This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Worm.Win32.Netsky

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

When I start my desktop PC I'm getting a popup box titled "Spyware Alert" and it says:
Security Warning! Worm.Win32.Netsky has been detected on your machine.
The virus is distributed via the Internet through emails and Active-X objects.
The virus has its own SMTP engineThe worm has its own smtp engine which means it gathers emails from your local computer and re-distributes itself.
In worst cases this worm can allow attachers to access your computer, stealing passwords and personal data.
Viruses can damage your confidential data and work on your computer.
Continue working in unprotected mode is very dangerous."
Type: Virus
System Affected: Windows 2000, NT, ME, XP, Vista, 7
Security Risk (0-5): 5
Recommendations: It is necessary to perform a full system scan.


There' an "OK" button at the bottom of the popup, but I just close it with the 'X' button. My wallpaper is now green, with a black box in the middle saying:
YOUR SYSTEM IS INFECTED!
System has been stopped due to a serious malfunction. Spyware activity has been detected.
It is recommended to use spyware removal tool to prevent data loss. Do not use the computer before all spyware is removed.


My McAfee Security Center/Anti-virus program won't open, it gives me an error message saying the system is infected and that I must perform a full scan. I can't open or run most programs on my machine, and the system keeps freezing up and becomes unresponsive within a few minutes of booting. I have trouble trying to connect to the Internet, so I unplugged the connection from my PC to avoid the virus from communicating. I'm posting this thread from my roommate's PC. I booted in Safe Mode and went through all the steps in your "Are You Infected" guide (by bringing the recommended programs over with a flash drive) but I was unable to run many of those programs. ATF Cleaner seemed to run okay but I wasn't able to create or access a System Restore point. I think ERUNT ran okay, but MBAM did not. I don't think GMER ran either but I think Defogger did (sorry, it's been over a week since I tried running all these and I didn't take very good notes). DDS didn't run either. I read previous threads with very similar symptoms and I noticed that many others posted HiJackThis log files, let me know if I should do the same. This is all way over my head so I'm completely lost on what to do next. Any help is very appreciated!!
Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I will post back shortly with instructions.
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


Since you've been transfering files from one pc to the infected one, it might be possible that the other pc will also be infected.
Let's do the following to try to minimize the possibility of infecting the other machine:

Do this on the clean computer.
Download Flash_Disinfector.exe by sUBs from HERE and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

–Next–

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

–Next–

OTL:
  • Download OTL to your desktop.
  • If the above download link doesn't work, then try downloading here.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
–Next–

Let's try GMER again:
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


To post in your next reply:
1. exeHelper log.
2. OTL logs.
3. GMER log.
Thanks for the reply! I just have a quick question - should I boot my (infected) PC in Safe Mode to install and run these programs? Or should I boot up like normal? If I should boot in Safe Mode, should I login as Admin, or does it matter?
Hi, Try logging in Normal windows first, download the tools then have them run, if this fails, you can try running the tools in safe mode with your usual account.
I was able to run all three programs in Safe Mode. Below are the contents of the log files you asked for (I'll split them between two posts). Also, I noticed the OTL log catalogs changes in the last 30 days, so I want to mention that it's probably been over 30 days since I first got this infection.

exehelper.log
exeHelper by Raktor
Build 20091220
Run at 21:24:42 on 03/03/10
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Error deleting C:\WINDOWS\system32\41.exe - Set for removal on reboot - PLEASE REBOOT
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

exeHelper by Raktor
Build 20091220
Run at 21:30:57 on 03/03/10
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Error deleting C:\WINDOWS\system32\41.exe - Set for removal on reboot - PLEASE REBOOT
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

OTL.txt
OTL logfile created on: 3/3/2010 9:34:58 PM - Run 1
OTL by OldTimer - Version 3.1.32.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 790.00 Mb Available Physical Memory | 77.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.31 Gb Total Space | 5.20 Gb Free Space | 3.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 7.45 Gb Total Space | 4.37 Gb Free Space | 58.56% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHAWN
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\SYSTEM32\smss32.exe (FiQupUKHYV)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (MSK80Service) – C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (LBTServ) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (STCAgent) – C:\Program Files\Cisco Systems\SSL VPN Client\Agent.exe (Cisco Systems, Inc.)
SRV - (AutoSyncService) – C:\Program Files\Memeo\AutoSync\MemeoService.exe (Memeo)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ATI Smart) – C:\WINDOWS\SYSTEM32\ati2sgag.exe ()
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (dlbx_device) – C:\WINDOWS\System32\dlbxcoms.exe (Dell)
SRV - (IAANTMon) – C:\Program Files\Intel\Intel Application Accelerator\IAANTmon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (vpnva) – C:\WINDOWS\SYSTEM32\DRIVERS\vpnva.sys (Cisco Systems, Inc.)
DRV - (mfehidk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (MPFP) – C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys (McAfee, Inc.)
DRV - (USBAAPL) – C:\WINDOWS\SYSTEM32\DRIVERS\usbaapl.sys (Apple, Inc.)
DRV - (GEARAspiWDM) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (AnyDVD) – C:\WINDOWS\SYSTEM32\DRIVERS\AnyDVD.sys (SlySoft, Inc.)
DRV - (ElbyCDIO) – C:\WINDOWS\SYSTEM32\DRIVERS\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (Pcouffin) – C:\WINDOWS\SYSTEM32\DRIVERS\pcouffin.sys (VSO Software)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (LMouFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (Secdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (CSVirtA) – C:\WINDOWS\SYSTEM32\DRIVERS\CSVirtA.sys (Cisco Systems, Inc.)
DRV - (RTL8187B) – C:\WINDOWS\SYSTEM32\DRIVERS\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ASCTRM) – C:\WINDOWS\SYSTEM32\DRIVERS\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (WmFilter) – C:\WINDOWS\SYSTEM32\DRIVERS\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\WINDOWS\SYSTEM32\DRIVERS\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\SYSTEM32\DRIVERS\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore) – C:\WINDOWS\SYSTEM32\DRIVERS\WmXlCore.sys (Logitech Inc.)
DRV - (smwdm) – C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys (Analog Devices, Inc.)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (senfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Creative Technology Ltd.)
DRV - (Ptilink) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (b57w2k) – C:\WINDOWS\SYSTEM32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (IntelC52) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (CDRPDACC) – C:\Program Files\321Studios\Shared\CDRPDACC.SYS (Arrowkey)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (SjyPkt) – C:\WINDOWS\SYSTEM32\DRIVERS\SjyPkt.sys (Windows ® 2000 DDK provider)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B) Intel® – C:\WINDOWS\SYSTEM32\DRIVERS\E100B325.SYS (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKCU\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/03/03 20:45:48 | 000,000,000 | —D | M]


O1 HOSTS File: ([2004/08/10 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DLBXCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBXtime.DLL ()
O4 - HKLM..\Run: [dlbxmon.exe] C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe (Dell)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [smss32.exe] C:\WINDOWS\SYSTEM32\smss32.exe (FiQupUKHYV)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\helper32.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\helper32.dll ()
O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} https://ra.hntb.com/CACHE/stc/1/binaries/stcweb.cab (STCWeb Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} https://ra.hntb.com/CACHE/stc/1/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {705EC6D4-B138-4079-A307-EF13E4889A82} https://ra.hntb.com/CACHE/sdesktop/install/…ies/instweb.cab (CSD ActiveX Installer)
O16 - DPF: {8494B5D2-DA6A-4BB8-9C15-6C18A312387E} https://ra.hntb.com/ui/Axt.cab (Caymas Secure Tunnel)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} https://ra.hntb.com/pdl/jt/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} file://E:\Ulead\setup.exe (InstallShield Setup Player 2K2)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab (DwnldGroupMgr Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\WINDOWS\DELL.BMP
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/19 15:07:14 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/03/01 23:50:02 | 000,000,000 | RHSD | M] - F:\autorun.inf – [ FAT32 ]
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/03 21:34:19 | 000,551,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/03/03 20:46:28 | 000,000,000 | —D | C] – C:\e9ac9bb30eb789cb19d6
[2010/03/03 20:45:08 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/02/16 00:35:53 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/16 00:35:51 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/16 00:35:51 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/16 00:35:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/16 00:34:27 | 005,115,840 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\ak8e4.exe.exe
[2010/02/16 00:29:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2010/02/16 00:28:02 | 005,115,840 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\aKlime84Ik.exe
[2010/02/16 00:05:44 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/02/16 00:05:25 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/02/16 00:03:53 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Administrator\Desktop\erunt_setup.exe
[2010/02/16 00:00:59 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Administrator\Desktop\SysRestorePoint.exe
[2010/02/15 23:39:36 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Administrator\Desktop\ATF-Cleaner.exe
[2010/02/15 23:31:50 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/01/17 17:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore
[2008/09/02 02:10:55 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/04/28 19:12:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/02/10 14:54:06 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2007/02/10 14:54:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2007/02/10 14:54:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Google
[2005/10/20 16:05:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\LocalService\Application Data\GTek
[2005/05/26 19:45:42 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2005/05/26 19:45:42 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2005/05/26 19:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[1979/12/31 23:00:00 | 000,151,552 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/03/03 21:34:24 | 001,048,576 | -H– | M] () – C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/03/03 21:18:09 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\IS15.exe
[2010/03/03 21:18:09 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\41.exe
[2010/03/03 21:18:05 | 000,002,931 | —- | M] () – C:\WINDOWS\System32\warning.html
[2010/03/03 21:17:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/03/03 20:46:20 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/03/03 20:40:31 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/03 20:40:29 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/02 00:04:18 | 000,551,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/03/02 00:04:06 | 000,290,816 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\exeHelper.com
[2010/02/28 18:38:49 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\NTUSER.INI
[2010/02/28 18:36:19 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\15724.exe
[2010/02/28 18:16:19 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\19169.exe
[2010/02/28 17:56:19 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\26500.exe
[2010/02/28 17:36:19 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\6334.exe
[2010/02/28 17:16:19 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\18467.exe
[2010/02/24 00:36:48 | 000,007,680 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/16 00:05:26 | 000,000,611 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2010/02/16 00:05:26 | 000,000,592 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2010/02/15 23:35:45 | 000,000,000 | —- | M] () – C:\Documents and Settings\Administrator\defogger_reenable
[2010/02/07 15:36:36 | 000,293,376 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\hmtfewe3.exe
[2010/02/07 15:33:16 | 005,115,840 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\aKlime84Ik.exe
[2010/02/07 15:33:16 | 005,115,840 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\ak8e4.exe.exe
[2010/02/07 15:26:32 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Administrator\Desktop\erunt_setup.exe
[2010/02/07 15:16:20 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Administrator\Desktop\SysRestorePoint.exe
[2010/02/07 15:08:48 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Administrator\Desktop\ATF-Cleaner.exe
[2010/02/07 14:31:22 | 000,050,477 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Defogger.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/03 21:24:29 | 000,290,816 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\exeHelper.com
[2010/02/16 00:33:50 | 000,293,376 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\hmtfewe3.exe
[2010/02/16 00:05:26 | 000,000,611 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2010/02/16 00:05:26 | 000,000,592 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2010/02/15 23:35:45 | 000,000,000 | —- | C] () – C:\Documents and Settings\Administrator\defogger_reenable
[2010/02/15 23:34:23 | 000,050,477 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Defogger.exe
[2010/01/28 07:51:42 | 000,007,680 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/24 17:35:00 | 000,018,432 | —- | C] () – C:\WINDOWS\System32\helper32.dll
[2010/01/24 15:49:59 | 000,000,008 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/10/23 20:10:56 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/10/23 20:10:54 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/11/05 09:10:39 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2006/05/06 22:10:01 | 000,001,362 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/19 22:11:30 | 000,001,209 | —- | C] () – C:\WINDOWS\dellstat.ini
[2006/02/18 17:03:29 | 000,000,416 | —- | C] () – C:\WINDOWS\IfoEdit.INI
[2006/02/08 19:57:49 | 000,000,087 | —- | C] () – C:\WINDOWS\dswplug.ini
[2006/02/08 19:57:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\mplaw7.dll
[2006/02/08 19:57:41 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\mplaa6.dll
[2006/02/08 19:57:41 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\mplam6.dll
[2006/02/08 19:57:41 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2005/07/23 14:58:11 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/06/17 20:38:11 | 000,006,173 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/06/12 11:04:51 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/06/12 10:36:20 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/05/26 20:27:09 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/05/26 20:23:43 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/05/26 19:48:18 | 000,000,367 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/01/20 03:56:00 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\dlbxinsr.dll
[2005/01/20 03:55:48 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\dlbxcur.dll
[2005/01/20 03:55:24 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\dlbxjswr.dll
[2005/01/20 03:54:40 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlbxinsb.dll
[2005/01/20 03:54:28 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\dlbxcub.dll
[2005/01/20 03:54:18 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\dlbxins.dll
[2005/01/20 03:53:44 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dlbxcu.dll
[2005/01/20 03:46:32 | 000,397,312 | —- | C] () – C:\WINDOWS\System32\dlbxutil.dll
[2004/09/15 21:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/19 15:22:58 | 000,000,791 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/19 15:16:26 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2004/08/10 04:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/03/30 15:45:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbxvs.dll
[2003/04/08 19:39:56 | 000,021,504 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2008/07/14 17:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Anvsoft
[2006/03/19 22:13:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/03/11 21:32:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco
[2008/08/22 20:07:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2006/01/21 17:38:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MCA1E8.tmp
[2008/04/27 04:22:47 | 000,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Memeo
[2008/09/08 15:57:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2008/11/05 09:12:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2006/02/08 19:58:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2008/08/22 16:02:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/07/14 17:29:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/02/08 20:11:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/04/20 16:05:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/08/20 22:31:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/02/15 19:54:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{A695AD8D-651B-4C8A-91DF-51F853449A57}
[2010/01/15 01:12:01 | 000,000,364 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2010/01/01 01:20:00 | 000,000,366 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 24 bytes -> C:\WINDOWS:842DBFFCDA80B78D
< End of report >
Extras.txt
OTL Extras logfile created on: 3/3/2010 9:34:58 PM - Run 1
OTL by OldTimer - Version 3.1.32.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 790.00 Mb Available Physical Memory | 77.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.31 Gb Total Space | 5.20 Gb Free Space | 3.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 7.45 Gb Total Space | 4.37 Gb Free Space | 58.56% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHAWN
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Disabled:AOL – File not found
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\STC\QA_07_05\wwwroot\cbt.exe" = C:\Program Files\STC\QA_07_05\wwwroot\cbt.exe:*:Enabled:Local Web Server – File not found
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC – File not found
"C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe" = C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe:*:Enabled:BF1942 – File not found
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Disabled:Steam – File not found
"C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" = C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE:*:Enabled:Microsoft Office Word – (Microsoft Corporation)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03A26689-82BB-6FF9-1FDA-93B18547C8C8}" = Catalyst Control Center Graphics Full New
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{127B684B-A002-44C8-99A7-6CF8F1E26873}" = PunkBuster for Battlefield 1942
"{14374619-0900-4056-BA06-C87C900AF9E6}" = QuickBooks Simple Start Special Edition
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD
"{21BC2871-0B96-9EC1-6CBF-A0B9BCBC0D89}" = Skins
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 13
"{2A6355EB-273D-4368-9DB6-FB99EBA9FABD}" = Cisco AnyConnect VPN Client
"{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{31E1050B-F69F-4A16-8F5A-E44D31901250}" = Ulead DVD DiskRecorder 2.1.1
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150080}" = J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3CBBEE47-C8F4-316A-92FF-ED7E3DFAE41E}" = ccc-core-static
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{410DB4DE-354D-F472-F66D-FCFF345A8960}" = Catalyst Control Center Graphics Previews Common
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}" = Jasc Paint Shop Photo Album 5
"{48EE6C79-1CE2-4CE8-B511-F2140B6781D6}" = Google Earth Pro
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{55937F00-A69B-4049-8D3A-1C7729742B6F}" = BUM
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5BF2B19D-9C79-492A-8969-F059F06A627F}" = Print to Fax
"{5C1DA723-24FC-48AD-93BA-925695C3EF26}" = Logitech Gaming Software
"{5F49D1B0-D558-F251-715E-A46CD0A30FED}" = ccc-utility
"{61BA2A5B-881D-EEF7-F5D2-5EFAF7CCBDA9}" = Catalyst Control Center Graphics Light
"{625BD732-ACDF-4552-BF22-98EBB413B6F3}" = McAfee Shredder
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{651E5E05-3416-E761-B919-37EF1F4272F9}" = Catalyst Control Center Core Implementation
"{6774F0CF-C7DD-4CB4-BCB2-11C3E08BBA03}" = McAfee Shredder
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{6BCEB97B-F315-455D-BC2D-565A1A6781E8}" = Memeo AutoBackup
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7191C910-3F72-B2CA-0FA5-F0E78F5F8FD2}" = CCC Help English
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}" = Jasc Paint Shop Pro Studio, Dell Editon
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{88F92798-59AB-474F-B40D-1EC5F782F7EE}" = Ulead VideoStudio 9.0
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Application Accelerator
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6E71574-2126-4E95-816E-32B2411C94BA}" = Ulead MediaStudio Pro 8.0
"{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}" = SimCity 4 Deluxe
"{AC0C7D59-DE76-4AC0-9A84-A3B4D315CE11}" = ArcSoft Media Card Companion
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.0
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint Plus
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B73B4A99-4173-4747-BBEC-0F05E966F9D2}" = Battlefield 1942: Secret Weapons of WWII
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C43421C0-0DCB-4F26-8A3B-BF16155F9879}" = TRENDnet TEW-424UB Wireless USB 2.0 Adapter Driver and Utility
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}" = Battlefield 1942: The Road To Rome
"{D87149B3-7A1D-4548-9CBF-032B791E5908}" = Desktop Doctor
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{EC33A4E0-A500-D4A2-C1F8-DCA04496B053}" = Catalyst Control Center Graphics Full Existing
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{FECA6067-869C-4F32-9F6E-574E1496CE44}" = Memeo AutoSync
"1Click DVD Copy 4.1" = 1Click DVD Copy 4.1
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"AnyDVD" = AnyDVD
"ATI Display Driver" = ATI Display Driver
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"Cisco Systems SSL VPN Client" = Cisco SSL VPN Client
"ComcastHSI" = Comcast High-Speed Internet Install Wizard
"CopyToDVD_is1" = CopyToDVD
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Photo AIO Printer 962" = Dell Photo AIO Printer 962
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"DVD X Rescue" = DVD X Rescue
"DVDFab Decrypter_is1" = DVDFab Decrypter 3.0.4.0
"DVDXCopyPlatinum" = DVD X Copy Platinum 4.0.3
"ffdshow" = ffdshow (remove only)
"GuitarScalesMethod_is1" = GSM [removed]
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{C43421C0-0DCB-4F26-8A3B-BF16155F9879}" = TRENDnet TEW-424UB Wireless USB 2.0 Adapter Driver and Utility
"InstallShield_{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"IsoBuster_is1" = IsoBuster 1.9.1
"Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch" = Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"MSC" = McAfee SecurityCenter
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"Picasa2" = Picasa 2
"PlayFLV" = PlayFLV
"RealPlayer 6.0" = RealPlayer Basic
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Super DVD Creator_is1" = Super DVD Creator 5.0
"TurboTax Premier 2005" = TurboTax Premier 2005
"Virtools3DLifePlayer" = Virtools 3D Life Player
"VSO DivxToDVD_is1" = DivxToDVD 0.5.2b
"VSO PhotoDVD_is1" = PhotoDVD 2.3.10
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/26/2010 7:46:22 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/1/2010 10:58:08 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/1/2010 11:23:23 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/1/2010 11:27:41 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/2/2010 1:46:19 AM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/4/2010 9:44:45 AM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/8/2010 8:44:23 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/20/2010 1:58:21 AM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/28/2010 6:27:06 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 3/3/2010 10:40:31 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

[ Application Events ]
Error - 1/26/2010 7:46:22 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/1/2010 10:58:08 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/1/2010 11:23:23 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/1/2010 11:27:41 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/2/2010 1:46:19 AM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/4/2010 9:44:45 AM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/8/2010 8:44:23 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/20/2010 1:58:21 AM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 2/28/2010 6:27:06 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 3/3/2010 10:40:31 PM | Computer Name = SHAWN | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

[ System Events ]
Error - 3/3/2010 11:19:16 PM | Computer Name = SHAWN | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 3/3/2010 11:19:16 PM | Computer Name = SHAWN | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD ElbyCDIO Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL

Error - 3/3/2010 11:24:17 PM | Computer Name = SHAWN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 3/3/2010 11:24:55 PM | Computer Name = SHAWN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 3/3/2010 11:24:55 PM | Computer Name = SHAWN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 3/3/2010 11:30:08 PM | Computer Name = SHAWN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 3/3/2010 11:31:10 PM | Computer Name = SHAWN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 3/3/2010 11:31:10 PM | Computer Name = SHAWN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 3/3/2010 11:31:51 PM | Computer Name = SHAWN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 3/3/2010 11:34:24 PM | Computer Name = SHAWN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}


< End of report >


GMER.txt
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-04 08:49:52
Windows 5.1.2600 Service Pack 3
Running: hmtfewe3.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\axtdypob.sys


—- System - GMER 1.0.15 —-

Code 86CC4948 ZwEnumerateKey
Code 86CC4910 ZwFlushInstructionCache
Code 86CC497E IofCallDriver
Code 86CFB4E6 IofCompleteRequest

—- Modules - GMER 1.0.15 —-

Module \systemroot\system32\drivers\H8SRTvviilsogqv.sys (*** hidden *** ) F72B0000-F72CC000 (114688 bytes)
—- Processes - GMER 1.0.15 —-

Library \\?\globalroot\systemroot\system32\H8SRTocpcieyagf.dll (*** hidden *** ) @ C:\WINDOWS\system32\winlogon.exe [252] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTocpcieyagf.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [580] 0x00870000
Library \\?\globalroot\systemroot\system32\H8SRTocpcieyagf.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [648] 0x00870000
Library \\?\globalroot\systemroot\system32\H8SRTocpcieyagf.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\iexplore.exe [1132] 0x00E70000

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\drivers\H8SRTvviilsogqv.sys (*** hidden *** ) [SYSTEM] H8SRTd.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTvviilsogqv.sys
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTvviilsogqv.sys
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTuuxskeyiui.dll
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTpvuyhrmoch.dat
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTgqrxvyimqn.dll
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@h8srtmsg \\?\globalroot\systemroot\system32\H8SRTocpcieyagf.dll
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@h8srtbbr \\?\globalroot\systemroot\system32\H8SRTdkocqwkvvg.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTvviilsogqv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTvviilsogqv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTuuxskeyiui.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTpvuyhrmoch.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTgqrxvyimqn.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@h8srtmsg \\?\globalroot\systemroot\system32\H8SRTocpcieyagf.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@h8srtbbr \\?\globalroot\systemroot\system32\H8SRTdkocqwkvvg.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTvviilsogqv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTvviilsogqv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTuuxskeyiui.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTpvuyhrmoch.dat
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTgqrxvyimqn.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtmsg \\?\globalroot\systemroot\system32\H8SRTocpcieyagf.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtbbr \\?\globalroot\systemroot\system32\H8SRTdkocqwkvvg.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\InprocServer32@ C:\WINDOWS\system32\wmpdxm.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\ProgID@ AMOVIE.ActiveMovieControl.2
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\TypeLib@ {05589fa0-c356-11ce-bf01-00aa0055595a}
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\Version@ 2.0
Reg HKLM\SOFTWARE\Classes\CLSID\{31E3FC97-DFA6-BD2D-E982-A7B9DBD87050}\VersionIndependentProgID@ AMOVIE.ActiveMovieControl
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\InprocServer32@ C:\WINDOWS\system32\THREED32.OCX
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\InprocServer32@InprocServer32 9~EowM9KA?EODmlI}'28Components_WINSYSDIR>`}1*n6d]T9]Ts8?N7]I`?
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\ProgID@ Threed.SSCheck
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\ToolboxBitmap32@ D:\qb336\SRC11~1.MSI\CD\CORECO~2\THREED32.OCX, 1
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\TypeLib@ {0BA686C6-F7D3-101A-993E-0000C0EF6F5E}
Reg HKLM\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\Version@ 1.0

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\All Users\Application Data\h8srtkrl32mainweq.dll 1523 bytes
File C:\Documents and Settings\All Users\Application Data\h8srtmainqt.dll 10734 bytes
File C:\Documents and Settings\SHAWN MURPHY\Local Settings\Temp\H8SRT3bfc.tmp 343040 bytes executable
File C:\WINDOWS\SYSTEM32\DRIVERS\H8SRTvviilsogqv.sys 39936 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\SYSTEM32\16827.exe 0 bytes
File C:\WINDOWS\SYSTEM32\H8SRTdkocqwkvvg.dll 40960 bytes executable
File C:\WINDOWS\SYSTEM32\H8SRTgqrxvyimqn.dll 40960 bytes executable
File C:\WINDOWS\SYSTEM32\H8SRTocpcieyagf.dll 16896 bytes executable
File C:\WINDOWS\SYSTEM32\H8SRTpvuyhrmoch.dat 175 bytes
File C:\WINDOWS\SYSTEM32\h8srtshsyst.dll 2096 bytes
File C:\WINDOWS\SYSTEM32\H8SRTuuxskeyiui.dll 23040 bytes executable

—- EOF - GMER 1.0.15 —-
Hi,

Your log shows signs of a trojan infection. The capabilities of this particular trojan include keylogging and password stealing so I advise you to take all precautions to safeguard your accounts, passwords, and sensitive data. If you have entered any credit card details or use your computer for financial/banking transactions, you should notify your banks and financial institutions that you may have been a victim of identity theft and to put a watch on your accounts. For more information, please read How to report ID theft, fraud, drive-by installs, hijacking and malware. I also recommend that you change your online passwords for email, banks, etc., immediately – from a clean computer. It bears repeating to change passwords from a clean computer only.

Many experts believe that once a computer has been infected with this type of Trojan, it is best to reformat and reinstall the Operating System. The reason is that even after cleaning, there may be some remnants left in the system. It is hard to discern how much damage has been done. Only you can decide whether it would be best to reformat and start over. We can proceed with the cleanup process if you prefer. If you decide to reformat, be sure save your important data to backup media but make sure that you scan it all before you put it back on a clean system. Please read the following: When should I re-format? How should I reinstall?

If you wish to continue with the clean up, please proceed with the following:

Are you familiar with these files, please don't open them if you are not familiar with these files, have you downloaded Malwarebytes with a random name or have you renamed the installation file after downloading?
C:\Documents and Settings\Administrator\Desktop\ak8e4.exe.exe
C:\Documents and Settings\Administrator\Desktop\aKlime84Ik.exe


–Next–

You have BitTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/d/security-centra…-p-id-theft-103

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall BitTorrent, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx

–Next–

Download Combofix from any of the links below. You must rename it before saving it. Save it as SubsFix.exe

* IMPORTANT !!! Save SubsFix.exe to your Desktop

Link 1
Link 2

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

–Next–

  • Open OTL.exe.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under File Scans -> File Age:, click on the drop down arrow then select 90 days.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • There will only be a single log produced. OTL.Txt.
    Note:This log can be located in the OTL. folder on you C:\ drive if it fails to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
To post in your next reply:
1. About the files mentioned above.
2. Combofix log.
3. OTL log.
Hi, It's been several days. Do you still need help on this? This thread will be closed if you don't respond within 24 hours.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI