\programs\startup\startupfaster\StartupFaster.ini StartupFolder: c:\docume~1\others\startm~1\programs\startup\startu~1\webshots.lnk - c:\program files\webshots\Launcher.exe StartupFolder: c:\docume~1\others\startm~1\programs\startup\startu~1\x1syst~1.lnk - c:\program files\x1\X1Systray.exe StartupFolder: c:\docume~1\others\startm~1\programs\startup\startu~1\x1.lnk - c:\program files\x1\X1.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\startu~1\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\startu~1\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\startu~1\hpzrcv01.lnk - c:\program files\hp\temp\{387d9916-bd27-480f-8cf0-3228832bbaa2}\setup\hpzstub.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\startu~1\hpzsetup.lnk - c:\program files\hp\temp\{387d9916-bd27-480f-8cf0-3228832bbaa2}\hpzstub.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\startu~1\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe StartupFolder: c:\documents and settings\all users\start menu\programs\startup\startupfaster\StartupFaster.ini uPolicies-explorer: NoInstrumentation = 0 (0x0) uPolicies-explorer: NoHelp = 0 (0x0) uPolicies-explorer: NoCommonGroups = 0 (0x0) uPolicies-explorer: NoStartMenuEjectPC = 0 (0x0) uPolicies-explorer: NoSimpleStartMenu = 0 (0x0) uPolicies-explorer: NoStartMenuSubFolders = 0 (0x0) uPolicies-explorer: NoDisconnect = 0 (0x0) uPolicies-explorer: NoNtSecurity = 0 (0x0) uPolicies-explorer: GreyMSIAds = 0 (0x0) uPolicies-explorer: ForceMaxRecentDocs = 0 (0x0) uPolicies-explorer: NoSMBalloonTip = 0 (0x0) uPolicies-explorer: NoSMBalloonTips = 0 (0x0) uPolicies-explorer: NoTaskGrouping = 0 (0x0) uPolicies-explorer: NoWebServices = 0 (0x0) uPolicies-explorer: NoFileUrl = 0 (0x0) uPolicies-explorer: NoExpandedNewMenu = 0 (0x0) uPolicies-explorer: SpecifyDefaultButtons = 0 (0x0) uPolicies-explorer: NoRecentDocsNetHood = 0 (0x0) uPolicies-explorer: PromptRunasInstallNetPath = 1 (0x1) uPolicies-explorer: NoResolveTrack = 0 (0x0) uPolicies-explorer: NoDevMgrUpdate = 0 (0x0) uPolicies-explorer: NoThumbnailCache = 0 (0x0) uPolicies-explorer: ForceCopyAclwithFile = 0 (0x0) uPolicies-explorer: StartRunNoHOMEPATH = 0 (0x0) uPolicies-explorer: HideClock = 0 (0x0) uPolicies-system: HideLogonScripts = 0 (0x0) mPolicies-explorer: NoResolveTrack = 0 (0x0) mPolicies-explorer: NoFileAssociate = 0 (0x0) mPolicies-system: NoDispSettingsPage = 0 (0x0) dPolicies-explorer: NoThemesTab = 0 (0x0) dPolicies-explorer: NoChangeAnimation = 0 (0x0) dPolicies-explorer: RestrictCpl = 0 (0x0) dPolicies-explorer: DisallowCpl = 0 (0x0) dPolicies-explorer: NoViewOnDrive = 0 (0x0) dPolicies-explorer: RestrictRun = 0 (0x0) dPolicies-explorer: DisallowRun = 0 (0x0) dPolicies-explorer: NoRecycleFiles = 0 (0x0) dPolicies-explorer: ForceRecycleBinSize = 0 (0x0) dPolicies-explorer: NoCustomizeWebView = 0 (0x0) dPolicies-explorer: NoFileAssociate = 0 (0x0) dPolicies-explorer: NoDFSTab = 0 (0x0) dPolicies-explorer: NoInstrumentation = 0 (0x0) dPolicies-explorer: NoCustomizeThisFolder = 0 (0x0) dPolicies-explorer: NoWebView = 0 (0x0) dPolicies-explorer: DontShowSuperHidden = 0 (0x0) dPolicies-explorer: NoOnlinePrintsWizard = 0 (0x0) dPolicies-explorer: NoPublishingWizard = 0 (0x0) dPolicies-explorer: NoSMConfigurePrograms = 0 (0x0) dPolicies-explorer: NoSMMyPictures = 0 (0x0) dPolicies-explorer: NoStartMenuMyMusic = 0 (0x0) dPolicies-explorer: NoHelp = 0 (0x0) dPolicies-explorer: NoCommonGroups = 0 (0x0) dPolicies-explorer: NoStartMenuEjectPC = 0 (0x0) dPolicies-explorer: NoSimpleStartMenu = 0 (0x0) dPolicies-explorer: NoStartMenuSubFolders = 0 (0x0) dPolicies-explorer: NoDisconnect = 0 (0x0) dPolicies-explorer: NoNtSecurity = 0 (0x0) dPolicies-explorer: GreyMSIAds = 0 (0x0) dPolicies-explorer: ForceMaxRecentDocs = 0 (0x0) dPolicies-explorer: NoSMBalloonTip = 0 (0x0) dPolicies-explorer: NoSMBalloonTips = 0 (0x0) dPolicies-explorer: HideClock = 0 (0x0) dPolicies-explorer: NoTaskGrouping = 0 (0x0) dPolicies-explorer: NoWebServices = 0 (0x0) dPolicies-explorer: NoFileUrl = 0 (0x0) dPolicies-explorer: NoExpandedNewMenu = 0 (0x0) dPolicies-explorer: SpecifyDefaultButtons = 0 (0x0) dPolicies-explorer: NoRecentDocsNetHood = 0 (0x0) dPolicies-explorer: PromptRunasInstallNetPath = 1 (0x1) dPolicies-explorer: NoResolveTrack = 0 (0x0) dPolicies-explorer: NoDevMgrUpdate = 0 (0x0) dPolicies-explorer: NoThumbnailCache = 0 (0x0) dPolicies-explorer: ForceCopyAclwithFile = 0 (0x0) dPolicies-explorer: StartRunNoHOMEPATH = 0 (0x0) dPolicies-system: NoVisualStyleChoice = 0 (0x0) dPolicies-system: NoColorChoice = 0 (0x0) dPolicies-system: NoSizeChoice = 0 (0x0) dPolicies-system: HideLogonScripts = 0 (0x0) IE: c:\program files\tencent\qq\SendMMS.htm IE: &Add animation to IncrediMail Style Box - c:\progra~1\incred~2\bin\resources\WebMenuImg.htm IE: &Winamp Toolbar Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Answers… - file:c:\program files\1-click answers\html\atiemenu.htm IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Download with GetRight - c:\program files\getright\GRdownload.htm IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: Logoff - file://c:\program files\siber systems\ai roboform\RoboFormComLogoff.html IE: Open with GetRight Browser - c:\program files\getright\GRbrowse.htm IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: Translate this web page with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htm IE: Translate with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Action.htm IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {95B3F550-91C4-4627-BCC4-521288C52977} - c:\program files\pplive\PPLive.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - {B119EB0C-C021-46CF-85B0-34A760E0D5FE} - c:\program files\iepro\iepro.dll IE: {023FA804-DCE1-4817-94ED-6BA4200F9AF2} - {023FA804-DCE1-4817-94ED-6BA4200F9AF2} - c:\program files\incredibar\bin\IBTBar.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: bankofamerica.com\www Trusted Zone: com.cn\mybank.icbc Trusted Zone: com.cn\www.icbc Trusted Zone: hotmail.com\www Trusted Zone: live.com\login Trusted Zone: microsoft.com\v4.Windowsupdate Trusted Zone: microsoft.com\Windowsupdate Trusted Zone: msn.com\www Trusted Zone: yahoo.com\www DPF: DirectAnimation Java Classes DPF: Microsoft XML Parser for Java DPF: Yahoo! MahJong Solitaire - hxxp://download.games.yahoo.com/games/clients/y/mjst4_x.cab DPF: Yahoo! Pool 2 - hxxp://download.games.yahoo.com/games/clients/y/pote_x.cab DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0D99625B-0619-4420-BB61-82DEE1B91D3A} - hxxps://ebank.gdb.com.cn/perbank/js/CertKitAx.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://download.ewido.net/ewidoOnlineScan.cab DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv9dmo.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://johnzheng2356.spaces.live.com//PhotoUpload/MsnPUpld.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - hxxp://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222675051475 DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - hxxp://chat.yahoo.com/cab/yacsui.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yuplapp.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} - hxxps://mybank.icbc.com.cn/icbc/newperbank/AxSafeControls.cab DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - hxxp://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38192.0495138889 DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D81CA86B-EF63-42AF-BEE3-4502D9A03C2D} - hxxp://wwws.musicmatch.com/graphics/WebPlayer/MMLRadio.cab DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yvwrctl.cab DPF: {E856B973-45FD-4559-8F82-EAB539144667} - hxxp://pccheckup.dellfix.com/rel/35/install/gtdownde.cab DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - hxxp://chat.msn.com/bin/msnchat45.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: MCPClient - c:\program files\common files\stardock\mcpstub.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\others\applic~1\mozilla\firefox\profiles\8g1iwoqs.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - component: c:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\opera\program\plugins\npdrmv2.dll FF - plugin: c:\program files\opera\program\plugins\nppl3260.dll FF - plugin: c:\program files\opera\program\plugins\nprjplug.dll FF - plugin: c:\program files\opera\program\plugins\nprpjplug.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: browser.blink_allowed - true FF - user.js: network.prefetch-next - true FF - user.js: nglayout.initialpaint.delay - 250 FF - user.js: layout.spellcheckDefault - 1 FF - user.js: browser.urlbar.autoFill - false FF - user.js: browser.search.openintab - false FF - user.js: browser.tabs.closeButtons - 1 FF - user.js: browser.tabs.opentabfor.middleclick - true FF - user.js: browser.tabs.tabMinWidth - 100 FF - user.js: browser.urlbar.hideGoButton - false ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-9-14 64160] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-5 114768] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-7-28 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-7-28 72944] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-3-3 353672] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-5 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2005-1-21 138680] R2 CMB8100;CMB8100;c:\windows\system32\drivers\CertClient.dat [2008-9-14 3038] R2 CMBProtector;CMBProtector;c:\windows\system32\drivers\CMBProtector.dat [2008-9-14 3584] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456] R2 lf;lf;c:\program files\everstrike\lock folder xp 3.2\UniShieldXP.sys [2003-7-3 45952] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2008-4-24 269648] R2 MOTOVISION;MotoVision For E680/680i, A780/760/768 Virtual Camera;c:\windows\system32\drivers\motovision.sys [2009-1-6 31145] R2 Vcs;Vcs support;c:\windows\system32\drivers\Vcs.sys [2005-2-11 6852] R3 AgilentUSBCam;E-Video DC-350 USB Camera;c:\windows\system32\drivers\Atusbcam.sys [2001-4-26 117984] R3 DirectDrv;DirectDrv;c:\windows\system32\drivers\MotoVisionDP.sys [2009-1-6 11941] R3 LMPC2;LMPC2;c:\windows\system32\drivers\lmpc2.sys [2007-10-25 4224] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2008-5-11 19160] S2 ICBC Daemon Service;ICBC Daemon Service;c:\program files\icbcebanktools\icbcantiphishing\IcbcDaemon.exe [2009-7-8 397192] S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2005-1-21 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2005-2-26 352920] S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\drivers\brgsp50.sys –> c:\windows\system32\drivers\BRGSp50.sys [?] S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2008-9-6 6016] S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [2004-3-9 95232] S3 DfSdkS;Defragmentation-Service;c:\program files\ashampoo\ashampoo winoptimizer 6\DfSdkS.exe [2009-8-10 410976] S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2009-6-21 18688] S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-6-21 8320] S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2009-6-21 42112] S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2009-6-21 23296] S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2009-1-6 23680] S3 NTSPPPOE;Efficient Networks Enternet P.P.P.o.E LAN Miniport Driver;c:\windows\system32\drivers\ntspppoe.sys [2003-4-13 161512] S3 RAWESR;RAWESR;\??\c:\progra~1\effici~1\entern~1\app\rawesr.sys –> c:\progra~1\effici~1\entern~1\app\RAWESR.SYS [?] S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2007-4-23 224896] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-7-28 7408] S3 ZD1211BU(TP-LINK);TL-WN322G/WN322G+ Wireless USB Adapter Driver(TP-LINK);c:\windows\system32\drivers\ZD1211BU.sys [2008-12-6 500736] S4 bckg32;Zone Backgammon Client;c:\windows\system32\rundll32.exe bckg32.dll,yduq –> c:\windows\system32\rundll32.exe bckg32.dll,yduq [?] S4 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-6-6 33176] =============== Created Last 30 ================ 2009-09-14 00:33 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-09-14 00:29 -cd-h— c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864} 2009-09-14 00:29 –d—– c:\program files\Lavasoft 2009-09-13 13:18 693,760 a——- c:\windows\is-V9TVU.exe 2009-09-13 13:18 10,498 a——- c:\windows\is-V9TVU.msg 2009-09-13 13:18 460 a——- c:\windows\is-V9TVU.lst 2009-09-12 16:01 2,688 a——- c:\windows\system32\settings.aaw 2009-09-12 16:01 720 a——- c:\windows\system32\history.aaw 2009-09-11 13:43 –d—– c:\docume~1\alluse~1\applic~1\WEBREG 2009-09-11 13:23 –d—– c:\program files\common files\HP 2009-09-11 13:21 –d—– c:\program files\HP 2009-09-11 13:15 157,446 a——- c:\windows\hphins27.dat 2009-09-11 13:15 787 ——– c:\windows\hphmdl27.dat 2009-09-11 13:14 271,704 a—-r– c:\windows\system32\hpzids01.dll 2009-09-11 13:13 117,760 a——- c:\windows\system32\hpzll5mu.dll 2009-09-10 07:01 –d—– c:\program files\SUPERAntiSpyware 2009-09-08 22:14 153,088 -c—— c:\windows\system32\dllcache\triedit.dll 2009-09-07 21:39 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2 2009-09-04 21:10 –d—– c:\program files\RMVB Converter ==================== Find3M ==================== 2009-09-18 20:24 4,212 a—h— c:\windows\system32\zllictbl.dat 2009-09-10 14:54 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 14:53 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-08-05 17:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-03 22:43 687,104 a——- c:\windows\is-C4T0L.exe 2009-07-18 03:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-17 11:10 232,200 a——- c:\windows\system32\PDBoot.exe 2009-07-15 14:43 410,984 a——- c:\windows\system32\deploytk.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll 2009-07-04 01:09 915,456 a——- c:\windows\system32\wininet.dll 2009-06-25 16:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 16:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 16:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 16:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 16:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 16:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-22 11:58 79,328 a——- c:\documents and settings\others\mqdmserd.sys 2009-06-22 11:58 5,936 a——- c:\documents and settings\others\mqdmwhnt.sys 2009-06-22 11:58 92,064 a——- c:\documents and settings\others\mqdmmdm.sys 2009-06-22 11:58 9,232 a——- c:\documents and settings\others\mqdmmdfl.sys 2009-06-22 11:58 4,048 a——- c:\documents and settings\others\mqdmcr.sys 2009-06-22 11:58 66,656 a——- c:\documents and settings\others\mqdmbus.sys 2009-06-22 11:58 6,208 a——- c:\documents and settings\others\mqdmcmnt.sys 2009-06-22 11:58 25,600 a——- c:\documents and settings\others\usbsermptxp.sys 2009-06-22 11:58 22,768 a——- c:\documents and settings\others\usbsermpt.sys 2007-04-23 14:21 269,824 a——- c:\windows\inf\wg111v3\vista64\wg111v3.sys 2007-04-23 14:11 224,896 a——- c:\windows\inf\wg111v3\wg111v3.sys 2006-12-15 11:30 315,392 a——- c:\windows\inf\wg111v3\InstallDriver.exe 2006-12-15 11:30 212,992 a——- c:\windows\inf\wg111v3\CopyWHQLDriver.exe 2006-12-15 11:30 98,304 a——- c:\windows\inf\wg111v3\UScanM.exe 2006-12-15 11:30 66,048 a——- c:\windows\inf\wg111v3\EAPPkt.sys 2006-12-15 11:30 28,672 a——- c:\windows\inf\wg111v3\SetDrv.exe 2006-12-15 11:30 20,480 a——- c:\windows\inf\wg111v3\RTWUPath.exe 2006-12-15 11:30 19,968 a——- c:\windows\inf\wg111v3\RTWREFU.EXE 2005-02-03 11:33 10,856 a–sh— c:\windows\system32\KGyGaAvL.sys ============= FINISH: 22:39:40.77 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 7/24/2004 3:39:12 PM System Uptime: 9/18/2009 8:14:47 PM (2 hours ago) Motherboard: Dell Computer Corporation | | 09U806 Processor: Intel® Pentium® 4 CPU 2.40GHz | U49 | 2392/533mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 28 GiB total, 1.118 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1123: 9/6/2009 12:12:59 AM - Removed SUPERAntiSpyware Professional RP1124: 9/6/2009 12:28:56 AM - Installed SUPERAntiSpyware Professional RP1125: 9/7/2009 9:39:46 PM - Software Distribution Service 3.0 RP1126: 9/8/2009 10:17:33 PM - Software Distribution Service 3.0 RP1127: 9/10/2009 6:42:06 AM - Removed SUPERAntiSpyware Professional RP1128: 9/10/2009 7:01:51 AM - Installed SUPERAntiSpyware Professional ==== Installed Programs ====================== ??????????? ÕÐÐÐרҵ°æ Ð¶ÔØ¿áÎÒÒôÀֺР1-Click Answers AbsoluteShield File Shredder AbsoluteShield Internet Eraser Pro AccessDirect ACDSee Pro Ace Utilities 2.4.1 Acrobat.com Active Security Monitor 1.0.0.315 Active WebCam Ad-Aware Additional Background Pack 1 Additional Clipart Pack 1 Additional Clipart Pack BW AddWeb 7 Pro Adobe AIR Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Photoshop Album 2.0 Starter Edition Adobe Photoshop CS Adobe Reader 9.1.3 Adobe Reader Chinese Simplified Fonts Ahead InCD Ahead InCD EasyWrite Reader Ahead Nero Burning ROM Ahead Nero BurnRights Ahead NeroMIX Ahead NeroVision Express AI RoboForm (All Users) AMF Daily Planner and PIM Aquatica 3 Aquatica 3D Aquatica Scenery Maker Ashampoo UnInstaller Platinum 2 Ashampoo WinOptimizer 6.30 Ask Toolbar ATI Control Panel ATI Display Driver AutoUpdate AV Voice Changer Software 3.0 Avant Browser (remove only) avast! Antivirus Babylon BACS BadCopy Pro Biz-Plan BootSkin Broadcom Advanced Control Suite BufferChm Business Card Designer Plus 7.3.0.0 Camfrog Server 3.2 (remove only) Camfrog Video Chat 5.3 Choice Guard CoffeeCup HTML Editor Conexant D480 MDC V.92 Modem Critical Update for Windows Media Player 11 (KB959772) CursorXP CustomerResearchQFolder Customizer XP CuteFTP 6 Professional CyberBuddy D4300 D4300_Help dBpoweramp Music Converter Dell Digital Jukebox Driver Dell Home Systems Services Agreement Dell Picture Studio - Dell Image Expert Dell Solution Center Dell Support DesktopX Professional DeviceDiscovery DeviceManagementQFolder Digital Line Detect Diskeeper Professional Premier Edition DivX DivX Player DJ_SF_03_D4300_ProductContext DJ_SF_03_D4300_Software DJ_SF_03_D4300_Software_Min Dream Aquarium DVDSentry Easy Video Joiner 5.21 ePrompter EPSON Printer Software eSupportQFolder Fetion 2008 FileSpecs extension for Ad-aware 6 Flight Simulator Screensaver 0.9 Free Internet TV v3.5 FreshDiagnose FTP Voyager 11.0 FunPhotor 6.0 getPlus® for Adobe GetRight Pro Good Sync version 4.6.10 GPBaseService Help and Support Customization HexDump extension for Ad-aware 6 Highway Pursuit HijackThis 2.0.2 Holding Pattern Screen Saver Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB954708) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) HP Customer Participation Program 10.0 HP Deskjet D4300 Printer Driver Software 10.0 Rel .3 HP Imaging Device Functions 10.0 HP Photosmart Essential 2.5 HP Smart Web Printing HP Solution Center 10.0 HP Update HPProductAssistant HPSSupply ICBC NetBank Client Controls ICM532 IconPackager ICQ6 iDailyDiary 3.52 IE7Pro imageN 1.4b IncrediBar IncrediMail Xe Intellisync® for Yahoo! Internet PrintWhere 2.6 InterVideo WinDVD ISO Recorder iTunes Java™ 6 Update 14 Junk Mail filter update Konvertor Label Designer Plus DELUXE 7.3.0.0 Lernout & Hauspie TruVoice American English TTS Engine LimeWire PRO 5.2.8 Lock Folder XP v3.2 LogonStudio LSP Explorer Pluginfor Ad-aware 6 Malwarebytes' Anti-Malware MarketResearch Messenger Control Plugin for Ad-aware Microsoft .NET Framework (English) Microsoft .NET Framework (English) v1.0.3705 Microsoft .NET Framework 1.0 Hotfix (KB928367) Microsoft .NET Framework 1.1 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft ActiveX Control Pad Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office 2000 SR-1 Premium Microsoft Office PowerPoint Viewer 2003 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Text-to-Speech Engine 4.0 (English) Microsoft User-Mode Driver Framework Feature Pack 1.0 Modem Helper Mozilla Firefox (3.0.13) MSN Music Assistant MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) myBabylon_English Toolbar NETGEAR WG111v3 wireless USB 2.0 adapter NJStar Communicator ObjectDock Plus Opera 9.64 Pando PerfectDisk 10 Professional phoenix.zip Picasa 3 Post-it® Software Notes Powertoys For Windows XP PPLive 1.9 PSSWCORE QuickTime RealPlayer Registry Mechanic 8.0 RelevantKnowledge RMVB Converter 1.8 Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Segoe UI SereneScreen Marine Aquarium 2 ShenProfessional 3.0 Shop for HP Supplies SimAQUARIUM2 Free Skype™ 4.1 SlimBrowser (remove only) SmartWebPrintingOC SnagIt 8 SolidConverterPDF SolutionCenter Sony Sound Forge 7.0 SpeedFan (remove only) Spelling Dictionaries Support For Adobe Reader 9 Spybot - Search & Destroy SpywareBlaster 4.2 SpywareGuard v2.2 Startup Faster! 2004 Status SUPERAntiSpyware Professional Switch Off Synacast Plug-in [removed] Synaptics Pointing Device Driver System Scheduler 3.31 TablePCRT Teleport Pro TimeLeft FREEWARE edition Timershot Powertoy for Windows XP Toolbox Trash Killer 2 TrayApp TreeSize Professional 3.3.3 Trillian Tweak-XP TypingMaster Pro TypingMaster TypingTest TZ Connection Booster 2.6 Unix Utilities for Yahoo! Widgets UnloadSupport Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB969497) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB973815) VC 9.0 Runtime Video Fixer 3.21 VideoToolkit01 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Vital Desktop (remove only) Volutive 1 vTuner Plus Water Screen Saver 1.1 Weather Watcher Weather Watcher Live WebFldrs XP WebReg Webshots Desktop Winamp Winamp Toolbar for Internet Explorer Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Safety scanner Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Live Writer Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinISO 5.3 WinMPG Video Convert 3.1 WinPatrol WinPcap 3.1 beta3 WinRAR archiver WinZip WinZip Self-Extractor Wisdom-soft ScreenHunter 4.0 Free WordPerfect Office 2002 WOT for Internet Explorer X1 Yahoo! Address AutoComplete Yahoo! Anti-Spy Yahoo! Browser Services Yahoo! Central Yahoo! Install Manager Yahoo! Mail Quick Select Tool (PhotoMail) Yahoo! Photos Easy Upload Tool 1v7 Yahoo! Toolbar Yahoo! Widgets ZoneAlarm Pro ==== Event Viewer Messages From Past Week ======== 9/18/2009 4:23:46 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the w32time service. 9/14/2009 4:53:26 AM, error: W32Time [34] - The time service has detected that the system time needs to be changed by +64752 seconds. The time service will not change the system time by more than +54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|75.95.235.43:123->207.46.197.32:123) is working properly. 9/14/2009 4:04:02 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the SENS service. 9/13/2009 4:04:21 AM, error: Service Control Manager [7001] - The Universal Plug and Play Device Host service depends on the SSDP Discovery Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 9/13/2009 4:04:20 AM, error: DCOM [10005] - DCOM got error "%1068" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 9/12/2009 4:00:52 PM, error: bcm4sbxp [4] - Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected. 9/12/2009 3:53:42 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service. 9/12/2009 2:47:26 PM, error: Service Control Manager [7034] - The ICBC Daemon Service service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 2:47:04 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd 9/12/2009 2:47:04 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting. 9/12/2009 2:45:36 PM, error: Service Control Manager [7001] - The InteractiveLogon service depends on the Terminal Services service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 9/12/2009 2:45:36 PM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 9/12/2009 1:24:01 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows CardSpace service to connect. 9/12/2009 1:24:01 PM, error: Service Control Manager [7000] - The Windows CardSpace service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. ==== End Of File ===========================
For the attch.txt, I tried many times to upload it, and it just kept on saying that the file was over 2mb while the fact is that the file is so small it only has 15kb in size. So I thought it would be easier for me to just copy and paste. Well, please see all above and thanks very much TomK!!!
Tom_q2356,

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.


The two cookies you indicated aren't malicious. You should be able to eliminate them by running this next tool. I must tell you that they will probably return once you go back out on the web. You can turn all cookies off in your browser, but you won't be able to log onto many sites.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hi TomK,

First of all, I want to thank all you guys here trying to help me take care of my computer problem. But after all this, I still cannot complete remove those two cookies or make sure they don't come back without affecting my logging into some very normal everyday websites? I have actually posted some threads here before regarding these two cookies and till today they are still an unsolved mystery. The thing is that these two cookies have been slowing down some aspects of my computer quiet a bit, for example, when I openned my idailydairy and trying to either type or copy and paste some texts it just felt like something is controlling my keyboard and I could hardly move the cursor to even select a word.

Is there a way you can help me make those two cookies go away once and for all and without affecting most of my normal browsing or reading emails or news on the web?

Also, I have been using ATF for almost a year already; so that does not really solve the problem.

Please give me an advice on if you think someone else from another forum or this forum would know exactly how to deal with these two particular cookies. I understand that they might not be the most malicious ones and they are in fact the rare ones I can search for any related topics on the google search engine.

Again, thanks for trying your best to help!
Tom_Q
Tom_q2356,

In Internet Explorer:
  • In the upper right of your screen click on Tools
  • Select Internet options.
  • Click on the Privacy tab
  • Click the Advanced button
  • Put a check in the Override automatic cookie handling box
  • Then under First party cookies… put a check by Prompt.
  • Under third party cookies… put a check by Block.
  • Click OK.
  • Then click on the General tab
  • The second "area" is called Browsing History… put a check by Delete history on exit.
  • Click the delete button to remove right now.
  • Click Apply then OK
Now, when you go to any site, IE will prompt you to accept or deny a cookie.

I also suggest that you consider installing a custom Hosts file. This will block you from being redirected to many sites. Information can be found here: http://mvps.org/winhelp2002/hosts.htm

Please give me an advice on if you think someone else from another forum or this forum would know exactly how to deal with these two particular cookies.

Quite possible. There are many that know more than me. Please advise that you would like me to close this thread and you will be free to seek other counsel.
Hi TomK,

Thanks for your instruction again! As you know I have been following it step by step because I trust everything from this forum. Please don't get me wrong, I did not mean to say that someone else is better than you guys here; I was just trying to say that those two cookies are very annoying and they seem to live in my computer forever. I just really want to kick them out completely. If you read some of my threads in the past in this forum, you will understand how serious I am trying to get rid of them, but each time I failed. Well, I have just made that internet option change to prompt as you asked me to and I hope it is going to help me with that. Also, because of the threads posted here in the past I have long before installed numerous different things including mvps host files you mentioned, like I said earlier on, I have tried out almost everything and I really need some good advice on this.

Thanks so very much!
Tom
Tom_q2356,

I do empty my cache on exit (I don't use IE hardly ever, usually I use FireFox).

I have never blocked all cookies like I suggested to you as I find it annoying to have to approve every one and I'm inherently lazy.

If you don't mind, run a Kaspersky online scan and we'll see if it flags them.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hi Tomk, I have already done that Kaspersky scan and nothing was found, also, I captured an very small size image of the scan result and could not upload it here. It actually took me nearly four hours to finish that scan. Well, let me just type them out here:
Objects scanned: 132137,
Threats found: 0,
Infected objects found: 0
Suspicious objects found: 0
scan duration: 03:53:45
Oh, I also forgot to mention that I personally never really use IE, I have been using Avant and SlimBrowser for the past 7 or 8 years.
I really appreciate it if you know any other way to deal with these, I am willing to try everything until they are gone for good.
Tom_q2356,

There is no virus showing but I'd like you to run ComboFix just to see what it does.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Well, first of all, I remember I ran combofix.exe before and the last time I ran that it did not prompt me to download or install Microsoft Windows Recovery Console. And this time I installed that because it asked me to. Below is the new log:
ComboFix 09-09-18.02 - Others 09/20/2009 21:12.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.596 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090920-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\windows\desktop
c:\windows\desktop\Fish.scr
c:\windows\dllmain.dll
c:\windows\fllib.dll
c:\windows\Fonts\acrsec.fon
c:\windows\Installer\34ddcf.msi
c:\windows\Installer\75269.msp
c:\windows\Installer\752cc.msi
c:\windows\Installer\8d708.msi
c:\windows\system\MSJAVAXP.DRV
c:\windows\system32\243a7238.dll

.
((((((((((((((((((((((((( Files Created from 2009-08-20 to 2009-09-20 )))))))))))))))))))))))))))))))
.

2009-09-13 16:33 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-13 16:29 . 2009-09-13 16:29 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-13 16:29 . 2009-09-13 16:29 ——– d—–w- c:\program files\Lavasoft
2009-09-13 05:18 . 2009-09-13 05:18 693760 —-a-w- c:\windows\is-V9TVU.exe
2009-09-11 05:43 . 2009-09-11 05:43 ——– d—–w- c:\documents and settings\All Users\Application Data\WEBREG
2009-09-11 05:42 . 2009-09-11 05:42 ——– d—–w- c:\documents and settings\Others\Application Data\HP
2009-09-11 05:24 . 2009-09-11 05:27 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2009-09-11 05:24 . 2009-09-11 05:24 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-09-11 05:23 . 2009-09-11 05:23 ——– d—–w- c:\program files\Common Files\HP
2009-09-11 05:21 . 2009-09-11 05:24 ——– d—–w- c:\program files\HP
2009-09-11 05:15 . 2009-09-11 07:06 157446 —-a-w- c:\windows\hphins27.dat
2009-09-11 05:15 . 2007-12-13 00:04 787 ——w- c:\windows\hphmdl27.dat
2009-09-11 05:14 . 2009-09-11 05:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-09-11 05:14 . 2007-11-08 15:06 271704 —-a-r- c:\windows\system32\hpzids01.dll
2009-09-11 05:13 . 2007-10-20 10:25 117760 —-a-w- c:\windows\system32\hpzll5mu.dll
2009-09-09 23:01 . 2009-09-13 02:49 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-09-08 14:14 . 2009-06-21 21:44 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-09-07 13:39 . 2009-09-07 13:39 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-09-04 13:10 . 2009-09-04 13:10 ——– d—–w- c:\program files\RMVB Converter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-20 09:32 . 2007-12-06 14:27 ——– d—–w- c:\documents and settings\Others\Application Data\SlimBrowser
2009-09-20 09:13 . 2005-01-16 06:03 ——– d—–w- c:\documents and settings\Others\Application Data\Skype
2009-09-20 08:14 . 2009-07-27 02:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Babylon
2009-09-20 03:11 . 2007-01-27 03:56 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-19 13:14 . 2009-07-16 23:06 ——– d—–w- c:\program files\SpywareGuard
2009-09-18 12:24 . 2004-06-02 12:50 4212 —ha-w- c:\windows\system32\zllictbl.dat
2009-09-17 14:57 . 2009-08-02 02:25 ——– d—–w- c:\program files\PIM
2009-09-16 14:52 . 2005-03-28 08:03 ——– d—–w- c:\documents and settings\Others\Application Data\SolidDocuments
2009-09-15 15:38 . 2004-06-11 10:33 ——– d—–w- c:\program files\SpywareBlaster
2009-09-14 14:54 . 2005-01-20 06:45 ——– d—–w- c:\program files\Trillian
2009-09-13 16:29 . 2005-02-02 04:43 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-09-13 16:25 . 2006-04-20 06:17 ——– d—–w- c:\program files\GetRight
2009-09-13 05:22 . 2008-04-24 09:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-12 15:16 . 2009-07-29 23:17 ——– d—a-w- c:\program files\eMule0.49c
2009-09-10 15:22 . 2007-03-01 13:11 ——– d—–w- c:\documents and settings\Others\Application Data\U3
2009-09-10 06:54 . 2008-07-20 05:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 06:53 . 2008-05-11 03:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 23:01 . 2009-07-15 06:59 ——– d—–w- c:\documents and settings\Others\Application Data\SUPERAntiSpyware.com
2009-09-09 15:29 . 2008-02-13 05:13 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-08 05:29 . 2004-12-03 08:54 ——– d—–w- c:\program files\ePrompter
2009-08-31 03:40 . 2009-01-09 23:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-28 15:16 . 2005-02-16 16:44 ——– d—–w- c:\program files\Teleport Pro
2009-08-24 14:14 . 2004-06-02 09:47 ——– d—–w- c:\program files\Avant Browser
2009-08-18 07:44 . 2009-07-27 02:56 ——– d—–w- c:\documents and settings\Others\Application Data\Babylon
2009-08-17 16:10 . 2004-11-23 00:40 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2005-01-21 01:11 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2005-01-21 01:11 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-04-05 02:49 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-05 02:49 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2005-01-21 01:11 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2005-02-25 18:12 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2005-01-21 01:11 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2004-06-24 07:58 97480 —-a-w- c:\windows\system32\AVASTSS.scr
2009-08-16 05:27 . 2004-06-01 01:02 ——– d—–w- c:\program files\CyberBuddy
2009-08-12 15:27 . 2003-03-30 18:02 55568 —-a-w- c:\documents and settings\Others\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 05:09 . 2009-07-29 22:12 ——– d—–w- c:\documents and settings\Others\Application Data\LimeWire
2009-08-10 04:24 . 2004-08-15 11:57 ——– dc—-w- c:\program files\Winpatrol Plus
2009-08-10 04:24 . 2004-08-12 01:27 ——– d—–w- c:\program files\Wisdom-soft ScreenHunter
2009-08-10 04:12 . 2005-03-28 16:01 ——– d—–w- c:\program files\Ashampoo
2009-08-09 09:48 . 2009-08-09 09:39 ——– d—–w- c:\program files\Dream Aquarium
2009-08-08 04:04 . 2009-08-08 04:04 ——– d—–w- c:\program files\ShenProfessional 3.0
2009-08-05 14:35 . 2009-08-05 14:31 ——– d—–w- c:\program files\Raxco
2009-08-05 09:01 . 2004-07-24 09:44 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 21:20 . 2009-08-03 21:20 ——– d—–w- c:\program files\ICBCEbankTools
2009-08-03 14:43 . 2009-08-03 14:43 687104 —-a-w- c:\windows\is-C4T0L.exe
2009-08-03 03:29 . 2009-08-03 03:14 ——– d—–w- c:\program files\Startup Inspector for Windows
2009-08-03 03:27 . 2009-08-03 03:27 ——– d—–w- c:\program files\LimeWire
2009-08-03 03:15 . 2009-08-03 03:15 ——– d—–w- c:\documents and settings\Others\Application Data\wsInspector
2009-08-01 13:32 . 2008-02-11 02:23 21 —-a-w- c:\windows\system32\mylk.dat
2009-07-30 22:02 . 2009-01-06 13:31 ——– d—–w- c:\program files\Mobile Vision PC Suite
2009-07-30 06:25 . 2009-06-24 23:59 ——– d—–w- c:\program files\myBabylon_English
2009-07-30 06:25 . 2009-07-30 06:25 ——– d—–w- c:\program files\Babylon
2009-07-29 16:14 . 2009-07-29 15:19 ——– d—–w- c:\program files\BearFlix
2009-07-29 15:30 . 2009-07-28 05:55 ——– d—–w- c:\documents and settings\Others\Application Data\DMCache
2009-07-29 15:13 . 2009-07-29 15:13 ——– d—–w- c:\documents and settings\Others\Application Data\IDM
2009-07-29 03:44 . 2009-07-29 03:43 ——– d—–w- c:\program files\Google
2009-07-28 07:35 . 2009-07-28 07:35 ——– d—–w- c:\documents and settings\Others\Application Data\Effexis Software
2009-07-28 07:35 . 2009-07-28 07:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Effexis Software
2009-07-28 04:32 . 2009-07-28 04:32 ——– d—–w- c:\documents and settings\Others\Application Data\AVG8
2009-07-28 04:08 . 2009-07-28 04:08 ——– d—–w- c:\program files\photo2sketch
2009-07-27 06:23 . 2009-07-27 06:23 ——– d—–w- c:\program files\Zeallsoft
2009-07-17 19:01 . 2002-09-03 16:27 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-17 03:10 . 2009-07-17 03:10 232200 —-a-w- c:\windows\system32\PDBoot.exe
2009-07-15 06:43 . 2009-05-12 12:19 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-07-13 15:43 . 2004-04-06 10:42 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2004-08-03 06:56 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2002-09-03 17:11 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-09-03 16:58 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-09-03 16:58 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-09-03 16:46 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2002-09-03 16:39 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2002-09-03 16:39 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2002-09-03 16:39 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2005-02-03 03:33 . 2005-01-21 02:52 10856 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupFaster"="c:\program files\Startup Faster 2004\StrpFstCfg.exe" [2006-07-08 1904640]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Others\Start Menu\Programs\Startup\StartupFaster
AMF Daily Planner and PIM.lnk - c:\program files\PIM\amf.exe [2009-8-14 2457600]
StartupFaster.ini [2009-9-19 1104]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2004-6-11 157000]
X1 System Tray.lnk - c:\program files\X1\X1Systray.exe [2005-10-1 331264]
X1.lnk - c:\program files\X1\X1.exe [2005-10-1 13479064]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoVisualStyleChoice"= 0 (0x0)
"NoColorChoice"= 0 (0x0)
"NoSizeChoice"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"DisallowRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideClock"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonuiX.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 04:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2003-08-25 02:25 139264 —-a-w- c:\program files\Common Files\Stardock\MCPStub.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Switch Off"=c:\program files\Switch Off\swoff.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DadApp"=c:\program files\Dell\AccessDirect\dadapp.exe
"DVDSentry"=c:\windows\System32\DSentry.exe
"pdfSaver3"=
"PrinterOn Printer Select 2.6"=c:\program files\PrinterOn Corporation\Internet PrintWhere 2.6\PW_PrinterSelect26.exe -NoUI

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\PPLive\\PPLive.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\KWMUSIC\\KwMusic.exe"=
"c:\\Program Files\\KWMUSIC\\KwMV.exe"=
"c:\\Program Files\\China Mobile\\Fetion\\FetionFX.exe"=
"c:\\Program Files\\China Mobile\\Fetion\\VMDotNet\\v2.0.50727\\FetionVM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25:TCP"= 25:TCP:File and Printer Sharing
"8529:TCP"= 8529:TCP:yduq

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [9/14/2009 12:33 AM 64160]
R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [4/5/2008 10:49 AM 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/28/2009 10:53 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/28/2009 10:53 AM 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [4/5/2008 10:49 AM 20560]
R2 CMB8100;CMB8100;c:\windows\SYSTEM32\DRIVERS\CertClient.dat [9/14/2008 7:52 AM 3038]
R2 CMBProtector;CMBProtector;c:\windows\SYSTEM32\DRIVERS\CMBProtector.dat [9/14/2008 7:52 AM 3584]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 PM 1029456]
R2 lf;lf;c:\program files\Everstrike\Lock Folder XP 3.2\UniShieldXP.sys [7/3/2003 9:50 PM 45952]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/24/2008 5:34 PM 269648]
R2 MOTOVISION;MotoVision For E680/680i, A780/760/768 Virtual Camera;c:\windows\SYSTEM32\DRIVERS\motovision.sys [1/6/2009 9:31 PM 31145]
R2 Vcs;Vcs support;c:\windows\SYSTEM32\DRIVERS\Vcs.sys [2/11/2005 11:36 PM 6852]
R3 AgilentUSBCam;E-Video DC-350 USB Camera;c:\windows\SYSTEM32\DRIVERS\Atusbcam.sys [4/26/2001 1:04 AM 117984]
R3 DirectDrv;DirectDrv;c:\windows\SYSTEM32\DRIVERS\MotoVisionDP.sys [1/6/2009 9:31 PM 11941]
R3 LMPC2;LMPC2;c:\windows\SYSTEM32\DRIVERS\lmpc2.sys [10/25/2007 10:30 PM 4224]
R3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [5/11/2008 11:53 AM 19160]
S2 ICBC Daemon Service;ICBC Daemon Service;c:\program files\ICBCEbankTools\ICBCAntiPhishing\IcbcDaemon.exe [7/8/2009 4:17 PM 397192]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\BRGSp50.sys –> c:\windows\system32\Drivers\BRGSp50.sys [?]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\SYSTEM32\DRIVERS\motfilt.sys [9/6/2008 10:15 PM 6016]
S3 DCamUSBUVT;ICM532A;c:\windows\SYSTEM32\DRIVERS\usbuvt.sys [3/9/2004 2:50 PM 95232]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [8/10/2009 12:13 PM 410976]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\SYSTEM32\DRIVERS\motccgp.sys [6/21/2009 1:21 PM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\SYSTEM32\DRIVERS\motccgpfl.sys [6/21/2009 1:21 PM 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\SYSTEM32\DRIVERS\motodrv.sys [6/21/2009 1:21 PM 42112]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\SYSTEM32\DRIVERS\Motousbnet.sys [6/21/2009 1:21 PM 23296]
S3 motport;Motorola USB Diagnostic Port;c:\windows\SYSTEM32\DRIVERS\motport.sys [1/6/2009 9:49 PM 23680]
S3 NTSPPPOE;Efficient Networks Enternet P.P.P.o.E LAN Miniport Driver;c:\windows\SYSTEM32\DRIVERS\ntspppoe.sys [4/13/2003 5:47 PM 161512]
S3 RAWESR;RAWESR;\??\c:\progra~1\EFFICI~1\ENTERN~1\app\RAWESR.SYS –> c:\progra~1\EFFICI~1\ENTERN~1\app\RAWESR.SYS [?]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\SYSTEM32\DRIVERS\wg111v3.sys [4/23/2007 2:11 PM 224896]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [7/28/2009 10:53 AM 7408]
S3 ZD1211BU(TP-LINK);TL-WN322G/WN322G+ Wireless USB Adapter Driver(TP-LINK);c:\windows\SYSTEM32\DRIVERS\ZD1211BU.sys [12/6/2008 5:44 PM 500736]
S4 bckg32;Zone Backgammon Client;c:\windows\system32\rundll32.exe bckg32.dll,yduq –> c:\windows\system32\rundll32.exe bckg32.dll,yduq [?]
S4 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [6/6/2009 4:08 PM 33176]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-09-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2006-10-01 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\SYSTEM32\cleanmgr.exe [2002-09-03 00:12]

2005-03-21 c:\windows\Tasks\FreshDiagnose Report.job
- c:\program files\FreshDevices\FreshDiagnose\fdiag.exe [2004-04-28 07:12]

2009-09-13 c:\windows\Tasks\Malwarebytes' Scheduled Update for Others.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-04-24 06:53]

2009-05-20 c:\windows\Tasks\User_Feed_Synchronization-{1EC03267-D26F-4AB1-9863-CC9FC678712A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 20:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
IE: c:\program files\Tencent\qq\SendMMS.htm
IE: &Add animation to IncrediMail Style Box - c:\progra~1\INCRED~2\bin\resources\WebMenuImg.htm
IE: &Winamp Toolbar Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Answers… - file:c:\program files\1-Click Answers\Html\atiemenu.htm
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Logoff - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComLogoff.html
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
IE: {{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
Trusted Zone: bankofamerica.com\www
Trusted Zone: com.cn\mybank.icbc
Trusted Zone: com.cn\www.icbc
Trusted Zone: hotmail.com\www
Trusted Zone: live.com\login
Trusted Zone: microsoft.com\v4.Windowsupdate
Trusted Zone: microsoft.com\Windowsupdate
Trusted Zone: msn.com\www
Trusted Zone: yahoo.com\www
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: {0D99625B-0619-4420-BB61-82DEE1B91D3A} - hxxps://ebank.gdb.com.cn/perbank/js/CertKitAx.cab
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://download.ewido.net/ewidoOnlineScan.cab
DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} - hxxps://mybank.icbc.com.cn/icbc/newperbank/AxSafeControls.cab
FF - ProfilePath - c:\documents and settings\Others\Application Data\Mozilla\Firefox\Profiles\8g1iwoqs.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Opera\program\plugins\npdrmv2.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
SafeBoot-svcWRSSSDK
AddRemove-AvantBrowser - c:\program files\Avant Browser\uninst.exe
AddRemove-WinPcapInst - c:\program files\WinPcap\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-20 21:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


C:\My Shared Folder

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CMB8100]
"ImagePath"="\??\c:\windows\system32\Drivers\CertClient.dat"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CMBProtector]
"ImagePath"="\??\c:\windows\system32\Drivers\CMBProtector.dat"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2104054462-3242262833-941974269-1007\Software\EduFont\E*d*u*O*f*f*i*c*e* *b„vW[\BCGWorkspace\WindowPlacement]
"MainWindowRect"=hex:fc,ff,ff,ff,fc,ff,ff,ff,04,04,00,00,04,03,00,00
"Flags"=dword:00000002
"ShowCmd"=dword:00000003

[HKEY_USERS\S-1-5-21-2104054462-3242262833-941974269-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-2104054462-3242262833-941974269-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1284)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\documents and settings\Others\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\program files\Common Files\Stardock\mcpstub.dll
.
Completion time: 2009-09-20 21:26
ComboFix-quarantined-files.txt 2009-09-20 13:24

Pre-Run: 1,284,497,408 bytes free
Post-Run: 1,239,371,776 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

437 — E O F — 2009-09-08 14:25

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI