This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] cyban.exe & mrp.exe revives upon deletion

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey,

Recently, I tried making my own service (specifically, the magicJack application to run quietly in the background without being disruptive with popups whenever someone calls) but it wouldn't start upon bootup. So I tried activating it manually, but it wouldn't start due to an error (Cannot start on local computer. Error 5: Access is denied).

I tried accessing the (hidden) folder the application was in, but it doesn't popup when I tick "Show hidden files and folders" within the Folder Options of the Control Panel. This particular setting doesn't save: it reverts back to "Do not show hidden files and folders."

So tried looking for a solution (editing registry to show hidden files, but it reverts also) and eventually, I tried using a new anti-virus (avast) and it picked up a "mrp.exe". I ran several scans and deleted it over and over but it comes back to haunt my computer. :wacko:
Then I tried MBAM (posted on the sticky, "Are you Infected?"), and noticed some other oddities… they also revive upon deletion.

And this morning, I can't double click to open my c drive: it asks what program to open the C drive with… :huh:
Below are the MBAM, GMER, DDS logs. (GMER was run in safe mode because computer kept crashing during the scans attempted)

Malwarebytes' Anti-Malware 1.43
Database version: 3502
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/6/2010 5:17:02 PM
mbam-log-2010-01-06 (17-17-02).txt

Scan type: Quick Scan
Objects scanned: 117666
Time elapsed: 9 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 7
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\cyban0.dll (Spyware.OnlineGames) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\iehlprobj.iehlprobj.1 (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7f235922-8f2c-4c08-83a8-bbe01bf9cc64} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7f23592c-8f2c-4c08-83a8-bbe01bf9cc64} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7f23592b-8f2c-4c08-83a8-bbe01bf9cc64} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7f23592b-8f2c-4c08-83a8-bbe01bf9cc64} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7f23592b-8f2c-4c08-83a8-bbe01bf9cc64} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\MNDOWN (Trojan.PWS) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cybansos (Spyware.OnlineGames) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\ieban0.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cyban.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cyban0.dll (Spyware.OnlineGames) -> Delete on reboot.
C:\WINDOWS\system32\cyban1.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-07 11:32:43
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\STEVEN~1\LOCALS~1\Temp\kwqdrkod.sys


—- System - GMER 1.0.15 —-

INT 0x63 ? 8A661BF8
INT 0x73 ? 8A662BF8
INT 0x83 ? 8A661BF8
INT 0x94 ? 8A661BF8
INT 0xA4 ? 8A661BF8
INT 0xB4 ? 8A661BF8

—- Devices - GMER 1.0.15 —-

Device 8A65F1F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device 89A7C3B0
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBPDO-0 89C40408
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A6631F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A6631F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A6631F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A6631F8
Device \Driver\usbuhci \Device\USBPDO-1 89C40408
Device \Driver\usbehci \Device\USBPDO-2 89C5D1F8
Device \Driver\usbehci \Device\USBPDO-3 89C5D1F8
Device \Driver\usbuhci \Device\USBPDO-4 89C40408
Device \Driver\usbuhci \Device\USBPDO-5 89C40408
Device \Driver\usbuhci \Device\USBPDO-6 89C40408
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6641F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A6641F8
Device \Driver\Cdrom \Device\CdRom0 89C41500
Device \Driver\Cdrom \Device\CdRom1 89C41500
Device \Driver\iastor \Device\Ide\iaStor0 [F7B605D0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iastor \Device\Ide\IAAStorageDevice-0 [F7B605D0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iastor \Device\Ide\IAAStorageDevice-1 [F7B605D0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 8A6641F8
Device \Driver\Cdrom \Device\CdRom2 89C41500
Device \Driver\Cdrom \Device\CdRom3 89C41500
Device \Driver\PCI_PNP2372 \Device\0000004a spyk.sys
Device \Driver\PCI_PNP2372 \Device\0000004a spyk.sys
Device \Driver\USBSTOR \Device\0000006c 89AAC1F8
Device \Driver\usbuhci \Device\USBFDO-0 89C40408
Device \Driver\usbuhci \Device\USBFDO-1 89C40408
Device \Driver\USBSTOR \Device\0000006e 89AAC1F8
Device \Driver\usbehci \Device\USBFDO-2 89C5D1F8
Device \Driver\USBSTOR \Device\0000006f 89AAC1F8
Device \Driver\usbuhci \Device\USBFDO-3 89C40408
Device \Driver\usbuhci \Device\USBFDO-4 89C40408
Device \Driver\sptd \Device\2499576122 spyk.sys
Device \Driver\Ftdisk \Device\FtControl 8A6641F8
Device \Driver\usbuhci \Device\USBFDO-5 89C40408
Device \Driver\usbehci \Device\USBFDO-6 89C5D1F8
Device \Driver\azxhibr2 \Device\Scsi\azxhibr21Port1Path0Target0Lun0 89C641F8
Device \Driver\azxhibr2 \Device\Scsi\azxhibr21Port1Path0Target1Lun0 89C641F8
Device \Driver\azxhibr2 \Device\Scsi\azxhibr21 89C641F8

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x1E 0x18 0x0A 0x5E …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5F 0x2F 0x00 0x85 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x7F 0x16 0x5A 0xFD …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBE 0x9B 0x13 0x2F …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xF3 0x1E 0xD7 0x5A …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD3 0xCE 0xBD 0x06 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB1 0x6A 0x4F 0x28 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x3D 0x89 0x7F 0xAC …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x1E 0x18 0x0A 0x5E …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5F 0x2F 0x00 0x85 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x7F 0x16 0x5A 0xFD …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBE 0x9B 0x13 0x2F …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xF3 0x1E 0xD7 0x5A …
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo@FriendlyName Indeo? video 5.10 Compression Filter
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo@CLSID {1F73E9B1-8C3A-11D0-A3BE-00A0C9244436}
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo@FilterData 0x02 0x00 0x00 0x00 …
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo@EncoderType 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{27FE8F59-AF60-59E4-7E11-E86FCD04D166}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{27FE8F59-AF60-59E4-7E11-E86FCD04D166}@jaojmkffkejfheginmim 0x62 0x61 0x63 0x69 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{27FE8F59-AF60-59E4-7E11-E86FCD04D166}@jaojmkffkejfheginmmm 0x62 0x61 0x6F 0x68 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{27FE8F59-AF60-59E4-7E11-E86FCD04D166}@iaogiaceghbhoglono 0x6B 0x61 0x70 0x68 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{27FE8F59-AF60-59E4-7E11-E86FCD04D166}@haahkogddiaeplmo 0x6B 0x61 0x70 0x68 …

—- EOF - GMER 1.0.15 —-

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 12:08:21.42 on 01/07/2010 Thu
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.932.81.1033.18.2038.1218 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: avast! antivirus 4.8.1368 [VPS 100107-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Nakido\nakido.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM7\aim.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Steven Zeng\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: SearchSettings Class: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\search settings\kb126\SearchSettings.dll
BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 7\SnagItBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: IEHlprObj Class: {7f23592b-8f2c-4c08-83a8-bbe01bf9cc64} - c:\windows\system32\ieban0.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SearchSettings Class: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\search settings\kb126\SearchSettings.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 7\SnagItIEAddin.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB: {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - No File
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: []
uRun: [Google Update] "c:\documents and settings\steven zeng\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Aim] "c:\program files\aim7\aim.exe" /d locale=en-US
uRun: [cybansos] c:\windows\system32\cyban.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: []
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [ZSSnp211] c:\windows\ZSSnp211.exe
mRun: [Domino] c:\windows\Domino.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [cdloader] "c:\documents and settings\localservice\application data\mjusbsp\cdloader2.exe" MAGICJACK
dRunOnce: [RunNarrator] Narrator.exe
IE: Download Link Using Mega Manager… - c:\program files\megaupload\mega manager\mm_file.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: google.com
Trusted Zone: yahoo.com
DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - hxxp://avatar.mabinogi.jp/3drender/renderer/mabiweb.2007.4.4.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {A4453425-32A4-4E0F-8FE9-E75F72C2BF9E} = 167.206.254.2,167.206.254.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\steven~1\applic~1\mozilla\firefox\profiles\6rmkf1jm.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\steven zeng\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-3-18 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2010-1-5 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-5 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-5 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-5 360584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-1-5 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2010-1-5 138680]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-5 285392]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 951632]
R2 Nakido;Nakido;c:\program files\nakido\nakido.exe [2009-7-9 328704]
R2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\rosettastoneltdservices\RosettaStoneDaemon.exe [2009-4-25 443712]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-4-26 24652]
S2 gupdate1ca2d864da01f8c;Google Update Service (gupdate1ca2d864da01f8c);"c:\program files\google\update\googleupdate.exe" /svc –> c:\program files\google\update\GoogleUpdate.exe [?]
S2 MagicJack;MagicJack;c:\program files\windows resource kits\tools\srvany.exe [2003-4-18 46]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2010-1-5 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2010-1-5 352920]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2009-12-24 480128]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [2009-12-24 1537280]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688]
S4 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-6-3 92008]

============== File Associations ===============

regfile=regedit.exe %1

=============== Created Last 30 ================

2010-01-07 12:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 12:07 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-07 12:00

–d—– c:\windows\system32\wbem\Repository
2010-01-07 11:59 –d—– C:\KEY
2010-01-06 14:19 96,256 —shr– c:\windows\system32\cyban0.dll
2010-01-06 13:32 –d—– c:\docume~1\steven~1\applic~1\Malwarebytes
2010-01-06 13:31 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-06 13:31 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-06 13:13 51 a——- c:\windows\wininit.ini
2010-01-06 13:07 –d—– c:\docume~1\steven~1\applic~1\mjusbsp
2010-01-05 23:13 –d—– c:\program files\TrendMicro
2010-01-05 21:53 –d-h— C:\$AVG
2010-01-05 21:53 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2010-01-05 21:53 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-01-05 21:53 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2010-01-05 21:53 –d—– c:\windows\system32\drivers\Avg
2010-01-05 21:52 –d—– c:\docume~1\alluse~1\applic~1\avg9
2010-01-05 19:12 –d—– c:\windows\system32\NtmsData
2010-01-05 19:06 3,153,920 a——- c:\windows\system32\secsetup.sdb
2010-01-05 18:02 99,840 —shr– c:\windows\system32\cyban2.dll
2010-01-05 18:02 96,256 —shr– c:\windows\system32\cyban1.dll
2010-01-04 21:57 –d—– c:\program files\Windows Resource Kits
2010-01-04 19:18 60,032 ac—— c:\windows\system32\dllcache\usbaudio.sys
2010-01-04 19:18 60,032 a——- c:\windows\system32\drivers\USBAUDIO.sys
2010-01-04 10:44 166,912 —shr– C:\mrp.exe
2010-01-02 14:52 162,816 a–shr– C:\wa.exe
2010-01-01 12:46 164,864 a–shr– C:\kalx8.exe
2009-12-31 09:05 168,960 a–shr– C:\ufc0q919.exe
2009-12-29 17:28 –d—– c:\program files\Fraps
2009-12-27 11:44 –d—– c:\program files\GOG.com
2009-12-25 20:27 –d—– c:\windows\system32\LogFiles
2009-12-25 20:23 –d—– c:\program files\Microsoft Bootvis
2009-12-25 00:59 –d—– c:\windows\EffectResources
2009-12-25 00:59 53,760 ac—— c:\windows\system32\dllcache\vfwwdm32.dll
2009-12-25 00:59 53,760 a——- c:\windows\system32\vfwwdm32.dll
2009-12-25 00:59 91,136 ac—— c:\windows\system32\dllcache\kswdmcap.ax
2009-12-25 00:59 43,008 ac—— c:\windows\system32\dllcache\ksxbar.ax
2009-12-25 00:59 91,136 a——- c:\windows\system32\kswdmcap.ax
2009-12-25 00:59 43,008 a——- c:\windows\system32\ksxbar.ax
2009-12-25 00:59 61,952 ac—— c:\windows\system32\dllcache\kstvtune.ax
2009-12-25 00:59 61,952 a——- c:\windows\system32\kstvtune.ax
2009-12-24 21:44 57,344 a——- c:\windows\ZSSnp211.exe
2009-12-24 21:44 49,152 a——- c:\windows\Domino.exe
2009-12-24 21:44 1,537,280 a——- c:\windows\system32\drivers\ZS211.sys
2009-12-24 21:44 480,128 a——- c:\windows\system32\drivers\vvftav211.sys
2009-12-24 21:44 274,432 a——- c:\windows\system32\ZS211Prp.Ax
2009-12-24 21:44 217,088 a——- c:\windows\amcap.exe
2009-12-24 21:44 188,416 a——- c:\windows\system32\VvftPrpav211.ax
2009-12-24 21:44 94,208 a——- c:\windows\system32\VvFtCtrl.dll
2009-12-24 21:44 81,920 a——- c:\windows\system32\ZS211STI.dll
2009-12-24 21:44 77,824 a——- c:\windows\ZS211Cap.exe
2009-12-24 21:44 –d—– c:\program files\Vimicro
2009-12-09 11:05 118 a——- c:\windows\system32\MRT.INI

==================== Find3M ====================

2010-01-06 12:43 166,912 —shr– c:\windows\system32\cyban.exe
2010-01-04 21:57 89,063 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-11-21 03:46 86,016 a——- c:\windows\system32\frapsvid.dll
2009-10-29 02:45 916,480 a——- c:\windows\system32\wininet.dll
2009-10-22 19:58 210,325 a——- c:\windows\Screen Calipers Uninstaller.exe
2009-10-22 16:17 210,029 a——- c:\windows\Screen Protractor Uninstaller.exe
2009-10-21 00:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-21 00:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-19 23:39 5,477,735 a——- C:\complete.exe
2009-10-19 23:38 1,147,865 a——- C:\ldraw027.exe
2009-10-15 14:47 25 a——- C:\popcinfot.dat
2009-10-13 05:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-12 08:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 08:38 79,872 a——- c:\windows\system32\raschap.dll
2009-10-11 04:17 411,368 a——- c:\windows\system32\deploytk.dll
2008-09-24 21:03 0 ac—— c:\documents and settings\steven zeng\dhtnodes.dat
2008-09-17 14:49 2,516 ac-sh— c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2008-09-17 14:44 8 -c-shr– c:\docume~1\alluse~1\applic~1\E3166CB2AA.sys
2008-07-15 11:58 56 a–shr– c:\windows\system32\AAB26C16E3.sys
2008-07-17 08:22 1,682 ac-sh— c:\windows\system32\KGyGaAvL.sys
2008-09-15 16:16 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091520080916\index.dat

============= FINISH: 12:09:23.50 ===============

Thank you for your time. :)
Hi there,

Are you still using AVG, as well as Avast? You should run one anti-virus program at a time.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hey jpshortstuff,

Thanks for the reply.
I unistalled AVG shortly after posting, so I only have avast running (as my anti-virus) now.

After running ComboFix, ticking "Show all hidden files" in Folder Options saves. ^_^
I can also double click to open the C drive now.
I still can't start that service I made (same error) although there might be some other reason why it doesn't work. (not sure)

Here's the ComboFix log:

ComboFix 10-01-04.01 - Steven Zeng 0/2010 Sun 14:57:33.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.932.81.1033.18.2038.1391 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100110-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\cmd.exe
c:\documents and settings\Steven Zeng\Local Settings\Tempals_inst.exe
c:\program files\Search Settings
c:\program files\Search Settings\kb126\SearchSettings.dll
c:\program files\Search Settings\SearchSettings.exe
c:\recycler\k-1-3542-4232123213-7676767-8888886
c:\windows\kb913800.exe
c:\windows\system32\cyban.exe
c:\windows\system32\cyban0.dll
c:\windows\system32\cyban1.dll
c:\windows\system32\cyban2.dll
c:\windows\system32\drivers\1028_DELL_XPS_Dell DM061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DM061 .MRK
c:\windows\system32\ieBAn0.dll
c:\windows\system32\ieban1.dll
c:\windows\system32\SIntf16.dll
c:\windows\unins000.dat
c:\windows\unins000.exe

.
((((((((((((((((((((((((( Files Created from 2009-12-10 to 2010-01-10 )))))))))))))))))))))))))))))))
.

2010-01-08 23:56 . 2009-12-24 16:58 6515976 —ha-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\in00000\setup.exe
2010-01-08 23:56 . 2009-12-24 16:54 730032 —ha-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ar00000\install.exe
2010-01-07 17:07 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 17:07 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 17:00 . 2010-01-07 17:00 ——– d—–w- c:\windows\system32\wbem\Repository
2010-01-07 16:59 . 2010-01-07 16:59 ——– d—–w- C:\KEY
2010-01-06 18:32 . 2010-01-06 18:32 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\Malwarebytes
2010-01-06 18:31 . 2010-01-06 18:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-06 18:31 . 2010-01-07 17:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-06 18:29 . 2010-01-07 16:59 ——– d—–w- c:\program files\ERUNT
2010-01-06 18:07 . 2009-12-24 16:58 6515976 —ha-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\Upgrade\setup1.exe
2010-01-06 18:07 . 2009-12-24 16:54 730032 —ha-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\Upgrade\install1.exe
2010-01-06 18:07 . 2010-01-08 23:56 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp
2010-01-06 13:17 . 2010-01-06 02:53 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-06 13:17 . 2010-01-06 02:53 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-06 13:17 . 2010-01-06 02:53 2033432 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-06 13:17 . 2010-01-06 02:52 916248 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-06 13:17 . 2010-01-06 02:53 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-06 13:17 . 2010-01-06 02:53 3967256 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-06 04:51 . 2009-11-24 23:49 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-06 04:51 . 2009-11-24 23:48 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-06 04:51 . 2009-11-24 23:47 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-06 04:51 . 2009-11-24 23:47 97480 —-a-w- c:\windows\system32\AvastSS.scr
2010-01-06 04:51 . 2009-11-24 23:51 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-06 04:51 . 2009-11-24 23:50 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-06 04:51 . 2009-11-24 23:50 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-06 04:51 . 2009-11-24 23:50 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-06 04:51 . 2009-11-24 23:54 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2010-01-06 04:51 . 2010-01-06 04:51 ——– d—–w- c:\program files\Alwil Software
2010-01-06 04:13 . 2010-01-06 04:13 388096 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-06 04:13 . 2010-01-06 04:13 ——– d—–w- c:\program files\TrendMicro
2010-01-06 02:53 . 2010-01-06 02:54 ——– d—–w- C:\$AVG
2010-01-06 02:53 . 2010-01-06 02:53 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-06 02:53 . 2010-01-06 02:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-06 02:53 . 2010-01-06 02:53 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-06 02:53 . 2010-01-06 02:53 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-06 02:53 . 2010-01-10 14:15 ——– d—–w- c:\windows\system32\drivers\Avg
2010-01-06 02:52 . 2010-01-06 02:52 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-06 02:36 . 2010-01-06 02:36 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-06 00:12 . 2010-01-10 19:53 ——– d—–w- c:\windows\system32\NtmsData
2010-01-05 20:43 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp\st00000
2010-01-05 20:43 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp\in00000
2010-01-05 20:43 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp\ar00000
2010-01-05 20:31 . 2010-01-05 20:31 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
2010-01-05 04:49 . 2010-01-05 23:34 ——– d–h–w- c:\documents and settings\mjusbsp\Upgrade
2010-01-05 04:49 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp\ug00000
2010-01-05 04:49 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp
2010-01-05 02:57 . 2010-01-05 02:57 ——– d—–w- c:\program files\Windows Resource Kits
2010-01-05 01:01 . 2010-01-05 01:01 ——– d—–w- c:\documents and settings\Steven Zeng\Local Settings\Application Data\tjnet
2010-01-05 00:18 . 2008-04-13 19:45 60032 -c–a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-01-05 00:18 . 2008-04-13 19:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-01-02 19:52 . 2010-01-02 19:51 162816 –sha-r- C:\wa.exe
2010-01-01 17:46 . 2010-01-01 17:46 164864 –sha-r- C:\kalx8.exe
2009-12-31 14:05 . 2009-12-31 14:05 168960 –sha-r- C:\ufc0q919.exe
2009-12-29 22:28 . 2009-12-29 22:28 ——– d—–w- c:\program files\Fraps
2009-12-27 16:44 . 2009-12-27 16:44 ——– d—–w- c:\program files\GOG.com
2009-12-26 01:27 . 2009-12-26 01:27 ——– d—–w- c:\windows\system32\LogFiles
2009-12-26 01:23 . 2009-12-26 06:08 ——– d—–w- c:\program files\Microsoft Bootvis
2009-12-25 05:59 . 2009-12-25 05:59 ——– d—–w- c:\windows\EffectResources
2009-12-25 05:59 . 2008-04-14 01:12 53760 -c–a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2009-12-25 05:59 . 2008-04-14 01:12 53760 —-a-w- c:\windows\system32\vfwwdm32.dll
2009-12-25 02:44 . 2008-12-30 19:11 57344 —-a-w- c:\windows\ZSSnp211.exe
2009-12-25 02:44 . 2008-12-30 19:10 49152 —-a-w- c:\windows\Domino.exe
2009-12-25 02:44 . 2008-12-30 19:11 94208 —-a-w- c:\windows\system32\VvFtCtrl.dll
2009-12-25 02:44 . 2008-12-30 19:11 81920 —-a-w- c:\windows\system32\ZS211STI.dll
2009-12-25 02:44 . 2008-12-30 19:11 77824 —-a-w- c:\windows\ZS211Cap.exe
2009-12-25 02:44 . 2008-12-30 19:11 480128 —-a-w- c:\windows\system32\drivers\vvftav211.sys
2009-12-25 02:44 . 2008-12-30 19:11 1537280 —-a-w- c:\windows\system32\drivers\ZS211.sys
2009-12-25 02:44 . 2008-12-30 19:10 217088 —-a-w- c:\windows\amcap.exe
2009-12-25 02:44 . 2009-12-25 02:44 ——– d—–w- c:\program files\Vimicro
2009-12-24 16:59 . 2009-12-24 16:59 93016 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ug00000\magicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 6515976 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ug00000\setup.exe
2009-12-24 16:58 . 2009-12-24 16:58 416328 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\magicJackLoader.exe
2009-12-24 16:58 . 2009-12-24 16:58 416328 —-a-w- c:\documents and settings\mjusbsp\magicJackLoader.exe
2009-12-24 16:58 . 2009-12-24 16:58 480608 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\octvqe1_apiw.dll
2009-12-24 16:58 . 2009-12-24 16:58 480608 —-a-w- c:\documents and settings\mjusbsp\octvqe1_apiw.dll
2009-12-24 16:58 . 2009-12-24 16:58 214360 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\TjVista.dll
2009-12-24 16:58 . 2009-12-24 16:58 214360 —-a-w- c:\documents and settings\mjusbsp\TjVista.dll
2009-12-24 16:58 . 2009-12-24 16:58 337240 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\TjIpSys.dll
2009-12-24 16:58 . 2009-12-24 16:58 337240 —-a-w- c:\documents and settings\mjusbsp\TjIpSys.dll
2009-12-24 16:58 . 2009-12-24 16:58 607600 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\SJHandsetMagicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 607600 —-a-w- c:\documents and settings\mjusbsp\SJHandsetMagicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 87384 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\st00000\mjsetup.exe
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\st00000\magicJack.dll
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\magicJack.dll
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\mjusbsp\magicJack.dll
2009-12-24 16:55 . 2009-12-24 16:55 12482904 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\magicJack.exe
2009-12-24 16:55 . 2009-12-24 16:55 12482904 —-a-w- c:\documents and settings\mjusbsp\magicJack.exe
2009-12-24 16:54 . 2009-12-24 16:54 730032 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ug00000\install.exe
2009-12-24 16:53 . 2009-12-24 16:53 87384 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\in00000\mjsetup.exe
2009-12-24 16:53 . 2009-12-24 16:53 93016 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\in00000\magicJack.dll
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\st00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\in00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\mjusbsp\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 50520 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\cdloader2.exe
2009-12-24 16:52 . 2009-12-24 16:52 50520 —-a-w- c:\documents and settings\mjusbsp\cdloader2.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-10 19:53 . 2009-04-11 22:07 ——– d—–w- c:\program files\Nakido
2010-01-10 15:52 . 2009-11-12 21:28 0 —-a-w- c:\documents and settings\Steven Zeng\Local Settings\Application Data\prvlcl.dat
2010-01-09 05:00 . 2009-08-31 18:01 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\uTorrent
2010-01-09 04:31 . 2008-05-14 22:13 ——– d—–w- c:\program files\Paint.NET
2010-01-06 18:28 . 2007-10-12 19:04 79016 —-a-w- c:\documents and settings\Steven Zeng\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-11 15:48 . 2009-12-11 15:48 45056 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{24EEF6D7-A7B6-4AA9-AFD9-407185A7769F}\MapleStory.exe1_24EEF6D7A7B64AA9AFD9407185A7769F.exe
2009-12-11 15:48 . 2009-12-11 15:48 45056 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{24EEF6D7-A7B6-4AA9-AFD9-407185A7769F}\MapleStory.exe_24EEF6D7A7B64AA9AFD9407185A7769F.exe
2009-12-11 15:48 . 2009-12-11 15:48 10134 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{24EEF6D7-A7B6-4AA9-AFD9-407185A7769F}\ARPPRODUCTICON.exe
2009-12-11 05:27 . 2009-01-06 02:15 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2009-12-09 16:07 . 2009-05-17 14:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-07 23:49 . 2009-12-07 23:49 ——– d—–w- c:\program files\Google
2009-12-07 23:41 . 2009-12-07 23:41 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\LEGO Company
2009-12-07 23:33 . 2009-12-07 23:30 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\DassaultSystemes
2009-12-07 23:30 . 2009-12-07 23:30 ——– d—–w- c:\documents and settings\All Users\Application Data\DassaultSystemes
2009-12-06 03:51 . 2009-12-06 03:51 ——– d—–w- c:\program files\Lame for Audacity
2009-11-21 08:46 . 2009-11-21 08:46 86016 —-a-w- c:\windows\system32\frapsvid.dll
2009-11-20 07:26 . 2009-11-20 07:26 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\runic games
2009-11-20 07:20 . 2009-11-20 07:20 ——– d—–w- c:\program files\Runic Games
2009-11-16 20:14 . 2007-10-13 14:02 ——– d—–w- c:\program files\Java
2009-11-16 20:13 . 2009-11-16 20:13 152576 —-a-w- c:\documents and settings\Steven Zeng\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-16 20:13 . 2009-11-16 20:13 79488 —-a-w- c:\documents and settings\Steven Zeng\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-12 23:52 . 2009-08-20 17:13 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\HpUpdate
2009-11-11 18:35 . 2009-11-11 18:35 45056 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\MapleStory.exe1_A6CCAEF5F1414BBEA6DAEA8A8362C7A6.exe
2009-11-11 18:35 . 2009-11-11 18:35 45056 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\MapleStory.exe_A6CCAEF5F1414BBEA6DAEA8A8362C7A6.exe
2009-10-29 07:45 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-23 00:58 . 2009-10-23 00:58 210325 —-a-w- c:\windows\Screen Calipers Uninstaller.exe
2009-10-22 21:17 . 2009-10-22 21:17 210029 —-a-w- c:\windows\Screen Protractor Uninstaller.exe
2009-10-21 05:38 . 2004-08-10 11:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 11:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 11:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-20 04:39 . 2009-10-20 04:38 5477735 —-a-w- C:\complete.exe
2009-10-20 04:38 . 2009-10-20 04:38 1147865 —-a-w- C:\ldraw027.exe
2009-10-15 19:47 . 2009-10-15 19:47 25 —-a-w- C:\popcinfot.dat
2009-10-13 10:30 . 2004-08-10 11:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-07-15 16:58 . 2008-06-29 14:01 56 –sha-r- c:\windows\system32\AAB26C16E3.sys
2008-07-17 13:22 . 2008-06-29 14:01 1682 -csha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-22 133104]
"Aim"="c:\program files\AIM7\aim.exe" [2009-10-05 3634024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-20 282624]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2008-12-30 57344]
"Domino"="c:\windows\Domino.exe" [2008-12-30 49152]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-06 02:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-01-06 13:17 2033432 —-a-w- c:\progra~1\AVG\AVG9\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2009-12-24 16:52 50520 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Funshion]
2008-12-22 06:21 2768896 —-a-w- c:\program files\Funshion Online\Funshion\Funshion.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-11-22 05:27 133104 —-atw- c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-09-19 13:36 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-06-03 12:46 251240 —-a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
2008-09-26 23:14 3660848 —-a-w- c:\program files\Veoh Networks\Veoh\VeohClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TomTomHOMEService"=2 (0x2)
"idsvc"=3 (0x3)
"magicJack Service"=2 (0x2)
"RosettaStoneDaemon"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Nexon\\MapleStory\\MapleStory.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Nexon\\MapleStory\\Patcher.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Funshion Online\\Funshion\\Funshion.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Nakido\\nakido.exe"=
"c:\\Documents and Settings\\Steven Zeng\\Desktop\\PACNyx v0.6.0\\PACNyx.exe"=
"c:\\Program Files\\softnyx\\GunboundWC\\GunBound.gme"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\DFO\\DFO.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\program files\RosettaStoneLtdServices\RosettaStoneLtdServices.exe"= c:\program files\RosettaStoneLtdServices\RosettaStoneLtdServices.exe:127.0.0.1/255.255.255.255:Enabled:Rosetta Stone Ltd Services
"c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe"= c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe:127.0.0.1/255.255.255.255:Enabled:Rosetta Stone Daemon
"c:\\Program Files\\AIM7\\aim.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\LocalService\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Documents and Settings\\Steven Zeng\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57572:TCP"= 57572:TCP:Pando Media Booster
"57572:UDP"= 57572:UDP:Pando Media Booster
"57923:TCP"= 57923:TCP:Pando Media Booster
"57923:UDP"= 57923:UDP:Pando Media Booster
"56712:TCP"= 56712:TCP:Pando Media Booster
"56712:UDP"= 56712:UDP:Pando Media Booster
"56278:TCP"= 56278:TCP:Pando Media Booster
"56278:UDP"= 56278:UDP:Pando Media Booster

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [1/5/2010 11:51 PM 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/5/2010 9:53 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/5/2010 9:53 PM 360584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/5/2010 11:51 PM 20560]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/5/2010 9:52 PM 285392]
R2 Nakido;Nakido;c:\program files\Nakido\nakido.exe [7/9/2009 6:24 PM 328704]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/26/2009 12:58 PM 24652]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/30/2007 10:53 AM 717296]
S2 gupdate1ca2d864da01f8c;Google Update Service (gupdate1ca2d864da01f8c);"c:\program files\Google\Update\GoogleUpdate.exe" /svc –> c:\program files\Google\Update\GoogleUpdate.exe [?]
S2 MagicJack;MagicJack;c:\program files\Windows Resource Kits\Tools\srvany.exe [4/18/2003 6:06 PM 46]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [12/24/2009 9:44 PM 480128]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [12/24/2009 9:44 PM 1537280]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 7:28 PM 47128]
S4 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [4/25/2009 7:45 PM 443712]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [7/10/2008 1:49 AM 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/10/2008 7:28 PM 369688]
S4 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [6/3/2009 7:46 AM 92008]
.
Contents of the 'Scheduled Tasks' folder

2010-01-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-01-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-1336601894-682003330-1003Core.job
- c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-22 05:27]

2010-01-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-1336601894-682003330-1003UA.job
- c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-22 05:27]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: google.com
Trusted Zone: yahoo.com
TCP: {A4453425-32A4-4E0F-8FE9-E75F72C2BF9E} = 167.206.254.2,167.206.254.1
DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - hxxp://avatar.mabinogi.jp/3drender/renderer/mabiweb.2007.4.4.cab
FF - ProfilePath - c:\documents and settings\Steven Zeng\Application Data\Mozilla\Firefox\Profiles\6rmkf1jm.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - false.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
MSConfigStartUp-AIM - c:\program files\AIM\aim.exe
MSConfigStartUp-cybansos - c:\windows\system32\cyban.exe
MSConfigStartUp-I-Hate-Keyloggers - c:\documents and settings\Steven Zeng\My Documents\i-hate-keyloggers.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
MSConfigStartUp-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
ActiveSetup-{26KLN5J0-4OPX-11WE-AAX3-24EF1F387272} - c:\recycler\k-1-3542-4232123213-7676767-8888886\hn.exe
AddRemove-Jpeg Bmp Tiff Png Converter_is1 - c:\program files\Free All to Image Jpg-Jpeg Bmp Tiff Png Converter\unins000.exe
AddRemove-WinGTK-1.3_is1 - c:\windows\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-10 15:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1275210071-1336601894-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{27FE8F59-AF60-59E4-7E11-E86FCD04D166}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jaojmkffkejfheginmim"=hex:62,61,63,69,00,00
"jaojmkffkejfheginmmm"=hex:62,61,6f,68,00,00
"iaogiaceghbhoglono"=hex:6b,61,70,68,69,6c,67,6f,69,6f,66,67,65,67,64,6e,6e,64,
61,6c,62,6d,00,00
"haahkogddiaeplmo"=hex:6b,61,70,68,69,6c,67,6f,69,6f,66,67,65,67,64,6e,64,67,
69,6b,6a,63,00,00
.
Completion time: 2010-01-10 15:04:41
ComboFix-quarantined-files.txt 2010-01-10 20:04

Pre-Run: 15,831,883,776 bytes free
Post-Run: 15,922,688,000 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 974C727EA368D3D1F3222E4A0755BCDE

Thanks. :D
Hi,

Looking better, a few bits and bobs left to deal with.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\wa.exe
C:\kalx8.exe
C:\ufc0q919.exe
C:\popcinfot.dat

FileLook::
C:\complete.exe
C:\ldraw027.exe
3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt.
Please also post C:\QooBox\Add-Remove Programs.txt.


OK, now let's get a thorough second opinion from an online AntiVirus scan.

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Let me know how things are running after this, and if any problems remain.
Hey,

Computer seems to in good condition now.
I don't see any anything acting funny, although the online scanner says otherwise?

Below are the logs you requested:

ComboFix 10-01-04.01 - Steven Zeng 0/2010 Sun 15:51:00.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.932.81.1033.18.2038.1441 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Steven Zeng\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100110-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"C:\kalx8.exe"
"C:\popcinfot.dat"
"C:\ufc0q919.exe"
"C:\wa.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\kalx8.exe
C:\popcinfot.dat
C:\ufc0q919.exe
C:\wa.exe

.
((((((((((((((((((((((((( Files Created from 2009-12-10 to 2010-01-10 )))))))))))))))))))))))))))))))
.

2010-01-08 23:56 . 2009-12-24 16:58 6515976 —ha-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\in00000\setup.exe
2010-01-08 23:56 . 2009-12-24 16:54 730032 —ha-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ar00000\install.exe
2010-01-07 17:07 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 17:07 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 17:00 . 2010-01-07 17:00 ——– d—–w- c:\windows\system32\wbem\Repository
2010-01-07 16:59 . 2010-01-07 16:59 ——– d—–w- C:\KEY
2010-01-06 18:32 . 2010-01-06 18:32 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\Malwarebytes
2010-01-06 18:31 . 2010-01-06 18:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-06 18:31 . 2010-01-07 17:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-06 18:29 . 2010-01-07 16:59 ——– d—–w- c:\program files\ERUNT
2010-01-06 18:07 . 2009-12-24 16:58 6515976 —ha-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\Upgrade\setup1.exe
2010-01-06 18:07 . 2009-12-24 16:54 730032 —ha-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\Upgrade\install1.exe
2010-01-06 18:07 . 2010-01-08 23:56 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp
2010-01-06 13:17 . 2010-01-06 02:53 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-06 13:17 . 2010-01-06 02:53 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-06 13:17 . 2010-01-06 02:53 2033432 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-06 13:17 . 2010-01-06 02:52 916248 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-06 13:17 . 2010-01-06 02:53 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-06 13:17 . 2010-01-06 02:53 3967256 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-06 04:51 . 2009-11-24 23:49 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-06 04:51 . 2009-11-24 23:48 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-06 04:51 . 2009-11-24 23:47 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-06 04:51 . 2009-11-24 23:47 97480 —-a-w- c:\windows\system32\AvastSS.scr
2010-01-06 04:51 . 2009-11-24 23:51 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-06 04:51 . 2009-11-24 23:50 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-06 04:51 . 2009-11-24 23:50 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-06 04:51 . 2009-11-24 23:50 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-06 04:51 . 2009-11-24 23:54 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2010-01-06 04:51 . 2010-01-06 04:51 ——– d—–w- c:\program files\Alwil Software
2010-01-06 04:13 . 2010-01-06 04:13 388096 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-06 04:13 . 2010-01-06 04:13 ——– d—–w- c:\program files\TrendMicro
2010-01-06 02:53 . 2010-01-06 02:54 ——– d—–w- C:\$AVG
2010-01-06 02:53 . 2010-01-06 02:53 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-06 02:53 . 2010-01-06 02:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-06 02:53 . 2010-01-06 02:53 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-06 02:53 . 2010-01-06 02:53 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-06 02:53 . 2010-01-10 14:15 ——– d—–w- c:\windows\system32\drivers\Avg
2010-01-06 02:52 . 2010-01-06 02:52 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-06 02:36 . 2010-01-06 02:36 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-06 00:12 . 2010-01-10 20:33 ——– d—–w- c:\windows\system32\NtmsData
2010-01-05 20:43 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp\st00000
2010-01-05 20:43 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp\in00000
2010-01-05 20:43 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp\ar00000
2010-01-05 20:31 . 2010-01-05 20:31 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
2010-01-05 04:49 . 2010-01-05 23:34 ——– d–h–w- c:\documents and settings\mjusbsp\Upgrade
2010-01-05 04:49 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp\ug00000
2010-01-05 04:49 . 2010-01-05 23:34 ——– d—–w- c:\documents and settings\mjusbsp
2010-01-05 02:57 . 2010-01-05 02:57 ——– d—–w- c:\program files\Windows Resource Kits
2010-01-05 01:01 . 2010-01-05 01:01 ——– d—–w- c:\documents and settings\Steven Zeng\Local Settings\Application Data\tjnet
2010-01-05 00:18 . 2008-04-13 19:45 60032 -c–a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-01-05 00:18 . 2008-04-13 19:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-12-29 22:28 . 2009-12-29 22:28 ——– d—–w- c:\program files\Fraps
2009-12-27 16:44 . 2009-12-27 16:44 ——– d—–w- c:\program files\GOG.com
2009-12-26 01:27 . 2009-12-26 01:27 ——– d—–w- c:\windows\system32\LogFiles
2009-12-26 01:23 . 2009-12-26 06:08 ——– d—–w- c:\program files\Microsoft Bootvis
2009-12-25 05:59 . 2009-12-25 05:59 ——– d—–w- c:\windows\EffectResources
2009-12-25 05:59 . 2008-04-14 01:12 53760 -c–a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2009-12-25 05:59 . 2008-04-14 01:12 53760 —-a-w- c:\windows\system32\vfwwdm32.dll
2009-12-25 02:44 . 2008-12-30 19:11 57344 —-a-w- c:\windows\ZSSnp211.exe
2009-12-25 02:44 . 2008-12-30 19:10 49152 —-a-w- c:\windows\Domino.exe
2009-12-25 02:44 . 2008-12-30 19:11 94208 —-a-w- c:\windows\system32\VvFtCtrl.dll
2009-12-25 02:44 . 2008-12-30 19:11 81920 —-a-w- c:\windows\system32\ZS211STI.dll
2009-12-25 02:44 . 2008-12-30 19:11 77824 —-a-w- c:\windows\ZS211Cap.exe
2009-12-25 02:44 . 2008-12-30 19:11 480128 —-a-w- c:\windows\system32\drivers\vvftav211.sys
2009-12-25 02:44 . 2008-12-30 19:11 1537280 —-a-w- c:\windows\system32\drivers\ZS211.sys
2009-12-25 02:44 . 2008-12-30 19:10 217088 —-a-w- c:\windows\amcap.exe
2009-12-25 02:44 . 2009-12-25 02:44 ——– d—–w- c:\program files\Vimicro
2009-12-24 16:59 . 2009-12-24 16:59 93016 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ug00000\magicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 6515976 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ug00000\setup.exe
2009-12-24 16:58 . 2009-12-24 16:58 416328 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\magicJackLoader.exe
2009-12-24 16:58 . 2009-12-24 16:58 416328 —-a-w- c:\documents and settings\mjusbsp\magicJackLoader.exe
2009-12-24 16:58 . 2009-12-24 16:58 480608 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\octvqe1_apiw.dll
2009-12-24 16:58 . 2009-12-24 16:58 480608 —-a-w- c:\documents and settings\mjusbsp\octvqe1_apiw.dll
2009-12-24 16:58 . 2009-12-24 16:58 214360 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\TjVista.dll
2009-12-24 16:58 . 2009-12-24 16:58 214360 —-a-w- c:\documents and settings\mjusbsp\TjVista.dll
2009-12-24 16:58 . 2009-12-24 16:58 337240 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\TjIpSys.dll
2009-12-24 16:58 . 2009-12-24 16:58 337240 —-a-w- c:\documents and settings\mjusbsp\TjIpSys.dll
2009-12-24 16:58 . 2009-12-24 16:58 607600 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\SJHandsetMagicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 607600 —-a-w- c:\documents and settings\mjusbsp\SJHandsetMagicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 87384 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\st00000\mjsetup.exe
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\st00000\magicJack.dll
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\magicJack.dll
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\mjusbsp\magicJack.dll
2009-12-24 16:55 . 2009-12-24 16:55 12482904 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\magicJack.exe
2009-12-24 16:55 . 2009-12-24 16:55 12482904 —-a-w- c:\documents and settings\mjusbsp\magicJack.exe
2009-12-24 16:54 . 2009-12-24 16:54 730032 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ug00000\install.exe
2009-12-24 16:53 . 2009-12-24 16:53 87384 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\in00000\mjsetup.exe
2009-12-24 16:53 . 2009-12-24 16:53 93016 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\in00000\magicJack.dll
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\st00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\in00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\mjusbsp\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 50520 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\cdloader2.exe
2009-12-24 16:52 . 2009-12-24 16:52 50520 —-a-w- c:\documents and settings\mjusbsp\cdloader2.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-10 20:48 . 2009-04-11 22:07 ——– d—–w- c:\program files\Nakido
2010-01-10 15:52 . 2009-11-12 21:28 0 —-a-w- c:\documents and settings\Steven Zeng\Local Settings\Application Data\prvlcl.dat
2010-01-09 05:00 . 2009-08-31 18:01 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\uTorrent
2010-01-09 04:31 . 2008-05-14 22:13 ——– d—–w- c:\program files\Paint.NET
2010-01-06 18:28 . 2007-10-12 19:04 79016 —-a-w- c:\documents and settings\Steven Zeng\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-11 15:48 . 2009-12-11 15:48 45056 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{24EEF6D7-A7B6-4AA9-AFD9-407185A7769F}\MapleStory.exe1_24EEF6D7A7B64AA9AFD9407185A7769F.exe
2009-12-11 15:48 . 2009-12-11 15:48 45056 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{24EEF6D7-A7B6-4AA9-AFD9-407185A7769F}\MapleStory.exe_24EEF6D7A7B64AA9AFD9407185A7769F.exe
2009-12-11 15:48 . 2009-12-11 15:48 10134 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{24EEF6D7-A7B6-4AA9-AFD9-407185A7769F}\ARPPRODUCTICON.exe
2009-12-11 05:27 . 2009-01-06 02:15 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2009-12-09 16:07 . 2009-05-17 14:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-07 23:49 . 2009-12-07 23:49 ——– d—–w- c:\program files\Google
2009-12-07 23:41 . 2009-12-07 23:41 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\LEGO Company
2009-12-07 23:33 . 2009-12-07 23:30 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\DassaultSystemes
2009-12-07 23:30 . 2009-12-07 23:30 ——– d—–w- c:\documents and settings\All Users\Application Data\DassaultSystemes
2009-12-06 03:51 . 2009-12-06 03:51 ——– d—–w- c:\program files\Lame for Audacity
2009-11-21 08:46 . 2009-11-21 08:46 86016 —-a-w- c:\windows\system32\frapsvid.dll
2009-11-20 07:26 . 2009-11-20 07:26 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\runic games
2009-11-20 07:20 . 2009-11-20 07:20 ——– d—–w- c:\program files\Runic Games
2009-11-16 20:14 . 2007-10-13 14:02 ——– d—–w- c:\program files\Java
2009-11-16 20:13 . 2009-11-16 20:13 152576 —-a-w- c:\documents and settings\Steven Zeng\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-16 20:13 . 2009-11-16 20:13 79488 —-a-w- c:\documents and settings\Steven Zeng\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-12 23:52 . 2009-08-20 17:13 ——– d—–w- c:\documents and settings\Steven Zeng\Application Data\HpUpdate
2009-11-11 18:35 . 2009-11-11 18:35 45056 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\MapleStory.exe1_A6CCAEF5F1414BBEA6DAEA8A8362C7A6.exe
2009-11-11 18:35 . 2009-11-11 18:35 45056 —-a-r- c:\documents and settings\Steven Zeng\Application Data\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\MapleStory.exe_A6CCAEF5F1414BBEA6DAEA8A8362C7A6.exe
2009-10-29 07:45 . 2006-03-04 03:33 916480 ——w- c:\windows\system32\wininet.dll
2009-10-23 00:58 . 2009-10-23 00:58 210325 —-a-w- c:\windows\Screen Calipers Uninstaller.exe
2009-10-22 21:17 . 2009-10-22 21:17 210029 —-a-w- c:\windows\Screen Protractor Uninstaller.exe
2009-10-21 05:38 . 2004-08-10 11:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 11:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 11:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-20 04:39 . 2009-10-20 04:38 5477735 —-a-w- C:\complete.exe
2009-10-20 04:38 . 2009-10-20 04:38 1147865 —-a-w- C:\ldraw027.exe
2009-10-13 10:30 . 2004-08-10 11:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-07-15 16:58 . 2008-06-29 14:01 56 –sha-r- c:\windows\system32\AAB26C16E3.sys
2008-07-17 13:22 . 2008-06-29 14:01 1682 -csha-w- c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

— C:\complete.exe —
Company: ——
File Description: ——
File Version: ——
Product Name: ——
Copyright: ——
Original Filename: ——
File size: 5477735
Created time: 2009-10-20 04:38
Modified time: 2009-10-20 04:39
MD5: 00DF3C51FBD97E979211CF1180C01D09
SHA1: 2F94E44BC8D75FE43AD0AD76BC947C05E1ED0ED2


— C:\ldraw027.exe —
Company: ——
File Description: ——
File Version: ——
Product Name: ——
Copyright: ——
Original Filename: ——
File size: 1147865
Created time: 2009-10-20 04:38
Modified time: 2009-10-20 04:38
MD5: 89AC31FBE776D288DD891446832B6E0A
SHA1: 8CA7D2E00A86688C975B86B72A88C455B0BDD7B5


((((((((((((((((((((((((((((( SnapShot@2010-01-10_20.02.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-10 20:48 . 2010-01-10 20:48 16384 c:\windows\Temp\Perflib_Perfdata_484.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-22 133104]
"Aim"="c:\program files\AIM7\aim.exe" [2009-10-05 3634024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-20 282624]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2008-12-30 57344]
"Domino"="c:\windows\Domino.exe" [2008-12-30 49152]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-06 02:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-01-06 13:17 2033432 —-a-w- c:\progra~1\AVG\AVG9\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2009-12-24 16:52 50520 —-a-w- c:\documents and settings\Steven Zeng\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Funshion]
2008-12-22 06:21 2768896 —-a-w- c:\program files\Funshion Online\Funshion\Funshion.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-11-22 05:27 133104 —-atw- c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-09-19 13:36 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-06-03 12:46 251240 —-a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
2008-09-26 23:14 3660848 —-a-w- c:\program files\Veoh Networks\Veoh\VeohClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TomTomHOMEService"=2 (0x2)
"idsvc"=3 (0x3)
"magicJack Service"=2 (0x2)
"RosettaStoneDaemon"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Nexon\\MapleStory\\MapleStory.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Nexon\\MapleStory\\Patcher.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Funshion Online\\Funshion\\Funshion.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Nakido\\nakido.exe"=
"c:\\Documents and Settings\\Steven Zeng\\Desktop\\PACNyx v0.6.0\\PACNyx.exe"=
"c:\\Program Files\\softnyx\\GunboundWC\\GunBound.gme"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\DFO\\DFO.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\program files\RosettaStoneLtdServices\RosettaStoneLtdServices.exe"= c:\program files\RosettaStoneLtdServices\RosettaStoneLtdServices.exe:127.0.0.1/255.255.255.255:Enabled:Rosetta Stone Ltd Services
"c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe"= c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe:127.0.0.1/255.255.255.255:Enabled:Rosetta Stone Daemon
"c:\\Program Files\\AIM7\\aim.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\LocalService\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Documents and Settings\\Steven Zeng\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57572:TCP"= 57572:TCP:Pando Media Booster
"57572:UDP"= 57572:UDP:Pando Media Booster
"57923:TCP"= 57923:TCP:Pando Media Booster
"57923:UDP"= 57923:UDP:Pando Media Booster
"56712:TCP"= 56712:TCP:Pando Media Booster
"56712:UDP"= 56712:UDP:Pando Media Booster
"56278:TCP"= 56278:TCP:Pando Media Booster
"56278:UDP"= 56278:UDP:Pando Media Booster

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [1/5/2010 11:51 PM 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/5/2010 9:53 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/5/2010 9:53 PM 360584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/5/2010 11:51 PM 20560]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/5/2010 9:52 PM 285392]
R2 Nakido;Nakido;c:\program files\Nakido\nakido.exe [7/9/2009 6:24 PM 328704]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/26/2009 12:58 PM 24652]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/30/2007 10:53 AM 717296]
S2 gupdate1ca2d864da01f8c;Google Update Service (gupdate1ca2d864da01f8c);"c:\program files\Google\Update\GoogleUpdate.exe" /svc –> c:\program files\Google\Update\GoogleUpdate.exe [?]
S2 MagicJack;MagicJack;c:\program files\Windows Resource Kits\Tools\srvany.exe [4/18/2003 6:06 PM 46]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [12/24/2009 9:44 PM 480128]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [12/24/2009 9:44 PM 1537280]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 7:28 PM 47128]
S4 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [4/25/2009 7:45 PM 443712]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [7/10/2008 1:49 AM 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/10/2008 7:28 PM 369688]
S4 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [6/3/2009 7:46 AM 92008]
.
Contents of the 'Scheduled Tasks' folder

2010-01-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-01-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-1336601894-682003330-1003Core.job
- c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-22 05:27]

2010-01-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-1336601894-682003330-1003UA.job
- c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-22 05:27]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: google.com
Trusted Zone: yahoo.com
TCP: {A4453425-32A4-4E0F-8FE9-E75F72C2BF9E} = 167.206.254.2,167.206.254.1
DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - hxxp://avatar.mabinogi.jp/3drender/renderer/mabiweb.2007.4.4.cab
FF - ProfilePath - c:\documents and settings\Steven Zeng\Application Data\Mozilla\Firefox\Profiles\6rmkf1jm.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Steven Zeng\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - false.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-10 15:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1275210071-1336601894-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{27FE8F59-AF60-59E4-7E11-E86FCD04D166}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jaojmkffkejfheginmim"=hex:62,61,63,69,00,00
"jaojmkffkejfheginmmm"=hex:62,61,6f,68,00,00
"iaogiaceghbhoglono"=hex:6b,61,70,68,69,6c,67,6f,69,6f,66,67,65,67,64,6e,6e,64,
61,6c,62,6d,00,00
"haahkogddiaeplmo"=hex:6b,61,70,68,69,6c,67,6f,69,6f,66,67,65,67,64,6e,64,67,
69,6b,6a,63,00,00
.
Completion time: 2010-01-10 15:59:06
ComboFix-quarantined-files.txt 2010-01-10 20:59
ComboFix2.txt 2010-01-10 20:04

Pre-Run: 15,937,314,816 bytes free
Post-Run: 15,898,218,496 bytes free

- - End Of File - - 1A6BFA6580925281B521C6EEC50B4EEA

7-Zip 4.65
AAC Decoder
AC3Filter (remove only)
Acrobat.com
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.2
Adobe Shockwave Player 11.5
AIM 7
Aliens vs. Predator 2
Apple Mobile Device Support
Apple Software Update
Audacity 1.2.6
AutoUpdate
avast! Antivirus
AVG Free 9.0
Beneton Movie GIF 1.1.2
BitLord 1.1
Bonjour
BufferChm
CDisplay 1.8
Combined Community Codec Pack 2008-09-21 16:18
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Critical Update for Windows Media Player 11 (KB959772)
CustomerResearchQFolder
D4100
D4100_Help
DAEMON Tools Toolbar
Dassault Systemes Software Prerequisites x86
Dell Driver Reset Tool
Dell Resource CD
DeviceManagementQFolder
DFOLauncher
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
Download Updater (AOL LLC)
eSupportQFolder
Evil Genius
Fraps
Funshion Movie on Demand
GemMaster Mystic
Google Chrome
Google SketchUp 7.1
Google Update Helper
GunboundWC
H.264 Decoder
Hexecute RC7
High Definition Audio Driver Package - KB835221
HiJackThis
Hotfix for Microsoft .NET Framework 3.0 (KB932471)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB945282)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946040)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946308)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946344)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947540)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947789)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB948127)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB951708)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB945282)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB946040)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB946308)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB947540)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB947789)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Customer Participation Program 7.0
HP Imaging Device Functions 7.0
HP Photosmart and Deskjet 7.0 Software
HP Photosmart Essential
HP Product Assistant
HP Solution Center 7.0
HP Update
hph_ProductContext
hph_readme
hph_software
hph_software_req
HPPhotoSmartExpress
HPProductAssistant
HPSSupply
InstantShareDevicesMFC
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
Java™ 6 Update 17
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
LAME v3.98.2 for Audacity
Mabinogi
Malwarebytes' Anti-Malware
MapleStory
MarketResearch
Mega Manager
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - JPN
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - JPN
Microsoft .NET Framework 3.5 Language Pack SP1 - jpn
Microsoft .NET Framework 3.5 Language Pack SP1 - 日本語
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Bootvis
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Project 2007 Service Pack 2 (SP2)
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2008
Microsoft SQL Server 2008 Browser
Microsoft SQL Server 2008 Common Files
Microsoft SQL Server 2008 Database Engine Services
Microsoft SQL Server 2008 Database Engine Shared
Microsoft SQL Server 2008 Management Objects
Microsoft SQL Server 2008 Native Client
Microsoft SQL Server 2008 RsFx Driver
Microsoft SQL Server 2008 Setup Support Files (English)
Microsoft SQL Server Compact 3.5 SP1 Design Tools English
Microsoft SQL Server Compact 3.5 SP1 English
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
Microsoft Visual C# 2008 Express Edition with SP1 - ENU
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
MKV Splitter
Mozilla Firefox (3.5.7)
MSXML 6.0 Parser (KB933579)
Nakido
OpenAL
OpenOffice.org Installer 1.0
Otto
Paint.NET v3.5.2
Pando Media Booster
PanoStandAlone
Persona 4 Analyzer
Python 2.6.2
QuickTime
Ragnarok Battle Offline
RagnarokOnline
RBO Extra Scenario Vol.1
RBO Extra Scenario Vol.2
RBO Extra Scenario Vol.3
RealPlayer
RGSS-RTP Standard
Rhapsody Player Engine
Rome - Total War™
Rosetta Stone Ltd Services
Screen Calipers
Screen Protractor
Search Settings 1.1
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Shop for HP Supplies
SigmaTel Audio
SnagIt 7
SolutionCenter
Sonic Encoders
Source Edit 4.0
Sql Server Customer Experience Improvement Program
SQL Server System CLR Types
Starcraft
Status
TomTom HOME 2.6.4.1641
TomTom HOME Visual Studio Merge Modules
Toolbox
Torchlight
TrayApp
Unload
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Outlook 2007 Junk Email Filter (kb976884)
Update for Windows Internet Explorer 8 (KB969497)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
VC80CRTRedist - 8.0.50727.762
VeohTV BETA
Versal FileDownload ActiveX Control Trial Version
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Warcraft III: All Products
WebFldrs XP
WebReg
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Movie Maker 2.0
Windows Presentation Foundation
Windows Resource Kit Tools
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
XML Paper Specification Shared Components Language Pack 1.0
XML Paper Specification Shared Components Pack 1.0
XviD MPEG-4 Codec
ZSMC USB PC Camera (ZS0211)
μTorrent

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=56107303dea5d44b8ce1fd1875230a93
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-01-10 11:29:07
# local_time=2010-01-10 06:29:07 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=769 16775141 100 98 0 198517600 0 0
# compatibility_mode=1024 16777191 100 0 4332304 4332304 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=101037
# found=229
# cleaned=0
# scan_time=8102
C:\Documents and Settings\Steven Zeng\Application Data\Sun\Java\Deployment\cache\6.0\47\4934abef-30bf9e56 probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Documents and Settings\Steven Zeng\Application Data\Sun\Java\Deployment\cache\6.0\58\22f687a-4d0fb48d probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\[4]-Submit_2010-01-10_15.50.51.zip a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettings.exe.vir Win32/Adware.Toolbar.Dealio application 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Program Files\Search Settings\kb126\SearchSettings.dll.vir Win32/Adware.Toolbar.Dealio application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP677\A0156036.dll probably a variant of Win32/PSW.OnLineGames trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP677\A0156094.dll probably a variant of Win32/PSW.OnLineGames trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP687\A0158929.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP687\A0158933.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP687\A0158963.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP687\A0158965.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP688\A0158983.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP688\A0159005.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP688\A0159023.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP688\A0160023.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP688\A0161023.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP689\A0161034.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP689\A0161044.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP689\A0162044.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP689\A0162056.inf Win32/PSW.OnLineGames.NMY trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP693\A0162212.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162240.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162256.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162271.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162283.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162311.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162337.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162407.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162412.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162454.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0162455.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0163454.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0163455.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0164454.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0164455.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0165454.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0165455.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0166454.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0166455.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0167454.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP694\A0167455.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0167479.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0167480.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0167484.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0167490.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0167491.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0168490.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0168491.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0169490.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0169491.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0170490.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0170491.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0171490.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0171491.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0171495.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0172491.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0173491.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0173500.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0174500.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0175500.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0176500.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0176513.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0177513.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0178513.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0179514.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0180514.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP695\A0181514.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP696\A0182514.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP696\A0182524.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP696\A0182528.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP696\A0183524.dll a variant of Win32/Pacex.Gen virus 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP696\A0183525.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0183543.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0184524.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0184525.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0185524.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0185525.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0186524.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0186525.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0187524.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0187525.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0187535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0187536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0188535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0188536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0189535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0189537.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0190535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0190536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0191535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0191536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0192535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0192536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0193535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0193536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0194535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0195535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0195536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0196535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0196536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0197535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0198535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0199535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0199536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0200535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0200536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0200539.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0200540.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0201535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0201536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0202535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0202536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0203535.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0203536.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0203546.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0203547.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0204546.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0204547.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0205546.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0205547.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0205564.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0205565.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0205567.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP697\A0205568.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0205597.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0205609.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0205610.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0205642.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0205643.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0205645.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0205646.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0206646.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0206647.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0206665.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP698\A0206670.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP699\A0206705.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0206740.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0207062.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0207086.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0207087.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0207088.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0207103.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0207104.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0207106.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP700\A0207107.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207109.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207113.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207115.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207116.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207117.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207167.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207168.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207288.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207289.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207305.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207306.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207309.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207326.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207338.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207362.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207378.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207386.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207403.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207404.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207591.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207605.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207623.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207624.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207627.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207628.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207816.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207817.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207829.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207860.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207861.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207871.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207872.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0207876.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0208023.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP701\A0208025.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP702\A0208030.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP702\A0208045.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP702\A0208046.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP703\A0208049.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP703\A0208088.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP703\A0208089.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP704\A0208104.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP705\A0208127.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP705\A0208152.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP705\A0208153.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP705\A0208179.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP705\A0208180.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP706\A0208187.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP706\A0208217.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP706\A0208226.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP706\A0208234.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP706\A0208235.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP706\A0208299.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP706\A0208301.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP706\A0208302.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0208306.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0209329.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0210327.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0210328.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0211327.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0211328.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0211383.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0211393.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0211395.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0211396.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0215398.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0216397.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0216398.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0217397.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0217398.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0217410.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0217411.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0218406.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0218408.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0218409.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0218412.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0219414.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP707\A0219415.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP708\A0219421.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP708\A0219433.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP708\A0219441.dll a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP708\A0219443.exe a variant of Win32/PSW.OnLineGames.ORO trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP711\A0222051.dll Win32/Adware.Toolbar.Dealio application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{EE166BBC-7EF4-42C8-B5D1-C3BD723E267F}\RP711\A0222052.exe Win32/Adware.Toolbar.Dealio application 00000000000000000000000000000000 I

Thanks again!
A lot of what ESET found is in your System Restore. This is inactive, and will be cleared when we uninstall ComboFix. The other entries were lingering in your Java Cache, which we will deal with now.

Open your Control Panel and double-click Java. Click the Settings… button in the Temporary Internet Files box on the General tab. Click Delete Files…, ensure all boxes are selected, then click OK.

Click Start >> Run, and copy/paste the following command then hit Enter:
cmd /c del /Q "c:\documents and settings\Steven Zeng\Local Settings\Application Data\prvlcl.dat"

Do you recognize these files?
C:\complete.exe
C:\ldraw027.exe

They look like they may be part of something called LegoDraw? If you didn't install/download a program like that, or don't recognize them, then delete them.

Open your Control Panel and double-click Add/Remove Programs. Find and Remove these old versions of Java:
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7


AVG and Avast are both still showing in your logs, and also in the Add/Remove list:
avast! Antivirus
AVG Free 9.0

You can uninstall the one you want to get rid of on the Add/Remove Programs list.

Any more problems at all?
Yes, I used ldraw for a school project a few months ago. I deleted the ldraw folder, ldraw.exe and complete.exe since I'm not using them anymore. Also uninstalled AVG completely this time. There are no more problems. :)
OK, just one step to uninstall ComboFix, and then we're done :thumbup:

Click Start >> Run, and then type ComboFix /u and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Now that your system appears to be clean, there's just a few steps I'd like you to consider to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
ComboFix didn't uninstall when I did the following (It did another scan): Click Start >> Run, and then type ComboFix /u and hit enter. The link is also broken, but I'm guessing it's the first article that pops up when googling "so how did i get infected in the first place"? Besides that, I'll keep my computer updated, and in check. Thanks for the help, jpshortstuff! :D
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI