This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google redirect/XP antispyware infection

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got the rogue XP Antispyware 2010 popups a few days ago. I was finally able to get Malware Bytes to run and it seemed to clear that up. However, I still have some issues with google search results redirecting my browser to different ad pages, some of which trigger Avast antivirus. I tried researching how to rid this thing, but there were many solutions, and the few I tried did not work, so I am hoping you can help me. Thank you!


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:04:00.62 on Tue 04/13/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.766.171 [GMT -4:00]

AV: avast! antivirus 4.8.1368 [VPS 100413-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Pink Calendar\PinkCal.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\ASTSRV.EXE
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Palo Alto Networks\Pan Connect\PanService.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Photodex\ProShowGold\progold3\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Red NoteBook\RedNoteBook.exe
C:\Documents and Settings\AndiL\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.refdesk.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: BayScribeObj Class: {5e028439-81c7-4b82-bc74-25156306f532} - c:\program files\bayscribe\bayscribe.dll
BHO: My Web Search Bar BHO: {8eab99c1-f9ec-4b64-a4ba-d9bcae8779c2} - c:\program files\mywebsearchwb\bar\1.bin\W6BAR.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {871F91FD-3A92-4988-A842-16AB2CFF5AF1} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {9404901D-06DA-4B23-A0EE-3EA4F64EC9B3} - No File
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [FinePrint Dispatcher v5] c:\windows\system32\spool\drivers\w32x86\3\fpdisp5a.exe
mRun: [F5D9050] c:\program files\belkin\f5d9050\Belkinwcui.exe
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [BCMSMMSG] BCMSMMSG.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SBAutoUpdate] "c:\program files\spywareblaster\sbautoupdate.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\andil\startm~1\programs\startup\pinkcal.lnk - c:\program files\pink calendar\PinkCal.exe
IE: c:\progra~1\common~1\btlink\btlink.dll//iemenu
IE: Add to Evernote - c:\program files\evernote\evernote3\enbar.dll/2000
IE: Add to EverNote - c:\program files\evernote\evernote\enbar.dll/2000
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: GuruNet… - file:c:\program files\gurunet\html\atiemenu.htm
IE: Locate Spot on Map by GPS - c:\program files\opanda\iexif 2.3\IExifMap.htm
IE: View Exif/GPS/IPTC with IExif - c:\program files\opanda\iexif 2.3\IExifCom.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {E0B8C461-F8FB-49b4-8373-FE32E9252800} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEE1} - c:\program files\evernote\evernote3\enbar.dll
Trusted Zone: adp.com
Trusted Zone: aol.com\free
Trusted Zone: dictaphone.com
Trusted Zone: ichart.com
Trusted Zone: nuance.com
Trusted Zone: seormc.org\connect
Trusted Zone: transcendservices.com
Trusted Zone: trcr.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/0/f/b/0fb0fab9-7f09-4bb6-86d8-8e791ba99ac5/VirtualEarth3D.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} - hxxp://www.pestscan.com/scanner/axscanner.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos2.walmart.com/WalmartActivia.cab
DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe
DPF: {53D40FAA-4E21-459F-AA87-E4D97FC3245A} - hxxps://www.transcendservices.com/help/Agent/setup.exe
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.adoramapix.com/components/aurigma/ImageUploader5.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - hxxp://toolbar.google.com/data/GoogleActivate.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9DDB393E-A5C2-40F7-A37F-4957CAC7C65C} - hxxp://workportal01.trcr.com/clientinstall/production/BTClient/ActiveXLoader.CAB
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {EF2E2523-5E55-4A8F-A0C9-0F2B7457290C} - hxxps://mls.trcr.com/CABS/SWTrackerCTL.CAB
DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} - hxxp://samsclubus.pnimedia.com/upload/activex/v3_0_0_2/PhotoCenter_ActiveX_Control.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: LMIinit - LMIinit.dll
AppInit_DLLs: WIKI.DLL c:\progra~1\google\google~3\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 relog_ap
LSA: Notification Packages = :\windows\system32\srrstr.dll cecli scecli scecli scecli

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-7 114768]
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [2009-1-7 57344]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-7 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-7 138680]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-8-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-1-24 47640]
R2 PanService;PanService;c:\program files\palo alto networks\pan connect\PanService.exe [2009-8-31 950272]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-12-11 3032360]
R3 PanSvd;Pan Virtual Miniport;c:\windows\system32\drivers\pansvd.sys [2009-8-31 27136]
R3 StreamSurge;StreamSurge Driver (miniport);c:\windows\system32\drivers\ss.sys [2008-8-20 19968]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-31 135664]
S3 APL531;OVT Scanner;c:\windows\system32\drivers\ov550i.sys [2006-7-31 580992]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-8-7 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-8-7 352920]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2008-9-21 14336]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-1-4 30192]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2008-12-11 15144]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 ohciusb;Open Host Controller Miniport USB Driver; [x]

=============== Created Last 30 ================

2010-04-12 21:06 664 a——- c:\windows\system32\d3d9caps.dat
2010-04-12 21:06 1,409 a——- c:\windows\QTFont.for
2010-04-12 21:06 54,156 a—h— c:\windows\QTFont.qfn
2010-04-12 09:50 411,368 a——- c:\windows\system32\deploytk.dll
2010-04-12 09:50 73,728 a——- c:\windows\system32\javacpl.cpl
2010-04-12 09:36 –d—– c:\program files\SpywareBlaster
2010-04-12 01:11 –d—– c:\windows\system32\wbem\Repository
2010-04-11 21:04 -cd—– C:\RootkitNO
2010-04-11 20:47 –d—– c:\program files\UnHackMe
2010-04-10 14:41 12,872 a——- c:\windows\system32\bootdelete.exe
2010-04-10 00:47 15,944 a——- c:\windows\system32\drivers\hitmanpro35.sys
2010-04-10 00:46 –d—– c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-04-10 00:46 –d—– c:\program files\Hitman Pro 3.5
2010-04-09 20:55 –d—– c:\documents and settings\andil\DoctorWeb
2010-04-08 13:22 279,552 a——- c:\windows\system32\swreg.exe
2010-04-08 13:22 109,056 a——- c:\windows\catchme.exe
2010-04-08 13:22 212,480 a——- c:\windows\system32\swxcacls.exe
2010-04-08 13:22 -cd—– C:\ComboFix
2010-04-08 01:19 –d—– c:\program files\CCleaner
2010-04-08 01:19 –d—– c:\docume~1\alluse~1\applic~1\avG
2010-03-31 00:44 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2010-03-19 01:22 61,224 a——- c:\documents and settings\andil\GoToAssistDownloadHelper.exe

==================== Find3M ====================

2010-04-12 23:34 4 a——- c:\docume~1\andil\applic~1\EXText Diagnostic Upload Queue.dat
2010-04-11 20:49 95,360 a——- c:\windows\system32\drivers\atapi.sys
2010-04-07 15:30 141,199 a——- c:\windows\hpoins14.dat
2010-03-30 09:32 365,440 ac—— c:\docume~1\andil\applic~1\GDIPFONTCACHEV1.DAT
2010-03-30 01:46 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 01:45 20,824 a——- c:\windows\system32\drivers\mbam.sys
2010-03-29 00:18 365,440 a——- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-30 19:49 84,992 a——- c:\windows\system32\atl70.dll
2010-01-14 22:30 60,744 a——- c:\documents and settings\andil\g2mdlhlpx.exe
2005-09-19 13:30 774,144 a——- c:\program files\RngInterstitial.dll
2005-05-07 22:49 6,132 ac—— c:\program files\top52–0047.htm
2005-05-07 22:48 6,132 ac—— c:\program files\top52–0028.htm
2005-05-07 22:47 1,039,189 ac—— c:\program files\01mp3ins.exe
2005-04-17 13:07 1,584,088 ac—— c:\program files\earpro4setup.exe
2005-03-27 21:08 10,831,584 ac—— c:\program files\PestPatrolv5.exe
2004-10-20 22:18 376,672 ac—— c:\program files\DLM_2200043_ENU.exe
2004-06-22 22:03 411,329 ac—— c:\program files\slimlist.exe
2004-05-04 12:50 8,029,451 ac—— c:\program files\SetupPestPatrolHome.exe
2004-04-07 10:28 2,736,029 ac—— c:\program files\treepadplus.zip
2004-02-20 00:15 457 ac—— c:\program files\INSTALL.LOG
2003-05-21 20:10 3,662,787 ac—— c:\program files\spybotsd12.exe
2003-05-15 12:17 2,838,184 ac—— c:\program files\ica32.exe
2003-05-14 00:30 260,684 ac—— c:\program files\ICQMessageArchive.exe
2003-05-13 19:14 1,897,672 ac—— c:\program files\winzip81.exe
2003-05-12 23:51 660,696 ac—— c:\program files\rednotebook19b.exe
2003-05-12 19:55 5,082,328 ac—— c:\program files\cuteftppro.exe
2003-05-12 19:48 3,025,408 ac—— c:\program files\cuteftp.exe
2003-05-12 19:16 3,978,384 ac—— c:\program files\icqpro2003a.exe

============= FINISH: 10:06:09.98 ===============

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-13 13:52:24
Windows 5.1.2600 Service Pack 2
Running: ryjnihwn.exe; Driver: C:\DOCUME~1\AndiL\LOCALS~1\Temp\pxtdrpod.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEE0766B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xEE076574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEE076A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEE07614C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xEE07664E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEE07608C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEE0760F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEE07676E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEE07672E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEE0768AE]

Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwCreateProcess [0xEE305878]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwCreateProcessEx [0xEE3059BC]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwCreateSection [0xEE305556]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwLoadDriver [0xEE3053FE]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwSetSystemInformation [0xEE30536C]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) NtCreateSection

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntoskrnl.exe!NtCreateSection 8056469B 7 Bytes JMP EE30555A \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
PAGE ntoskrnl.exe!ZwCreateProcessEx 80581F0E 7 Bytes JMP EE3059C0 \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
PAGE ntoskrnl.exe!ZwSetSystemInformation 805A26F4 5 Bytes JMP EE305370 \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
PAGE ntoskrnl.exe!ZwLoadDriver 805A410A 7 Bytes JMP EE305402 \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
PAGE ntoskrnl.exe!ZwCreateProcess 805B0B34 5 Bytes JMP EE30587C \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
? dhmcf.sys The system cannot find the file specified. !
.rsrc C:\WINDOWS\System32\DRIVERS\imapi.sys entry point in ".rsrc" section [0xF789C214]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\Explorer.EXE[976] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 008C000A
.text C:\WINDOWS\Explorer.EXE[976] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 008D000A
.text C:\WINDOWS\Explorer.EXE[976] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 008B000C
.text C:\WINDOWS\system32\wuauclt.exe[3416] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 003B000A
.text C:\WINDOWS\system32\wuauclt.exe[3416] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 003C000A
.text C:\WINDOWS\system32\wuauclt.exe[3416] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 003A000C
.text C:\WINDOWS\System32\svchost.exe[3956] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 003A000A
.text C:\WINDOWS\System32\svchost.exe[3956] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 003B000A
.text C:\WINDOWS\System32\svchost.exe[3956] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 0039000C
.text C:\WINDOWS\System32\svchost.exe[3956] USER32.dll!GetCursorPos 77D4BD76 5 Bytes JMP 00DC000A
.text C:\WINDOWS\System32\svchost.exe[3956] ole32.dll!CoCreateInstance 774FFAC3 3 Bytes JMP 00DB000A
.text C:\WINDOWS\System32\svchost.exe[3956] ole32.dll!CoCreateInstance + 4 774FFAC7 1 Byte [89]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device -> \Driver\atapi \Device\Harddisk0\DR0 83D51AC8

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Control.dll 499712 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\dirapi.dll 1490944 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\DynaPlayer.dll 24576 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\iml32.dll 630784 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Install.log 77819 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Plugin.dll 249856 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\PluginPing.dll 397312 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Proj.dll 151552 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\QuitRemote.exe 45056 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr 9622 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\SwInit.exe 77824 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\SwLogo.bmp 42040 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\SwMenu.dll 86016 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\SwOnce.dll 98304 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\UNWISE.EXE 149504 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\autodownload.txt 2379 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\CBrowser.x32 28672 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download\MacromediaInc 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download\MacromediaInc\AnimatedGIFAssetw32 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download\MacromediaInc\MixServices 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download\MacromediaInc\PNGImportExport 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\INetURL.x32 40960 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\Multiusr.x32 159744 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\Netfile.x32 53248 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\Netlingo.x32 49152 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\Speech.x32 53248 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Control.dll 483328 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\dirapi.dll 1097728 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\dirapi.mch 41493 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Download.dll 65536 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Download.exe 40960 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\DswMedia 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\DynaPlayer.dll 24576 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\iml32.dll 561152 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Install.log 35929 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Plugin.dll 249856 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\PluginPing.dll 380928 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Prefs 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Proj.dll 159744 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\QuitRemote.exe 45056 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Shockwave Log 82542 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwInit.exe 77824 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwLogo.bmp 15414 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwMenu.dll 90112 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwOnce.dll 94208 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\UNWISE.EXE 162304 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\CBrowser.x32 28672 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\DirectSound.x32 32768 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Flash Asset.x32 753664 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Font Asset.x32 69632 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Font Xtra.x32 282624 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\INetURL.x32 49152 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\MacroMix.x32 53248 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Multiusr.x32 159744 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Netfile.x32 53248 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Netlingo.x32 49152 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Shockwave 3d Asset.x32 1560576 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Shockwave Updater.x32 61440 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Sound Control.x32 53248 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Speech.x32 57344 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Swadcmpr.x32 69632 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Swastrm.x32 57344 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Text Asset.x32 98304 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\TextXtra.x32 348160 bytes executable
File C:\WINDOWS\System32\DRIVERS\imapi.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-

Attachments:

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

1.Please do not run any other tool untill instructed to do so!
2.Please reply to this thread, do not start another!
3.Please tell me about any problems that have occurred during the fix.
4.Please tell me of any other symptoms you may be having as these can help also.
5.Please try as much as possible not to run anything while executing a fix.

If you follow these instructions, everything should go smoothly.

uninstall some programs

1. click on start
2. then go to settings
3. after that you need control panel
4. look for the icon add/remove programs
click on the following programs

Coupon Printer for Windows
DNA
WeatherBug
WeatherBug Browser Bar - powered by MyWebSearch


and click on remove



SystemLook:

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
:filefind
imapi.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

:run combofix:

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode.
This allows us to more easily help you should your computer have a problem after an attempted removal of malware.
It is a simple procedure that will only take a few moments of your time.


Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.
Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the report in your next post:

C:\ComboFix.txt


"information and logs"

  • In your next post I need the following

  • Log from system look
  • log from combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
Thank you for the quick reply.

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 16:20 on 13/04/2010 by AndiL (Administrator - Elevation successful)

========== filefind ==========

Searching for "imapi.sys"
C:\I386\IMAPI.SYS –a–c 39808 bytes [20:08 01/05/2003] [10:00 29/08/2002] 3CB4410747F2330D97B10B656D5BB2AC
C:\WINDOWS\$NtServicePackUninstall$\imapi.sys —–c 39808 bytes [23:32 21/09/2008] [10:00 29/08/2002] 3CB4410747F2330D97B10B656D5BB2AC
C:\WINDOWS\ServicePackFiles\i386\imapi.sys —— 41856 bytes [23:52 21/09/2008] [04:00 04/08/2004] F8AA320C6A0409C0380E5D8A99D76EC6
C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\imapi.sys –a— 42112 bytes [15:58 20/12/2008] [18:40 13/04/2008] 083A052659F5310DD8B6A6CB05EDCF8E
C:\WINDOWS\SoftwareDistribution\Download\9ded4ee34a35fced0033d3e152a36e0e\imapi.sys –a–c 41856 bytes [06:00 04/08/2004] [06:00 04/08/2004] F8AA320C6A0409C0380E5D8A99D76EC6
C:\WINDOWS\SYSTEM32\DRIVERS\imapi.sys –a— 41856 bytes [18:17 21/09/2008] [17:43 13/04/2010] F8AA320C6A0409C0380E5D8A99D76EC6

-=End Of File=-


ComboFix 10-04-13.02 - AndiL 04/13/2010 16:45:33.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.766.315 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100413-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\AndiL\Local Settings\Temporary Internet Files\070NXwOk7.jpg
c:\documents and settings\AndiL\Local Settings\Temporary Internet Files\8AvoVh.jpg
c:\documents and settings\AndiL\Local Settings\Temporary Internet Files\ck2fg8kc.jpg
c:\documents and settings\AndiL\Local Settings\Temporary Internet Files\HAcY2.jpg
c:\documents and settings\AndiL\Recent\bayscribe.com.url
c:\program files\INSTALL.LOG
c:\program files\Internet Explorer\SET6A7.tmp
c:\program files\Shared
c:\windows\eSellerateEngine.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\ss.sys
c:\windows\system32\Temp
c:\windows\system32\tmp.reg
G:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_OHCIUSB
——-\Service_ohciusb
——-\Service_StreamSurge


((((((((((((((((((((((((( Files Created from 2010-03-13 to 2010-04-13 )))))))))))))))))))))))))))))))
.

2010-04-13 13:59 . 2010-04-13 13:59 ——– d—–w- c:\program files\ERUNT
2010-04-13 13:16 . 2010-04-13 13:16 ——– d-s—w- c:\documents and settings\LocalService\UserData
2010-04-13 01:06 . 2010-04-13 01:06 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-13 01:06 . 2010-04-13 01:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-04-12 13:51 . 2010-04-12 13:51 ——– d—–w- c:\program files\Common Files\Java
2010-04-12 13:50 . 2010-04-12 13:49 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-04-12 13:36 . 2010-04-13 18:00 ——– d—–w- c:\program files\SpywareBlaster
2010-04-12 05:11 . 2010-04-12 05:11 ——– d—–w- c:\windows\system32\wbem\Repository
2010-04-12 01:04 . 2010-04-12 01:04 ——– dc—-w- C:\RootkitNO
2010-04-12 00:47 . 2010-04-12 05:11 ——– d—–w- c:\program files\UnHackMe
2010-04-11 18:35 . 2010-04-11 18:35 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities
2010-04-10 18:41 . 2010-04-10 18:41 12872 —-a-w- c:\windows\system32\bootdelete.exe
2010-04-10 15:27 . 2010-04-10 15:27 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Identities
2010-04-10 04:47 . 2010-04-12 05:16 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-04-10 04:46 . 2010-04-10 18:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-04-10 04:46 . 2010-04-10 04:46 ——– d—–w- c:\program files\Hitman Pro 3.5
2010-04-10 00:55 . 2010-04-10 01:41 ——– d—–w- c:\documents and settings\AndiL\DoctorWeb
2010-04-09 12:28 . 2010-04-09 12:28 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-04-08 13:15 . 2010-04-08 13:15 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2010-04-08 05:19 . 2010-04-08 05:19 ——– d—–w- c:\program files\CCleaner
2010-04-08 05:19 . 2010-04-08 05:19 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\avG
2010-04-08 05:19 . 2010-04-08 05:19 ——– d—–w- c:\documents and settings\All Users\Application Data\avG
2010-03-31 04:44 . 2010-03-31 04:44 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-03-19 05:22 . 2010-03-19 05:22 ——– d—–w- c:\documents and settings\AndiL\Local Settings\Application Data\Citrix
2010-03-19 05:22 . 2010-03-19 05:22 61224 —-a-w- c:\documents and settings\AndiL\GoToAssistDownloadHelper.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-13 21:10 . 2008-12-11 16:39 ——– d—–w- c:\documents and settings\AndiL\Application Data\WTablet
2010-04-13 21:09 . 2008-04-12 13:54 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-13 20:16 . 2008-06-06 04:41 ——– d—–w- c:\program files\DNA
2010-04-13 20:16 . 2009-02-25 15:30 ——– d—–w- c:\program files\Coupons
2010-04-13 20:12 . 2010-01-31 03:04 4 —-a-w- c:\documents and settings\AndiL\Application Data\EXText Diagnostic Upload Queue.dat
2010-04-13 17:43 . 2008-09-21 18:17 41856 —-a-w- c:\windows\system32\drivers\imapi.sys
2010-04-13 05:37 . 2005-03-30 04:18 ——– d—–w- c:\documents and settings\AndiL\Application Data\BayScribe
2010-04-12 13:49 . 2005-07-27 19:11 ——– d—–w- c:\program files\Java
2010-04-12 01:29 . 2003-08-12 16:55 ——– d—–w- c:\program files\Trend Micro
2010-04-12 00:49 . 2008-09-21 18:17 95360 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-04-10 18:41 . 2008-03-02 18:36 ——– d—–w- c:\program files\ActionDex
2010-04-09 04:06 . 2010-03-05 21:46 ——– d—–w- c:\program files\T2KAdmin
2010-04-08 05:19 . 2003-09-03 15:19 ——– d—–w- c:\documents and settings\All Users\Application Data\GuruNet
2010-04-08 05:19 . 2009-09-07 03:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-08 03:16 . 2007-08-24 04:41 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-04-08 03:14 . 2007-08-24 04:40 ——– d—–w- c:\documents and settings\AndiL\Application Data\SUPERAntiSpyware.com
2010-04-08 03:13 . 2009-11-10 23:32 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-04-07 19:30 . 2008-03-18 16:14 141199 —-a-w- c:\windows\hpoins14.dat
2010-04-06 22:28 . 2010-03-05 21:45 ——– d—–w- c:\program files\Common Files\TRCR
2010-03-30 05:46 . 2009-09-07 03:49 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 05:45 . 2009-09-07 03:49 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-29 04:18 . 2008-06-19 12:34 365440 —-a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-03-21 18:55 . 2003-05-13 03:51 ——– d—–w- c:\program files\Red NoteBook
2010-03-07 14:19 . 2010-03-04 21:21 ——– d—–w- c:\documents and settings\All Users\Application Data\boost_interprocess
2010-03-05 21:58 . 2010-03-05 21:45 ——– d—–w- c:\program files\TRCR
2010-03-05 21:56 . 2010-03-05 21:56 ——– d—–w- c:\documents and settings\AndiL\Application Data\Transcend
2010-03-05 21:47 . 2010-03-05 21:47 ——– d—–w- c:\program files\VoiceScribe
2010-03-05 21:47 . 2003-04-29 23:21 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-05 21:46 . 2010-03-05 21:45 ——– d—–w- c:\program files\Common Files\MModal
2010-03-05 21:34 . 2010-03-05 21:33 ——– d—–w- c:\program files\iTivity
2010-03-04 21:11 . 2010-03-04 21:11 ——– d—–w- c:\program files\Common Files\Topaz Labs
2010-03-04 21:11 . 2009-01-22 18:25 ——– d—–w- c:\program files\Topaz Labs
2010-02-18 19:37 . 2010-01-31 02:44 ——– d—–w- c:\documents and settings\AndiL\Application Data\UPD_TEMP
2010-01-30 23:49 . 2010-01-30 23:49 84992 —-a-w- c:\windows\system32\atl70.dll
2010-01-15 02:30 . 2010-01-15 02:30 60744 —-a-w- c:\documents and settings\AndiL\g2mdlhlpx.exe
2005-09-19 17:30 . 2005-09-19 17:30 774144 —-a-w- c:\program files\RngInterstitial.dll
2005-05-08 02:49 . 2005-05-08 02:49 6132 -c–a-w- c:\program files\top52–0047.htm
2005-05-08 02:48 . 2005-05-08 02:48 6132 -c–a-w- c:\program files\top52–0028.htm
2005-05-08 02:47 . 2005-05-08 02:47 1039189 -c–a-w- c:\program files\01mp3ins.exe
2005-04-17 17:07 . 2005-04-17 17:07 1584088 -c–a-w- c:\program files\earpro4setup.exe
2005-03-28 01:08 . 2005-03-28 01:08 10831584 -c–a-w- c:\program files\PestPatrolv5.exe
2004-10-21 02:18 . 2004-10-21 02:18 376672 -c–a-w- c:\program files\DLM_2200043_ENU.exe
2004-06-23 02:03 . 2004-06-23 02:03 411329 -c–a-w- c:\program files\slimlist.exe
2004-05-04 16:50 . 2004-05-04 16:50 8029451 -c–a-w- c:\program files\SetupPestPatrolHome.exe
2004-04-07 14:28 . 2004-04-07 14:28 2736029 -c–a-w- c:\program files\treepadplus.zip
2003-05-22 00:10 . 2003-05-22 00:10 3662787 -c–a-w- c:\program files\spybotsd12.exe
2003-05-15 16:17 . 2003-05-15 16:17 2838184 -c–a-w- c:\program files\ica32.exe
2003-05-14 04:30 . 2003-05-14 04:30 260684 -c–a-w- c:\program files\ICQMessageArchive.exe
2003-05-13 23:14 . 2003-05-13 23:14 1897672 -c–a-w- c:\program files\winzip81.exe
2003-05-13 03:51 . 2003-05-13 03:51 660696 -c–a-w- c:\program files\rednotebook19b.exe
2003-05-12 23:55 . 2003-05-12 23:55 5082328 -c–a-w- c:\program files\cuteftppro.exe
2003-05-12 23:48 . 2003-05-12 23:42 3025408 -c–a-w- c:\program files\cuteftp.exe
2003-05-12 23:16 . 2003-05-12 23:16 3978384 -c–a-w- c:\program files\icqpro2003a.exe
2003-08-15 15:43 . 2003-08-15 15:43 98304 —-a-w- c:\program files\internet explorer\plugins\IEHelper.dll
.
c:\program files\Critical Thinking Demos\Word Roots Software B1 Trial\UninstallerData\Word Roots Software B1 Trial Uninstall .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-21 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"FinePrint Dispatcher v5"="c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2003-06-17 376832]
"F5D9050"="c:\program files\Belkin\F5D9050\Belkinwcui.exe" [2006-03-14 1585152]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"SBAutoUpdate"="c:\program files\SpywareBlaster\sbautoupdate.exe" [2009-04-09 923176]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 53760]

c:\documents and settings\AndiL\Start Menu\Programs\Startup\
PinkCal.lnk - c:\program files\Pink Calendar\PinkCal.exe [2007-8-18 610304]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 01:34 87352 —-a-w- c:\windows\SYSTEM32\LMIinit.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 8.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 8.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Dataviz Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Dataviz Messenger.lnk
backup=c:\windows\pss\Dataviz Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Device Detector 2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Device Detector 2.lnk
backup=c:\windows\pss\Device Detector 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\eFax Tray Menu.lnk
backup=c:\windows\pss\eFax Tray Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GuruNet.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\GuruNet.lnk
backup=c:\windows\pss\GuruNet.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Live Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Live Menu.lnk
backup=c:\windows\pss\Live Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Printkey2000.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
backup=c:\windows\pss\Printkey2000.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^AndiL^Start Menu^Programs^Startup^.lnk]
path=c:\documents and settings\AndiL\Start Menu\Programs\Startup\.lnk
backup=c:\windows\pss\.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^AndiL^Start Menu^Programs^Startup^eBot.lnk]
path=c:\documents and settings\AndiL\Start Menu\Programs\Startup\eBot.lnk
backup=c:\windows\pss\eBot.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^AndiL^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\AndiL\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^AndiL^Start Menu^Programs^Startup^Memeo AutoBackup Launcher.lnk]
path=c:\documents and settings\AndiL\Start Menu\Programs\Startup\Memeo AutoBackup Launcher.lnk
backup=c:\windows\pss\Memeo AutoBackup Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^AndiL^Start Menu^Programs^Startup^Memeo AutoSync Launcher.lnk]
path=c:\documents and settings\AndiL\Start Menu\Programs\Startup\Memeo AutoSync Launcher.lnk
backup=c:\windows\pss\Memeo AutoSync Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2005-09-21 18:16 110592 —-a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\basicsmssmenu]
2007-10-09 22:21 169328 —-a-w- c:\program files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CaISSDT]
c:\program files\CA\eTrust Internet Security Suite\caissdt.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-05-15 01:01 644696 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A940]
2003-02-17 23:00 86102 —-a-w- c:\program files\Dell AIO Printer A940\dlbabmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E6TaskPanel]
c:\program files\EarthLink TotalAccess\TaskPanl.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eTrustPPAP]
c:\program files\CA\eTrust PestPatrol\PPActiveDetection.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-04-07 19:28 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-08-20 20:51 118784 —-a-w- c:\windows\SYSTEM32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 02:34 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-08-20 20:55 155648 —-a-w- c:\windows\SYSTEM32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2004-11-26 21:42 1349120 —-a-w- c:\program files\Ahead\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-12-11 18:10 267048 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
c:\progra~1\ICQ\ICQNet.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyStartUp10.0]
c:\program files\Microsoft Money\System\Activation.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2004-12-07 21:44 1884160 —-a-w- c:\program files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 15:50 155648 —-a-w- c:\windows\SYSTEM32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
c:\progra~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
c:\program files\Picasa2\PicasaMediaDetector.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-12-11 16:56 286720 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
c:\program files\Spyware Doctor\SDTrayApp.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
c:\program files\Java\jre1.5.0_11\bin\jusched.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-21 01:14 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2003-04-29 23:31 151597 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2005-09-21 18:16 918472 —-a-w- c:\program files\Acronis\TrueImage\TrueImageMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AcrSch2Svc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Palm\\HOTSYNC.EXE"=
"c:\\Program Files\\CuteFtp\\CUTFTP32.EXE"=
"c:\\Program Files\\iTivity\\bin\\connector_od.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
""=

R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [8/7/2009 11:40 AM 114768]
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\SYSTEM32\ASTSRV.EXE [1/7/2009 2:03 PM 57344]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [8/7/2009 11:40 AM 20560]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [8/11/2008 2:41 PM 12856]
R2 PanService;PanService;c:\program files\Palo Alto Networks\Pan Connect\PanService.exe [8/31/2009 6:04 PM 950272]
R2 TabletServicePen;TabletServicePen;c:\windows\SYSTEM32\Pen_Tablet.exe [12/11/2008 12:37 PM 3032360]
R3 PanSvd;Pan Virtual Miniport;c:\windows\SYSTEM32\DRIVERS\pansvd.sys [8/31/2009 5:59 PM 27136]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/31/2010 2:04 AM 135664]
S3 APL531;OVT Scanner;c:\windows\SYSTEM32\DRIVERS\ov550i.sys [7/31/2006 9:44 PM 580992]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/4/2007 10:18 AM 30192]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\SYSTEM32\DRIVERS\wacmoumonitor.sys [12/11/2008 12:37 PM 15144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 06:04]

2010-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 06:04]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.refdesk.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: c:\progra~1\COMMON~1\BTLINK\btlink.dll//iemenu
IE: Add to Evernote - c:\program files\Evernote\Evernote3\enbar.dll/2000
IE: Add to EverNote - c:\program files\EverNote\EverNote\enbar.dll/2000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: GuruNet… - file:c:\program files\GuruNet\Html\atiemenu.htm
IE: Locate Spot on Map by GPS - c:\program files\Opanda\IExif 2.3\IExifMap.htm
IE: View Exif/GPS/IPTC with IExif - c:\program files\Opanda\IExif 2.3\IExifCom.htm
Trusted Zone: adp.com
Trusted Zone: aol.com\free
Trusted Zone: dictaphone.com
Trusted Zone: ichart.com
Trusted Zone: nuance.com
Trusted Zone: seormc.org\connect
Trusted Zone: transcendservices.com
Trusted Zone: trcr.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
DPF: {53D40FAA-4E21-459F-AA87-E4D97FC3245A} - hxxps://www.transcendservices.com/help/Agent/setup.exe
DPF: {9DDB393E-A5C2-40F7-A37F-4957CAC7C65C} - hxxp://workportal01.trcr.com/clientinstall/production/BTClient/ActiveXLoader.CAB
DPF: {EF2E2523-5E55-4A8F-A0C9-0F2B7457290C} - hxxps://mls.trcr.com/CABS/SWTrackerCTL.CAB
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys
AddRemove-Mystical - c:\windows\unvise32.exe
AddRemove-NetAccess SSL 4.0 - c:\program files\NetAccess SSL\Setup\Setup.exe
AddRemove-OVT Scanner - c:\windows\omniuns.exe USB\Vid_05a9&PID_1550



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-13 17:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x83D53AC8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf767bfc3
\Driver\ACPI -> ACPI.sys @ 0xf75eecb8
\Driver\atapi -> atapi.sys @ 0xf75a67b4
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0094
ParseProcedure -> ntoskrnl.exe @ 0x8056f08e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0094
ParseProcedure -> ntoskrnl.exe @ 0x8056f08e
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1008)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll

- - - - - - - > 'lsass.exe'(1064)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(632)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\ftpxext.dll
c:\program files\WS_FTP Pro\nsftpch.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
———————— Other Running Processes ————————
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\BCMSMMSG.exe
c:\program files\Seagate\Basics\Service\SyncServicesBasics.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Photodex\ProShowGold\progold3\ScsiAccess.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2010-04-13 17:29:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-13 21:29
ComboFix2.txt 2007-09-01 22:27

Pre-Run: 9,786,556,416 bytes free
Post-Run: 10,487,001,088 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 3D3C93271E70B0E196239BCE8157E181


Unfortunately after those steps, I am now unable to connect to the internet and my email is also disabled on that computer, so I hope that is an easy fix. I will await further instructions.
Unfortunately despite trying all of the instructions for reconnecting to the internet from the bleeping computer site, it is still not connecting. I am supposed to be working online this evening and may have to try a system restore if I can't get it working as I cannot afford to miss work. I am sure that will hinder our process here, but I don't know what else to do. Later Edit: I did have to do a system restore which went fine. Prior to that my computer was able to physically connect to the internet via router but I could not get email or an internet page to load, I kept getting DNS server errors, so I am not sure what was happening there. I tried repairing the connection as suggested by combofix instructions but that did not work. I physically disconnected and reconnected all cables just to be sure. If you can make suggestions on what I can try if that happens again, I will re-follow all of the above instructions to get back to the point where I was when I posted the last logs above. Thanks so much.
Good afternoon

please have this thread closed
http://forums.techguy.org/malware-removal-…gle-search.html

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

RenV::
c:\program files\Critical Thinking Demos\Word Roots Software B1 Trial\UninstallerData\Word Roots Software B1 Trial Uninstall .exe

TDL::
C:\WINDOWS\System32\DRIVERS\imapi.sys


Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
[external image: Posted Image]
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

"information and logs"

  • In your next post I need the following

  • log from combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I am worried about running Combofix again without a way to get it to connect to the internet afterwards. Please see last post. Thank you.
Hello

ok iets do it this way

Create Batch File

Open Notepad and copy/paste the entire contents of the codebox below, into Notepad:
@echo off
copy /y C:\WINDOWS\ServicePackFiles\i386\imapi.sys c:\windows\system32\drivers
del %0
Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes.
Choose to Save type as - All Files and where to save - Desktop - then close the Notepad file.
It should look like this: 🖼Click to load external image (Posted Image)

Boot into Safe Mode

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.

Run Batch File

run the batch file "fix.bat" we just made

restart the computer and let me know how things are running

gringo
Okay, seemingly in better shape now. I was able to get connected to the internet, and I don't seem to have any browser redirects now. I am signing off for tonight to get a few hours sleep but will check back tomorrow. I really appreciate your help with this.
Good evening

I am signing off for tonight to get a few hours sleep but will check back tomorrow

I hear you when you do come back tell how things are - that will let me know my next step

gringo
The Good news: I am no longer getting redirects from google to ads The Bad news: I am getting avast popups regarding a Win 32 trojan which seems to be in C:\WINDOWS\TEMP\ … (various) . svchost. exe. Also now Avast showing Win32:Alureon-FZ in C:\WINDOWS\System32\drivers\Imapi.sys Virus warning popups are now constant when running anything. I will await further instructions. Thanks
Hello

Please print out these instructions, or copy them to a Notepad file. It will make it easier for you to follow the instructions and complete all of the necessary steps..

Vista and Win 7 Users please Right Click and run as Admin all programs that I ask you to run

uninstall some programs

1. click on start
2. then go to settings
3. after that you need control panel
4. look for the icon add/remove programs
click on the following programs

Adobe Reader 7.0.7

and click on remove

Update Adobe Reader

Recently there have been vunerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version.

You can download it from http://www.adobe.com/products/acrobat/readstep2.html
After installing the latest Adobe Reader, uninstall all previous versions.
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

If you don't like Adobe Reader (33.5 MB), you can download Foxit PDF Reader(3.5MB) from here. It's a much smaller file to download and uses a lot less resources than Adobe Reader.

Note: When installing FoxitReader, be carefull not to install anything to do with AskBar.

TFC(Temp File Cleaner):

  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.
Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

: Malwarebytes' Anti-Malware :

  • Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


:Kaspersky scan:

  • Please go to Kaspersky website and perform an online antivirus scan.

    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • Log From Kaspersky
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
Log from MBAM. The Kaspersky is taking forever so I will post that one when it finishes, which at this rate will be tomorrow. Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3988 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 4/14/2010 4:42:37 PM mbam-log-2010-04-14 (16-42-37).txt Scan type: Quick scan Objects scanned: 122234 Time elapsed: 12 minute(s), 44 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) In the meantime…. ever since running the Combofix there has been an issue with internet connection. I was able to finally get a connection following some advice on the bleeping computer boards. (running Winsockxpfix) However, Combofix messed up my connections to the software clients/networks I need for work and I am unable to get those restored. I tried downloading and reinstalling the clients, but it will boot me off in the middle of the download and then I just get DNS server errors and have to redo the Winsockxpfix to get the internet back up. I just cannot afford to be out of work very long. Is there a way we can restore my settings for that? Otherwise, no more Avast pop-ups since my last post and computer otherwise seems to be running well. I will post the Kaspersky as soon as it completes, but it is going to be a while. Thank you!.

ever since running the Combofix there has been an issue with internet connection. I was able to finally get a connection following some advice on the bleeping computer boards. (running Winsockxpfix) However, Combofix messed up my connections to the software clients/networks I need for work and I am unable to get those restored. I tried downloading and reinstalling the clients, but it will boot me off in the middle of the download and then I just get DNS server errors and have to redo the Winsockxpfix to get the internet back up. I just cannot afford to be out of work very long. Is there a way we can restore my settings for that?

I will check this report that I asked for and if I don't see anything there I will send you to the networking room and they should be able to handle this


I would like to see this report please

extra combofix report

I need to see one of the extra reports combofix makes

  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box
C:\Qoobox\ComboFix-quarantined-files.txt
  • click ok
  • copy and paste the report into this topic for me to review
Thank you so much for checking… Here is that report: 2010-04-13 21:27:18 . 2010-04-13 21:27:18 474 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-OVT Scanner.reg.dat 2010-04-13 21:27:18 . 2010-04-13 21:27:18 490 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-NetAccess SSL 4.0.reg.dat 2010-04-13 21:27:18 . 2010-04-13 21:27:18 586 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-Mystical.reg.dat 2010-04-13 21:26:12 . 2010-04-13 21:26:12 546 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-klmdb.sys.reg.dat 2010-04-13 21:10:25 . 2007-08-17 19:48:16 40 -c–a-w- C:\Qoobox\Quarantine\G\Autorun.inf.vir 2010-04-13 21:03:08 . 2010-04-13 21:03:08 11,314 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\Service_StreamSurge.reg.dat 2010-04-13 21:00:26 . 2010-04-13 21:00:26 2,048 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\Service_ohciusb.reg.dat 2010-04-13 21:00:25 . 2010-04-13 21:00:25 1,388 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_OHCIUSB.reg.dat 2010-04-13 20:59:39 . 2010-04-13 20:59:39 14,011 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2010-04-13 20:33:36 . 2010-04-13 20:33:36 51 -c–a-w- C:\Qoobox\Quarantine\catchme.log 2010-04-11 23:57:26 . 2010-04-11 23:57:26 5,819 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\AndiL\Local Settings\Temporary Internet Files\HAcY2.jpg.vir 2010-04-11 23:57:26 . 2010-04-11 23:57:26 776 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\AndiL\Local Settings\Temporary Internet Files\8AvoVh.jpg.vir 2010-04-11 23:57:26 . 2010-04-11 23:57:26 2,259 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\AndiL\Local Settings\Temporary Internet Files\ck2fg8kc.jpg.vir 2010-04-11 23:57:26 . 2010-04-11 23:57:26 949 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\AndiL\Local Settings\Temporary Internet Files\070NXwOk7.jpg.vir 2008-09-21 18:31:47 . 2004-08-04 05:56:52 93,184 —-a-w- C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\SET6A7.tmp.vir 2008-08-21 03:49:05 . 2005-06-18 07:48:46 19,968 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\ss.sys.vir 2007-09-01 22:16:12 . 2007-07-09 02:23:08 15,399 -c–a-w- C:\Qoobox\Quarantine\C\ComboFix\FProps.vbs.vir 2007-08-23 05:51:09 . 2005-11-15 16:08:04 36 -c–a-w- C:\Qoobox\Quarantine\F\autorun.inf.vir 2007-08-23 05:48:43 . 2007-08-23 05:48:43 852 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\LEGACY_WINNOTIFY.reg.cf 2007-08-18 00:44:49 . 2007-08-24 04:53:41 5,140 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\tmp.reg.vir 2007-06-05 23:07:33 . 2007-06-05 23:07:33 506,749 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\autorun.inf.vir 2006-10-20 14:48:30 . 2007-02-06 05:28:48 5,372 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\009752C5.vir 2006-10-03 16:42:23 . 2007-02-06 05:28:47 5,372 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\009AA02A.vir 2006-09-02 20:42:37 . 2007-02-05 14:01:22 5,372 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0125FCEC.vir 2006-08-19 02:45:11 . 2007-02-05 14:01:23 5,372 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\001D8D3F.vir 2006-08-08 23:15:46 . 2006-08-18 14:40:28 79 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01FDA099.vir 2006-08-06 03:05:27 . 2006-08-06 03:05:27 1,076 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\023F58A2.bin.vir 2006-06-24 18:14:53 . 2007-02-06 05:13:25 5,372 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0002BD7A.vir 2006-03-21 19:00:28 . 2006-03-21 19:00:28 1,144 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00B2BFF2.bin.vir 2006-03-05 15:58:01 . 2006-03-05 15:58:01 1,080 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0032D137.bin.vir 2006-02-12 12:56:14 . 2006-02-12 12:56:14 1,116 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0016E40B.bin.vir 2006-02-10 22:51:44 . 2006-02-10 22:51:44 1,048 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0212EA7D.bin.vir 2006-01-20 16:30:10 . 2006-01-20 16:30:10 1,040 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00B19B97.bin.vir 2006-01-10 17:27:07 . 2006-01-10 17:27:07 1,140 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00EC1F24.bin.vir 2006-01-10 13:27:00 . 2006-01-10 13:27:00 1,188 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00104A49.bin.vir 2006-01-01 22:34:15 . 2006-01-01 22:34:15 1,120 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0119B7A1.bin.vir 2006-01-01 22:34:14 . 2006-01-01 22:34:14 1,120 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0119B6D5.bin.vir 2006-01-01 22:34:14 . 2006-01-01 22:34:14 1,120 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0119B5BC.bin.vir 2005-12-17 18:27:40 . 2005-12-17 18:27:40 1,080 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\004843C1.bin.vir 2005-12-16 17:15:06 . 2005-12-16 17:15:06 1,320 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00D5861C.bin.vir 2005-12-15 22:26:42 . 2005-12-15 22:26:42 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\019672B8.bin.vir 2005-12-15 22:26:42 . 2005-12-15 22:26:42 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\019671ED.bin.vir 2005-12-15 22:26:42 . 2005-12-15 22:26:42 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01967122.bin.vir 2005-12-15 22:26:41 . 2005-12-15 22:26:41 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01967076.bin.vir 2005-12-15 22:26:41 . 2005-12-15 22:26:41 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01966F8B.bin.vir 2005-12-15 22:26:41 . 2005-12-15 22:26:41 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01966E91.bin.vir 2005-12-15 16:56:32 . 2005-12-15 16:56:32 1,084 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00682B5B.bin.vir 2005-12-13 18:47:44 . 2005-12-13 18:47:44 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\012C5A51.bin.vir 2005-12-13 18:47:44 . 2005-12-13 18:47:44 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\012C5977.bin.vir 2005-12-13 18:47:44 . 2005-12-13 18:47:44 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\012C585D.bin.vir 2005-12-11 16:52:23 . 2005-12-11 16:52:23 1,072 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0015FFB6.bin.vir 2005-12-10 23:26:51 . 2005-12-10 23:26:51 1,056 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\002047FA.bin.vir 2005-12-08 18:28:14 . 2005-12-08 18:28:14 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\013A0E50.bin.vir 2005-12-08 12:58:05 . 2005-12-08 12:58:05 1,112 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\000BC85B.bin.vir 2005-12-07 04:13:11 . 2005-12-07 04:13:11 992 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\015D5DDD.bin.vir 2005-12-06 22:13:03 . 2005-12-11 16:52:21 79 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0013A50D.vir 2005-12-06 18:24:26 . 2005-12-06 18:24:26 980 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01199786.bin.vir 2005-12-06 18:24:26 . 2005-12-06 18:24:26 980 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\011996DA.bin.vir 2005-12-06 18:24:26 . 2005-12-06 18:24:26 980 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\011995F0.bin.vir 2005-12-06 18:24:26 . 2005-12-06 18:24:26 980 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\011994C7.bin.vir 2005-12-04 02:43:57 . 2005-12-04 02:43:57 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\02A6156A.bin.vir 2005-12-03 23:43:55 . 2005-12-03 23:43:55 1,036 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\02014249.bin.vir 2005-12-03 23:13:55 . 2005-12-03 23:13:55 1,132 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01E5CA2E.bin.vir 2005-12-03 22:43:55 . 2005-12-03 22:43:55 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01CA5233.bin.vir 2005-12-03 15:43:24 . 2005-12-03 15:43:24 1,084 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00494775.bin.vir 2005-12-03 15:13:23 . 2005-12-03 15:13:23 1,084 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\002DCEFD.bin.vir 2005-12-01 19:59:20 . 2005-12-01 19:59:20 900 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00566ABD.bin.vir 2005-12-01 18:59:17 . 2005-12-01 18:59:17 1,112 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\001F72B8.bin.vir 2005-12-01 18:59:17 . 2005-12-01 18:59:17 1,112 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\001F7095.bin.vir 2005-12-01 13:50:26 . 2005-12-01 13:50:26 1,112 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0025EC21.bin.vir 2005-11-30 22:43:44 . 2005-11-30 22:43:44 1,124 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\020D4BE4.bin.vir 2005-11-30 22:43:44 . 2005-11-30 22:43:44 1,124 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\020D4B47.bin.vir 2005-11-30 22:43:43 . 2005-11-30 22:43:43 1,124 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\020D49FF.bin.vir 2005-11-29 13:27:30 . 2005-11-29 13:27:30 1,104 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\000C3C53.bin.vir 2005-11-28 22:30:42 . 2005-11-28 22:30:42 1,068 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01F94A5E.bin.vir 2005-11-28 18:30:32 . 2005-11-28 18:30:32 1,036 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\011D6C1D.bin.vir 2005-11-28 18:30:32 . 2005-11-28 18:30:32 1,036 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\011D6B62.bin.vir 2005-11-28 18:30:32 . 2005-11-28 18:30:32 1,036 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\011D5EEE.bin.vir 2005-11-28 18:30:29 . 2005-11-28 18:30:29 1,036 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\011D5D96.bin.vir 2005-11-26 21:51:08 . 2005-11-26 21:51:08 1,000 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\013C3F0B.bin.vir 2005-11-20 14:24:20 . 2005-11-20 14:24:20 1,404 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0006880E.bin.vir 2005-11-19 19:40:51 . 2005-09-27 00:40:49 594,432 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004012_.tmp.dll.vir 2005-11-19 19:39:09 . 2002-08-29 10:00:00 558,080 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004010_.tmp.dll.vir 2005-11-19 19:39:09 . 2002-08-29 10:00:00 557,056 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004006_.tmp.dll.vir 2005-11-19 19:39:09 . 2002-08-29 10:00:00 258,048 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004005_.tmp.dll.vir 2005-11-19 19:39:09 . 2002-08-29 10:00:00 29,184 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004004_.tmp.dll.vir 2005-11-19 19:39:09 . 2002-08-29 10:00:00 99,840 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004002_.tmp.dll.vir 2005-11-19 19:39:09 . 2002-08-29 10:00:00 126,976 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003999_.tmp.dll.vir 2005-11-19 19:39:09 . 2004-06-17 17:58:35 930,816 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003998_.tmp.dll.vir 2005-11-19 19:39:09 . 2002-08-29 10:00:00 12,288 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003997_.tmp.dll.vir 2005-11-19 19:39:09 . 2002-08-29 10:00:00 295,936 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003996_.tmp.dll.vir 2005-11-19 19:39:08 . 2004-10-28 01:29:54 681,984 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003994_.tmp.dll.vir 2005-11-19 19:39:08 . 2002-08-29 10:00:00 108,544 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003991_.tmp.dll.vir 2005-11-19 19:39:08 . 2003-05-01 21:56:12 654,336 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003989_.tmp.dll.vir 2005-11-19 19:39:08 . 2002-08-29 10:00:00 6,656 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003988_.tmp.dll.vir 2005-11-19 19:39:08 . 2002-08-29 10:00:00 569,344 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003984_.tmp.dll.vir 2005-11-19 19:39:08 . 2002-08-29 10:00:00 522,240 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003982_.tmp.dll.vir 2005-11-19 19:39:08 . 2002-08-29 10:00:00 217,088 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003981_.tmp.dll.vir 2005-11-19 19:39:07 . 2002-08-29 10:00:00 631,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003979_.tmp.dll.vir 2005-11-19 19:39:07 . 2002-08-29 10:00:00 55,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003978_.tmp.dll.vir 2005-11-19 19:39:07 . 2002-08-29 10:00:00 54,272 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003977_.tmp.dll.vir 2005-11-19 19:39:07 . 2002-08-29 10:00:00 54,784 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003975_.tmp.dll.vir 2005-11-19 19:39:07 . 2002-08-29 10:00:00 411,136 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003974_.tmp.dll.vir 2005-11-19 19:39:07 . 2004-03-30 01:48:36 136,704 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003971_.tmp.dll.vir 2005-11-19 19:39:07 . 2002-08-29 10:00:00 101,376 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003970_.tmp.dll.vir 2005-11-19 19:39:07 . 2002-08-29 10:00:00 932,864 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003968_.tmp.dll.vir 2005-11-19 19:39:06 . 2002-08-29 10:00:00 45,568 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003967_.tmp.dll.vir 2005-11-19 19:39:05 . 2004-12-07 19:34:37 79,872 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003966_.tmp.dll.vir 2005-11-19 19:39:05 . 2005-10-04 01:38:18 1,799,552 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003959_.tmp.dll.vir 2005-11-19 19:39:05 . 2005-06-11 02:41:12 102,400 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003958_.tmp.dll.vir 2005-11-19 19:39:05 . 2002-08-29 10:00:00 132,096 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003957_.tmp.dll.vir 2005-11-19 19:39:05 . 2003-10-21 23:06:41 119,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_003956_.tmp.dll.vir 2005-11-15 22:12:51 . 2005-11-15 22:12:51 1,104 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01E10C8F.bin.vir 2005-11-06 19:21:49 . 2005-11-06 19:21:49 1,048 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00C62F5A.bin.vir 2005-10-31 03:03:38 . 2005-10-31 03:03:38 988 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\029F52D3.bin.vir 2005-10-24 04:15:05 . 2005-10-24 04:15:05 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\02CCC019.bin.vir 2005-10-13 12:30:32 . 2005-10-13 12:30:33 1,044 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0002C26B.bin.vir 2005-10-11 20:40:52 . 2005-10-11 20:40:52 356,352 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\eSellerateEngine.dll.vir 2005-10-06 04:21:12 . 2005-10-06 04:21:12 1,036 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\038F9981.bin.vir 2005-09-29 00:16:54 . 2005-09-29 00:16:54 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\02952684.bin.vir 2005-09-27 00:40:49 . 2005-09-27 00:40:49 594,432 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006442_.tmp.dll.vir 2005-09-25 17:12:32 . 2005-09-25 17:12:32 1,108 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00753EF4.bin.vir 2005-09-23 16:36:37 . 2005-09-23 16:36:37 1,032 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00F9FC46.bin.vir 2005-09-16 12:20:09 . 2005-09-16 12:20:09 1,080 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00027CF6.bin.vir 2005-09-15 17:22:47 . 2005-09-15 17:22:47 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00E02E71.bin.vir 2005-09-11 15:46:57 . 2005-09-11 15:46:57 1,104 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0039DA1E.bin.vir 2005-09-08 19:25:32 . 2005-09-08 19:25:32 1,140 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\019E8A50.bin.vir 2005-08-26 15:36:51 . 2005-08-26 15:36:51 1,148 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00C2B2F4.bin.vir 2005-08-25 21:46:08 . 2005-08-25 21:46:08 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0233B7E3.bin.vir 2005-08-25 21:46:08 . 2005-08-25 21:46:08 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0233B728.bin.vir 2005-08-25 21:46:08 . 2005-08-25 21:46:08 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0233B67C.bin.vir 2005-08-25 21:46:07 . 2005-08-25 21:46:07 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0233B592.bin.vir 2005-08-25 21:46:07 . 2005-08-25 21:46:07 1,088 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0233B498.bin.vir 2005-08-24 16:26:37 . 2005-08-24 16:26:37 1,068 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\008BB765.bin.vir 2005-08-18 23:48:55 . 2005-08-18 23:48:55 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\02287C47.bin.vir 2005-08-17 19:50:51 . 2005-08-17 19:50:51 1,372 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00574A6F.bin.vir 2005-08-16 03:12:56 . 2005-08-16 03:12:56 956 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\02E8BC77.bin.vir 2005-08-15 16:12:32 . 2005-08-15 16:12:32 1,044 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\008C1DCF.bin.vir 2005-08-14 21:30:26 . 2005-08-14 21:30:26 1,060 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0159224F.bin.vir 2005-08-14 18:30:21 . 2005-08-14 18:30:21 1,140 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00B443C4.bin.vir 2005-08-08 14:47:20 . 2002-08-29 10:00:00 558,080 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006440_.tmp.dll.vir 2005-08-08 14:47:19 . 2002-08-29 10:00:00 557,056 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006436_.tmp.dll.vir 2005-08-08 14:47:19 . 2002-08-29 10:00:00 258,048 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006435_.tmp.dll.vir 2005-08-08 14:47:19 . 2002-08-29 10:00:00 29,184 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006434_.tmp.dll.vir 2005-08-08 14:47:19 . 2002-08-29 10:00:00 99,840 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006432_.tmp.dll.vir 2005-08-08 14:47:19 . 2002-08-29 10:00:00 126,976 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006429_.tmp.dll.vir 2005-08-08 14:47:19 . 2004-06-17 17:58:35 930,816 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006428_.tmp.dll.vir 2005-08-08 14:47:19 . 2002-08-29 10:00:00 295,936 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006426_.tmp.dll.vir 2005-08-08 14:47:19 . 2002-08-29 10:00:00 12,288 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006427_.tmp.dll.vir 2005-08-08 14:47:19 . 2004-10-28 01:29:54 681,984 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006424_.tmp.dll.vir 2005-08-08 14:47:19 . 2002-08-29 10:00:00 108,544 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006421_.tmp.dll.vir 2005-08-08 14:47:18 . 2003-05-01 21:56:12 654,336 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006419_.tmp.dll.vir 2005-08-08 14:47:18 . 2002-08-29 10:00:00 6,656 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006418_.tmp.dll.vir 2005-08-08 14:47:18 . 2002-08-29 10:00:00 569,344 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006414_.tmp.dll.vir 2005-08-08 14:47:18 . 2002-08-29 10:00:00 37,376 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006413_.tmp.dll.vir 2005-08-08 14:47:18 . 2002-08-29 10:00:00 522,240 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006412_.tmp.dll.vir 2005-08-08 14:47:18 . 2002-08-29 10:00:00 217,088 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006411_.tmp.dll.vir 2005-08-08 14:47:18 . 2002-08-29 10:00:00 631,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006409_.tmp.dll.vir 2005-08-08 14:47:18 . 2002-08-29 10:00:00 55,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006408_.tmp.dll.vir 2005-08-08 14:47:18 . 2002-08-29 10:00:00 54,272 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006407_.tmp.dll.vir 2005-08-08 14:47:17 . 2002-08-29 10:00:00 54,784 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006405_.tmp.dll.vir 2005-08-08 14:47:16 . 2002-08-29 10:00:00 411,136 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006404_.tmp.dll.vir 2005-08-08 14:47:15 . 2004-03-30 01:48:36 136,704 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006401_.tmp.dll.vir 2005-08-08 14:47:15 . 2002-08-29 10:00:00 101,376 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006400_.tmp.dll.vir 2005-08-08 14:47:15 . 2002-08-29 10:00:00 932,864 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006398_.tmp.dll.vir 2005-08-08 14:47:15 . 2002-08-29 10:00:00 45,568 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006397_.tmp.dll.vir 2005-08-08 14:47:15 . 2004-12-07 19:34:37 79,872 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006396_.tmp.dll.vir 2005-08-08 14:47:15 . 2005-03-02 01:34:32 1,797,120 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006389_.tmp.dll.vir 2005-08-08 14:47:15 . 2005-06-11 02:41:12 102,400 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006388_.tmp.dll.vir 2005-08-08 14:47:15 . 2002-08-29 10:00:00 132,096 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006387_.tmp.dll.vir 2005-08-08 14:47:14 . 2003-10-21 23:06:41 119,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_006386_.tmp.dll.vir 2005-07-27 06:33:19 . 2005-07-27 06:33:19 1,012 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\032B8F75.bin.vir 2005-07-27 06:33:19 . 2005-07-27 06:33:19 1,012 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\032B8EAA.bin.vir 2005-07-27 06:33:19 . 2005-07-27 06:33:19 1,012 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\032B8DEF.bin.vir 2005-07-27 06:33:19 . 2005-07-27 06:33:19 1,012 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\032B8CD6.bin.vir 2005-07-24 18:14:35 . 2005-07-24 18:14:35 1,112 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\01A1807E.bin.vir 2005-07-22 16:11:23 . 2005-07-22 16:11:23 1,100 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\001BD955.bin.vir 2005-07-21 21:36:11 . 2005-07-21 21:36:11 1,076 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0167F460.bin.vir 2005-07-21 15:05:54 . 2005-07-21 15:05:54 1,152 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0002A406.bin.vir 2005-07-20 16:57:38 . 2005-07-20 16:57:38 1,124 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\000FAEC5.bin.vir 2005-07-17 00:25:09 . 2005-07-17 00:25:09 1,076 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\019B762A.bin.vir 2005-07-14 23:28:02 . 2005-07-14 23:28:02 365 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf.vir 2005-07-14 14:19:53 . 2005-07-14 14:19:53 1,052 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00025FF8.bin.vir 2005-07-13 17:59:21 . 2005-07-13 17:59:21 1,092 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0008772C.bin.vir 2005-07-13 07:46:35 . 2005-07-13 07:46:35 1,092 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\03566F88.bin.vir 2005-07-13 07:46:35 . 2005-07-13 07:46:35 1,092 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\03566EDD.bin.vir 2005-07-13 07:46:35 . 2005-07-13 07:46:35 1,092 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\03566DD3.bin.vir 2005-07-12 22:46:19 . 2005-07-12 22:46:19 1,024 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0167C9C6.bin.vir 2005-07-12 21:16:15 . 2005-07-12 21:16:15 1,052 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0115582E.bin.vir 2005-07-12 17:46:09 . 2005-07-12 17:46:09 1,112 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0054FD91.bin.vir 2005-07-12 16:16:06 . 2005-07-12 16:16:06 1,088 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0002895A.bin.vir 2005-07-11 22:35:47 . 2005-07-11 22:35:47 1,000 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\015FC6EE.bin.vir 2005-07-11 21:35:46 . 2005-07-11 21:35:46 1,048 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0128D2A2.bin.vir 2005-07-11 18:35:42 . 2005-07-11 18:35:42 1,080 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0083F772.bin.vir 2005-07-11 16:35:37 . 2005-07-11 16:35:37 1,036 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00160842.bin.vir 2005-07-10 23:28:26 . 2005-07-10 23:28:26 1,060 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\0091FFFA.bin.vir 2005-07-10 21:28:23 . 2005-07-10 21:28:23 1,036 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\002417AF.bin.vir 2005-07-10 18:28:17 . 2005-07-10 18:28:17 1,068 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\008BE386.bin.vir 2005-07-10 15:58:03 . 2005-07-10 15:58:03 1,060 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00025876.bin.vir 2005-07-10 00:51:50 . 2005-07-10 00:51:50 828 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00CD5483.bin.vir 2005-07-09 21:51:46 . 2005-07-09 21:51:46 968 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00287AF9.bin.vir 2005-07-09 21:51:41 . 2005-07-09 21:51:41 468 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\00286629.bin.vir 2005-07-09 21:51:40 . 2005-07-09 21:51:40 1,024 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\History\search.vir 2005-07-09 21:51:40 . 2006-08-08 15:40:21 11,273 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Settings\prevcfg.htm.vir 2005-07-09 21:51:36 . 2007-02-06 05:40:10 5,920 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\Cache\files.ini.vir 2005-07-09 21:45:58 . 2005-07-09 21:45:58 53,248 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\1.bin\W6WBTEMP.DLL.vir 2005-07-09 21:45:57 . 2005-07-09 21:45:57 4,988 —-a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\1.bin\W6NTSTBR.JAR.vir 2005-07-09 21:45:57 . 2005-07-09 21:45:57 4,853 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\1.bin\W6FFXTBR.JAR.vir 2004-10-25 05:59:27 . 2002-08-29 10:00:00 29,184 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004113_.tmp.dll.vir 2004-10-25 05:59:24 . 2002-08-29 10:00:00 295,936 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004105_.tmp.dll.vir 2004-10-25 05:59:23 . 2004-10-28 01:29:54 681,984 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004103_.tmp.dll.vir 2004-10-25 05:59:23 . 2002-08-29 10:00:00 108,544 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004100_.tmp.dll.vir 2004-10-25 05:59:20 . 2002-08-29 10:00:00 631,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004088_.tmp.dll.vir 2004-10-25 05:59:20 . 2002-08-29 10:00:00 55,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004087_.tmp.dll.vir 2004-10-25 05:59:19 . 2002-08-29 10:00:00 54,272 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004086_.tmp.dll.vir 2004-10-25 05:59:19 . 2002-08-29 10:00:00 54,784 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004084_.tmp.dll.vir 2004-10-25 05:59:19 . 2002-08-29 10:00:00 411,136 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004083_.tmp.dll.vir 2004-10-25 05:59:18 . 2004-03-30 01:48:36 136,704 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004080_.tmp.dll.vir 2004-10-25 05:59:18 . 2002-08-29 10:00:00 101,376 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004079_.tmp.dll.vir 2004-10-25 05:59:17 . 2002-08-29 10:00:00 932,864 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004077_.tmp.dll.vir 2004-10-25 05:59:17 . 2002-08-29 10:00:00 45,568 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004076_.tmp.dll.vir 2004-10-25 05:59:17 . 2004-12-07 19:34:37 79,872 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004075_.tmp.dll.vir 2004-10-25 05:59:15 . 2005-03-02 01:34:32 1,797,120 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004068_.tmp.dll.vir 2004-10-25 05:59:15 . 2002-08-29 10:00:00 99,328 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004067_.tmp.dll.vir 2004-10-25 05:59:15 . 2002-08-29 10:00:00 132,096 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004066_.tmp.dll.vir 2004-10-25 05:59:15 . 2003-10-21 23:06:41 119,808 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004065_.tmp.dll.vir 2004-10-03 16:35:19 . 2004-10-03 16:35:19 284 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\AndiL\Recent\bayscribe.com.url.vir 2004-09-11 18:05:08 . 2004-05-18 03:46:28 593,408 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004152_.tmp.dll.vir 2004-09-11 18:01:12 . 2002-08-29 10:00:00 558,080 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004150_.tmp.dll.vir 2004-09-11 18:01:10 . 2002-08-29 10:00:00 258,048 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004145_.tmp.dll.vir 2004-09-11 18:01:10 . 2002-08-29 10:00:00 29,184 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004144_.tmp.dll.vir 2004-09-11 18:01:09 . 2002-08-29 10:00:00 126,976 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004139_.tmp.dll.vir 2004-09-11 18:01:08 . 2002-08-29 10:00:00 12,288 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004137_.tmp.dll.vir 2004-09-11 18:01:08 . 2002-08-29 10:00:00 295,936 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004136_.tmp.dll.vir 2004-09-11 18:01:07 . 2002-08-29 10:00:00 6,656 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004128_.tmp.dll.vir 2004-09-11 18:01:05 . 2002-08-29 10:00:00 522,240 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004122_.tmp.dll.vir 2004-09-11 18:01:04 . 2005-03-11 22:07:13 594,432 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004121_.tmp.dll.vir 2004-09-11 18:01:03 . 2002-08-29 10:00:00 557,056 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004115_.tmp.dll.vir 2004-09-11 18:01:03 . 2002-08-29 10:00:00 99,840 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004111_.tmp.dll.vir 2004-09-11 18:01:02 . 2002-08-29 10:00:00 126,976 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004108_.tmp.dll.vir 2004-09-11 18:01:02 . 2004-06-17 17:58:35 930,816 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004107_.tmp.dll.vir 2004-09-11 18:01:01 . 2003-05-01 21:56:12 654,336 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004098_.tmp.dll.vir 2004-09-11 18:01:01 . 2002-08-29 10:00:00 6,656 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004097_.tmp.dll.vir 2004-02-20 04:15:14 . 2004-02-20 04:15:16 457 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 217,088 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004090_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 522,240 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004091_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 569,344 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004093_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 12,288 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004106_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 258,048 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004114_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 558,080 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004119_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 37,376 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004123_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 569,344 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004124_.tmp.dll.vir 2002-08-29 10:00:00 . 2003-05-01 21:56:12 654,336 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004129_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 108,544 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004131_.tmp.dll.vir 2002-08-29 10:00:00 . 2004-03-30 01:48:36 667,648 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004134_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 930,304 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004138_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 99,840 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004142_.tmp.dll.vir 2002-08-29 10:00:00 . 2002-08-29 10:00:00 557,056 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_004146_.tmp.dll.vir 2002-02-19 03:22:14 . 2002-02-19 03:22:14 12,008 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\fad.sys.vir
Finally I got a full Kaspersky scan: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, April 15, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, April 15, 2010 14:04:16 Records in database: 3946709 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ Scan statistics: Objects scanned: 177224 Threats found: 6 Infected objects found: 7 Suspicious objects found: 0 Scan duration: 07:30:12 File name / Threat / Threats count C:\Documents and Settings\AndiL\Desktop\Unused Desktop Shortcuts\Amazing Keyboard Secrets v1_0.exe Infected: not-a-virus:AdWare.Win32.WebStars.b 1 C:\Documents and Settings\AndiL\Desktop\Unused Desktop Shortcuts\memory-card-data-recovery-demo.exe Infected: not-a-virus:AdWare.Win32.Rabio.th 1 C:\Program Files\PestPatrol\Quarantine\20040504120834078.zip Infected: not-a-virus:AdWare.Win32.Wintol.at 1 C:\QooBox\Quarantine\C\Program Files\MyWebSearchWB\bar\1.bin\W6WBTEMP.DLL.vir Infected: not-a-virus:AdWare.Win32.WeatherBug.f 1 C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2516\A0557255.sys Infected: Rootkit.Win32.TDSS.ap 1 C:\WINDOWS\SYSTEM32\DRIVERS\imapi.sys Infected: Rootkit.Win32.TDSS.ap 1 C:\WINDOWS\SYSTEM32\DRIVERS\ohciusb.zip Infected: Rootkit.Win32.Agent.mc 1 Selected area has been scanned.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI