This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] worm.win32.netsky - fake virus warnings

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I don't know how, but yesterday I got infected with a trojan that barrages me with fake warnings about viruses and spyware, telling me my computer is infected with "worm.win32.netsky." It just about crippled my laptop. I can only start Windows XP by booting into safe mode. I've tried to run Smitfraudfix and SmitRem, but when I try to open them I get an error message saying, "Application cannot be executed. The file is infected. Please activate your antivirus software." The Task Manager is also blocked. I would really appreciate some help.

Here is my HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:40:23, on 12/26/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\winupdate86.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
F2 - REG:system.ini: Shell=Explorer.exe logon.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [wiloyanate] Rundll32.exe "hikemavi.dll",s
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1236730104656
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} (Enlite 2.x Simulation Engine Installer) - http://myitlab.pearsoned.com/Pegasus/Modul…ces/ax/stub.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll loditija.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 7470 bytes
Hi Nift, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

When running thee tools, if possible close the warnings with X. These are fake alerts generated by the malware.

NEXT

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

[img width=309 height=91]http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
Thanks
Actually, I appreciate the help, but I found a solution to my problem elsewhere because it took so long to get a reply that I thought my thread had gotten buried under all the topics. I cleared at least enough of the trojan to perform a system restore and now my laptop is running fine, but I'll go ahead and post the GMER and OTL scan logs here just in case my system still contains traces of the trojan.

One problem, though. Running GMER crashed Windows. Some blue screen error message about "pxtdpipow.sys". I can still give you the OTL log:

OTL logfile created on: 1/1/2010 7:52:07 PM - Run 2
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Documents and Settings\Jason\Desktop\scanners
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 218.00 Mb Available Physical Memory | 21.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.84 Gb Total Space | 8.49 Gb Free Space | 8.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 926.03 Gb Total Space | 352.52 Gb Free Space | 38.07% Space Free | Partition Type: NTFS
Drive G: | 5.47 Gb Total Space | 1.13 Gb Free Space | 20.67% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME
Current User Name: Jason
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jason\Desktop\scanners\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe ()
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\WINDOWS\system32\Crypserv.exe (CrypKey (Canada) Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jason\Desktop\scanners\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\winsta.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Adobe LM Service) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (msvsmon90) – F:\Program Files\Microsoft Visual Studdio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (seclogonUPS) – C:\WINDOWS\System32\advpack.dll (Microsoft Corporation)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (wltrysvc) – C:\WINDOWS\System32\WLTRYSVC.EXE ()
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Ati HotKey Poller) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
SRV - (OracleXEClrAgent) – C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe ()
SRV - (OracleXETNSListener) – C:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE ()
SRV - (OracleMTSRecoveryService) – C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe (Oracle Corporation)
SRV - (OracleJobSchedulerXE) – c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe ()
SRV - (OracleServiceXE) – c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE (Oracle Corporation)
SRV - (MA_CMIDI_InstallerService) – C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe ()
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (aspnet_stateAudioSrv) – C:\WINDOWS\System32\adsmsexto.exe ()
SRV - (SwPrvShellHWDetection) – C:\WINDOWS\System32\1031c.exe (Microsoft Corporation)
SRV - (SENSRpcSs) – C:\WINDOWS\System32\actmovier.exe (Microsoft Corporation)
SRV - (ImapiService License) – C:\WINDOWS\System32\alf2cdp.exe (Microsoft Corporation)
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (CrypKey (Canada) Ltd.)


========== Driver Services (SafeList) ==========

DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdguard.sys (COMODO)
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files\CyberLink\PowerDVD8\000.fcl (Cyberlink Corp.)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (NSTATION) – C:\WINDOWS\system32\drivers\nstation.sys (TASCAM)
DRV - (EWAVE) – C:\WINDOWS\system32\drivers\ew.sys (TASCAM)
DRV - (FILESPY) – C:\WINDOWS\system32\drivers\filespy.sys (TASCAM)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (DSproct) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (MA_CMIDI) – C:\WINDOWS\system32\drivers\ma_cmidi.sys (M-Audio)
DRV - (CLEDX) – C:\WINDOWS\system32\drivers\cledx.sys (Team H2O)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8080

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}:2.3.50
FF - prefs.js..extensions.enabledItems: {8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}:0.15
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071301000019


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/28 20:52:01 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/28 20:52:00 | 00,000,000 | —D | M]

[2008/04/03 15:54:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Extensions
[2009/12/31 22:24:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions
[2009/12/28 18:48:01 | 00,000,000 | —D | M] (Session Manager) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}(2)
[2009/09/23 11:58:53 | 00,000,000 | —D | M] (ScrapBook) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2009/12/28 18:47:08 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{54BB9F3F-07E5-486c-9B39-C7398B99391C}(2)
[2009/11/10 14:31:08 | 00,000,000 | —D | M] (CacheViewer) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}
[2009/11/10 14:31:08 | 00,000,000 | —D | M] (Live HTTP Headers) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2009/12/28 18:48:02 | 00,000,000 | —D | M] (WOT) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)
[2009/12/28 18:48:02 | 00,000,000 | —D | M] (ReminderFox) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}(2)
[2009/12/28 18:47:59 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}(2)
[2009/12/28 18:47:59 | 00,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2009/09/23 11:58:43 | 00,000,000 | —D | M] (Answers) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2009/09/23 11:58:43 | 00,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/12/28 18:48:00 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{dc572301-7619-498c-a57d-39143191b318}(2)
[2009/12/28 18:48:04 | 00,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(2)
[2009/12/28 18:48:20 | 00,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(2)
[2009/01/11 15:46:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]
[2009/11/10 14:31:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]
[2009/06/01 15:28:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]
[2009/12/28 18:48:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\piclens@cooliris(2).com
[2009/12/28 18:48:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\tineye@ideeinc(2).com
[2009/12/28 18:48:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\TooManyTabs@visibotech(2).com
[2009/09/24 12:13:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]
[2008/10/06 17:37:47 | 00,000,523 | —- | M] () – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\searchplugins\daemon-search.xml
[2009/12/31 22:24:34 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/01/23 00:20:30 | 00,491,520 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2008/11/04 20:29:17 | 00,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll

O1 HOSTS File: (736 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll (BitComet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; All by Gigaget - C:\Program Files\Giganology\Gigaget\getAllurl.htm ()
O8 - Extra context menu item: &Download; by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll (BitComet)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} http://www.pcpitstop.com/internet/pcpConnCheck.cab (iCC Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1236730104656 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} http://myitlab.pearsoned.com/Pegasus/Modul…ces/ax/stub.cab (Enlite 2.x Simulation Engine Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (logon.exe) - C:\WINDOWS\System32\logon.exe ()
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Common Files\svchost.exe) - C:\Program Files\Common Files\svchost.exe File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{19373339-5531-11de-9e60-0019b977261c}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{19373339-5531-11de-9e60-0019b977261c}\Shell\Explore\command - "" = autorun.exe
O33 - MountPoints2\{19373339-5531-11de-9e60-0019b977261c}\Shell\Open\command - "" = autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/01 19:04:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\eBay
[2010/01/01 19:01:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\scanners
[2010/01/01 02:47:13 | 00,000,000 | —D | C] – C:\Program Files\EF CheckSum Manager
[2009/12/31 18:24:20 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\Mirror's Edge
[2009/12/28 18:52:04 | 00,000,000 | RH-D | C] – C:\Documents and Settings\Jason\Recent
[2009/12/28 18:50:31 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/12/28 18:45:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\Simon & Garfunkel
[2009/12/28 18:45:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\Season 3
[2009/12/28 18:45:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\Fatboy Slim - The Greatest Hits - Why Try Harder - 2006
[2009/12/28 18:45:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\SOS
[2009/12/28 18:45:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\Panda Bear
[2009/12/28 18:45:39 | 00,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2009/12/28 18:12:51 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/12/26 16:39:52 | 00,000,000 | —D | C] – C:\Malwarebytes' Anti-Malware
[2009/12/26 16:27:01 | 00,000,000 | —D | C] – C:\Anti-Malware Programs
[2009/12/26 00:12:32 | 00,000,000 | —D | C] – C:\Program Files\PowerISO
[2009/12/26 00:12:16 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\PowerISO
[2009/12/25 03:03:25 | 00,000,000 | —D | C] – C:\$WIN_NT$.~BT
[2009/12/25 02:34:11 | 00,000,000 | —D | C] – C:\Program Files\WinISO
[2009/12/25 02:33:28 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\WinISO_5.3
[2009/12/25 02:04:07 | 00,000,000 | —D | C] – C:\Program Files\Cobian Backup 9
[2009/12/25 02:01:03 | 00,000,000 | —D | C] – C:\Program Files\EASEUS
[2009/12/17 00:48:38 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Application Data\Plogue
[2009/12/17 00:48:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Application Data\Plogue Art et Technologie, Inc
[2009/12/08 23:05:23 | 00,000,000 | —D | C] – C:\Program Files\Lavalys
[2009/12/04 23:52:28 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/12/04 23:39:50 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2009/08/20 14:23:21 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/08/20 14:23:21 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/08/20 14:23:20 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/08/20 14:23:20 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/01 19:31:49 | 00,528,784 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/01/01 19:31:49 | 00,446,438 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/01/01 19:31:49 | 00,073,226 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/01/01 19:27:33 | 00,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4278838382-2642953312-2933363751-1006.job
[2010/01/01 19:27:33 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/01 19:27:25 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/01 19:27:22 | 10,721,03424 | -HS- | M] () – C:\hiberfil.sys
[2010/01/01 18:55:05 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part18.rar
[2010/01/01 18:52:47 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part17.rar
[2010/01/01 18:36:03 | 11,010,048 | —- | M] () – C:\Documents and Settings\Jason\ntuser.dat
[2010/01/01 18:26:32 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part19.rar
[2010/01/01 17:05:43 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part15.rar
[2010/01/01 16:43:21 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part16.rar
[2010/01/01 04:33:11 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Jason\ntuser.ini
[2010/01/01 04:01:28 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part14.rar
[2010/01/01 01:33:54 | 12,082,4195 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Anvil.The.Story.Of.Anvil.2008.DVDRip.XviD.part4.rar
[2010/01/01 00:51:09 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part13.rar
[2010/01/01 00:05:02 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part12.rar
[2009/12/31 23:46:47 | 20,971,5201 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Anvil.The.Story.Of.Anvil.2008.DVDRip.XviD.part3.rar
[2009/12/31 23:27:34 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part11.rar
[2009/12/31 22:50:42 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part10.rar
[2009/12/31 22:24:09 | 00,000,048 | —- | M] () – C:\WINDOWS\System32\w3data.vss
[2009/12/31 22:24:09 | 00,000,048 | —- | M] () – C:\WINDOWS\System32\msvcsv60.dll
[2009/12/31 22:24:09 | 00,000,048 | —- | M] () – C:\WINDOWS\msocreg32.dat
[2009/12/31 21:26:17 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part09.rar
[2009/12/31 18:09:12 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part08.rar
[2009/12/31 17:31:16 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part07.rar
[2009/12/31 16:53:32 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part06.rar
[2009/12/31 16:18:10 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part05.rar
[2009/12/31 13:35:45 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part04.rar
[2009/12/31 12:59:04 | 00,000,433 | –S- | M] () – C:\WINDOWS\System32\504267629.dat
[2009/12/31 03:11:48 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part03.rar
[2009/12/31 02:22:47 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part02.rar
[2009/12/30 23:01:25 | 10,043,1872 | —- | M] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part01.rar
[2009/12/29 23:16:08 | 00,006,534 | —- | M] () – C:\Documents and Settings\Jason\Application Data\wklnhst.dat
[2009/12/28 20:52:04 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/12/28 18:43:54 | 00,000,623 | —- | M] () – C:\WINDOWS\win.ini
[2009/12/28 18:43:54 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/12/28 00:53:08 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/12/26 23:35:08 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\jofasatu
[2009/12/26 13:53:36 | 00,034,308 | -H– | M] () – C:\WINDOWS\System32\logon.exe
[2009/12/25 03:31:57 | 00,001,420 | -H– | M] () – C:\WINDOWS\EPMBatch.ept
[2009/12/21 17:14:06 | 00,004,727 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Intel eBay.rtf
[2009/12/21 17:06:10 | 00,004,926 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Corsair eBay.rtf
[2009/12/15 02:31:40 | 00,435,582 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Dancing Choose cover.mp3
[2009/12/15 00:13:00 | 00,723,974 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Crowns.mp3
[2009/12/11 21:32:48 | 00,435,582 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Dancing Choose cover (piano).mp3
[2009/12/05 04:34:46 | 10,436,8477 | —- | M] () – C:\Documents and Settings\Jason\Desktop\michael_franti__spearhead_-_stay_human_2001.rar
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/01 18:35:23 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part18.rar
[2010/01/01 18:07:00 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part19.rar
[2010/01/01 17:54:45 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part17.rar
[2010/01/01 16:44:10 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part15.rar
[2010/01/01 16:21:25 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part16.rar
[2010/01/01 03:47:55 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part14.rar
[2010/01/01 00:53:09 | 12,082,4195 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Anvil.The.Story.Of.Anvil.2008.DVDRip.XviD.part4.rar
[2010/01/01 00:37:45 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part13.rar
[2009/12/31 23:51:25 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part12.rar
[2009/12/31 23:14:14 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part11.rar
[2009/12/31 22:37:23 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part10.rar
[2009/12/31 22:36:00 | 20,971,5201 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Anvil.The.Story.Of.Anvil.2008.DVDRip.XviD.part3.rar
[2009/12/31 22:18:33 | 01,245,121 | —- | C] () – C:\Documents and Settings\Jason\Desktop\B-MirPhi.part04.rar
[2009/12/31 22:18:21 | 05,000,000 | —- | C] () – C:\Documents and Settings\Jason\Desktop\B-MirPhi.part03.rar
[2009/12/31 22:18:06 | 05,000,000 | —- | C] () – C:\Documents and Settings\Jason\Desktop\B-MirPhi.part02.rar
[2009/12/31 22:17:58 | 05,000,000 | —- | C] () – C:\Documents and Settings\Jason\Desktop\B-MirPhi.part01.rar
[2009/12/31 22:17:58 | 00,010,496 | —- | C] () – C:\Documents and Settings\Jason\Desktop\BEAT.nfo
[2009/12/31 22:17:58 | 00,001,410 | —- | C] () – C:\Documents and Settings\Jason\Desktop\file_id.diz
[2009/12/31 21:12:48 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part09.rar
[2009/12/31 17:55:40 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part08.rar
[2009/12/31 17:17:46 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part07.rar
[2009/12/31 16:40:18 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part06.rar
[2009/12/31 16:04:18 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part05.rar
[2009/12/31 13:10:34 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part04.rar
[2009/12/31 02:57:52 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part03.rar
[2009/12/31 02:09:16 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part02.rar
[2009/12/30 22:47:53 | 10,043,1872 | —- | C] () – C:\Documents and Settings\Jason\Desktop\XLNAAD.part01.rar
[2009/12/28 20:41:36 | 00,034,308 | -H– | C] () – C:\WINDOWS\System32\logon.exe
[2009/12/28 18:55:54 | 10,721,03424 | -HS- | C] () – C:\hiberfil.sys
[2009/12/25 03:25:44 | 00,250,032 | —- | C] () – C:\Documents and Settings\Jason\Desktop\NTLDR
[2009/12/25 02:19:23 | 00,001,420 | -H– | C] () – C:\WINDOWS\EPMBatch.ept
[2009/12/21 15:39:10 | 00,004,727 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Intel eBay.rtf
[2009/12/21 14:50:46 | 00,004,926 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Corsair eBay.rtf
[2009/12/15 00:05:25 | 00,723,974 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Crowns.mp3
[2009/12/12 03:36:01 | 00,435,582 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Dancing Choose cover.mp3
[2009/12/11 21:16:48 | 00,435,582 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Dancing Choose cover (piano).mp3
[2009/12/05 04:35:23 | 05,034,552 | —- | C] () – C:\Documents and Settings\Jason\Desktop\05 Rock The Nation.mp3
[2009/12/05 04:30:46 | 10,436,8477 | —- | C] () – C:\Documents and Settings\Jason\Desktop\michael_franti__spearhead_-_stay_human_2001.rar
[2009/11/01 16:47:25 | 00,002,352 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/10/19 20:21:54 | 00,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/10/19 20:21:54 | 00,000,205 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2009/10/17 18:15:17 | 00,473,600 | —- | C] () – C:\WINDOWS\System32\Harmony.dll
[2009/10/17 18:15:17 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\Unlha32.dll
[2009/10/13 00:57:21 | 00,000,000 | —- | C] () – C:\WINDOWS\braid.ini
[2009/10/13 00:29:54 | 00,000,000 | —- | C] () – C:\WINDOWS\redsky.ini
[2009/10/12 22:49:12 | 00,000,000 | —- | C] () – C:\WINDOWS\Hot air balloon.ini
[2009/10/03 17:47:41 | 00,000,064 | —- | C] () – C:\WINDOWS\minitab.ini
[2009/05/30 21:54:02 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/05/27 21:59:17 | 00,000,110 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/05/21 23:01:13 | 00,000,048 | —- | C] () – C:\WINDOWS\System32\msvcsv60.dll
[2009/05/06 17:12:10 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\utilpt32.dll
[2009/04/23 15:35:45 | 00,000,600 | —- | C] () – C:\Documents and Settings\Jason\Application Data\winscp.rnd
[2009/04/23 15:33:25 | 00,020,811 | —- | C] () – C:\WINDOWS\System32\drivers\IPFWHook.sys
[2009/01/23 16:47:21 | 00,147,192 | —- | C] () – C:\WINDOWS\System32\guard32.dll
[2009/01/18 19:50:39 | 00,000,250 | —- | C] () – C:\WINDOWS\gmer.ini
[2009/01/18 19:50:37 | 00,884,736 | —- | C] () – C:\WINDOWS\gmer.dll
[2008/12/17 17:43:13 | 00,000,604 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\T2
[2008/12/17 17:43:13 | 00,000,604 | -H– | C] () – C:\Program Files\STLL Notifier
[2008/12/05 00:59:09 | 00,000,144 | —- | C] () – C:\WINDOWS\Eudcedit.ini
[2008/11/11 22:39:36 | 00,000,626 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/11/04 21:03:34 | 00,000,000 | —- | C] () – C:\Documents and Settings\Jason\Application Data\AVSDVDPlayer.m3u
[2008/10/29 15:38:43 | 00,000,077 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2008/10/29 15:38:37 | 00,028,518 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2008/10/29 15:38:32 | 00,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2008/10/20 14:13:58 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/10/06 17:27:05 | 00,717,296 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/10/01 16:29:56 | 00,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/10/01 16:29:56 | 00,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/10/01 16:29:54 | 00,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/10/01 16:29:53 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/10/01 16:29:53 | 00,084,480 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/10/01 16:29:53 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/08/20 23:40:33 | 00,000,111 | —- | C] () – C:\WINDOWS\Sansa Media Converter.INI
[2008/08/08 13:49:18 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/06/10 18:07:20 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/06/10 18:03:26 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/06/10 18:03:26 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/06/08 23:05:29 | 02,463,976 | —- | C] () – C:\WINDOWS\System32\NPSWF32.dll
[2008/05/22 16:18:54 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/04/29 20:19:19 | 00,104,448 | —- | C] () – C:\Documents and Settings\Jason\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/04/05 00:05:19 | 00,006,534 | —- | C] () – C:\Documents and Settings\Jason\Application Data\wklnhst.dat
[2008/04/03 19:53:30 | 00,029,696 | —- | C] () – C:\WINDOWS\System32\asutl8.dll
[2008/04/02 20:20:01 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/04/02 19:51:03 | 00,000,128 | —- | C] () – C:\Documents and Settings\Jason\Local Settings\Application Data\fusioncache.dat
[2008/04/02 19:45:36 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/04/02 19:41:08 | 00,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2008/04/02 19:35:01 | 00,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/02 19:27:48 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/04/02 19:27:46 | 00,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/04/01 08:41:01 | 00,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/04/01 08:39:37 | 00,001,121 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2008/01/09 15:01:48 | 00,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2004/08/10 13:12:05 | 00,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:51:26 | 00,006,672 | —- | C] () – C:\WINDOWS\System32\advpack.dllb.dat
[2004/08/10 12:51:10 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\kvv30ra.dll
[2004/08/10 12:51:10 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\clauth2.dll
[2004/08/10 12:51:10 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\clauth1.dll
[2004/08/10 12:51:10 | 00,000,339 | —- | C] () – C:\WINDOWS\System32\ol0cli9.dll
[2004/08/10 12:51:10 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\prsgrc.dll
[2004/08/10 12:51:10 | 00,000,072 | —- | C] () – C:\WINDOWS\System32\ssprs.dll
[2004/08/10 12:51:10 | 00,000,016 | -H– | C] () – C:\WINDOWS\System32\or4syj8.dll
[2004/08/10 12:51:06 | 00,025,308 | -H– | C] () – C:\Documents and Settings\Jason\Application Data\windows.dat
[2003/11/16 03:48:02 | 00,909,312 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2003/11/16 03:48:00 | 01,060,864 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2003/11/15 10:54:18 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/10/06 16:42:58 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll

========== LOP Check ==========

[2009/10/24 14:14:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2009/08/18 03:33:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Audio Ease
[2009/05/17 19:11:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cakewalk
[2009/08/05 18:51:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Celemony Software GmbH
[2009/12/04 23:39:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2008/06/02 20:17:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Last.fm
[2009/03/03 13:59:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\myitlab
[2009/07/12 02:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/11/01 16:58:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2009/05/07 21:28:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2009/10/19 20:25:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2009/06/11 14:34:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/10/19 20:22:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SPSS
[2009/10/12 23:32:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2009/12/27 01:03:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/07 23:46:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tiffen
[2009/05/27 21:59:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/06/04 17:42:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VertusTech
[2008/04/02 19:34:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/07/07 23:44:37 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{3DDB0D6A-2256-4D46-A1A3-C97907A49312}
[2009/08/27 15:20:39 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{8E4DC1D0-364F-4942-85CD-BCD7298D633E}
[2009/08/27 15:23:29 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{A7689876-F0D2-4DC6-9C70-CA306AA80853}
[2009/11/15 15:22:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\.purple
[2009/10/24 14:15:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\acccore
[2009/07/14 01:24:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Antares
[2008/04/03 19:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Anvil Studio
[2009/08/18 03:33:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Audio Ease
[2009/07/29 21:54:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Braid
[2009/05/17 22:19:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Cakewalk
[2008/04/03 23:24:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\CoreCodec
[2009/04/23 15:42:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\CoreFTP
[2008/10/06 17:27:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\DAEMON Tools
[2008/08/18 17:12:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\FLV Extract
[2009/07/22 18:53:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\GrabIt
[2009/03/11 15:36:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\IrfanView
[2009/07/16 16:20:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Moyea
[2008/07/19 22:40:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\NetMedia Providers
[2008/04/15 20:26:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Notepad++
[2008/05/16 18:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Opera
[2009/12/17 00:48:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Plogue
[2009/12/17 00:48:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Plogue Art et Technologie, Inc
[2009/05/07 22:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Propellerhead Software
[2008/07/19 22:40:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Publish Providers
[2008/04/03 19:49:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Renegade Minds
[2009/06/12 00:42:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Sony
[2009/06/11 14:55:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Sony Setup
[2009/04/23 15:29:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\SSH
[2009/05/25 22:15:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Steinberg
[2008/04/05 00:05:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Template
[2008/12/01 00:08:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Thomson Learning
[2009/07/07 23:48:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Tiffen
[2009/05/27 21:59:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Ulead Systems
[2009/08/18 01:56:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\uTorrent
[2009/12/01 14:26:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\VitySoft
[2009/05/27 17:53:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
< End of report >
Hi Nift,

You are still infected. I do not see an antivirus program installed.

You have a program installed that may cause problems with some of the tools. We need to dosable the drivers temporarily.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1
Link 2
to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
Followed all of your instructions. Everything is still running smoothly as far as I can tell. Here is the ComboFix log:



ComboFix 10-01-02.01 - Jason 01/02/2010 16:21:42.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.515 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\1031c.exe
c:\windows\system32\504267629.dat
c:\windows\system32\actmovier.exe
c:\windows\system32\adsmsexto.exe
c:\windows\system32\advapi32l.dat
c:\windows\system32\advpack.dllu.exe
c:\windows\system32\images
c:\windows\system32\images\toolbar\calendar.gif
c:\windows\system32\images\toolbar\crlogo.gif
c:\windows\system32\images\toolbar\export.gif
c:\windows\system32\images\toolbar\export_over.gif
c:\windows\system32\images\toolbar\exportd.gif
c:\windows\system32\images\toolbar\First.gif
c:\windows\system32\images\toolbar\first_over.gif
c:\windows\system32\images\toolbar\Firstd.gif
c:\windows\system32\images\toolbar\gotopage.gif
c:\windows\system32\images\toolbar\gotopage_over.gif
c:\windows\system32\images\toolbar\gotopaged.gif
c:\windows\system32\images\toolbar\grouptree.gif
c:\windows\system32\images\toolbar\grouptree_over.gif
c:\windows\system32\images\toolbar\grouptreed.gif
c:\windows\system32\images\toolbar\grouptreepressed.gif
c:\windows\system32\images\toolbar\Last.gif
c:\windows\system32\images\toolbar\last_over.gif
c:\windows\system32\images\toolbar\Lastd.gif
c:\windows\system32\images\toolbar\Next.gif
c:\windows\system32\images\toolbar\next_over.gif
c:\windows\system32\images\toolbar\Nextd.gif
c:\windows\system32\images\toolbar\Prev.gif
c:\windows\system32\images\toolbar\prev_over.gif
c:\windows\system32\images\toolbar\Prevd.gif
c:\windows\system32\images\toolbar\print.gif
c:\windows\system32\images\toolbar\print_over.gif
c:\windows\system32\images\toolbar\printd.gif
c:\windows\system32\images\toolbar\Refresh.gif
c:\windows\system32\images\toolbar\refresh_over.gif
c:\windows\system32\images\toolbar\refreshd.gif
c:\windows\system32\images\toolbar\Search.gif
c:\windows\system32\images\toolbar\search_over.gif
c:\windows\system32\images\toolbar\searchd.gif
c:\windows\system32\images\toolbar\up.gif
c:\windows\system32\images\toolbar\up_over.gif
c:\windows\system32\images\toolbar\upd.gif
c:\windows\system32\images\tree\begindots.gif
c:\windows\system32\images\tree\beginminus.gif
c:\windows\system32\images\tree\beginplus.gif
c:\windows\system32\images\tree\blank.gif
c:\windows\system32\images\tree\blankdots.gif
c:\windows\system32\images\tree\dots.gif
c:\windows\system32\images\tree\lastdots.gif
c:\windows\system32\images\tree\lastminus.gif
c:\windows\system32\images\tree\lastplus.gif
c:\windows\system32\images\tree\Magnify.gif
c:\windows\system32\images\tree\minus.gif
c:\windows\system32\images\tree\minusbox.gif
c:\windows\system32\images\tree\plus.gif
c:\windows\system32\images\tree\plusbox.gif
c:\windows\system32\images\tree\singleminus.gif
c:\windows\system32\images\tree\singleplus.gif
c:\windows\system32\inf
c:\windows\system32\inf\MA_CMIDI.INF
c:\windows\system32\logon.exe
c:\windows\system32\lsprst7.dll
c:\windows\system32\msvcsv60.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ASPNET_STATEAUDIOSRV
——-\Legacy_SECLOGONUPS
——-\Legacy_SENSRPCSS
——-\Legacy_SWPRVSHELLHWDETECTION
——-\Service_aspnet_stateAudioSrv
——-\Service_seclogonUPS
——-\Service_SENSRpcSs
——-\Service_SwPrvShellHWDetection


((((((((((((((((((((((((( Files Created from 2009-12-02 to 2010-01-02 )))))))))))))))))))))))))))))))
.

2010-01-02 22:36 . 2010-01-02 22:36 32 –s-a-w- c:\windows\system32\4003333767.dat
2010-01-01 08:47 . 2010-01-01 08:47 ——– d—–w- c:\program files\EF CheckSum Manager
2009-12-29 00:53 . 2009-12-29 00:53 ——– d—–w- c:\windows\system32\wbem\Repository
2009-12-29 00:50 . 2009-12-29 00:50 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-29 00:45 . 2009-12-29 00:46 ——– d–h–w- c:\windows\msdownld.tmp
2009-12-29 00:12 . 2009-12-29 00:45 ——– d—–w- c:\program files\ERUNT
2009-12-27 07:03 . 2009-12-27 07:03 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-12-26 22:39 . 2009-12-29 00:46 ——– d—–w- C:\Malwarebytes' Anti-Malware
2009-12-26 22:27 . 2009-12-29 00:46 ——– d—–w- C:\Anti-Malware Programs
2009-12-26 06:12 . 2009-12-29 00:46 ——– d—–w- c:\program files\PowerISO
2009-12-25 09:03 . 2009-12-25 09:03 ——– d—–w- C:\$WIN_NT$.~BT
2009-12-25 08:34 . 2009-12-29 00:46 ——– d—–w- c:\program files\WinISO
2009-12-25 08:04 . 2009-12-29 00:46 ——– d—–w- c:\program files\Cobian Backup 9
2009-12-25 08:01 . 2009-12-25 08:01 ——– d—–w- c:\program files\EASEUS
2009-12-17 06:48 . 2009-12-17 06:48 ——– d—–w- c:\documents and settings\Jason\Application Data\Plogue
2009-12-17 06:48 . 2009-12-17 06:48 ——– d—–w- c:\documents and settings\Jason\Application Data\Plogue Art et Technologie, Inc
2009-12-09 05:05 . 2009-12-09 05:05 ——– d—–w- c:\program files\Lavalys
2009-12-05 05:39 . 2009-12-05 05:39 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-02 22:36 . 2009-01-23 22:47 ——– d—–w- c:\program files\COMODO
2010-01-02 06:25 . 2009-05-10 20:11 ——– d—–w- c:\program files\Everything
2010-01-01 22:25 . 2009-05-22 04:57 ——– d—–w- c:\program files\IK Multimedia
2010-01-01 05:48 . 2008-04-03 01:30 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-01 05:48 . 2008-10-30 00:12 ——– d—–w- c:\program files\Vstplugins
2010-01-01 04:24 . 2009-05-22 05:01 48 —-a-w- c:\windows\msocreg32.dat
2009-12-30 05:16 . 2008-04-05 06:05 6534 —-a-w- c:\documents and settings\Jason\Application Data\wklnhst.dat
2009-12-29 00:53 . 2009-11-20 20:43 ——– d—–w- c:\program files\UltraVPN
2009-12-29 00:50 . 2009-12-01 20:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware(2)
2009-12-27 07:03 . 2009-10-24 20:39 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-27 07:03 . 2008-05-01 21:56 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-23 10:07 . 2008-07-11 03:48 ——– d—–w- c:\program files\Zoom Player
2009-12-15 05:14 . 2009-07-16 02:00 ——– d—–w- c:\program files\MusicLab
2009-12-02 05:41 . 2009-05-06 23:12 ——– d—–w- c:\program files\Translator
2009-12-01 20:26 . 2009-12-01 20:26 ——– d—–w- c:\documents and settings\Jason\Application Data\VitySoft
2009-11-20 05:19 . 2008-04-28 05:18 ——– d—–w- c:\documents and settings\Jason\Application Data\OpenOffice.org2
2009-11-15 21:22 . 2009-10-24 20:06 ——– d—–w- c:\documents and settings\Jason\Application Data\.purple
2009-11-14 00:25 . 2009-11-14 00:25 ——– d—–w- c:\program files\WorldOfGoo
2009-11-02 01:09 . 2008-04-03 02:21 102904 —-a-w- c:\documents and settings\Jason\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-02 01:05 . 2009-11-01 22:47 2352 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-10-20 02:21 . 2009-10-20 02:21 1025 —-a-w- c:\windows\system32\sysprs7.dll
2008-12-17 23:43 . 2008-12-17 23:43 604 —ha-w- c:\program files\STLL Notifier
2004-08-04 11:00 . 2004-08-10 18:51 61952 –sh–r- c:\windows\system32\alf2cdp.exe
2006-05-03 09:06 . 2008-08-18 23:17 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2008-08-18 23:17 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2008-08-18 23:17 216064 –sh–r- c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-22 1392640]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"Midi1"=gmidi.dll
"Midi2"=MYokeNT.DLL
"midi3"=ma_cmidn.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 12:58 611712 —-a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2007-03-01 04:06 2321600 —-a-w- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2009-10-01 20:20 3634024 —-a-w- c:\program files\AIM\aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2008-05-19 21:24 91432 —-a-w- c:\program files\CyberLink\Shared Files\brs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
2004-02-19 11:23 61440 —-a-w- c:\dell\bldbubg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-08-08 12:11 490952 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
2007-02-20 17:29 1191936 —-a-w- c:\program files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2006-08-29 02:57 395776 —-a-w- c:\program files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EW Message Server]
2006-12-10 07:08 45056 —-a-w- c:\windows\system32\msg32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-04-30 03:36 133104 —-atw- c:\documents and settings\Jason\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 06:47 31016 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
2005-10-23 05:00 385024 —-a-w- c:\program files\Syncrosoft\POS\H2O\cledx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-05-02 23:16 184320 ——w- c:\program files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
2007-12-14 17:36 50472 ——w- c:\program files\CyberLink\PowerDVD8\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 21:18 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
2008-03-21 02:23 83240 ——w- c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2009-10-13 02:24 2000112 —-a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wltrysvc"=3 (0x3)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"aawservice"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"PCTAVSvc"=2 (0x2)
"gusvc"=3 (0x3)
"sdCoreService"=3 (0x3)
"sdAuxService"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\SPSSInc\\SPSS16\\spss.exe"=
"c:\\Program Files\\SPSSInc\\SPSS16\\spss.com"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.com"=
"c:\\Program Files\\SPSSInc\\Statistics17\\SPSSWinWrapIDE.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Pidgin\\pidgin.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24162:TCP"= 24162:TCP:BitComet 24162 TCP
"24162:UDP"= 24162:UDP:BitComet 24162 UDP
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 8:24 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 8:24 PM 74480]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [5/15/2008 12:07 PM 61424]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [10/29/2008 10:04 PM 33792]
S2 ImapiService License;IMAPI CD-Burning COM Service ImapiService License;c:\windows\system32\alf2cdp.exe srv –> c:\windows\system32\alf2cdp.exe srv [?]
S3 EWAVE;EWAVE;c:\windows\system32\drivers\ew.sys [12/23/2008 2:55 PM 1447040]
S3 FILESPY;FILESPY;c:\windows\system32\drivers\filespy.sys [12/23/2008 2:55 PM 26992]
S3 NSTATION;NSTATION;c:\windows\system32\drivers\nstation.sys [12/23/2008 2:55 PM 18944]
S3 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE –> c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE [?]
S3 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE [2/1/2006 11:49 PM 204800]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 8:24 PM 7408]
S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE –> c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/6/2008 5:27 PM 717296]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{84CEDF98-9A75-46F8-CC0C-66D1A49FCD5B}]
2007-06-13 10:23 110173 —h–w- c:\program files\Java\jar.exe
.
Contents of the 'Scheduled Tasks' folder

2010-01-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4278838382-2642953312-2933363751-1006.job
- c:\documents and settings\Jason\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-30 03:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyServer = 127.0.0.1:8080
IE: &Download All by Gigaget - c:\program files\Giganology\Gigaget\getallurl.htm
IE: &Download by Gigaget - c:\program files\Giganology\Gigaget\geturl.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071301000019.dll
FF - plugin: c:\documents and settings\Jason\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - false.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-COMODO Internet Security - c:\program files\COMODO\COMODO Internet Security\cfp.exe
MSConfigStartUp-ModemOnHold - c:\program files\NetWaiting\netWaiting.exe
MSConfigStartUp-WD Spindown Utility - c:\program files\Western Digital Technologies\Spindown\ExSpinDn.exe
ActiveSetup-{Y101Y238-S37I-3BV5-F7I2-R5O5YR7RPE2W} - c:\program files\Common Files\svchost.exe
AddRemove-Best Service Chris Hein - Guitars - f:\progra~1\BESTSE~1\CHRISH~1\UNWISE.EXE
AddRemove-Best Service Chris Hein Bass - f:\progra~1\BESTSE~1\CHRISH~2\UNWISE.EXE
AddRemove-East West Boesendorfer 290 - f:\progra~1\EASTWE~1\BOESEN~1\UNWISE.EXE
AddRemove-East West EWQLSO Gold Edition - f:\progra~1\EASTWE~1\EWQLSO~1\UNWISE.EXE
AddRemove-East West Ra - f:\progra~1\EASTWE~1\Ra\UNWISE.EXE
AddRemove-East West Stormdrum Kompakt - f:\progra~1\EASTWE~1\STORMD~1\UNWISE.EXE
AddRemove-Matroska Pack - c:\program files\Matroska Pack\uninstall.exe
AddRemove-Microsoft Visual Studio 2008 Professional Edition - ENU - f:\program files\Microsoft Visual Studdio 9.0\Microsoft Visual Studio 2008 Professional Edition - ENU\setup.exe
AddRemove-Native Instruments Akoustik Piano - f:\progra~1\NATIVE~1\AKOUST~1\UNWISE.EXE
AddRemove-NI Service Center - f:\progra~1\NATIVE~1\DXi\SERVIC~1\UNWISE.EXE
AddRemove-Vir2 Instruments Acoustic Legends HD - f:\progra~1\VIR2IN~1\ACOUST~1\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-02 16:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

c:\program files\Internet Explorer\iexplore.exe [3048] 0x86D3BDA0

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-4278838382-2642953312-2933363751-1006\Software\Microsoft\Multimedia\D$@€ù‡©*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-4278838382-2642953312-2933363751-1006\Software\Microsoft\Multimedia\*hƒ*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CakewalkPlugIns\d†Ýw€æ*øå**]
"Description"="Cakewal"
"HelpFilePath"=""
"HelpFileTopic"=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{156E5059-1974-1C21-234A49AFACAB4059}\{B90FCDFF-5527-F999-5BDD8AB8903FEB58}\{85FE2661-9FF6-1F38-3936C76FCE54F605}*]
"RA4KGUJC6T6LBNJRIDQ63C2L6C1"=hex:01,00,01,00,00,00,00,00,f7,8a,3d,85,55,45,07,
82,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{91EC4B89-4AF2-1685-8B077627C8A43419}\{2EE609D8-52A7-5ABD-6D921F70AFC106D5}\{F0CB3253-4F19-C88D-A2C81B3BBC751916}*]
"RA4KGUJC6T6LBNJRIDQ63C2L6C1"=hex:01,00,01,00,00,00,00,00,f7,8a,3d,85,55,45,07,
82,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(552)
c:\windows\system32\MYokeNT.DLL
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(608)
c:\windows\system32\MYokeNT.DLL

- - - - - - - > 'explorer.exe'(3488)
c:\windows\system32\MYokeNT.DLL
c:\windows\system32\shdoclc.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
.
**************************************************************************
.
Completion time: 2010-01-02 16:56:34 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-02 22:56
ComboFix2.txt 2009-01-23 00:21

Pre-Run: 11,320,868,864 bytes free
Post-Run: 10,960,846,848 bytes free

- - End Of File - - FE4865C1DE250104871C3935A3495451
Hi Nift,

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    C:\Qoobox\Quarantine\C\windows\system32\msvcsv60.dll

  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Please note that C:\Qoobox\Quarantine\C\windows\system32\msvcsv60.dll is one complete line.

Open windows explorer and navigate to this folder C:\Qoobox
  • Click once on it
  • In the right hand panel, locate this file Add-Remove programs.txt
  • Please post the contents

Pleae post back with
  • VirScan results
  • Add-Remove programs.txt
Thanks
VirSCAN:

VirSCAN.org Scanned Report :
Scanned time : 2010/01/02 19:02:19 (EST)
Scanner results: Scanners did not find malware!
File Name : msvcsv60.dll.vir
File Size : 48 byte
File Type : data
MD5 : d08b9fc57e1da6dc4d2d47d99914b1f6
SHA1 : d6d2d81c93d3bcdc2021b3fc3686a8b51b752130
Online report : http://virscan.org/report/98d63af7dfe39f95…9e94d27b15.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100103060344 2010-01-03 4.28 -
AhnLab V3 2010.01.03.00 2010.01.03 2010-01-03 1.05 -
AntiVir 8.2.1.122 7.10.2.111 2010-01-01 0.49 -
Antiy 2.0.18 20091231.3551759 2009-12-31 0.12 -
Arcavir 2009 201001021256 2010-01-02 0.02 -
Authentium 5.1.1 201001012232 2010-01-01 1.23 -
AVAST! 4.7.4 100102-1 2010-01-02 0.00 -
AVG 8.5.288 270.14.124/2597 2010-01-02 0.30 -
BitDefender 7.81008.4810142 7.29713 2010-01-03 4.08 -
CA (VET) 35.1.0 7209 2009-12-31 8.16 -
ClamAV 0.95.2 10246 2010-01-01 0.00 -
Comodo 3.13.579 3409 2010-01-02 0.92 -
CP Secure 1.3.0.5 2009.12.31 2009-12-31 0.01 -
Dr.Web 4.44.0.9170 2009.12.29 2009-12-29 8.21 -
F-Prot 4.4.4.56 20100101 2010-01-01 1.22 -
F-Secure 7.02.73807 2010.01.02.01 2010-01-02 0.05 -
Fortinet 11.336- 11.336 2010-01-02 0.19 -
GData 19.9698/19.656 20100102 2010-01-02 5.91 -
ViRobot 20091231 2009.12.31 2009-12-31 0.43 -
Ikarus T3.1.01.79 2010.01.02.74879 2010-01-02 4.20 -
JiangMin 13.0.900 2010.01.02 2010-01-02 15.05 -
Kaspersky 5.5.10 2010.01.02 2010-01-02 0.03 -
KingSoft 2009.2.5.15 2010.1.2.20 2010-01-02 0.73 -
McAfee 5.3.00 5849 2010-01-02 3.33 -
Microsoft 1.5302 2010.01.02 2010-01-02 7.69 -
Norman 6.01.09 6.01.00 2009-12-31 2.00 -
Panda 9.05.01 2010.01.02 2010-01-02 2.72 -
Trend Micro 9.000-1003 6.740.04 2010-01-02 0.02 -
Quick Heal 10.00 2010.01.02 2010-01-02 2.20 -
Rising 20.0 22.28.03.04 2009-12-31 0.36 -
Sophos 3.03.0 4.49 2010-01-03 2.85 -
Sunbelt 3.9.2388.2 5595 2010-01-02 2.50 -
Symantec 1.3.0.24 20091231.017 2009-12-31 0.26 -
nProtect 20091230.01 6747377 2009-12-30 4.91 -
The Hacker [removed] v00126 2010-01-02 1.48 -
VBA32 3.12.12.1 20100101.1056 2010-01-01 2.28 -
VirusBuster 4.5.11.10 10.118.17/2016664 2010-01-03 2.37 -







Add-Remove Programs.txt:

Sansa Media Converter
µTorrent
4Front Bass Module 1.0 VSTi
4Front E-Piano Module 1.0 VSTi
4Front Piano Module 1.0 VSTi
7-Zip 4.64
Addictive Drums
Adobe AIR
Adobe Anchor Service CS3
Adobe Anchor Service CS4
Adobe Asset Services CS3
Adobe Audition 1.5
Adobe Audition 3.0
Adobe Audition 3.0.1 Patch
Adobe Bridge 1.0
Adobe Bridge CS3
Adobe Bridge CS4
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps CS4
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Common File Installer
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS3
Adobe Device Central CS4
Adobe Dreamweaver CS4
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash CS3
Adobe Flash CS3 Professional
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Video Encoder
Adobe Fonts All
Adobe Help Center 1.0
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe Linguistics CS3
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS2
Adobe Premiere Pro CS3
Adobe Premiere Pro CS3 Functional Content
Adobe Premiere Pro CS3 Third Party Content
Adobe Reader 7.0.8
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Shockwave Player
Adobe Stock Photos 1.0
Adobe Stock Photos CS3
Adobe Type Support CS4
Adobe Update Manager CS3
Adobe Update Manager CS4
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP DVA Panels CS3
Adobe XMP Panels CS3
Adobe XMP Panels CS4
AIM 7
Anvil Studio
AOLIcon
Apple Software Update
ASIO4ALL
ATI Catalyst Control Center
ATI Display Driver
Audacity 1.2.6
AudioEase Altiverb VST RTAS v6.10
AutoUpdate
Best Service Chris Hein - Guitars
Best Service Chris Hein Bass
BitComet 1.02
braid
Broadcom Management Programs
Camtasia Studio 6
Chicken Systems Translator v2.9.5.8
Conexant HDA D110 MDC V.92 Modem
Connect
Crystal Reports Basic for Visual Studio 2008
CSR
CyberLink PowerDVD 8
DAEMON Tools Toolbar
dBpoweramp DSP Effects
dBpoweramp m4a Codec
dBpoweramp Music Converter
DC++ 0.7091
Dell Support 3.2.1
Dell Wireless WLAN Card
Dfx
Diet Analysis Plus 8.0
Digital Line Detect
DivX Codec
DivX Converter
DivX Player
DivX Web Player
Documentation & Support Launcher
Download Updater (AOL LLC)
DreamStation DXi2
DVD Decrypter (Remove Only)
East West Boesendorfer 290
East West EWQLSO Gold Edition
East West Ra
East West Stormdrum Kompakt
EF CheckSum Manager
Everything 1.2.0.323
Extreme Sample Converter v3.5.3
ffdshow [rev 2946] [2009-05-15]
FL Studio v7.0
FLV Player 2.0, build 24
Games, Music, & Photos Launcher
Garritan Jazz Big Band
Garritan Personal Orchestra
Gigaget
Google Chrome
GTK+ Runtime 2.14.7 rev a (remove only)
Guitar and Drum Trainer 2
Haali Media Splitter
Heart Of Darkness
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hot air balloon
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB908673)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB934428-v2)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB937930)
InstantStorm 1.5
IrfanView (remove only)
IsoBuster 2.5
Java™ 6 Update 11
K-Lite Codec Pack 4.1.7 (Full)
kuler
Last.fm 1.5.4.24567
MA_CMIDI
Malwarebytes' Anti-Malware
Matroska Pack
MediaDirect
Melodyne 3.2
Microsoft .NET Compact Framework 2.0 SP2
Microsoft .NET Compact Framework 3.5
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Device Emulator version 3.0 - ENU
Microsoft Document Explorer 2008
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Visual Web Developer 2007
Microsoft Office Visual Web Developer MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2000 Sample Database Scripts
Microsoft SQL Server Compact 3.5 Design Tools ENU
Microsoft SQL Server Compact 3.5 ENU
Microsoft SQL Server Compact 3.5 for Devices ENU
Microsoft SQL Server Database Publishing Wizard 1.2
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Visual Studio 2008 Professional Edition - ENU
Microsoft Visual Studio Web Authoring Component
Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
Microsoft Windows SDK for Visual Studio 2008 Tools
Microsoft Windows SDK for Visual Studio 2008 Win32 Tools
Microsoft Works
MIDI Yoke
Minitab 15 English
Miroslav Philharmonik CE
Miroslav Philharmonik Instruments
MKVtoolnix 2.2.0
Modem Helper
Mozilla Firefox (3.5.6)
MSXML 6.0 Parser (KB933579)
Native Instruments Akoustik Piano
Native Instruments Guitar Rig 3
Native Instruments Kontakt 3
Native Instruments Service Center
NI Service Center
Notepad++
Octoshape add-in for Adobe Flash Player
OpenOffice.org 2.4
Oracle Data Provider for .NET Help
Oracle Database 10g Express Edition
PDF Settings
Photoshop Camera Raw
Picasa 3
Pidgin
Project64 1.6
PSPad editor
QuickSet
QuickTime
Real Alternative 1.9.0
Reason 4.0
redsky
rgc:audio sfz VSTi v1.96
RPG Maker 2000 1.05
RTP 1.32 Add-On for RM2k
RTP de RPG Maker 2003
RTP for RM2K (Png, Wav, Midi, Fonts)
Screenblast Movie Studio 3.0
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
sfArk
Sibelius 5
Sibelius Scorch (ActiveX Only)
Sibelius Sounds Essentials
Snagit 9.1
SONAR 8.0 Producer Edition
Sonic DLA
Sony Vegas Pro 8.0
SPSS 16.0
SPSS Statistics 17.0
SSH Secure Shell
Steinberg Cubase SX v3.1.1.944
Steinberg The Grand 2
Steinberg The Grand 2 v2.0.0.1152
Suite Shared Configuration CS4
SUPER © Version 2008.bld.32 (July 8, 2008)
SUPERAntiSpyware Free Edition
Synaptics Pointing Device Driver
Syncrosoft's License Control
SyncroSoft Emu (Remove only)
Tascam GigaStudio v3.21
TBS WMP Plug-in
The Core Media Player 4.0
The KMPlayer (remove only)
Time Adjuster STANDARD 3.1
Trilogy
TruePianos 1.4.1
TruePianos: Amber Module 1.4.0
TruePianos: Diamond Module 1.4.0
TruePianos: Emerald Module 1.4.0
TruePianos: Sapphire Module 1.4.0
Ulead GIF Animator 5
Uninstall DreamSuite Bonus
Update for Windows XP (KB896256)
Update for Windows XP (KB898461)
Update for Windows XP (KB912945)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB946627)
Vertus Fluid Mask 3 3.0.8
Viewpoint Media Player
Vir2 Instruments Acoustic Legends HD
Virtual Sound Canvas DXi
Visual Studio 2005 Tools for Office Second Edition Runtime
Visual Studio Tools for the Office system 3.0 Runtime
VLC media player 0.9.2
VST Bridge 1.1
WebFldrs XP
Winamp
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Mobile 5.0 SDK R2 for Pocket PC
Windows Mobile 5.0 SDK R2 for Smartphone
Windows Presentation Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892627
Windows XP Hotfix - KB893056
WinRAR archiver
WM Capture
Xilisoft Video Converter Ultimate
XML Paper Specification Shared Components Pack 1.0
Zoom Player (remove only)
Hi Nift,


µTorrent and BitComet
You have µTorrent and BitComet, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it. It's not the programs theselvs that are the problem, but what can be downloaded with the, usually from an unknown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm


I would recommend that you uninstall µTorrent and BitComet, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


We will use combofix again but run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

Dequarantine::
C:\Qoobox\Quarantine\C\windows\system32\msvcsv60.dll.vir

Quit::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

A log called DeQuarantine_log.txt should popup when combofix has finished.

Next

Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK

One more scan just to check our handiwork.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Please post back with
  • DeQuarantine_log.txt
  • Kaspersky log
  • new OTL log (there will only be an OTL.txt this time)
Thanks
DeQuarantine log:

C:\Qoobox\Quarantine\C\windows\system32\msvcsv60.dll.vir -> C:\windows\system32\msvcsv60.dll ( 48 bytes )




Kaspersky log
(Sorry about the messy formatting. It was copied from an HTML file.)

KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, January 4, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, January 04, 2010 20:03:47
Records in database: 3355455

Scan settings
scan using the following database extended
Scan archives yes
Scan e-mail databases yes

Scan area My Computer
C:\
D:\

Scan statistics
Objects scanned 223057
Threats found 6
Infected objects found 7
Suspicious objects found 0
Scan duration 06:22:31

File name Threat Threats count
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\6.0\10\630c3e4a-248d4782 Infected: Trojan-Downloader.Java.OpenStream.ad 1
C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K2MX4CW8\marrychristmasforyou[1].htm Infected: Trojan-Downloader.JS.Kazmet.e 1
C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K2MX4CW8\nevpizdy-nenyznie50domain[1].htm Infected: Trojan-Downloader.JS.Kazmet.e 1
C:\Program Files\Java\jar.exe Infected: Trojan.Win32.Agent.cnhi 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\1031c.exe.vir Infected: Trojan.Win32.Monder.gen 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\adsmsexto.exe.vir Infected: Backdoor.Win32.IRCNite.fh 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\_logon_.exe.zip Infected: Trojan.Win32.Vilsel.pqd 1
Selected area has been scanned.




OTL log:
OTL logfile created on: 1/4/2010 8:58:40 PM - Run 3
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Documents and Settings\Jason\Desktop\scanners
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 561.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 51.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.84 Gb Total Space | 9.10 Gb Free Space | 8.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME
Current User Name: Jason
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jason\Local Settings\Temp\jkos-Jason\binaries\ScanningProcess.exe (Kaspersky Lab.)
PRC - C:\Documents and Settings\Jason\Desktop\scanners\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Everything\Everything.exe ()
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe ()
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\WINDOWS\system32\logon.scr (Microsoft Corporation)
PRC - C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Crypserv.exe (CrypKey (Canada) Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jason\Desktop\scanners\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (msvsmon90) – File not found
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Adobe LM Service) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (wltrysvc) – C:\WINDOWS\System32\WLTRYSVC.EXE ()
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Ati HotKey Poller) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
SRV - (OracleXEClrAgent) – C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe ()
SRV - (OracleXETNSListener) – C:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE ()
SRV - (OracleMTSRecoveryService) – C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe (Oracle Corporation)
SRV - (OracleJobSchedulerXE) – c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe ()
SRV - (OracleServiceXE) – c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE (Oracle Corporation)
SRV - (MA_CMIDI_InstallerService) – C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe ()
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ClipSrvdmserver) – C:\WINDOWS\System32\adsldpi.exe ()
SRV - (ImapiService License) – C:\WINDOWS\System32\alf2cdp.exe (Microsoft Corporation)
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (CrypKey (Canada) Ltd.)


========== Driver Services (SafeList) ==========

DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files\CyberLink\PowerDVD8\000.fcl (Cyberlink Corp.)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (NSTATION) – C:\WINDOWS\system32\drivers\nstation.sys (TASCAM)
DRV - (EWAVE) – C:\WINDOWS\system32\drivers\ew.sys (TASCAM)
DRV - (FILESPY) – C:\WINDOWS\system32\drivers\filespy.sys (TASCAM)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (DSproct) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (MA_CMIDI) – C:\WINDOWS\system32\drivers\ma_cmidi.sys (M-Audio)
DRV - (CLEDX) – C:\WINDOWS\system32\drivers\cledx.sys (Team H2O)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8080

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}:2.3.50
FF - prefs.js..extensions.enabledItems: {8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}:0.15
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071301000019
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.7.4
FF - prefs.js..extensions.enabledItems: {54BB9F3F-07E5-486c-9B39-C7398B99391C}:3.1.2009110201
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/28 20:52:01 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/28 20:52:00 | 00,000,000 | —D | M]

[2008/04/03 15:54:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Extensions
[2010/01/01 21:28:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions
[2010/01/01 21:27:52 | 00,000,000 | —D | M] (Session Manager) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2009/12/28 18:48:01 | 00,000,000 | —D | M] (Session Manager) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}(2)
[2009/09/23 11:58:53 | 00,000,000 | —D | M] (ScrapBook) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/01/01 21:27:52 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{54BB9F3F-07E5-486c-9B39-C7398B99391C}
[2009/12/28 18:47:08 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{54BB9F3F-07E5-486c-9B39-C7398B99391C}(2)
[2009/11/10 14:31:08 | 00,000,000 | —D | M] (CacheViewer) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}
[2009/11/10 14:31:08 | 00,000,000 | —D | M] (Live HTTP Headers) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2010/01/01 21:27:52 | 00,000,000 | —D | M] (WOT) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2009/12/28 18:48:02 | 00,000,000 | —D | M] (WOT) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)
[2009/12/28 18:48:02 | 00,000,000 | —D | M] (ReminderFox) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}(2)
[2009/12/28 18:47:59 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}(2)
[2009/12/28 18:47:59 | 00,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2009/09/23 11:58:43 | 00,000,000 | —D | M] (Answers) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2009/09/23 11:58:43 | 00,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/12/28 18:48:00 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{dc572301-7619-498c-a57d-39143191b318}(2)
[2009/12/28 18:48:04 | 00,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(2)
[2009/12/28 18:48:20 | 00,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(2)
[2009/01/11 15:46:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]
[2009/11/10 14:31:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]
[2009/06/01 15:28:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]
[2009/12/28 18:48:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\piclens@cooliris(2).com
[2009/12/28 18:48:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\tineye@ideeinc(2).com
[2009/12/28 18:48:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\TooManyTabs@visibotech(2).com
[2009/09/24 12:13:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]
[2008/10/06 17:37:47 | 00,000,523 | —- | M] () – C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\searchplugins\daemon-search.xml
[2010/01/04 01:29:46 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/01/23 00:20:30 | 00,491,520 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2008/11/04 20:29:17 | 00,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll (BitComet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; All by Gigaget - C:\Program Files\Giganology\Gigaget\getAllurl.htm ()
O8 - Extra context menu item: &Download; by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll (BitComet)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} http://www.pcpitstop.com/internet/pcpConnCheck.cab (iCC Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1236730104656 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} http://myitlab.pearsoned.com/Pegasus/Modul…ces/ax/stub.cab (Enlite 2.x Simulation Engine Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{19373339-5531-11de-9e60-0019b977261c}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{19373339-5531-11de-9e60-0019b977261c}\Shell\Explore\command - "" = autorun.exe
O33 - MountPoints2\{19373339-5531-11de-9e60-0019b977261c}\Shell\Open\command - "" = autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/04 00:04:29 | 00,000,000 | –SD | C] – C:\jgh
[2010/01/02 17:13:22 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2010/01/02 17:07:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Local Settings\Application Data\Temp
[2010/01/02 16:20:53 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/01/02 16:20:53 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/01/02 16:20:53 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/01/02 16:16:31 | 00,000,000 | —D | C] – C:\Qoobox
[2010/01/01 21:31:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\Ethno World 4
[2010/01/01 19:04:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\eBay
[2010/01/01 19:01:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\scanners
[2010/01/01 02:47:13 | 00,000,000 | —D | C] – C:\Program Files\EF CheckSum Manager
[2009/12/28 18:52:04 | 00,000,000 | RH-D | C] – C:\Documents and Settings\Jason\Recent
[2009/12/28 18:50:31 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/12/28 18:45:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Desktop\Panda Bear
[2009/12/28 18:45:39 | 00,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2009/12/28 18:12:51 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/12/26 16:39:52 | 00,000,000 | —D | C] – C:\Malwarebytes' Anti-Malware
[2009/12/26 16:27:01 | 00,000,000 | —D | C] – C:\Anti-Malware Programs
[2009/12/26 00:12:32 | 00,000,000 | —D | C] – C:\Program Files\PowerISO
[2009/12/25 03:03:25 | 00,000,000 | —D | C] – C:\$WIN_NT$.~BT
[2009/12/25 02:34:11 | 00,000,000 | —D | C] – C:\Program Files\WinISO
[2009/12/25 02:04:07 | 00,000,000 | —D | C] – C:\Program Files\Cobian Backup 9
[2009/12/25 02:01:03 | 00,000,000 | —D | C] – C:\Program Files\EASEUS
[2009/12/17 00:48:38 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Application Data\Plogue
[2009/12/17 00:48:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Jason\Application Data\Plogue Art et Technologie, Inc
[2009/12/08 23:05:23 | 00,000,000 | —D | C] – C:\Program Files\Lavalys
[2009/08/20 14:23:21 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/08/20 14:23:21 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/08/20 14:23:20 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/08/20 14:23:20 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/04 20:43:24 | 00,004,308 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Kaspersky results.html
[2010/01/04 20:07:32 | 00,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4278838382-2642953312-2933363751-1006UA.job
[2010/01/04 18:58:49 | 00,019,834 | —- | M] () – C:\Documents and Settings\Jason\Desktop\me.jpg
[2010/01/04 17:07:04 | 00,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4278838382-2642953312-2933363751-1006Core.job
[2010/01/04 14:41:08 | 00,528,784 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/01/04 14:41:08 | 00,446,438 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/01/04 14:41:08 | 00,073,226 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/01/04 14:36:39 | 00,000,032 | –S- | M] () – C:\WINDOWS\System32\504267629.dat
[2010/01/04 14:36:38 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/04 14:36:35 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/04 14:36:33 | 10,721,03424 | -HS- | M] () – C:\hiberfil.sys
[2010/01/04 04:07:32 | 11,272,192 | —- | M] () – C:\Documents and Settings\Jason\ntuser.dat
[2010/01/04 04:07:25 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Jason\ntuser.ini
[2010/01/04 00:07:51 | 00,000,048 | —- | M] () – C:\WINDOWS\System32\msvcsv60.dll
[2010/01/02 16:40:00 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/02 16:39:38 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/01/02 16:14:39 | 03,817,750 | R— | M] () – C:\Documents and Settings\Jason\Desktop\jgh.exe
[2010/01/02 16:07:09 | 00,000,020 | —- | M] () – C:\Documents and Settings\Jason\defogger_reenable
[2009/12/31 22:24:09 | 00,000,048 | —- | M] () – C:\WINDOWS\System32\w3data.vss
[2009/12/31 22:24:09 | 00,000,048 | —- | M] () – C:\WINDOWS\msocreg32.dat
[2009/12/29 23:16:08 | 00,006,534 | —- | M] () – C:\Documents and Settings\Jason\Application Data\wklnhst.dat
[2009/12/28 20:52:04 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/12/28 18:43:54 | 00,000,623 | —- | M] () – C:\WINDOWS\win.ini
[2009/12/28 00:53:08 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/12/26 23:35:08 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\jofasatu
[2009/12/25 03:31:57 | 00,001,420 | -H– | M] () – C:\WINDOWS\EPMBatch.ept
[2009/12/21 17:14:06 | 00,004,727 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Intel eBay.rtf
[2009/12/21 17:06:10 | 00,004,926 | —- | M] () – C:\Documents and Settings\Jason\Desktop\Corsair eBay.rtf
[2009/12/09 22:54:07 | 00,261,632 | —- | M] () – C:\WINDOWS\PEV.exe
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/04 20:43:24 | 00,004,308 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Kaspersky results.html
[2010/01/04 18:58:34 | 00,019,834 | —- | C] () – C:\Documents and Settings\Jason\Desktop\me.jpg
[2010/01/04 00:07:51 | 00,000,048 | —- | C] () – C:\WINDOWS\System32\msvcsv60.dll
[2010/01/02 17:02:42 | 00,000,978 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4278838382-2642953312-2933363751-1006UA.job
[2010/01/02 17:02:42 | 00,000,926 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4278838382-2642953312-2933363751-1006Core.job
[2010/01/02 16:52:01 | 00,000,032 | –S- | C] () – C:\WINDOWS\System32\504267629.dat
[2010/01/02 16:20:53 | 00,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/01/02 16:20:53 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/01/02 16:20:53 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/01/02 16:20:53 | 00,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/01/02 16:20:53 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/01/02 16:14:38 | 03,817,750 | R— | C] () – C:\Documents and Settings\Jason\Desktop\jgh.exe
[2010/01/02 16:06:58 | 00,000,020 | —- | C] () – C:\Documents and Settings\Jason\defogger_reenable
[2009/12/28 18:55:54 | 10,721,03424 | -HS- | C] () – C:\hiberfil.sys
[2009/12/25 02:19:23 | 00,001,420 | -H– | C] () – C:\WINDOWS\EPMBatch.ept
[2009/12/21 15:39:10 | 00,004,727 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Intel eBay.rtf
[2009/12/21 14:50:46 | 00,004,926 | —- | C] () – C:\Documents and Settings\Jason\Desktop\Corsair eBay.rtf
[2009/11/01 16:47:25 | 00,002,352 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/10/19 20:21:54 | 00,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/10/17 18:15:17 | 00,473,600 | —- | C] () – C:\WINDOWS\System32\Harmony.dll
[2009/10/17 18:15:17 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\Unlha32.dll
[2009/10/13 00:57:21 | 00,000,000 | —- | C] () – C:\WINDOWS\braid.ini
[2009/10/13 00:29:54 | 00,000,000 | —- | C] () – C:\WINDOWS\redsky.ini
[2009/10/12 22:49:12 | 00,000,000 | —- | C] () – C:\WINDOWS\Hot air balloon.ini
[2009/10/03 17:47:41 | 00,000,064 | —- | C] () – C:\WINDOWS\minitab.ini
[2009/05/30 21:54:02 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/05/27 21:59:17 | 00,000,110 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/05/06 17:12:10 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\utilpt32.dll
[2009/04/23 15:35:45 | 00,000,600 | —- | C] () – C:\Documents and Settings\Jason\Application Data\winscp.rnd
[2009/04/23 15:33:25 | 00,020,811 | —- | C] () – C:\WINDOWS\System32\drivers\IPFWHook.sys
[2009/01/18 19:50:39 | 00,000,250 | —- | C] () – C:\WINDOWS\gmer.ini
[2009/01/18 19:50:37 | 00,884,736 | —- | C] () – C:\WINDOWS\gmer.dll
[2008/12/17 17:43:13 | 00,000,604 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\T2
[2008/12/17 17:43:13 | 00,000,604 | -H– | C] () – C:\Program Files\STLL Notifier
[2008/12/05 00:59:09 | 00,000,144 | —- | C] () – C:\WINDOWS\Eudcedit.ini
[2008/11/11 22:39:36 | 00,000,626 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/11/04 21:03:34 | 00,000,000 | —- | C] () – C:\Documents and Settings\Jason\Application Data\AVSDVDPlayer.m3u
[2008/10/29 15:38:43 | 00,000,077 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2008/10/29 15:38:37 | 00,028,518 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2008/10/29 15:38:32 | 00,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2008/10/20 14:13:58 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/10/01 16:29:56 | 00,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/10/01 16:29:56 | 00,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/10/01 16:29:54 | 00,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/10/01 16:29:53 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/10/01 16:29:53 | 00,084,480 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/10/01 16:29:53 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/08/20 23:40:33 | 00,000,111 | —- | C] () – C:\WINDOWS\Sansa Media Converter.INI
[2008/08/08 13:49:18 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/06/10 18:07:20 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/06/10 18:03:26 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/06/10 18:03:26 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/06/08 23:05:29 | 02,463,976 | —- | C] () – C:\WINDOWS\System32\NPSWF32.dll
[2008/05/22 16:18:54 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/04/29 20:19:19 | 00,104,448 | —- | C] () – C:\Documents and Settings\Jason\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/04/05 00:05:19 | 00,006,534 | —- | C] () – C:\Documents and Settings\Jason\Application Data\wklnhst.dat
[2008/04/03 19:53:30 | 00,029,696 | —- | C] () – C:\WINDOWS\System32\asutl8.dll
[2008/04/02 20:20:01 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/04/02 19:51:03 | 00,000,128 | —- | C] () – C:\Documents and Settings\Jason\Local Settings\Application Data\fusioncache.dat
[2008/04/02 19:45:36 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/04/02 19:41:08 | 00,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2008/04/02 19:35:01 | 00,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/02 19:27:48 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/04/02 19:27:46 | 00,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/04/01 08:41:01 | 00,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/04/01 08:39:37 | 00,001,121 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2008/01/09 15:01:48 | 00,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2004/08/10 13:12:05 | 00,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:51:26 | 00,006,672 | —- | C] () – C:\WINDOWS\System32\advpack.dllb.dat
[2004/08/10 12:51:10 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\kvv30ra.dll
[2004/08/10 12:51:10 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\clauth2.dll
[2004/08/10 12:51:10 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\clauth1.dll
[2004/08/10 12:51:10 | 00,000,339 | —- | C] () – C:\WINDOWS\System32\ol0cli9.dll
[2004/08/10 12:51:10 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\prsgrc.dll
[2004/08/10 12:51:10 | 00,000,072 | —- | C] () – C:\WINDOWS\System32\ssprs.dll
[2004/08/10 12:51:10 | 00,000,016 | -H– | C] () – C:\WINDOWS\System32\or4syj8.dll
[2004/08/10 12:51:06 | 00,025,308 | -H– | C] () – C:\Documents and Settings\Jason\Application Data\windows.dat
[2003/11/16 03:48:02 | 00,909,312 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2003/11/16 03:48:00 | 01,060,864 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2003/11/15 10:54:18 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/10/06 16:42:58 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll

========== LOP Check ==========

[2009/10/24 14:14:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2009/08/18 03:33:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Audio Ease
[2009/05/17 19:11:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cakewalk
[2009/08/05 18:51:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Celemony Software GmbH
[2009/12/04 23:39:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2008/06/02 20:17:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Last.fm
[2009/03/03 13:59:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\myitlab
[2009/07/12 02:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/11/01 16:58:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2009/05/07 21:28:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2009/10/19 20:25:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2009/06/11 14:34:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/10/19 20:22:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SPSS
[2009/10/12 23:32:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2009/12/27 01:03:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/07 23:46:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tiffen
[2009/05/27 21:59:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/06/04 17:42:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VertusTech
[2008/04/02 19:34:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/07/07 23:44:37 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{3DDB0D6A-2256-4D46-A1A3-C97907A49312}
[2009/08/27 15:20:39 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{8E4DC1D0-364F-4942-85CD-BCD7298D633E}
[2009/08/27 15:23:29 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{A7689876-F0D2-4DC6-9C70-CA306AA80853}
[2009/11/15 15:22:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\.purple
[2009/10/24 14:15:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\acccore
[2009/07/14 01:24:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Antares
[2008/04/03 19:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Anvil Studio
[2009/08/18 03:33:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Audio Ease
[2009/07/29 21:54:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Braid
[2009/05/17 22:19:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Cakewalk
[2008/04/03 23:24:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\CoreCodec
[2009/04/23 15:42:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\CoreFTP
[2008/10/06 17:27:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\DAEMON Tools
[2008/08/18 17:12:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\FLV Extract
[2009/07/22 18:53:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\GrabIt
[2009/03/11 15:36:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\IrfanView
[2009/07/16 16:20:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Moyea
[2008/07/19 22:40:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\NetMedia Providers
[2008/04/15 20:26:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Notepad++
[2008/05/16 18:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Opera
[2009/12/17 00:48:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Plogue
[2009/12/17 00:48:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Plogue Art et Technologie, Inc
[2009/05/07 22:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Propellerhead Software
[2008/07/19 22:40:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Publish Providers
[2008/04/03 19:49:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Renegade Minds
[2009/06/12 00:42:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Sony
[2009/06/11 14:55:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Sony Setup
[2009/04/23 15:29:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\SSH
[2009/05/25 22:15:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Steinberg
[2008/04/05 00:05:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Template
[2008/12/01 00:08:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Thomson Learning
[2009/07/07 23:48:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Tiffen
[2009/05/27 21:59:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Ulead Systems
[2009/08/18 01:56:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\uTorrent
[2009/12/01 14:26:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\VitySoft
[2009/05/27 17:53:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Jason\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
< End of report >
Hi Nift,

Just some tidying up to do. Some of the Kaspersky detections are quarantined files. These will be removed as part of the tools clean up.

Open Internet Explorer
  • at the top click Tools
  • Click Internet Options
  • Click Connections tab
  • Click Lan Settings button
  • Make sure the box beside "Use a proxy sever for your Lan" is UNchecked
  • OK your way out.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8080

:Services

:Reg

:Files
C:\Program Files\Java\jar.exe
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\6.0\10\630c3e4a-248d4782 
C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K2MX4CW8\marrychristmasforyou[1].htm 
C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K2MX4CW8\nevpizdy-nenyznie50domain[1].htm 

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log .

We will renable your drivers and clean up the tools when you post back.

Thanks
OTL log:

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Program Files\Java\jar.exe moved successfully.
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\6.0\10\630c3e4a-248d4782 moved successfully.
C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K2MX4CW8\marrychristmasforyou[1].htm moved successfully.
C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K2MX4CW8\nevpizdy-nenyznie50domain[1].htm moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 2847805 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Jason
->Temp folder emptied: 94098592 bytes
->Temporary Internet Files folder emptied: 26609939 bytes
->Java cache emptied: 2032085 bytes
->FireFox cache emptied: 93198573 bytes
->Google Chrome cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 32902 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 209.00 mb


OTL by OldTimer - Version 3.1.20.1 log created on 01052010_151746

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Hi Nift,

If no other problems, we can clean up our tools. Keep Defogger, we will use it shortly.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER.zip
  • GMER.exe

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep MBAM updated and use it regularly.


To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.



This is very important. Without an antivirus program installed you will get reinfected in a short time. You can get a good free one from one of these vendors. Please chose one and install it.

Avast
Help and support can be found here Avast Forum
AVG
Help and support can be found here AVG Forum
Antivir PersonalEditionClassic
Help and support can be found here Avira Personal Support Forum


Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.0.8 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have an antivirus program (hopefully you have one installed by now) and an on demand antispyware program.

For resident antispyware I suggest either

Windows Defender
OR
Winpatrol

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware,IMO)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".


Take care
THANK YOU!!! Not only only is the infection gone, I'm also no longer experiencing a problem that's been pestering me for months where most of my programs were unable to connect to the internet! Thanks so much for the help! Made my day! :notworthy:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI