This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected with Gen:Trojan.Heur.iq8@YcK6Ffe

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,I have had to re-post as I did not follow the correct procedure before :blush: Anyway…..I thought I was malware free up until I decided to do a free online Virus scan with Bitdefender.After the scan completed it found two trojans calledTrojan.Wimad.Gen.1 which it disinfected and one Trojan called Gen:Trojan.Heur.iq8@YcK6Ffe which it failed to delete.I then clicked on the send report for analysis.I then ran an E-SET online san and it did not detect anything.I ran Avast stand-alone removal tool and this also did not pick up any detections. I still have a copy of the Bitdefender log file which I will post last.First I will post Mbytes,G-mer and DDS logs >>> Malwarebytes' Anti-Malware 1.44
Database version: 3632
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

25/01/2010 05:39:05
mbam-log-2010-01-25 (05-39-05).txt

Scan type: Quick Scan
Objects scanned: 114220
Time elapsed: 3 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-25 06:03:15
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Alistair\LOCALS~1\Temp\kfqiqaog.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xABDC458C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xABDC4E0C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xABDC5922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xABDC5E94]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwCreateFile [0xAB5B9772]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xABDC3436]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xABDC5D6C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xABDC4192]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xABDC5C28]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xABDC434E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xABDC5FC6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xABDC7C08]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwCreateThread [0xAB5B8FAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xABDC5CCA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xABDC75FA]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwDeleteKey [0xAB5B9594]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwDeleteValueKey [0xAB5B9466]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xABDC5576]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xABDC85CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xABDC3ECA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xABDC3F74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xABDC5382]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwLoadDriver [0xAB5B8DE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xABDC3412]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xABDC3424]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwMapViewOfSection [0xAB5B8B84]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xABDC40C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xABDC5F36]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenFile [0xAB5B99C2]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenKey [0xAB5B9760]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xABDC5E04]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenProcess [0xAB5B90CE]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenSection [0xAB5B9234]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xABDC6068]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenThread [0xAB5B917E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xABDC401E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xABDC3C46]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xABDC7FD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xABDC3896]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwQueueApcThread [0xAB5B905C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xABDC3B0E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xABDC32B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xABDC63F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xABDC62B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xABDC739A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xABDCAE2C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xABDC84AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xABDC3248]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSecureConnectPort [0xAB5B9AF0]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetContextThread [0xAB5B8B16]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xABDC6C4A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xABDC7786]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetSystemInformation [0xAB5B8F3E]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetValueKey [0xAB5B9660]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xABDC81F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xABDC8320]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xABDC7526]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwTerminateProcess [0xAB5B934C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xABDC4860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xABDC7E8A]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwWriteVirtualMemory [0xAB5B8A48]

Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

—- EOF - GMER 1.0.15 —-



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 6:04:34.79 on 25/01/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3326.2858 [GMT 0:00]

AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Alistair\Desktop\dds.scr

============== Pseudo HJT Report ===============

BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll
uRun: [EPSON SX410 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifce.exe /fu "c:\windows\temp\E_SC.tmp" /EF "HKCU"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
mRun: [SkyTel] SkyTel.EXE
mRun: [AntiLogger] "c:\program files\antilogger\AntiLogger.exe" /minimized
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {4248FE82-7FCB-46AC-B270-339F08212110}
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\kloehk.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: GrcorticOcm.Grcortic: {79b34a1f-d8fd-474f-84f3-8622d06faf40} - c:\windows\system32\grcortic.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\alistair\applic~1\mozilla\firefox\profiles\pbbl1whh.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://m.uk.yahoo.com/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-1-7 28552]
R1 AntiLog32;AntiLog32;c:\program files\antilogger\AntiLog32.sys [2010-1-12 116072]
R1 EIO_XP;EIO_XP;c:\windows\system32\drivers\EIO_XP.sys [2010-1-21 12288]
R1 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2009-9-1 128016]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-12-15 315408]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-12-15 1858144]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-1-6 12672]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2010-1-5 14976]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2010-1-20 93184]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
R3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [2009-12-16 532992]
S2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-10-20 340456]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\c0.tmp –> c:\windows\system32\C0.tmp [?]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2009-12-17 14424]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-1-11 16456]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-1-11 11088]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S3 Video3D;ASUS Video3D Service;c:\windows\system32\drivers\video3d32.sys –> c:\windows\system32\drivers\Video3D32.sys [?]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2009-12-15 90352]

=============== Created Last 30 ================

2010-01-24 11:21 –d—– c:\program files\MAME
2010-01-23 06:17 –d—– c:\docume~1\alistair\applic~1\QuickScan
2010-01-21 13:10 –d—– c:\program files\ATI Technologies
2010-01-21 13:10 –d—– c:\program files\ATI
2010-01-21 13:09 –d—– C:\ATI
2010-01-21 12:11 12,288 a—-r– c:\windows\system32\drivers\EIO_XP.sys
2010-01-21 12:09 53,760 ac—— c:\windows\system32\dllcache\vfwwdm32.dll
2010-01-21 12:09 53,760 a——- c:\windows\system32\vfwwdm32.dll
2010-01-21 12:08 –d—– c:\program files\ASUS
2010-01-21 10:05 –d—– c:\program files\Essentials Codec Pack
2010-01-21 08:09 –d—– c:\docume~1\alistair\applic~1\PowerUp Software
2010-01-21 08:08 –d—– c:\docume~1\alluse~1\applic~1\PowerUp Software
2010-01-21 06:38 –d—– c:\program files\ESET
2010-01-20 09:32 195,072 a—-r– c:\windows\system32\fdco1ins.dll
2010-01-20 09:32 195,072 a—-r– c:\windows\system32\fdco1.dll
2010-01-20 09:32 53,632 a—-r– c:\windows\system32\drivers\NVENETFD.sys
2010-01-20 09:32 4,805 a——- c:\windows\system32\nvnrm.nvu
2010-01-20 09:31 888,064 a—-r– c:\windows\system32\drivers\nvnrm.sys
2010-01-20 09:31 37,376 a—-r– c:\windows\system32\nvconrm.dll
2010-01-20 09:31 22,016 a—-r– c:\windows\system32\drivers\nvnetbus.sys
2010-01-20 09:31 9,216 a—-r– c:\windows\system32\bdco1ins.dll
2010-01-20 09:31 9,216 a—-r– c:\windows\system32\bdco1.dll
2010-01-20 09:19 –d—– c:\program files\common files\ATI Technologies
2010-01-20 09:07 10 a——- c:\windows\WININIT.INI
2010-01-20 09:06 0 a——- c:\windows\ativpsrm.bin
2010-01-20 09:06 19,017 a——- c:\windows\atiogl.xml
2010-01-20 09:05 93,184 a—-r– c:\windows\system32\drivers\AtiHdmi.sys
2010-01-20 08:58 –d—– c:\program files\My Company Name
2010-01-20 06:46 –d—– c:\program files\SpeedFan
2010-01-20 06:46 45 a——- c:\windows\system32\initdebug.nfo
2010-01-18 06:49 –d—– c:\docume~1\alistair\applic~1\KALiNKOsoft
2010-01-13 01:58 –d—– c:\program files\FairUse Wizard 2
2010-01-13 01:06 –d—– c:\docume~1\alistair\applic~1\AnvSoft
2010-01-13 01:06 –d—– c:\program files\AnvSoft
2010-01-12 22:32 –d—– c:\program files\common files\DivX Shared
2010-01-12 19:31 -cd-h— c:\docume~1\alluse~1\applic~1\{ADBE1C37-5B60-41F1-8C26-C3F880D609C1}
2010-01-12 08:48 8,576 a——- c:\windows\system32\drivers\apgiywudryke.sys
2010-01-12 08:44 8,576 a——- c:\windows\system32\drivers\admqnrgkhnlw.sys
2010-01-12 08:43 8,576 a——- c:\windows\system32\drivers\yeoqjaedbosu.sys
2010-01-12 08:42 8,576 a——- c:\windows\system32\drivers\ywghcedstlcr.sys
2010-01-12 08:41 8,576 a——- c:\windows\system32\drivers\ynltosggncjp.sys
2010-01-12 08:40 8,576 a——- c:\windows\system32\drivers\ydugtctlvwoo.sys
2010-01-12 08:37 8,576 a——- c:\windows\system32\drivers\yhikanbisygi.sys
2010-01-12 08:34 –d—– c:\documents and settings\alistair\Pavark
2010-01-12 08:19 161,296 a——- c:\windows\system32\drivers\tmcomm.sys
2010-01-12 07:21 –d—– c:\program files\JockerSoft
2010-01-12 01:06 27,612 a——- c:\windows\syscall.dat
2010-01-12 01:06 –d—– c:\program files\AntiLogger
2010-01-11 23:09 461,368 a——- c:\windows\system32\pwNative.exe
2010-01-11 23:09 16,456 a——- c:\windows\system32\pwdrvio.sys
2010-01-11 23:09 11,088 a——- c:\windows\system32\pwdspio.sys
2010-01-11 23:09 –d—– c:\program files\Partition Wizard Home Edition 4.2.2
2010-01-10 22:13 –d—– c:\documents and settings\alistair\.thumbnails
2010-01-10 22:08 –d—– c:\documents and settings\alistair\.gimp-2.6
2010-01-10 21:13 –d—– c:\docume~1\alluse~1\applic~1\Simply Super Software
2010-01-10 15:09 –d—– c:\documents and settings\alistair\DoctorWeb
2010-01-10 14:23 –d—– c:\windows\Performance
2010-01-10 05:10 –d—– c:\docume~1\alluse~1\applic~1\Innovative Solutions
2010-01-10 05:10 –d—– c:\program files\Innovative Solutions
2010-01-09 12:00 –d—– c:\windows\$regcmp$
2010-01-09 11:56 –d—– c:\program files\Intel Corporation
2010-01-09 11:52 –d—– c:\program files\SystemRequirementsLab
2010-01-08 12:21 –d—– c:\docume~1\alluse~1\applic~1\DriverScanner
2010-01-08 12:21 –d—– c:\docume~1\alistair\applic~1\Uniblue
2010-01-08 11:37 –d—– c:\windows\system32\%PersonalRootCertificateFolder%
2010-01-07 01:46 28,552 a——- c:\windows\system32\drivers\pavboot.sys
2010-01-07 01:45 –d—– c:\program files\Panda Security
2010-01-06 15:15 –d-h— C:\VJVod_Cache
2010-01-06 02:17 12,672 a——- c:\windows\system32\drivers\cpuz132_x32.sys
2010-01-06 02:17 –d—– c:\program files\CPUID
2010-01-06 02:12 –d—– c:\program files\Wise Registry Cleaner
2010-01-06 02:09 3,840 a——- c:\windows\system32\drivers\BANTExt.sys
2010-01-06 02:09 –d—– c:\program files\Belarc
2010-01-06 01:34 –d—– c:\program files\VS Revo Group
2010-01-06 01:09 –d—– c:\program files\Registry Clean Expert
2010-01-05 20:51 –d—– c:\program files\AviSynth 2.5
2010-01-05 20:25 –d—– c:\program files\DVD Shrink
2010-01-05 20:22 –d—– c:\program files\DVD Decrypter
2010-01-05 20:19 –d—– c:\docume~1\alistair\applic~1\RipIt4Me
2010-01-05 00:51 14,976 a——- c:\windows\system32\drivers\SBKUPNT.SYS
2010-01-05 00:51 13,312 a——- c:\windows\system32\DEVLOAD.EXE
2010-01-05 00:50 2,799 a——- c:\windows\SKLANG.INI
2010-01-05 00:50 306,688 a——- c:\windows\IsUninst.exe
2010-01-04 21:39 –d—– c:\windows\system32\NtmsData
2010-01-04 19:46 –d—– c:\program files\LSoft Technologies
2010-01-04 00:27 11,254 a——- c:\windows\system32\locate.com
2010-01-03 21:51 –d—– c:\docume~1\alistair\applic~1\Mp3tag
2010-01-03 21:51 –d—– c:\program files\Mp3tag
2010-01-03 21:41 –d—– c:\docume~1\alluse~1\applic~1\F-Secure
2010-01-03 19:14 1,071,088 a——- c:\windows\system32\MSCOMCTL.OCX
2010-01-03 19:14 118,784 a——- c:\windows\system32\MSSTDFMT.DLL
2010-01-03 19:14 –d—– c:\program files\SpywareBlaster
2010-01-03 17:43 –d—– c:\windows\system32\Adobe
2010-01-03 16:58 3,426,072 a——- c:\windows\system32\d3dx9_32.dll
2010-01-03 16:58 2,414,360 a——- c:\windows\system32\d3dx9_31.dll
2010-01-03 16:58 –d—– c:\windows\Logs
2010-01-02 20:29 1,184,984 a——- c:\windows\system32\wvc1dmod.dll
2010-01-02 20:29 626,688 a——- c:\windows\system32\vp7vfw.dll
2010-01-02 20:29 217,127 a——- c:\windows\system32\drv43260.dll
2010-01-02 20:29 208,935 a——- c:\windows\system32\drv33260.dll
2010-01-02 20:29 176,165 a——- c:\windows\system32\drv23260.dll
2010-01-02 20:29 102,439 a——- c:\windows\system32\sipr3260.dll
2010-01-02 20:29 65,602 a——- c:\windows\system32\cook3260.dll
2010-01-02 20:26 87,608 a——- c:\docume~1\alistair\applic~1\inst.exe
2010-01-02 20:06 –d—– c:\windows\system32\QuickTime
2010-01-02 20:01 –d—– c:\docume~1\alistair\applic~1\PhotoFiltre
2010-01-02 20:01 –d—– c:\program files\PhotoFiltre
2010-01-02 19:55 –d—– c:\docume~1\alistair\applic~1\CBS Interactive
2010-01-02 17:29 –d—– c:\program files\Readon Technology
2010-01-02 16:49 –d—– c:\docume~1\alistair\applic~1\MozillaControl
2010-01-02 16:49 –d—– c:\program files\Mozilla ActiveX Control v1.7.12
2010-01-02 15:53 –d—– c:\windows\system32\nagasoft
2010-01-02 13:27 32 a——- c:\windows\system32\msvcsv60.dll
2009-12-29 22:17 –d—– c:\docume~1\alistair\applic~1\TuneUp Software
2009-12-29 22:17 –d—– c:\docume~1\alluse~1\applic~1\TuneUp Software
2009-12-29 22:17 –dsh— c:\docume~1\alluse~1\applic~1\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-29 15:24 –d—– c:\program files\IrfanView
2009-12-28 07:16 a-dshr– C:\cmdcons
2009-12-27 07:28 –d—– c:\program files\CCleaner

==================== Find3M ====================

2010-01-21 08:08 119,296 a——- c:\windows\system32\zlib.dll
2010-01-07 16:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-02 20:29 47,360 a——- c:\windows\system32\drivers\pcouffin.sys
2010-01-02 20:29 47,360 a——- c:\docume~1\alistair\applic~1\pcouffin.sys
2009-12-25 06:57 218,624 a——- c:\windows\system32\uxtheme.dll
2009-12-24 06:13 96,512 ——– c:\windows\system32\drivers\atapi.sys
2009-12-21 19:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-15 07:46 411,368 a——- c:\windows\system32\deploytk.dll
2009-12-15 06:00 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-12-15 05:02 315,392 a——- c:\windows\HideWin.exe
2009-12-15 04:57 108,059 a——- c:\windows\system32\drivers\klin.dat
2009-12-15 04:57 95,259 a——- c:\windows\system32\drivers\klick.dat
2009-12-15 04:20 21,640 a——- c:\windows\system32\emptyregdb.dat
2009-12-14 14:20 131,072 a–shr– c:\windows\system32\grcortic.dll
2009-12-03 05:38 1,060,864 a——- c:\windows\system32\MFC71.dll
2009-11-25 03:27 446,464 a——- c:\windows\system32\ATIDEMGX.dll
2009-11-25 03:26 300,032 a——- c:\windows\system32\ati2dvag.dll
2009-11-25 03:11 208,896 a——- c:\windows\system32\atipdlxx.dll
2009-11-25 03:11 155,648 a——- c:\windows\system32\Oemdspif.dll
2009-11-25 03:10 26,112 a——- c:\windows\system32\Ati2mdxx.exe
2009-11-25 03:10 43,520 a——- c:\windows\system32\ati2edxx.dll
2009-11-25 03:10 155,648 a——- c:\windows\system32\ati2evxx.dll
2009-11-25 03:09 602,112 a——- c:\windows\system32\ati2evxx.exe
2009-11-25 03:07 53,248 a——- c:\windows\system32\ATIDDC.DLL
2009-11-25 02:59 311,296 a——- c:\windows\system32\atiiiexx.dll
2009-11-25 02:59 3,538,496 a——- c:\windows\system32\ati3duag.dll
2009-11-25 02:44 13,533,184 a——- c:\windows\system32\atioglxx.dll
2009-11-25 02:43 2,142,848 a——- c:\windows\system32\ativvaxx.dll
2009-11-25 02:42 887,724 a——- c:\windows\system32\ativva6x.dat
2009-11-25 02:26 65,024 a——- c:\windows\system32\atimpc32.dll
2009-11-25 02:26 65,024 a——- c:\windows\system32\amdpcom32.dll
2009-11-25 02:21 565,248 a——- c:\windows\system32\atikvmag.dll
2009-11-25 02:20 45,056 a——- c:\windows\system32\aticalrt.dll
2009-11-25 02:20 45,056 a——- c:\windows\system32\aticalcl.dll
2009-11-25 02:19 176,128 a——- c:\windows\system32\atiadlxx.dll
2009-11-25 02:18 17,408 a——- c:\windows\system32\atitvo32.dll
2009-11-25 02:18 3,612,672 a——- c:\windows\system32\aticaldd.dll
2009-11-25 02:17 397,312 a——- c:\windows\system32\atiok3x2.dll
2009-11-25 02:12 638,976 a——- c:\windows\system32\ati2cqag.dll
2009-11-21 15:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-21 02:34 592,488 a——- c:\windows\system32\nvudisp.exe
2009-11-19 21:42 592,488 a——- c:\windows\system32\NVUNINST.EXE
2009-11-14 00:49 120,056 ——– c:\windows\system32\pxcpyi64.exe
2009-11-14 00:49 118,520 ——– c:\windows\system32\pxinsi64.exe
2009-11-14 00:47 856,064 a——- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 856,064 a——- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 847,872 a——- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 843,776 a——- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 839,680 a——- c:\windows\system32\divx_xx11.dll
2009-10-29 04:48 499,712 a——- c:\windows\system32\msvcp71.dll
2009-10-29 04:48 348,160 a——- c:\windows\system32\msvcr71.dll

============= FINISH: 6:04:48.84 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 15/12/2009 04:23:46
System Uptime: 25/01/2010 05:26:31 (1 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5N-MX
Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz | Socket 775 | 2000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 233 GiB total, 182.772 GiB free.
D: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

Class GUID: {5458011F-08D4-4605-93A2-F03E61BEDBA3}
Description: Enhanced Display Driver Helper Service
Device ID: ROOT\ASUSOTHERDEVICES\0000
Manufacturer: ASUSTeK
Name: Enhanced Display Driver Helper Service
PNP Device ID: ROOT\ASUSOTHERDEVICES\0000
Service: asuskbnt

==== System Restore Points ===================

RP1: 25/01/2010 05:31:36 - System Checkpoint
RP2: 25/01/2010 05:31:48 - Automatic Restore Point

==== Installed Programs ======================

7-Zip 4.65
a-squared Free 4.5
AAC Decoder
ABBYY FineReader 6.0 Sprint
Active@ KillDisk FREE Suite
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Shockwave Player 11.5
Advanced SystemCare 3
Allok Video Joiner 4.4.1117
AmpliTube Metal
AmpliTube2
AntiLogger
Any Video Converter 3.0.1
ASIO4ALL
ASUS Utilities
ASUS VGA Driver
ATI Catalyst Install Manager
ATI Display Driver
µTorrent
AutoUpdate
AviSynth 2.5
Belarc Advisor 8.1
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
CCleaner
CodecInstaller 2.10.2
ConvertHelper 2.2
ConvertXtoDVD 4.0.9.322
CPUID CPU-Z 1.53
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Plus Web Player
DivX Version Checker
DriverMax 5
DVD Decrypter (Remove Only)
DVD Shrink 3.2
Epson Easy Photo Print 2
EPSON Scan
Epson Stylus SX210_SX410_TX210_TX410 Manual
EPSON SX410 Series Printer Uninstall
EPSON Web-To-Page
ERUNT 1.1j
ESET Online Scanner v3
FairUse Wizard 2
Foxit Reader
Free Download Manager 3.0
Free Registry Defrag
Full Tilt Poker
GrcorticOcm
H.264 Decoder
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976098-v2)
IconTweaker
ImgBurn
Intel® Processor ID Utility
IrfanView (remove only)
Java™ 6 Update 17
Kaspersky Internet Security 2010
Line 6 Uninstaller
Little Registry Cleaner
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MKV Splitter
Motorola Driver Installation
Mozilla Firefox (3.5.7)
Mp3tag v2.45a
NVIDIA Drivers
P2PFilter 3.0.5
Panda ActiveScan 2.0
Partition Wizard Home Edition 4.2.2
PC Pitstop Optimize3 3.0
PeerBlock 1.0.0 (r181)
PhotoFiltre
PicSizer
PokerStars
QuickTime
Readon TV Movie Radio Player [removed]
Realtek High Definition Audio Driver
Revo Uninstaller 1.85
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB976325)
Skins
Smart Defrag
Sophos Anti-Rootkit 1.5.0
SpeedFan (remove only)
SpywareBlaster 4.2
Styler
SUPERAntiSpyware Free Edition
Switch Sound File Converter
System Requirements Lab
Tweak UI
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.0.3
WebFldrs XP
Winamp
Windows Essentials Media Codec Pack 2.3d
Windows Internet Explorer 8
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Service Pack 3
Wise Registry Cleaner 4 Free 4.92

==== Event Viewer Messages From Past Week ========

21/01/2010 12:44:43, error: atapi [9] - The device, \Device\Ide\IdePort2, did not respond within the timeout period.
21/01/2010 12:27:37, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
21/01/2010 12:04:10, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\drivers\ati2mtag.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6891.
21/01/2010 11:53:14, error: Service Control Manager [7000] - The SBKUPNT service failed to start due to the following error: Access is denied.
21/01/2010 11:13:29, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
21/01/2010 11:13:19, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
21/01/2010 11:13:02, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BANTExt Fips intelppm kl1 KLIF pavboot SASDIFSV SASKUTIL
21/01/2010 11:12:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
21/01/2010 10:29:27, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
21/01/2010 08:08:48, error: Service Control Manager [7034] - The PinnacleUpdate Service service terminated unexpectedly. It has done this 1 time(s).
20/01/2010 09:32:11, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Type with the following error: Access is denied.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativvaxx.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.208.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativtmxx.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativmvxx.ax. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativdaxx.ax. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati3duag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.630.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati3d1ag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.4071.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2dvag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6891.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2dvaa.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.13.10.5019.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2cqag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.404.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\drivers\ati2mtag.sys could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ativvaxx.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati3duag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati2dvag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati2cqag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:44, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\nv4_disp.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:44, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\drivers\nv4_mini.sys could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:39, information: Windows File Protection [64002] - File replacement was attempted on the protected system file nv4_mini.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.5673.
20/01/2010 08:29:39, information: Windows File Protection [64002] - File replacement was attempted on the protected system file nv4_disp.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.5673.

==== End Of File ===========================


And here is the Bitdefender log > BitDefender Online Scanner







Scan report generated at: Fri, Jan 22, 2010 - 17:05:11









Scan path: C:\;D:\;F:\;G:\;H:\;I:\;J:\;















Statistics

Time


00:29:00

Files


162901

Folders


5827

Boot Sectors


0

Archives


1873

Packed Files


7751







Results

Identified Viruses


2

Infected Files


3

Suspect Files


0

Warnings


0

Disinfected


2

Deleted Files


0







Engines Info

Virus Definitions


4895792

Engine build


AVCORE v2.1 Windows/i386 11.0.0.33 (Nov 24 2009)

Scan plugins


17

Archive plugins


44

Unpack plugins


8

E-mail plugins


6

System plugins


4







Scan Settings

First Action


Disinfect

Second Action


Delete

Heuristics


Yes

Enable Warnings


Yes

Scanned Extensions


*;

Exclude Extensions




Scan Emails


Yes

Scan Archives


Yes

Scan Packed


Yes

Scan Files


Yes

Scan Boot


Yes








Scanned File


Status

C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq=>(Quarantine-6)


Infected with: Trojan.Wimad.Gen.1

C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq=>(Quarantine-6)


Disinfected

C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq


Update failed

C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq=>(Quarantine-6)


Infected with: Trojan.Wimad.Gen.1

C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq=>(Quarantine-6)


Disinfected

C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq


Update failed

C:\WINDOWS\system32\grcortic.dll


Infected with: Gen:Trojan.Heur.iq8@YcK6Ffe

C:\WINDOWS\system32\grcortic.dll


Disinfection failed

C:\WINDOWS\system32\grcortic.dll


Delete failed


I am concerned as I don't how dangerous this Trojan is and was wondering if I should change all my online banking details/passwords,etc,etc.?I really hope I don't have to re-format :pullhair: as I not long ago done a fresh install! Any help with this issue is greatly appreciated,thanks.
Hi,

Please do the following:

submit a file to virustotal for analysis
  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file c:\windows\system32\grcortic.dll
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results

Make sure you copy and save the results post the results in your next reply


NEXT



Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi CatByte ,thanks for the quick reply! I cannot seem to find this grcortic.dll in Windows System32 Folder,even when I use the search function.I almost forgot to tell you….A few days ago my Kaspersky updated and then said it found this trojan called Trojan Downloader Win32 U.B. uia and it was going to disinfect it and that I had to re-start my computer,however when it restarted it said it could not disinfect the file and prompted me to delete it which I decided not to do until I received a reply.Currently My AV has an exclamation on the icon and ocassionally says threat detected and gives me the option to neutralize.I am not sure what actions to take,should I continue with the combofix procedure?
Yes, my apologies, that file is hiding:

show hidden files and folders first:

  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.

You should now be able to see it to upload it.

If you still cannot find it - your AV may have moved it - continue on with ComboFix
Hi CatByte ,When I unchecked the system files I found it with a search.I tried sending the file to Virus Total however after sending a text came up saying 0 bytes sent and I went to try again but the grcortic.dll was gone :unsure: I searched for it using the search function and it was gone,the exclamation mark in kaspersky also disappeared….As I couldnt find it I went ahead with combofix.Here is the Combofix logfile >>> ComboFix 10-01-27.06 - Alistair 28/01/2010 17:00:47.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3326.2876 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Alistair\Application Data\inst.exe
c:\windows\system32\drivers\admqnrgkhnlw.sys
c:\windows\system32\Drivers\apgiywudryke.sys
c:\windows\system32\drivers\ydugtctlvwoo.sys
c:\windows\system32\drivers\yeoqjaedbosu.sys
c:\windows\system32\Drivers\yhikanbisygi.sys
c:\windows\system32\drivers\ynltosggncjp.sys
c:\windows\system32\Drivers\ywghcedstlcr.sys
c:\windows\system32\msvcsv60.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_admqnrgkhnlw
——-\Legacy_apgiywudryke
——-\Legacy_ydugtctlvwoo
——-\Legacy_yeoqjaedbosu
——-\Legacy_yhikanbisygi
——-\Legacy_ynltosggncjp
——-\Legacy_ywghcedstlcr
——-\Service_admqnrgkhnlw
——-\Service_apgiywudryke
——-\Service_ydugtctlvwoo
——-\Service_yeoqjaedbosu
——-\Service_yhikanbisygi
——-\Service_ynltosggncjp
——-\Service_ywghcedstlcr


((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-28 )))))))))))))))))))))))))))))))
.

2010-01-26 00:34 . 2010-01-26 00:36 ——– d—–w- c:\program files\Romcenter
2010-01-25 05:32 . 2010-01-25 05:33 ——– d—–w- c:\program files\ERUNT
2010-01-23 06:17 . 2010-01-23 07:28 ——– d—–w- c:\documents and settings\Alistair\Application Data\QuickScan
2010-01-22 16:20 . 2010-01-23 06:26 ——– d—–w- c:\windows\BDOSCAN8
2010-01-21 13:12 . 2010-01-21 13:12 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI
2010-01-21 13:09 . 2010-01-21 13:09 ——– d—–w- C:\ATI
2010-01-21 12:11 . 2006-06-14 13:44 12288 —-a-r- c:\windows\system32\drivers\EIO_XP.sys
2010-01-21 12:09 . 2008-04-14 00:12 53760 -c–a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-01-21 12:09 . 2008-04-14 00:12 53760 —-a-w- c:\windows\system32\vfwwdm32.dll
2010-01-21 12:08 . 2010-01-21 13:06 ——– d—–w- c:\program files\ASUS
2010-01-21 10:05 . 2010-01-28 10:36 ——– d—–w- c:\program files\Essentials Codec Pack
2010-01-21 08:09 . 2010-01-21 08:09 ——– d—–w- c:\documents and settings\Alistair\Application Data\PowerUp Software
2010-01-21 08:08 . 2010-01-21 08:08 ——– d—–w- c:\documents and settings\All Users\Application Data\PowerUp Software
2010-01-21 06:38 . 2010-01-21 06:38 ——– d—–w- c:\program files\ESET
2010-01-20 09:32 . 2007-09-20 10:07 53632 —-a-r- c:\windows\system32\drivers\NVENETFD.sys
2010-01-20 09:32 . 2007-09-20 10:07 195072 —-a-r- c:\windows\system32\fdco1ins.dll
2010-01-20 09:32 . 2007-09-20 10:07 195072 —-a-r- c:\windows\system32\fdco1.dll
2010-01-20 09:31 . 2007-09-20 10:07 22016 —-a-r- c:\windows\system32\drivers\nvnetbus.sys
2010-01-20 09:31 . 2007-09-20 10:07 888064 —-a-r- c:\windows\system32\drivers\nvnrm.sys
2010-01-20 09:31 . 2007-09-20 10:06 9216 —-a-r- c:\windows\system32\bdco1ins.dll
2010-01-20 09:31 . 2007-09-20 10:06 9216 —-a-r- c:\windows\system32\bdco1.dll
2010-01-20 09:31 . 2007-09-15 01:19 37376 —-a-r- c:\windows\system32\nvconrm.dll
2010-01-20 09:23 . 2010-01-20 09:23 ——– d—–w- c:\documents and settings\Alistair\Local Settings\Application Data\ATI
2010-01-20 09:23 . 2010-01-20 09:23 ——– d—–w- c:\documents and settings\Alistair\Application Data\ATI
2010-01-20 09:19 . 2010-01-20 09:19 ——– d—–w- c:\program files\Common Files\ATI Technologies
2010-01-20 09:06 . 2010-01-20 09:06 0 —-a-w- c:\windows\ativpsrm.bin
2010-01-20 09:05 . 2008-10-31 05:52 93184 —-a-r- c:\windows\system32\drivers\AtiHdmi.sys
2010-01-20 08:58 . 2010-01-20 08:58 ——– d—–w- c:\program files\My Company Name
2010-01-20 06:46 . 2010-01-21 15:31 ——– d—–w- c:\program files\SpeedFan
2010-01-18 07:35 . 2010-01-18 07:37 ——– d—–w- c:\documents and settings\Alistair\Application Data\dvdcss
2010-01-18 06:49 . 2010-01-18 06:49 ——– d—–w- c:\documents and settings\Alistair\Application Data\KALiNKOsoft
2010-01-18 06:47 . 2010-01-21 08:08 119296 —-a-w- c:\windows\system32\zlib.dll
2010-01-18 06:47 . 2008-01-13 19:59 36864 —-a-w- c:\windows\system32\dxinputdll.dll
2010-01-18 06:47 . 2008-01-13 16:36 91632 —-a-w- c:\windows\system32\dsofile.dll
2010-01-18 06:47 . 2007-04-04 18:53 81768 —-a-w- c:\windows\system32\xinput1_3.dll
2010-01-18 06:47 . 2001-04-05 06:43 94208 –s—r- c:\windows\system32\msstkprp.dll
2010-01-18 06:47 . 1999-05-17 13:55 57344 ——w- c:\windows\system32\ADsSecurity.dll
2010-01-18 06:47 . 1998-06-18 00:00 89360 —-a-w- c:\windows\system32\VB5DB.DLL
2010-01-17 09:09 . 2010-01-17 09:09 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2010-01-13 01:58 . 2010-01-13 01:58 ——– d—–w- c:\program files\FairUse Wizard 2
2010-01-13 01:06 . 2010-01-13 01:06 ——– d—–w- c:\documents and settings\Alistair\Application Data\AnvSoft
2010-01-13 01:06 . 2010-01-13 01:06 ——– d—–w- c:\program files\AnvSoft
2010-01-12 23:48 . 2010-01-12 23:48 138240 —-a-w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll
2010-01-12 23:48 . 2010-01-12 23:48 138240 —-a-w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll
2010-01-12 23:48 . 2010-01-12 23:48 138240 —-a-w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll
2010-01-12 23:48 . 2010-01-12 23:48 138240 —-a-w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll
2010-01-12 22:32 . 2010-01-12 22:32 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-01-12 19:31 . 2010-01-12 19:31 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{ADBE1C37-5B60-41F1-8C26-C3F880D609C1}
2010-01-12 19:31 . 2010-01-12 16:14 2680680 -c–a-w- c:\documents and settings\All Users\Application Data\{ADBE1C37-5B60-41F1-8C26-C3F880D609C1}\AntiLogger_Setup.exe
2010-01-12 08:34 . 2010-01-12 08:45 ——– d—–w- c:\documents and settings\Alistair\Pavark
2010-01-12 08:19 . 2010-01-12 08:19 161296 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2010-01-12 07:21 . 2010-01-12 07:21 ——– d—–w- c:\documents and settings\Alistair\Local Settings\Application Data\JockerSoft
2010-01-12 07:21 . 2010-01-12 07:21 ——– d—–w- c:\program files\JockerSoft
2010-01-12 01:06 . 2010-01-12 19:31 27612 —-a-w- c:\windows\syscall.dat
2010-01-12 01:06 . 2010-01-12 19:31 ——– d—–w- c:\program files\AntiLogger
2010-01-11 23:09 . 2009-12-21 20:39 461368 —-a-w- c:\windows\system32\pwNative.exe
2010-01-11 23:09 . 2009-12-21 20:39 16456 —-a-w- c:\windows\system32\pwdrvio.sys
2010-01-11 23:09 . 2009-12-21 20:39 11088 —-a-w- c:\windows\system32\pwdspio.sys
2010-01-11 23:09 . 2010-01-11 23:09 ——– d—–w- c:\program files\Partition Wizard Home Edition 4.2.2
2010-01-11 04:13 . 2010-01-11 04:13 ——– d—–w- c:\documents and settings\Alistair\Application Data\ImgBurn
2010-01-11 04:08 . 2010-01-11 04:08 ——– d—–w- c:\program files\ImgBurn
2010-01-10 22:13 . 2010-01-16 04:59 ——– d—–w- c:\documents and settings\Alistair\Application Data\gtk-2.0
2010-01-10 22:13 . 2010-01-10 22:13 ——– d—–w- c:\documents and settings\Alistair\.thumbnails
2010-01-10 22:08 . 2010-01-16 05:05 ——– d—–w- c:\documents and settings\Alistair\.gimp-2.6
2010-01-10 21:13 . 2010-01-10 21:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Simply Super Software
2010-01-10 15:09 . 2010-01-10 15:09 ——– d—–w- c:\documents and settings\Alistair\DoctorWeb
2010-01-10 14:23 . 2010-01-10 14:23 ——– d—–w- c:\windows\Performance
2010-01-10 14:23 . 2010-01-10 14:23 ——– d—–w- c:\documents and settings\Alistair\Local Settings\Application Data\Microsoft Corporation
2010-01-10 05:10 . 2010-01-10 05:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Innovative Solutions
2010-01-10 05:10 . 2010-01-10 05:10 ——– d—–w- c:\documents and settings\Alistair\Local Settings\Application Data\Innovative Solutions
2010-01-10 05:10 . 2010-01-10 05:10 ——– d—–w- c:\program files\Innovative Solutions
2010-01-09 12:00 . 2010-01-09 12:01 ——– d—–w- c:\windows\$regcmp$
2010-01-09 11:56 . 2010-01-09 11:56 ——– d—–w- c:\program files\Intel Corporation
2010-01-09 11:52 . 2010-01-09 11:52 ——– d—–w- c:\program files\SystemRequirementsLab
2010-01-09 11:52 . 2010-01-12 23:48 ——– d—–w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab
2010-01-09 11:52 . 2010-01-09 11:52 247296 —-a-w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab\SRLProxy_srl_4_0_11_0_d_ind.dll
2010-01-09 11:52 . 2010-01-09 11:52 247296 —-a-w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab\SRLProxy_srl_4_0_11_0_c_ind.dll
2010-01-09 11:52 . 2010-01-09 11:52 247296 —-a-w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab\SRLProxy_srl_4_0_11_0_b_ind.dll
2010-01-09 11:52 . 2010-01-09 11:52 247296 —-a-w- c:\documents and settings\Alistair\Application Data\SystemRequirementsLab\SRLProxy_srl_4_0_11_0_a_ind.dll
2010-01-08 12:21 . 2010-01-08 12:47 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverScanner
2010-01-08 12:21 . 2010-01-08 12:47 ——– d—–w- c:\documents and settings\Alistair\Application Data\Uniblue
2010-01-08 11:37 . 2010-01-08 11:37 ——– d—–w- c:\windows\system32\%PersonalRootCertificateFolder%
2010-01-07 01:46 . 2009-06-30 09:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2010-01-07 01:45 . 2010-01-07 01:45 ——– d—–w- c:\program files\Panda Security
2010-01-06 15:15 . 2010-01-06 15:15 ——– d—–w- C:\VJVod_Cache
2010-01-06 02:17 . 2010-01-06 02:17 ——– d—–w- c:\program files\CPUID
2010-01-06 02:17 . 2009-03-27 01:16 12672 —-a-w- c:\windows\system32\drivers\cpuz132_x32.sys
2010-01-06 02:12 . 2010-01-06 02:14 ——– d—–w- c:\program files\Wise Registry Cleaner
2010-01-06 02:09 . 2010-01-06 02:09 ——– d—–w- c:\program files\Belarc
2010-01-06 02:09 . 2008-02-27 12:49 3840 —-a-w- c:\windows\system32\drivers\BANTExt.sys
2010-01-06 01:34 . 2010-01-06 01:34 ——– d—–w- c:\program files\VS Revo Group
2010-01-06 01:09 . 2010-01-06 01:09 ——– d—–w- c:\program files\Registry Clean Expert
2010-01-05 20:51 . 2010-01-05 20:51 ——– d—–w- c:\program files\AviSynth 2.5
2010-01-05 20:50 . 2010-01-21 10:01 ——– d—–w- c:\program files\Gabest
2010-01-05 20:25 . 2010-01-05 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-01-05 20:25 . 2010-01-05 20:25 ——– d—–w- c:\program files\DVD Shrink
2010-01-05 20:22 . 2010-01-05 20:22 ——– d—–w- c:\program files\DVD Decrypter
2010-01-05 20:20 . 2010-01-05 20:20 643072 —-a-w- c:\documents and settings\Alistair\Application Data\RipIt4Me\updater\ri4mupdater.exe
2010-01-05 20:19 . 2010-01-05 21:04 ——– d—–w- c:\documents and settings\Alistair\Application Data\RipIt4Me
2010-01-05 00:52 . 2010-01-05 00:52 ——– d—–w- c:\documents and settings\Alistair\Local Settings\Application Data\Help
2010-01-05 00:51 . 2001-07-13 13:56 14976 —-a-w- c:\windows\system32\drivers\SBKUPNT.SYS
2010-01-05 00:51 . 1997-02-08 17:11 13312 —-a-w- c:\windows\system32\DEVLOAD.EXE
2010-01-05 00:50 . 1998-10-29 16:45 306688 —-a-w- c:\windows\IsUninst.exe
2010-01-04 21:39 . 2010-01-04 21:41 ——– d—–w- c:\windows\system32\NtmsData
2010-01-04 19:46 . 2010-01-04 19:46 ——– d—–w- c:\program files\LSoft Technologies
2010-01-04 00:27 . 2005-01-14 02:41 11254 —-a-w- c:\windows\system32\locate.com
2010-01-03 21:51 . 2010-01-03 21:51 ——– d—–w- c:\documents and settings\Alistair\Application Data\Mp3tag
2010-01-03 21:51 . 2010-01-03 21:51 ——– d—–w- c:\program files\Mp3tag
2010-01-03 21:41 . 2010-01-03 21:41 ——– d—–w- c:\documents and settings\All Users\Application Data\F-Secure
2010-01-03 19:14 . 2010-01-09 11:59 ——– d—–w- c:\program files\SpywareBlaster
2010-01-03 19:14 . 2005-08-25 19:18 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL
2010-01-03 17:43 . 2010-01-03 17:43 ——– d—–w- c:\windows\system32\Adobe
2010-01-03 17:41 . 2010-01-03 17:42 1956528 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2010-01-03 17:40 . 2010-01-03 20:30 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-03 16:58 . 2006-11-29 13:06 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2010-01-03 16:58 . 2006-09-28 16:05 2414360 —-a-w- c:\windows\system32\d3dx9_31.dll
2010-01-03 16:58 . 2010-01-03 16:58 ——– d—–w- c:\windows\Logs
2010-01-03 16:57 . 2010-01-03 19:20 ——– d—–w- c:\documents and settings\Alistair\Application Data\Winamp
2010-01-02 20:29 . 2009-09-02 21:58 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2010-01-02 20:29 . 2009-09-02 21:58 65602 —-a-w- c:\windows\system32\cook3260.dll
2010-01-02 20:29 . 2009-09-02 21:58 217127 —-a-w- c:\windows\system32\drv43260.dll
2010-01-02 20:29 . 2009-09-02 21:58 208935 —-a-w- c:\windows\system32\drv33260.dll
2010-01-02 20:29 . 2009-09-02 21:58 176165 —-a-w- c:\windows\system32\drv23260.dll
2010-01-02 20:29 . 2009-09-02 21:58 102439 —-a-w- c:\windows\system32\sipr3260.dll
2010-01-02 20:29 . 2009-09-02 21:57 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-28 17:07 . 2009-12-15 04:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-01-28 16:58 . 2009-12-15 10:35 ——– d—–w- c:\documents and settings\Alistair\Application Data\Vso
2010-01-28 16:07 . 2009-12-15 09:23 ——– d—–w- c:\documents and settings\Alistair\Application Data\Free Download Manager
2010-01-28 10:47 . 2009-12-16 02:54 32 —-a-w- c:\windows\msocreg32.dat
2010-01-26 15:59 . 2009-12-15 04:36 21432 —-a-w- c:\documents and settings\Alistair\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-23 18:04 . 2009-12-15 10:12 ——– d—–w- c:\documents and settings\Alistair\Application Data\uTorrent
2010-01-22 04:21 . 2010-01-21 13:10 ——– d—–w- c:\program files\ATI
2010-01-21 13:11 . 2010-01-21 13:10 ——– d—–w- c:\program files\ATI Technologies
2010-01-21 13:10 . 2010-01-21 13:10 10134 —-a-r- c:\documents and settings\Alistair\Application Data\Microsoft\Installer\{A778A787-08A4-4089-CB68-02A9737DE532}\ARPPRODUCTICON.exe
2010-01-21 13:06 . 2009-12-15 04:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-20 09:09 . 2009-12-15 04:45 ——– d—–w- c:\program files\NVIDIA Corporation
2010-01-20 08:56 . 2009-12-15 05:01 ——– d—–w- c:\program files\Common Files\InstallShield
2010-01-20 05:39 . 2009-12-16 04:38 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-17 12:55 . 2009-12-15 13:39 ——– d—–w- c:\program files\a-squared Free
2010-01-14 05:24 . 2009-12-15 08:07 ——– d—–w- c:\program files\IObit
2010-01-14 04:52 . 2009-12-15 09:47 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-12 22:33 . 2009-12-15 08:15 ——– d—–w- c:\program files\DivX
2010-01-12 09:50 . 2009-12-15 09:49 ——– d—–w- c:\program files\Common Files\Little Registry Cleaner
2010-01-12 09:24 . 2009-12-15 08:16 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-12 04:01 . 2009-12-15 08:36 ——– d—–w- c:\program files\Common Files\Real
2010-01-12 03:33 . 2009-12-16 01:56 ——– d—–w- c:\documents and settings\Alistair\Application Data\DivX
2010-01-12 02:41 . 2009-12-16 00:19 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2010-01-07 16:07 . 2009-12-15 08:16 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 . 2009-12-15 08:16 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 17:57 . 2009-12-15 08:07 ——– d—–w- c:\documents and settings\Alistair\Application Data\IObit
2010-01-05 19:58 . 2009-12-17 03:27 ——– d—–w- c:\program files\PeerBlock
2010-01-03 20:36 . 2009-12-20 12:37 52224 —-a-w- c:\documents and settings\Alistair\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-03 20:36 . 2009-12-15 08:21 117760 —-a-w- c:\documents and settings\Alistair\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-03 16:58 . 2009-12-24 08:15 ——– d—–w- c:\program files\Winamp
2010-01-02 20:42 . 2009-12-15 09:56 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-01-02 20:29 . 2009-12-15 10:35 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2010-01-02 20:29 . 2009-12-15 10:35 47360 —-a-w- c:\documents and settings\Alistair\Application Data\pcouffin.sys
2010-01-02 20:29 . 2009-12-15 10:35 47360 —-a-w- c:\documents and settings\Alistair\Application Data\pcouffin.sys
2010-01-02 20:29 . 2009-12-15 10:35 ——– d—–w- c:\program files\VSO
2010-01-02 17:37 . 2009-12-15 14:31 ——– d—–w- c:\program files\PokerStars
2010-01-02 17:37 . 2009-12-15 14:32 ——– d—–w- c:\program files\Full Tilt Poker
2009-12-29 15:24 . 2009-12-29 15:24 ——– d—–w- c:\program files\IrfanView
2009-12-27 07:28 . 2009-12-27 07:28 ——– d—–w- c:\program files\CCleaner
2009-12-25 07:03 . 2009-12-25 07:03 15086 —-a-r- c:\documents and settings\Alistair\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_7b12541d.exe
2009-12-25 07:03 . 2009-12-25 07:03 15086 —-a-r- c:\documents and settings\Alistair\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe
2009-12-25 07:03 . 2009-12-15 08:41 ——– d—–w- c:\program files\Styler
2009-12-25 06:57 . 2004-08-04 12:00 218624 —-a-w- c:\windows\system32\uxtheme.dll
2009-12-24 09:29 . 2009-12-24 09:29 ——– d—–w- c:\documents and settings\All Users\Application Data\DFX
2009-12-24 09:29 . 2009-12-24 09:29 ——– d—–w- c:\program files\Common Files\DFX
2009-12-24 06:13 . 2004-08-04 12:00 96512 ——w- c:\windows\system32\drivers\atapi.sys
2009-12-24 05:31 . 2009-12-24 05:28 ——– d—–w- c:\program files\Windows Live Safety Center
2009-12-23 14:56 . 2009-12-23 14:56 ——– d—–w- c:\program files\Trend Micro
2009-12-22 19:59 . 2009-12-22 19:59 ——– d—–w- c:\program files\P2PFilter
2009-12-21 19:14 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-20 12:36 . 2009-12-15 08:21 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-20 10:34 . 2009-12-20 10:33 ——– d—–w- c:\program files\Allok Video Joiner
2009-12-20 10:00 . 2009-12-20 10:00 ——– d—–w- c:\documents and settings\Alistair\Application Data\Xilisoft Corporation
2009-12-20 06:04 . 2009-12-20 05:50 ——– d—–r- c:\program files\UniversalTcpipPatch
2009-12-19 23:32 . 2009-12-19 23:32 ——– d—–w- c:\program files\ConvertHelper
2009-12-19 04:20 . 2009-12-16 07:05 ——– d—–w- c:\program files\QuickTime
2009-12-19 03:04 . 2009-12-19 03:04 ——– d—–w- c:\program files\Common Files\Motorola Shared
2009-12-18 01:37 . 2009-12-18 01:37 ——– d—–w- c:\program files\NCH Software
2009-12-18 01:34 . 2009-12-18 01:34 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-12-18 01:34 . 2009-12-18 01:34 ——– d—–w- c:\program files\NCH Swift Sound
2009-12-18 01:34 . 2009-12-18 01:34 ——– d—–w- c:\documents and settings\Alistair\Application Data\NCH Swift Sound
2009-12-16 07:07 . 2009-12-16 07:07 ——– d—–w- c:\documents and settings\Alistair\Application Data\Apple Computer
2009-12-16 07:05 . 2009-12-16 07:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-16 02:57 . 2009-12-16 02:53 ——– d—–w- c:\program files\IK Multimedia
2009-12-16 02:53 . 2009-12-16 02:53 ——– d—–w- c:\program files\Steinberg
2009-12-16 02:52 . 2009-12-16 02:52 ——– d—–w- c:\program files\ASIO4ALL v2
2009-12-16 02:45 . 2009-12-16 02:41 ——– d—–w- c:\documents and settings\Alistair\Application Data\Line 6
2009-12-16 02:41 . 2009-12-16 02:41 ——– d—–w- c:\program files\Common Files\Digidesign
2009-12-16 02:41 . 2009-12-16 02:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Line 6
2009-12-16 02:41 . 2009-12-16 02:41 ——– d—–w- c:\program files\Line6
2009-12-15 13:27 . 2009-12-15 13:27 177024 —-a-w- c:\documents and settings\Alistair\Application Data\Mozilla\Firefox\Profiles\pbbl1whh.default\FlashGot.exe
2009-12-15 10:54 . 2009-12-15 09:47 ——– d—–w- c:\documents and settings\Alistair\Application Data\Auslogics
2009-12-15 10:53 . 2009-12-15 10:04 ——– d—–w- c:\program files\ABBYY FineReader 6.0 Sprint
2009-12-15 10:53 . 2009-12-15 10:53 ——– d—–w- c:\documents and settings\Alistair\Application Data\EPSON
2009-12-15 10:13 . 2009-12-15 10:13 ——– d—–w- c:\program files\uTorrent
2009-12-15 10:07 . 2009-12-15 10:02 ——– d—–w- c:\documents and settings\All Users\Application Data\EPSON
2009-12-15 10:05 . 2009-12-15 10:05 ——– d—–w- c:\documents and settings\All Users\Application Data\UDL
2009-12-15 10:04 . 2009-12-15 10:04 ——– d—–w- c:\program files\Epson Software
2009-12-15 10:04 . 2009-12-15 10:02 ——– d—–w- c:\program files\epson
2009-12-15 09:56 . 2009-12-15 09:56 ——– d—–w- c:\program files\PCPitstop
2009-12-15 09:48 . 2009-12-15 09:48 ——– d—–w- c:\program files\Little Registry Cleaner
2009-12-15 09:31 . 2009-12-15 09:31 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2009-12-15 09:23 . 2009-12-15 09:23 ——– d—–w- c:\program files\Free Download Manager
2009-12-15 09:23 . 2009-12-15 09:23 ——– d—–w- c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2009-12-15 08:56 . 2009-12-15 08:33 ——– d—–w- c:\program files\IconTweaker
2009-12-15 08:46 . 2009-12-15 08:46 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-15 08:43 . 2009-12-15 08:43 ——– d—–w- c:\documents and settings\Alistair\Application Data\Styler
2009-12-15 08:38 . 2009-12-15 08:38 ——– d—–w- c:\program files\VideoLAN
2009-12-15 08:33 . 2009-12-15 08:33 ——– d—–w- c:\documents and settings\All Users\Application Data\IconTweaker
2009-12-15 08:21 . 2009-12-15 08:21 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-15 08:21 . 2009-12-15 08:21 ——– d—–w- c:\documents and settings\Alistair\Application Data\SUPERAntiSpyware.com
2009-12-15 08:21 . 2009-12-15 08:21 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-12-15 08:16 . 2009-12-15 08:16 ——– d—–w- c:\documents and settings\Alistair\Application Data\Malwarebytes
2009-12-15 08:16 . 2009-12-15 08:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-15 08:14 . 2009-12-15 08:14 ——– d—–w- c:\program files\Sophos
2009-12-15 08:06 . 2009-12-15 08:06 ——– d—–w- c:\program files\AxiomX
2009-12-15 08:03 . 2009-12-15 08:03 ——– d—–w- c:\documents and settings\Alistair\Application Data\Foxit
2009-12-15 08:03 . 2009-12-15 08:03 ——– d—–w- c:\program files\Foxit Software
2009-12-15 08:02 . 2009-12-15 08:02 ——– d—–w- c:\program files\7-Zip
2009-12-15 07:46 . 2009-12-15 07:46 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-15 07:46 . 2009-12-15 07:46 ——– d—–w- c:\program files\Java
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-20 340456]
"SkyTel"="SkyTel.EXE" [2007-08-03 1826816]
"AntiLogger"="c:\program files\AntiLogger\AntiLogger.exe" [2010-01-12 2221928]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-11-24 98304]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [14/10/2009 20:18 36880]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [07/01/2010 01:46 28552]
R1 AntiLog32;AntiLog32;c:\program files\AntiLogger\AntiLog32.sys [12/01/2010 16:14 116072]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/11/2009 08:43 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/11/2009 08:43 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [15/12/2009 13:39 1858144]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [06/01/2010 02:17 12672]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [05/01/2010 00:51 14976]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 13:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/10/2009 18:39 19472]
R3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [16/12/2009 02:42 532992]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\C0.tmp –> c:\windows\system32\C0.tmp [?]
S3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [17/12/2009 03:27 14424]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [11/01/2010 23:09 16456]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [11/01/2010 23:09 11088]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/11/2009 08:43 7408]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [15/12/2009 09:56 90352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
.
——- Supplementary Scan ——-
.
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
FF - ProfilePath - c:\documents and settings\Alistair\Application Data\Mozilla\Firefox\Profiles\pbbl1whh.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://m.uk.yahoo.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-28 17:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\C0.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1192)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3500)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-28 17:09:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-28 17:09

Pre-Run: 201,807,163,392 bytes free
Post-Run: 201,750,999,040 bytes free

- - End Of File - - A01ED62A653167CE209BB3B5AFA7E078
There was also a combofix logfile called quarantined files which I did not post previously as I am not sure what log you wanted but here is the log incase I posted the wrong one > 2010-01-28 17:04:08 . 2010-01-28 17:04:08 1,180 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_ywghcedstlcr.reg.dat 2010-01-28 17:04:08 . 2010-01-28 17:04:08 1,180 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_ynltosggncjp.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:08 1,180 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_yhikanbisygi.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 1,180 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_yeoqjaedbosu.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 1,180 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_ydugtctlvwoo.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 1,180 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_apgiywudryke.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 1,180 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_admqnrgkhnlw.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 838 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_ywghcedstlcr.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 838 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_ynltosggncjp.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 838 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_yhikanbisygi.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 838 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_yeoqjaedbosu.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 838 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_ydugtctlvwoo.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 838 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_apgiywudryke.reg.dat 2010-01-28 17:04:07 . 2010-01-28 17:04:07 838 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_admqnrgkhnlw.reg.dat 2010-01-28 17:03:26 . 2010-01-28 17:03:26 6,921 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2010-01-28 17:00:12 . 2010-01-28 17:00:12 51 —-a-w- C:\Qoobox\Quarantine\catchme.log 2010-01-12 08:48:21 . 2010-01-12 08:48:14 8,576 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\apgiywudryke.sys.vir 2010-01-12 08:44:34 . 2010-01-12 08:44:29 8,576 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\admqnrgkhnlw.sys.vir 2010-01-12 08:43:30 . 2010-01-12 08:43:25 8,576 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\yeoqjaedbosu.sys.vir 2010-01-12 08:42:16 . 2010-01-12 08:42:10 8,576 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ywghcedstlcr.sys.vir 2010-01-12 08:41:14 . 2010-01-12 08:41:06 8,576 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ynltosggncjp.sys.vir 2010-01-12 08:40:27 . 2010-01-12 08:40:18 8,576 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ydugtctlvwoo.sys.vir 2010-01-12 08:37:52 . 2010-01-12 08:36:09 8,576 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\yhikanbisygi.sys.vir 2010-01-02 20:26:37 . 2010-01-02 20:29:52 87,608 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Alistair\Application Data\inst.exe.vir 2010-01-02 13:27:12 . 2010-01-28 10:47:06 32 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\msvcsv60.dll.vir
Hi,

Please do the following:

Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Hi ,The PC seems to be running a bit better…..here is the E-SET log > ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=69916ff5ca3dd94cbfdc201fcd4816ad # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-01-21 07:06:13 # local_time=2010-01-21 07:06:13 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 2479422 2479422 0 0 # compatibility_mode=1280 16777191 100 0 3206561 3206561 0 0 # compatibility_mode=8192 67108863 100 0 3688 3688 0 0 # scanned=54175 # found=0 # cleaned=0 # scan_time=1588 # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=69916ff5ca3dd94cbfdc201fcd4816ad # end=stopped # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-01-22 05:32:03 # local_time=2010-01-22 05:32:03 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 2603601 2603601 0 0 # compatibility_mode=1280 16777175 100 0 3330740 3330740 0 0 # compatibility_mode=8192 67108863 100 0 127867 127867 0 0 # scanned=42883 # found=0 # cleaned=0 # scan_time=1359 # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=69916ff5ca3dd94cbfdc201fcd4816ad # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-01-28 06:44:30 # local_time=2010-01-28 06:44:30 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 3125754 3125754 0 0 # compatibility_mode=1280 16777191 100 0 3852893 3852893 0 0 # compatibility_mode=8192 67108863 100 0 650020 650020 0 0 # scanned=61763 # found=0 # cleaned=0 # scan_time=1953
The machine is clean

we just need to do some housekeeping now.

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • For realtime protection against spyware, try SpywareTerminator


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Hi CatByte, I did another online scan with bitdefender and it is still saying I am infected…..I am a bit confused as kaspersky says my computer is ok.I have saved a logfile >>> BitDefender Online Scanner Scan report generated at: Thu, Jan 28, 2010 - 22:42:42 Scan path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\SandboxShared;C:\Documents and Settings\Alistair\My Documents;C:\Documents and Settings\All Users\Documents;C:\;D:\;F:\;G:\;H:\;I:\;J:\;C:\Documents and Settings\Alistair\My Documents;C:\Documents and Settings\Alistair\Desktop\Downloads;C:\Documents and Settings\Alistair\Desktop\Security; Statistics Time 00:35:53 Files 219252 Folders 5972 Boot Sectors 0 Archives 2310 Packed Files 8932 Results Identified Viruses 2 Infected Files 4 Suspect Files 0 Warnings 0 Disinfected 0 Deleted Files 0 Engines Info Virus Definitions 4939799 Engine build AVCORE v2.1 Windows/i386 11.0.0.33 (Nov 24 2009) Scan plugins 17 Archive plugins 44 Unpack plugins 8 E-mail plugins 6 System plugins 4 Scan Settings First Action Report Second Action Prompt Heuristics Yes Enable Warnings Yes Scanned Extensions *; Exclude Extensions Scan Emails Yes Scan Archives Yes Scan Packed Yes Scan Files Yes Scan Boot Yes Scanned File Status C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\4c3d7d5f7a17e932.klq=>(Quarantine-6) Infected with: Gen:Trojan.Heur.iq8@YcK6Ffe C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq=>(Quarantine-6) Infected with: Trojan.Wimad.Gen.1 C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq=>(Quarantine-6) Infected with: Trojan.Wimad.Gen.1 C:\System Volume Information\_restore{94CA66B5-A239-4D3E-A0D6-082AB325BA97}\RP2\A0011726.dll Infected with: Gen:Trojan.Heur.iq8@YcK6Ffe
Look at the paths identified - Kaspersky Quarantine which you can empty and an old system restore point, which will clean up when you uninstall combofix. Your machine is clean.
Hi Catbyte , I thought that it had something to do with kaspersky quarantine but was not sure so thought it better to ask before the thread gets closed……Many thanks for responding so quickly and taking the time to help me out :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI