This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Yahoo redirect and unable to install TrendMicro updates

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I've recently discovered that my searches on Yahoo are being redirected. After doing a search, I'm able to navigate to the first search result that I click on, but every search result I click on thereafter is redirected because the sites end up being blocked my TrendMicro even though they shouldn't be. Also, manually navigating to some sites are also redirected and then subsequently blocked by TrendMicro. However, performing search on Google do not present this problem. Also, whenever I attempt to download my latest update for TrendMicro, at the end after it is downloaded, I receive an error saying an error prevented my security software from connecting with the internet even though my internet connection is fine. I've checked my hosts file and it only has one entry. I ran HiJackThis and I've posted the results. Any help you can offer would be greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:55 PM, on 4/11/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fantasysports.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194497498187
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194497457718
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 6639 bytes
Hi aquadeath2, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Make sure these settings are correct.

Open Internet Explorer
  • at the top click Tools
  • Click Internet Options
  • Click Connections tab
  • Click Lan Settings button
  • Make sure the box beside "Use a proxy sever for your Lan" is UNchecked
  • OK your way out.

Open hijackthis, do a system scan only and checkmark these lines, if present

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



NEXT

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Next

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
No need for a Hijackthis log this time.

Thanks
Thank you for your detailed reply. I believe I followed all of your instructions and I've posted the log reports below.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-11 23:48:16
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JASONR~1\LOCALS~1\Temp\fwtdakob.sys


—- System - GMER 1.0.15 —-

SSDT 89A45C60 ZwCreateKey
SSDT 89A45160 ZwCreateProcess
SSDT 89A45420 ZwCreateProcessEx
SSDT 89A46AC0 ZwCreateThread
SSDT 89A461E0 ZwDeleteKey
SSDT 89A464A0 ZwDeleteValueKey
SSDT 89A46C60 ZwLoadDriver
SSDT 89A456E0 ZwOpenProcess
SSDT 89A45F20 ZwSetValueKey
SSDT 89A459A0 ZwTerminateProcess
SSDT 89A46920 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xB9A02380, 0x346307, 0xE8000020]
.rsrc C:\WINDOWS\System32\DRIVERS\rasacd.sys entry point in ".rsrc" section [0xBAD91C14]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Webroot\Washer\WasherSvc.exe[688] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0008ED99 C:\Program Files\Webroot\Washer\WasherSvc.exe (Window Washer Engine/Webroot Software, Inc.)
.text C:\WINDOWS\System32\svchost.exe[1416] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\svchost.exe[1416] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\svchost.exe[1416] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\System32\svchost.exe[1416] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 0302000A
.text C:\WINDOWS\Explorer.EXE[1784] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\WINDOWS\Explorer.EXE[1784] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C0000A
.text C:\WINDOWS\Explorer.EXE[1784] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A3000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DD000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A2000C
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E46DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E45A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E47A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A3000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DD000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A2000C
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD101 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E25466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E46DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E45A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E47A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB20 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4AA7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \FileSystem\Fastfat \Fat SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 89BEDAC8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB2 0x02 0x18 0x72 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB2 0x02 0x18 0x72 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB2 0x02 0x18 0x72 …

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\System32\DRIVERS\rasacd.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-

OTL logfile created on: 4/11/2010 11:58:19 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 149.38 Gb Free Space | 64.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: REINYSCOMP
Current User Name: Jason Reinhard
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (wwEngineSvc) – C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (FirebirdServerMAGIXInstance) – C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)


========== Driver Services (SafeList) ==========

DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (tmactmon) – C:\WINDOWS\system32\drivers\tmactmon.sys ()
DRV - (tmevtmgr) – C:\WINDOWS\system32\drivers\tmevtmgr.sys ()
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys ()
DRV - (dvd43llh) – C:\WINDOWS\system32\drivers\dvd43llh.sys (RIF)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (JGOGO) – C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (WINFLASH) – C:\Program Files\U-ABIT\FlashMenu\WINFLASH.SYS ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Memctl) – C:\Program Files\U-ABIT\FlashMenu\MEMCTL.SYS ()
DRV - (RT25USBAP) – C:\WINDOWS\system32\drivers\rt25usbap.sys (Ralink Technology Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (SI3132) – C:\WINDOWS\System32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (SiFilter) – C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.fantasysports.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://sports.yahoo.com/fantasy"
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 7171
FF - prefs.js..network.proxy.no_proxies_on: "*.local,localhost,127.0.0.1"

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 03:31:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 03:31:12 | 000,000,000 | —D | M]

[2009/05/25 03:25:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Extensions
[2010/04/11 03:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Firefox\Profiles\2hqnyucz.default\extensions
[2010/04/10 18:46:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Firefox\Profiles\2hqnyucz.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
[2009/05/25 03:25:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/05/25 11:04:03 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1194497498187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1194497457718 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/08 00:13:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/04/11 14:37:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jason Reinhard\Recent
[2010/04/11 12:21:22 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/11 12:05:45 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/04/11 12:02:19 | 000,181,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/04/11 12:01:14 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/04/11 11:37:49 | 000,000,000 | —D | C] – C:\Program Files\HiJackThis
[2010/04/11 11:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Jason Reinhard\Application Data\Malwarebytes
[2010/04/11 11:24:21 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/11 11:24:19 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/11 11:24:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/11 11:24:18 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/11 00:52:12 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/11 00:02:45 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/10 23:25:54 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/04/10 23:25:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/10 19:18:37 | 000,067,200 | R— | C] (Silicon Image, Inc.) – C:\WINDOWS\System32\drivers\SI3132_2.sys
[2010/04/10 18:42:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Jason Reinhard\Application Data\QuickScan
[2010/04/10 17:40:57 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/04/10 15:23:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/09 17:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/09 17:22:03 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/03/24 16:42:00 | 000,000,000 | —D | C] – C:\Program Files\Doom
[2009/07/18 16:25:14 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/05/25 02:13:27 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2007/12/13 14:57:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/11/08 03:43:16 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[1996/11/17 17:00:00 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\IMPLODE.DLL
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/11 23:57:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/11 23:55:07 | 000,000,433 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010/04/11 23:54:46 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/11 23:54:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/11 22:11:11 | 000,002,521 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Desktop\Microsoft Outlook.lnk
[2010/04/11 19:31:53 | 006,553,600 | —- | M] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat
[2010/04/11 19:31:53 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Jason Reinhard\ntuser.ini
[2010/04/11 19:31:48 | 003,712,656 | -H– | M] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\IconCache.db
[2010/04/11 19:31:43 | 000,000,634 | —- | M] () – C:\WINDOWS\win.ini
[2010/04/11 19:31:43 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/11 19:31:43 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/11 12:00:57 | 000,013,702 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/10 23:05:26 | 000,008,832 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasacd.sys
[2010/04/04 12:34:05 | 000,870,128 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Application Data\mcs.rma
[2010/04/04 12:34:05 | 000,000,004 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Application Data\A0C936
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/28 16:37:40 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Desktop\Will Geroni.doc
[2010/03/24 16:44:00 | 000,000,044 | —- | M] () – C:\WINDOWS\WININIT.INI
[2010/03/14 11:05:42 | 000,360,124 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/14 11:05:42 | 000,314,838 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/14 11:05:42 | 000,041,040 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/11 12:04:20 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/10 19:05:19 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/08 16:47:28 | 000,000,803 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Desktop\Internet Explorer.lnk
[2010/03/28 13:48:40 | 000,024,064 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Desktop\Will Geroni.doc
[2010/03/25 21:39:30 | 006,553,600 | —- | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat
[2010/03/24 16:44:00 | 000,000,044 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/03/24 16:42:00 | 000,004,711 | —- | C] () – C:\WINDOWS\System32\dmouse.vxd
[2009/09/07 14:52:19 | 000,000,028 | —- | C] () – C:\WINDOWS\Robota.INI
[2009/09/07 14:46:27 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\mgxasio2.dll
[2009/09/07 14:45:23 | 000,120,200 | —- | C] () – C:\WINDOWS\System32\DLLDEV32i.dll
[2009/09/07 14:45:08 | 000,006,211 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2009/05/25 04:10:42 | 000,000,445 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\burnaware.ini
[2009/05/24 10:14:42 | 000,003,598 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\773F1E3B-FA7D-4EFD-BA91-EDE8C94400CB.txt
[2009/05/23 15:52:56 | 000,005,270 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\773F1E3B-FA7D-4EFD-BA91-EDE8C94400CB.txt
[2009/05/23 00:10:22 | 000,003,638 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\1B63A34D-D468-480C-9BFD-C7118A69BA98.txt
[2009/05/22 16:38:35 | 000,004,426 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\1B63A34D-D468-480C-9BFD-C7118A69BA98.txt
[2009/05/01 22:43:08 | 000,870,128 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\mcs.rma
[2009/05/01 22:43:08 | 000,000,004 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\A0C936
[2009/02/19 20:09:55 | 000,000,088 | —- | C] () – C:\WINDOWS\Battle.ini
[2009/02/19 20:09:55 | 000,000,037 | —- | C] () – C:\WINDOWS\progman.ini
[2008/09/05 17:35:43 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/07/31 19:37:00 | 000,142,864 | —- | C] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2008/07/31 19:37:00 | 000,052,752 | —- | C] () – C:\WINDOWS\System32\drivers\tmactmon.sys
[2008/07/31 19:37:00 | 000,052,624 | —- | C] () – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2008/05/20 17:49:20 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/05/20 17:49:20 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/05/20 17:49:20 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/05/19 21:56:56 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2008/05/17 00:16:25 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/05/16 23:45:01 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2008/05/09 23:33:40 | 000,000,252 | —- | C] () – C:\WINDOWS\dvdtoaviconverter.ini
[2008/04/24 22:00:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\AVSDVDPlayer.m3u
[2008/02/14 02:54:19 | 000,000,107 | —- | C] () – C:\Documents and Settings\Jason Reinhard\default.pls
[2008/02/12 15:48:36 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/12 10:20:02 | 000,001,024 | —- | C] () – C:\Documents and Settings\Jason Reinhard\.rnd
[2008/01/19 03:03:15 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2007/12/14 12:49:05 | 000,000,211 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Network.ini
[2007/11/28 01:47:35 | 000,000,600 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\PUTTY.RND
[2007/11/11 23:58:04 | 000,019,456 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/10 19:32:20 | 000,000,480 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/10 14:10:34 | 000,000,321 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\SephirothSkirmishStats.ini
[2007/11/10 14:10:34 | 000,000,112 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Skirmish.ini
[2007/11/10 14:08:50 | 000,000,407 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Options.ini
[2007/11/09 01:00:47 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2007/11/08 23:45:55 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2007/11/08 02:14:46 | 000,010,848 | —- | C] () – C:\WINDOWS\System32\drivers\WinFlash.sys
[2007/11/08 00:35:14 | 000,006,016 | —- | C] () – C:\WINDOWS\System32\drivers\ALLOW-IO.SYS
[2007/11/08 00:20:23 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat.LOG
[2007/11/08 00:20:23 | 000,000,278 | -HS- | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.ini
[2007/10/19 20:56:16 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/18 05:02:34 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/06/28 12:43:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/06/28 12:43:00 | 001,474,560 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/06/28 12:43:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/06/28 12:43:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/06/28 12:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/04/21 19:29:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acoustica
[2008/09/05 17:43:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2008/08/01 20:35:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Funcom
[2009/09/07 19:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoldWave
[2009/09/07 14:58:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MAGIX
[2008/06/16 18:43:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/14 03:49:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/12 16:14:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/21 19:33:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Acoustica
[2007/11/09 23:19:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Aim
[2008/08/16 01:08:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Amazon
[2008/05/16 15:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Atari
[2010/01/25 22:20:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Bioshock
[2008/04/08 18:31:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Feedreader
[2008/05/16 15:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Leadertech
[2009/09/07 14:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\MAGIX
[2008/06/23 22:07:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\My Battle for Middle-earth Files
[2010/04/10 18:44:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\QuickScan
[2009/05/25 02:13:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\qweoujzr(2)
[2007/11/15 11:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Viewpoint
[2010/04/11 23:57:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:411E1BE2
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6971CCC5
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB669950
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B835CF2D
< End of report >

OTL Extras logfile created on: 4/11/2010 11:58:19 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 149.38 Gb Free Space | 64.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: REINYSCOMP
Current User Name: Jason Reinhard
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"C:\Program Files\Qnext\qnextclient.exe" = C:\Program Files\Qnext\qnextclient.exe:*:Enabled:qnextclient – ()
"C:\Program Files\Activision\Call To Power 2\ctp2_program\ctp\ctp2.exe" = C:\Program Files\Activision\Call To Power 2\ctp2_program\ctp\ctp2.exe:*:Enabled:Call to Power 2 – (Activision Studios)
"C:\Program Files\EA GAMES\The Battle for Middle-earth ™\game.dat" = C:\Program Files\EA GAMES\The Battle for Middle-earth ™\game.dat:*:Enabled:The Battle for Middle-earth ™ – ()
"C:\Program Files\EA GAMES\The Battle for Middle-earth ™\patchget.dat" = C:\Program Files\EA GAMES\The Battle for Middle-earth ™\patchget.dat:*:Enabled:patchgrabber – (Electronic Arts)
"C:\Program Files\Hasbro Interactive\Stratego\Stratego.exe" = C:\Program Files\Hasbro Interactive\Stratego\Stratego.exe:*:Enabled:Stratego – ( )
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper – (Microsoft Corporation)
"C:\Program Files\Microsoft Games\Age of Empires III\age3.exe" = C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:*:Enabled:Age of Empires III – (Ensemble Studios)
"C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe" = C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs – (Ensemble Studios)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Java\jre1.6.0_03\bin\java.exe" = C:\Program Files\Java\jre1.6.0_03\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\WiFiConnector\NintendoWFCReg.exe" = C:\Program Files\WiFiConnector\NintendoWFCReg.exe:*:Enabled:Nintendo Wi-Fi USB Connector – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{047E5F60-5357-43FB-A080-1912EB0132A4}" = FlashMenu
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1087BD66-01A3-40EA-949F-CD511E5189AA}" = TEAM MANAGER Lite 5.0
"{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{32A3A4F4-B792-11D6-A78A-00B0D0160030}" = Java™ SE Development Kit 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMB36X Raid Configurer
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C117F31-28A8-4477-BE91-64AC0A2204AD}" = Microsoft IntelliPoint 6.01
"{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{962E05CF-3394-496D-0091-850CF1762F6B}" = The Battle for Middle-earth ™
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro Internet Security
"{AC76BA86-7AD7-1033-7B44-A81100000003}" = Adobe Reader 8.1.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D75915D3-6CFF-445F-A346-18ED6EF2F618}" = Microsoft IntelliType Pro 6.01
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Acoustica Effects Pack" = Acoustica Effects Pack
"Acoustica Mixcraft 4.5" = Acoustica Mixcraft 4.5
"Acoustica MP3 Audio Mixer" = Acoustica MP3 Audio Mixer
"Acoustica_is1" = Acoustica 4.1
"Activision_CTP2UninstallKey" = Call To Power 2
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AOL Instant Messenger" = AOL Instant Messenger
"Audacity_is1" = Audacity 1.2.6
"AVS DVD Player_is1" = AVS DVD Player version 2.4
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BurnAware Free_is1" = BurnAware Free 2.3.5
"CCleaner" = CCleaner
"DVD Flick_is1" = DVD Flick
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab 6_is1" = DVDFab 6.1.2.5 (27/10/2009)
"DVDx_is1" = DVDx
"Firebird SQL Server US" = Firebird SQL Server - MAGIX Edition
"GoldWave v5.52" = GoldWave v5.52
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs
"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"MagicDisc 2.5.79" = MagicDisc 2.5.79
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.18)" = Mozilla Firefox (3.0.18)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Qnext" = Qnext
"Rhapsody" = Rhapsody
"Stratego" = Stratego
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"WiFiConnector" = Nintendo Wi-Fi USB Connector Registration Tool
"Window Washer" = Window Washer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/27/2008 10:55:05 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 11/27/2008 4:39:09 PM | Computer Name = REINYSCOMP | Source = Application Error | ID = 1000
Description = Faulting application aim.exe, version 5.9.6089.0, faulting module
locateui.ocm, version 5.9.6089.0, fault address 0x00015627.

Error - 11/27/2008 10:24:39 PM | Computer Name = REINYSCOMP | Source = Application Error | ID = 1000
Description = Faulting application ctp2.exe, version 1.2.0.0, faulting module unknown,
version 0.0.0.0, fault address 0x00000000.

Error - 11/28/2008 2:09:42 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 11/28/2008 10:27:43 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 11/29/2008 1:14:34 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 11/29/2008 1:00:11 PM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 11/30/2008 1:37:24 PM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 12/1/2008 7:26:13 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 12/1/2008 4:49:38 PM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

[ System Events ]
Error - 4/11/2010 10:06:56 PM | Computer Name = REINYSCOMP | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 4/11/2010 10:06:56 PM | Computer Name = REINYSCOMP | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 4/11/2010 10:07:23 PM | Computer Name = REINYSCOMP | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00508D9DC132 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 4/11/2010 10:09:41 PM | Computer Name = REINYSCOMP | Source = ipnathlp | ID = 31012
Description = The DNS proxy agent encountered an error while obtaining the local
list of name-resolution servers. Some DNS or WINS servers may be inaccessible to
clients on the local network. The data is the error code.

Error - 4/11/2010 10:09:41 PM | Computer Name = REINYSCOMP | Source = ipnathlp | ID = 31012
Description = The DNS proxy agent encountered an error while obtaining the local
list of name-resolution servers. Some DNS or WINS servers may be inaccessible to
clients on the local network. The data is the error code.

Error - 4/11/2010 10:09:48 PM | Computer Name = REINYSCOMP | Source = ipnathlp | ID = 31012
Description = The DNS proxy agent encountered an error while obtaining the local
list of name-resolution servers. Some DNS or WINS servers may be inaccessible to
clients on the local network. The data is the error code.

Error - 4/11/2010 10:10:42 PM | Computer Name = REINYSCOMP | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.11
on the Network Card with network address 00508D9DC132.

Error - 4/11/2010 11:54:57 PM | Computer Name = REINYSCOMP | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 4/11/2010 11:55:11 PM | Computer Name = REINYSCOMP | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 4/11/2010 11:55:11 PM | Computer Name = REINYSCOMP | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.


< End of report >
Hi aquadeath2,

We need to look for a replacement file but first we have a few things to take care of.

Do you have an XP disk?

You have a program who's drivers may interfere with some of our tools. We will use this next tool to disable the. Please leave them disabled until we are done.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers.
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.



Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :filefind
    rasacd.*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with the SystemLook log.

Thanks
I do have an XP disk. Pasted below is the result of the SystemLook scan. SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 17:05 on 12/04/2010 by Jason Reinhard (Administrator - Elevation successful) ========== filefind ========== Searching for "rasacd.*" C:\WINDOWS\system32\dllcache\rasacd.sys –a–c 8832 bytes [16:53 03/09/2002] [03:05 11/04/2010] FE0D99D6F31E4FAD8159F690D68DED9C C:\WINDOWS\system32\drivers\rasacd.sys –a— 8832 bytes [16:53 03/09/2002] [03:05 11/04/2010] FE0D99D6F31E4FAD8159F690D68DED9C -=End Of File=-
Hi aquadeath2,

Good. Let's try this first. We will rename a file and copy a new copy of it into the C:\WINDOWS\system32\drivers folder.


You may want to print out or copy and paste these instructions into a notepad as you will will be in safe mode and will not have access to this thread. Save the notepad to your desktop for east reference.

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.


Open windows explorer (right click your start button and click explore)
  • Double click local drive(c:)
  • At the top click Folders
  • Next click Tools
  • Click Folder Options
  • Click the view tab
  • check Display the contents of system folders
  • check Show hidden files and folders
  • uncheck "Hide extensions for known file types" box
  • uncheck "Hide protecting operating system files" box
Click apply, click ok

Navigate to this folder C:\WINDOWS\system32\dllcache
  • In the right hand panel locate this file rasacd.sys
  • Right click it and select copy

Next, in the left hand panel, navigate to this folder C:\WINDOWS\system32\drivers
  • In the left hand panel locate this file rasacd.sys
  • Right click it and select rename
  • On the keyboard, type rasacd.old
  • Hit enter and accept any warning you may be given

In the left hand panel right click on the drivers folder and select paste.

Please confirm the presence of both rasacd.old and rasacd.sys are present in the left hand panel. Please note rasacd.sys may be located at the bottom of the list.

Close the window and reboot into normal windows.

In normal windows,

Click your start button, click run. Copy and paste the following line into the run box and click ok.

cmd /c mbr -t>"%userprofile%\Desktop\mbr.txt"

A file called mbr.txt will appear on your desktop, please post it's contents.

How is the computer?

Thanks
Thank you very much for your time and help! That seemed to do the trick as I can now search on Yahoo without problem and TrendMirco is magically up to date. I am curious to know what the problem was and/or what virus/malware/rootkit/whatever I had and why moving over those files solved my problem. I have some knowledge about this stuff and just want to expand upon it if possible in case I see something like this again.

As requested, here are the contents of the mbr.txt file.

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys
kernel: MBR read successfully
user & kernel MBR OK
Hi aquadeath2,

You were infected with a variant of the TDL3 disk controller hijacker. We replaced the infected driver.

Let's continue and make sure nothing is remaining,


You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window. OTL.Txt


Plesae post back with
  • MBAM log
  • OTL.txt
Computer still ok?

Thanks
Everything still seems to be ok. I've done some searches and none of the links I clicked on were blocked and I was able to download and install a TrendMicro update. Pasted below are the contents of the two log files you requested.

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3985

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

4/13/2010 6:16:52 PM
mbam-log-2010-04-13 (18-16-52).txt

Scan type: Quick scan
Objects scanned: 101778
Time elapsed: 4 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

___________________________

OTL logfile created on: 4/13/2010 6:19:26 PM - Run 2
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 149.00 Gb Free Space | 63.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: REINYSCOMP
Current User Name: Jason Reinhard
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (wwEngineSvc) – C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (FirebirdServerMAGIXInstance) – C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)


========== Driver Services (SafeList) ==========

DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (tmactmon) – C:\WINDOWS\system32\drivers\tmactmon.sys ()
DRV - (tmevtmgr) – C:\WINDOWS\system32\drivers\tmevtmgr.sys ()
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys ()
DRV - (dvd43llh) – C:\WINDOWS\system32\drivers\dvd43llh.sys (RIF)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (JGOGO) – C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (WINFLASH) – C:\Program Files\U-ABIT\FlashMenu\WINFLASH.SYS ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Memctl) – C:\Program Files\U-ABIT\FlashMenu\MEMCTL.SYS ()
DRV - (RT25USBAP) – C:\WINDOWS\system32\drivers\rt25usbap.sys (Ralink Technology Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (SI3132) – C:\WINDOWS\System32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (SiFilter) – C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.fantasysports.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://sports.yahoo.com/fantasy"
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 7171
FF - prefs.js..network.proxy.no_proxies_on: "*.local,localhost,127.0.0.1"

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 03:31:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 03:31:12 | 000,000,000 | —D | M]

[2009/05/25 03:25:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Extensions
[2010/04/11 03:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Firefox\Profiles\2hqnyucz.default\extensions
[2010/04/10 18:46:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Firefox\Profiles\2hqnyucz.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
[2009/05/25 03:25:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/05/25 11:04:03 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1194497498187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1194497457718 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/08 00:13:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/04/13 18:05:00 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/04/12 19:07:57 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/12 19:07:55 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/04/11 14:37:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jason Reinhard\Recent
[2010/04/11 12:21:22 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/11 12:05:45 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/04/11 12:02:19 | 000,181,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/04/11 12:01:14 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/04/11 11:37:49 | 000,000,000 | —D | C] – C:\Program Files\HiJackThis
[2010/04/11 11:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Jason Reinhard\Application Data\Malwarebytes
[2010/04/11 11:24:21 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/11 11:24:19 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/11 11:24:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/11 11:24:18 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/11 00:52:12 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/11 00:02:45 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/10 23:25:54 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/04/10 23:25:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/10 19:18:37 | 000,067,200 | R— | C] (Silicon Image, Inc.) – C:\WINDOWS\System32\drivers\SI3132_2.sys
[2010/04/10 18:42:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Jason Reinhard\Application Data\QuickScan
[2010/04/10 17:40:57 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/04/10 15:23:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/09 17:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/03/24 16:42:00 | 000,000,000 | —D | C] – C:\Program Files\Doom
[2009/07/18 16:25:14 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/05/25 02:13:27 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2007/12/13 14:57:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/11/08 03:43:16 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[1996/11/17 17:00:00 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\IMPLODE.DLL
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/13 18:04:38 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/13 18:03:03 | 000,002,521 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Desktop\Microsoft Outlook.lnk
[2010/04/13 18:01:56 | 000,000,433 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010/04/13 18:01:36 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/13 18:01:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/12 22:40:47 | 006,553,600 | —- | M] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat
[2010/04/12 22:40:47 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Jason Reinhard\ntuser.ini
[2010/04/12 22:40:41 | 004,316,096 | -H– | M] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\IconCache.db
[2010/04/12 20:48:53 | 000,013,702 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/12 20:47:49 | 000,000,634 | —- | M] () – C:\WINDOWS\win.ini
[2010/04/12 20:47:49 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/12 20:47:49 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/12 19:08:06 | 000,001,100 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/04/12 19:08:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/12 17:03:09 | 000,000,000 | —- | M] () – C:\Documents and Settings\Jason Reinhard\defogger_reenable
[2010/04/10 23:05:26 | 000,008,832 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasacd.sys
[2010/04/04 12:34:05 | 000,870,128 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Application Data\mcs.rma
[2010/04/04 12:34:05 | 000,000,004 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Application Data\A0C936
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/28 16:37:40 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Desktop\Will Geroni.doc
[2010/03/24 16:44:00 | 000,000,044 | —- | M] () – C:\WINDOWS\WININIT.INI
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/12 20:49:44 | 000,000,277 | —- | C] () – C:\Documents and Settings\Jason Reinhard\mbr.log
[2010/04/12 19:08:06 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/12 17:03:09 | 000,000,000 | —- | C] () – C:\Documents and Settings\Jason Reinhard\defogger_reenable
[2010/04/11 12:04:20 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/10 19:05:19 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/08 16:47:28 | 000,000,803 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Desktop\Internet Explorer.lnk
[2010/03/28 13:48:40 | 000,024,064 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Desktop\Will Geroni.doc
[2010/03/25 21:39:30 | 006,553,600 | —- | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat
[2010/03/24 16:44:00 | 000,000,044 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/03/24 16:42:00 | 000,004,711 | —- | C] () – C:\WINDOWS\System32\dmouse.vxd
[2009/09/07 14:52:19 | 000,000,028 | —- | C] () – C:\WINDOWS\Robota.INI
[2009/09/07 14:46:27 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\mgxasio2.dll
[2009/09/07 14:45:23 | 000,120,200 | —- | C] () – C:\WINDOWS\System32\DLLDEV32i.dll
[2009/09/07 14:45:08 | 000,006,211 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2009/05/25 04:10:42 | 000,000,445 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\burnaware.ini
[2009/05/24 10:14:42 | 000,003,598 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\773F1E3B-FA7D-4EFD-BA91-EDE8C94400CB.txt
[2009/05/23 15:52:56 | 000,005,270 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\773F1E3B-FA7D-4EFD-BA91-EDE8C94400CB.txt
[2009/05/23 00:10:22 | 000,003,638 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\1B63A34D-D468-480C-9BFD-C7118A69BA98.txt
[2009/05/22 16:38:35 | 000,004,426 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\1B63A34D-D468-480C-9BFD-C7118A69BA98.txt
[2009/05/01 22:43:08 | 000,870,128 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\mcs.rma
[2009/05/01 22:43:08 | 000,000,004 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\A0C936
[2009/02/19 20:09:55 | 000,000,088 | —- | C] () – C:\WINDOWS\Battle.ini
[2009/02/19 20:09:55 | 000,000,037 | —- | C] () – C:\WINDOWS\progman.ini
[2008/09/05 17:35:43 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/05/20 17:49:20 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/05/20 17:49:20 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/05/20 17:49:20 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/05/19 21:56:56 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2008/05/17 00:16:25 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/05/16 23:45:01 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2008/05/09 23:33:40 | 000,000,252 | —- | C] () – C:\WINDOWS\dvdtoaviconverter.ini
[2008/04/24 22:00:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\AVSDVDPlayer.m3u
[2008/02/14 02:54:19 | 000,000,107 | —- | C] () – C:\Documents and Settings\Jason Reinhard\default.pls
[2008/02/12 15:48:36 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/12 10:20:02 | 000,001,024 | —- | C] () – C:\Documents and Settings\Jason Reinhard\.rnd
[2008/01/19 03:03:15 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2007/12/14 12:49:05 | 000,000,211 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Network.ini
[2007/11/28 01:47:35 | 000,000,600 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\PUTTY.RND
[2007/11/11 23:58:04 | 000,019,456 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/10 19:32:20 | 000,000,480 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/10 14:10:34 | 000,000,321 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\SephirothSkirmishStats.ini
[2007/11/10 14:10:34 | 000,000,112 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Skirmish.ini
[2007/11/10 14:08:50 | 000,000,407 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Options.ini
[2007/11/09 01:00:47 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2007/11/08 23:45:55 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2007/11/08 02:14:46 | 000,010,848 | —- | C] () – C:\WINDOWS\System32\drivers\WinFlash.sys
[2007/11/08 00:35:14 | 000,006,016 | —- | C] () – C:\WINDOWS\System32\drivers\ALLOW-IO.SYS
[2007/11/08 00:20:23 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat.LOG
[2007/11/08 00:20:23 | 000,000,278 | -HS- | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.ini
[2007/10/19 20:56:16 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/18 05:02:34 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/06/28 12:43:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/06/28 12:43:00 | 001,474,560 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/06/28 12:43:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/06/28 12:43:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/06/28 12:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:411E1BE2
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6971CCC5
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB669950
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B835CF2D
< End of report >
Hi aquadeath2,

Looks not to bad. You have old vulnerable java installed.

  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 19
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u19-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs and uninstall


Java™ 6 Update 3

Do not uninstall Java TM 6 Update 19 if found! :yeah:

Reboot your computer.

  • Double-click on the saved file ( jre-6u19-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

:Reg

:Files
C:\WINDOWS\system32\drivers\rasacd.old

:Commands
[emptytemp]

Then click the Run Fix button at the top
  • Let the program run unhindered

One more scan to check our work.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.
Please post back with
  • Kaspersky log
  • new OTL.txt
Thanks
I updated my JRE succesfully. However, when I went to run the OTL scan, it appeared to freeze as I had let it run for about 2 hours and it still said at the bottom, "Killing processes…DO NOT INTERRUPT." I did not run the Kaspersky scan since I did not get through the OTL scan. Thoughts/suggestions/next course of action?
Hi

I'm not sure why OTL would have stalled. Close it if it's still open.

Then do this


Create and run this batchfile

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad.
Do Not copy the word CODE

@echo off
reg query "HKLM\system\currentcontrolset\services\rasacd" /v imagepath > result.txt
start result.txt
del %0

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "myfix.bat"
  • Click save

You will have a new file on your desktop called myfix.bat with an icon that looks like this 📎bat.PNG

Double click myfix.bat to run it. A notepad named result.txt will open, please posts it's contents.


Open OTL and obtain a new scan log.
Pasted below are the two logs you requested:

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\system\currentcontrolset\services\rasacd
imagepath REG_EXPAND_SZ System32\DRIVERS\rasacd.sys
_________________________________________________________________

OTL logfile created on: 4/15/2010 4:14:44 PM - Run 3
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 151.89 Gb Free Space | 65.23% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: REINYSCOMP
Current User Name: Jason Reinhard
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (wwEngineSvc) – C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (FirebirdServerMAGIXInstance) – C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)


========== Driver Services (SafeList) ==========

DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (tmactmon) – C:\WINDOWS\system32\drivers\tmactmon.sys ()
DRV - (tmevtmgr) – C:\WINDOWS\system32\drivers\tmevtmgr.sys ()
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys ()
DRV - (dvd43llh) – C:\WINDOWS\system32\drivers\dvd43llh.sys (RIF)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (JGOGO) – C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (WINFLASH) – C:\Program Files\U-ABIT\FlashMenu\WINFLASH.SYS ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Memctl) – C:\Program Files\U-ABIT\FlashMenu\MEMCTL.SYS ()
DRV - (RT25USBAP) – C:\WINDOWS\system32\drivers\rt25usbap.sys (Ralink Technology Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (SI3132) – C:\WINDOWS\System32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (SiFilter) – C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.fantasysports.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://sports.yahoo.com/fantasy"
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 7171
FF - prefs.js..network.proxy.no_proxies_on: "*.local,localhost,127.0.0.1"

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 03:31:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/14 18:54:13 | 000,000,000 | —D | M]

[2009/05/25 03:25:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Extensions
[2010/04/11 03:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Firefox\Profiles\2hqnyucz.default\extensions
[2010/04/10 18:46:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Firefox\Profiles\2hqnyucz.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
[2010/04/14 18:54:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/05/25 11:04:03 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1194497498187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1194497457718 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/08 00:13:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found – C:\WINDOWS\System32\drivers\rasacd.old
[2010/04/14 18:54:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/14 18:54:13 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/04/14 18:54:13 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/04/14 18:54:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/04/14 18:54:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/04/14 18:54:13 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/04/12 19:07:57 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/12 19:07:55 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/04/11 14:37:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jason Reinhard\Recent
[2010/04/11 12:21:22 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/11 12:05:45 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/04/11 12:02:19 | 000,181,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/04/11 12:01:14 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/04/11 11:37:49 | 000,000,000 | —D | C] – C:\Program Files\HiJackThis
[2010/04/11 11:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Jason Reinhard\Application Data\Malwarebytes
[2010/04/11 11:24:21 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/11 11:24:19 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/11 11:24:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/11 11:24:18 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/11 00:52:12 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/11 00:02:45 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/10 23:25:54 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/04/10 23:25:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/10 19:18:37 | 000,067,200 | R— | C] (Silicon Image, Inc.) – C:\WINDOWS\System32\drivers\SI3132_2.sys
[2010/04/10 18:42:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Jason Reinhard\Application Data\QuickScan
[2010/04/10 17:40:57 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/04/10 15:23:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/09 17:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/03/24 16:42:00 | 000,000,000 | —D | C] – C:\Program Files\Doom
[2009/07/18 16:25:14 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/05/25 02:13:27 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2007/12/13 14:57:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/11/08 03:43:16 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[1996/11/17 17:00:00 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\IMPLODE.DLL
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/15 16:12:45 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/15 16:10:15 | 000,000,433 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010/04/15 16:10:02 | 000,002,521 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Desktop\Microsoft Outlook.lnk
[2010/04/15 16:09:42 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/15 16:09:36 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/14 22:18:40 | 006,553,600 | —- | M] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat
[2010/04/14 22:18:40 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Jason Reinhard\ntuser.ini
[2010/04/14 18:55:22 | 004,318,424 | -H– | M] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\IconCache.db
[2010/04/14 18:55:14 | 000,000,634 | —- | M] () – C:\WINDOWS\win.ini
[2010/04/14 18:55:14 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/14 18:55:14 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/14 18:53:46 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/04/14 18:53:46 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/04/14 18:53:46 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/04/14 18:53:46 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/04/14 18:53:46 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/04/13 20:02:25 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\tmvsthfud.bin
[2010/04/13 20:02:20 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\tmvsthfss.bin
[2010/04/13 18:28:45 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/12 20:48:53 | 000,013,702 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/12 19:08:06 | 000,001,100 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/04/12 19:08:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/12 17:03:09 | 000,000,000 | —- | M] () – C:\Documents and Settings\Jason Reinhard\defogger_reenable
[2010/04/10 23:05:26 | 000,008,832 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasacd.sys
[2010/04/04 12:34:05 | 000,870,128 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Application Data\mcs.rma
[2010/04/04 12:34:05 | 000,000,004 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Application Data\A0C936
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/24 16:44:00 | 000,000,044 | —- | M] () – C:\WINDOWS\WININIT.INI
[2010/03/19 18:05:50 | 004,874,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmp.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/13 18:26:30 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/04/12 20:49:44 | 000,000,277 | —- | C] () – C:\Documents and Settings\Jason Reinhard\mbr.log
[2010/04/12 19:08:06 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/12 17:03:09 | 000,000,000 | —- | C] () – C:\Documents and Settings\Jason Reinhard\defogger_reenable
[2010/04/11 12:04:20 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/10 19:05:19 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/08 16:47:28 | 000,000,803 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Desktop\Internet Explorer.lnk
[2010/03/25 21:39:30 | 006,553,600 | —- | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat
[2010/03/24 16:44:00 | 000,000,044 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/03/24 16:42:00 | 000,004,711 | —- | C] () – C:\WINDOWS\System32\dmouse.vxd
[2009/09/07 14:52:19 | 000,000,028 | —- | C] () – C:\WINDOWS\Robota.INI
[2009/09/07 14:46:27 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\mgxasio2.dll
[2009/09/07 14:45:23 | 000,120,200 | —- | C] () – C:\WINDOWS\System32\DLLDEV32i.dll
[2009/09/07 14:45:08 | 000,006,211 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2009/05/25 04:10:42 | 000,000,445 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\burnaware.ini
[2009/05/24 10:14:42 | 000,003,598 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\773F1E3B-FA7D-4EFD-BA91-EDE8C94400CB.txt
[2009/05/23 15:52:56 | 000,005,270 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\773F1E3B-FA7D-4EFD-BA91-EDE8C94400CB.txt
[2009/05/23 00:10:22 | 000,003,638 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\1B63A34D-D468-480C-9BFD-C7118A69BA98.txt
[2009/05/22 16:38:35 | 000,004,426 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\1B63A34D-D468-480C-9BFD-C7118A69BA98.txt
[2009/05/01 22:43:08 | 000,870,128 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\mcs.rma
[2009/05/01 22:43:08 | 000,000,004 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\A0C936
[2009/02/19 20:09:55 | 000,000,088 | —- | C] () – C:\WINDOWS\Battle.ini
[2009/02/19 20:09:55 | 000,000,037 | —- | C] () – C:\WINDOWS\progman.ini
[2008/09/05 17:35:43 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/07/31 19:37:00 | 000,142,864 | —- | C] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2008/07/31 19:37:00 | 000,052,752 | —- | C] () – C:\WINDOWS\System32\drivers\tmactmon.sys
[2008/07/31 19:37:00 | 000,052,624 | —- | C] () – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2008/05/20 17:49:20 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/05/20 17:49:20 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/05/20 17:49:20 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/05/19 21:56:56 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2008/05/17 00:16:25 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/05/16 23:45:01 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2008/05/09 23:33:40 | 000,000,252 | —- | C] () – C:\WINDOWS\dvdtoaviconverter.ini
[2008/04/24 22:00:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\AVSDVDPlayer.m3u
[2008/02/14 02:54:19 | 000,000,107 | —- | C] () – C:\Documents and Settings\Jason Reinhard\default.pls
[2008/02/12 15:48:36 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/12 10:20:02 | 000,001,024 | —- | C] () – C:\Documents and Settings\Jason Reinhard\.rnd
[2008/01/19 03:03:15 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2007/12/14 12:49:05 | 000,000,211 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Network.ini
[2007/11/28 01:47:35 | 000,000,600 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\PUTTY.RND
[2007/11/11 23:58:04 | 000,019,456 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/10 19:32:20 | 000,000,480 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/10 14:10:34 | 000,000,321 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\SephirothSkirmishStats.ini
[2007/11/10 14:10:34 | 000,000,112 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Skirmish.ini
[2007/11/10 14:08:50 | 000,000,407 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Options.ini
[2007/11/09 01:00:47 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2007/11/08 23:45:55 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2007/11/08 02:14:46 | 000,010,848 | —- | C] () – C:\WINDOWS\System32\drivers\WinFlash.sys
[2007/11/08 00:35:14 | 000,006,016 | —- | C] () – C:\WINDOWS\System32\drivers\ALLOW-IO.SYS
[2007/11/08 00:20:23 | 000,016,384 | -H– | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat.LOG
[2007/11/08 00:20:23 | 000,000,278 | -HS- | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.ini
[2007/10/19 20:56:16 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/18 05:02:34 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/06/28 12:43:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/06/28 12:43:00 | 001,474,560 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/06/28 12:43:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/06/28 12:43:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/06/28 12:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:411E1BE2
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6971CCC5
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB669950
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B835CF2D
< End of report >
Hi

That looks ok. Might have been Trend Micro not wanting to be stooped. Let's do it this way.

Open FireFox

Under "Tools" in the browser tool bar select "Options".
In the "Options" window that pops up, click the "Advanced" tab at the top.
Click the "Network" subtab, and then click the "Settings" button in the "Connections" area.
If "No proxy" isn't selected, click it to mark "No proxy"



Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.


Then run the Kaspersky online scan.
Here is the result of the Kaspersky scan. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, April 15, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, April 15, 2010 22:03:40 Records in database: 3949128 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Objects scanned: 77603 Threats found: 1 Infected objects found: 1 Suspicious objects found: 0 Scan duration: 01:31:26 File name / Threat / Threats count C:\Program Files\Trend Micro\Internet Security\Quarantine\trfepalu.dll Infected: Trojan-Clicker.Win32.Delf.cbe 1 Selected area has been scanned.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI