This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] BackDooor.Generic12.AAVT

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

AVG detected Trojan Horse BackDoor.Generic12.AAVT. I followed How to Remove the Generic 12.AAVT Trojan and Are You Infected? (in that order). When I first ran Malwarebytes I got the following log

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

23/02/2010 08:01:31
mbam-log-2010-02-23 (08-01-31).txt

Scan type: Quick Scan
Objects scanned: 136980
Time elapsed: 11 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{df058c45-cd18-453e-8745-5a77f60722ab} (Adware.Gdown) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b5a33c35-7298-4d15-8753-a2e851e2eab3} (Adware.Gdown) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d2b812-752d-4af1-a2fb-968c4d8446db} (Adware.Gdown) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e856b973-45fd-4559-8f82-eab539144667} (Adware.Gdown) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\{F9197A7E-CE10-458e-85F8-5B0CE6DF2BBE} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\GTDownDE_87.ocx (Adware.Gdown) -> Quarantined and deleted successfully.
C:\Documents and Settings\lisa\Local Settings\Temp\Rar$EX02.359\Adobe CS4 Activation Patch\Adobe CS4 Keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.



After doing this I deleted my system restore point and created a new one, as AVG was detecting Generic12.AAVT in a system restore file. A few hours later my daily AVG scan detected the Trojan again, with the following info:

"C:\WINDOWS\system32\drivers\netbt.sys";"Trojan horse BackDoor.Generic12.AAVT";"Object is white-listed (critical/system file that should not be removed)"

I ran Malwarebytes again, and a few times since. Every time the log has been the same:

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

24/02/2010 01:36:26
mbam-log-2010-02-24 (01-36-26).txt

Scan type: Quick Scan
Objects scanned: 132855
Time elapsed: 6 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\{F9197A7E-CE10-458e-85F8-5B0CE6DF2BBE} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


The registry key it says was deleted shows up every time.
When I try to check for updates for Malwarebytes I get the following error code:

Error code: 732 (0,0)

I'm using a computer on a college network with proxy settings that sometimes cause problems when applications try to access the internet, so this could be what's happening here.
When following the Are You Infected? thread, everything goes smoothly until I run GMER. Every time I run it my computer crashes, showing a blue screen with the following message:

STOP: c000021a {Fatal System Error}
The Windows Logon Process system process terminated unexpectedly with a status of 0xc0000005 (0x00000000 0x00000000)
The system has been shut down


This crash doesn't always happen at the same stage of the scan, in fact the first time it crashed before I'd even pressed "Scan".

I ran Defogger but it made no difference.

DDS doesn't seem to be doing anything, when I double-click the file, dds.scr opens immediately in Notepad as gibberish. No scan seems to take place and neither DDS.txt nor attach.txt open. When I check the properties of the file, I see that Windows is associating the script with AutoCAD (which I have installed). Could this be a problem?

EDIT: I downloaded another version of DDS and it worked. The reports are very long, should I post them or attach them?

If I've left out anything please let me know.
Thank you in advance.
Please post the logs Also, please try running GMER in safe mode, uncheck the box beside "files" as well as "Sections" and "IAT/EAT" make sure your security programs and disabled and all other windows are closed.
Hi CatByte

Thanks for your reply.

I tried running GMER with Windows running in safe mode. The computer didn't crash this time but when the scan finished (it took about 6 hours) Windows froze and I couldn't save or copy the results. Comparing GMER with Windows in normal mode and safe mode, one thing I noticed is that while scanning in normal mode (before the system crashed) there were a lot more results in the "Rootkit/Malware" list. Most noticeably, the file netbt.sys (which AVG identifies as infected but white-listed) appeared in the list a number of times in normal mode, but not at all in safe mode. I'll try running GMER in safe mode again tonight.

Below is DDS.txt


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 3:13:00.18 on 24/02/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.298 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe -k bthsvcs
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Software Update 3\SoftAuto.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\Donal\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Donal\My Documents\Downloads\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.mhhe.com/simproject
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell.co.uk/myway
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=2057
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {2bae58c2-79f9-45d1-a286-81f911301c3a} - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Web Test Recorder: {8c84b9f5-3d9e-4204-bb0b-f85d46455868} - mscoree.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe"
uRun: []
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [ShowLOMControl] 1 (0x1)
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [msci] c:\docume~1\donal\locals~1\temp\2007111125215_mcinfo.exe /insfin
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [tsnpstd3] c:\windows\tsnpstd3.exe
mRun: [snpstd3] c:\windows\vsnpstd3.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [MP10_EnsureFileVer] c:\windows\inf\unregmp2.exe /EnsureFileVersions
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\donal\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\donal\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\donal\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart17.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223424891709
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\donal\applic~1\mozilla\firefox\profiles\tamgyp9z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://en-gb.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\donal\application data\mozilla\firefox\profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-25 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-11-5 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-7-25 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-8 285392]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
S3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\drivers\ptsimbus.sys –> c:\windows\system32\drivers\PTSimBus.sys [?]
S3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\drivers\ptsimhid.sys –> c:\windows\system32\drivers\PTSimHid.sys [?]
S3 VSPerfDrv;Performance Tools Driver;c:\program files\microsoft visual studio 8\team tools\performance tools\VSPerfDrv.sys [2005-9-23 54464]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2005-9-23 2799808]

=============== Created Last 30 ================

2010-02-23 07:48:20 0 d—–w- c:\docume~1\donal\applic~1\Malwarebytes
2010-02-23 07:48:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 07:48:12 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-23 07:48:11 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 07:48:11 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-18 20:56:59 102400 —-a-w- c:\windows\mmvem.exe
2010-02-11 17:07:04 0 d—–w- c:\program files\Mendeley Desktop
2010-02-03 12:51:29 0 d—–w- c:\docume~1\donal\applic~1\Clickteam
2010-02-03 12:51:26 111 —-a-w- c:\windows\easkdiry.ini
2010-01-25 19:50:36 311 —-a-w- c:\windows\SWWATER.INI
2010-01-25 19:44:38 0 d—–w- c:\program files\PharosSystems
2010-01-25 19:44:20 0 d—–w- c:\program files\Pharos
2010-01-25 17:28:52 209964 —-a-w- c:\documents and settings\donal\.recently-used.xbel

==================== Find3M ====================

2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23791.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23790.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378F.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378E.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378D.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378C.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378B.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378A.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23789.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23788.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23787.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23786.DLL
2009-12-31 16:50:03 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-31 16:50:03 353792 ——w- c:\windows\system32\dllcache\srv.sys
2009-12-31 15:33:06 70656 ——w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ——w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-26 03:53:03 223440 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2009-12-18 13:05:43 634648 ——w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ——w- c:\windows\system32\dllcache\ieakui.dll
2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-16 18:43:27 343040 ——w- c:\windows\system32\dllcache\mspaint.exe
2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-14 07:08:23 33280 ——w- c:\windows\system32\dllcache\csrsrv.dll
2009-12-10 14:54:13 201728 —-a-w- c:\windows\system32\Analogy.scr
2009-12-08 19:27:51 2189184 ——w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-08 19:26:15 2145280 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-08 18:43:51 2023936 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-08 18:43:50 2066048 ——w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-08 09:23:28 474112 ——w- c:\windows\system32\dllcache\shlwapi.dll
2009-12-04 18:22:22 455424 ——w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-27 17:11:44 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:11:44 17920 ——w- c:\windows\system32\dllcache\msyuv.dll
2009-11-27 17:11:44 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11:44 1291776 ——w- c:\windows\system32\dllcache\quartz.dll
2009-11-27 16:07:35 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07:35 8704 —-a-w- c:\windows\system32\dllcache\tsbyuv.dll
2009-11-27 16:07:35 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07:35 28672 ——w- c:\windows\system32\dllcache\msvidc32.dll
2009-11-27 16:07:34 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07:34 84992 ——w- c:\windows\system32\dllcache\avifil32.dll
2009-11-27 16:07:34 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07:34 48128 ——w- c:\windows\system32\dllcache\iyuv_32.dll
2009-11-27 16:07:34 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07:34 11264 ——w- c:\windows\system32\dllcache\msrle32.dll

============= FINISH: 3:13:33.20 ===============


And here is Attach.txt


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 01/11/2007 12:32:31
System Uptime: 24/02/2010 02:13:05 (1 hours ago)

Motherboard: Dell Inc. | |
Processor: Genuine Intel® CPU T2400 @ 1.83GHz | Microprocessor | 1830/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 69 GiB total, 41.254 GiB free.
D: is CDROM ()
X: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 23/02/2010 08:30:57 - System Checkpoint
RP2: 24/02/2010 01:21:26 - Automatic Restore Point
RP3: 24/02/2010 03:00:21 - Software Distribution Service 3.0

==== Installed Programs ======================

µTorrent
Ableton Live v7.0.1
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Reader 9.3
Alarm Clock v1.0
Analogy Screen Saver
AutoCAD 2007 - English
Autodesk DWF Viewer
AVG Free 9.0
Broadcom Management Programs
Canon Utilities Digital Photo Professional 3.7
Canon Utilities EOS Utility
CinepPlayer 30 Update
Conexant HDA D110 MDC V.92 Modem
Creative Centrale
Creative Removable Disk Manager
Creative Software Update
CutePDF Writer 2.7
Dell Media Experience
Dell Support 5.0.0 (630)
Dell System Restore
Digital Line Detect
Dropbox
ERUNT 1.1j
GIMP 2.4.5
GlassFish V2 UR2
Google Talk Plugin
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Inkscape 0.46
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
Internal Network Card Power Management
Internet Explorer Default Page
Java 2 Runtime Environment, SE v1.4.2_03
Java DB 10.3.1.4
Java™ 6 Update 15
Java™ 6 Update 2
Java™ 6 Update 7
Java™ SE Development Kit 6 Update 7
Macromedia Flash Player 8
Malwarebytes' Anti-Malware
MATLAB 7.1
mCore
MCU
mDrWiFi
MediaMonkey 3.0
Mendeley Desktop 0.9.5.2
mHlpDell
Microsoft .NET Compact Framework 1.0 SP3 Developer
Microsoft .NET Compact Framework 2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Device Emulator version 1.0 - ENU
Microsoft Document Explorer 2005
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
Microsoft SQL Server 2005 Tools Express Edition
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual J# 2.0 Redistributable Package
Microsoft Visual Studio 2005 Team Suite - ENU
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Works 7.0
mIWA
mLogView
mMHouse
Mobile note taker 3.0
Modem Helper
Mozilla Firefox (3.5.8)
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser
mWlsSafe
mWMI
mXML
mZConfig
NetBeans IDE 6.1
NetWaiting
OpenOffice.org 2.3
Pd-0.39.3-extended
PDF Manual NW-E010 Series
Pharos
Picasa 3
PowerDVD 5.7
PowerISO
Pro/ENGINEER Schools Edition Release Wildfire 4.0 Datecode M030
Protege 3.3.1
QuickSet
QuickTime
RealPlayer
Scribus [removed]
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
Sonic Activation Module
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spelling Dictionaries Support For Adobe Reader 9
Synaptics Pointing Device Driver
SyncBack
TrueCrypt
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
USB PC Camera Plus
VideoLAN VLC media player 0.8.6d
Viewpoint Media Player
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows XP Service Pack 3
WinRAR archiver

==== Event Viewer Messages From Past Week ========

24/02/2010 01:54:49, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s).
23/02/2010 08:07:35, error: Service Control Manager [7034] - The MATLAB Server service terminated unexpectedly. It has done this 1 time(s).
23/02/2010 06:01:44, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
23/02/2010 00:10:21, error: Service Control Manager [7000] - The adfs service failed to start due to the following error: The system cannot find the file specified.
22/02/2010 21:43:37, error: Dhcp [1002] - The IP address lease 10.6.1.116 for the Network Card with network address 00130212666E has been denied by the DHCP server 10.3.64.4 (The DHCP Server sent a DHCPNACK message).
19/02/2010 12:03:47, error: Dhcp [1002] - The IP address lease 10.5.18.196 for the Network Card with network address 0015C54BB53B has been denied by the DHCP server 10.3.0.4 (The DHCP Server sent a DHCPNACK message).
18/02/2010 13:31:10, error: Dhcp [1002] - The IP address lease 10.3.4.245 for the Network Card with network address 0015C54BB53B has been denied by the DHCP server 10.3.0.2 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================
This is not a bump, I promise! CatByte - apologies, I misread your last post. I went back and ran GMER in safe mode with the boxes you said unchecked this time. The scan was finished in a matter of minutes and Windows didn't freeze up this time. However I have another problem… I can't access the Save or Copy buttons. The window doesn't fit on the screen, and I've tried resizing it every which way but to no avail. There's no scroll bar to move up or down. I tried navigating with my keyboard and also tried Ctrl Alt <- (to flip the screen on its side) but neither worked. I tried copying and pasting into Notepad but this also didn't work. I can barely see the Scan/Stop button, and then the OK and Cancel buttons are directly below that. I can't access any of the others. Thanks again
Hi, that's OK

did you note if there were any alerts to any rootkits found on the system?

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
In the Rootkit/Malware window of GMER there are a handful of entries. They seemed related to device drivers (e.g. I think the driver for my touchpad was there twice)

I ran Combofix. After a few seconds the following warning popped up:

Parasites found !!

The following files were trying to attach to ComboFix. They shall be disabled. Kindly note down on paper the name of each file. We may need it later.

C:\PROGRA~1\PHAROS~1\Core\PRNTRACK.DLL


ComboFix was unable to connect to the internet to download the Microsoft Windows Recovery Console, probably due to the password-protected proxy I mentioned. It continued scanning and after a few seconds this warning popped up:

Rootkit !!

ComboFix has detected the presence of rootkit activity and needs to reboot the machine


Computer rebooted, and when I signed back in to my profile the ComboFix window was still there. No desktop, taskbar, icons etc. I thought it was still scanning and left it like that for over an hour. Eventually I pressed the power button and a large number of "DLL Initialization Failed" windows appeared, along with the Windows taskbar and desktop icons. ComboFix still sat there doing nothing. Eventually I rebooted again. Again the ComboFix window was there when I signed in, this time it started from scratch. It ran the scan and produced a log (pasted below). The rootkit warning did not appear this time. Should I install Microsoft Windows Recovery Console directly and run ComboFix again?

ComboFix 10-02-24.03 - Donal 25/02/2010 20:06:27.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.444 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\progra~1\PHAROS~1\Core\PRNTRACK.DLL


((((((((((((((((((((((((( Files Created from 2010-01-25 to 2010-02-25 )))))))))))))))))))))))))))))))
.

2010-02-24 17:58 . 2010-02-24 18:18 ——– d—–w- c:\documents and settings\Donal\.artofillusion
2010-02-24 17:33 . 2010-02-24 17:34 ——– d—–w- c:\documents and settings\Donal\.SunDownloadManager
2010-02-24 17:24 . 2010-02-24 18:18 ——– d—–w- c:\program files\ArtOfIllusion
2010-02-24 16:47 . 2009-11-12 17:04 4296704 —-a-w- c:\windows\DXLib80Ux64.dll
2010-02-24 16:47 . 2009-11-12 16:53 2805760 —-a-w- c:\windows\DXLib80U.dll
2010-02-24 16:47 . 2009-09-01 17:03 473600 —-a-w- c:\windows\SYCLicense80Ux64_090901.dll
2010-02-24 16:47 . 2009-09-01 17:01 425984 —-a-w- c:\windows\SYCLicenseU_090901.dll
2010-02-24 16:47 . 2009-09-01 17:01 278528 —-a-w- c:\windows\SYCLicense_090901.dll
2010-02-24 16:47 . 2009-12-02 21:02 532480 —-a-w- c:\windows\SYCGUI71.dll
2010-02-24 16:47 . 2009-12-02 19:48 696320 —-a-w- c:\windows\SYCGUI80U.dll
2010-02-24 16:47 . 2009-12-02 19:47 824320 —-a-w- c:\windows\SYCGUI80Ux64.dll
2010-02-24 16:47 . 2009-11-12 16:41 2826240 —-a-w- c:\windows\DXLib71.dll
2010-02-24 16:47 . 2009-11-12 16:00 3055616 —-a-w- c:\windows\DXLib60.dll
2010-02-24 16:47 . 2009-12-02 19:24 532480 —-a-w- c:\windows\SYCGUI.dll
2010-02-24 16:47 . 2010-02-24 16:47 ——– d—–w- c:\program files\SYCODE
2010-02-24 01:23 . 2010-02-24 01:23 ——– d—–w- c:\program files\ERUNT
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\documents and settings\Donal\Application Data\Malwarebytes
2010-02-23 07:48 . 2010-01-07 16:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 07:48 . 2010-01-07 16:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-18 20:56 . 2010-02-18 20:56 102400 —-a-w- c:\windows\mmvem.exe
2010-02-11 17:08 . 2010-02-11 17:08 ——– d—–w- c:\documents and settings\Donal\Local Settings\Application Data\Mendeley Ltd
2010-02-11 17:07 . 2010-02-11 17:07 ——– d—–w- c:\program files\Mendeley Desktop
2010-02-03 12:51 . 2010-02-03 12:51 ——– d—–w- c:\documents and settings\Donal\Application Data\Clickteam

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-25 20:05 . 2010-01-09 15:20 ——– d—–w- c:\documents and settings\Donal\Application Data\Dropbox
2010-02-25 20:04 . 2007-11-05 20:40 ——– d—–w- c:\documents and settings\Donal\Application Data\OpenOffice.org2
2010-02-24 17:35 . 2010-02-24 17:35 ——– d—–w- c:\program files\JMF2.1.1e
2010-02-24 17:31 . 2006-04-20 11:16 ——– d—–w- c:\program files\Common Files\Java
2010-02-24 17:30 . 2006-04-20 11:16 ——– d—–w- c:\program files\Java
2010-02-24 00:00 . 2010-01-05 19:11 ——– d—–w- c:\program files\SyncBack
2010-02-22 21:33 . 2008-11-11 23:30 ——– d—–w- c:\program files\MATLAB71
2010-02-11 17:09 . 2007-11-05 20:41 1 —-a-w- c:\documents and settings\Donal\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-01-25 19:45 . 2010-01-25 19:44 ——– d—–w- c:\program files\Pharos
2010-01-25 17:28 . 2008-04-24 22:28 ——– d—–w- c:\documents and settings\Donal\Application Data\gtk-2.0
2010-01-21 01:53 . 2007-11-05 20:43 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-09 15:21 . 2010-01-09 15:21 89854 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\Uninstall.exe
2010-01-05 10:00 . 2004-08-10 11:51 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-10 11:51 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-10 11:50 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2006-04-20 10:56 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-31 00:48 . 2009-12-31 00:48 21968784 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\Dropbox.exe
2009-12-26 03:53 . 2009-12-26 03:53 223440 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2009-12-17 17:14 . 2009-01-27 13:38 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2004-08-10 12:01 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-16 14:42 . 2009-12-24 11:03 872960 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 14:42 . 2009-12-24 11:03 43008 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 14:42 . 2009-12-24 11:03 340480 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 14:41 . 2009-12-24 11:03 346624 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-14 07:08 . 2004-08-10 11:50 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-10 14:54 . 2009-12-10 14:54 201728 —-a-w- c:\windows\system32\Analogy.scr
2009-12-09 01:19 . 2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
2009-12-08 19:26 . 2004-08-10 11:51 2145280 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 21:59 2023936 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2006-04-20 10:56 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-05-28 401408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 397312]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-12-15 839680]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-20 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-11-29 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-28 185872]
"MP10_EnsureFileVer"="c:\windows\inf\unregmp2.exe" [2008-04-14 208896]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Donal\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Donal\Application Data\Dropbox\bin\Dropbox.exe [2009-12-31 21968784]
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2009-4-18 11000]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-20 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-08 02:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_07\\jre\\bin\\java.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\nms\\nmsd.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\obj\\pro_comm_msg.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\obj\\xtop.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\MD 86149 Notetaker\\Easy note taker.exe"=
"c:\\Documents and Settings\\Donal\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [25/07/2008 20:49 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [25/07/2008 20:49 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [08/11/2009 02:03 285392]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 11:42 64000]
S3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\DRIVERS\PTSimBus.sys –> c:\windows\system32\DRIVERS\PTSimBus.sys [?]
S3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\DRIVERS\PTSimHid.sys –> c:\windows\system32\DRIVERS\PTSimHid.sys [?]
S3 VSPerfDrv;Performance Tools Driver;c:\program files\Microsoft Visual Studio 8\Team Tools\Performance Tools\VSPerfDrv.sys [23/09/2005 02:42 54464]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 07:01 2799808]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012Core.job
- c:\documents and settings\lisa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-17 13:19]

2010-02-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012UA.job
- c:\documents and settings\lisa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-17 13:19]

2010-02-24 c:\windows\Tasks\SyncBack Daily Iomega College 4 Sync.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-24 c:\windows\Tasks\SyncBack DropBox.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-21 c:\windows\Tasks\SyncBack Weekly HD sync.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-21 c:\windows\Tasks\SyncBack Weekly Images Backup Iomega.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.mhhe.com/simproject
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=2057
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://en-gb.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

BHO-{2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-25 20:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0xF77C7BDE]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7541f28
\Driver\ACPI -> ACPI.sys @ 0xf73d4cb8
\Driver\atapi -> atapi.sys @ 0xf738c852
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Bluetooth Device (Personal Area Network) -> SendCompleteHandler -> NDIS.sys @ 0xf7270bb0
PacketIndicateHandler -> NDIS.sys @ 0xf725fa0d
SendHandler -> NDIS.sys @ 0xf7273b40
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc2A.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\@*& Æ]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1336)
c:\windows\system32\WININET.dll
c:\progra~1\PHAROS~1\Core\PRNTRACK.DLL
c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-25 20:20:52
ComboFix-quarantined-files.txt 2010-02-25 20:20

Pre-Run: 44,047,867,904 bytes free
Post-Run: 44,252,880,896 bytes free

- - End Of File - - A6D1631A96366259E44DACC54E363A01
Hi,

I installed the Recovery Console by moving my computer to a different network and running ComboFix again (because I can't find the XP CD). The log from that run is below.

ComboFix 10-02-25.02 - Donal 25/02/2010 22:57:49.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.460 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\srchasst\nls302en.lex

.
((((((((((((((((((((((((( Files Created from 2010-01-25 to 2010-02-25 )))))))))))))))))))))))))))))))
.

2010-02-24 17:58 . 2010-02-24 18:18 ——– d—–w- c:\documents and settings\Donal\.artofillusion
2010-02-24 17:33 . 2010-02-24 17:34 ——– d—–w- c:\documents and settings\Donal\.SunDownloadManager
2010-02-24 17:24 . 2010-02-24 18:18 ——– d—–w- c:\program files\ArtOfIllusion
2010-02-24 16:47 . 2009-11-12 17:04 4296704 —-a-w- c:\windows\DXLib80Ux64.dll
2010-02-24 16:47 . 2009-11-12 16:53 2805760 —-a-w- c:\windows\DXLib80U.dll
2010-02-24 16:47 . 2009-09-01 17:03 473600 —-a-w- c:\windows\SYCLicense80Ux64_090901.dll
2010-02-24 16:47 . 2009-09-01 17:01 425984 —-a-w- c:\windows\SYCLicenseU_090901.dll
2010-02-24 16:47 . 2009-09-01 17:01 278528 —-a-w- c:\windows\SYCLicense_090901.dll
2010-02-24 16:47 . 2009-12-02 21:02 532480 —-a-w- c:\windows\SYCGUI71.dll
2010-02-24 16:47 . 2009-12-02 19:48 696320 —-a-w- c:\windows\SYCGUI80U.dll
2010-02-24 16:47 . 2009-12-02 19:47 824320 —-a-w- c:\windows\SYCGUI80Ux64.dll
2010-02-24 16:47 . 2009-11-12 16:41 2826240 —-a-w- c:\windows\DXLib71.dll
2010-02-24 16:47 . 2009-11-12 16:00 3055616 —-a-w- c:\windows\DXLib60.dll
2010-02-24 16:47 . 2009-12-02 19:24 532480 —-a-w- c:\windows\SYCGUI.dll
2010-02-24 16:47 . 2010-02-24 16:47 ——– d—–w- c:\program files\SYCODE
2010-02-24 01:23 . 2010-02-24 01:23 ——– d—–w- c:\program files\ERUNT
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\documents and settings\Donal\Application Data\Malwarebytes
2010-02-23 07:48 . 2010-01-07 16:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 07:48 . 2010-01-07 16:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-18 20:56 . 2010-02-18 20:56 102400 —-a-w- c:\windows\mmvem.exe
2010-02-11 17:08 . 2010-02-11 17:08 ——– d—–w- c:\documents and settings\Donal\Local Settings\Application Data\Mendeley Ltd
2010-02-11 17:07 . 2010-02-11 17:07 ——– d—–w- c:\program files\Mendeley Desktop
2010-02-03 12:51 . 2010-02-03 12:51 ——– d—–w- c:\documents and settings\Donal\Application Data\Clickteam

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-25 23:11 . 2007-11-05 20:40 ——– d—–w- c:\documents and settings\Donal\Application Data\OpenOffice.org2
2010-02-25 23:11 . 2010-01-09 15:20 ——– d—–w- c:\documents and settings\Donal\Application Data\Dropbox
2010-02-24 17:35 . 2010-02-24 17:35 ——– d—–w- c:\program files\JMF2.1.1e
2010-02-24 17:31 . 2006-04-20 11:16 ——– d—–w- c:\program files\Common Files\Java
2010-02-24 17:30 . 2006-04-20 11:16 ——– d—–w- c:\program files\Java
2010-02-24 00:00 . 2010-01-05 19:11 ——– d—–w- c:\program files\SyncBack
2010-02-22 21:33 . 2008-11-11 23:30 ——– d—–w- c:\program files\MATLAB71
2010-01-25 19:45 . 2010-01-25 19:44 ——– d—–w- c:\program files\Pharos
2010-01-25 17:28 . 2008-04-24 22:28 ——– d—–w- c:\documents and settings\Donal\Application Data\gtk-2.0
2010-01-21 01:53 . 2007-11-05 20:43 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-05 10:00 . 2004-08-10 11:51 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-10 11:51 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-10 11:50 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2006-04-20 10:56 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-26 03:53 . 2009-12-26 03:53 223440 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2009-12-17 17:14 . 2009-01-27 13:38 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2004-08-10 12:01 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-10 11:50 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-10 14:54 . 2009-12-10 14:54 201728 —-a-w- c:\windows\system32\Analogy.scr
2009-12-08 19:26 . 2004-08-10 11:51 2145280 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 21:59 2023936 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2006-04-20 10:56 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-05-28 401408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 397312]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-12-15 839680]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-20 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-11-29 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-28 185872]
"MP10_EnsureFileVer"="c:\windows\inf\unregmp2.exe" [2008-04-14 208896]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Donal\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Donal\Application Data\Dropbox\bin\Dropbox.exe [2009-12-31 21968784]
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2009-4-18 11000]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-20 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-08 02:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_07\\jre\\bin\\java.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\nms\\nmsd.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\obj\\pro_comm_msg.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\obj\\xtop.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\MD 86149 Notetaker\\Easy note taker.exe"=
"c:\\Documents and Settings\\Donal\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [25/07/2008 20:49 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [25/07/2008 20:49 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [08/11/2009 02:03 285392]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 11:42 64000]
S3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\DRIVERS\PTSimBus.sys –> c:\windows\system32\DRIVERS\PTSimBus.sys [?]
S3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\DRIVERS\PTSimHid.sys –> c:\windows\system32\DRIVERS\PTSimHid.sys [?]
S3 VSPerfDrv;Performance Tools Driver;c:\program files\Microsoft Visual Studio 8\Team Tools\Performance Tools\VSPerfDrv.sys [23/09/2005 02:42 54464]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 07:01 2799808]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012Core.job
- c:\documents and settings\lisa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-17 13:19]

2010-02-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012UA.job
- c:\documents and settings\lisa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-17 13:19]

2010-02-24 c:\windows\Tasks\SyncBack Daily Iomega College 4 Sync.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-24 c:\windows\Tasks\SyncBack DropBox.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-21 c:\windows\Tasks\SyncBack Weekly HD sync.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-21 c:\windows\Tasks\SyncBack Weekly Images Backup Iomega.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.mhhe.com/simproject
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=2057
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://en-gb.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-25 23:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xF78FFBDE]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7541f28
\Driver\ACPI -> ACPI.sys @ 0xf73d4cb8
\Driver\atapi -> atapi.sys @ 0xf738c852
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Broadcom 440x 10/100 Integrated Controller -> SendCompleteHandler -> NDIS.sys @ 0xf7270bb0
PacketIndicateHandler -> NDIS.sys @ 0xf725fa0d
SendHandler -> NDIS.sys @ 0xf7273b40
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc21.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\@*& Æ]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2504)
c:\windows\system32\WININET.dll
c:\progra~1\PHAROS~1\Core\PRNTRACK.DLL
c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\MATLAB71\webserver\bin\win32\matlabserver.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\MATLAB71\bin\win32\MATLAB.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
c:\progra~1\PHAROS~1\Core\CTskMstr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\rundll32.exe
c:\program files\OpenOffice.org 2.3\program\soffice.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\OpenOffice.org 2.3\program\soffice.BIN
.
**************************************************************************
.
Completion time: 2010-02-25 23:20:51 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-25 23:20
ComboFix2.txt 2010-02-25 20:20

Pre-Run: 44,215,095,296 bytes free
Post-Run: 44,159,385,600 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 9B7855E5166137850A5C4E049A1972A4


The log from TDSSKiller is below

23:26:12:062 3224 TDSS rootkit removing tool 2.2.7 Feb 25 2010 10:44:44
23:26:12:062 3224 ================================================================================
23:26:12:062 3224 SystemInfo:

23:26:12:062 3224 OS Version: 5.1.2600 ServicePack: 3.0
23:26:12:078 3224 Product type: Workstation
23:26:12:078 3224 ComputerName: DDKVK32J
23:26:12:078 3224 UserName: Donal
23:26:12:078 3224 Windows directory: C:\WINDOWS
23:26:12:078 3224 Processor architecture: Intel x86
23:26:12:078 3224 Number of processors: 2
23:26:12:078 3224 Page size: 0x1000
23:26:12:078 3224 Boot type: Normal boot
23:26:12:078 3224 ================================================================================
23:26:12:078 3224 UnloadDriverW: NtUnloadDriver error 2
23:26:12:078 3224 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
23:26:12:093 3224 Initialize success
23:26:12:093 3224
23:26:12:093 3224 Scanning Services …
23:26:12:093 3224 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
23:26:12:093 3224 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
23:26:12:093 3224 wfopen_ex: Trying to KLMD file open
23:26:12:093 3224 wfopen_ex: File opened ok (Flags 2)
23:26:12:093 3224 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
23:26:12:093 3224 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
23:26:12:093 3224 wfopen_ex: Trying to KLMD file open
23:26:12:093 3224 wfopen_ex: File opened ok (Flags 2)
23:26:12:812 3224 GetAdvancedServicesInfo: Raw services enum returned 403 services
23:26:12:828 3224 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
23:26:12:828 3224 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
23:26:12:828 3224
23:26:12:828 3224 Scanning Kernel memory …
23:26:12:828 3224 Devices to scan: 5
23:26:12:828 3224
23:26:12:828 3224 Driver Name: Disk
23:26:12:828 3224 IRP_MJ_CREATE : F7543BB0
23:26:12:828 3224 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
23:26:12:828 3224 IRP_MJ_CLOSE : F7543BB0
23:26:12:828 3224 IRP_MJ_READ : F753DD1F
23:26:12:828 3224 IRP_MJ_WRITE : F753DD1F
23:26:12:828 3224 IRP_MJ_QUERY_INFORMATION : 804F4562
23:26:12:828 3224 IRP_MJ_SET_INFORMATION : 804F4562
23:26:12:828 3224 IRP_MJ_QUERY_EA : 804F4562
23:26:12:828 3224 IRP_MJ_SET_EA : 804F4562
23:26:12:828 3224 IRP_MJ_FLUSH_BUFFERS : F753E2E2
23:26:12:828 3224 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
23:26:12:828 3224 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
23:26:12:828 3224 IRP_MJ_DIRECTORY_CONTROL : 804F4562
23:26:12:828 3224 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
23:26:12:828 3224 IRP_MJ_DEVICE_CONTROL : F753E3BB
23:26:12:828 3224 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7541F28
23:26:12:828 3224 IRP_MJ_SHUTDOWN : F753E2E2
23:26:12:828 3224 IRP_MJ_LOCK_CONTROL : 804F4562
23:26:12:828 3224 IRP_MJ_CLEANUP : 804F4562
23:26:12:828 3224 IRP_MJ_CREATE_MAILSLOT : 804F4562
23:26:12:828 3224 IRP_MJ_QUERY_SECURITY : 804F4562
23:26:12:828 3224 IRP_MJ_SET_SECURITY : 804F4562
23:26:12:828 3224 IRP_MJ_POWER : F753FC82
23:26:12:828 3224 IRP_MJ_SYSTEM_CONTROL : F754499E
23:26:12:828 3224 IRP_MJ_DEVICE_CHANGE : 804F4562
23:26:12:828 3224 IRP_MJ_QUERY_QUOTA : 804F4562
23:26:12:828 3224 IRP_MJ_SET_QUOTA : 804F4562
23:26:12:843 3224 sion
23:26:12:843 3224 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
23:26:12:843 3224
23:26:12:843 3224 Driver Name: Disk
23:26:12:843 3224 IRP_MJ_CREATE : F7543BB0
23:26:12:843 3224 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
23:26:12:843 3224 IRP_MJ_CLOSE : F7543BB0
23:26:12:843 3224 IRP_MJ_READ : F753DD1F
23:26:12:843 3224 IRP_MJ_WRITE : F753DD1F
23:26:12:843 3224 IRP_MJ_QUERY_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_SET_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_EA : 804F4562
23:26:12:843 3224 IRP_MJ_SET_EA : 804F4562
23:26:12:843 3224 IRP_MJ_FLUSH_BUFFERS : F753E2E2
23:26:12:843 3224 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_DIRECTORY_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_DEVICE_CONTROL : F753E3BB
23:26:12:843 3224 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7541F28
23:26:12:843 3224 IRP_MJ_SHUTDOWN : F753E2E2
23:26:12:843 3224 IRP_MJ_LOCK_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_CLEANUP : 804F4562
23:26:12:843 3224 IRP_MJ_CREATE_MAILSLOT : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_SECURITY : 804F4562
23:26:12:843 3224 IRP_MJ_SET_SECURITY : 804F4562
23:26:12:843 3224 IRP_MJ_POWER : F753FC82
23:26:12:843 3224 IRP_MJ_SYSTEM_CONTROL : F754499E
23:26:12:843 3224 IRP_MJ_DEVICE_CHANGE : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_QUOTA : 804F4562
23:26:12:843 3224 IRP_MJ_SET_QUOTA : 804F4562
23:26:12:843 3224 sion
23:26:12:843 3224 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
23:26:12:843 3224
23:26:12:843 3224 Driver Name: Disk
23:26:12:843 3224 IRP_MJ_CREATE : F7543BB0
23:26:12:843 3224 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
23:26:12:843 3224 IRP_MJ_CLOSE : F7543BB0
23:26:12:843 3224 IRP_MJ_READ : F753DD1F
23:26:12:843 3224 IRP_MJ_WRITE : F753DD1F
23:26:12:843 3224 IRP_MJ_QUERY_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_SET_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_EA : 804F4562
23:26:12:843 3224 IRP_MJ_SET_EA : 804F4562
23:26:12:843 3224 IRP_MJ_FLUSH_BUFFERS : F753E2E2
23:26:12:843 3224 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_DIRECTORY_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_DEVICE_CONTROL : F753E3BB
23:26:12:843 3224 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7541F28
23:26:12:843 3224 IRP_MJ_SHUTDOWN : F753E2E2
23:26:12:843 3224 IRP_MJ_LOCK_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_CLEANUP : 804F4562
23:26:12:843 3224 IRP_MJ_CREATE_MAILSLOT : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_SECURITY : 804F4562
23:26:12:843 3224 IRP_MJ_SET_SECURITY : 804F4562
23:26:12:843 3224 IRP_MJ_POWER : F753FC82
23:26:12:843 3224 IRP_MJ_SYSTEM_CONTROL : F754499E
23:26:12:843 3224 IRP_MJ_DEVICE_CHANGE : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_QUOTA : 804F4562
23:26:12:843 3224 IRP_MJ_SET_QUOTA : 804F4562
23:26:12:843 3224 sion
23:26:12:843 3224 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
23:26:12:843 3224
23:26:12:843 3224 Driver Name: Disk
23:26:12:843 3224 IRP_MJ_CREATE : F7543BB0
23:26:12:843 3224 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
23:26:12:843 3224 IRP_MJ_CLOSE : F7543BB0
23:26:12:843 3224 IRP_MJ_READ : F753DD1F
23:26:12:843 3224 IRP_MJ_WRITE : F753DD1F
23:26:12:843 3224 IRP_MJ_QUERY_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_SET_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_EA : 804F4562
23:26:12:843 3224 IRP_MJ_SET_EA : 804F4562
23:26:12:843 3224 IRP_MJ_FLUSH_BUFFERS : F753E2E2
23:26:12:843 3224 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_DIRECTORY_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_DEVICE_CONTROL : F753E3BB
23:26:12:843 3224 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7541F28
23:26:12:843 3224 IRP_MJ_SHUTDOWN : F753E2E2
23:26:12:843 3224 IRP_MJ_LOCK_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_CLEANUP : 804F4562
23:26:12:843 3224 IRP_MJ_CREATE_MAILSLOT : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_SECURITY : 804F4562
23:26:12:843 3224 IRP_MJ_SET_SECURITY : 804F4562
23:26:12:843 3224 IRP_MJ_POWER : F753FC82
23:26:12:843 3224 IRP_MJ_SYSTEM_CONTROL : F754499E
23:26:12:843 3224 IRP_MJ_DEVICE_CHANGE : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_QUOTA : 804F4562
23:26:12:843 3224 IRP_MJ_SET_QUOTA : 804F4562
23:26:12:843 3224 sion
23:26:12:843 3224 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
23:26:12:843 3224
23:26:12:843 3224 Driver Name: atapi
23:26:12:843 3224 IRP_MJ_CREATE : F73906F2
23:26:12:843 3224 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
23:26:12:843 3224 IRP_MJ_CLOSE : F73906F2
23:26:12:843 3224 IRP_MJ_READ : 804F4562
23:26:12:843 3224 IRP_MJ_WRITE : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_SET_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_EA : 804F4562
23:26:12:843 3224 IRP_MJ_SET_EA : 804F4562
23:26:12:843 3224 IRP_MJ_FLUSH_BUFFERS : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
23:26:12:843 3224 IRP_MJ_DIRECTORY_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_DEVICE_CONTROL : F7390712
23:26:12:843 3224 IRP_MJ_INTERNAL_DEVICE_CONTROL : F738C852
23:26:12:843 3224 IRP_MJ_SHUTDOWN : 804F4562
23:26:12:843 3224 IRP_MJ_LOCK_CONTROL : 804F4562
23:26:12:843 3224 IRP_MJ_CLEANUP : 804F4562
23:26:12:843 3224 IRP_MJ_CREATE_MAILSLOT : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_SECURITY : 804F4562
23:26:12:843 3224 IRP_MJ_SET_SECURITY : 804F4562
23:26:12:843 3224 IRP_MJ_POWER : F739073C
23:26:12:843 3224 IRP_MJ_SYSTEM_CONTROL : F7397336
23:26:12:843 3224 IRP_MJ_DEVICE_CHANGE : 804F4562
23:26:12:843 3224 IRP_MJ_QUERY_QUOTA : 804F4562
23:26:12:843 3224 IRP_MJ_SET_QUOTA : 804F4562
23:26:12:843 3224 siohd: 0
23:26:12:875 3224 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
23:26:12:875 3224
23:26:12:875 3224 Completed
23:26:12:875 3224
23:26:12:875 3224 Results:
23:26:12:875 3224 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
23:26:12:875 3224 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
23:26:12:875 3224 File objects infected / cured / cured on reboot: 0 / 0 / 0
23:26:12:875 3224
23:26:12:875 3224 KLMD(ARK) unloaded successfully
Hi,

Please try this scan as well:



Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • select the "none" button at the top
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    /md5start
    netbt.sys
    /md5stop
    %systemroot%\system32\drivers\*.sys /lockedfiles /all
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
I ran GMER in safe mode again and wrote down the entries in the Rootkit/Malware tab.

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys(Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys(Synaptics Touchpad Driver/Synaptics, Inc.)
Device \FileSystem\Fastfat \Fat F6AEED20
Device \FileSystem\Fastfat \Fat F6B06631
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016411a5852
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0016411a5852(not active ControlSet)

I ran OTL, OTL.txt:

OTL logfile created on: 26/02/2010 01:13:03 - Run 1
OTL by OldTimer - Version 3.1.30.2 Folder = C:\Documents and Settings\Donal\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 403.00 Mb Available Physical Memory | 40.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.20 Gb Total Space | 41.15 Gb Free Space | 59.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DDKVK32J
Current User Name: Donal
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Donal\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Documents and Settings\Donal\Application Data\Dropbox\bin\Dropbox.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Creative\Software Update 3\SoftAuto.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 2.3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 2.3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\tsnpstd3.exe (SONIX)
PRC - C:\Program Files\PharosSystems\Core\CTskMstr.exe (Pharos Systems International)
PRC - C:\WINDOWS\vsnpstd3.exe ()
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
PRC - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\MATLAB71\bin\win32\MATLAB.exe (The MathWorks Inc.)
PRC - C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe ()
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Program Files\NetWaiting\netwaiting.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Donal\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\PharosSystems\Core\PRNTRACK.DLL (Pharos Systems International)
MOD - C:\WINDOWS\system32\MadCHook.dll (www.madshi.net)
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (Pharos Systems ComTaskMaster) – C:\Program Files\PharosSystems\Core\CTskMstr.exe (Pharos Systems International)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (msvsmon80) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (matlabserver) – C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe ()
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mhhe.com/simproject
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.startup.homepage: "http://en-gb.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: [removed]:1.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.autoconfig_url: "http://proxypac.tcd.ie/accelerated_pac_base.pac"

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2009/12/12 08:47:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/10/28 14:34:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/20 14:30:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/24 17:45:24 | 000,000,000 | —D | M]

[2009/02/03 18:11:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Mozilla\Extensions
[2010/02/24 17:49:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions
[2008/05/03 22:28:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{2bae58c2-79f9-45d1-a286-81f911301c3a}
[2009/01/06 21:21:31 | 000,000,000 | —D | M] (BlockSite) – C:\Documents and Settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
[2009/01/19 21:23:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\[removed]
[2008/10/20 19:45:58 | 000,001,058 | —- | M] () – C:\Documents and Settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\searchplugins\a9.xml
[2008/10/20 19:44:32 | 000,001,032 | —- | M] () – C:\Documents and Settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\searchplugins\wikipedia-eng.xml
[2010/02/24 17:30:48 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/09/10 12:02:08 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2009/09/10 12:02:08 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2009/09/10 12:02:08 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009/09/10 12:02:09 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/02/25 23:10:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2BAE58C2-79F9-45D1-A286-81F911301C3A} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [ShowLOMControl] Reg Error: Invalid data type. File not found
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe (SONIX)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - HKCU..\Run: [SoftAuto.exe] C:\Program Files\Creative\Software Update 3\SoftAuto.exe (Creative Technology Ltd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\Donal\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Donal\Application Data\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Documents and Settings\Donal\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1223424891709 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17454841580224512)

========== Files/Folders - Created Within 14 Days ==========

[2010/02/26 01:06:30 | 000,549,888 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Donal\Desktop\OTL.exe
[2010/02/25 23:25:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Donal\Desktop\tdsskiller
[2010/02/25 22:42:46 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/02/25 18:35:13 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/02/25 18:35:13 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/02/25 18:35:13 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/02/25 18:35:13 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/02/25 18:30:58 | 000,000,000 | —D | C] – C:\Qoobox
[2010/02/24 17:58:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Donal\.artofillusion
[2010/02/24 17:35:30 | 000,000,000 | —D | C] – C:\Program Files\JMF2.1.1e
[2010/02/24 17:33:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Donal\.SunDownloadManager
[2010/02/24 17:31:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/02/24 17:24:38 | 000,000,000 | —D | C] – C:\Program Files\ArtOfIllusion
[2010/02/24 16:47:32 | 004,296,704 | —- | C] (SYCODE) – C:\WINDOWS\DXLib80Ux64.dll
[2010/02/24 16:47:32 | 002,805,760 | —- | C] (SYCODE) – C:\WINDOWS\DXLib80U.dll
[2010/02/24 16:47:32 | 000,473,600 | —- | C] (SYCODE) – C:\WINDOWS\SYCLicense80Ux64_090901.dll
[2010/02/24 16:47:32 | 000,425,984 | —- | C] (SYCODE) – C:\WINDOWS\SYCLicenseU_090901.dll
[2010/02/24 16:47:32 | 000,278,528 | —- | C] (SYCODE) – C:\WINDOWS\SYCLicense_090901.dll
[2010/02/24 16:47:31 | 003,055,616 | —- | C] (SYCODE) – C:\WINDOWS\DXLib60.dll
[2010/02/24 16:47:31 | 002,826,240 | —- | C] (SYCODE) – C:\WINDOWS\DXLib71.dll
[2010/02/24 16:47:31 | 000,824,320 | —- | C] (SYCODE) – C:\WINDOWS\SYCGUI80Ux64.dll
[2010/02/24 16:47:31 | 000,696,320 | —- | C] (SYCODE) – C:\WINDOWS\SYCGUI80U.dll
[2010/02/24 16:47:31 | 000,532,480 | —- | C] (SYCODE) – C:\WINDOWS\SYCGUI71.dll
[2010/02/24 16:47:30 | 000,532,480 | —- | C] (SYCODE) – C:\WINDOWS\SYCGUI.dll
[2010/02/24 16:47:28 | 000,000,000 | —D | C] – C:\Program Files\SYCODE
[2010/02/24 01:24:02 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/02/24 01:23:21 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/02/23 08:20:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Donal\Desktop\whatthetech
[2010/02/23 07:48:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Donal\Application Data\Malwarebytes
[2010/02/23 07:48:14 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/23 07:48:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/23 07:48:11 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/23 07:48:11 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/23 00:27:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Donal\Desktop\The Audience's Listening
[2010/02/18 20:56:59 | 000,102,400 | —- | C] (Meta Media Inc) – C:\WINDOWS\mmvem.exe
[2009/02/04 23:48:54 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/10/08 01:50:51 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/07/25 20:47:50 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/12/20 20:54:56 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnpstd3.dll
[2007/12/20 20:54:56 | 000,061,440 | —- | C] ( ) – C:\WINDOWS\System32\vsnpstd3.dll
[2007/12/20 20:54:56 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnpstd3.dll
[2007/12/20 20:54:56 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\csnpstd3.dll
[2007/12/20 17:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2007/11/05 20:40:18 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/11/01 12:34:39 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/02/26 01:06:34 | 000,549,888 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donal\Desktop\OTL.exe
[2010/02/26 01:00:04 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/26 00:59:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/26 00:59:56 | 1063,714,816 | -HS- | M] () – C:\hiberfil.sys
[2010/02/26 00:29:26 | 011,796,480 | -H– | M] () – C:\Documents and Settings\Donal\NTUSER.DAT
[2010/02/26 00:29:26 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Donal\ntuser.ini
[2010/02/25 23:30:00 | 000,000,972 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012UA.job
[2010/02/25 23:24:46 | 000,154,321 | —- | M] () – C:\Documents and Settings\Donal\Desktop\tdsskiller.zip
[2010/02/25 23:11:05 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/25 23:10:16 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/02/25 22:42:56 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/02/25 22:41:13 | 056,265,151 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/25 22:40:34 | 003,873,109 | R— | M] () – C:\Documents and Settings\Donal\Desktop\ComboFix.exe
[2010/02/24 18:13:24 | 000,000,339 | —- | M] () – C:\Documents and Settings\Donal\.spmanagerprefs
[2010/02/24 17:35:34 | 000,001,715 | —- | M] () – C:\Documents and Settings\Donal\Desktop\JMStudio.lnk
[2010/02/24 17:25:51 | 000,000,124 | —- | M] () – C:\Documents and Settings\Donal\My Documents\std.out
[2010/02/24 17:09:19 | 000,015,026 | —- | M] () – C:\Documents and Settings\Donal\Desktop\ptfe-insulating-block.dxf
[2010/02/24 04:30:00 | 000,000,920 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012Core.job
[2010/02/24 02:01:28 | 000,589,824 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/02/24 02:01:28 | 000,489,742 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/02/24 02:01:28 | 000,089,776 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/02/24 00:00:08 | 000,000,368 | —- | M] () – C:\WINDOWS\tasks\SyncBack DropBox.job
[2010/02/24 00:00:06 | 000,000,408 | —- | M] () – C:\WINDOWS\tasks\SyncBack Daily Iomega College 4 Sync.job
[2010/02/22 21:39:48 | 000,000,157 | —- | M] () – C:\WINDOWS\matlab.ini
[2010/02/22 21:33:38 | 000,000,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MATLAB 7.1.lnk
[2010/02/21 22:00:06 | 000,000,382 | —- | M] () – C:\WINDOWS\tasks\SyncBack Weekly HD sync.job
[2010/02/21 19:00:04 | 000,000,408 | —- | M] () – C:\WINDOWS\tasks\SyncBack Weekly Images Backup Iomega.job
[2010/02/18 20:56:59 | 000,102,400 | —- | M] (Meta Media Inc) – C:\WINDOWS\mmvem.exe
[2010/02/15 20:27:43 | 000,208,896 | —- | M] () – C:\Documents and Settings\Donal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/14 12:21:13 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/12 02:03:54 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/26 00:59:56 | 1063,714,816 | -HS- | C] () – C:\hiberfil.sys
[2010/02/25 23:24:45 | 000,154,321 | —- | C] () – C:\Documents and Settings\Donal\Desktop\tdsskiller.zip
[2010/02/25 22:42:56 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/02/25 22:42:52 | 000,260,272 | —- | C] () – C:\cmldr
[2010/02/25 18:35:13 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/02/25 18:35:13 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/02/25 18:35:13 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/02/25 18:35:13 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/02/25 18:35:13 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/02/25 18:29:56 | 003,873,109 | R— | C] () – C:\Documents and Settings\Donal\Desktop\ComboFix.exe
[2010/02/24 18:06:39 | 000,000,339 | —- | C] () – C:\Documents and Settings\Donal\.spmanagerprefs
[2010/02/24 17:35:34 | 000,001,715 | —- | C] () – C:\Documents and Settings\Donal\Desktop\JMStudio.lnk
[2010/02/24 17:35:31 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\jsound.dll
[2010/02/24 17:35:31 | 000,380,928 | —- | C] () – C:\WINDOWS\System32\jmmpa.dll
[2010/02/24 17:35:31 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\jmh261.dll
[2010/02/24 17:35:31 | 000,184,320 | —- | C] () – C:\WINDOWS\System32\jmvh263.dll
[2010/02/24 17:35:31 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\jmjpeg.dll
[2010/02/24 17:35:31 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\jmh263enc.dll
[2010/02/24 17:35:31 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\jmg723.dll
[2010/02/24 17:35:31 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\jmmpegv.dll
[2010/02/24 17:35:31 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\jmutil.dll
[2010/02/24 17:35:31 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\jmgsm.dll
[2010/02/24 17:35:31 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\jmam.dll
[2010/02/24 17:35:31 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\jmcvid.dll
[2010/02/24 17:35:31 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\jmacm.dll
[2010/02/24 17:35:31 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\jmvfw.dll
[2010/02/24 17:35:31 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\jmdaud.dll
[2010/02/24 17:35:31 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\jmvcm.dll
[2010/02/24 17:35:31 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\jmgdi.dll
[2010/02/24 17:35:31 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\jmfjawt.dll
[2010/02/24 17:35:31 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\jmddraw.dll
[2010/02/24 17:35:31 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\jmmci.dll
[2010/02/24 17:35:31 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\jmdaudc.dll
[2010/02/24 17:09:17 | 000,015,026 | —- | C] () – C:\Documents and Settings\Donal\Desktop\ptfe-insulating-block.dxf
[2010/02/23 00:33:14 | 000,000,368 | —- | C] () – C:\WINDOWS\tasks\SyncBack DropBox.job
[2010/02/22 21:33:38 | 000,000,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MATLAB 7.1.lnk
[2010/02/03 12:51:26 | 000,000,111 | —- | C] () – C:\WINDOWS\easkdiry.ini
[2010/01/25 19:50:36 | 000,000,311 | —- | C] () – C:\WINDOWS\SWWATER.INI
[2009/10/13 17:28:53 | 000,003,830 | —- | C] () – C:\WINDOWS\Tablet8000x6000.ini
[2009/10/13 17:24:32 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\ucinst32.dll
[2009/04/14 23:15:37 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2008/11/11 23:54:54 | 000,000,157 | —- | C] () – C:\WINDOWS\matlab.ini
[2008/05/21 19:09:30 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2008/01/03 19:45:51 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2007/12/20 20:56:26 | 000,032,345 | —- | C] () – C:\WINDOWS\unvpeye.ini
[2007/12/20 20:55:02 | 000,015,498 | —- | C] () – C:\WINDOWS\snpstd3.ini
[2007/12/12 05:21:22 | 000,000,128 | —- | C] () – C:\Documents and Settings\Donal\Local Settings\Application Data\fusioncache.dat
[2007/11/10 00:41:51 | 000,000,273 | —- | C] () – C:\Documents and Settings\Donal\Local Settings\Application Data\devcpp.cfg
[2007/11/10 00:41:43 | 000,004,411 | —- | C] () – C:\Documents and Settings\Donal\Local Settings\Application Data\devcpp.ini
[2007/11/01 15:14:43 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\SDL_ttf.dll
[2007/11/01 15:14:43 | 000,315,392 | —- | C] () – C:\WINDOWS\System32\SDL_mixer.dll
[2007/11/01 15:14:43 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\SDL.dll
[2007/11/01 15:14:43 | 000,169,443 | —- | C] () – C:\WINDOWS\System32\jpeg.dll
[2007/11/01 15:14:43 | 000,126,976 | —- | C] () – C:\WINDOWS\System32\libpng13.dll
[2007/11/01 15:14:43 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\SDL_gfx.dll
[2007/11/01 15:14:43 | 000,055,808 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/11/01 15:14:43 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SDL_image.dll
[2007/11/01 14:51:26 | 000,208,896 | —- | C] () – C:\Documents and Settings\Donal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/01 14:12:09 | 000,000,520 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/01 12:36:59 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/04/20 11:36:59 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/04/20 11:29:29 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/04/20 11:21:48 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/04/20 10:58:02 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006/04/20 10:57:56 | 000,000,400 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/21 09:37:44 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 12:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 12:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/05/28 01:52:36 | 000,106,496 | —- | C] () – C:\WINDOWS\japi.dll
[2001/06/24 09:32:44 | 000,172,032 | —- | C] () – C:\WINDOWS\japi2.dll

========== LOP Check ==========

[2009/04/18 16:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/11/08 02:03:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/10/20 21:05:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2007/11/01 13:05:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2008/05/01 23:40:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2009/12/26 03:53:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TrueCrypt
[2006/04/20 11:26:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/11/05 21:11:02 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{90F3B5EB-A471-42F9-A905-991C2DB2312C}
[2008/11/05 21:11:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{C39CADE8-EC32-4A3E-ADF3-99FB5B7A317D}
[2008/08/20 00:01:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Ableton
[2008/05/19 15:49:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Arduino
[2009/04/19 04:23:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Autodesk
[2009/10/30 00:36:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Canon
[2010/02/03 12:51:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Clickteam
[2010/02/26 01:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Dropbox
[2010/01/25 17:28:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\gtk-2.0
[2009/02/14 20:59:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Inkscape
[2007/11/12 12:29:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Leadertech
[2008/05/01 23:40:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Propellerhead Software
[2009/04/04 20:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\PTC
[2008/11/24 18:11:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\Template
[2009/12/26 03:59:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\TrueCrypt
[2009/11/16 19:15:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\uTorrent
[2008/05/03 22:29:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Donal\Application Data\WinMX Music
[2010/02/24 00:00:06 | 000,000,408 | —- | M] () – C:\WINDOWS\Tasks\SyncBack Daily Iomega College 4 Sync.job
[2010/02/24 00:00:08 | 000,000,368 | —- | M] () – C:\WINDOWS\Tasks\SyncBack DropBox.job
[2010/02/21 22:00:06 | 000,000,382 | —- | M] () – C:\WINDOWS\Tasks\SyncBack Weekly HD sync.job
[2010/02/21 19:00:04 | 000,000,408 | —- | M] () – C:\WINDOWS\Tasks\SyncBack Weekly Images Backup Iomega.job

========== Purity Check ==========



========== Custom Scans ==========



< MD5 for: NETBT.SYS >
[2004/08/04 04:00:00 | 000,162,816 | —- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B – C:\i386\netbt.sys
[2004/08/04 04:00:00 | 000,162,816 | —- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B – C:\WINDOWS\$NtServicePackUninstall$\netbt.sys
[2008/04/13 19:21:00 | 000,162,816 | —- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D – C:\WINDOWS\ServicePackFiles\i386\netbt.sys
[2008/04/13 19:21:00 | 000,162,816 | —- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D – C:\WINDOWS\system32\drivers\netbt.sys

< %systemroot%\system32\drivers\*.sys /lockedfiles /all >

< %systemroot%\System32\config\*.sav >
[2010/02/26 00:59:29 | 016,777,216 | -HS- | M] () – C:\WINDOWS\system32\config\8monrowg.sav
[2004/08/10 11:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 11:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 11:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >


Extras.Txt:

OTL Extras logfile created on: 26/02/2010 01:13:03 - Run 1
OTL by OldTimer - Version 3.1.30.2 Folder = C:\Documents and Settings\Donal\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 403.00 Mb Available Physical Memory | 40.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.20 Gb Total Space | 41.15 Gb Free Space | 59.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DDKVK32J
Current User Name: Donal
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Digital Photo Professional] – C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 – File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\PharosSystems\Core\CTskMstr.exe" = C:\Program Files\PharosSystems\Core\CTskMstr.exe:*:Enabled:Pharos Com Task Master – (Pharos Systems International)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Java\jre1.6.0_07\bin\java.exe" = C:\Program Files\Java\jre1.6.0_07\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Java\jdk1.6.0_07\bin\java.exe" = C:\Program Files\Java\jdk1.6.0_07\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Java\jdk1.6.0_07\jre\bin\java.exe" = C:\Program Files\Java\jdk1.6.0_07\jre\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – ()
"C:\Program Files\ProENGINEER Schools Edition\i486_nt\nms\nmsd.exe" = C:\Program Files\ProENGINEER Schools Edition\i486_nt\nms\nmsd.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC – (PTC)
"C:\Program Files\ProENGINEER Schools Edition\i486_nt\obj\pro_comm_msg.exe" = C:\Program Files\ProENGINEER Schools Edition\i486_nt\obj\pro_comm_msg.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC – (PTC)
"C:\Program Files\ProENGINEER Schools Edition\i486_nt\obj\xtop.exe" = C:\Program Files\ProENGINEER Schools Edition\i486_nt\obj\xtop.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC – (PTC)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\MD 86149 Notetaker\Easy note taker.exe" = C:\Program Files\MD 86149 Notetaker\Easy note taker.exe:*:Disabled:Mobile note taker – (MEDION)
"C:\Documents and Settings\Donal\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Donal\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – ()
"C:\Program Files\PharosSystems\Core\CTskMstr.exe" = C:\Program Files\PharosSystems\Core\CTskMstr.exe:*:Enabled:Pharos Com Task Master – (Pharos Systems International)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}" = Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{1862162E-3BBC-448F-AA63-49F33152D54A}" = Microsoft Visual Studio 2005 Team Suite - ENU
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1CBE3804-20DF-48DA-B048-895C206E80A5}" = Microsoft SQL Server VSS Writer
"{1F528948-0E80-4C96-B455-DE4167CB1DF7}" = Internal Network Card Power Management
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 18
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java™ SE Development Kit 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4038EAF0-6F8E-4068-88F6-A417958B8AC5}" = PDF Manual NW-E010 Series
"{4442AB48-DEC4-4B39-B067-1F75BF8017E7}" = Creative Centrale
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A19E752-56D4-4B22-BACC-256B491E8756}" = Mobile note taker 3.0
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5783F2D7-5001-0409-0002-0060B0CE6BBA}" = AutoCAD 2007 - English
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{625386A4-B6B6-4911-A6E8-23189C3F2D15}" = Microsoft .NET Compact Framework 2.0
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6C531060-84FB-4F96-8F33-29DF020632EB}" = Microsoft .NET Compact Framework 1.0 SP3 Developer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{78B75C6D-E53C-424C-BF83-4B63BD4A6682}" = Microsoft Device Emulator version 1.0 - ENU
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C03FBE-4492-4133-BBAB-421CD88ADA32}" = OpenOffice.org 2.3
"{86604C06-DA30-425E-AECE-47304FE81C45}" = Creative Software Update
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}" = Dell Media Experience
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{BBC783B7-8725-3B1C-B49A-BA7F09391251}" = Google Talk Plugin
"{BF251EAF-8697-4E89-BF09-C998F97BBC40}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41F4616-44B6-4E8D-BFC7-4267862A2CE1}" = CinepPlayer 30 Update
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD49361E-3FE6-457E-90A1-9C59E29B5D02}" = Java DB 10.3.1.4
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera Plus
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"Ableton Live_is1" = Ableton Live v7.0.1
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Alarm Clock_is1" = Alarm Clock v1.0
"Analogy" = Analogy Screen Saver
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"AVG9Uninstall" = AVG Free 9.0
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative Centrale" = Creative Centrale
"Creative Removable Disk Manager" = Creative Removable Disk Manager
"CutePDF Writer Installation" = CutePDF Writer 2.7
"DellSupport" = Dell Support 5.0.0 (630)
"DPP" = Canon Utilities Digital Photo Professional 3.7
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Inkscape" = Inkscape 0.46
"Java Media Framework 2.1.1e" = Java Media Framework 2.1.1e
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MatlabR14SP3" = MATLAB 7.1
"MediaMonkey_is1" = MediaMonkey 3.0
"Mendeley Desktop" = Mendeley Desktop 0.9.5.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Team Suite - ENU" = Microsoft Visual Studio 2005 Team Suite - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Microsoft Visual Studio 2005 Tools for Office Runtime
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"nbi-glassfish-[removed].20080515" = GlassFish V2 UR2
"nbi-nb-base-[removed].200805300101" = NetBeans IDE 6.1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"pd_is1" = Pd-0.39.3-extended
"Pharos" = Pharos
"Picasa 3" = Picasa 3
"PowerISO" = PowerISO
"Pro/ENGINEER Schools Edition Release Wildfire 4.0 Datecode M030" = Pro/ENGINEER Schools Edition Release Wildfire 4.0 Datecode M030
"ProInst" = Intel® PROSet/Wireless Software
"Protege 3.3.1" = Protege 3.3.1
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"Scribus [removed]" = Scribus [removed]
"ShockwaveFlash" = Macromedia Flash Player 8
"STL Import for Pro ENGINEER_is1" = STL Import for Pro ENGINEER
"SyncBack_is1" = SyncBack
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TrueCrypt" = TrueCrypt
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.4.5
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 25/02/2010 12:43:08 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 12:44:09 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 13:21:53 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 13:22:54 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 16:05:20 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 16:06:22 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 18:37:03 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 18:38:05 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 18:56:24 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

Error - 25/02/2010 18:57:26 | Computer Name = DDKVK32J | Source = matlabserver | ID = 0
Description =

[ System Events ]
Error - 25/02/2010 20:32:41 | Computer Name = DDKVK32J | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 25/02/2010 20:32:42 | Computer Name = DDKVK32J | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 25/02/2010 20:33:10 | Computer Name = DDKVK32J | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31

Error - 25/02/2010 20:33:10 | Computer Name = DDKVK32J | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31

Error - 25/02/2010 20:33:10 | Computer Name = DDKVK32J | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31

Error - 25/02/2010 20:33:10 | Computer Name = DDKVK32J | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 25/02/2010 20:33:10 | Computer Name = DDKVK32J | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD APPDRV AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SCDEmu
Tcpip
truecrypt

Error - 25/02/2010 20:52:05 | Computer Name = DDKVK32J | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 25/02/2010 20:53:25 | Computer Name = DDKVK32J | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 25/02/2010 21:00:10 | Computer Name = DDKVK32J | Source = Service Control Manager | ID = 7000
Description = The adfs service failed to start due to the following error: %%2


< End of report >
Run from C:\Documents and Settings\Donal\My Documents\Downloads\maxhandle.exe on 26/02/2010 at 10:47:49.50

System pid: 4 16D0: C:\WINDOWS\system32\config\8monrowg.sav
lsass.exe pid: 1036 518: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 1304 990: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 1596 12C: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 1728 210: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
spoolsv.exe pid: 340 140: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
jqs.exe pid: 720 EC: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
sqlservr.exe pid: 1412 64: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
CTskMstr.exe pid: 1976 244: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
alg.exe pid: 3416 7C: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
Dropbox.exe pid: 2192 1F4: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
firefox.exe pid: 168 1CC: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
Hi,

Please do the following:

Go to Start > Run > type in cmd to open a command window:


Then copy / paste the following into the open command window

copy C:\WINDOWS\system32\drivers\netbt.sys c:\windows\system32\dllcache
copy /y c:\windows\system32\dllcache\netbt.sys C:\WINDOWS\system32\drivers


Now reboot your machine and re run the maxhandle program and post the resulting log
Run from C:\Documents and Settings\Donal\My Documents\Downloads\maxhandle.exe on 26/02/2010 at 13:33:20.79

System pid: 4 1614: C:\WINDOWS\system32\config\8monrowg.sav
lsass.exe pid: 1048 58C: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 1432 240: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 1940 124: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
svchost.exe pid: 400 20C: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
spoolsv.exe pid: 636 140: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
jqs.exe pid: 1912 EC: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
matlabserver.exe pid: 2136 98: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
sqlservr.exe pid: 2436 68: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
CTskMstr.exe pid: 2808 23C: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
Dropbox.exe pid: 3908 1F4: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86
alg.exe pid: 4008 98: \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074\L\max++.00.x86

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI