[Resolved] Various Infections - such as rootkit
15 min read
Please do the following:
Download Combofix from either of the links below. You must rename it to combo.exe before saving it.
Save it to your desktop. Change the save as file type to "all files"
**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
- If you are using Firefox, make sure that your download settings are as follows:
- Tools->Options->Main tab
- Set to "Always ask me where to Save the files".
Link 1
Link 2
———————————————————–
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
———————————————————–
- NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
———————————————————–
- Double click on the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
- Please post the C:\ComboFix.txt so we can continue cleaning the system.
———————————————————–
Exactly the same thing happens irrespective of whether I start it on the desktop or usb and whether I start it in normal mode or Safe Mode.
Following on from your suggestion about processes I have also tried to remove all process first except for these
taskmgr.exe
explorer.exe
svchost.exe - a few
spoolsv.exe
lsass.exe
services.exe
winlogon.exe
csrss.exe
smss.exe
System Idle Process
There is a System in the processes which will not end as well.
combofix still does not start. After it has run the following processes are added to the above
cmd.cfxxe
pev.exe
iexplore.exe
iexplore.exe
ctfmin.exe
Let's try this program instead:
Download OTL to your Desktop
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output.
- Check the boxes beside LOP Check and Purity Check.
- Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT
- Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
OTL logfile created on: 02.02.2010 14:31:45 - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\Mayte\Desktop
Windows XP Home Edition Service Pack 3, v.5657 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 73,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 16,54 Gb Free Space | 22,19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,92 Gb Total Space | 1,92 Gb Free Space | 99,72% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MAYTE-9BDDE8BE8
Current User Name: Mayte
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Mayte\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Live\Toolbar\wltuser.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Mayte\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.3264_x-ww_d751ffbf\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\linkinfo.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (HauppaugeTVServer) – C:\Program Files\WinTV\HCWTVServer.exe (Hauppauge Computer Works)
SRV - (EPGService) – C:\Program Files\WinTV\EPG Services\System\EPGService.exe (Hauppauge Computer Works)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (USBAAPL) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (N) – C:\Program Files\NewTech Infosystems\NTI Ripper\ [2009.06.16 06:44:24 | 000,000,000 | —D | M]
DRV - (NinjaUSB) – C:\WINDOWS\system32\drivers\NinjaUSB.sys ()
DRV - (GEARAspiWDM) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (CVPNDRVA) – C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (hcw95rc) – C:\WINDOWS\system32\drivers\hcw95rc.sys (Hauppauge Computer Works, Inc.)
DRV - (hcw95bda) – C:\WINDOWS\system32\drivers\hcw95bda.sys (Hauppauge Computer Works, Inc.)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (ElbyDelay) – C:\WINDOWS\system32\drivers\ElbyDelay.sys (Elaborate Bytes AG)
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (CVirtA) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (PID_08A0) QuickCam IM(PID_08A0) – C:\WINDOWS\system32\drivers\LV302AV.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVEzLoader) LifeView EZ-USB FX2 FIRMWARE LOADER (LVEzLD06.sys) – C:\WINDOWS\system32\drivers\LVEzLD06.sys (Animation Technologies Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs LLC)
DRV - (cercsr6) – C:\WINDOWS\system32\drivers\cercsr6.sys (Adaptec, Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000005
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.2.20080717
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..network.proxy.http: "63.148.167.30"
FF - prefs.js..network.proxy.http_port: 1080
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2010.01.14 15:20:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.01.16 11:40:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.01.16 11:40:16 | 000,000,000 | —D | M]
[2008.12.24 08:22:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\Mozilla\Extensions
[2010.01.26 21:06:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\extensions
[2009.06.16 09:29:43 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009.09.23 23:10:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\extensions\[removed]
[2009.11.15 11:07:16 | 000,002,163 | —- | M] () – C:\Documents and Settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\searchplugins\bing.xml
[2010.01.26 21:16:32 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008.05.25 19:07:26 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008.03.24 19:21:00 | 002,889,088 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: ([2004.08.04 11:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (ZoneAlarm Spy Blocker BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EPGServiceTool] C:\Program Files\WinTV\EPG Services\System\EPGClient.exe (Hauppauge Inc.)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\xxxx.exe File not found
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Password.lnk = C:\Documents and Settings\Mayte\Local Settings\Temp\Password.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr =
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.01.05 15:12:33 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008.07.29 12:34:02 | 000,000,000 | RHSD | M] - E:\AutoRun – [ FAT ]
O33 - MountPoints2\{4af5fa13-5993-11de-b4b2-00123f82a435}\Shell - "" = AutoRun
O33 - MountPoints2\{4af5fa13-5993-11de-b4b2-00123f82a435}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8c3af734-f2f9-11dc-bf8e-00123f82a435}\Shell - "" = AutoRun
O33 - MountPoints2\{8c3af734-f2f9-11dc-bf8e-00123f82a435}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008.01.05 00:37:22 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Error starting restore point: 31
Error closing restore point: The sequence number is invalid.
========== Files/Folders - Created Within 30 Days ==========
[2010.02.02 14:26:47 | 000,548,864 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mayte\Desktop\OTL.exe
[2010.02.02 11:13:32 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010.01.28 14:19:14 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010.01.28 11:06:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Mayte\Application Data\Malwarebytes
[2010.01.28 10:57:51 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.01.28 10:57:47 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010.01.28 10:57:47 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010.01.28 10:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.01.27 21:46:30 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Mayte\Desktop\mbam-setup(2).exe
[2010.01.27 21:39:47 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Mayte\Desktop\xxxx.exe
[2010.01.27 00:27:37 | 000,000,000 | —D | C] – C:\Program Files\Malware Defense
[2010.01.26 22:21:38 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010.01.26 22:21:38 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010.01.26 22:21:38 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010.01.26 22:21:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008.04.14 22:16:13 | 022,744,616 | —- | C] (Macrovision Corporation) – C:\Program Files\ElsterFormular2007-Setup.exe
[2008.03.03 12:06:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008.01.05 22:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2008.01.05 22:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Intel
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.02.02 14:22:38 | 000,548,864 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mayte\Desktop\OTL.exe
[2010.02.02 14:16:27 | 000,002,447 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2010.02.02 14:15:49 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010.02.02 14:15:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010.02.02 11:20:14 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Mayte\ntuser.ini
[2010.02.02 11:20:13 | 006,029,312 | -H– | M] () – C:\Documents and Settings\Mayte\NTUSER.DAT
[2010.02.01 14:20:10 | 003,841,968 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\combo.exe
[2010.02.01 14:00:32 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010.01.28 14:19:14 | 000,001,742 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\HijackThis.lnk
[2010.01.28 10:57:55 | 000,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.01.28 10:48:08 | 000,001,188 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-789336058-839522115-1004UA.job
[2010.01.27 21:46:30 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Mayte\Desktop\mbam-setup(2).exe
[2010.01.27 21:40:00 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Mayte\Desktop\xxxx.exe
[2010.01.27 00:27:50 | 000,001,611 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense Support.lnk
[2010.01.27 00:27:50 | 000,000,705 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense.lnk
[2010.01.26 22:27:15 | 000,001,917 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010.01.26 21:50:23 | 000,000,008 | —- | M] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2010.01.26 21:07:32 | 000,468,864 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010.01.26 21:07:32 | 000,401,364 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010.01.26 21:07:32 | 000,061,374 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010.01.26 20:51:12 | 054,686,882 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010.01.26 20:51:12 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010.01.26 08:37:33 | 000,001,136 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-789336058-839522115-1004Core.job
[2010.01.07 16:07:14 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.01.07 16:07:04 | 000,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.02.01 14:21:41 | 003,841,968 | —- | C] () – C:\Documents and Settings\Mayte\Desktop\combo.exe
[2010.01.28 14:19:14 | 000,001,742 | —- | C] () – C:\Documents and Settings\Mayte\Desktop\HijackThis.lnk
[2010.01.28 10:57:55 | 000,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.01.27 00:27:50 | 000,001,611 | —- | C] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense Support.lnk
[2010.01.27 00:27:50 | 000,000,705 | —- | C] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense.lnk
[2010.01.26 21:50:10 | 000,000,008 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009.06.16 06:42:40 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIRIPPER.dll
[2009.06.16 06:32:21 | 000,024,704 | —- | C] () – C:\WINDOWS\System32\drivers\NinjaUSB.sys
[2008.07.04 00:04:14 | 011,132,416 | —- | C] () – C:\Program Files\vpnclient-win-msi-5.0.03.0530-k9.exe
[2008.05.22 00:45:33 | 003,168,683 | —- | C] () – C:\Program Files\SopCast.zip
[2008.04.17 08:08:56 | 000,197,408 | —- | C] () – C:\WINDOWS\System32\vpnapi.dll
[2008.04.17 08:08:44 | 000,193,312 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2008.03.07 22:41:04 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008.02.29 19:55:00 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\UNWISE.INI
[2008.02.29 19:51:21 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dmcrypto.dll
[2008.02.29 19:50:34 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\hcwChDB.dll
[2008.02.29 19:49:48 | 000,006,741 | —- | C] () – C:\WINDOWS\HCWPNP.INI
[2008.02.29 19:47:43 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008.01.31 05:30:58 | 000,120,320 | —- | C] () – C:\Documents and Settings\Mayte\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.31 05:25:34 | 000,029,480 | —- | C] () – C:\WINDOWS\System32\InstHelper.dll
[2008.01.11 23:35:44 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008.01.11 23:35:43 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008.01.11 07:05:42 | 000,001,751 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008.01.08 22:14:13 | 000,000,131 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008.01.05 23:19:48 | 000,009,255 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008.01.05 23:19:31 | 000,000,260 | —- | C] () – C:\WINDOWS\_delis32.ini
[2008.01.05 23:08:58 | 000,000,483 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003.01.08 00:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2008.04.14 22:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ElsterFormular
[2008.04.10 07:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FlashFXP
[2008.04.07 22:11:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fotobuch.de AG
[2008.01.08 22:46:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008.01.08 22:28:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009.11.29 22:40:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.06.17 07:20:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\EBookSys
[2008.04.07 22:11:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\fotobuch.de AG
[2008.03.07 22:47:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\InterVideo
[2009.06.16 00:35:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Mayte\Application Data\Printer Info Cache
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004.08.04 11:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2007.12.01 00:36:18 | 019,995,189 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2007.12.01 00:36:18 | 019,995,189 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2007.11.30 17:31:08 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=A42ABFAEE59A1DC0E47014E7B5D76AD6 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2007.11.30 17:31:08 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=A42ABFAEE59A1DC0E47014E7B5D76AD6 – C:\WINDOWS\system32\dllcache\agp440.sys
[2007.11.30 17:31:08 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=A42ABFAEE59A1DC0E47014E7B5D76AD6 – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.04 11:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2007.12.01 00:36:18 | 019,995,189 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2007.12.01 00:36:18 | 019,995,189 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2007.11.30 17:24:44 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=335BB30ED68CF3DC0EE2BDDB438B6A9B – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2007.11.30 17:24:44 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=335BB30ED68CF3DC0EE2BDDB438B6A9B – C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2004.08.04 11:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2007.12.01 00:25:36 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=086FFA8479114AE3ECE616D7EB848577 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2007.12.01 00:25:36 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=086FFA8479114AE3ECE616D7EB848577 – C:\WINDOWS\system32\eventlog.dll
[2008.04.14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2004.08.04 11:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >
[2006.05.11 17:30:52 | 000,247,808 | —- | M] (Intel Corporation) MD5=294110966CEDD127629C5BE48367C8CF – C:\WINDOWS\dell\iastor\iastor.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2007.12.01 00:25:48 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=327309E36308F9DFB8D4699DF384D421 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2007.12.01 00:25:48 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=327309E36308F9DFB8D4699DF384D421 – C:\WINDOWS\system32\netlogon.dll
[2004.08.04 11:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: NVATABUS.SYS >
[2006.03.17 01:51:32 | 000,099,840 | —- | M] (NVIDIA Corporation) MD5=B7FB72492B753930EC70A0F49D04F12F – C:\WINDOWS\dell\nvraid\NvAtaBus.sys
< MD5 for: SCECLI.DLL >
[2004.08.04 11:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2007.12.01 00:25:52 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=625D7B39B09AB60A683AF4B95575056E – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2007.12.01 00:25:52 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=625D7B39B09AB60A683AF4B95575056E – C:\WINDOWS\system32\scecli.dll
[2008.04.14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008.01.05 00:46:51 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008.01.05 00:46:51 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008.01.05 00:46:51 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report >
OTL Extras logfile created on: 02.02.2010 14:31:45 - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\Mayte\Desktop
Windows XP Home Edition Service Pack 3, v.5657 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 73,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 16,54 Gb Free Space | 22,19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,92 Gb Total Space | 1,92 Gb Free Space | 99,72% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MAYTE-9BDDE8BE8
Current User Name: Mayte
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = SafariHTML] – C:\Program Files\Safari\Safari.exe (Apple Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Safari\Safari.exe" -url "%1" (Apple Inc.)
https [open] – "C:\Program Files\Safari\Safari.exe" -url "%1" (Apple Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" =
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 – (IniCom Networks, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Joost\xulrunner\tvprunner.exe" = C:\Program Files\Joost\xulrunner\tvprunner.exe:*:Enabled:tvprunner – File not found
"C:\Program Files\dm\fotobuch.de AG\Designer 2.0\Designer.exe" = C:\Program Files\dm\fotobuch.de AG\Designer 2.0\Designer.exe:*:Designer.exe – ()
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 – (IniCom Networks, Inc.)
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application – (www.sopcast.com)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Documents and Settings\Mayte\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Mayte\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – File not found
"C:\Documents and Settings\Mayte\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Mayte\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – File not found
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04830D0F-F980-4EC0-89F1-594F2FD2A1B5}" = ElsterFormular 2008/2009
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0DD140D3-9563-481E-AA75-BA457CBDAEF2}" = PC Inspector File Recovery
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2227E1FA-01F5-483C-AB0E-2A308E900B3D}" = InterVideo FilterSDK for Hauppauge
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4C271126-C295-4828-A901-5910AE0C258B}" = Cisco Systems VPN Client 5.0.03.0530
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6DE13770-01B7-4366-8DA6-48237793F445}" = VoiceOver Kit
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{88A785A2-3EA6-4A2D-ABEE-68E9E55A39F8}" = NTI Ripper
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B480BD2A-F1BA-4FE6-8C8E-34C6111B72C9}" = ElsterFormular 2007/2008
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F04CAFE3-D52F-4EFC-A1E8-316BD4C525D6}" = NTI Shadow
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AnyDVD" = AnyDVD
"AVG8Uninstall" = AVG 8.5
"CloneDVD2" = CloneDVD2
"CloneDVDmobile" = CloneDVDmobile
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.92 Modem
"Designer 2.0_is1" = Designer 2.0
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"Hauppauge English Help Files and Resources" = Hauppauge English Help Files and Resources
"Hauppauge WinTV" = Hauppauge WinTV
"Hauppauge WinTV DVB-T EPG Service" = Hauppauge WinTV DVB-T EPG Service
"Hauppauge WinTV Scheduler" = Hauppauge WinTV Scheduler
"Hauppauge WinTV TV Services" = Hauppauge WinTV TV Services
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"Malware Defense" = Malware Defense
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.17)" = Mozilla Firefox (3.0.17)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ProInst" = Intel® PROSet/Wireless Software
"QcDrv" = Logitech® Camera Driver
"RealAlt_is1" = Real Alternative 1.60
"Red Eye Remover_is1" = Red Eye Remover 2.0
"SopCast" = SopCast 3.0.3
"VLC media player" = VLC media player 0.9.9
"Web Photo Album_is1" = Web Photo Album 1.1
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xilisoft Video Converter" = Xilisoft Video Converter 3
"Xvid_is1" = Xvid 1.1.3 final uninstall
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"TS" = Total Security
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 25.01.2010 15:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 25.01.2010 16:48:00 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 25.01.2010 17:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 26.01.2010 02:48:04 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 26.01.2010 02:48:04 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 26.01.2010 16:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 26.01.2010 17:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 26.01.2010 19:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 27.01.2010 16:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
Error - 28.01.2010 05:48:01 | Computer Name = MAYTE-9BDDE8BE8 | Source = Application Error | ID = 1000
Description = Faulting application googleupdate.exe, version 1.2.131.7, faulting
module googleupdate.exe, version 1.2.131.7, fault address 0x00006eef.
[ System Events ]
Error - 02.02.2010 09:25:14 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
Error - 02.02.2010 09:25:28 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Cisco Systems, Inc. VPN Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 02.02.2010 09:25:34 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The EPGService service terminated unexpectedly. It has done this
1 time(s).
Error - 02.02.2010 09:25:36 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Event Log service terminated unexpectedly.
It has done this 1 time(s).
Error - 02.02.2010 09:25:54 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).
Error - 02.02.2010 09:26:03 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 02.02.2010 09:26:05 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The SeaPort service terminated unexpectedly. It has done this 1 time(s).
Error - 02.02.2010 09:26:11 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Bonjour-Dienst service terminated unexpectedly. It has done this
1 time(s).
Error - 02.02.2010 09:26:15 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Registry Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 02.02.2010 09:26:19 | Computer Name = MAYTE-9BDDE8BE8 | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 2 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
< End of report >
Please do the following:
Run OTL.exe
- Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL
:OTL O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found. [2010.01.27 00:27:37 | 000,000,000 | —D | C] – C:\Program Files\Malware Defense [2010.01.27 00:27:50 | 000,001,611 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense Support.lnk [2010.01.27 00:27:50 | 000,000,705 | —- | M] () – C:\Documents and Settings\Mayte\Desktop\Malware Defense.lnk O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Password.lnk = C:\Documents and Settings\Mayte\Local Settings\Temp\Password.exe File not found [2010.01.26 21:50:23 | 000,000,008 | —- | M] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini :Commands [purity] [emptytemp] [start explorer] [Reboot] - Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post the OTL log
NEXT
- Download TDSSKiller and save it to your Desktop.
Extract the file and run it.
Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)
please post the content of that log TDSSKiller
So I ran the OTL script in OTL
It prompted to reboot.
On reboot it only showed the desktop and the .txt file.
We had to reboot again so that we had full windows again.
Here is that txt file.
All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully.
C:\Program Files\Malware Defense folder moved successfully.
C:\Documents and Settings\Mayte\Desktop\Malware Defense Support.lnk moved successfully.
C:\Documents and Settings\Mayte\Desktop\Malware Defense.lnk moved successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Password.lnk moved successfully.
C:\Documents and Settings\All Users\Application Data\sysReserve.ini moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
User: LocalService
->Temp folder emptied: 480 bytes
->Temporary Internet Files folder emptied: 3394134 bytes
User: Mayte
->Temp folder emptied: 892725 bytes
->Temporary Internet Files folder emptied: 102992614 bytes
->Java cache emptied: 74145925 bytes
->FireFox cache emptied: 101043551 bytes
->Apple Safari cache emptied: 34174631 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 750349 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 19383825 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1712880 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 224036 bytes
Total Files Cleaned = 323,00 mb
OTL by OldTimer - Version 3.1.27.1 log created on 02032010_111340
Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\SDA62C49F.tmp scheduled to be moved on reboot.
Registry entries deleted on Reboot…
Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\SDA62C49F.tmp scheduled to be moved on reboot.
Registry entries deleted on Reboot…
09:39:47:327 1556 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
09:39:47:327 1556 ================================================================================
09:39:47:327 1556 SystemInfo:
09:39:47:327 1556 OS Version: 5.1.2600 ServicePack: 3.0
09:39:47:327 1556 Product type: Workstation
09:39:47:327 1556 ComputerName: MAYTE-9BDDE8BE8
09:39:47:327 1556 UserName: Mayte
09:39:47:327 1556 Windows directory: C:\WINDOWS
09:39:47:327 1556 Processor architecture: Intel x86
09:39:47:327 1556 Number of processors: 1
09:39:47:327 1556 Page size: 0x1000
09:39:47:327 1556 Boot type: Normal boot
09:39:47:327 1556 ================================================================================
09:39:47:337 1556 UnloadDriverW: NtUnloadDriver error 2
09:39:47:337 1556 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
09:39:47:357 1556 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
09:39:47:447 1556 UtilityInit: KLMD drop and load success
09:39:47:447 1556 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
09:39:47:447 1556 UtilityInit: KLMD open success
09:39:47:447 1556 UtilityInit: Initialize success
09:39:47:447 1556
09:39:47:447 1556 Scanning Services …
09:39:47:447 1556 CreateRegParser: Registry parser init started
09:39:47:447 1556 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
09:39:47:447 1556 CreateRegParser: DisableWow64Redirection error
09:39:47:447 1556 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
09:39:47:447 1556 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
09:39:47:447 1556 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
09:39:47:447 1556 wfopen_ex: Trying to KLMD file open
09:39:47:447 1556 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
09:39:47:447 1556 wfopen_ex: File opened ok (Flags 2)
09:39:47:447 1556 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: E748F8
09:39:47:447 1556 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
09:39:47:447 1556 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
09:39:47:447 1556 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
09:39:47:447 1556 wfopen_ex: Trying to KLMD file open
09:39:47:447 1556 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
09:39:47:447 1556 wfopen_ex: File opened ok (Flags 2)
09:39:47:447 1556 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: E749A0
09:39:47:447 1556 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
09:39:47:447 1556 CreateRegParser: EnableWow64Redirection error
09:39:47:447 1556 CreateRegParser: RegParser init completed
09:39:47:948 1556 GetAdvancedServicesInfo: Raw services enum returned 355 services
09:39:47:948 1556 ScanTDL2Services: Exact detect H8SRTd.sys (h: 1)
09:39:47:948 1556 RegNode HKLM\SYSTEM\ControlSet001\services\H8SRTd.sys infected by TDSS rootkit … 09:39:47:958 1556 will be deleted on reboot
09:39:47:968 1556 DeleteTDL2Service: SafeBoot Minimal doesn't infected
09:39:47:968 1556 DeleteTDL2Service: SafeBoot Network doesn't infected
09:39:47:978 1556 RegNode HKLM\SYSTEM\ControlSet003\services\H8SRTd.sys infected by TDSS rootkit … 09:39:47:978 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: SafeBoot Minimal doesn't infected
09:39:47:988 1556 DeleteTDL2Service: SafeBoot Network doesn't infected
09:39:47:988 1556 File C:\WINDOWS\system32\drivers\H8SRTlhylqbdmtk.sys infected by TDSS rootkit … 09:39:47:988 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: H8SRTd. Type: 1
09:39:47:988 1556 DeleteTDL2Service: Module clone ImagePath, skipping
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: H8SRTc. Type: 1
09:39:47:988 1556 File C:\WINDOWS\system32\H8SRTltewcpqcvh.dll infected by TDSS rootkit … 09:39:47:988 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: H8SRTsrcr. Type: 1
09:39:47:988 1556 File C:\WINDOWS\system32\H8SRTkdpxwkbopj.dat infected by TDSS rootkit … 09:39:47:988 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: h8srtserf. Type: 1
09:39:47:988 1556 File C:\WINDOWS\system32\H8SRTyekkxuroow.dll infected by TDSS rootkit … 09:39:47:988 1556 will be deleted on reboot
09:39:47:988 1556 DeleteTDL2Service: Module enum: Name: h8srtmsg. Type: 1
09:39:47:988 1556 File C:\WINDOWS\system32\H8SRTftypepfvvi.dll infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 DeleteTDL2Service: Module enum: Name: h8srtbbr. Type: 1
09:39:47:998 1556 File C:\WINDOWS\system32\H8SRTlaqyqbapuf.dll infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 ScanTDL2Services: DeleteEvilService(H8SRTd.sys) success
09:39:47:998 1556 ScanTDL2Services: Exact detect UACd.sys (h: 1)
09:39:47:998 1556 RegNode HKLM\SYSTEM\ControlSet001\services\UACd.sys infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 DeleteTDL2Service: SafeBoot Minimal doesn't infected
09:39:47:998 1556 DeleteTDL2Service: SafeBoot Network doesn't infected
09:39:47:998 1556 RegNode HKLM\SYSTEM\ControlSet003\services\UACd.sys infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 DeleteTDL2Service: SafeBoot Minimal doesn't infected
09:39:47:998 1556 DeleteTDL2Service: SafeBoot Network doesn't infected
09:39:47:998 1556 File C:\WINDOWS\system32\drivers\UACxdkpakxymx.sys infected by TDSS rootkit … 09:39:47:998 1556 will be deleted on reboot
09:39:47:998 1556 DeleteTDL2Service: Module enum: Name: UACd. Type: 1
09:39:47:998 1556 DeleteTDL2Service: Module clone ImagePath, skipping
09:39:47:998 1556 DeleteTDL2Service: Module enum: Name: UACc. Type: 1
09:39:47:998 1556 File C:\WINDOWS\system32\UACobvdjbnexm.dll infected by TDSS rootkit … 09:39:48:008 1556 will be deleted on reboot
09:39:48:008 1556 DeleteTDL2Service: Module enum: Name: UACbbr. Type: 1
09:39:48:008 1556 File C:\WINDOWS\system32\UACofrqcwkrje.dll infected by TDSS rootkit … 09:39:48:008 1556 will be deleted on reboot
09:39:48:008 1556 DeleteTDL2Service: Module enum: Name: UACsr. Type: 1
09:39:48:008 1556 File C:\WINDOWS\system32\UACtkyxhvpphw.dat infected by TDSS rootkit … 09:39:48:008 1556 will be deleted on reboot
09:39:48:008 1556 DeleteTDL2Service: Module enum: Name: uacserf. Type: 1
09:39:48:008 1556 File C:\WINDOWS\system32\UAChkwnswewfs.dll infected by TDSS rootkit … 09:39:48:008 1556 will be deleted on reboot
09:39:48:018 1556 ScanTDL2Services: DeleteEvilService(UACd.sys) success
09:39:48:018 1556 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
09:39:48:018 1556 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
09:39:48:018 1556
09:39:48:018 1556 Scanning Kernel memory …
09:39:48:018 1556 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
09:39:48:018 1556 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8A6A2910
09:39:48:018 1556 DetectCureTDL3: KLMD_GetDeviceObjectList returned 2 DevObjects
09:39:48:018 1556
09:39:48:018 1556 DetectCureTDL3: DEVICE_OBJECT: 8A6C1C68
09:39:48:018 1556 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A6C1C68
09:39:48:018 1556 KLMD_ReadMem: Trying to ReadMemory 0x8A6C1C68[0x38]
09:39:48:018 1556 DetectCureTDL3: DRIVER_OBJECT: 8A6A2910
09:39:48:018 1556 KLMD_ReadMem: Trying to ReadMemory 0x8A6A2910[0xA8]
09:39:48:018 1556 KLMD_ReadMem: Trying to ReadMemory 0xE1022240[0x18]
09:39:48:018 1556 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
09:39:48:018 1556 DetectCureTDL3: IrpHandler (0) addr: F765DBB0
09:39:48:018 1556 DetectCureTDL3: IrpHandler (1) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (2) addr: F765DBB0
09:39:48:018 1556 DetectCureTDL3: IrpHandler (3) addr: F7657D1F
09:39:48:018 1556 DetectCureTDL3: IrpHandler (4) addr: F7657D1F
09:39:48:018 1556 DetectCureTDL3: IrpHandler (5) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (6) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (7) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (8) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (9) addr: F76582E2
09:39:48:018 1556 DetectCureTDL3: IrpHandler (10) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (11) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (12) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (13) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (14) addr: F76583BB
09:39:48:018 1556 DetectCureTDL3: IrpHandler (15) addr: F765BF28
09:39:48:018 1556 DetectCureTDL3: IrpHandler (16) addr: F76582E2
09:39:48:018 1556 DetectCureTDL3: IrpHandler (17) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (18) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (19) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (20) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (21) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (22) addr: F7659C82
09:39:48:018 1556 DetectCureTDL3: IrpHandler (23) addr: F765E99E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (24) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (25) addr: 804FA87E
09:39:48:018 1556 DetectCureTDL3: IrpHandler (26) addr: 804FA87E
09:39:48:018 1556 TDL3_FileDetect: Processing driver: Disk
09:39:48:018 1556 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
09:39:48:018 1556 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
09:39:48:028 1556 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
09:39:48:028 1556
09:39:48:028 1556 DetectCureTDL3: DEVICE_OBJECT: 8A6CBAB8
09:39:48:028 1556 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A6CBAB8
09:39:48:028 1556 DetectCureTDL3: DEVICE_OBJECT: 8A6BC9A0
09:39:48:028 1556 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A6BC9A0
09:39:48:028 1556 DetectCureTDL3: DEVICE_OBJECT: 8A73E940
09:39:48:028 1556 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A73E940
09:39:48:028 1556 KLMD_ReadMem: Trying to ReadMemory 0x8A73E940[0x38]
09:39:48:028 1556 DetectCureTDL3: DRIVER_OBJECT: 8A6CA558
09:39:48:028 1556 KLMD_ReadMem: Trying to ReadMemory 0x8A6CA558[0xA8]
09:39:48:028 1556 KLMD_ReadMem: Trying to ReadMemory 0xE17758B0[0x1A]
09:39:48:028 1556 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
09:39:48:028 1556 DetectCureTDL3: IrpHandler (0) addr: F74AC6F2
09:39:48:028 1556 DetectCureTDL3: IrpHandler (1) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (2) addr: F74AC6F2
09:39:48:028 1556 DetectCureTDL3: IrpHandler (3) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (4) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (5) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (6) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (7) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (8) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (9) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (10) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (11) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (12) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (13) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (14) addr: F74AC712
09:39:48:028 1556 DetectCureTDL3: IrpHandler (15) addr: F74A8850
09:39:48:028 1556 DetectCureTDL3: IrpHandler (16) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (17) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (18) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (19) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (20) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (21) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (22) addr: F74AC73C
09:39:48:028 1556 DetectCureTDL3: IrpHandler (23) addr: F74B3336
09:39:48:028 1556 DetectCureTDL3: IrpHandler (24) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (25) addr: 804FA87E
09:39:48:028 1556 DetectCureTDL3: IrpHandler (26) addr: 804FA87E
09:39:48:028 1556 KLMD_ReadMem: Trying to ReadMemory 0xF74A9862[0x400]
09:39:48:028 1556 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
09:39:48:028 1556 TDL3_FileDetect: Processing driver: atapi
09:39:48:028 1556 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
09:39:48:028 1556 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
09:39:48:038 1556 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
09:39:48:038 1556 UtilityBootReinit: Reboot required for cure complete..
09:39:48:038 1556 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmdb.sys) returned status 00000000
09:39:48:048 1556 UtilityBootReinit: KLMD drop success
09:39:48:068 1556 KLMD_ApplyPendList: Pending buffer(FB4_588F, 1904) dropped successfully
09:39:48:068 1556 UtilityBootReinit: Cure on reboot scheduled successfully
09:39:48:068 1556
09:39:48:068 1556 Completed
I am now able to run Malwarebytes in safe mode and am doing so now.
One question. In C there is a _OTL folder with moved things in there. Can this be deleted?
Malwarebytes' Anti-Malware 1.44
Database version: 3628
Windows 5.1.2600 Service Pack 3, v.5657 (Safe Mode)
Internet Explorer 7.0.5730.13
04.02.2010 11:25:22
mbam-log-2010-02-04 (11-25-22).txt
Scan type: Full Scan (C:\|)
Objects scanned: 173494
Time elapsed: 50 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 19
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servises (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\h8srtd.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Common Files\TSUninstall (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Start Menu\Programs\malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
Files Infected:
C:\32788R22FWJFW\Combo-Fix.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\_OTL\MovedFiles\02032010_111340\C_Program Files\Malware Defense\uninstall.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\TSUninstall\Uninstall.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Start Menu\Programs\malware Defense\Malware Defense Support.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Start Menu\Programs\malware Defense\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Start Menu\Programs\malware Defense\Uninstall Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Computer Scan.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Help.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Registration.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Security Center.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Settings.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Total Security.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\TS\Update.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Application Data\Microsoft\Internet Explorer\Quick Launch\TS.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\h8srtshsyst.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\h8srtsrcr.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mayte\Local Settings\Temp\H8SRT962c.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
ComboFix 10-02-04.06 - Mayte 05.02.2010 9:50.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2030.1530 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\combo.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\h8srtkrl32mainweq.dll
c:\documents and settings\All Users\Application Data\h8srtmainqt.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.
2010-02-03 10:13 . 2010-02-03 10:13 ——– d—–w- C:\_OTL
2010-01-28 13:19 . 2010-01-28 13:19 ——– d—–w- c:\program files\Trend Micro
2010-01-28 10:06 . 2010-01-28 10:06 ——– d—–w- c:\documents and settings\Mayte\Application Data\Malwarebytes
2010-01-28 09:57 . 2010-01-07 15:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-28 09:57 . 2010-02-01 13:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-28 09:57 . 2010-01-28 09:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-28 09:57 . 2010-01-07 15:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 08:47 . 2008-01-05 22:14 ——– d—–w- c:\documents and settings\Mayte\Application Data\Skype
2010-02-04 08:46 . 2009-03-20 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-02-04 08:37 . 2010-02-04 08:37 0 –sh–w- c:\windows\SDA62C49F.tmp
2010-01-27 20:44 . 2009-05-24 07:55 ——– d—–w- c:\program files\Web Photo Album
2010-01-26 06:47 . 2009-02-26 17:52 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-17 20:52 . 2009-12-05 01:13 79488 —-a-w- c:\documents and settings\Mayte\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-29 21:34 . 2009-11-29 21:34 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-29 21:31 . 2009-11-29 21:31 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-11-15 10:05 . 2008-01-08 21:52 55272 -c–a-w- c:\documents and settings\Mayte\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-07-04 08:21 . 2008-07-03 23:04 11132416 -c–a-w- c:\program files\vpnclient-win-msi-5.0.03.0530-k9.exe
2008-05-21 23:45 . 2008-05-21 23:45 3168683 —-a-w- c:\program files\SopCast.zip
2008-04-14 21:16 . 2008-04-14 21:16 22744616 -c–a-w- c:\program files\ElsterFormular2007-Setup.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-20 114688]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-20 221184]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-16 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-13 2043160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico [2008-7-15 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-20 18:53 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2007-11-15 02:45 1608640 -c–a-w- c:\program files\SlySoft\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPGServiceTool]
2007-08-01 02:26 675840 —-a-w- c:\progra~1\WinTV\EPG Services\System\EPGClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 15:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\dm\\fotobuch.de AG\\Designer 2.0\\Designer.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/20/2009 7:59 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/20/2009 7:59 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/20/2009 7:58 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/20/2009 7:58 PM 297752]
R2 EPGService;EPGService;c:\progra~1\WinTV\EPG Services\System\EPGService.exe [2/29/2008 7:54 PM 431104]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11/15/2009 10:59 AM 54752]
S0 axqp;axqp;c:\windows\system32\drivers\jjgomll.sys –> c:\windows\system32\drivers\jjgomll.sys [?]
S0 jjevmd;jjevmd;c:\windows\system32\drivers\pcqcdlbj.sys –> c:\windows\system32\drivers\pcqcdlbj.sys [?]
S0 klmdb;klmdb;c:\windows\system32\drivers\klmdb.sys –> c:\windows\system32\drivers\klmdb.sys [?]
S2 LVEzLoader;LifeView EZ-USB FX2 FIRMWARE LOADER (LVEzLD06.sys);c:\windows\system32\drivers\LVEzLD06.sys [2/24/2008 11:12 PM 15360]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\WinTV\HCWTVS~1.EXE [2/29/2008 7:51 PM 815104]
S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;c:\windows\system32\drivers\hcw95bda.sys [2/29/2008 7:47 PM 487424]
S3 hcw95rc;Hauppauge MOD7700 IR Driver;c:\windows\system32\drivers\hcw95rc.sys [2/29/2008 7:47 PM 15488]
S3 N;N;\??\c:\program files\NewTech Infosystems\NTI Ripper\ –> c:\program files\NewTech Infosystems\NTI Ripper\ [?]
S3 NinjaUSB;Freecom Turbo USB 2.0;c:\windows\system32\drivers\NinjaUSB.sys [6/16/2009 6:32 AM 24704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-09-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Mayte\Application Data\Mozilla\Firefox\Profiles\w7yeotk6.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000005.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Google Update - c:\documents and settings\Mayte\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
AddRemove-TS - c:\program files\TS\tsc.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-05 09:55
Windows 5.1.2600 Service Pack 3, v.5657 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N]
"ImagePath"="\??\c:\program files\NewTech Infosystems\NTI Ripper\"
.
Completion time: 2010-02-05 09:57:48
ComboFix-quarantined-files.txt 2010-02-05 08:57
Pre-Run: 18.211.606.528 bytes free
Post-Run: 18.189.754.368 bytes free
- - End Of File - - 2A85F5F72215F3E129103F4C8F37ACED
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI