This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE8 web browser keeps redirecting me

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, Please help….

When I search a topic & then click any of the links my web browser redirects me to a random site or another search site.
It has now become VERY frustrating!!!

At present I have done the following:

Checked my drives for adware/ spyware etc & deleted anything that has been found (aparently all is good - I also did this in safe mode).

Uninstalled & re-installed IE8.

Increased my level of security on my internet browser.

Downloaded CWShedder - Nothing!

FINALLY, as nothing seems to have worked, I have downloaded Hijackthis & here is the log results of the search:

Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\ProgramData\DatacardService\DataCardMonitor.exe
C:\Program Files\Dell Photo AIO Printer 922\DLBTmon.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\Google Media Server\GoogleMediaScanner.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apvfb.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.designhousestockholm.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\mseigu32.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlbtmon.exe] "C:\Program Files\Dell Photo AIO Printer 922\dlbtmon.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [none] c:\AUTOEXEC.BAT
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Media Scanner] "C:\Program Files\Google\Google Media Server\GoogleMediaScanner.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [cbssreg] C:\Windows\TEMP\iyfc.tmp\svchost.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [cbssreg] C:\Windows\TEMP\iyfc.tmp\svchost.exe (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{920DE905-0E5C-4DCA-98A9-09D9356A7BD7}: NameServer = 93.188.164.228,93.188.161.46
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.164.228,93.188.161.46
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.228,93.188.161.46
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: AVGRSSTX.DLL C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DCSHost.exe - Unknown owner - C:\ProgramData\DatacardService\DCSHost.exe
O23 - Service: dlbt_device - - C:\Windows\system32\dlbtcoms.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google MediaServer - Google Inc. - C:\Program Files\Google\Google Media Server\GoogleMediaServer.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RtkHDMIService - Realtek Semiconductor - C:\Windows\RtkAudioService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
–
End of file - 12537 bytes

Can anyone advise me if I should delete any of the above/ what to do if all this looks normal?!

Many thanks,
Marm.
Hello Marm and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
Thank you RPMcMurphy……. Sorry in advance - Just to keep you up to date; I have already downloaded & ran the following since my first post & before seeing your reply ( I hope this has not affected anything further?): ATF-Cleaner MBAM GMER Rootkit Patiently awaiting your instructions! Thanks again, Marm.
Marm,

That's fine, just post the GMER and MBAM logs for me along with these:

🖼Click to load external image (Posted Image) Please run HijackThis and follow these instructions:
  • Click the Do a system scan only button to produce a log.
  • Place a check mark beside each one of the following items if they are present:
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\mseigu32.exe,

O4 - HKLM\..\Run: [none] c:\AUTOEXEC.BAT
O4 - HKUS\S-1-5-18\..\Run: [cbssreg] C:\Windows\TEMP\iyfc.tmp\svchost.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [cbssreg] C:\Windows\TEMP\iyfc.tmp\svchost.exe (User 'Default user')

O17 - HKLM\System\CCS\Services\Tcpip\..\{920DE905-0E5C-4DCA-98A9-09D9356A7BD7}: NameServer = 93.188.164.228,93.188.161.46
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.164.228,93.188.161.46
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.228,93.188.161.46
  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the Fix checked button.
  • Close the HijackThis window.
🖼Click to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    ipconfig /flushdns /c
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time.
Please include the following in your next post:
  • OTL and OTL Extras logs
  • MBAM log
  • GMER log
Hi,

After runing HijackThis, only the following item needed to be fixed:

F2 - REG:system.ini: Userinit=C:\Windows\system32\userinit.exe,C:\Windows\system32\mseigu32.exe,

Here are the logs that you have requested:


OTL logfile created on: 15/03/2010 00:24:53 - Run 1
OTL by OldTimer - Version 3.1.37.1 Folder = C:\Users\Adam\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.65 Gb Total Space | 170.17 Gb Free Space | 76.43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SOFIE-PC
Current User Name: Adam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Adam\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Google\Google Media Server\GoogleMediaServer.exe (Google Inc.)
PRC - C:\Program Files\Google\Google Media Server\GoogleMediaScanner.exe (Google Inc.)
PRC - C:\ProgramData\DatacardService\DCSHOST.exe ()
PRC - C:\ProgramData\DatacardService\DataCardMonitor.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe (Sony Corporation)
PRC - C:\Program Files\Sony\Network Utility\NSUService.exe (Sony Corporation)
PRC - C:\Program Files\Sony\Network Utility\LANUtil.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Windows\RTKAUDIOSERVICE.EXE (Realtek Semiconductor)
PRC - C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files\Apoint\Apvfb.exe (ALPS)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe (ArcSoft, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Windows\System32\dlbtcoms.exe ( )
PRC - C:\Program Files\Dell Photo AIO Printer 922\DLBTmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (SafeList) ==========

MOD - C:\Users\Adam\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Google MediaServer) – C:\Program Files\Google\Google Media Server\GoogleMediaServer.exe (Google Inc.)
SRV - (DCSHost.exe) – C:\ProgramData\DatacardService\DCSHOST.exe ()
SRV - (NSUService) – C:\Program Files\Sony\Network Utility\NSUService.exe (Sony Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (RtkHDMIService) – C:\Windows\RTKAUDIOSERVICE.EXE (Realtek Semiconductor)
SRV - (VAIO Power Management) – C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation)
SRV - (SOHDs) – C:\Program Files\Sony\VAIO Media plus\SOHDs.exe (Sony Corporation)
SRV - (SOHDms) – C:\Program Files\Sony\VAIO Media plus\SOHDms.exe (Sony Corporation)
SRV - (SOHCImp) – C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe (Sony Corporation)
SRV - (VcmIAlzMgr) – C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation)
SRV - (VcmXmlIfHelper) – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe (Sony Corporation)
SRV - (VzFw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (uCamMonitor) – C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe (ArcSoft, Inc.)
SRV - (dlbt_device) – C:\Windows\System32\dlbtcoms.exe ( )
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.designhousestockholm.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2010/03/13 22:42:28 | 000,000,936 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DLBTCATS] C:\Windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.DLL ()
O4 - HKLM..\Run: [dlbtmon.exe] C:\Program Files\Dell Photo AIO Printer 922\dlbtmon.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Google Media Scanner] C:\Program Files\Google\Google Media Server\GoogleMediaScanner.exe (Google Inc.)
O4 - HKCU..\Run: [NSUFloatingUI] C:\Program Files\Sony\Network Utility\LANUtil.exe (Sony Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (AVGRSSTX.DLL) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\Users\Adam\Pictures\Images\Cells Colour 2.jpg
O24 - Desktop BackupWallPaper: C:\Users\Adam\Pictures\Images\Cells Colour 2.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/23 20:21:24 | 000,000,057 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{1c48fce4-85d9-11de-988f-001e3df57d8b}\Shell - "" = AutoRun
O33 - MountPoints2\{1c48fcef-85d9-11de-988f-001e3df57d8b}\Shell - "" = AutoRun
O33 - MountPoints2\{fb8e9461-8772-11de-b2be-001dba20c53b}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/21 02:34:27 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/03/15 00:22:33 | 000,555,008 | —- | C] (OldTimer Tools) – C:\Users\Adam\Desktop\OTL.exe
[2010/03/14 08:33:59 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Local\Adobe
[2010/03/14 08:33:55 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Local\Apple Computer
[2010/03/14 01:43:33 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/03/14 00:52:34 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Malwarebytes
[2010/03/14 00:52:30 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/14 00:52:29 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/03/14 00:52:28 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/14 00:52:28 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/13 21:57:03 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/03/13 12:37:47 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/03/13 12:37:42 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\SUPERAntiSpyware.com
[2010/03/13 12:37:42 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/03/13 12:36:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2010/03/11 12:45:06 | 000,000,000 | -HSD | C] – C:\Windows\System32\%APPDATA%
[2010/03/11 02:34:36 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Registry Clean BackUp
[2010/03/10 03:07:58 | 000,000,000 | —D | C] – C:\Users\Adam\Desktop\Bookmarks HTML test
[2010/03/03 01:46:18 | 000,000,000 | —D | C] – C:\Windows\System32\freecom
[2010/03/03 01:04:19 | 000,000,000 | R–D | C] – C:\Users\Adam\Documents\Notes
[2010/03/02 20:15:26 | 000,000,000 | -HSD | C] – C:\Users\Adam\AppData\Roaming\lowsec
[2008/11/10 12:59:31 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\dlbtinpa.dll
[2008/11/10 12:59:31 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\dlbtiesc.dll
[2008/11/10 12:59:31 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\DLBThcp.dll
[2008/11/10 12:59:30 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\dlbtserv.dll
[2008/11/10 12:59:30 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\dlbtusb1.dll
[2008/11/10 12:59:30 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\dlbthbn3.dll
[2008/11/10 12:59:30 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\dlbtcomc.dll
[2008/11/10 12:59:30 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\dlbtpmui.dll
[2008/11/10 12:59:30 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\dlbtlmpm.dll
[2008/11/10 12:59:30 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\dlbtcomm.dll
[2008/11/10 12:59:30 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\dlbtprox.dll
[2008/11/10 12:59:30 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\dlbtpplc.dll

========== Files - Modified Within 14 Days ==========

[2010/03/15 00:23:48 | 007,077,888 | —- | M] () – C:\Users\Adam\ntuser.dat
[2010/03/15 00:22:36 | 000,555,008 | —- | M] (OldTimer Tools) – C:\Users\Adam\Desktop\OTL.exe
[2010/03/15 00:18:09 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/03/15 00:18:09 | 000,600,378 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/03/15 00:18:09 | 000,105,852 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/03/15 00:13:31 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/15 00:13:26 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/15 00:13:26 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/15 00:13:25 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/15 00:13:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/15 00:13:05 | 3219,169,280 | -HS- | M] () – C:\hiberfil.sys
[2010/03/15 00:11:56 | 000,002,140 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/03/15 00:11:45 | 000,524,288 | -HS- | M] () – C:\Users\Adam\ntuser.dat{0cd24c9f-2e97-11df-8544-001dba20c53b}.TMContainer00000000000000000001.regtrans-ms
[2010/03/15 00:11:45 | 000,065,536 | -HS- | M] () – C:\Users\Adam\ntuser.dat{0cd24c9f-2e97-11df-8544-001dba20c53b}.TM.blf
[2010/03/15 00:11:40 | 003,125,762 | -H– | M] () – C:\Users\Adam\AppData\Local\IconCache.db
[2010/03/14 23:52:19 | 057,145,304 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/03/14 23:51:31 | 000,001,878 | -H– | M] () – C:\Users\Adam\Documents\Default.rdp
[2010/03/14 23:41:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/14 08:34:40 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{2F590AE5-98F9-451C-B109-6DDF794A7FA1}.job
[2010/03/14 01:43:34 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/03/14 01:43:33 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/03/14 01:43:33 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/03/14 01:43:09 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/03/14 00:52:33 | 000,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/13 21:57:05 | 000,001,874 | —- | M] () – C:\Users\Adam\Desktop\HijackThis.lnk
[2010/03/13 14:03:50 | 000,001,356 | —- | M] () – C:\Users\Adam\AppData\Local\d3d9caps.dat
[2010/03/13 13:20:43 | 000,524,288 | -HS- | M] () – C:\Users\Adam\ntuser.dat{0cd24c9f-2e97-11df-8544-001dba20c53b}.TMContainer00000000000000000002.regtrans-ms
[2010/03/13 12:29:08 | 000,524,288 | -HS- | M] () – C:\Users\Adam\ntuser.dat{0e494a3c-1e57-11df-9650-001dba20c53b}.TMContainer00000000000000000001.regtrans-ms
[2010/03/13 12:29:08 | 000,065,536 | -HS- | M] () – C:\Users\Adam\ntuser.dat{0e494a3c-1e57-11df-9650-001dba20c53b}.TM.blf
[2010/03/08 22:02:54 | 000,431,616 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/03/08 14:46:21 | 000,121,656 | —- | M] () – C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/04 22:55:44 | 000,000,274 | —- | M] () – C:\Windows\wininit.ini

========== Files Created - No Company Name ==========

[2010/03/14 00:52:33 | 000,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/13 21:57:05 | 000,001,874 | —- | C] () – C:\Users\Adam\Desktop\HijackThis.lnk
[2010/03/13 16:53:18 | 3219,169,280 | -HS- | C] () – C:\hiberfil.sys
[2010/03/13 12:30:45 | 000,524,288 | -HS- | C] () – C:\Users\Adam\ntuser.dat{0cd24c9f-2e97-11df-8544-001dba20c53b}.TMContainer00000000000000000002.regtrans-ms
[2010/03/13 12:30:45 | 000,524,288 | -HS- | C] () – C:\Users\Adam\ntuser.dat{0cd24c9f-2e97-11df-8544-001dba20c53b}.TMContainer00000000000000000001.regtrans-ms
[2010/03/13 12:30:45 | 000,065,536 | -HS- | C] () – C:\Users\Adam\ntuser.dat{0cd24c9f-2e97-11df-8544-001dba20c53b}.TM.blf
[2010/02/26 22:05:17 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/02/26 17:44:42 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/02/24 01:31:07 | 000,000,274 | —- | C] () – C:\Windows\wininit.ini
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2008/11/10 12:59:31 | 000,434,176 | —- | C] () – C:\Windows\System32\dlbtutil.dll
[2008/11/10 12:59:31 | 000,274,432 | —- | C] () – C:\Windows\System32\DLBTinst.dll
[2008/11/10 12:59:30 | 000,176,128 | —- | C] () – C:\Windows\System32\dlbtinsb.dll
[2008/11/10 12:59:30 | 000,159,744 | —- | C] () – C:\Windows\System32\dlbtins.dll
[2008/11/10 12:59:30 | 000,135,168 | —- | C] () – C:\Windows\System32\dlbtjswr.dll
[2008/11/10 12:59:30 | 000,106,496 | —- | C] () – C:\Windows\System32\dlbtinsr.dll
[2008/11/10 12:59:30 | 000,086,016 | —- | C] () – C:\Windows\System32\dlbtcub.dll
[2008/11/10 12:59:30 | 000,073,728 | —- | C] () – C:\Windows\System32\dlbtcu.dll
[2008/11/10 12:59:30 | 000,069,632 | —- | C] () – C:\Windows\System32\DLBTcfg.dll
[2008/11/10 12:59:30 | 000,036,864 | —- | C] () – C:\Windows\System32\dlbtcur.dll
[2008/11/10 12:57:30 | 000,061,440 | —- | C] () – C:\Windows\System32\dlbtcnv4.dll
[2008/11/10 12:57:29 | 000,040,960 | —- | C] () – C:\Windows\System32\dlbtvs.dll
[2008/11/10 12:57:28 | 000,344,064 | —- | C] () – C:\Windows\System32\dlbtcoin.dll
[2008/11/04 19:29:30 | 000,053,760 | —- | C] () – C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/04 18:39:22 | 000,001,356 | —- | C] () – C:\Users\Adam\AppData\Local\d3d9caps.dat
[2008/06/02 20:49:55 | 000,000,000 | —- | C] () – C:\Windows\VAIOUpdt.INI
[2008/06/02 20:44:29 | 000,344,064 | —- | C] () – C:\Windows\System32\SSMSIppCustom.dll
[2008/05/16 20:37:14 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/10/30 17:44:52 | 000,393,216 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2007/05/15 07:43:50 | 000,013,765 | —- | C] () – C:\Windows\System32\drivers\UCharger.sys
[2006/11/02 12:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 07:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/08/21 15:45:40 | 000,241,664 | —- | C] () – C:\Windows\System32\hppapr04.dll
[2001/11/14 20:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2009/02/24 13:06:41 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/11/05 22:51:45 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\InterVideo
[2010/03/02 20:15:59 | 000,000,000 | -HSD | M] – C:\Users\Adam\AppData\Roaming\lowsec
[2009/12/10 15:31:04 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\TeamViewer
[2009/01/29 13:03:02 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Template
[2009/10/01 13:56:55 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Transparent
[2010/02/27 11:20:23 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Trusteer
[2010/03/15 00:11:56 | 000,032,556 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/03/14 08:34:40 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{2F590AE5-98F9-451C-B109-6DDF794A7FA1}.job

========== Purity Check ==========



========== Custom Scans ==========


< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.

< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/21 02:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 09:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/10 23:32:28 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/10 23:32:28 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 02:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\drivers\atapi.sys
[2008/01/21 02:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 02:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 09:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 09:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 09:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2008/04/22 00:20:41 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\Windows\Drivers\INF\SATA Driver (Intel) (Non-RAID)\IaStor.sys
[2010/02/27 07:02:51 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\Windows\System32\drivers\iaStor.sys
[2008/04/22 00:20:41 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_77c04a30\iaStor.sys
[2008/04/22 00:20:41 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\Windows\System32\DriverStore\FileRepository\iastor.inf_054cd65f\iaStor.sys

< MD5 for: IASTORV.SYS >
[2008/01/21 02:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 02:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 02:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 09:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/10 23:28:24 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/10 23:28:24 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 02:24:05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 09:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 02:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 02:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 02:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/21 02:24:50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/10 23:28:26 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/10 23:28:26 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/05/13 00:05:16 | 000,372,736 | —- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – C:\Windows\System32\ATIDEMGX.dll
[2009/04/10 23:27:48 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009/04/10 23:28:24 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/01/21 03:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 03:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 03:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 10:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 10:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< End of report >



OTL Extras logfile created on: 15/03/2010 00:24:53 - Run 1
OTL by OldTimer - Version 3.1.37.1 Folder = C:\Users\Adam\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.65 Gb Total Space | 170.17 Gb Free Space | 76.43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SOFIE-PC
Current User Name: Adam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Opera.HTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Opera\opera.exe" File not found
https [open] – "C:\Program Files\Opera\opera.exe" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1B9D4953-4090-4134-9505-E292CFCACBAD}" = rport=445 | protocol=6 | dir=out | app=system |
"{330ECF3F-5500-4E3F-ACB5-9202C76B0180}" = lport=139 | protocol=6 | dir=in | app=system |
"{4575D617-FBDB-4732-88F8-5D118FAFC79B}" = lport=445 | protocol=6 | dir=in | app=system |
"{601CEA3E-3B69-4CBA-9CD1-773F0E0D34C8}" = lport=138 | protocol=17 | dir=in | app=system |
"{876528B1-F789-4E36-A7CC-37EB2CA0CC6D}" = rport=138 | protocol=17 | dir=out | app=system |
"{A673481A-05C3-47E7-A135-4DB9DD8AF00E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C5606D2B-CB48-438D-AE76-4843829741EA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CAC6DD75-97C9-43A7-B0A5-1FDEDC246116}" = rport=139 | protocol=6 | dir=out | app=system |
"{D21E586B-B21D-4197-8483-A838B84C24C6}" = lport=137 | protocol=17 | dir=in | app=system |
"{E4ECBAC8-7A70-4E93-9FB8-602718B845F1}" = rport=137 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04D2ECE7-8487-4957-BE66-10338063DB56}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0FFB9C0A-9E3C-4A6A-90F3-5E67EFF5541D}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"{11883764-DCD5-4D14-BDE5-A7B91EFE47A3}" = protocol=17 | dir=in | app=c:\windows\system32\dlbtcoms.exe |
"{24F025BD-2535-467B-B5A2-4B503EB18F58}" = dir=in | app=c:\program files\avg\avg9\avgemc.exe |
"{26BF1507-1BBA-4C6B-A8E1-99A7153B5104}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{3964151D-2EDA-4028-8071-211486E6816E}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3CE2FECE-3725-4041-82F7-20F19CA42A58}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4340CDAB-19AA-4D79-B5C7-CF86F8F9D0E5}" = protocol=17 | dir=in | app=c:\program files\google\google talk\googletalk.exe |
"{47419497-095F-4FE8-875A-574F0A75A434}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5001B691-7D51-454D-A405-CAD09B3F4E66}" = protocol=17 | dir=in | app=c:\program files\dell photo aio printer 922\dlbtmon.exe |
"{55EE352F-E4ED-42E4-B314-0E0BE9D669FD}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{569D3EB4-0167-45F8-A1B8-49E323B3C82D}" = protocol=6 | dir=in | app=c:\program files\google\google media server\googlemediaserver.exe |
"{5C61305B-3A9D-45AD-AB81-099A03266122}" = protocol=6 | dir=in | app=c:\program files\dell photo aio printer 922\dlbtaiox.exe |
"{87163F61-E2D9-441D-B7FD-980AD83244A8}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"{9E96BA5C-41E9-4804-AB5E-4A3B768B9BBA}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{9FD059AF-E40E-436D-8609-6C16D9CA02EA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A8335682-D5B5-46D2-9AA4-FB274030EC71}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{AF04831F-1DCB-497F-AD87-66503295E105}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\dlbtpswx.exe |
"{B5764FAF-BF50-4A91-8A67-F3EAEBDB473D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B6B1C0AD-7729-4F1E-8FE7-94EFF5593DC1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BAFD5B7A-4E3C-44B5-8A21-D335E65A4FAD}" = protocol=6 | dir=in | app=c:\program files\dell photo aio printer 922\dlbtmon.exe |
"{BC57815D-23CD-4AAF-8816-3BF043ED0137}" = protocol=17 | dir=in | app=c:\program files\dell photo aio printer 922\dlbtaiox.exe |
"{C18DE59A-587F-4233-ACD4-DD0E96B20BBD}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\dlbtpswx.exe |
"{C213FE1C-7857-494F-8D1E-5428E9E06C6C}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C8E4B4FA-97BD-44C2-B420-6A12206FE5BB}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe |
"{D23DDCB9-CA2F-4E96-BB8C-D80760742810}" = protocol=6 | dir=in | app=c:\program files\google\google talk\googletalk.exe |
"{DDE6EB96-7C6D-4998-844B-B253F89C203D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{DF291F3B-7883-41EF-90A0-186FBD21C2B8}" = protocol=6 | dir=in | app=c:\windows\system32\dlbtcoms.exe |
"{E0B1CD01-05F7-416D-B047-C41F6EA1ACFF}" = protocol=17 | dir=in | app=c:\program files\google\google media server\googlemediaserver.exe |
"{EC2AC539-E714-4F4F-B1E8-A4247F89C029}" = dir=in | app=c:\program files\avg\avg9\avgupd.exe |
"{FC34F0F2-A6AA-4C1E-8959-CE7C3D5A409C}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{4065EB58-5E09-48DF-ADFD-68FCB2EC29CF}C:\program files\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"TCP Query User{900DDDAB-3F4B-4A77-BB6A-CE2D39A36C17}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{55158195-DF1B-4587-BB14-C0CF0E89694F}C:\program files\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"UDP Query User{F172F732-0385-46CD-8A71-9A433288F56D}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony Video Shared Library
"{02D63222-CF76-E080-74DD-975B1672ED67}" = Catalyst Control Center Core Implementation
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.1.0.2200
"{0405000A-0570-549A-A819-3BCEEAA1B40B}" = Catalyst Control Center Localization Hungarian
"{06786A53-D2D8-47CD-696A-ABC83625EBFE}" = Catalyst Control Center Graphics Light
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{1316AEF2-E086-46C7-B1FB-8C9A39A2ABF9}" = VAIO Media plus
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14E7357F-487C-3BF6-7955-B898AA76306E}" = CCC Help Russian
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15D5C238-4C2E-4AEA-A66D-D6989A4C586B}" = VAIO Launcher
"{16D9D199-E8A0-9FBA-DDF3-0E2D7826D694}" = Catalyst Control Center Localization Spanish
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18C24BF9-3B71-6F89-848C-D78C40197216}" = CCC Help Chinese Traditional
"{1974FF16-2A0A-76AF-D948-0037B0CB8EB5}" = CCC Help Hungarian
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1E87F957-F850-D9F9-60F3-842955AAF519}" = Catalyst Control Center Localization German
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{2018C019-30D9-4240-8C01-0865C10DCF5A}" = VAIO Presentation Support
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{23825B69-36DF-4DAD-9CFD-118D11D80F16}" = VAIO Content Folder Setting
"{26921B2E-3E62-47F9-A514-1FC4A83BD738}" = Intel® PROSet/Wireless WiFi Software
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 18
"{27A2ABE9-E4C4-45DD-B9A8-CEEEE380E7E1}" = VAIO Content Metadata Intelligent Analyzing Manager
"{2C3D71B4-85C4-5FA9-859E-1413F94EF642}" = Catalyst Control Center Localization Greek
"{310395F2-9206-159B-43B0-BF63D9F01B61}" = Catalyst Control Center Localization Turkish
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{326DC400-1FC4-4D7D-946D-06D1EAB93200}" = VAIO Guide 
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3B659FAD-E772-44A3-B7E7-560FF084669F}" = VAIO Smart Network
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{43DA617D-1B80-0B70-FAA0-52AFCE853F40}" = CCC Help Finnish
"{4742375A-9BD3-46D0-E0CC-A8819D2E2C54}" = CCC Help Greek
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BB5D5A7-F75E-D8D9-0DF8-AA2C1F188CEB}" = Catalyst Control Center Localization French
"{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = Click to Disc Editor
"{4EA55D20-27FB-45D7-8726-147E8A5F6C62}" = VAIO MusicBox
"{4FCBFEDD-0CBF-A4A8-79D3-E9EAD37336C9}" = CCC Help Chinese Standard
"{54C91EE3-65B9-A931-8382-12B2A02709F8}" = ATI Catalyst Install Manager
"{5511F0CC-59E0-02AD-941F-2323DA2BB377}" = CCC Help Swedish
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}" = VAIO DVD Menu Data Basic
"{5A29796D-2566-3ADA-043D-28C51CD7D4C3}" = Catalyst Control Center Localization Chinese Standard
"{5C5EE8F2-0B38-4C13-AE4E-A87A237FE718}" =
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{5D803295-DD78-0143-F64B-0D80852C43E9}" = CCC Help Italian
"{5F5867F0-2D23-4338-A206-01A76C823924}" = VAIO Power Management
"{61FD2585-3337-8822-899B-68612742BA2F}" = Catalyst Control Center Localization Russian
"{6332AFF1-9D9A-429C-AA03-F82749FA4F49}" = SonicStage Mastering Studio
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}" = Click to Disc
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6C7196C0-D205-03E7-39A1-7A23AB69F659}" = CCC Help Czech
"{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}" = VAIO Movie Story Template Data
"{70D43D66-53BF-257F-72FC-96FB33B39276}" = Catalyst Control Center Graphics Full New
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{723F5CDD-839A-FF16-4CFA-C4E0AA54A315}" = ccc-core-static
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
"{73BD4567-1C4E-8D45-1D28-3D469026A883}" = Skins
"{757CC5BA-BF08-46A5-8D10-64C6FDF659C6}" = VAIO Content Metadata Manager Setting
"{761205A9-41DC-48C9-2CC1-F197D372DBEF}" = Catalyst Control Center Localization Italian
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{786C5747-1437-443D-B06E-79A00FE45110}" = Adobe Stock Photos 1.0
"{7BB90344-0647-468E-925A-7F69F7983421}" = ArcSoft Magic-i Visual Effects
"{7E5DEF65-FE91-02F2-C291-22741AC34017}" = Catalyst Control Center Localization Danish
"{81063354-9060-42B2-A000-1EBE96778AA9}" = iTunes
"{826E7114-AA2E-59AA-1916-2A753DC49153}" = ccc-utility
"{8299B94E-7F85-65A9-B0FA-6F6A8A6D4FBD}" = Catalyst Control Center Localization Thai
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}" = VAIO Update 4
"{8626472F-7AD7-C83B-66FA-00E0A1C50A26}" = Catalyst Control Center Localization Swedish
"{8662A65A-A2A1-072C-708D-1C1262776F6A}" = CCC Help Thai
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C3CD8CF-7012-51E5-107B-5A8C75701E1A}" = CCC Help Dutch
"{8ED3A392-28F1-4375-97AC-BF275B5855F9}" = OpenMG Secure Module 5.0.00
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{918CFAF6-AC40-F2C8-C044-7FA95C8A7099}" = CCC Help German
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{963B65F9-89C7-48BB-8E40-E7583DEC7C8D}" = SonicStage Mastering Studio
"{96D0B6C6-5A72-4B47-8583-A87E55F5FE81}" =
"{98FC7A64-774B-49B5-B046-4B4EBC053FA9}" = VAIO MusicBox Sample Music
"{9973498D-EA29-4A68-BE0B-C88D6E03E928}" = ArcSoft WebCam Companion 2
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C1C8A04-F8CA-4472-A92D-4288CE32DE86}" = SonicStage Mastering Studio Plugins
"{9C71059E-6DDD-4958-9251-7A5F865B6BA0}" = VAIO Content Metadata Intelligent Analyzing Manager
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Pointing-device for VAIO
"{A33E457B-5369-481F-8B53-71108AE2EB5B}" = Roxio Easy Media Creator 10 LJ
"{A4399CF4-7A3F-4E84-B763-AD352640203D}" = VAIO Content Metadata XML Interface Library
"{A55A277A-4336-FACF-991A-52B51B8FAE78}" = Catalyst Control Center Localization Finnish
"{A5D54806-AA49-BBFF-A2D3-76FA3DF096FA}" = Catalyst Control Center Localization Korean
"{A63E7492-A0BC-4BB9-89A7-352965222380}" = VAIO Original Function Setting
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" = Setting Utility Series
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AAE442C0-F28B-8D58-1A1C-D566F9BCD294}" = Catalyst Control Center Localization Portuguese
"{AC76BA86-1033-F400-BA7E-000000000003}" = Adobe Acrobat 8 Standard - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AD05F1FF-F284-402D-952A-ABCA6A6063FB}" = Adobe Illustrator CS2
"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}" = Adobe Bridge 1.0
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}" = VAIO Movie Story
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{B6B0D277-D003-307F-CF94-5F5894DFA3F1}" = Catalyst Control Center Graphics Full Existing
"{B74D4E10-0000-0000-0000-EDED00000102}" = Adobe ExtendScript Toolkit 1.0
"{B7C03E84-AF46-42F4-809D-D4127D9086D0}" = VAIO Edit Components 6.4
"{BC653BB7-0AF0-22E5-A895-902AD52675CA}" = CCC Help Portuguese
"{BCEABBD6-6EDA-4246-7EDB-D68FCCD78A65}" = Catalyst Control Center Graphics Previews Common
"{BDD17603-CB75-0639-E6DA-0D9AA92A605B}" = CCC Help English
"{BF5F6A06-0FC3-BEC0-9CC1-54D870A9EF97}" = Catalyst Control Center Localization Chinese Traditional
"{C221CE66-9C07-8EA7-8EF6-AAD8E4588AE0}" = CCC Help French
"{C455F37C-E92E-5CEB-382D-8B8EC580266F}" = Catalyst Control Center Localization Norwegian
"{C6F150F6-AE89-30C7-6256-C40CF9328602}" = Catalyst Control Center Graphics Previews Vista
"{C7477742-DDB4-43E5-AC8D-0259E1E661B1}" = VAIO Event Service
"{C93F4E7C-1B31-449B-A304-EF277CF55E39}" = Catalyst Control Center - Branding
"{CBAE1EE5-F6E0-BDEF-0D49-C2AE46BE3B88}" = CCC Help Polish
"{CC56A2CB-EC09-4175-B8BD-93E2440D410B}" = VAIO Content Metadata Manager Setting
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D06F5884-B439-440B-A58D-6C057C2FF8EB}" = Click to Disc
"{D0AE373E-C276-432B-9A95-F8DD356A8242}" = VAIO Movie Story
"{D3AF5596-546F-5975-39B4-259A197C7E24}" = Catalyst Control Center Localization Japanese
"{D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3}" = VAIO Wallpaper Contents
"{D90507A2-6183-497D-9075-951DC80362DA}" = VAIO Media plus
"{DD362256-A7A2-4524-9457-213DDC2AFC2A}" = Adobe After Effects 7.0
"{DDF57E4A-66B5-E9CC-C2A2-F2C98C57912C}" = CCC Help Turkish
"{DEBA60A3-7CDE-48D7-993D-7C68663AEE68}" = VAIO Content Metadata Intelligent Analyzing Manager
"{DF7DB916-90E5-40F2-9010-B8125EB5FD6F}" = SonicStage Mastering Studio Audio Filter
"{E27D2C9F-83A1-A34C-E366-26EADB9270F7}" = Catalyst Control Center Localization Dutch
"{E2E7667F-C286-D110-7F9D-FC397A2607A8}" = CCC Help Danish
"{E7821540-B8F8-304F-1B97-C43D8582EB18}" = CCC Help Norwegian
"{E8CA49A5-25C6-D80A-ED46-9D48A8B5D5F5}" = CCC Help Japanese
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EC37A846-53AC-4DA7-98FA-76A4E74AA900}" = SonicStage Mastering Studio Audio Filter Custom Preset
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{F06300A2-87AE-042F-DE0F-1A5E380877C5}" = Catalyst Control Center Localization Czech
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F20E6529-0B46-FC26-378F-62CD640A98C4}" = Catalyst Control Center Localization Polish
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F485E43D-18B1-4B40-AF4B-EDA78E91DA80}" = Dolby Control Center
"{F570A6CC-53ED-4AA9-8B08-551CD3E38D8B}" =
"{F754B561-ACAD-A3FA-AF54-3E5F9E662B04}" = CCC Help Korean
"{F8821B6D-B6C9-E676-9B7D-3269F36A1769}" = CCC Help Spanish
"{FACD3674-FC12-4B6C-A923-E1D687704E9B}" = VAIO Content Metadata XML Interface Library
"{FD9E03B5-AEEA-4D59-B512-6CE4AA0281D4}" = Byki
"{FE51662F-D8F6-43B5-99D9-D4894AF00F83}" = Roxio Easy Media Creator Home
"7-Zip" = 7-Zip 4.65
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Acrobat 8 Standard - English, Français, Deutsch" = Adobe Acrobat 8.1.4 Standard
"Adobe After Effects 7.0" = Adobe After Effects 7.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Illustrator CS2" = Adobe Illustrator CS2 Tryout
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AVG9Uninstall" = AVG Free 9.0
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"Comviq Surf Connect" = Comviq Surf Connect
"Dell Photo AIO Printer 922" = Dell Photo AIO Printer 922
"dt icon module" =
"EPSON Printer and Utilities" = EPSON Printer Software
"Google Desktop" = Google Desktop
"Google Media Server" = Google Media Server
"gtfirstboot Setting Request" =
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = Click to Disc Editor
"InstallShield_{8ED3A392-28F1-4375-97AC-BF275B5855F9}" = OpenMG Secure Module 5.0.00
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MarketingTools" = Vaio Marketing Tools
"MFU Module" =
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"ProInst" = Intel PROSet Wireless
"Rapport_msi" = Rapport
"VAIO Help and Support" =
"VAIO_My Club VAIO" = My Club VAIO
"VLC media player" = VLC media player 0.9.2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Byki Express for Adam" = Byki Express for Adam

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 05/03/2010 08:26:57 | Computer Name = Sofie-PC | Source = WinMgmt | ID = 10
Description =

Error - 06/03/2010 04:22:34 | Computer Name = Sofie-PC | Source = WinMgmt | ID = 10
Description =

Error - 07/03/2010 12:49:20 | Computer Name = Sofie-PC | Source = WinMgmt | ID = 10
Description =

Error - 07/03/2010 13:40:18 | Computer Name = Sofie-PC | Source = SPP | ID = 16387
Description =

Error - 07/03/2010 13:40:18 | Computer Name = Sofie-PC | Source = System Restore | ID = 8193
Description =

Error - 07/03/2010 13:40:18 | Computer Name = Sofie-PC | Source = System Restore | ID = 8210
Description =

Error - 07/03/2010 17:03:58 | Computer Name = Sofie-PC | Source = Application Error | ID = 1000
Description = Faulting application Acrobat.exe, version 8.1.0.137, time stamp 0x46444c82,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x0a0d0d2e, process id 0x10b4, application start time 0x01cabe39a9bcaf64.

Error - 07/03/2010 20:00:10 | Computer Name = Sofie-PC | Source = SPP | ID = 16387
Description =

Error - 07/03/2010 20:00:11 | Computer Name = Sofie-PC | Source = System Restore | ID = 8193
Description =

Error - 07/03/2010 20:00:11 | Computer Name = Sofie-PC | Source = System Restore | ID = 8210
Description =

[ System Events ]
Error - 13/03/2010 09:48:51 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 13/03/2010 09:48:51 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 13/03/2010 09:48:51 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 13/03/2010 12:53:56 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 13/03/2010 15:29:39 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 13/03/2010 21:26:04 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 13/03/2010 21:45:45 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 14/03/2010 04:19:16 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 14/03/2010 19:11:55 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 14/03/2010 20:13:48 | Computer Name = Sofie-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >



1st MBAM Log created!


Malwarebytes' Anti-Malware 1.44
Database version: 3865
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

14/03/2010 01:22:26
mbam-log-2010-03-14 (01-22-26).txt

Scan type: Quick Scan
Objects scanned: 118113
Time elapsed: 3 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 12
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ROUA3O12PW (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\TOY5KNQ8OC (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\none (Trojan.Dropper) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.164.228,93.188.161.46 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{920de905-0e5c-4dca-98a9-09d9356a7bd7}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{920de905-0e5c-4dca-98a9-09d9356a7bd7}\NameServer (Trojan.DNSChanger) -> Data: 93.188.164.228,93.188.161.46 -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\spool\prtprocs\w32x86\00000924.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.



Second MBAM Log Created!


Malwarebytes' Anti-Malware 1.44
Database version: 3865
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

14/03/2010 04:17:07
mbam-log-2010-03-14 (04-17-07).txt

Scan type: Quick Scan
Objects scanned: 118223
Time elapsed: 3 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


GMER Log

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-14 09:53:00
Windows 6.0.6002 Service Pack 2
Running: svlxc6im.exe; Driver: C:\Users\Adam\AppData\Local\Temp\uglcypod.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwAssignProcessToJobObject [0x90556D42]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwCreateFile [0x9055744E]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteFile [0x9055759A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteKey [0x9055AD28]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteValueKey [0x9055AD5A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenFile [0x905574FE]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenProcess [0x90556E86]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenThread [0x90557078]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwProtectVirtualMemory [0x905571AA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwQueryValueKey [0x9055AE2E]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRenameKey [0x9055AD98]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwReplaceKey [0x9055ADCA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRestoreKey [0x9055ADFC]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetContextThread [0x90556CF0]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetInformationFile [0x905575FA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetValueKey [0x9055ACC8]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSuspendThread [0x90556C94]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x904FD320]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwTerminateThread [0x90556C38]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 191 82EF88F4 4 Bytes [42, 6D, 55, 90] {INC EDX; INSD ; PUSH EBP; NOP }
.text ntkrnlpa.exe!KeSetEvent + 1D9 82EF893C 4 Bytes [4E, 74, 55, 90] {DEC ESI; JZ 0x58; NOP }
.text ntkrnlpa.exe!KeSetEvent + 2D1 82EF8A34 8 Bytes [9A, 75, 55, 90, 28, AD, 55, …] {CALL FAR 0x55ad:0x28905575; NOP }
.text ntkrnlpa.exe!KeSetEvent + 2E1 82EF8A44 4 Bytes [5A, AD, 55, 90] {POP EDX; LODSD ; PUSH EBP; NOP }
.text ntkrnlpa.exe!KeSetEvent + 3D1 82EF8B34 4 Bytes [FE, 74, 55, 90]
.text …
.rsrc C:\Windows\system32\DRIVERS\iaStor.sys entry point in ".rsrc" section [0x838D1014]
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EC08000, 0x1F926A, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1372] ntdll.dll!KiUserApcDispatcher 77365D18 5 Bytes JMP 00412480 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1372] USER32.dll!InSendMessageEx + 3B1 774CE6B0 6 Bytes JMP 716E001E
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1372] WS2_32.dll!getaddrinfo 75DC418A 5 Bytes JMP 71640022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1372] WS2_32.dll!gethostbyname 75DD62D4 5 Bytes JMP 71670022
.text C:\Windows\system32\svchost.exe[1528] ntdll.dll!NtProtectVirtualMemory 77364D34 5 Bytes JMP 0086000A
.text C:\Windows\system32\svchost.exe[1528] ntdll.dll!NtWriteVirtualMemory 77365674 5 Bytes JMP 008B000A
.text C:\Windows\system32\svchost.exe[1528] ntdll.dll!KiUserExceptionDispatcher 77365DC8 5 Bytes JMP 0081000A
.text C:\Windows\system32\svchost.exe[1528] ole32.dll!CoCreateInstance 77209EA6 5 Bytes JMP 00AD000A
.text C:\Windows\system32\svchost.exe[1528] USER32.dll!GetCursorPos 774E0B88 5 Bytes JMP 00AE000A
.text C:\Windows\Explorer.EXE[4236] ntdll.dll!NtProtectVirtualMemory 77364D34 5 Bytes JMP 0066000A
.text C:\Windows\Explorer.EXE[4236] ntdll.dll!NtWriteVirtualMemory 77365674 5 Bytes JMP 0067000A
.text C:\Windows\Explorer.EXE[4236] ntdll.dll!KiUserExceptionDispatcher 77365DC8 5 Bytes JMP 0065000A
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4328] ntdll.dll!KiUserApcDispatcher 77365D18 5 Bytes JMP 004394A0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4328] WS2_32.dll!getaddrinfo 75DC418A 5 Bytes JMP 71670022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4328] WS2_32.dll!gethostbyname 75DD62D4 5 Bytes JMP 716E0022

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [742B7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7430A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [742BBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [742AF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [742B75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [742AE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [742E8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [742BDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [742AFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [742AFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [742A71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7433CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [742DC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [742AD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [742A6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [742A687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [742B2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device -> \Driver\iaStor \Device\Harddisk0\DR0 8657FA9A

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3d02abe2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3d8b7307
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3d8b730b
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3d8b7317
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3d8b731d
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3df57d8b
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3df57d8b@001e75b26e63 0x09 0x4F 0x7C 0x05 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3df57d8b@a007989f71c3 0x77 0x7B 0xA7 0x8A …
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001e3d02abe2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001e3d8b7307 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001e3d8b730b (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001e3d8b7317 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001e3d8b731d (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001e3df57d8b (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001e3df57d8b@001e75b26e63 0x09 0x4F 0x7C 0x05 …
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001e3df57d8b@a007989f71c3 0x77 0x7B 0xA7 0x8A …

—- Files - GMER 1.0.15 —-

File C:\Windows\system32\DRIVERS\iaStor.sys suspicious modification

—- EOF - GMER 1.0.15 —-


Thanks,
Marm.
Marm,

🖼Click to load external image (Posted Image) You are infected with a trojan and rootkit know to sometimes have backdoor properties. Rootkits and Backdoor Trojans are very dangerous because they use advanced techniques (backdoors) to bypass security mechanisms and steal sensitive information which they send back to the hacker. If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately limit your online activity until your system is cleaned. All passwords should be changed immediately using a different computer and banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please include the following in your next post:
  • ComboFix log
Hi RPMcMurphy, Don't know if the following information is of any interest but when ComboFix was deleteing some recycle bin folders the message "Program Failed to initiate properly" . Before I could click ok the computer started to reboot & then the following log report was made: ComboFix 10-03-14.06 - Adam 15/03/2010 10:47:10.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3069.1728 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2355012822-1505145729-1817729130-500 c:\$recycle.bin\S-1-5-21-2867428185-1645830329-2549438106-500 c:\$recycle.bin\S-1-5-21-3716795607-2812649300-1795958332-500 c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk Infected copy of c:\windows\system32\DRIVERS\iaStor.sys was found and disinfected Restored copy from - Kitty ate it :P . ((((((((((((((((((((((((( Files Created from 2010-02-15 to 2010-03-15 ))))))))))))))))))))))))))))))) . 2010-03-15 10:54 . 2010-03-15 10:56 ——– d—–w- c:\users\Adam\AppData\Local\temp 2010-03-14 08:33 . 2010-03-14 08:33 ——– d—–w- c:\users\Adam\AppData\Local\Adobe 2010-03-14 08:33 . 2010-03-14 08:33 ——– d—–w- c:\users\Adam\AppData\Local\Apple Computer 2010-03-14 01:43 . 2010-03-14 01:43 12464 —-a-w- c:\windows\system32\avgrsstx.dll 2010-03-14 00:52 . 2010-03-14 00:52 ——– d—–w- c:\users\Adam\AppData\Roaming\Malwarebytes 2010-03-14 00:52 . 2010-01-07 16:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-14 00:52 . 2010-03-14 00:52 ——– d—–w- c:\programdata\Malwarebytes 2010-03-14 00:52 . 2010-03-14 00:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-03-14 00:52 . 2010-01-07 16:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-03-13 21:57 . 2010-03-13 21:57 ——– d—–w- c:\program files\Trend Micro 2010-03-13 12:37 . 2010-03-13 12:37 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2010-03-13 12:37 . 2010-03-13 12:37 ——– d—–w- c:\users\Adam\AppData\Roaming\SUPERAntiSpyware.com 2010-03-13 12:37 . 2010-03-13 12:37 ——– d—–w- c:\program files\SUPERAntiSpyware 2010-03-13 12:36 . 2010-03-13 12:36 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard 2010-03-11 12:45 . 2010-03-11 12:45 ——– d-sh–w- c:\windows\system32\%APPDATA% 2010-03-11 12:44 . 2010-02-20 23:06 24064 —-a-w- c:\windows\system32\nshhttp.dll 2010-03-11 12:44 . 2010-02-20 23:05 30720 —-a-w- c:\windows\system32\httpapi.dll 2010-03-11 12:44 . 2010-02-20 20:53 411648 —-a-w- c:\windows\system32\drivers\http.sys 2010-03-11 02:26 . 2007-02-18 21:11 296960 —-a-w- c:\windows\winhlp32.exe 2010-03-11 02:26 . 2007-02-18 21:11 194560 —-a-w- c:\windows\system32\ftsrch.dll 2010-03-11 02:26 . 2007-02-18 21:11 9728 —-a-w- c:\windows\system32\ftlx041e.dll 2010-03-11 02:26 . 2007-02-18 21:11 9216 —-a-w- c:\windows\system32\ftlx0411.dll 2010-03-03 01:46 . 2010-03-03 01:46 ——– d—–w- c:\windows\system32\freecom 2010-03-02 20:15 . 2010-03-02 20:15 ——– d-sh–w- c:\users\Adam\AppData\Roaming\lowsec 2010-03-02 20:06 . 2010-03-02 20:06 ——– d—–w- c:\users\Sofie\AppData\Roaming\Trusteer 2010-02-27 12:02 . 2010-02-27 12:02 390528 —-a-w- c:\windows\system32\drivers\RapportBuka.sys 2010-02-27 11:20 . 2010-02-27 11:20 ——– d—–w- c:\users\Adam\AppData\Roaming\Trusteer 2010-02-27 11:20 . 2010-02-27 11:20 ——– d—–w- c:\program files\Trusteer 2010-02-27 11:19 . 2010-02-27 11:19 ——– d—–w- c:\programdata\Trusteer 2010-02-26 23:20 . 2010-02-26 23:20 ——– d—–w- c:\program files\Windows Portable Devices 2010-02-26 23:18 . 2009-10-01 01:02 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe 2010-02-26 22:21 . 2010-02-26 22:22 ——– d—–w- c:\windows\system32\ca-ES 2010-02-26 22:21 . 2010-02-26 22:22 ——– d—–w- c:\windows\system32\eu-ES 2010-02-26 22:21 . 2010-02-26 22:22 ——– d—–w- c:\windows\system32\vi-VN 2010-02-26 22:18 . 2010-02-26 22:18 ——– d—–w- c:\windows\system32\SPReview 2010-02-26 22:10 . 2009-04-10 23:28 928768 —-a-w- c:\windows\system32\scavenge.dll 2010-02-26 22:10 . 2009-04-10 23:27 57856 —-a-w- c:\windows\system32\compcln.exe 2010-02-26 22:04 . 2009-04-10 23:28 87040 —-a-w- c:\windows\system32\mssitlb.dll 2010-02-26 16:25 . 2010-01-25 12:00 471552 —-a-w- c:\windows\system32\secproc_isv.dll 2010-02-25 14:44 . 2010-02-12 10:32 293376 —-a-w- c:\windows\system32\browserchoice.exe 2010-02-23 23:39 . 2010-02-23 23:39 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-02-23 20:20 . 2010-01-23 09:26 2048 —-a-w- c:\windows\system32\tzres.dll 2010-02-22 12:44 . 2010-02-22 12:44 ——– d—–w- c:\program files\iPod 2010-02-22 12:44 . 2010-02-22 12:44 ——– d—–w- c:\program files\iTunes 2010-02-22 12:44 . 2010-02-22 12:44 ——– d—–w- c:\program files\Bonjour 2010-02-20 23:49 . 2010-02-20 23:49 ——– d—–w- c:\program files\7-Zip 2010-02-20 08:34 . 2005-04-13 16:36 ——– d—–w- c:\users\Public\Photoshop CS2 2010-02-19 10:19 . 2010-02-19 10:19 ——– d—–w- c:\windows\Sun 2010-02-19 02:26 . 2010-02-19 02:26 ——– d—–w- c:\programdata\Adobe Systems 2010-02-19 02:20 . 2010-02-20 20:07 ——– d—–w- c:\program files\Common Files\Adobe Systems Shared 2010-02-18 20:54 . 2007-03-23 04:05 29272 —-a-r- c:\windows\system32\AdobePDF.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-15 10:54 . 2008-05-16 19:41 12 —-a-w- c:\windows\bthservsdp.dat 2010-03-15 10:23 . 2008-11-10 13:02 ——– d—–w- c:\program files\Dl_cats 2010-03-14 01:43 . 2010-03-14 01:43 360584 —-a-w- c:\programdata\avg9\update\backup\avgtdix.sys 2010-03-14 01:43 . 2010-03-14 01:43 333192 —-a-w- c:\programdata\avg9\update\backup\avgldx86.sys 2010-03-14 01:43 . 2010-03-14 01:43 28424 —-a-w- c:\programdata\avg9\update\backup\avgmfx86.sys 2010-03-14 01:43 . 2009-10-22 12:22 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-03-14 01:43 . 2009-10-22 12:22 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-03-14 01:43 . 2009-10-22 12:22 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-03-13 14:03 . 2008-11-04 18:39 1356 —-a-w- c:\users\Adam\AppData\Local\d3d9caps.dat 2010-03-13 12:38 . 2010-03-13 12:38 52224 —-a-w- c:\users\Adam\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-03-13 12:38 . 2010-03-13 12:38 117760 —-a-w- c:\users\Adam\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-03-11 12:47 . 2008-06-02 20:18 ——– d—–w- c:\programdata\Microsoft Help 2010-03-11 02:00 . 2008-06-02 20:42 ——– d—–w- c:\programdata\Uninstall 2010-03-08 14:46 . 2008-11-04 18:39 121656 —-a-w- c:\users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT 2010-03-06 23:07 . 2010-03-06 23:07 1232496 —-a-w- c:\programdata\Google\Google Toolbar\Component\GoogleCld_D9AEC8D4D1915047.dll 2010-03-06 23:07 . 2008-05-16 20:07 ——– d—–w- c:\program files\Google 2010-03-04 15:15 . 2009-10-22 12:21 ——– d—–w- c:\programdata\avg9 2010-02-27 12:02 . 2010-02-27 12:02 390528 —-a-w- c:\programdata\Trusteer\Rapport\store\exts\RapportBukaBroom\13897\RapportBuka.sys 2010-02-27 12:02 . 2010-02-27 12:02 249856 —-a-w- c:\programdata\Trusteer\Rapport\store\exts\RapportBukaBroom\13897\RapportBukaBroom.dll 2010-02-27 07:24 . 2008-05-16 21:24 ——– d—–w- c:\programdata\FLEXnet 2010-02-27 07:02 . 2008-04-22 00:20 312344 —-a-w- c:\windows\system32\drivers\iaStor.sys 2010-02-26 23:20 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat 2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar 2010-02-26 22:22 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar 2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery 2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal 2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender 2010-02-26 17:17 . 2010-02-26 17:17 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2010-02-25 14:23 . 2008-05-16 21:23 ——– d—–w- c:\program files\Common Files\Adobe 2010-02-22 12:44 . 2008-11-04 18:52 ——– d—–w- c:\program files\Common Files\Apple 2010-02-21 15:29 . 2009-02-24 12:47 ——– d—–w- c:\programdata\NOS 2010-02-21 14:37 . 2010-02-21 14:37 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe 2010-02-20 20:08 . 2008-05-16 20:26 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-02-15 18:41 . 2010-02-15 18:41 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2010-02-10 12:57 . 2010-02-10 12:57 ——– d—–w- c:\programdata\WindowsSearch 2010-02-04 10:45 . 2010-02-04 10:44 ——– d—–w- c:\program files\QuickTime 2010-02-02 12:33 . 2010-02-02 12:33 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbF96D.tmp.exe 2010-01-28 01:01 . 2008-05-16 21:25 ——– d—–w- c:\program files\Common Files\Java 2010-01-27 23:47 . 2008-05-16 21:25 ——– d—–w- c:\program files\Java 2010-01-25 12:00 . 2010-02-26 16:25 152576 —-a-w- c:\windows\system32\secproc_ssp_isv.dll 2010-01-25 12:00 . 2010-02-26 16:25 152064 —-a-w- c:\windows\system32\secproc_ssp.dll 2010-01-25 12:00 . 2010-02-26 16:25 471552 —-a-w- c:\windows\system32\secproc.dll 2010-01-25 11:58 . 2010-02-26 16:25 332288 —-a-w- c:\windows\system32\msdrm.dll 2010-01-25 08:21 . 2010-02-26 16:25 526336 —-a-w- c:\windows\system32\RMActivate_isv.exe 2010-01-25 08:21 . 2010-02-26 16:25 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2010-01-25 08:21 . 2010-02-26 16:25 518144 —-a-w- c:\windows\system32\RMActivate.exe 2010-01-25 08:21 . 2010-02-26 16:25 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe 2010-01-21 20:51 . 2008-11-05 22:20 ——– d—–w- c:\program files\Microsoft Silverlight 2010-01-06 15:39 . 2010-02-26 16:25 1696256 —-a-w- c:\windows\system32\gameux.dll 2010-01-06 15:38 . 2010-02-26 16:25 28672 —-a-w- c:\windows\system32\Apphlpdm.dll 2010-01-06 15:38 . 2010-02-26 16:25 173056 —-a-w- c:\windows\AppPatch\AcXtrnal.dll 2010-01-06 15:38 . 2010-02-26 16:25 542720 —-a-w- c:\windows\AppPatch\AcLayers.dll 2010-01-06 15:38 . 2010-02-26 16:25 458752 —-a-w- c:\windows\AppPatch\AcSpecfc.dll 2010-01-06 15:38 . 2010-02-26 16:25 2159616 —-a-w- c:\windows\AppPatch\AcGenral.dll 2010-01-06 13:30 . 2010-02-26 16:25 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-01-02 06:38 . 2010-02-27 11:32 916480 —-a-w- c:\windows\system32\wininet.dll 2010-01-02 06:32 . 2010-02-27 11:32 71680 —-a-w- c:\windows\system32\iesetup.dll 2010-01-02 06:32 . 2010-02-27 11:32 109056 —-a-w- c:\windows\system32\iesysprep.dll 2010-01-02 04:57 . 2010-02-27 11:32 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2009-12-17 17:14 . 2009-02-10 12:35 411368 —-a-w- c:\windows\system32\deploytk.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}] 2009-11-25 13:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-07-17 262144] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "Google Media Scanner"="c:\program files\Google\Google Media Server\GoogleMediaScanner.exe" [2009-09-11 319488] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-06 39408] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-02-18 2012912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\Apoint\Apoint.exe" [2008-02-23 122880] "RtHDVCpl"="RtHDVCpl.exe" [2008-04-29 6111232] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992] "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-04-04 317280] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440] "DLBTCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2007-02-12 73728] "dlbtmon.exe"="c:\program files\Dell Photo AIO Printer 922\dlbtmon.exe" [2007-02-28 431600] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608] "Skytel"="Skytel.exe" [2008-04-29 1826816] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2008-05-13 06:45 98304 —-a-w- c:\windows\System32\VESWinlogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AML] 2008-03-26 22:48 1093632 —-a-w- c:\program files\Sony\VAIO Launcher\AML.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo 1400 Series] 2007-08-02 05:00 182272 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIBUA.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] 2009-11-26 11:28 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MarketingTools] 2008-06-02 20:39 36864 —-a-w- c:\program files\Sony\Marketing Tools\MarketingTools.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-10 23:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2008-01-21 02:25 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(B):1e,66,8e,3b,ab,52,ca,01 R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2007-12-12 28464] R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-11-26 30192] R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2008-12-30 103040] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-17 12872] R3 UCharger;Energizer Usb Charger Driver;c:\windows\system32\Drivers\UCharger.sys [2007-05-15 13765] R4 SOHCImp;VAIO Media plus Content Importer;c:\program files\Sony\VAIO Media plus\SOHCImp.exe [2008-03-05 104288] R4 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Sony\VAIO Media plus\SOHDms.exe [2008-03-05 350048] R4 SOHDs;VAIO Media plus Device Searcher;c:\program files\Sony\VAIO Media plus\SOHDs.exe [2008-03-05 63328] R4 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2008-03-03 333088] R4 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2008-03-03 87328] S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-14 216200] S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-03-14 242696] S1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-02-27 390528] S1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [2010-02-25 58984] S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2010-02-25 108904] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-02-17 66632] S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-03-14 916760] S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-14 308064] S2 DCSHost.exe;DCSHost.exe;c:\programdata\DatacardService\DCSHost.exe [2009-05-19 110592] S2 Google MediaServer;Google MediaServer;c:\program files\Google\Google Media Server\GoogleMediaServer.exe [2009-09-11 622080] S2 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [2008-07-17 233472] S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2010-02-25 779496] S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032] S2 RtkHDMIService;RtkHDMIService;c:\windows\RtkAudioService.exe [2008-04-29 98304] S2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2007-11-10 104960] S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2008-04-24 411488] S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-01-31 17408] S3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2007-12-17 9344] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 getPlusHelper REG_MULTI_SZ getPlusHelper LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder 2010-03-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 13:30] 2010-03-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 13:30] 2010-03-14 c:\windows\Tasks\User_Feed_Synchronization-{2F590AE5-98F9-451C-B109-6DDF794A7FA1}.job - c:\windows\system32\msfeedssync.exe [2010-02-27 04:56] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.designhousestockholm.com/ uInternet Settings,ProxyOverride = *.local IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html . - - - - ORPHANS REMOVED - - - - Toolbar-Locked - (no file) SafeBoot-dmboot.sys SafeBoot-dmio.sys SafeBoot-dmload.sys SafeBoot-dmadmin SafeBoot-dmserver SafeBoot-SRService MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe AddRemove-{A33E457B-5369-481F-8B53-71108AE2EB5B} - c:\programdata\Uninstall\{A33E457B-5369-481F-8B53-71108AE2EB5B}\setup.exe ************************************************************************** scanning hidden processes … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLBTCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b4 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'Explorer.exe'(7816) c:\program files\Trusteer\Rapport\bin\rooksbas.dll c:\windows\system32\btncopy.dll . ———————— Other Running Processes ———————— . c:\windows\system32\WLANExt.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\dlbtcoms.exe c:\program files\Intel\WiFi\bin\EvtEng.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe c:\program files\Sony\VAIO Event Service\VESMgr.exe c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\windows\system32\DllHost.exe c:\program files\Sony\VAIO Event Service\VESMgrSub.exe c:\windows\system32\DllHost.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\windows\system32\WUDFHost.exe c:\program files\Sony\VAIO Power Management\SPMgr.exe c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe c:\windows\servicing\TrustedInstaller.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE . ************************************************************************** . Completion time: 2010-03-15 11:02:38 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-15 11:02 Pre-Run: 182,337,880,064 bytes free Post-Run: 182,261,190,656 bytes free - - End Of File - - 091A0FFB24335AC621BA2F7C95D4163D Very much looking forward to your reply, Marm.
Marm,

We are making progress. It looks like you had an Energizer USB Battery Charger installed on your system. In case you were not aware, it was recently discovered that the software for that charger has been identified as a potential security vulnerability. See this article for more information. I'm going to remove the driver and check to make sure the other files are gone as well. ComboFix removed the startup entry for your bluetooth device. If you would like me to restore that, plese let me know in your next post.

🖼Click to load external image (Posted Image) Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    Arucer.dll
    
    :folderfind
    Energizer UsbCharger
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above KillAll::

KillAll::

Driver::
UCharger

File::
c:\windows\system32\Drivers\UCharger.sys

Folder::
c:\users\Adam\AppData\Roaming\lowsec

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:
  • systemlook log
  • ComboFix log
  • How is your computer running
Hi RPMcMurphy,

Fantastic - I can't thank you enough for your time & effort in this matter! My PC seems to be running really well - of course I will wait untill you give me the all clear!

Just gotta say; What a brilliant web site this is & what a great service all you techs are providing! To the uninitiated, all the coded trappings of any pc is a veritable minefield so THANKS again for your help!!!

No need to worry about the start up enrty for my bluetooth devise - it's not needed right now & can always set that up again at a later date.

Marm.

Here are the logs that you have requested:

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 11:17 on 16/03/2010 by Adam (Administrator - Elevation successful)

========== filefind ==========

Searching for "Arucer.dll"
No files found.

========== folderfind ==========

Searching for "Energizer UsbCharger"
No folders found.

-=End Of File=-



ComboFix 10-03-14.06 - Adam 16/03/2010 11:27:53.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3069.1828 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Adam\Desktop\CFScript.txt
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\system32\Drivers\UCharger.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Adam\AppData\Roaming\lowsec
c:\users\Adam\AppData\Roaming\lowsec\local.ds
c:\users\Adam\AppData\Roaming\lowsec\user.ds
c:\users\Adam\AppData\Roaming\lowsec\user.ds.lll
c:\windows\system32\Drivers\UCharger.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UCharger


((((((((((((((((((((((((( Files Created from 2010-02-16 to 2010-03-16 )))))))))))))))))))))))))))))))
.

2010-03-16 11:32 . 2010-03-16 11:40 ——– d—–w- c:\users\Adam\AppData\Local\temp
2010-03-16 11:32 . 2010-03-16 11:32 ——– d—–w- c:\users\Sofie\AppData\Local\temp
2010-03-16 11:32 . 2010-03-16 11:32 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-03-14 08:33 . 2010-03-14 08:33 ——– d—–w- c:\users\Adam\AppData\Local\Adobe
2010-03-14 08:33 . 2010-03-14 08:33 ——– d—–w- c:\users\Adam\AppData\Local\Apple Computer
2010-03-14 01:43 . 2010-03-14 01:43 360584 —-a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-03-14 01:43 . 2010-03-14 01:43 333192 —-a-w- c:\programdata\avg9\update\backup\avgldx86.sys
2010-03-14 01:43 . 2010-03-14 01:43 28424 —-a-w- c:\programdata\avg9\update\backup\avgmfx86.sys
2010-03-14 01:43 . 2010-03-14 01:43 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-14 00:52 . 2010-03-14 00:52 ——– d—–w- c:\users\Adam\AppData\Roaming\Malwarebytes
2010-03-14 00:52 . 2010-01-07 16:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-14 00:52 . 2010-03-14 00:52 ——– d—–w- c:\programdata\Malwarebytes
2010-03-14 00:52 . 2010-03-14 00:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-14 00:52 . 2010-01-07 16:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-13 21:57 . 2010-03-13 21:57 ——– d—–w- c:\program files\Trend Micro
2010-03-13 12:38 . 2010-03-13 12:38 52224 —-a-w- c:\users\Adam\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-13 12:38 . 2010-03-13 12:38 117760 —-a-w- c:\users\Adam\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-13 12:37 . 2010-03-13 12:37 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2010-03-13 12:37 . 2010-03-13 12:37 ——– d—–w- c:\users\Adam\AppData\Roaming\SUPERAntiSpyware.com
2010-03-13 12:37 . 2010-03-13 12:37 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-03-13 12:36 . 2010-03-13 12:36 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-03-11 12:45 . 2010-03-11 12:45 ——– d-sh–w- c:\windows\system32\%APPDATA%
2010-03-11 12:44 . 2010-02-20 23:06 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-03-11 12:44 . 2010-02-20 23:05 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-03-11 12:44 . 2010-02-20 20:53 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-03-11 02:26 . 2007-02-18 21:11 296960 —-a-w- c:\windows\winhlp32.exe
2010-03-11 02:26 . 2007-02-18 21:11 194560 —-a-w- c:\windows\system32\ftsrch.dll
2010-03-11 02:26 . 2007-02-18 21:11 9728 —-a-w- c:\windows\system32\ftlx041e.dll
2010-03-11 02:26 . 2007-02-18 21:11 9216 —-a-w- c:\windows\system32\ftlx0411.dll
2010-03-06 23:07 . 2010-03-06 23:07 1232496 —-a-w- c:\programdata\Google\Google Toolbar\Component\GoogleCld_D9AEC8D4D1915047.dll
2010-03-03 01:46 . 2010-03-03 01:46 ——– d—–w- c:\windows\system32\freecom
2010-03-02 20:06 . 2010-03-02 20:06 ——– d—–w- c:\users\Sofie\AppData\Roaming\Trusteer
2010-02-27 12:02 . 2010-02-27 12:02 390528 —-a-w- c:\windows\system32\drivers\RapportBuka.sys
2010-02-27 12:02 . 2010-02-27 12:02 390528 —-a-w- c:\programdata\Trusteer\Rapport\store\exts\RapportBukaBroom\13897\RapportBuka.sys
2010-02-27 12:02 . 2010-02-27 12:02 249856 —-a-w- c:\programdata\Trusteer\Rapport\store\exts\RapportBukaBroom\13897\RapportBukaBroom.dll
2010-02-27 11:20 . 2010-02-27 11:20 ——– d—–w- c:\users\Adam\AppData\Roaming\Trusteer
2010-02-27 11:20 . 2010-02-27 11:20 ——– d—–w- c:\program files\Trusteer
2010-02-27 11:19 . 2010-02-27 11:19 ——– d—–w- c:\programdata\Trusteer
2010-02-26 23:20 . 2010-02-26 23:20 ——– d—–w- c:\program files\Windows Portable Devices
2010-02-26 23:18 . 2009-10-01 01:02 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-02-26 22:21 . 2010-02-26 22:22 ——– d—–w- c:\windows\system32\ca-ES
2010-02-26 22:21 . 2010-02-26 22:22 ——– d—–w- c:\windows\system32\eu-ES
2010-02-26 22:21 . 2010-02-26 22:22 ——– d—–w- c:\windows\system32\vi-VN
2010-02-26 22:18 . 2010-02-26 22:18 ——– d—–w- c:\windows\system32\SPReview
2010-02-26 22:10 . 2009-04-10 23:28 928768 —-a-w- c:\windows\system32\scavenge.dll
2010-02-26 22:10 . 2009-04-10 23:27 57856 —-a-w- c:\windows\system32\compcln.exe
2010-02-26 22:04 . 2009-04-10 23:28 87040 —-a-w- c:\windows\system32\mssitlb.dll
2010-02-26 16:25 . 2010-01-25 12:00 471552 —-a-w- c:\windows\system32\secproc_isv.dll
2010-02-25 14:44 . 2010-02-12 10:32 293376 —-a-w- c:\windows\system32\browserchoice.exe
2010-02-23 23:39 . 2010-02-23 23:39 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-23 20:20 . 2010-01-23 09:26 2048 —-a-w- c:\windows\system32\tzres.dll
2010-02-22 12:44 . 2010-02-22 12:44 ——– d—–w- c:\program files\iPod
2010-02-22 12:44 . 2010-02-22 12:44 ——– d—–w- c:\program files\iTunes
2010-02-22 12:44 . 2010-02-22 12:44 ——– d—–w- c:\program files\Bonjour
2010-02-21 14:37 . 2010-02-21 14:37 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2010-02-20 23:49 . 2010-02-20 23:49 ——– d—–w- c:\program files\7-Zip
2010-02-20 08:34 . 2005-04-13 16:36 ——– d—–w- c:\users\Public\Photoshop CS2
2010-02-19 10:19 . 2010-02-19 10:19 ——– d—–w- c:\windows\Sun
2010-02-19 02:26 . 2010-02-19 02:26 ——– d—–w- c:\programdata\Adobe Systems
2010-02-19 02:20 . 2010-02-20 20:07 ——– d—–w- c:\program files\Common Files\Adobe Systems Shared
2010-02-18 20:54 . 2007-03-23 04:05 29272 —-a-r- c:\windows\system32\AdobePDF.dll
2010-02-15 18:41 . 2010-02-15 18:41 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-16 11:32 . 2008-05-16 19:41 2140 —-a-w- c:\windows\bthservsdp.dat
2010-03-16 11:09 . 2008-11-10 13:02 ——– d—–w- c:\program files\Dl_cats
2010-03-15 11:26 . 2008-06-02 20:18 ——– d—–w- c:\programdata\Microsoft Help
2010-03-15 11:26 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-03-14 01:43 . 2009-10-22 12:22 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-14 01:43 . 2009-10-22 12:22 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-14 01:43 . 2009-10-22 12:22 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-13 14:03 . 2008-11-04 18:39 1356 —-a-w- c:\users\Adam\AppData\Local\d3d9caps.dat
2010-03-11 02:00 . 2008-06-02 20:42 ——– d—–w- c:\programdata\Uninstall
2010-03-08 14:46 . 2008-11-04 18:39 121656 —-a-w- c:\users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-06 23:07 . 2008-05-16 20:07 ——– d—–w- c:\program files\Google
2010-03-04 15:15 . 2009-10-22 12:21 ——– d—–w- c:\programdata\avg9
2010-02-27 07:24 . 2008-05-16 21:24 ——– d—–w- c:\programdata\FLEXnet
2010-02-27 07:02 . 2008-04-22 00:20 312344 —-a-w- c:\windows\system32\drivers\iaStor.sys
2010-02-26 23:20 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2010-02-26 22:22 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2010-02-26 17:17 . 2010-02-26 17:17 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-02-25 14:23 . 2008-05-16 21:23 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-22 12:44 . 2008-11-04 18:52 ——– d—–w- c:\program files\Common Files\Apple
2010-02-21 15:29 . 2009-02-24 12:47 ——– d—–w- c:\programdata\NOS
2010-02-20 20:08 . 2008-05-16 20:26 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-10 12:57 . 2010-02-10 12:57 ——– d—–w- c:\programdata\WindowsSearch
2010-02-04 10:45 . 2010-02-04 10:44 ——– d—–w- c:\program files\QuickTime
2010-02-02 12:33 . 2010-02-02 12:33 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbF96D.tmp.exe
2010-01-28 01:01 . 2008-05-16 21:25 ——– d—–w- c:\program files\Common Files\Java
2010-01-27 23:47 . 2008-05-16 21:25 ——– d—–w- c:\program files\Java
2010-01-25 12:00 . 2010-02-26 16:25 152576 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-26 16:25 152064 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-26 16:25 471552 —-a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-26 16:25 332288 —-a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-26 16:25 526336 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-26 16:25 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-26 16:25 518144 —-a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-26 16:25 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-21 20:51 . 2008-11-05 22:20 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-06 15:39 . 2010-02-26 16:25 1696256 —-a-w- c:\windows\system32\gameux.dll
2010-01-06 15:38 . 2010-02-26 16:25 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2010-01-06 15:38 . 2010-02-26 16:25 173056 —-a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-26 16:25 542720 —-a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-06 15:38 . 2010-02-26 16:25 458752 —-a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-26 16:25 2159616 —-a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 13:30 . 2010-02-26 16:25 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-01-02 06:38 . 2010-02-27 11:32 916480 —-a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-02-27 11:32 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-02-27 11:32 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-02-27 11:32 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-17 17:14 . 2009-02-10 12:35 411368 —-a-w- c:\windows\system32\deploytk.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 13:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-07-17 262144]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Google Media Scanner"="c:\program files\Google\Google Media Server\GoogleMediaScanner.exe" [2009-09-11 319488]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-06 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-02-18 2012912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2008-02-23 122880]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-29 6111232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-04-04 317280]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"DLBTCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2007-02-12 73728]
"dlbtmon.exe"="c:\program files\Dell Photo AIO Printer 922\dlbtmon.exe" [2007-02-28 431600]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"Skytel"="Skytel.exe" [2008-04-29 1826816]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2008-05-13 06:45 98304 —-a-w- c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AML]
2008-03-26 22:48 1093632 —-a-w- c:\program files\Sony\VAIO Launcher\AML.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo 1400 Series]
2007-08-02 05:00 182272 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIBUA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2009-11-26 11:28 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MarketingTools]
2008-06-02 20:39 36864 —-a-w- c:\program files\Sony\Marketing Tools\MarketingTools.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 23:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):1e,66,8e,3b,ab,52,ca,01

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2007-12-12 28464]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-11-26 30192]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2008-12-30 103040]
R4 SOHCImp;VAIO Media plus Content Importer;c:\program files\Sony\VAIO Media plus\SOHCImp.exe [2008-03-05 104288]
R4 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Sony\VAIO Media plus\SOHDms.exe [2008-03-05 350048]
R4 SOHDs;VAIO Media plus Device Searcher;c:\program files\Sony\VAIO Media plus\SOHDs.exe [2008-03-05 63328]
R4 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2008-03-03 333088]
R4 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2008-03-03 87328]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-14 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-03-14 242696]
S1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-02-27 390528]
S1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [2010-02-25 58984]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2010-02-25 108904]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-02-17 66632]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-03-14 916760]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-14 308064]
S2 DCSHost.exe;DCSHost.exe;c:\programdata\DatacardService\DCSHost.exe [2009-05-19 110592]
S2 Google MediaServer;Google MediaServer;c:\program files\Google\Google Media Server\GoogleMediaServer.exe [2009-09-11 622080]
S2 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [2008-07-17 233472]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2010-02-25 779496]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S2 RtkHDMIService;RtkHDMIService;c:\windows\RtkAudioService.exe [2008-04-29 98304]
S2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2007-11-10 104960]
S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2008-04-24 411488]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-01-31 17408]
S3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-17 12872]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2007-12-17 9344]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
getPlusHelper REG_MULTI_SZ getPlusHelper
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 13:30]

2010-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 13:30]

2010-03-14 c:\windows\Tasks\User_Feed_Synchronization-{2F590AE5-98F9-451C-B109-6DDF794A7FA1}.job
- c:\windows\system32\msfeedssync.exe [2010-02-27 04:56]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.designhousestockholm.com/
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-16 11:40
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBTCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b4

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(8244)
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlbtcoms.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\windows\system32\DllHost.exe
c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\WUDFHost.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2010-03-16 11:43:42 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-16 11:43
ComboFix2.txt 2010-03-15 11:02

Pre-Run: 179,988,082,688 bytes free
Post-Run: 179,898,609,664 bytes free

- - End Of File - - 70BBDC3011C27C628B096FAA076C954A
Marm,

You're welcome. Let's run these two scans to be sure we have everything:

🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • MBAM log
  • Kaspersky log
Here are the log reports of the last two scans: Malwarebytes' Anti-Malware 1.44 Database version: 3874 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18882 17/03/2010 00:43:22 mbam-log-2010-03-17 (00-43-22).txt Scan type: Full Scan (C:\|D:\|E:\|F:\|) Objects scanned: 289441 Time elapsed: 1 hour(s), 17 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, March 17, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, March 16, 2010 20:39:39 Records in database: 3814253 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 153025 Threats found: 3 Infected objects found: 3 Suspicious objects found: 0 Scan duration: 02:16:00 File name / Threat / Threats count C:\Qoobox\Quarantine\C\Windows\System32\drivers\iaStor.sys.vir Infected: Rootkit.Win32.Tdss.ai 1 C:\Users\Adam\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\5c244c96-72e97954 Infected: Exploit.OSX.Smid.c 1 C:\Users\Adam\Downloads\Program Aplications\Adobe.Photoshop.Plugins.Professional.45026.exe Infected: Packed.Win32.Krap.as 1 Selected area has been scanned.
Marm,

I'll clean those last two detections up for you (the other one is already in quarantine), then your PC looks clean:

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Users\Adam\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\5c244c96-72e97954
    C:\Users\Adam\Downloads\Program Aplications\Adobe.Photoshop.Plugins.Professional.45026.exe
    
    :Commands
    [emptytemp]
    [EMPTYFLASH]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
Next you have some important cleanup and housekeeping to tend to:

🖼Click to load external image (Posted Image) Delete your outdated versions of JAVA
  • Go to Start > control Panel > Add/Remove Programs
  • Remove these two programs:
    Java™ 6 Update 4
    Java™ 6 Update 7
🖼Click to load external image (Posted Image) Go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
🖼Click to load external image (Posted Image) Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens:
    Combofix /Uninstall
🖼Click to load external image (Posted Image)

🖼Click to load external image (Posted Image) Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Manually delete any remaining logs or tools.
🖼Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Consider running in a limited user account. See this post for more information.
  • Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!
Hi RPMcMurphy, Again, thanks for all your help. Suggestions noted! It seems that I may have to go through all this & possibly more with my partners laptop?! Here is the final OTL log report: All processes killed ========== FILES ========== File\Folder C:\Users\Adam\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\5c244c96-72e97954 not found. File\Folder C:\Users\Adam\Downloads\Program Aplications\Adobe.Photoshop.Plugins.Professional.45026.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: Adam ->Temp folder emptied: 6255804 bytes ->Temporary Internet Files folder emptied: 438826721 bytes ->Java cache emptied: 5055 bytes ->Flash cache emptied: 6314 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 198 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: Sofie ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Java cache emptied: 31579021 bytes ->Flash cache emptied: 908 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 168 bytes RecycleBin emptied: 1555 bytes Total Files Cleaned = 455.00 mb [EMPTYFLASH] User: Adam ->Flash cache emptied: 0 bytes User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Public User: Sofie ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.1.37.1 log created on 03172010_094303 Files\Folders moved on Reboot… Registry entries deleted on Reboot… Marm.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI