This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect Virus

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello there,

I have been infected with the Google Redirect Virus, not only on my desktop computer but on my laptop as well. There is another computer on my home network that has also been infected (thank goodness my server is unaffected). I do consider myself somewhat computer savvy, but this one has me stumped. While assisting me with this problem (and thank you so much for offering your time and expertise), would it be possible to explain each step and its purpose in as much detail as possible? I am an IT student and am always eager to learn more. Also, it would enable me to clean up my laptop and the other computer in my home network without bothering you good people.

Thank you so much.

Here is the requested information:

DDS.txt


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 18:02:00.73 on Fri 03/19/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1454 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\WallpaperSSPro\WallpaperSS.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Allyson Whitney\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AdobeBridge]
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [nvmcdb97] rundll32.exe "c:\documents and settings\allyson whitney\local settings\application data\nvmcdb97\nvmcdb97.dll", DllInit
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [HitmanPro35] "c:\program files\hitman pro 3.5\HitmanPro35.exe" /scan:boot
StartupFolder: c:\docume~1\allyso~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1268242024359
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\allyso~1\applic~1\mozilla\firefox\profiles\2wm9dp5t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-3-10 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-3-10 29512]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-10 308064]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2010-3-10 30192]

=============== Created Last 30 ================

2010-03-19 17:45 –d—– c:\program files\Trend Micro
2010-03-19 15:43 –d—– c:\docume~1\allyso~1\applic~1\Malwarebytes
2010-03-19 15:43 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-19 15:43 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-19 15:43 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-19 15:43 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-19 13:18 12,872 a——- c:\windows\system32\bootdelete.exe
2010-03-19 13:11 15,944 a——- c:\windows\system32\drivers\hitmanpro35.sys
2010-03-19 13:11 –d—– c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-03-19 13:11 –d—– c:\program files\Hitman Pro 3.5
2010-03-17 13:22 –d—– c:\program files\Smart Diary Suite 4
2010-03-15 18:45 56 a—h— c:\windows\system32\ezsidmv.dat
2010-03-15 18:34 –d–r– c:\program files\Skype
2010-03-15 18:31 –d—– c:\program files\Fantasy Grounds II
2010-03-15 18:31 –d—– c:\docume~1\allyso~1\applic~1\Fantasy Grounds II
2010-03-15 16:28 18,448 a——- c:\windows\system32can4d
2010-03-14 11:43 –d—– C:\Temp
2010-03-13 15:20 –d—– c:\program files\DivX
2010-03-13 15:20 –d—– c:\program files\common files\DivX Shared
2010-03-13 15:12 8 a——- c:\windows\system32\nvModes.dat
2010-03-11 15:37 –d-h— C:\BJPrinter
2010-03-11 15:37 116,736 a——- c:\windows\system32\CNMLM6s.DLL
2010-03-11 15:37 7,680 a——- c:\windows\system32\CNMVS6s.DLL
2010-03-11 15:37 25,856 ac—— c:\windows\system32\dllcache\usbprint.sys
2010-03-11 15:37 25,856 a——- c:\windows\system32\drivers\usbprint.sys
2010-03-11 15:37 15,104 ac—— c:\windows\system32\dllcache\usbscan.sys
2010-03-11 15:37 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2010-03-11 15:36 –d—– c:\program files\Canon
2010-03-11 15:36 557,056 a——- c:\windows\system32\CNCC130.DLL
2010-03-11 15:36 94,208 a——- c:\windows\system32\CNCL130.DLL
2010-03-11 15:36 90,112 a——- c:\windows\system32\CNCI130.DLL
2010-03-11 15:36 389,180 a——- c:\windows\system32\UCS32P.DLL
2010-03-11 15:36 49,152 a——- c:\windows\system32\cncisco.dll
2010-03-11 15:36 –d-h— C:\CanonMP
2010-03-11 15:29 26,368 ac—— c:\windows\system32\dllcache\usbstor.sys
2010-03-11 15:27 –d—– c:\program files\Jasc Software Inc
2010-03-11 15:23 –d—– c:\program files\common files\SWF Studio
2010-03-11 15:21 –d—– c:\docume~1\allyso~1\applic~1\WallpaperSSPro
2010-03-11 15:21 –d—– c:\program files\WallpaperSSPro
2010-03-11 13:01 348,160 a——- c:\windows\eSellerateEngine.dll
2010-03-11 13:01 –d—– c:\program files\JJS
2010-03-11 02:12 664 a——- c:\windows\system32\d3d9caps.dat
2010-03-10 21:33 –d—– c:\program files\common files\Macrovision Shared
2010-03-10 20:43 –d—– c:\docume~1\allyso~1\applic~1\BitTorrent
2010-03-10 20:42 –d—– c:\program files\BitTorrent
2010-03-10 19:08 691,696 a——- c:\windows\system32\drivers\sptd.sys
2010-03-10 19:08 –d—– c:\program files\DAEMON Tools Lite
2010-03-10 19:08 –d—– c:\docume~1\allyso~1\applic~1\DAEMON Tools Lite
2010-03-10 19:07 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2010-03-10 18:52 30,512 a——- c:\windows\system32\mdimon.dll
2010-03-10 18:52 32,592 a——- c:\windows\system32\msonpmon.dll
2010-03-10 18:49 –d—– c:\windows\SHELLNEW
2010-03-10 18:26 –d—– c:\windows\system32\Adobe
2010-03-10 18:05 411,368 a——- c:\windows\system32\deploytk.dll
2010-03-10 18:05 73,728 a——- c:\windows\system32\javacpl.cpl
2010-03-10 16:10 –d-h— C:\$AVG
2010-03-10 16:10 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-03-10 16:10 –d—– c:\windows\system32\drivers\Avg
2010-03-10 16:10 216,200 a——- c:\windows\system32\drivers\avgldx86.sys
2010-03-10 16:10 –d—– c:\program files\AVG
2010-03-10 16:10 –d—– c:\docume~1\alluse~1\applic~1\avg9
2010-03-10 15:47 –dsh— c:\documents and settings\allyson whitney\IECompatCache
2010-03-10 15:47 –dsh— c:\documents and settings\allyson whitney\PrivacIE
2010-03-10 15:29 –dsh— c:\documents and settings\allyson whitney\IETldCache
2010-03-10 15:28 31,056 a——- c:\windows\system32\BMXStateBkp-{00000000-00000000-0000000A-00001102-00000004-20021102}.rfx
2010-03-10 15:28 31,056 a——- c:\windows\system32\BMXState-{00000000-00000000-0000000A-00001102-00000004-20021102}.rfx
2010-03-10 15:28 30,528 a——- c:\windows\system32\BMXCtrlState-{00000000-00000000-0000000A-00001102-00000004-20021102}.rfx
2010-03-10 15:28 30,528 a——- c:\windows\system32\BMXBkpCtrlState-{00000000-00000000-0000000A-00001102-00000004-20021102}.rfx
2010-03-10 15:28 11,564 a——- c:\windows\system32\DVCState-{00000000-00000000-0000000A-00001102-00000004-20021102}.rfx
2010-03-10 15:28 4,958,588 a——- c:\windows\{00000000-00000000-0000000A-00001102-00000004-20021102}.BAK
2010-03-10 15:11 –d—– c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2010-03-10 15:11 –d—– c:\program files\NVIDIA Corporation
2010-03-10 13:56 –d—– c:\windows\system32\XPSViewer
2010-03-10 13:55 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2010-03-10 13:55 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-10 13:55 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-10 13:55 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-10 13:55 –d—– C:\bb12aeed81744ad80835daf4
2010-03-10 13:55 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2010-03-10 13:55 575,488 ——– c:\windows\system32\xpsshhdr.dll
2010-03-10 13:55 117,760 ——– c:\windows\system32\prntvpt.dll
2010-03-10 13:47 –d—– c:\program files\Windows Media Connect 2
2010-03-10 13:45 –d—– c:\windows\system32\URTTemp
2010-03-10 13:44 455,424 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2010-03-10 13:35 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2010-03-10 13:35 272,128 ——– c:\windows\system32\drivers\bthport.sys
2010-03-10 13:29 26,144 a——- c:\windows\system32\spupdsvc.exe
2010-03-10 13:29 –d—– c:\windows\system32\PreInstall
2010-03-10 13:29 –d-h— c:\windows\$hf_mig$
2010-03-10 13:27 21,728 a——- c:\windows\system32\wucltui.dll.mui
2010-03-10 13:27 17,632 a——- c:\windows\system32\wuaueng.dll.mui
2010-03-10 13:27 15,072 a——- c:\windows\system32\wuaucpl.cpl.mui
2010-03-10 13:27 15,064 a——- c:\windows\system32\wuapi.dll.mui
2010-03-10 13:27 –d—– c:\windows\system32\SoftwareDistribution
2010-03-10 13:27 –dsh— c:\documents and settings\allyson whitney\UserData
2010-03-10 13:26 –d—– c:\documents and settings\Allyson Whitney
2010-03-10 13:22 –ds—- c:\windows\system32\Microsoft
2010-03-10 13:22 8,192 a——- c:\windows\REGLOCS.OLD
2010-03-10 13:19 21,896 ac—— c:\windows\system32\dllcache\tdipx.sys
2010-03-10 13:18 92,416 ac—— c:\windows\system32\dllcache\mga.sys
2010-03-10 13:17 78,848 ac—— c:\windows\system32\dllcache\dayi.ime
2010-03-10 13:16 133,632 ac—— c:\windows\system32\dllcache\iisrtl.dll
2010-03-10 13:14 –dsh— c:\documents and settings\all users\DRM
2010-03-10 13:14 488 a—hr– c:\windows\system32\WindowsLogon.manifest
2010-03-10 13:14 488 a—hr– c:\windows\system32\logonui.exe.manifest
2010-03-10 13:14 –ds—- c:\windows\Downloaded Program Files
2010-03-10 13:14 –d–r– c:\windows\Offline Web Pages
2010-03-10 13:13 –d-h— c:\program files\WindowsUpdate
2010-03-10 13:13 –d—– c:\program files\common files\MSSoap
2010-03-10 13:10 –d—– c:\program files\Messenger
2010-03-10 13:10 –d—– c:\program files\MSN Gaming Zone
2010-03-10 13:10 –d—– c:\program files\Windows NT
2010-03-10 08:01 –d—– c:\program files\common files\ODBC
2010-03-10 08:01 –d—– c:\program files\common files\SpeechEngines
2010-03-10 08:00 –d–r– c:\documents and settings\all users\Documents

==================== Find3M ====================

2010-03-10 22:37 73,312 a——- c:\windows\system32\drivers\adfs.sys
2010-03-10 14:28 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-03-10 13:46 409,600 a——- c:\windows\system32\wrap_oal.dll
2010-03-10 13:46 114,688 a——- c:\windows\system32\OpenAL32.dll
2010-03-10 13:11 21,640 a——- c:\windows\system32\emptyregdb.dat
2010-03-09 15:03 1,614,848 a——- c:\windows\system32\sfcfiles.dll
2010-03-09 15:03 73,600 a——- c:\windows\system32\drivers\viamraid.sys
2010-01-30 23:14 990,208 a——- c:\windows\system32\syssetup.dll
2010-01-18 02:30 348,160 a——- c:\windows\system32\msvcr71.dll
2010-01-18 02:30 499,712 a——- c:\windows\system32\msvcp71.dll
2010-01-12 13:03 14,458,880 a——- c:\windows\system32\nvoglnt.dll
2010-01-12 13:03 11,632,640 a——- c:\windows\system32\nvcompiler.dll
2010-01-12 13:03 6,359,168 a——- c:\windows\system32\nv4_disp.dll
2010-01-12 13:03 4,104,192 a——- c:\windows\system32\nvcuda.dll
2010-01-12 13:03 4,077,672 a——- c:\windows\system32\nvcuvenc.dll
2010-01-12 13:03 2,283,526 a——- c:\windows\system32\nvdata.bin
2010-01-12 13:03 2,259,560 a——- c:\windows\system32\nvcuvid.dll
2010-01-12 13:03 1,081,344 a——- c:\windows\system32\nvapi.dll
2010-01-12 13:03 182,888 a——- c:\windows\system32\nvcodins.dll
2010-01-12 13:03 182,888 a——- c:\windows\system32\nvcod.dll
2010-01-12 13:03 61,440 a——- c:\windows\system32\OpenCL.dll
2010-01-11 23:17 13,666,408 a——- c:\windows\system32\nvcpl.dll
2010-01-11 23:17 278,120 a——- c:\windows\system32\nvmccs.dll
2010-01-11 23:17 154,216 a——- c:\windows\system32\nvsvc32.exe
2010-01-11 23:17 145,000 a——- c:\windows\system32\nvcolor.exe
2010-01-11 23:17 110,696 a——- c:\windows\system32\nvmctray.dll
2010-01-11 23:17 81,920 a——- c:\windows\system32\nvwddi.dll
2009-12-22 01:20 81,920 ——– c:\windows\system32\ieencode.dll
2009-12-21 15:14 916,480 a——- c:\windows\system32\wininet.dll

============= FINISH: 18:02:22.20 ===============

gmer.txt


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-20 10:45:31
Windows 5.1.2600 Service Pack 3
Running: xuposroi.exe; Driver: C:\DOCUME~1\ALLYSO~1\LOCALS~1\Temp\axrdapow.sys


—- System - GMER 1.0.15 —-

SSDT spge.sys ZwCreateKey [0xF74E40E0]
SSDT spge.sys ZwEnumerateKey [0xF74FCDA4]
SSDT spge.sys ZwEnumerateValueKey [0xF74FD132]
SSDT spge.sys ZwOpenKey [0xF74E40C0]
SSDT spge.sys ZwQueryKey [0xF74FD20A]
SSDT spge.sys ZwQueryValueKey [0xF74FD08A]
SSDT spge.sys ZwSetValueKey [0xF74FD29C]

INT 0x62 ? 8A64FBF8
INT 0x73 ? 8A652BF8
INT 0x82 ? 8A64FBF8
INT 0xA4 ? 8A376E98
INT 0xA4 ? 8A376E98
INT 0xA4 ? 8A376E98
INT 0xA4 ? 8A376E98
INT 0xA4 ? 8A376E98
INT 0xA4 ? 8A376E98

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8A5DF1F8
Device \FileSystem\Fastfat \FatCdrom 8A3BD500
Device \Driver\usbuhci \Device\USBPDO-0 8A3E0500
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A5E11F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A5E11F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A5E11F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A5E11F8
Device \Driver\usbuhci \Device\USBPDO-1 8A3E0500
Device \Driver\usbuhci \Device\USBPDO-2 8A3E0500
Device \Driver\usbuhci \Device\USBPDO-3 8A3E0500
Device \Driver\usbehci \Device\USBPDO-4 8A1A81F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6501F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A6501F8
Device \Driver\Cdrom \Device\CdRom0 8A1F3500
Device \Driver\Cdrom \Device\CdRom1 8A1F3500
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\NetBT \Device\NetBt_Wins_Export 8971F1F8
Device \Driver\PCI_PNP6448 \Device\0000004a spge.sys
Device \Driver\PCI_PNP6448 \Device\0000004a spge.sys
Device \Driver\NetBT \Device\NetbiosSmb 8971F1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{057F1B9E-B576-4889-8490-374D64CBCED2} 8971F1F8
Device \Driver\usbuhci \Device\USBFDO-0 8A3E0500
Device \Driver\USBSTOR \Device\0000007a 8A3BA1F8
Device \Driver\usbuhci \Device\USBFDO-1 8A3E0500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 897161F8
Device \Driver\usbuhci \Device\USBFDO-2 8A3E0500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 897161F8
Device \Driver\USBSTOR \Device\0000007c 8A3BA1F8
Device \Driver\usbuhci \Device\USBFDO-3 8A3E0500
Device \Driver\sptd \Device\645233948 spge.sys
Device \Driver\usbehci \Device\USBFDO-4 8A1A81F8
Device \Driver\Ftdisk \Device\FtControl 8A6501F8
Device \Driver\viamraid \Device\Scsi\viamraid1 8A5E01F8
Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 8A5E01F8
Device \Driver\ane6hon1 \Device\Scsi\ane6hon11Port3Path0Target0Lun0 8A1AF1F8
Device \Driver\ane6hon1 \Device\Scsi\ane6hon11 8A1AF1F8
Device \FileSystem\Fastfat \Fat 8A3BD500

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 8A3B4500

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC5 0x10 0xBF 0x79 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x15 0xA6 0xE1 0x80 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xED 0x69 0xE3 0xE9 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC5 0x10 0xBF 0x79 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x15 0xA6 0xE1 0x80 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xED 0x69 0xE3 0xE9 …

—- EOF - GMER 1.0.15 —-

Also, here is the HijackThis text for reference.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:45:14 PM, on 3/19/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\WallpaperSSPro\WallpaperSS.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [HitmanPro35] "C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe" /scan:boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [nvmcdb97] rundll32.exe "C:\Documents and Settings\Allyson Whitney\Local Settings\Application Data\nvmcdb97\nvmcdb97.dll", DllInit
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1268242024359
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5712 bytes

Attachments:

Hi ladykrimson, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Please disconnect the other infected computers from your network. We don't want to the possibly of them reinfecting this one. We can look at the others once we are finished with this one.

As these forums are monitored by malware authors, I will not be able to tell you much about how the tools we will use work. It looks like you may be infected with a disk controller hijacker.

You have a program that may cause false reading in some of the tools. We will disable some drivers until we are finished cleaning this machine.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
I believe this is the correct file?

ComboFix 10-03-20.06 - Allyson Whitney 03/21/2010 15:52:54.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1558 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\jgh.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\sfcfiles.dll

.
((((((((((((((((((((((((( Files Created from 2010-02-21 to 2010-03-21 )))))))))))))))))))))))))))))))
.

2010-03-21 19:12 . 2010-03-21 19:52 ——– d—–w- C:\ComboFix
2010-03-20 23:37 . 2010-03-20 23:38 139502 —-a-w- C:\MGlogs.zip
2010-03-20 23:37 . 2010-03-20 23:38 ——– d—–w- C:\MGtools
2010-03-20 23:37 . 2010-03-20 21:55 2388938 —-a-w- C:\MGtools.exe
2010-03-20 21:57 . 2010-03-20 21:57 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-20 21:57 . 2010-03-21 18:56 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\SUPERAntiSpyware.com
2010-03-20 21:57 . 2010-03-21 18:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-03-20 21:42 . 2010-03-20 21:42 ——– d—–w- c:\program files\CCleaner
2010-03-19 21:55 . 2010-03-19 21:55 ——– d—–w- c:\program files\ERUNT
2010-03-19 21:45 . 2010-03-19 21:45 ——– d—–w- c:\program files\Trend Micro
2010-03-19 19:43 . 2010-03-19 19:43 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Malwarebytes
2010-03-19 19:43 . 2010-03-19 19:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-19 19:43 . 2010-03-21 18:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-19 17:18 . 2010-03-19 17:18 12872 —-a-w- c:\windows\system32\bootdelete.exe
2010-03-19 17:11 . 2010-03-20 22:38 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-03-19 17:11 . 2010-03-19 17:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-03-19 17:11 . 2010-03-19 17:11 ——– d—–w- c:\program files\Hitman Pro 3.5
2010-03-19 16:56 . 2010-03-19 16:56 ——– d—–w- c:\windows\Sun
2010-03-17 17:22 . 2010-03-17 17:23 ——– d—–w- c:\program files\Smart Diary Suite 4
2010-03-17 17:22 . 2010-03-20 23:04 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\nvmcdb97
2010-03-15 22:45 . 2010-03-15 22:45 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-03-15 22:36 . 2010-03-21 16:32 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\skypePM
2010-03-15 22:34 . 2010-03-21 19:12 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–w- c:\program files\Common Files\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–r- c:\program files\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2010-03-15 22:31 . 2010-03-18 19:06 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Fantasy Grounds II
2010-03-15 22:31 . 2010-03-15 23:34 ——– d—–w- c:\program files\Fantasy Grounds II
2010-03-14 15:43 . 2010-03-15 04:06 ——– d—–w- C:\Temp
2010-03-13 19:12 . 2010-03-13 21:03 8 —-a-w- c:\windows\system32\nvModes.dat
2010-03-12 11:26 . 2008-04-14 08:42 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2010-03-11 19:37 . 2010-03-11 19:37 ——– d—–w- C:\BJPrinter
2010-03-11 19:37 . 2004-08-17 10:00 7680 —-a-w- c:\windows\system32\CNMVS6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 54272 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 17920 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 116736 —-a-w- c:\windows\system32\CNMLM6s.DLL
2010-03-11 19:37 . 2008-04-14 05:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-03-11 19:37 . 2008-04-14 05:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2010-03-11 19:37 . 2008-04-14 05:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-03-11 19:37 . 2008-04-14 05:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-03-11 19:36 . 2010-03-11 19:36 ——– d—–w- c:\program files\Canon
2010-03-11 19:36 . 2004-10-26 19:03 557056 —-a-w- c:\windows\system32\CNCC130.DLL
2010-03-11 19:36 . 2004-10-26 19:03 90112 —-a-w- c:\windows\system32\CNCI130.DLL
2010-03-11 19:36 . 2004-09-08 04:53 94208 —-a-w- c:\windows\system32\CNCL130.DLL
2010-03-11 19:36 . 2010-03-11 19:36 ——– d—–w- C:\CanonMP
2010-03-11 19:36 . 2004-10-26 19:15 49152 —-a-w- c:\windows\system32\cncisco.dll
2010-03-11 19:36 . 2002-05-24 17:04 389180 —-a-w- c:\windows\system32\UCS32P.DLL
2010-03-11 19:29 . 2008-04-14 05:15 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys
2010-03-11 19:27 . 2010-03-11 19:27 ——– d—–w- c:\program files\Jasc Software Inc
2010-03-11 19:27 . 2010-03-11 19:27 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Jasc Software Inc
2010-03-11 19:23 . 2010-03-11 19:23 ——– d—–w- c:\program files\Common Files\SWF Studio
2010-03-11 19:21 . 2010-03-12 03:11 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\WallpaperSSPro
2010-03-11 19:21 . 2010-03-11 19:21 ——– d—–w- c:\program files\WallpaperSSPro
2010-03-11 17:01 . 2010-03-11 17:01 ——– d—–w- c:\program files\JJS
2010-03-11 17:01 . 2010-03-20 21:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-11 17:01 . 2010-03-11 17:01 ——– d—–w- c:\program files\Common Files\InstallShield
2010-03-11 06:12 . 2010-03-11 06:12 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-11 01:58 . 2010-03-11 01:58 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-03-11 01:50 . 2005-07-25 15:59 28672 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird\Profiles\yqzbn8qk.default\extensions\{31513E58-F253-47ad-86DB-D5F21E905429}\components\mintray-9178506d-2005072516-trunk.dll
2010-03-11 01:50 . 2009-12-09 22:31 20992 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird\Profiles\yqzbn8qk.default\extensions\{de1b245c-de57-11da-ba2d-0050c2490048}\library\WINNT-32\MinimizeToTrayPlus.dll
2010-03-11 01:49 . 2009-12-14 12:57 213504 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird\Profiles\yqzbn8qk.default\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}\components\calbscmp.dll
2010-03-11 01:47 . 2010-03-11 01:50 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird
2010-03-11 01:47 . 2010-03-11 01:47 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Thunderbird
2010-03-11 01:42 . 2010-03-11 01:42 ——– d—–w- c:\program files\Adobe Media Player
2010-03-11 01:33 . 2010-03-11 01:33 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2010-03-11 00:52 . 2010-03-11 00:52 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-03-11 00:43 . 2010-03-15 17:14 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\BitTorrent
2010-03-11 00:42 . 2010-03-11 00:42 ——– d—–w- c:\program files\BitTorrent
2010-03-10 23:08 . 2010-03-10 23:08 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-03-10 23:08 . 2010-03-10 23:08 ——– d—–w- c:\program files\DAEMON Tools Lite
2010-03-10 23:08 . 2010-03-11 16:49 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\DAEMON Tools Lite
2010-03-10 23:07 . 2010-03-10 23:08 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-03-10 22:52 . 2006-10-27 00:58 30512 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-03-10 22:52 . 2006-10-27 00:58 30512 —-a-w- c:\windows\system32\mdimon.dll
2010-03-10 22:52 . 2006-10-27 00:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-03-10 22:52 . 2006-10-27 00:56 32592 —-a-w- c:\windows\system32\msonpmon.dll
2010-03-10 22:51 . 2010-03-10 22:51 ——– d—–w- c:\program files\Microsoft Works
2010-03-10 22:50 . 2010-03-10 22:50 ——– d—–w- c:\program files\Microsoft.NET
2010-03-10 22:49 . 2010-03-10 22:49 ——– d—–w- c:\windows\SHELLNEW
2010-03-10 22:49 . 2010-03-10 22:49 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Microsoft Help
2010-03-10 22:49 . 2010-03-10 22:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-10 22:48 . 2010-03-10 22:48 ——– d—–r- C:\MSOCache
2010-03-10 22:26 . 2010-03-10 22:26 ——– d—–w- c:\windows\system32\Adobe
2010-03-10 22:24 . 2010-02-01 01:45 38784 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-03-10 22:24 . 2010-03-10 22:24 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-03-10 22:23 . 2010-03-11 01:45 ——– d—–w- c:\program files\Common Files\Adobe
2010-03-10 22:23 . 2010-02-01 01:45 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-03-10 22:23 . 2010-03-10 22:23 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-03-10 22:22 . 2010-03-11 01:59 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Adobe
2010-03-10 22:22 . 2010-03-10 22:22 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-03-10 22:22 . 2010-03-10 23:18 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-10 22:06 . 2010-03-20 23:52 ——– d—–w- c:\program files\Mozilla Thunderbird
2010-03-10 22:05 . 2010-03-10 22:05 ——– d—–w- c:\program files\Common Files\Java
2010-03-10 22:05 . 2010-03-10 22:05 503808 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-55e28313-n\msvcp71.dll
2010-03-10 22:05 . 2010-03-10 22:05 499712 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-55e28313-n\jmc.dll
2010-03-10 22:05 . 2010-03-10 22:05 348160 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-55e28313-n\msvcr71.dll
2010-03-10 22:05 . 2010-03-10 22:05 61440 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1e6a7f01-n\decora-sse.dll
2010-03-10 22:05 . 2010-03-10 22:05 12800 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1e6a7f01-n\decora-d3d.dll
2010-03-10 22:05 . 2010-03-10 22:05 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-10 22:05 . 2010-03-10 22:05 ——– d—–w- c:\program files\Java
2010-03-10 21:56 . 2010-03-10 21:56 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Google
2010-03-10 21:56 . 2010-03-10 21:56 ——– d—–w- c:\program files\Google
2010-03-10 20:19 . 2010-03-10 20:19 0 —-a-w- c:\windows\nsreg.dat
2010-03-10 20:19 . 2010-03-10 20:19 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Mozilla
2010-03-10 20:10 . 2010-03-13 13:05 ——– d—–w- C:\$AVG
2010-03-10 20:10 . 2010-03-21 12:57 ——– d—–w- c:\windows\system32\drivers\Avg
2010-03-10 20:10 . 2010-03-13 13:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-10 20:10 . 2010-03-13 13:04 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-10 20:10 . 2010-03-13 13:03 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-10 20:10 . 2010-03-10 20:10 ——– d—–w- c:\program files\AVG
2010-03-10 20:10 . 2010-03-10 20:10 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-10 19:51 . 2010-03-20 23:38 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\ApplicationHistory
2010-03-10 19:47 . 2010-03-10 19:47 ——– d-sh–w- c:\documents and settings\Allyson Whitney\IECompatCache
2010-03-10 19:47 . 2010-03-10 19:47 ——– d-sh–w- c:\documents and settings\Allyson Whitney\PrivacIE
2010-03-10 19:30 . 2010-03-11 01:58 27488 —-a-w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-10 19:29 . 2010-03-10 19:29 ——– d-sh–w- c:\documents and settings\Allyson Whitney\IETldCache
2010-03-10 19:11 . 2010-03-10 19:11 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-03-10 19:11 . 2010-03-10 19:12 ——– d—–w- c:\program files\NVIDIA Corporation
2010-03-10 19:09 . 2009-12-11 08:38 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-03-10 19:09 . 2010-03-10 19:09 ——– d—–w- c:\windows\ie8updates
2010-03-10 19:09 . 2009-12-21 19:14 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-03-10 19:09 . 2009-12-21 19:14 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-03-10 19:09 . 2009-12-21 19:14 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-10 19:09 . 2009-12-21 19:14 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-10 19:09 . 2009-12-21 19:14 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-19 21:34 . 2010-03-10 17:47 ——– d—–w- c:\program files\Windows Media Connect 2
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\DivX
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\program files\DivX
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-03-11 02:37 . 2008-08-14 12:57 73312 —-a-w- c:\windows\system32\drivers\adfs.sys
2010-03-10 18:28 . 2010-03-10 17:14 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-10 17:56 . 2010-03-10 17:56 ——– d—–w- c:\program files\MSBuild
2010-03-10 17:56 . 2010-03-10 17:56 ——– d—–w- c:\program files\Reference Assemblies
2010-03-10 17:46 . 2010-03-10 17:46 409600 —-a-w- c:\windows\system32\wrap_oal.dll
2010-03-10 17:46 . 2010-03-10 17:46 114688 —-a-w- c:\windows\system32\OpenAL32.dll
2010-03-10 17:46 . 2010-03-10 17:46 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Creative
2010-03-10 17:16 . 2010-03-10 17:16 ——– d—–w- c:\program files\microsoft frontpage
2010-03-10 17:11 . 2010-03-10 17:11 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-03-09 19:03 . 2010-03-09 19:03 73600 —-a-w- c:\windows\system32\drivers\viamraid.sys
2010-02-01 01:45 . 2010-03-11 01:52 38784 —-a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-31 03:14 . 2010-03-09 19:03 990208 —-a-w- c:\windows\system32\syssetup.dll
2010-01-18 06:30 . 2010-01-18 06:30 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-01-18 06:30 . 2010-01-18 06:30 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-01-12 17:03 . 2010-01-12 17:03 6359168 —-a-w- c:\windows\system32\nv4_disp.dll
2010-01-12 17:03 . 2010-01-12 17:03 61440 —-a-w- c:\windows\system32\OpenCL.dll
2010-01-12 17:03 . 2010-01-12 17:03 4104192 —-a-w- c:\windows\system32\nvcuda.dll
2010-01-12 17:03 . 2010-01-12 17:03 4077672 —-a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 17:03 . 2010-01-12 17:03 2283526 —-a-w- c:\windows\system32\nvdata.bin
2010-01-12 17:03 . 2010-01-12 17:03 2259560 —-a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 17:03 . 2010-01-12 17:03 182888 —-a-w- c:\windows\system32\nvcodins.dll
2010-01-12 17:03 . 2010-01-12 17:03 182888 —-a-w- c:\windows\system32\nvcod.dll
2010-01-12 17:03 . 2010-01-12 17:03 14458880 —-a-w- c:\windows\system32\nvoglnt.dll
2010-01-12 17:03 . 2010-01-12 17:03 11632640 —-a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 17:03 . 2010-01-12 17:03 1081344 —-a-w- c:\windows\system32\nvapi.dll
2010-01-12 17:03 . 2010-01-12 17:03 10276768 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-01-12 03:17 . 2010-01-12 03:17 278120 —-a-w- c:\windows\system32\nvmccs.dll
2010-01-12 03:17 . 2010-01-12 03:17 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2010-01-12 03:17 . 2010-01-12 03:17 145000 —-a-w- c:\windows\system32\nvcolor.exe
2010-01-12 03:17 . 2010-01-12 03:17 13666408 —-a-w- c:\windows\system32\nvcpl.dll
2010-01-12 03:17 . 2010-01-12 03:17 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-01-12 03:17 . 2010-01-12 03:17 81920 —-a-w- c:\windows\system32\nvwddi.dll
2009-12-31 16:50 . 2008-04-14 03:45 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:20 . 2009-12-22 05:20 81920 ——w- c:\windows\system32\ieencode.dll
2010-03-10 21:56 . 2010-03-10 21:56 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

——- Sigcheck ——-

[-] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\atapi.sys
[-] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys

[-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\asyncmac.sys
[-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\asyncmac.sys
[-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys

[-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\ERDNT\cache\beep.sys
[-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
[-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys

[-] 2008-04-14 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\kbdclass.sys
[-] 2008-04-14 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys

[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\ndis.sys
[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ndis.sys
[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys

[-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\ntfs.sys
[-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ntfs.sys
[-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys

[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\ERDNT\cache\null.sys
[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys
[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys

[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\ERDNT\cache\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys

[-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\browser.dll
[-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll
[-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\browser.dll

[-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\lsass.exe
[-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe
[-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\lsass.exe

[-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\netman.dll
[-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll
[-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\netman.dll

[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\ERDNT\cache\qmgr.dll
[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll
[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\dllcache\qmgr.dll

[-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\ERDNT\cache\rpcss.dll
[-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll
[-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll
[-] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[-] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\rpcss.dll

[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\ERDNT\cache\services.exe
[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\services.exe
[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe
[-] 2009-02-06 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2008-04-14 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\services.exe

[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\spoolsv.exe
[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\system32\spoolsv.exe
[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\spoolsv.exe

[-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\winlogon.exe
[-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\winlogon.exe

[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\ERDNT\cache\comctl32.dll
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll

[-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\cryptsvc.dll
[-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll
[-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\cryptsvc.dll

[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\ERDNT\cache\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[-] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[-] 2008-04-14 08:41 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\$NtUninstallKB950974$\es.dll

[-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\imm32.dll
[-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll
[-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\imm32.dll

[-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\ERDNT\cache\kernel32.dll
[-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll
[-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll
[-] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB959426$\kernel32.dll

[-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\linkinfo.dll
[-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll
[-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\linkinfo.dll

[-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\lpk.dll
[-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll
[-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\lpk.dll

[-] 2009-12-22 . AD17006339C1934D86449F335C241FF1 . 3073536 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\mshtml.dll
[-] 2009-12-21 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876] . . c:\windows\ERDNT\cache\mshtml.dll
[-] 2009-12-21 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876] . . c:\windows\SoftwareDistribution\Download\f1062d4e51d6818acdde68ea67673088\SP3GDR\mshtml.dll
[-] 2009-12-21 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876] . . c:\windows\system32\mshtml.dll
[-] 2009-12-21 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876] . . c:\windows\system32\dllcache\mshtml.dll
[-] 2009-12-21 . E6B64C6C729BBC38AB7CC92CE33F97A5 . 5945856 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
[-] 2009-12-21 . E6B64C6C729BBC38AB7CC92CE33F97A5 . 5945856 . . [8.00.6001.22967] . . c:\windows\SoftwareDistribution\Download\f1062d4e51d6818acdde68ea67673088\SP3QFE\mshtml.dll
[-] 2009-10-29 . C0F9AC6FAB2C788FFEE3E69585A0E93F . 5944320 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll
[-] 2009-10-29 . C0F9AC6FAB2C788FFEE3E69585A0E93F . 5944320 . . [8.00.6001.22945] . . c:\windows\SoftwareDistribution\Download\73e29923811a3a72ca5380ec0acd4745\SP3QFE\mshtml.dll
[-] 2009-10-29 . CBB1EF54B86EDB78649909DD1699E5CA . 5940736 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\mshtml.dll
[-] 2009-10-29 . CBB1EF54B86EDB78649909DD1699E5CA . 5940736 . . [8.00.6001.18854] . . c:\windows\SoftwareDistribution\Download\73e29923811a3a72ca5380ec0acd4745\SP3GDR\mshtml.dll
[-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\mshtml.dll
[-] 2008-04-14 . A706E122B398FE1AB85CB9B75D044223 . 3066880 . . [6.00.2900.5512] . . c:\windows\ie8\mshtml.dll

[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\ERDNT\cache\msvcrt.dll
[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll
[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\dllcache\msvcrt.dll

[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\ERDNT\cache\mswsock.dll
[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll
[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll
[-] 2008-06-20 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
[-] 2008-04-14 . B4138E99236F0F57D4CF49BAE98A0746 . 245248 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\mswsock.dll

[-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\netlogon.dll
[-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll
[-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\netlogon.dll

[-] 2009-12-09 . 05BE3D9A71972223AFF6A3C823BA51B1 . 2189312 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2009-12-08 . 9696C553F994340CD6AA5C5A724C3A19 . 2145280 . . [5.1.2600.5913] . . c:\windows\ERDNT\cache\ntoskrnl.exe
[-] 2009-12-08 . 9696C553F994340CD6AA5C5A724C3A19 . 2145280 . . [5.1.2600.5913] . . c:\windows\system32\ntoskrnl.exe
[-] 2009-02-08 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2009-02-06 . 0CBA44D0938D57F334C0862424148B70 . 2145280 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB977165-v2$\ntoskrnl.exe
[-] 2008-04-14 . 40F8880122A030A7E9E1FEDEA833B33D . 2145280 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\ntoskrnl.exe

[-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\ERDNT\cache\powrprof.dll
[-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll
[-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\powrprof.dll

[-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\scecli.dll
[-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll
[-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\scecli.dll

[-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\sfc.dll
[-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll
[-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\sfc.dll

[-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\svchost.exe
[-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
[-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\svchost.exe

[-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\tapisrv.dll
[-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll
[-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\tapisrv.dll

[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\user32.dll
[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\user32.dll

[-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\userinit.exe
[-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
[-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\userinit.exe

[-] 2009-12-22 . BD27AF5C72D2FBFE491D3A3A8429B974 . 668672 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\wininet.dll
[-] 2009-12-21 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876] . . c:\windows\ERDNT\cache\wininet.dll
[-] 2009-12-21 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876] . . c:\windows\SoftwareDistribution\Download\f1062d4e51d6818acdde68ea67673088\SP3GDR\wininet.dll
[-] 2009-12-21 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876] . . c:\windows\system32\wininet.dll
[-] 2009-12-21 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876] . . c:\windows\system32\dllcache\wininet.dll
[-] 2009-12-21 . 5E1F666B8955FD77E65D65C4C4D882A3 . 916480 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll
[-] 2009-12-21 . 5E1F666B8955FD77E65D65C4C4D882A3 . 916480 . . [8.00.6001.22967] . . c:\windows\SoftwareDistribution\Download\f1062d4e51d6818acdde68ea67673088\SP3QFE\wininet.dll
[-] 2009-10-29 . 6AF52998B90F72FF2325D84D90EDA1CC . 916480 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll
[-] 2009-10-29 . 6AF52998B90F72FF2325D84D90EDA1CC . 916480 . . [8.00.6001.22945] . . c:\windows\SoftwareDistribution\Download\73e29923811a3a72ca5380ec0acd4745\SP3QFE\wininet.dll
[-] 2009-10-29 . 75240F6EDBCE7B85DF66874407D38A4F . 916480 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\wininet.dll
[-] 2009-10-29 . 75240F6EDBCE7B85DF66874407D38A4F . 916480 . . [8.00.6001.18854] . . c:\windows\SoftwareDistribution\Download\73e29923811a3a72ca5380ec0acd4745\SP3GDR\wininet.dll
[-] 2009-03-08 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\wininet.dll
[-] 2008-04-14 . 7A4F775ABB2F1C97DEF3E73AFA2FAEDD . 666112 . . [6.00.2900.5512] . . c:\windows\ie8\wininet.dll

[-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\ws2_32.dll
[-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll
[-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ws2_32.dll

[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ERDNT\cache\explorer.exe
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe


[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\ctfmon.exe
[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ctfmon.exe

[-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ERDNT\cache\shsvcs.dll
[-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\shsvcs.dll
[-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\shsvcs.dll

[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\regsvc.dll
[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll
[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\regsvc.dll

[-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\schedsvc.dll
[-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll
[-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\schedsvc.dll

[-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\ssdpsrv.dll
[-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll
[-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ssdpsrv.dll

[-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\termsrv.dll
[-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
[-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\termsrv.dll

[-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\appmgmts.dll
[-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\system32\appmgmts.dll
[-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\appmgmts.dll

[-] 2001-08-23 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\ERDNT\cache\acpiec.sys
[-] 2001-08-23 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

[-] 2008-04-13 22:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ERDNT\cache\aec.sys
[-] 2008-04-13 22:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys

[-] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\ip6fw.sys
[-] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ip6fw.sys
[-] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys

[-] 2008-04-14 08:41 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\ERDNT\cache\mfc40u.dll
[-] 2008-04-14 08:41 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll
[-] 2008-04-14 08:41 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\system32\dllcache\mfc40u.dll

[-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\msgsvc.dll
[-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll
[-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\msgsvc.dll

[-] 2008-04-14 08:42 . C7E39EA41233E9F5B86C8DA3A9F1E4A8 . 52224 . . [9.0.1.56] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[-] 2006-10-19 02:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\ERDNT\cache\mspmsnsv.dll
[-] 2006-10-19 02:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-10-19 02:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll

[-] 2009-12-09 . FFDCE1EEA79C678C40237D4E031E5B51 . 2066176 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrnlpa.exe
[-] 2009-12-08 . 089F1E207B067A4DDEB2EEC37BBB1AA7 . 2023936 . . [5.1.2600.5913] . . c:\windows\ERDNT\cache\ntkrnlpa.exe
[-] 2009-12-08 . 089F1E207B067A4DDEB2EEC37BBB1AA7 . 2023936 . . [5.1.2600.5913] . . c:\windows\system32\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2009-02-06 . 65D4220799E6FC2CB079070A6393CC0E . 2023936 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB977165-v2$\ntkrnlpa.exe
[-] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-04-14 . 7F653A89F6E89E3AE0D49830EECE35D4 . 2023936 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe

[-] 2008-04-14 08:42 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\ERDNT\cache\ntmssvc.dll
[-] 2008-04-14 08:42 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll
[-] 2008-04-14 08:42 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\system32\dllcache\ntmssvc.dll

[-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\upnphost.dll
[-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll
[-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\upnphost.dll

c:\windows\System32\cngaudit.dll … is missing !!
.
((((((((((((((((((((((((((((( SnapShot@2010-03-21_16.48.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-21 19:13 . 2010-03-21 19:13 16384 c:\windows\Temp\Perflib_Perfdata_1a4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-22 26101032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2007-04-09 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 19968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-12 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-03-10 30192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-03-11 611712]
"HitmanPro35"="c:\program files\Hitman Pro 3.5\HitmanPro35.exe" [2010-03-19 5650240]

c:\documents and settings\Allyson Whitney\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 13:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
@="Service"

S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-13 216200]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-13 308064]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter
DcomLaunch REG_MULTI_SZ DcomLaunch TermService
eapsvcs REG_MULTI_SZ eaphost
dot3svc REG_MULTI_SZ dot3svc
WudfServiceGroup REG_MULTI_SZ WUDFSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
CryptSvc
DMServer
DHCP
ERSvc
EventSystem
HidServ
LanmanWorkstation
Messenger
Netman
TrkWks
W32Time
WZCSVC
wscsvc
xmlprov
napagent
WmdmPmSN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
Alerter
LmHosts

.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Allyson Whitney\Application Data\Mozilla\Firefox\Profiles\2wm9dp5t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-21 15:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Denied: (A 2) (Everyone)
@="FlashProp Class"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash6.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{8D8763AB-E93B-4812-964E-F04E0008FD50}\Version]
@Denied: (A) (Everyone)
@="{8D8763AB-E93B-4812-964E-F04E0008FD50}"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash6.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.1"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash6.ocx, 1"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash6.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash6.ocx, 1"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"

[HKEY_LOCAL_MACHINE\softwareSoftware\Microsoft\Windows NT\CurrentVersion\Windows]
@Denied: (Full) (Everyone)
@Denied: (Full) (Everyone)
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(744)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2010-03-21 15:57:31
ComboFix-quarantined-files.txt 2010-03-21 19:57
ComboFix2.txt 2010-03-21 19:22
ComboFix3.txt 2010-03-21 16:50
ComboFix4.txt 2010-03-20 23:13

Pre-Run: 242,832,715,776 bytes free
Post-Run: 242,825,515,008 bytes free

- - End Of File - - 8DB9F2C00D1DE587F6EB204FDBDEDC28
Hi ladykrimson,

Combofix was ran on this machine several times. In order to get a clear picture of what was removed I will need to see all the logs.

Please open windows explorer and navigate to this folder C:\Qoobox . In the right hand panel locate these 4 files
  • ComboFix2.txt
  • ComboFix3.txt
  • ComboFix4.txt
  • Add-Remove Programs.txt
When did you install Windows XP Service Pack 3?

Please post the reguested logs.

Thanks
Hi ladykrimson,

BitTorrent
You have BitTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall BitTorrent, however that choice is up to you. If you choose to remove this program, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


Where did you get this program from? Smart Diary Suite 4

Did you make any changes to this machine between running combofix the 3rd and 4th time? There are some discrepancies in part of the combofix logs created in a 37 minute span.

Are you still being redirected?

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :dir
    c:\documents and settings\Allyson Whitney\Local Settings\Application Data\nvmcdb97
    
    :filefind
    sfcfiles.*
    cngaudit.*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
I don't use BitTorrent very often at all, so I will uninstall it.

I got Smart Diary Suite from here:

http://www.sdiary.com/

I ran Combofix a total of four times. The first time, I ran the one I had downloaded a while back…then I noticed that the instructions were to download this version, so I did so and ran that version. (I have a slight problem with reading comprehension). I forgot to rename the downloaded file, so I renamed it and ran it again. Then I noticed I forgot to shut down my AVG, so I ran it again. Sorry for the confusion.

After I ran the Combofix, the redirecting stopped.

Here is the result of the SystemLook:

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 10:56 on 22/03/2010 by Allyson Whitney (Administrator - Elevation successful)

========== dir ==========

c:\documents and settings\Allyson Whitney\Local Settings\Application Data\nvmcdb97 - Parameters: "(none)"

—Files—
None found.

—Folders—
None found.

========== filefind ==========

Searching for "sfcfiles.*"
C:\Qoobox\Quarantine\C\WINDOWS\system32\sfcfiles.dll.vir –a— 1614848 bytes [19:03 09/03/2010] [19:03 09/03/2010] 362BC5AF8EAF712832C58CC13AE05750

Searching for "cngaudit.*"
C:\MGtools\temp\VSP1\cngaudit.dllmg –a— 11776 bytes [10:46 02/11/2006] [10:46 02/11/2006] 7F15B4953378C8B5161D65C26D5FED4D

-=End Of File=-
Hi ladykrimson,

Looking at the logs I thought the redirects should have gone away after the first run of combofix. However something happened between the 3rd and 4th runs. Do you have an XP cd?

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

Folder::
c:\documents and settings\Allyson Whitney\Local Settings\Application Data\nvmcdb97

DeQuarantine::
C:\Qoobox\c\windows\system32\sfcfiles.dll.vir

RegLock:: 
[HKEY_LOCAL_MACHINE\softwareSoftware\Microsoft\Windows NT\CurrentVersion\Windows]

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

You will recieve 2 logs this time, combofix.txt and dequarantine.txt. Please post both.

Thanks
I cannot find a file called dequarantine.txt. Here is the combofix file:

ComboFix 10-03-22.02 - Allyson Whitney 03/22/2010 17:54:18.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1361 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
Command switches used :: c:\documents and settings\Allyson Whitney\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ALLYSO~1\LOCALS~1\Temp\NewsFeed[1].dll
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\~DFK45a5605.tmp
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\1eaadjc.dll
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\bass.dll
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\engine_vx.dll
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\kfgresk.dll
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\mjcriu.dll
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\peaadje.dll
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\qwadjb.dll
c:\documents and settings\Allyson Whitney\Application Data\Microsoft\rsaadjd.dll
c:\documents and settings\Allyson Whitney\Local Settings\Application Data\nvmcdb97
c:\documents and settings\Allyson Whitney\Local Settings\temp\NewsFeed[1].dll

.
((((((((((((((((((((((((( Files Created from 2010-02-22 to 2010-03-22 )))))))))))))))))))))))))))))))
.

2010-03-20 23:37 . 2010-03-20 23:38 139502 —-a-w- C:\MGlogs.zip
2010-03-20 23:37 . 2010-03-20 23:38 ——– d—–w- C:\MGtools
2010-03-20 23:37 . 2010-03-20 21:55 2388938 —-a-w- C:\MGtools.exe
2010-03-20 21:57 . 2010-03-20 21:57 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-20 21:57 . 2010-03-21 18:56 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\SUPERAntiSpyware.com
2010-03-20 21:57 . 2010-03-21 18:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-03-20 21:42 . 2010-03-20 21:42 ——– d—–w- c:\program files\CCleaner
2010-03-19 21:55 . 2010-03-19 21:55 ——– d—–w- c:\program files\ERUNT
2010-03-19 21:45 . 2010-03-19 21:45 ——– d—–w- c:\program files\Trend Micro
2010-03-19 19:43 . 2010-03-19 19:43 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Malwarebytes
2010-03-19 19:43 . 2010-03-19 19:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-19 19:43 . 2010-03-21 18:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-19 17:18 . 2010-03-19 17:18 12872 —-a-w- c:\windows\system32\bootdelete.exe
2010-03-19 17:11 . 2010-03-22 22:04 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-03-19 17:11 . 2010-03-19 17:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-03-19 17:11 . 2010-03-19 17:11 ——– d—–w- c:\program files\Hitman Pro 3.5
2010-03-19 16:56 . 2010-03-19 16:56 ——– d—–w- c:\windows\Sun
2010-03-17 17:22 . 2010-03-17 17:23 ——– d—–w- c:\program files\Smart Diary Suite 4
2010-03-15 22:45 . 2010-03-15 22:45 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-03-15 22:36 . 2010-03-22 22:05 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\skypePM
2010-03-15 22:34 . 2010-03-22 22:05 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–w- c:\program files\Common Files\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–r- c:\program files\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2010-03-15 22:31 . 2010-03-18 19:06 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Fantasy Grounds II
2010-03-15 22:31 . 2010-03-15 23:34 ——– d—–w- c:\program files\Fantasy Grounds II
2010-03-14 15:43 . 2010-03-15 04:06 ——– d—–w- C:\Temp
2010-03-13 19:12 . 2010-03-13 21:03 8 —-a-w- c:\windows\system32\nvModes.dat
2010-03-11 19:37 . 2010-03-11 19:37 ——– d—–w- C:\BJPrinter
2010-03-11 19:37 . 2004-08-17 10:00 7680 —-a-w- c:\windows\system32\CNMVS6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 54272 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 17920 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 116736 —-a-w- c:\windows\system32\CNMLM6s.DLL
2010-03-11 19:37 . 2008-04-14 05:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-03-11 19:37 . 2008-04-14 05:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2010-03-11 19:37 . 2008-04-14 05:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-03-11 19:37 . 2008-04-14 05:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-03-11 19:36 . 2010-03-11 19:36 ——– d—–w- c:\program files\Canon
2010-03-11 19:36 . 2004-10-26 19:03 557056 —-a-w- c:\windows\system32\CNCC130.DLL
2010-03-11 19:36 . 2004-10-26 19:03 90112 —-a-w- c:\windows\system32\CNCI130.DLL
2010-03-11 19:36 . 2004-09-08 04:53 94208 —-a-w- c:\windows\system32\CNCL130.DLL
2010-03-11 19:36 . 2010-03-11 19:36 ——– d—–w- C:\CanonMP
2010-03-11 19:36 . 2004-10-26 19:15 49152 —-a-w- c:\windows\system32\cncisco.dll
2010-03-11 19:36 . 2002-05-24 17:04 389180 —-a-w- c:\windows\system32\UCS32P.DLL
2010-03-11 19:29 . 2008-04-14 05:15 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys
2010-03-11 19:27 . 2010-03-11 19:27 ——– d—–w- c:\program files\Jasc Software Inc
2010-03-11 19:27 . 2010-03-11 19:27 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Jasc Software Inc
2010-03-11 19:23 . 2010-03-11 19:23 ——– d—–w- c:\program files\Common Files\SWF Studio
2010-03-11 19:21 . 2010-03-12 03:11 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\WallpaperSSPro
2010-03-11 19:21 . 2010-03-22 15:48 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-11 19:21 . 2010-03-11 19:21 ——– d—–w- c:\program files\WallpaperSSPro
2010-03-11 17:01 . 2010-03-11 17:01 ——– d—–w- c:\program files\JJS
2010-03-11 17:01 . 2010-03-20 21:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-11 17:01 . 2010-03-11 17:01 ——– d—–w- c:\program files\Common Files\InstallShield
2010-03-11 06:12 . 2010-03-11 06:12 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-11 01:58 . 2010-03-11 01:58 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-03-11 01:47 . 2010-03-11 01:50 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird
2010-03-11 01:47 . 2010-03-11 01:47 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Thunderbird
2010-03-11 01:42 . 2010-03-11 01:42 ——– d—–w- c:\program files\Adobe Media Player
2010-03-11 01:33 . 2010-03-11 01:33 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2010-03-11 00:52 . 2010-03-11 00:52 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-03-11 00:43 . 2010-03-15 17:14 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\BitTorrent
2010-03-10 23:08 . 2010-03-10 23:08 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-03-10 23:08 . 2010-03-10 23:08 ——– d—–w- c:\program files\DAEMON Tools Lite
2010-03-10 23:08 . 2010-03-11 16:49 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\DAEMON Tools Lite
2010-03-10 23:07 . 2010-03-10 23:08 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-03-10 22:52 . 2006-10-27 00:58 30512 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-03-10 22:52 . 2006-10-27 00:58 30512 —-a-w- c:\windows\system32\mdimon.dll
2010-03-10 22:52 . 2006-10-27 00:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-03-10 22:52 . 2006-10-27 00:56 32592 —-a-w- c:\windows\system32\msonpmon.dll
2010-03-10 22:51 . 2010-03-10 22:51 ——– d—–w- c:\program files\Microsoft Works
2010-03-10 22:50 . 2010-03-10 22:50 ——– d—–w- c:\program files\Microsoft.NET
2010-03-10 22:49 . 2010-03-10 22:49 ——– d—–w- c:\windows\SHELLNEW
2010-03-10 22:49 . 2010-03-10 22:49 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Microsoft Help
2010-03-10 22:49 . 2010-03-10 22:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-10 22:48 . 2010-03-10 22:48 ——– d—–r- C:\MSOCache
2010-03-10 22:26 . 2010-03-10 22:26 ——– d—–w- c:\windows\system32\Adobe
2010-03-10 22:24 . 2010-03-10 22:24 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-03-10 22:23 . 2010-03-11 01:45 ——– d—–w- c:\program files\Common Files\Adobe
2010-03-10 22:23 . 2010-03-10 22:23 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-03-10 22:22 . 2010-03-11 01:59 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Adobe
2010-03-10 22:22 . 2010-03-10 23:18 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-10 22:06 . 2010-03-21 20:49 ——– d—–w- c:\program files\Mozilla Thunderbird
2010-03-10 22:05 . 2010-03-10 22:05 ——– d—–w- c:\program files\Common Files\Java
2010-03-10 22:05 . 2010-03-10 22:05 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-10 22:05 . 2010-03-10 22:05 ——– d—–w- c:\program files\Java
2010-03-10 21:56 . 2010-03-10 21:56 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Google
2010-03-10 21:56 . 2010-03-10 21:56 ——– d—–w- c:\program files\Google
2010-03-10 20:19 . 2010-03-10 20:19 0 —-a-w- c:\windows\nsreg.dat
2010-03-10 20:19 . 2010-03-10 20:19 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Mozilla
2010-03-10 20:10 . 2010-03-13 13:05 ——– d—–w- C:\$AVG
2010-03-10 20:10 . 2010-03-22 13:36 ——– d—–w- c:\windows\system32\drivers\Avg
2010-03-10 20:10 . 2010-03-13 13:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-10 20:10 . 2010-03-13 13:04 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-10 20:10 . 2010-03-13 13:03 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-10 20:10 . 2010-03-10 20:10 ——– d—–w- c:\program files\AVG
2010-03-10 20:10 . 2010-03-10 20:10 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-10 19:51 . 2010-03-20 23:38 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\ApplicationHistory
2010-03-10 19:47 . 2010-03-10 19:47 ——– d-sh–w- c:\documents and settings\Allyson Whitney\IECompatCache
2010-03-10 19:47 . 2010-03-10 19:47 ——– d-sh–w- c:\documents and settings\Allyson Whitney\PrivacIE
2010-03-10 19:30 . 2010-03-11 01:58 27488 —-a-w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-10 19:29 . 2010-03-10 19:29 ——– d-sh–w- c:\documents and settings\Allyson Whitney\IETldCache
2010-03-10 19:11 . 2010-03-10 19:11 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-03-10 19:11 . 2010-03-10 19:12 ——– d—–w- c:\program files\NVIDIA Corporation
2010-03-10 19:09 . 2009-12-11 08:38 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-03-10 19:09 . 2010-03-10 19:09 ——– d—–w- c:\windows\ie8updates
2010-03-10 19:09 . 2009-12-21 19:14 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-03-10 19:09 . 2009-12-21 19:14 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-03-10 19:09 . 2009-12-21 19:14 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-10 19:09 . 2009-12-21 19:14 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-10 19:09 . 2009-12-21 19:14 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-03-10 19:09 . 2009-12-21 19:14 11070464 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-03-10 19:09 . 2010-03-10 19:09 ——– dc-h–w- c:\windows\ie8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-19 21:34 . 2010-03-10 17:47 ——– d—–w- c:\program files\Windows Media Connect 2
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\DivX
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\program files\DivX
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-03-11 02:37 . 2008-08-14 12:57 73312 —-a-w- c:\windows\system32\drivers\adfs.sys
2010-03-10 18:28 . 2010-03-10 17:14 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-10 17:56 . 2010-03-10 17:56 ——– d—–w- c:\program files\MSBuild
2010-03-10 17:56 . 2010-03-10 17:56 ——– d—–w- c:\program files\Reference Assemblies
2010-03-10 17:46 . 2010-03-10 17:46 409600 —-a-w- c:\windows\system32\wrap_oal.dll
2010-03-10 17:46 . 2010-03-10 17:46 114688 —-a-w- c:\windows\system32\OpenAL32.dll
2010-03-10 17:46 . 2010-03-10 17:46 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Creative
2010-03-10 17:16 . 2010-03-10 17:16 ——– d—–w- c:\program files\microsoft frontpage
2010-03-10 17:11 . 2010-03-10 17:11 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-03-09 19:03 . 2010-03-09 19:03 73600 —-a-w- c:\windows\system32\drivers\viamraid.sys
2010-01-31 03:14 . 2010-03-09 19:03 990208 —-a-w- c:\windows\system32\syssetup.dll
2010-01-18 06:30 . 2010-01-18 06:30 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-01-18 06:30 . 2010-01-18 06:30 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-01-12 17:03 . 2010-01-12 17:03 6359168 —-a-w- c:\windows\system32\nv4_disp.dll
2010-01-12 17:03 . 2010-01-12 17:03 61440 —-a-w- c:\windows\system32\OpenCL.dll
2010-01-12 17:03 . 2010-01-12 17:03 4104192 —-a-w- c:\windows\system32\nvcuda.dll
2010-01-12 17:03 . 2010-01-12 17:03 4077672 —-a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 17:03 . 2010-01-12 17:03 2283526 —-a-w- c:\windows\system32\nvdata.bin
2010-01-12 17:03 . 2010-01-12 17:03 2259560 —-a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 17:03 . 2010-01-12 17:03 182888 —-a-w- c:\windows\system32\nvcodins.dll
2010-01-12 17:03 . 2010-01-12 17:03 182888 —-a-w- c:\windows\system32\nvcod.dll
2010-01-12 17:03 . 2010-01-12 17:03 14458880 —-a-w- c:\windows\system32\nvoglnt.dll
2010-01-12 17:03 . 2010-01-12 17:03 11632640 —-a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 17:03 . 2010-01-12 17:03 1081344 —-a-w- c:\windows\system32\nvapi.dll
2010-01-12 17:03 . 2010-01-12 17:03 10276768 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-01-12 03:17 . 2010-01-12 03:17 278120 —-a-w- c:\windows\system32\nvmccs.dll
2010-01-12 03:17 . 2010-01-12 03:17 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2010-01-12 03:17 . 2010-01-12 03:17 145000 —-a-w- c:\windows\system32\nvcolor.exe
2010-01-12 03:17 . 2010-01-12 03:17 13666408 —-a-w- c:\windows\system32\nvcpl.dll
2010-01-12 03:17 . 2010-01-12 03:17 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-01-12 03:17 . 2010-01-12 03:17 81920 —-a-w- c:\windows\system32\nvwddi.dll
2009-12-31 16:50 . 2008-04-14 03:45 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2010-03-10 21:56 . 2010-03-10 21:56 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-22 26101032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2007-04-09 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 19968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-12 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-03-10 30192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-03-11 611712]
"HitmanPro35"="c:\program files\Hitman Pro 3.5\HitmanPro35.exe" [2010-03-19 5650240]

c:\documents and settings\Allyson Whitney\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 13:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/10/2010 7:08 PM 691696]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/10/2010 4:10 PM 216200]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/10/2010 4:10 PM 308064]
R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [3/19/2010 1:11 PM 15944]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [3/10/2010 5:56 PM 30192]

— Other Services/Drivers In Memory —

*NewlyCreated* - HITMANPRO35
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Allyson Whitney\Application Data\Mozilla\Firefox\Profiles\2wm9dp5t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-22 18:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spgy.sys >>UNKNOWN [0x8A5C9938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf765bf28
\Driver\ACPI -> ACPI.sys @ 0xf74a3cb8
\Driver\atapi -> atapi.sys @ 0xf7978b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
NDIS: VIA Compatable Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xb8744bb0
PacketIndicateHandler -> NDIS.sys @ 0xb8751a21
SendHandler -> NDIS.sys @ 0xb872f87b
user & kernel MBR OK

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(768)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(584)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2010-03-22 18:14:27 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-22 22:14
ComboFix2.txt 2010-03-21 19:57
ComboFix3.txt 2010-03-21 19:22
ComboFix4.txt 2010-03-21 16:50
ComboFix5.txt 2010-03-22 19:32

Pre-Run: 242,785,193,984 bytes free
Post-Run: 242,756,124,672 bytes free

- - End Of File - - 93DEFE04924A933861E455AE897B786A
Hi ladykrimson,

This looks much better. However your cd emulators appear to have been reenabled and may account for a strange log entry.

Please run Defogger again and leave the disabled drivers disabled until we are finished. Please follow these instructions again.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Next

Click your start button, click run. Copy and paste the following line in to the run box and click OK

cmd /c mbr -t>"%userprofile%\Desktop\mbr.txt"

A file called mbr.txt will appear on your desktop, please post it's contents.

Thanks
I still can't find a "dequarantine.txt" file anywhere.

This is what happened:

1. Made certain all antivirus software was disabled.
2. Ran the DeFogger and disabled the CD emulator.
3. Dragged the CFScript.txt file onto the ComboFix.
4. ComboFix popped up a window asking if I would like to update….I clicked "Yes."
5. It updated and restarted the ComboFix.
6. Received notification that I had CD Emulation drivers on my computer and that ComboFix needed to disable them.
7. ComboFix restarted my computer.
8. ComboFix AGAIN asked me if I want to update, to which I clicked "Yes"
9. ComboFix restarted.
10. ComboFix scanned the computer.
11. ComboFix popped up a log.

I thought that, perhaps, when ComboFix restarted my computer that the emulators might have restarted, causing some kind of error. I went ahead and uninstalled the emulator and tried to run the scan again. That time it didn't ask me to update nor did it tell me that I had emulators. However, I still can't find the "dequarantine.txt" file. Here is the ComboFix log:

ComboFix 10-03-23.01 - Allyson Whitney 03/23/2010 14:20:29.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1509 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
Command switches used :: c:\documents and settings\Allyson Whitney\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2010-02-23 to 2010-03-23 )))))))))))))))))))))))))))))))
.

2010-03-23 18:15 . 2010-03-23 18:25 ——– d—–w- c:\windows\system32\NtmsData
2010-03-23 18:09 . 2010-03-23 18:12 ——– d—–w- C:\jgh15572j
2010-03-23 16:19 . 2010-03-23 16:22 ——– d—–w- C:\jgh
2010-03-20 23:37 . 2010-03-20 23:38 139502 —-a-w- C:\MGlogs.zip
2010-03-20 23:37 . 2010-03-20 23:38 ——– d—–w- C:\MGtools
2010-03-20 23:37 . 2010-03-20 21:55 2388938 —-a-w- C:\MGtools.exe
2010-03-20 21:57 . 2010-03-20 21:57 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-20 21:57 . 2010-03-21 18:56 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\SUPERAntiSpyware.com
2010-03-20 21:57 . 2010-03-21 18:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-03-20 21:42 . 2010-03-20 21:42 ——– d—–w- c:\program files\CCleaner
2010-03-19 21:55 . 2010-03-19 21:55 ——– d—–w- c:\program files\ERUNT
2010-03-19 21:45 . 2010-03-19 21:45 ——– d—–w- c:\program files\Trend Micro
2010-03-19 19:43 . 2010-03-19 19:43 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Malwarebytes
2010-03-19 19:43 . 2010-03-19 19:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-19 19:43 . 2010-03-21 18:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-19 17:18 . 2010-03-19 17:18 12872 —-a-w- c:\windows\system32\bootdelete.exe
2010-03-19 17:11 . 2010-03-22 22:04 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-03-19 17:11 . 2010-03-19 17:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-03-19 17:11 . 2010-03-19 17:11 ——– d—–w- c:\program files\Hitman Pro 3.5
2010-03-19 16:56 . 2010-03-19 16:56 ——– d—–w- c:\windows\Sun
2010-03-17 17:22 . 2010-03-17 17:23 ——– d—–w- c:\program files\Smart Diary Suite 4
2010-03-15 22:45 . 2010-03-15 22:45 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-03-15 22:36 . 2010-03-23 18:12 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\skypePM
2010-03-15 22:34 . 2010-03-23 18:14 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–w- c:\program files\Common Files\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–r- c:\program files\Skype
2010-03-15 22:34 . 2010-03-15 22:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2010-03-15 22:31 . 2010-03-18 19:06 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Fantasy Grounds II
2010-03-15 22:31 . 2010-03-15 23:34 ——– d—–w- c:\program files\Fantasy Grounds II
2010-03-14 15:43 . 2010-03-15 04:06 ——– d—–w- C:\Temp
2010-03-13 19:12 . 2010-03-13 21:03 8 —-a-w- c:\windows\system32\nvModes.dat
2010-03-12 11:26 . 2008-04-14 08:42 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2010-03-11 19:37 . 2010-03-11 19:37 ——– d—–w- C:\BJPrinter
2010-03-11 19:37 . 2004-08-17 10:00 7680 —-a-w- c:\windows\system32\CNMVS6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 54272 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 17920 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD6s.DLL
2010-03-11 19:37 . 2004-08-17 10:00 116736 —-a-w- c:\windows\system32\CNMLM6s.DLL
2010-03-11 19:37 . 2008-04-14 05:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-03-11 19:37 . 2008-04-14 05:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2010-03-11 19:37 . 2008-04-14 05:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-03-11 19:37 . 2008-04-14 05:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-03-11 19:36 . 2010-03-11 19:36 ——– d—–w- c:\program files\Canon
2010-03-11 19:36 . 2004-10-26 19:03 557056 —-a-w- c:\windows\system32\CNCC130.DLL
2010-03-11 19:36 . 2004-10-26 19:03 90112 —-a-w- c:\windows\system32\CNCI130.DLL
2010-03-11 19:36 . 2004-09-08 04:53 94208 —-a-w- c:\windows\system32\CNCL130.DLL
2010-03-11 19:36 . 2010-03-11 19:36 ——– d—–w- C:\CanonMP
2010-03-11 19:36 . 2004-10-26 19:15 49152 —-a-w- c:\windows\system32\cncisco.dll
2010-03-11 19:36 . 2002-05-24 17:04 389180 —-a-w- c:\windows\system32\UCS32P.DLL
2010-03-11 19:29 . 2008-04-14 05:15 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys
2010-03-11 19:27 . 2010-03-11 19:27 ——– d—–w- c:\program files\Jasc Software Inc
2010-03-11 19:27 . 2010-03-11 19:27 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Jasc Software Inc
2010-03-11 19:23 . 2010-03-11 19:23 ——– d—–w- c:\program files\Common Files\SWF Studio
2010-03-11 19:21 . 2010-03-12 03:11 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\WallpaperSSPro
2010-03-11 19:21 . 2010-03-22 22:32 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-11 19:21 . 2010-03-11 19:21 ——– d—–w- c:\program files\WallpaperSSPro
2010-03-11 17:01 . 2010-03-11 17:01 ——– d—–w- c:\program files\JJS
2010-03-11 17:01 . 2010-03-20 21:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-11 17:01 . 2010-03-11 17:01 ——– d—–w- c:\program files\Common Files\InstallShield
2010-03-11 06:12 . 2010-03-11 06:12 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-11 01:58 . 2010-03-11 01:58 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-03-11 01:50 . 2005-07-25 15:59 28672 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird\Profiles\yqzbn8qk.default\extensions\{31513E58-F253-47ad-86DB-D5F21E905429}\components\mintray-9178506d-2005072516-trunk.dll
2010-03-11 01:50 . 2009-12-09 22:31 20992 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird\Profiles\yqzbn8qk.default\extensions\{de1b245c-de57-11da-ba2d-0050c2490048}\library\WINNT-32\MinimizeToTrayPlus.dll
2010-03-11 01:49 . 2009-12-14 12:57 213504 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird\Profiles\yqzbn8qk.default\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}\components\calbscmp.dll
2010-03-11 01:47 . 2010-03-11 01:50 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Thunderbird
2010-03-11 01:47 . 2010-03-11 01:47 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Thunderbird
2010-03-11 01:42 . 2010-03-11 01:42 ——– d—–w- c:\program files\Adobe Media Player
2010-03-11 01:33 . 2010-03-11 01:33 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2010-03-11 00:52 . 2010-03-11 00:52 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-03-11 00:43 . 2010-03-15 17:14 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\BitTorrent
2010-03-10 23:08 . 2010-03-10 23:08 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-03-10 23:08 . 2010-03-11 16:49 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\DAEMON Tools Lite
2010-03-10 23:07 . 2010-03-10 23:08 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-03-10 22:52 . 2006-10-27 00:58 30512 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-03-10 22:52 . 2006-10-27 00:58 30512 —-a-w- c:\windows\system32\mdimon.dll
2010-03-10 22:52 . 2006-10-27 00:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-03-10 22:52 . 2006-10-27 00:56 32592 —-a-w- c:\windows\system32\msonpmon.dll
2010-03-10 22:51 . 2010-03-10 22:51 ——– d—–w- c:\program files\Microsoft Works
2010-03-10 22:50 . 2010-03-10 22:50 ——– d—–w- c:\program files\Microsoft.NET
2010-03-10 22:49 . 2010-03-10 22:49 ——– d—–w- c:\windows\SHELLNEW
2010-03-10 22:49 . 2010-03-10 22:49 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Microsoft Help
2010-03-10 22:49 . 2010-03-10 22:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-10 22:48 . 2010-03-10 22:48 ——– d—–r- C:\MSOCache
2010-03-10 22:26 . 2010-03-10 22:26 ——– d—–w- c:\windows\system32\Adobe
2010-03-10 22:24 . 2010-02-01 01:45 38784 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-03-10 22:24 . 2010-03-10 22:24 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-03-10 22:23 . 2010-03-11 01:45 ——– d—–w- c:\program files\Common Files\Adobe
2010-03-10 22:23 . 2010-02-01 01:45 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-03-10 22:23 . 2010-03-10 22:23 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-03-10 22:22 . 2010-03-11 01:59 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Adobe
2010-03-10 22:22 . 2010-03-10 22:22 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-03-10 22:22 . 2010-03-10 23:18 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-10 22:06 . 2010-03-23 18:16 ——– d—–w- c:\program files\Mozilla Thunderbird
2010-03-10 22:05 . 2010-03-10 22:05 ——– d—–w- c:\program files\Common Files\Java
2010-03-10 22:05 . 2010-03-10 22:05 503808 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-55e28313-n\msvcp71.dll
2010-03-10 22:05 . 2010-03-10 22:05 499712 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-55e28313-n\jmc.dll
2010-03-10 22:05 . 2010-03-10 22:05 348160 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-55e28313-n\msvcr71.dll
2010-03-10 22:05 . 2010-03-10 22:05 61440 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1e6a7f01-n\decora-sse.dll
2010-03-10 22:05 . 2010-03-10 22:05 12800 —-a-w- c:\documents and settings\Allyson Whitney\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1e6a7f01-n\decora-d3d.dll
2010-03-10 22:05 . 2010-03-10 22:05 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-10 22:05 . 2010-03-10 22:05 ——– d—–w- c:\program files\Java
2010-03-10 21:56 . 2010-03-10 21:56 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Google
2010-03-10 21:56 . 2010-03-10 21:56 ——– d—–w- c:\program files\Google
2010-03-10 20:19 . 2010-03-10 20:19 0 —-a-w- c:\windows\nsreg.dat
2010-03-10 20:19 . 2010-03-10 20:19 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\Mozilla
2010-03-10 20:10 . 2010-03-13 13:05 ——– d—–w- C:\$AVG
2010-03-10 20:10 . 2010-03-23 13:23 ——– d—–w- c:\windows\system32\drivers\Avg
2010-03-10 20:10 . 2010-03-13 13:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-10 20:10 . 2010-03-13 13:04 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-10 20:10 . 2010-03-13 13:03 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-10 20:10 . 2010-03-10 20:10 ——– d—–w- c:\program files\AVG
2010-03-10 20:10 . 2010-03-10 20:10 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-10 19:51 . 2010-03-20 23:38 ——– d—–w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\ApplicationHistory
2010-03-10 19:47 . 2010-03-10 19:47 ——– d-sh–w- c:\documents and settings\Allyson Whitney\IECompatCache
2010-03-10 19:47 . 2010-03-10 19:47 ——– d-sh–w- c:\documents and settings\Allyson Whitney\PrivacIE
2010-03-10 19:30 . 2010-03-11 01:58 27488 —-a-w- c:\documents and settings\Allyson Whitney\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-10 19:29 . 2010-03-10 19:29 ——– d-sh–w- c:\documents and settings\Allyson Whitney\IETldCache
2010-03-10 19:11 . 2010-03-10 19:11 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-03-10 19:11 . 2010-03-10 19:12 ——– d—–w- c:\program files\NVIDIA Corporation
2010-03-10 19:09 . 2009-12-11 08:38 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-03-10 19:09 . 2010-03-10 19:09 ——– d—–w- c:\windows\ie8updates
2010-03-10 19:09 . 2009-12-21 19:14 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-03-10 19:09 . 2009-12-21 19:14 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-03-10 19:09 . 2009-12-21 19:14 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-10 19:09 . 2009-12-21 19:14 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-10 19:09 . 2009-12-21 19:14 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-19 21:34 . 2010-03-10 17:47 ——– d—–w- c:\program files\Windows Media Connect 2
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\DivX
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\program files\DivX
2010-03-13 19:20 . 2010-03-13 19:20 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-03-11 02:37 . 2008-08-14 12:57 73312 —-a-w- c:\windows\system32\drivers\adfs.sys
2010-03-10 18:28 . 2010-03-10 17:14 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-10 17:56 . 2010-03-10 17:56 ——– d—–w- c:\program files\MSBuild
2010-03-10 17:56 . 2010-03-10 17:56 ——– d—–w- c:\program files\Reference Assemblies
2010-03-10 17:46 . 2010-03-10 17:46 409600 —-a-w- c:\windows\system32\wrap_oal.dll
2010-03-10 17:46 . 2010-03-10 17:46 114688 —-a-w- c:\windows\system32\OpenAL32.dll
2010-03-10 17:46 . 2010-03-10 17:46 ——– d—–w- c:\documents and settings\Allyson Whitney\Application Data\Creative
2010-03-10 17:16 . 2010-03-10 17:16 ——– d—–w- c:\program files\microsoft frontpage
2010-03-10 17:11 . 2010-03-10 17:11 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-03-09 19:03 . 2010-03-09 19:03 73600 —-a-w- c:\windows\system32\drivers\viamraid.sys
2010-02-01 01:45 . 2010-03-11 01:52 38784 —-a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-31 03:14 . 2010-03-09 19:03 990208 —-a-w- c:\windows\system32\syssetup.dll
2010-01-18 06:30 . 2010-01-18 06:30 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-01-18 06:30 . 2010-01-18 06:30 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-01-12 17:03 . 2010-01-12 17:03 6359168 —-a-w- c:\windows\system32\nv4_disp.dll
2010-01-12 17:03 . 2010-01-12 17:03 61440 —-a-w- c:\windows\system32\OpenCL.dll
2010-01-12 17:03 . 2010-01-12 17:03 4104192 —-a-w- c:\windows\system32\nvcuda.dll
2010-01-12 17:03 . 2010-01-12 17:03 4077672 —-a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 17:03 . 2010-01-12 17:03 2283526 —-a-w- c:\windows\system32\nvdata.bin
2010-01-12 17:03 . 2010-01-12 17:03 2259560 —-a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 17:03 . 2010-01-12 17:03 182888 —-a-w- c:\windows\system32\nvcodins.dll
2010-01-12 17:03 . 2010-01-12 17:03 182888 —-a-w- c:\windows\system32\nvcod.dll
2010-01-12 17:03 . 2010-01-12 17:03 14458880 —-a-w- c:\windows\system32\nvoglnt.dll
2010-01-12 17:03 . 2010-01-12 17:03 11632640 —-a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 17:03 . 2010-01-12 17:03 1081344 —-a-w- c:\windows\system32\nvapi.dll
2010-01-12 17:03 . 2010-01-12 17:03 10276768 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-01-12 03:17 . 2010-01-12 03:17 278120 —-a-w- c:\windows\system32\nvmccs.dll
2010-01-12 03:17 . 2010-01-12 03:17 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2010-01-12 03:17 . 2010-01-12 03:17 145000 —-a-w- c:\windows\system32\nvcolor.exe
2010-01-12 03:17 . 2010-01-12 03:17 13666408 —-a-w- c:\windows\system32\nvcpl.dll
2010-01-12 03:17 . 2010-01-12 03:17 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-01-12 03:17 . 2010-01-12 03:17 81920 —-a-w- c:\windows\system32\nvwddi.dll
2009-12-31 16:50 . 2008-04-14 03:45 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2010-03-10 21:56 . 2010-03-10 21:56 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-03-21_16.48.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-23 18:11 . 2010-03-23 18:11 16384 c:\windows\Temp\Perflib_Perfdata_36c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-22 26101032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2007-04-09 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 19968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-12 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-03-10 30192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-03-11 611712]
"HitmanPro35"="c:\program files\Hitman Pro 3.5\HitmanPro35.exe" [2010-03-19 5650240]

c:\documents and settings\Allyson Whitney\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 13:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/10/2010 4:10 PM 216200]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/10/2010 4:10 PM 308064]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/10/2010 7:08 PM 691696]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [3/10/2010 5:56 PM 30192]

— Other Services/Drivers In Memory —

*NewlyCreated* - DMADMIN
*NewlyCreated* - NTMSSVC
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Allyson Whitney\Application Data\Mozilla\Firefox\Profiles\2wm9dp5t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-23 14:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(752)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(708)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-03-23 14:28:09
ComboFix-quarantined-files.txt 2010-03-23 18:28
ComboFix2.txt 2010-03-23 16:40
ComboFix3.txt 2010-03-22 22:14
ComboFix4.txt 2010-03-21 19:57
ComboFix5.txt 2010-03-23 18:19

Pre-Run: 242,719,891,456 bytes free
Post-Run: 242,692,976,640 bytes free

- - End Of File - - 642A0F04A35338E34CABC631C08976BA

And here is the mbr.txt content:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Hi ladykrimson,

That's ok everything looks fine now. It was your emulators that caused the false reading.

We'll use SystemLook again.

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :filefind
    sfcfiles.*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

One more scan just to check our work.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Please post back with
  • SystemLook log
  • Kaspersky log
How is the computer?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI