This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware Defense Trojan

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, so i get on my PC running XP and i find out i have this Malware Defense virus. I remember i had it a few years ago and got rid of it with Malware Bytes, but this time when i tried to run it, it wouldn't open. Next thing i do is try to restart the computer, i do that and then it pretty much freezes after a minute or so. After doing that i ran the computer through Safe Mode with networking and ran the Malware program, it found no viruses on safe mode. Next thing i do is restart back into regular mode and this time i can actually open the Malware program but it scans for about 12 seconds and freezes at some System 32 file. The last thing i tried was to do a system restore through safe mode. I find a date and press 'Next' button but it doesn't do anything, it just stays at the same screen for hours. I ran everything but GMER in safe mode, i couldnt get it to open for some reason. Could you also help with that? Now for the logs: DDS (Ver_09-12-01.01) - NTFSx86 NETWORK Run by [removed] at 16:47:45.25 on Mon 01/18/2010 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.621 [GMT -5:00] AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9} AV: avast! antivirus 4.8.1368 [VPS 100117-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Emil\Desktop\dds.scr ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: Babylon: {965b54b0-71e0-4611-8de7-f73fa0b20e26} - c:\program files\babylon\babylon toolbar\BabylonIEToolBar.dll TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll uRun: [RocketDock] "c:\windows\bricopacks\vista inspirat 2\rocketdock\RocketDock.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [cls_pack.exe] c:\docume~1\emil\locals~1\temp\cls_pack.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin mRun: [QuickTime Task] "c:\program files\qt lite\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe StartupFolder: c:\docume~1\emil\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE IE: &Search IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Translate with &Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Translate.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - hxxp://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187919102890 DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} - hxxp://support.gateway.com/support/serialharvest/gwCID.CAB DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} - hxxp://www.worldwinner.com/games/v49/luxor/luxor.cab DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} - hxxp://www.worldwinner.com/games/v67/swapit/swapit.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: navnet - {AD6E5643-7B0C-46AA-95AD-9773FF2A857A} - c:\program files\navnetapp\ComUtilities.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll Hosts: 91.212.65.122 spyware-protector-2009.com Hosts: 91.212.65.122 www.spyware-protector-2009.com Hosts: 91.212.65.122 secure.spyware-protector-2009.com Hosts: 91.212.65.122 knocker ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\emil\applic~1\mozilla\firefox\profiles\gscqgllo.default\ FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query= FF - prefs.js: browser.search.selectedEngine - AIM Search FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query= FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\documents and settings\emil\application data\mozilla\firefox\profiles\gscqgllo.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPStreamPlug.dll FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\qt lite\plugins\npqtplugin.dll FF - plugin: c:\program files\qt lite\plugins\npqtplugin2.dll FF - plugin: c:\program files\qt lite\plugins\npqtplugin3.dll FF - plugin: c:\program files\qt lite\plugins\npqtplugin4.dll FF - plugin: c:\program files\qt lite\plugins\npqtplugin5.dll FF - plugin: c:\program files\qt lite\plugins\npqtplugin6.dll FF - plugin: c:\program files\qt lite\plugins\npqtplugin7.dll FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-28 114768] S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-28 20560] S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-28 138680] S2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\program files\autodesk\3ds max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-3-12 86016] S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2009-4-16 3032360] S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-8-28 24652] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-8-28 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-8-28 352920] S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2009-6-2 33792] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-2-10 38496] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2009-1-29 89256] S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2009-1-29 15016] S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2009-1-29 120744] S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2009-1-29 114216] S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2009-1-29 25512] S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2009-1-29 110632] S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2009-1-29 115752] S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-4-16 15144] =============== Created Last 30 ================ 2010-01-16 06:44:55 0 d—–w- c:\docume~1\alluse~1\applic~1\Poser 2010-01-16 06:44:32 0 d—–w- c:\docume~1\emil\applic~1\Poser 2010-01-16 06:19:31 0 d—–w- c:\program files\Smith Micro 2010-01-13 01:02:59 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll 2010-01-08 02:01:19 215920 —-a-w- c:\windows\system32\muweb.dll 2010-01-08 02:01:18 274288 —-a-w- c:\windows\system32\mucltui.dll 2010-01-08 02:01:18 16736 —-a-w- c:\windows\system32\mucltui.dll.mui 2010-01-07 02:29:42 0 d—–w- c:\documents and settings\emil\Tracing 2010-01-07 02:28:26 0 d—–w- c:\program files\Microsoft 2010-01-07 02:28:10 0 d—–w- c:\program files\Windows Live SkyDrive 2010-01-07 02:25:15 0 d—–w- c:\program files\common files\Windows Live 2010-01-04 01:38:29 0 d—–w- c:\documents and settings\emil\.assistant 2010-01-03 04:03:48 0 d—–w- c:\documents and settings\emil\scenes 2010-01-03 02:07:37 0 d—–w- c:\program files\Next Limit 2009-12-31 07:34:42 0 d—–w- c:\program files\NavNetApp ==================== Find3M ==================== 2009-10-29 05:38:23 667136 —-a-w- c:\windows\system32\wininet.dll 2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll 2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll 2009-02-03 23:51:35 162 —-a-w- c:\program files\setuplog.txt 2008-02-27 16:05:16 0 —-a-w- c:\program files\temp01 2007-11-04 06:28:32 23 —-a-w- c:\program files\hfkud16.sys 2007-11-04 22:10:37 8 –sh–r- c:\windows\system32\DB347142E2.sys 2007-11-04 22:10:37 848 –sha-w- c:\windows\system32\KGyGaAvL.sys ============= FINISH: 16:48:41.84 ===============
[external image: Posted Image]

Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Please download HostsXpert from the link below.

http://www.funkytoad.com/download/HostsXpert.zip

Unzip HostsXpert.zip
Open HostsXpert.exe.

you have to click: ''make hosts writable'' in the top right corner, then press the ''restore MS hosts file'' option

Close program when complete.

Empty Recycle Bin

Reboot and also please describe how your computer behaves at the moment.
I am currently trying to do this and i have a few questions. First when i run HostsXpert i do not see the "make hosts writable" in the top right corner, there is nothing there. Next, after i reboot do i reboot into safe mode or start up normally? And finally a while back i got rid of my recycle bin to replace with mac style icons, and in safe mode those icons do not come up and the recycle bin isint there, so could you tell me how to get it back so i can empty it. Thanks.
Ok well now i dont even get to log into my account. After i reboot the computer and the windows xp logo comes up the screen just goes black and my cursor comes up. And thats about it, i can move it around but nothing else. The screen is just completely black,
These are showing in your DDS scan. That's what's causing part of your problems. Hosts: 91.212.65.122 spyware-protector-2009.com Hosts: 91.212.65.122 www.spyware-protector-2009.com Hosts: 91.212.65.122 secure.spyware-protector-2009.com Hosts: 91.212.65.122 knocker

So what do i do with them? How can i get rid of them.

That file I have you download and run should have removed them.
Can you try Safe Mode and see if you get the desktop icons?

After i did the first part i got some microsoft word icons. If you want i can get a screen shot and upload it.

See if you can get (MBAM) MalwareBytes to run.
It runs on safe mode, and i tried a quick scan but nothing was found. When i try to reboot normally i get that black screen so i cant even log in to start MBAM.
Try this in Safe Mode then. 1. Click Start. 2. Point to All Programs. 3. Point to Accessories. 4. Point to System Tools. 5. Click System Restore. 6. Follow the instructions on the wizard. See if you can find a date the the PC worked.
I had tried that already. Once i can pick a date i press next, and at the next screen when i press Next it does absolutely nothing. No matter how much time i wait nothing happens.
If that doesn't work do this:

Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer.


Download Combofix from any of the links below but rename it to ABCD.exe before saving it to your desktop.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Link 1
Link 2


Double click on the ABCD.exe ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.


**Note: It is important that it is saved directly to your desktop**

——————————————————————–

With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.


Go to Microsoft's website => http://support.microsoft.com/kb/310994

Scroll down to Step 1, and select the download that's appropriate for your Operating System. Download the file & save it as it's originally named.

Note: If you have SP3, use the SP2 package.


———————————————————————

Transfer all files you just downloaded, to the desktop of the infected computer.

——————————————————————–


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

[external image: Posted Image]


  • Drag the setup package onto ComboFix.exe and drop it.

  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.


    [external image: Posted Image]


  • At the next prompt, click 'Yes' to run the full ComboFix scan.

  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply using Copy/Paste.


Notes:

Give it atleast 20-30 minutes to finish if needed.

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Also please describe how your computer behaves in your next reply.
Ok here is the log i ran in safe mode.

ComboFix 10-01-20.04 - Emil 01/20/2010 20:06:53.1.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.795 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ABCD.exe
Command switches used :: c:\documents and settings\Emil\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: avast! antivirus 4.8.1368 [VPS 100117-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Java\jre6\bin\jucheck.exe
c:\windows\run.log
c:\windows\system32\drivers\H8SRToqxwnkniqa.sys
c:\windows\system32\H8SRTeonbpdurfc.dll
c:\windows\system32\H8SRTidyllvioto.dll
c:\windows\system32\H8SRTiqjwsouxbh.dll
c:\windows\system32\h8srtkrl32mainweq.dll
c:\windows\system32\H8SRTotfmurqpap.dat
c:\windows\system32\h8srtshsyst.dll
c:\windows\system32\H8SRTwmuydvxegw.dll
c:\windows\system32\prsgrc.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_H8SRTd.sys
——-\Legacy_H8SRTd.sys


((((((((((((((((((((((((( Files Created from 2009-12-21 to 2010-01-21 )))))))))))))))))))))))))))))))
.

2010-01-21 00:57 . 2010-01-21 01:01 ——– d—–w- C:\ABCD
2010-01-16 06:44 . 2010-01-16 06:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Poser
2010-01-16 06:44 . 2010-01-16 06:44 ——– d—–w- c:\documents and settings\Emil\Application Data\Poser
2010-01-16 06:19 . 2010-01-16 06:19 ——– d—–w- c:\program files\Smith Micro
2010-01-13 01:02 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-08 07:12 . 2010-01-08 07:12 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2010-01-08 02:01 . 2009-08-07 00:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-01-08 02:01 . 2009-08-07 00:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-01-07 02:29 . 2010-01-18 08:50 ——– d—–w- c:\documents and settings\Emil\Tracing
2010-01-07 02:28 . 2010-01-07 02:28 ——– d—–w- c:\program files\Microsoft
2010-01-07 02:28 . 2010-01-07 02:28 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-01-07 02:27 . 2010-01-07 02:28 ——– d—–w- c:\program files\Windows Live
2010-01-07 02:25 . 2010-01-07 02:25 ——– d—–w- c:\program files\Common Files\Windows Live
2010-01-04 01:38 . 2010-01-04 01:38 ——– d—–w- c:\documents and settings\Emil\.assistant
2010-01-03 04:03 . 2010-01-04 01:49 ——– d—–w- c:\documents and settings\Emil\scenes
2010-01-03 02:07 . 2010-01-03 02:07 ——– d—–w- c:\program files\Next Limit
2009-12-31 07:34 . 2009-12-31 07:34 ——– d—–w- c:\program files\NavNetApp
2009-12-29 02:18 . 2009-12-29 03:57 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\PMB Files

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 00:43 . 2010-01-21 00:43 777 —-a-w- c:\documents and settings\All Users\Application Data\h8srtkrl32mainweq.dll
2010-01-18 08:49 . 2009-04-16 14:57 ——– d—–w- c:\documents and settings\Emil\Application Data\WTablet
2010-01-18 08:49 . 2009-03-25 02:35 ——– d—–w- c:\documents and settings\Emil\Application Data\DNA
2010-01-18 08:49 . 2008-07-04 22:25 ——– d—–w- c:\program files\DNA
2010-01-18 06:19 . 2009-02-10 21:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-18 06:11 . 2009-04-17 13:17 ——– d—–w- c:\documents and settings\LocalService\Application Data\WTablet
2010-01-18 04:58 . 2009-03-25 02:35 ——– d—–w- c:\documents and settings\Emil\Application Data\BitTorrent
2010-01-18 03:29 . 2009-05-02 17:08 ——– d—–w- c:\documents and settings\Guest\Application Data\WTablet
2010-01-13 06:59 . 2009-01-14 03:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-09 08:54 . 2007-08-25 00:20 88808 —-a-w- c:\documents and settings\Emil\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-09 08:21 . 2009-01-14 03:25 ——– d—–w- c:\program files\Microsoft Works
2010-01-03 02:07 . 2007-08-23 04:04 ——– d—–w- c:\program files\Common Files\InstallShield
2009-12-29 02:18 . 2008-11-17 19:44 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2009-12-08 00:04 . 2008-12-02 21:43 ——– d—–w- c:\documents and settings\Guest\Application Data\Apple Computer
2009-11-24 23:54 . 2009-08-28 07:50 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-08-28 07:51 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-08-28 07:51 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-08-28 07:51 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-08-28 07:51 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-08-28 07:51 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-08-28 07:51 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-08-28 07:51 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-08-28 07:51 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 05:38 . 2006-02-28 12:00 667136 —-a-w- c:\windows\system32\wininet.dll
2009-02-03 23:51 . 2009-02-03 23:51 162 —-a-w- c:\program files\setuplog.txt
2008-02-27 16:05 . 2008-02-27 16:05 0 —-a-w- c:\program files\temp01
2007-11-04 06:28 . 2007-11-04 06:28 23 —-a-w- c:\program files\hfkud16.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2007-11-04 22:10 . 2007-11-04 22:10 8 –sh–r- c:\windows\system32\DB347142E2.sys
2007-11-04 22:10 . 2007-11-04 22:10 848 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 630784]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-14 323392]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-12-23 2935480]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-27 198160]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"QuickTime Task"="c:\program files\QT Lite\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

c:\documents and settings\Emil\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SetPointII.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SetPointII.lnk
backup=c:\windows\pss\SetPointII.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Emil^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Emil\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Emil^Start Menu^Programs^Startup^RocketDock.lnk]
path=c:\documents and settings\Emil\Start Menu\Programs\Startup\RocketDock.lnk
backup=c:\windows\pss\RocketDock.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-11 00:51 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\Reader_SL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2004-07-20 17:22 57344 —-a-w- c:\windows\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2004-08-24 18:01 2552320 —-a-w- c:\windows\ALCWZRD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-11-14 02:56 323392 —-a-w- c:\program files\DNA\btdna.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
2005-02-08 03:00 98304 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIACA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-06-26 21:13 1207080 —-a-w- c:\progra~1\MICROS~3\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2004-03-17 19:10 61952 —-a-w- c:\windows\system32\Hdaudpropshortcut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-06-05 17:39 292136 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2007-07-17 21:39 55824 —-a-w- c:\windows\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-10-07 18:33 13574144 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-10-07 18:33 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-10-07 18:33 1630208 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2007-08-07 00:05 200704 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 21:18 413696 —-a-w- c:\program files\QT Lite\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-10-31 23:42 32768 —-a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
2007-03-18 22:05 630784 —-a-w- c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-08-24 18:14 77824 —-a-w- c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
2008-08-13 22:06 3660848 —-a-w- c:\program files\Veoh Networks\Veoh\VeohClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2008-10-09 22:11 3502840 —-a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Documents and Settings\\Emil\\My Documents\\download\\Other\\Recents\\BeatPack 0.8.1 Beta\\BeatPack.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2010\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Next Limit\\RealFlow4\\realflow.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Smith Micro\\Poser 8\\Poser.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"57839:TCP"= 57839:TCP:Pando Media Booster
"57839:UDP"= 57839:UDP:Pando Media Booster
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"56882:TCP"= 56882:TCP:Pando Media Booster
"56882:UDP"= 56882:UDP:Pando Media Booster
"58032:TCP"= 58032:TCP:Pando Media Booster
"58032:UDP"= 58032:UDP:Pando Media Booster
"57578:TCP"= 57578:TCP:Pando Media Booster
"57578:UDP"= 57578:UDP:Pando Media Booster

S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/28/2009 2:51 AM 114768]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/28/2009 2:51 AM 20560]
S2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [3/12/2009 4:36 PM 86016]
S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [4/16/2009 9:56 AM 3032360]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/28/2007 10:18 PM 24652]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [6/2/2009 5:37 PM 33792]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2/10/2009 4:24 PM 38496]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [1/29/2009 9:05 PM 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [1/29/2009 9:05 PM 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [1/29/2009 9:05 PM 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [1/29/2009 9:05 PM 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [1/29/2009 9:05 PM 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [1/29/2009 9:05 PM 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [1/29/2009 9:05 PM 115752]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [4/16/2009 9:56 AM 15144]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/2/2009 3:46 PM 721904]
.
Contents of the 'Scheduled Tasks' folder

2009-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Search;
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Translate with &Babylon; - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
FF - ProfilePath - c:\documents and settings\Emil\Application Data\Mozilla\Firefox\Profiles\gscqgllo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;=
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Emil\Application Data\Mozilla\Firefox\Profiles\gscqgllo.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPStreamPlug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin.dll
FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin6.dll
FF - plugin: c:\program files\QT Lite\Plugins\npqtplugin7.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-AIM - c:\program files\AIM\aim.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_07\bin\jusched.exe
AddRemove-Adobe SVG Viewer - c:\program files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe
AddRemove-Pcsx2_is1 - c:\program files\Pcsx2_0.9.4\unins000.exe
AddRemove-SWiSH Max2 - c:\windows\unvise32.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-20 20:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-746137067-1060284298-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)

[HKEY_USERS\S-1-5-21-746137067-1060284298-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ED32AB90-7CA5-7E88-A248-601CBE747AED}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-746137067-1060284298-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:49,e1,7e,9c,6e,cc,ab,aa,d9,4f,55,fd,5d,03,2b,92,e8,1a,62,e1,68,07,ea,
ab,5d,b9,8f,3b,c8,f5,55,45,cc,85,76,e3,23,0e,21,51,2c,ae,bf,4e,e5,ab,f0,be,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50

[HKEY_USERS\S-1-5-21-746137067-1060284298-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:99,f1,f8,48,ed,7f,a3,42,6a,b8,48,4f,60,f9,c9,64,f4,74,49,df,00,
84,26,c9,b1,55,f4,97,da,01,57,19,e2,5f,e1,50,51,65,1b,05,60,92,90,6c,de,e2,\
"rkeysecu"=hex:26,03,9b,74,77,74,5d,33,6f,37,5a,ae,e9,47,ef,de
.
Completion time: 2010-01-20 20:32:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-21 01:32
ComboFix2.txt 2009-03-17 18:35

Pre-Run: 134,457,106,432 bytes free
Post-Run: 138,387,824,640 bytes free

- - End Of File - - A02D445BFF10AA9F49A500F1482B30EF

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI