This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware infection

50 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got a Malware, from going to a streaming links site, with the name AVE.exe that would popup this xp defender fake virus remover and would give me a rundll32.exe error when i tried to access control pad and things like that and avast was unable to stop it from infecting my computer, i was able to get rid of that or atleast i think i was by using malware bytes anti-malware but im still getting lots of infection attempts that are getting blocked by avast but i disconnected just in case anyway but i still get some attempts everyonce in a while. also i am unable to access the system restore function since i think one of the viruses turned it off as it is telling me admin has denied access but never done anything with admin tools. I also got Helios and was able to find a hidden process named MSSYSM~1.exe that i googled and seems to be associated with a virus but i'm not sure how to get rid of it. Thanks in advance.
Hi TangJuice, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode
Please post back with
  • Both OTL log
  • GMER log

Thanks
Hey, here is the OTL file

OTL logfile created on: 29/04/2010 1:46:03 PM - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\Tang Family\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.82 Gb Total Space | 16.91 Gb Free Space | 7.26% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 625.36 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 149.01 Gb Total Space | 4.27 Gb Free Space | 2.86% Space Free | Partition Type: FAT32
Drive H: | 439.42 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded
Drive K: | 1.90 Gb Total Space | 1.90 Gb Free Space | 99.87% Space Free | Partition Type: FAT32

Computer Name: MAINCOMPUTER
Current User Name: Tang Family
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Tang Family\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc.exe (eSXi)
PRC - c:\Program Files\iTunes\ituneshelper .exe (Apple Inc.)
PRC - c:\Program Files\Java\jre6\bin\jusched .exe (Sun Microsystems, Inc.)
PRC - c:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager .exe (Linksys, LLC)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - c:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth .exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc .exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\wdbtnmgr .exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - c:\Program Files\ScanSoft\OmniPageSE4\opwarese4 .exe (Nuance Communications, Inc.)
PRC - c:\Program Files\Windows Defender\msascui .exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Nero PhotoShow 4\data\Xtras\mssysmgr .exe (Nero AG / Nero Inc.)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - c:\Program Files\Common Files\InstallShield\UpdateService\issch .exe (Macrovision Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - c:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Tang Family\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll (Nuance Communications, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (NMIndexingService) – File not found
SRV - (LiveUpdate Notice Ex) – File not found
SRV - (CLTNetCnService) – File not found
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (eSXi)
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\rswin_3653.dll ()
SRV - (DAUpdaterSvc) – c:\Program Files\Valve\Steam\SteamApps\common\dragon age origins\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (usnjsvc) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (GarenaPEngine) – C:\Documents and Settings\Steven\Local Settings\Temp\ICJ494B.tmp ()
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (WUSB54GCv3) – C:\WINDOWS\system32\drivers\WUSB54GCv3.sys (Ralink Technology, Corp.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (Changer) – C:\WINDOWS\system32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) – C:\WINDOWS\system32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (SCDEmu) – C:\WINDOWS\system32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (MxlW2k) – C:\WINDOWS\system32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (iastor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (IABFilt) – C:\WINDOWS\system32\DRIVERS\IABFilt.sys (Iomega)
DRV - (BCM42RLY) – C:\WINDOWS\system32\bcm42rly.sys (Broadcom Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.torrentpond.com/|http://www.google.ca/|http://login.live.com/login.srf?id=2|http://www.facebook.com/|http://commondreams.org/|http://www.yousendit.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/10 13:21:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/28 17:54:58 | 000,000,000 | —D | M]

[2009/05/03 13:29:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Tang Family\Application Data\Mozilla\Extensions
[2010/04/28 18:28:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Tang Family\Application Data\Mozilla\Firefox\Profiles\3bgkpl36.default\extensions
[2010/04/28 18:28:22 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Tang Family\Application Data\Mozilla\Firefox\Profiles\3bgkpl36.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/28 18:28:50 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2008/09/24 19:10:36 | 000,000,909 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Companion BHO) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Megaupload Toolbar) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (eSXi)
O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (eSXi)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (eSXi)
O4 - HKLM..\Run: [Linksys Wireless Manager] C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe (eSXi)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (eSXi)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (eSXi)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (eSXi)
O4 - HKLM..\Run: [QuickTime Task] c:\program files\quicktime\qttask .exe (eSXi)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\System32\stsystra.exe (eSXi)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (eSXi)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (eSXi)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (eSXi)
O4 - HKLM..\Run: [WD Button Manager] C:\WINDOWS\System32\wdbtnmgr.exe (eSXi)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (eSXi)
O4 - HKCU..\Run: [Nero PhotoShow Media Manager] C:\Program Files\Nero\Nero PhotoShow 4\data\Xtras\mssysmgr .exe (Nero AG / Nero Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab (ijjiPlugin2 Class)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://play.battlefield-heroes.com/static/…er_4.0.15.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\efcbbyv: DllName - efcbbyv.dll - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/02/24 12:58:12 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1998/12/13 03:43:32 | 000,000,040 | R— | M] () - F:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2008/01/07 23:51:18 | 000,000,000 | —D | M] - G:\autorun – [ FAT32 ]
O32 - AutoRun File - [2009/10/27 04:44:49 | 000,000,075 | R— | M] () - H:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{c1892af4-e94f-11da-9571-00123f748615}\Shell - "" = AutoRun
O33 - MountPoints2\{c1892af4-e94f-11da-9571-00123f748615}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c1892af4-e94f-11da-9571-00123f748615}\Shell\AutoRun\command - "" = F:\SETUP.EXE – [1998/12/01 01:04:40 | 000,025,600 | R— | M] ()
O33 - MountPoints2\{d36c83a9-f3cf-11dc-96ba-00123f748615}\Shell - "" = AutoRun
O33 - MountPoints2\{d36c83a9-f3cf-11dc-96ba-00123f748615}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{d36c83a9-f3cf-11dc-96ba-00123f748615}\Shell\AutoRun\command - "" = H:\Torchlight_Setup.exe – [2009/10/27 04:44:49 | 363,449,992 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2006/02/24 07:42:18 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/04/29 13:42:09 | 000,563,712 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Tang Family\Desktop\OTL.exe
[2010/04/29 13:27:39 | 000,000,000 | —D | C] – C:\Program Files\ClamWinPortable
[2010/04/29 13:27:04 | 006,409,512 | —- | C] (PortableApps.com) – C:\Documents and Settings\Tang Family\Desktop\ClamWinPortable_0.95.3_English.paf.exe
[2010/04/28 22:47:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Tang Family\Desktop\ClamWinPortable
[2010/04/28 18:14:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Tang Family\Local Settings\Application Data\Apple
[2010/04/28 17:57:19 | 000,468,992 | —- | C] (MIEL e-Security Pvt. Ltd.) – C:\Documents and Settings\Tang Family\Desktop\Helios Lite.exe
[2010/04/28 13:51:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Tang Family\Application Data\Malwarebytes
[2010/04/28 13:51:17 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/28 13:51:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/28 13:51:14 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/28 13:51:14 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/27 13:24:44 | 000,036,864 | —- | C] (eSXi) – C:\Documents and Settings\Tang Family\wdbtnmgr.exe
[2010/04/27 13:24:44 | 000,036,864 | —- | C] (eSXi) – C:\Documents and Settings\Tang Family\wdbtnmgr .exe
[2010/04/27 13:24:42 | 000,036,864 | —- | C] (eSXi) – C:\Documents and Settings\Tang Family\nwiz.exe
[2010/04/27 13:24:42 | 000,036,864 | —- | C] (eSXi) – C:\Documents and Settings\Tang Family\nwiz .exe
[2010/04/27 13:24:38 | 000,036,864 | —- | C] (eSXi) – C:\Documents and Settings\Tang Family\stsystra.exe
[2010/04/27 13:24:38 | 000,036,864 | —- | C] (eSXi) – C:\Documents and Settings\Tang Family\stsystra .exe
[2010/04/27 13:24:37 | 000,036,864 | —- | C] (eSXi) – C:\Documents and Settings\Tang Family\rundll32 .exe
[2010/04/27 13:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/27 13:07:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/04/27 12:57:23 | 000,034,688 | —- | C] (Toshiba Corp.) – C:\WINDOWS\System32\drivers\lbrtfdc.sys
[2010/04/27 12:57:23 | 000,034,688 | —- | C] (Toshiba Corp.) – C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2010/04/27 12:57:21 | 000,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2010/04/27 12:57:19 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\changer.sys
[2010/04/27 12:57:19 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\changer.sys
[2010/04/27 12:47:50 | 000,142,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aec.sys
[2010/04/27 12:46:18 | 000,036,864 | —- | C] (eSXi) – C:\WINDOWS\System32\stsystra.exe.delme122
[2010/04/27 12:46:18 | 000,036,864 | —- | C] (eSXi) – C:\WINDOWS\System32\stsystra.exe
[2010/04/27 12:46:18 | 000,036,864 | —- | C] (eSXi) – C:\WINDOWS\System32\stsystra .exe
[2010/04/05 17:07:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ADInstruments
[2010/04/05 17:06:56 | 000,000,000 | —D | C] – C:\Program Files\ADInstruments
[2010/04/05 17:06:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ADInstruments
[2010/04/01 21:16:49 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/29 13:40:46 | 000,293,376 | —- | M] () – C:\Documents and Settings\Tang Family\Desktop\9jck9fw2.exe
[2010/04/29 13:38:54 | 000,563,712 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Tang Family\Desktop\OTL.exe
[2010/04/29 13:34:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1614895754-839522115-1003UA.job
[2010/04/29 13:00:36 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2010/04/29 12:00:36 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2010/04/29 11:45:08 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/29 11:37:39 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2010/04/29 11:37:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2010/04/29 11:27:27 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2010/04/29 11:27:27 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2010/04/29 11:27:20 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010/04/29 11:26:55 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/29 11:26:41 | 000,036,864 | —- | M] (eSXi) – C:\WINDOWS\System32\wdbtnmgr.exe
[2010/04/29 11:26:38 | 000,036,864 | —- | M] (eSXi) – C:\WINDOWS\System32\nwiz.exe
[2010/04/29 11:26:34 | 000,036,864 | —- | M] (eSXi) – C:\WINDOWS\System32\stsystra.exe
[2010/04/29 11:25:57 | 000,138,618 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/29 11:25:02 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/29 11:24:55 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/29 00:53:57 | 000,036,864 | —- | M] (eSXi) – C:\WINDOWS\System32\wdbtnmgr.exe.delme132
[2010/04/29 00:53:55 | 000,036,864 | —- | M] (eSXi) – C:\WINDOWS\System32\nwiz.exe.delme129
[2010/04/29 00:53:52 | 000,036,864 | —- | M] (eSXi) – C:\WINDOWS\System32\stsystra.exe.delme122
[2010/04/29 00:51:35 | 006,029,312 | -H– | M] () – C:\Documents and Settings\Tang Family\ntuser.dat
[2010/04/29 00:51:03 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Tang Family\ntuser.ini
[2010/04/29 00:50:53 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2010/04/29 00:50:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/04/28 22:43:52 | 006,409,512 | —- | M] (PortableApps.com) – C:\Documents and Settings\Tang Family\Desktop\ClamWinPortable_0.95.3_English.paf.exe
[2010/04/28 18:14:08 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/28 17:14:33 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2010/04/28 17:14:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/04/28 13:51:19 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/28 13:10:52 | 000,011,958 | -HS- | M] () – C:\Documents and Settings\Tang Family\Local Settings\Application Data\KLry0l
[2010/04/28 13:10:04 | 000,011,962 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\KLry0l
[2010/04/28 13:09:31 | 000,036,864 | —- | M] (eSXi) – C:\Documents and Settings\Tang Family\wdbtnmgr.exe
[2010/04/28 13:09:28 | 000,036,864 | —- | M] (eSXi) – C:\Documents and Settings\Tang Family\nwiz.exe
[2010/04/28 13:09:25 | 000,036,864 | —- | M] (eSXi) – C:\Documents and Settings\Tang Family\stsystra.exe
[2010/04/28 13:07:50 | 000,011,878 | -HS- | M] () – C:\Documents and Settings\Tang Family\Local Settings\Application Data\1167664209
[2010/04/27 13:39:03 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2010/04/27 13:39:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/04/27 13:24:44 | 000,036,864 | —- | M] (eSXi) – C:\Documents and Settings\Tang Family\wdbtnmgr .exe
[2010/04/27 13:24:42 | 000,036,864 | —- | M] (eSXi) – C:\Documents and Settings\Tang Family\nwiz .exe
[2010/04/27 13:24:38 | 000,036,864 | —- | M] (eSXi) – C:\Documents and Settings\Tang Family\stsystra .exe
[2010/04/27 13:24:37 | 000,036,864 | —- | M] (eSXi) – C:\Documents and Settings\Tang Family\rundll32 .exe
[2010/04/27 13:24:10 | 000,072,840 | —- | M] () – C:\Documents and Settings\Tang Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/27 13:02:39 | 000,011,994 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\1167664209
[2010/04/27 12:46:18 | 000,036,864 | —- | M] (eSXi) – C:\WINDOWS\System32\stsystra .exe
[2010/04/27 06:34:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1614895754-839522115-1003Core.job
[2010/04/14 21:30:52 | 000,056,380 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/08 01:32:22 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/04/07 11:08:02 | 000,280,536 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/04/05 17:07:09 | 000,000,817 | —- | M] () – C:\Documents and Settings\All Users\Desktop\LabChart 7 Reader.lnk
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/29 13:42:11 | 000,293,376 | —- | C] () – C:\Documents and Settings\Tang Family\Desktop\9jck9fw2.exe
[2010/04/29 11:37:39 | 000,000,268 | -H– | C] () – C:\sqmdata14.sqm
[2010/04/29 11:37:39 | 000,000,244 | -H– | C] () – C:\sqmnoopt14.sqm
[2010/04/29 11:27:30 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At24.job
[2010/04/29 11:27:30 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At23.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At9.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At8.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At7.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At6.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At22.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At21.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At20.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At19.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At18.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At17.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At16.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At15.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At14.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At13.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At12.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At11.job
[2010/04/29 11:27:29 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At10.job
[2010/04/29 11:27:28 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At5.job
[2010/04/29 11:27:27 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2010/04/29 11:27:27 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2010/04/29 11:27:26 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2010/04/29 00:50:53 | 000,000,268 | -H– | C] () – C:\sqmdata13.sqm
[2010/04/29 00:50:53 | 000,000,244 | -H– | C] () – C:\sqmnoopt13.sqm
[2010/04/28 17:14:33 | 000,000,268 | -H– | C] () – C:\sqmdata12.sqm
[2010/04/28 17:14:32 | 000,000,244 | -H– | C] () – C:\sqmnoopt12.sqm
[2010/04/28 13:51:19 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/28 13:07:50 | 000,011,878 | -HS- | C] () – C:\Documents and Settings\Tang Family\Local Settings\Application Data\1167664209
[2010/04/27 13:39:03 | 000,000,268 | -H– | C] () – C:\sqmdata11.sqm
[2010/04/27 13:39:03 | 000,000,244 | -H– | C] () – C:\sqmnoopt11.sqm
[2010/04/27 13:37:32 | 000,011,958 | -HS- | C] () – C:\Documents and Settings\Tang Family\Local Settings\Application Data\KLry0l
[2010/04/27 13:03:42 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2010/04/27 13:02:39 | 000,011,994 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1167664209
[2010/04/27 12:45:33 | 000,011,962 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KLry0l
[2010/04/14 21:30:52 | 000,056,380 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/05 17:07:09 | 000,000,817 | —- | C] () – C:\Documents and Settings\All Users\Desktop\LabChart 7 Reader.lnk
[2009/09/10 13:28:58 | 000,000,000 | —- | C] () – C:\WINDOWS\syscheck.INI
[2009/06/20 14:08:08 | 000,279,712 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2009/06/20 14:08:08 | 000,025,888 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2009/03/01 16:33:54 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/01/28 17:20:43 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2008/11/25 18:24:37 | 000,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2008/10/28 18:40:48 | 000,173,552 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/06 01:19:19 | 000,000,004 | —- | C] () – C:\WINDOWS\info147.sys
[2008/08/29 16:42:32 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/05/20 14:49:49 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2008/04/11 22:23:24 | 000,000,122 | —- | C] () – C:\WINDOWS\WA.INI
[2008/01/08 13:43:20 | 000,000,247 | —- | C] () – C:\WINDOWS\{0B5FF5D5-32AC-4576-BC9C-C6402980642D}_WiseFW.ini
[2007/09/12 22:00:47 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/09/12 22:00:25 | 000,000,319 | —- | C] () – C:\WINDOWS\game.ini
[2007/08/08 23:14:16 | 000,000,394 | —- | C] () – C:\WINDOWS\kaillera.ini
[2007/06/27 20:45:20 | 000,000,031 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2006/12/21 15:45:07 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\psfind.dll
[2006/07/09 18:32:09 | 000,000,026 | —- | C] () – C:\WINDOWS\WAR2R.INI
[2006/07/06 13:42:03 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/05/22 00:57:41 | 000,639,224 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2006/05/15 13:26:30 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS2v.DLL
[2006/05/07 14:36:09 | 000,002,750 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2006/05/03 19:18:13 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/05/03 19:18:13 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/05/03 19:18:13 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2006/04/06 14:11:20 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2006/03/21 22:01:36 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/03/21 15:13:33 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/03/20 11:43:05 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/02/24 16:49:32 | 000,000,343 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/02/24 16:36:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/10 04:06:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/12/10 04:06:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/12/10 04:06:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/12/10 04:06:00 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/12/10 04:06:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/12/10 04:06:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[1998/10/11 01:07:38 | 000,088,576 | —- | C] () – C:\WINDOWS\System32\Iticheck.dll

========== LOP Check ==========

[2010/04/05 17:12:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ADInstruments
[2009/11/05 06:27:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BioWare
[2008/08/29 16:38:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/03/24 23:42:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2007/04/17 02:31:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
[2010/03/01 03:41:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts Inc
[2007/06/04 12:39:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2008/05/20 15:35:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Funcom
[2008/08/29 16:42:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/09/06 17:09:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/04/11 06:05:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/10/06 21:01:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2010/03/10 13:24:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2007/06/16 12:29:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Tang Family\Application Data\Iomega Automatic Backup Pro
[2007/06/06 10:23:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tang Family\Application Data\Leadertech
[2009/05/03 13:34:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Tang Family\Application Data\MEGAUPLOADTOOLBAR
[2006/07/29 10:22:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Tang Family\Application Data\My Battle for Middle-earth™ II Files
[2008/08/29 16:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Tang Family\Application Data\ScanSoft
[2006/07/06 11:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Tang Family\Application Data\Simple Star
[2010/04/29 11:27:20 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2010/04/29 12:00:36 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2010/04/29 13:00:36 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2010/04/29 11:27:27 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2010/04/29 11:27:27 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2010/04/29 11:27:30 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\At9.job
[2010/04/29 11:45:08 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/29 15:35:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/08/29 15:35:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/29 15:35:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/08/29 15:35:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 08:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 08:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2005/04/25 09:29:54 | 000,502,784 | —- | M] (Intel Corporation) MD5=61258AB922B659AC4DF47936EE63C8DE – C:\Program Files\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys
[2005/04/25 09:28:14 | 000,871,040 | —- | M] (Intel Corporation) MD5=D593517879E65167DF35F6015814AC59 – C:\Program Files\Intel\Intel Matrix Storage Manager\Driver\iaStor.sys
[2005/04/25 11:28:14 | 000,871,040 | —- | M] (Intel Corporation) MD5=D593517879E65167DF35F6015814AC59 – C:\WINDOWS\dell\iastor\iastor.sys
[2005/04/25 09:28:14 | 000,871,040 | —- | M] (Intel Corporation) MD5=D593517879E65167DF35F6015814AC59 – C:\WINDOWS\system32\drivers\iaStor.sys
[2005/04/25 11:28:14 | 000,871,040 | —- | M] (Intel Corporation) MD5=D593517879E65167DF35F6015814AC59 – C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATABUS.SYS >
[2005/05/17 18:45:08 | 000,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\WINDOWS\dell\nvraid\NvAtaBus.sys
[2005/05/17 18:45:08 | 000,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\WINDOWS\system32\drivers\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 08:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2008/03/17 00:51:07 | 000,639,224 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2006/02/24 07:46:44 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/02/24 07:46:44 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/02/24 07:46:43 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Here is the OTL extras

OTL Extras logfile created on: 29/04/2010 1:46:03 PM - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\Tang Family\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.82 Gb Total Space | 16.91 Gb Free Space | 7.26% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 625.36 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 149.01 Gb Total Space | 4.27 Gb Free Space | 2.86% Space Free | Partition Type: FAT32
Drive H: | 439.42 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded
Drive K: | 1.90 Gb Total Space | 1.90 Gb Free Space | 99.87% Space Free | Partition Type: FAT32

Computer Name: MAINCOMPUTER
Current User Name: Tang Family
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"6112:TCP" = 6112:TCP:*:Enabled:Warcraft
"2303:UDP" = 2303:UDP:*:Enabled:battlelan
"2573:UDP" = 2573:UDP:*:Enabled:Battlelan
"8395:TCP" = 8395:TCP:*:Enabled:League of Legends Launcher
"8395:UDP" = 8395:UDP:*:Enabled:League of Legends Launcher
"8396:TCP" = 8396:TCP:*:Enabled:League of Legends Launcher
"8396:UDP" = 8396:UDP:*:Enabled:League of Legends Launcher
"8397:TCP" = 8397:TCP:*:Enabled:League of Legends Launcher
"8397:UDP" = 8397:UDP:*:Enabled:League of Legends Launcher
"8398:TCP" = 8398:TCP:*:Enabled:League of Legends Launcher
"8398:UDP" = 8398:UDP:*:Enabled:League of Legends Launcher
"8399:TCP" = 8399:TCP:*:Enabled:League of Legends Launcher
"8399:UDP" = 8399:UDP:*:Enabled:League of Legends Launcher
"8380:TCP" = 8380:TCP:*:Enabled:League of Legends Launcher
"8380:UDP" = 8380:UDP:*:Enabled:League of Legends Launcher
"8381:TCP" = 8381:TCP:*:Enabled:League of Legends Launcher
"8381:UDP" = 8381:UDP:*:Enabled:League of Legends Launcher
"8382:TCP" = 8382:TCP:*:Enabled:League of Legends Launcher
"8382:UDP" = 8382:UDP:*:Enabled:League of Legends Launcher
"1034:TCP" = 1034:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\NCsoft\Exteel\System\Exteel.exe" = C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel – File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer – File not found
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
"C:\Program Files\Valve\Steam\SteamApps\booyakashaka\counter-strike source\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\booyakashaka\counter-strike source\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\Azureus\Azureus.exe" = C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus – File not found
"C:\Program Files\Midway Home Entertainment\Rise and Fall Demo\Bin\RiseAndFallDemo.exe" = C:\Program Files\Midway Home Entertainment\Rise and Fall Demo\Bin\RiseAndFallDemo.exe:*:Enabled:Application – File not found
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – File not found
"C:\Program Files\Microsoft Games\Rise of Nations\rise.exe" = C:\Program Files\Microsoft Games\Rise of Nations\rise.exe:*:Enabled:Rise of Nations – File not found
"C:\Program Files\Ubisoft\Demo\Ghost Recon Advanced Warfighter Demo\GRAW_demo.exe" = C:\Program Files\Ubisoft\Demo\Ghost Recon Advanced Warfighter Demo\GRAW_demo.exe:*:Enabled:GRAW_demo – File not found
"C:\Program Files\Turbine\Dungeons & Dragons Online - Stormreach\dndclient.exe" = C:\Program Files\Turbine\Dungeons & Dragons Online - Stormreach\dndclient.exe:*:Enabled:dndclient – File not found
"C:\Program Files\THQ\Dawn Of War\W40k.exe" = C:\Program Files\THQ\Dawn Of War\W40k.exe:*:Enabled:W40k – File not found
"C:\Program Files\THQ\Dawn Of War\W40kWA.exe" = C:\Program Files\THQ\Dawn Of War\W40kWA.exe:*:Enabled:W40kWA – File not found
"C:\Program Files\Electronic Arts\The Battle for Middle-earth ™ II\game.dat" = C:\Program Files\Electronic Arts\The Battle for Middle-earth ™ II\game.dat:*:Enabled:The Battle for Middle-earth™ II – File not found
"C:\Program Files\Electronic Arts\The Battle for Middle-earth ™ II\patchget.dat" = C:\Program Files\Electronic Arts\The Battle for Middle-earth ™ II\patchget.dat:*:Enabled:patchgrabber – File not found
"C:\NeverwinterNights\NWN\nwmain.exe" = C:\NeverwinterNights\NWN\nwmain.exe:*:Enabled:Neverwinter Nights – File not found
"C:\NeverwinterNights\NWN\nwupdate.exe" = C:\NeverwinterNights\NWN\nwupdate.exe:*:Enabled:NWN Update Program – File not found
"C:\Program Files\Hamachi\hamachi.exe" = C:\Program Files\Hamachi\hamachi.exe:*:Enabled:Hamachi Client – (LogMeIn Inc.)
"C:\Program Files\BitLord\BitLord.exe" = C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord – File not found
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – File not found
"C:\Program Files\Starcraft\StarCraft.exe" = C:\Program Files\Starcraft\StarCraft.exe:*:Enabled:Starcraft – (Blizzard Entertainment)
"C:\Program Files\World In Conflict - Closed MP Beta\wic.exe" = C:\Program Files\World In Conflict - Closed MP Beta\wic.exe:*:Enabled:World in Conflict – File not found
"C:\ijji\ENGLISH\Gunz\Gunz.exe" = C:\ijji\ENGLISH\Gunz\Gunz.exe:*:Enabled:Gunz – File not found
"C:\Documents and Settings\Steven\My Documents\steven\wowclient-downloader.exe" = C:\Documents and Settings\Steven\My Documents\steven\wowclient-downloader.exe:*:Enabled:Blizzard Downloader – File not found
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main – File not found
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD – File not found
"C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater – File not found
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server – File not found
"C:\Program Files\Valve\Steam\SteamApps\booyakashaka\source sdk base\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\booyakashaka\source sdk base\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\THQ\Company of Heroes\RelicCOH.exe" = C:\Program Files\THQ\Company of Heroes\RelicCOH.exe:*:Enabled:RelicCOH – File not found
"C:\WINDOWS\system32\bfwexqec.exe" = C:\WINDOWS\system32\bfw
"C:\Program Files\DC++\DCPlusPlus.exe" = C:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++ – File not found
"C:\Program Files\myTunes Redux\mDNSResponder.exe" = C:\Program Files\myTunes Redux\mDNSResponder.exe:*:Enabled:mDNSResponder – File not found
"C:\Program Files\Warcraft III\Frozen Throne.exe" = C:\Program Files\Warcraft III\Frozen Throne.exe:*:Enabled:Warcraft III - The Frozen Throne – (Blizzard Entertainment)
"C:\Program Files\Warcraft III\w3l.exe" = C:\Program Files\Warcraft III\w3l.exe:*:Enabled:w3l.exe – ()
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III – (Blizzard Entertainment)
"C:\Program Files\Ocean Technology\GG E-Sports Platform\GGclient.exe" = C:\Program Files\Ocean Technology\GG E-Sports Platform\GGclient.exe:*:Enabled:GG E-Sports Platform Client – File not found
"C:\Program Files\Ida\Ida.exe" = C:\Program Files\Ida\Ida.exe:*:Enabled:Ida.exe – (Queen's University)
"C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe" = C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:*:Enabled:UT3 – File not found
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" = C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client – File not found
"C:\Program Files\Ocean Technology\GG E-Sports Platform\Garena.exe" = C:\Program Files\Ocean Technology\GG E-Sports Platform\Garena.exe:*:Enabled:Garena – (Ocean Global Holding)
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"C:\Program Files\NCsoft\Exteel\System\Exteel.exe" = C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel – File not found
"C:\Program Files\Valve\Steam\Steam.exe" = C:\Program Files\Valve\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Garena\Garena.exe" = C:\Program Files\Garena\Garena.exe:*:Enabled:Garena – (Garena Online PTE LTD)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – (Microsoft Corporation)
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player – File not found
"C:\Riot Games\League of Legends\Air\LolClient.exe" = C:\Riot Games\League of Legends\Air\LolClient.exe:*:Enabled:League of Legends Lobby – File not found
"C:\Riot Games\League of Legends\Game\League of Legends.exe" = C:\Riot Games\League of Legends\Game\League of Legends.exe:*:Enabled:League of Legends Game Client – File not found
"C:\Program Files\Valve\Steam\SteamApps\common\dragon age origins\bin_ship\daupdatersvc.service.exe" = C:\Program Files\Valve\Steam\SteamApps\common\dragon age origins\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater – (BioWare)
"C:\Program Files\Valve\Steam\SteamApps\common\dragon age origins\bin_ship\DAOrigins.exe" = C:\Program Files\Valve\Steam\SteamApps\common\dragon age origins\bin_ship\DAOrigins.exe:*:Enabled:Dragon Age: Origins – (BioWare)
"C:\Program Files\Valve\Steam\SteamApps\common\dragon age origins\DAOriginsLauncher.exe" = C:\Program Files\Valve\Steam\SteamApps\common\dragon age origins\DAOriginsLauncher.exe:*:Enabled:Dragon Age: Origins – (BioWare)
"C:\Program Files\Valve\Steam\SteamApps\common\empire total war\Empire.exe" = C:\Program Files\Valve\Steam\SteamApps\common\empire total war\Empire.exe:*:Enabled:Empire: Total War – (The Creative Assembly Ltd)
"C:\Program Files\Valve\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe" = C:\Program Files\Valve\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2 – ()
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam™
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0A146245-DB79-4197-BF5D-FE1A699A2CC7}" = Camera Window DS
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0B5FF5D5-32AC-4576-BC9C-C6402980642D}" = Ida
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP520_series" = Canon MP520 series
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}" = Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1CBE3804-20DF-48DA-B048-895C206E80A5}" = Microsoft SQL Server VSS Writer
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{50E25180-3BDC-4B6D-80A2-3F1F0C9CF39D}" = Camera Window DVC
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{54F6C98F-94A0-421C-B90E-0B6A2A96A9CF}" = Pure Networks Platform
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = PlayNC Launcher
"{625386A4-B6B6-4911-A6E8-23189C3F2D15}" = Microsoft .NET Compact Framework 2.0
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{63A6E9A9-A190-46D4-9430-2DB28654AFD8}" = Norton 360
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABAF1E2-BEB6-4C32-BD9F-0CA733EE7453}" = Iomega Automatic Backup Pro
"{6C3A75A6-9A90-44A3-A703-82AC1EA6A85D}" = Camera Window MC
"{6C531060-84FB-4F96-8F33-29DF020632EB}" = Microsoft .NET Compact Framework 1.0 SP3 Developer
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78B75C6D-E53C-424C-BF83-4B63BD4A6682}" = Microsoft Device Emulator version 1.0 - ENU
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7BC95DD7-E93D-49F9-87EC-93F56FCB333C}" = ADInstruments LabChart 7.1 Reader
"{81063354-9060-42B2-A000-1EBE96778AA9}" = iTunes
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83F12F73-D52E-40C0-93B1-463C311C4E17}" = Dawn Of War
"{85DD724B-15E5-4572-81BF-CF9031D83848}" = Ventrilo Server
"{89C89156-A70F-4C6D-9CAE-2EA71F1396FE}" = Garena
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{901F8ED7-13E8-43EF-B738-2FE89B0588EB}" = Camera Access Library
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91190409-6000-11D3-8CFE-0050048383C9}" = Microsoft Publisher 2002
"{983CE4AE-052A-4AD6-92ED-177DFC85DAE5}" = Warcraft III 1.22 Patch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1D0D14A-B776-4907-BC00-5149F2298086}" = Camera Support Core Library
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2EB8F2E-6D9B-4F8B-96EB-F976D33F416F}" = Camera Window DVC
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3382A07-BFF1-4A8D-9524-DEF82AE3F58B}" = League of Legends
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A804B134-F03D-4EFD-9BC0-DCD257AA1B22}" = Hitman Blood Money
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BF251EAF-8697-4E89-BF09-C998F97BBC40}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DD8408E9-9421-484F-979D-DB6361E3E828}" = Dawn Of War - Winter Assault
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{FCD9CD52-7222-4672-94A0-A722BA702FD0}" = Dell Resource CD
"{FD052FB9-FE90-4438-B355-15EDC89D8FB1}" = Microsoft Games for Windows - LIVE Redistributable
"{FD6C6B7F-5696-48C5-A601-2EE9E50C3D46}" = WD Firewire HID Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Akamai" = Akamai NetSession Interface
"avast!" = avast! Antivirus
"CANONBJ_Deinstall_CNMCP2v.DLL" = Canon S600
"CANONIJPLM100" = PIXMA Extended Survey Program
"DotaKeys" = DotaKeys 1.32.00
"DVD Shrink_is1" = DVD Shrink 3.2
"GameSpy Arcade" = GameSpy Arcade
"GOM Player" = GOM Player
"Hamachi" = Hamachi [removed]
"hon" = Heroes of Newerth
"ICCup Launcher_is1" = ICCup Launcher
"InstallShield_{0A146245-DB79-4197-BF5D-FE1A699A2CC7}" = Canon Camera Window DSLR 5 for ZoomBrowser EX
"InstallShield_{50E25180-3BDC-4B6D-80A2-3F1F0C9CF39D}" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"InstallShield_{6C3A75A6-9A90-44A3-A703-82AC1EA6A85D}" = Canon Camera Window MC 6 for ZoomBrowser EX
"InstallShield_{901F8ED7-13E8-43EF-B738-2FE89B0588EB}" = Canon Camera Access Library
"InstallShield_{A1D0D14A-B776-4907-BC00-5149F2298086}" = Canon Camera Support Core Library
"InstallShield_{A2EB8F2E-6D9B-4F8B-96EB-F976D33F416F}" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"InstallShield_{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"InterActual Player" = InterActual Player
"IsoBuster_is1" = IsoBuster 2.2
"Linksys Wireless Manager" = Linksys Wireless Manager
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MegauploadToolbar" = Megaupload Toolbar
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.0.17)" = Mozilla Firefox (3.0.17)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"NVIDIA Drivers" = NVIDIA Drivers
"PCFriendly" = PCFriendly
"PowerISO" = PowerISO
"PROSet" = Intel® PRO Network Connections Drivers
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 6.0" = RealPlayer
"Runic Games Torchlight" = Torchlight
"ShockwaveFlash" = Macromedia Flash Player 8
"Starcraft" = Starcraft
"Steam App 10500" = Empire: Total War
"Steam App 17450" = Dragon Age: Origins
"Steam App 550" = Left 4 Dead 2
"SystemRequirementsLab" = System Requirements Lab
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.4a
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Worms Armageddon - New Edition" = Worms Armageddon - New Edition
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 25/03/2010 2:22:48 AM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir3360\TEMP_INSTALL\i\agxjaHJvbWV0aGVtZXNyDAsSBEZpbGUYwcoEDA
failed, 00000005.

Error - 25/03/2010 2:22:48 AM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir3360\DECODED_IMAGES
failed, 00000005.

Error - 25/03/2010 7:53:31 PM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir12621\TEMP_INSTALL\manifest.json
failed, 00000005.

Error - 25/03/2010 7:53:31 PM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir12621\TEMP_INSTALL\i\agxjaHJvbWV0aGVtZXNyDAsSBEZpbGUY1toEDA
failed, 00000005.

Error - 25/03/2010 7:53:31 PM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir12621\TEMP_INSTALL\i\agxjaHJvbWV0aGVtZXNyDAsSBEZpbGUY2NoEDA
failed, 00000005.

Error - 25/03/2010 7:53:31 PM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir12621\TEMP_INSTALL\i\agxjaHJvbWV0aGVtZXNyDAsSBEZpbGUY5tIEDA
failed, 00000005.

Error - 25/03/2010 7:53:31 PM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir12621\TEMP_INSTALL\i\agxjaHJvbWV0aGVtZXNyDAsSBEZpbGUYlfkEDA
failed, 00000005.

Error - 25/03/2010 7:53:31 PM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir12621\TEMP_INSTALL\i\agxjaHJvbWV0aGVtZXNyDAsSBEZpbGUYvOIEDA
failed, 00000005.

Error - 25/03/2010 7:53:31 PM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir12621\TEMP_INSTALL\i\agxjaHJvbWV0aGVtZXNyDAsSBEZpbGUYz9YFDA
failed, 00000005.

Error - 25/03/2010 7:53:31 PM | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Steven\Local Settings\Temp\scoped_dir12621\DECODED_IMAGES
failed, 00000005.

[ Application Events ]
Error - 04/04/2010 12:37:54 PM | Computer Name = MAINCOMPUTER | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 04/04/2010 12:38:02 PM | Computer Name = MAINCOMPUTER | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/04/2010 8:14:19 PM | Computer Name = MAINCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/04/2010 8:14:55 PM | Computer Name = MAINCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/04/2010 6:06:53 PM | Computer Name = MAINCOMPUTER | Source = VsJITDebugger | ID = 4096
Description = An unhandled win32 exception occurred in process #3248. Just-In-Time
debugging this exception failed with the following error: The process ID is invalid.

Check
the documentation index for 'Just-in-time debugging, errors' for more information.

Error - 27/04/2010 12:57:09 PM | Computer Name = MAINCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application ave.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 27/04/2010 12:57:09 PM | Computer Name = MAINCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application ave.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 27/04/2010 1:24:22 PM | Computer Name = MAINCOMPUTER | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 28/04/2010 1:10:39 PM | Computer Name = MAINCOMPUTER | Source = crypt32 | ID = 131075
Description = Failed auto update retrieval of third-party root list cab from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: This operation returned because the timeout period expired.

Error - 29/04/2010 11:45:07 AM | Computer Name = MAINCOMPUTER | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024001f, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 2.4.4587.1000, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 28/04/2010 1:10:09 PM | Computer Name = MAINCOMPUTER | Source = Service Control Manager | ID = 7034
Description = The LiveUpdate Notice Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 28/04/2010 1:11:08 PM | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10010
Description = The server {58FC39EB-9DBD-4EA7-B7B4-9404CC6ACFAB} did not register
with DCOM within the required timeout.

Error - 28/04/2010 5:16:13 PM | Computer Name = MAINCOMPUTER | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cercsr6

Error - 28/04/2010 5:44:01 PM | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10010
Description = The server {58FC39EB-9DBD-4EA7-B7B4-9404CC6ACFAB} did not register
with DCOM within the required timeout.

Error - 28/04/2010 6:07:19 PM | Computer Name = MAINCOMPUTER | Source = Service Control Manager | ID = 7000
Description = The HeliosLite service failed to start due to the following error:
%%2

Error - 29/04/2010 12:53:04 AM | Computer Name = MAINCOMPUTER | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cercsr6

Error - 29/04/2010 11:26:01 AM | Computer Name = MAINCOMPUTER | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Akamai service.

Error - 29/04/2010 11:26:29 AM | Computer Name = MAINCOMPUTER | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cercsr6

Error - 29/04/2010 1:46:27 PM | Computer Name = MAINCOMPUTER | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 29/04/2010 1:46:27 PM | Computer Name = MAINCOMPUTER | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >
And the GMER file

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-29 17:47:41
Windows 5.1.2600 Service Pack 3
Running: 9jck9fw2.exe; Driver: C:\DOCUME~1\TANGFA~1\LOCALS~1\Temp\pxdirpob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAD1B26B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAD1B2574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAD1B2A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAD1B214C]
SSDT sptd.sys ZwEnumerateKey [0xBA6D684E]
SSDT sptd.sys ZwEnumerateValueKey [0xBA6D6BEE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAD1B264E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAD1B208C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAD1B20F0]
SSDT sptd.sys ZwQueryKey [0xBA6D6CC6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAD1B276E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAD1B272E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAD1B28AE]

—- Kernel code sections - GMER 1.0.15 —-

? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.rsrc C:\WINDOWS\system32\drivers\pciide.sys entry point in ".rsrc" section [0xBAE70814]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9112360, 0x372FAD, 0xE8000020]
.text USBPORT.SYS!DllUnload B90CA8AC 5 Bytes JMP 8A5561B8
init C:\WINDOWS\system32\DRIVERS\mohfilt.sys entry point in "init" section [0xBAC33760]
? System32\Drivers\amfc5l3k.SYS The system cannot find the path specified. !
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xA9BAD300, 0x3AF78, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xBAC18300, 0x1BCE, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\Explorer.EXE[1372] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A1000A
.text C:\WINDOWS\Explorer.EXE[1372] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00AF000A
.text C:\WINDOWS\Explorer.EXE[1372] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A0000C
.text C:\WINDOWS\System32\svchost.exe[1480] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 007E000A
.text C:\WINDOWS\System32\svchost.exe[1480] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 007F000A
.text C:\WINDOWS\System32\svchost.exe[1480] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 007D000C
.text C:\WINDOWS\System32\svchost.exe[1480] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0269000A
.text C:\WINDOWS\System32\svchost.exe[1480] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 0265000A
.text C:\WINDOWS\system32\wuauclt.exe[2804] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00AB000A
.text C:\WINDOWS\system32\wuauclt.exe[2804] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00AC000A
.text C:\WINDOWS\system32\wuauclt.exe[2804] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003D000C

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8A5551D8

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Fastfat \FatCdrom 8922E1D8

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\usbuhci \Device\USBPDO-0 89A517E8
Device \Driver\usbuhci \Device\USBPDO-1 89A517E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A5C91D8
Device \Driver\dmio \Device\DmControl\DmConfig 8A5C91D8
Device \Driver\dmio \Device\DmControl\DmPnP 8A5C91D8
Device \Driver\dmio \Device\DmControl\DmInfo 8A5C91D8
Device \Driver\usbehci \Device\USBPDO-2 89A52980
Device \Driver\usbuhci \Device\USBPDO-3 89A517E8
Device \Driver\usbuhci \Device\USBPDO-4 89A517E8

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\00000056 \Device\00000057 sptd.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A5581D8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IABFilt.sys (Volume Filter Driver Windows 2000/XP/2003/Iomega)

Device \Driver\Ftdisk \Device\HarddiskVolume2 8A5581D8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IABFilt.sys (Volume Filter Driver Windows 2000/XP/2003/Iomega)

Device \Driver\Cdrom \Device\CdRom0 899C4558
Device \Driver\iastor \Device\Ide\iaStor0 8A5571D8
Device \Driver\atapi \Device\Ide\IdePort0 [BA550B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [BA550B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [BA550B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 899C4558
Device \Driver\Cdrom \Device\CdRom2 899C4558
Device \Driver\NetBT \Device\NetBT_Tcpip_{2164E598-1316-419A-9693-C7446EABE023} 896C87E8
Device \Driver\Cdrom \Device\CdRom3 899C4558
Device \Driver\USBSTOR \Device\00000081 897DB778
Device \Driver\Cdrom \Device\CdRom4 899C4558
Device \Driver\USBSTOR \Device\00000082 897DB778
Device \Driver\NetBT \Device\NetBt_Wins_Export 896C87E8
Device \Driver\USBSTOR \Device\00000077 897DB778
Device \Driver\NetBT \Device\NetbiosSmb 896C87E8

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\usbuhci \Device\USBFDO-0 89A517E8
Device \Driver\usbuhci \Device\USBFDO-1 89A517E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8980F1D8
Device \Driver\usbuhci \Device\USBFDO-2 89A517E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8980F1D8
Device \Driver\USBSTOR \Device\0000007c 897DB778
Device \Driver\usbuhci \Device\USBFDO-3 89A517E8
Device \Driver\usbehci \Device\USBFDO-4 89A52980
Device \Driver\Ftdisk \Device\FtControl 8A5581D8
Device \Driver\amfc5l3k \Device\Scsi\amfc5l3k1 899B5980
Device \Driver\amfc5l3k \Device\Scsi\amfc5l3k1Port2Path0Target1Lun0 899B5980
Device \Driver\amfc5l3k \Device\Scsi\amfc5l3k1Port2Path0Target2Lun0 899B5980
Device \Driver\amfc5l3k \Device\Scsi\amfc5l3k1Port2Path0Target0Lun0 899B5980
Device \FileSystem\Fastfat \Fat 8922E1D8

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Cdfs \Cdfs 897BF758
Device -> \Driver\iastor \Device\Harddisk0\DR0 8A43DEE4

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 896059734
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 164332345
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x33 0x85 0xDF 0x3F …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3C 0xF8 0x96 0x5A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xB4 0x15 0xB7 0x8F …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3D 0x50 0x76 0xF5 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xFC 0x88 0xF4 0xF6 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x33 0x85 0xDF 0x3F …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xA8 0x79 0x84 0x29 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x19 0x12 0x5B 0x8E …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x76 0xAA 0x08 0xAC …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x33 0x85 0xDF 0x3F …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3C 0xF8 0x96 0x5A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xB4 0x15 0xB7 0x8F …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3D 0x50 0x76 0xF5 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xFC 0x88 0xF4 0xF6 …

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\pciide.sys suspicious modification
File C:\WINDOWS\system32\drivers\iastor.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hi TangJuice,

Your system has been infected by one or more Rootkits/Backdoor Trojans.

These can remotely control your computer, steal critical system information and Download and Execute files

I suggest you do the following immediately:
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer the new passwords could be compromised.


You have both Norton 360 and Avast antivirus installed. Multiple antvirus programs do not mean more protection. This can actually mean less as they will conflict causing system slow downs. Pleas uninstall one of them. Let me know which one you decide to keep.


You have a program whose drives will interfer with some of the tools we are going to use. We will disable them with this next tool. Please do not re-enable them untill we are done.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


Next

Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O20 - Winlogon\Notify\efcbbyv: DllName - efcbbyv.dll - File not found
[2010/04/27 13:37:32 | 000,011,958 | -HS- | C] () – C:\Documents and Settings\Tang Family\Local Settings\Application Data\KLry0l
[2010/04/27 12:45:33 | 000,011,962 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KLry0l
[2010/04/28 13:07:50 | 000,011,878 | -HS- | M] () – C:\Documents and Settings\Tang Family\Local Settings\Application Data\1167664209
[2010/04/27 13:02:39 | 000,011,994 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\1167664209

:Files
C:\sqmdata*.sqm
C:\WINDOWS\tasks\At*.job
C:\sqmnoopt*.sqm

:Commands
[emptytemp]
[emptyflash]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.


Next

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • OTL fix log
  • combofix log
How's the computer?

Thanks
Hey, here is the otl fix log All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\efcbbyv\ deleted successfully. File C:\Documents and Settings\Tang Family\Local Settings\Application Data\KLry0l not found. C:\Documents and Settings\All Users\Application Data\KLry0l moved successfully. File C:\Documents and Settings\Tang Family\Local Settings\Application Data\1167664209 not found. C:\Documents and Settings\All Users\Application Data\1167664209 moved successfully. ========== FILES ========== C:\sqmdata00.sqm moved successfully. C:\sqmdata01.sqm moved successfully. C:\sqmdata02.sqm moved successfully. C:\sqmdata03.sqm moved successfully. C:\sqmdata04.sqm moved successfully. C:\sqmdata05.sqm moved successfully. C:\sqmdata06.sqm moved successfully. C:\sqmdata07.sqm moved successfully. C:\sqmdata08.sqm moved successfully. C:\sqmdata09.sqm moved successfully. C:\sqmdata10.sqm moved successfully. C:\sqmdata11.sqm moved successfully. C:\sqmdata12.sqm moved successfully. C:\sqmdata13.sqm moved successfully. C:\sqmdata14.sqm moved successfully. C:\sqmdata15.sqm moved successfully. C:\WINDOWS\tasks\At1.job moved successfully. C:\WINDOWS\tasks\At10.job moved successfully. C:\WINDOWS\tasks\At11.job moved successfully. C:\WINDOWS\tasks\At12.job moved successfully. C:\WINDOWS\tasks\At13.job moved successfully. C:\WINDOWS\tasks\At14.job moved successfully. C:\WINDOWS\tasks\At15.job moved successfully. C:\WINDOWS\tasks\At16.job moved successfully. C:\WINDOWS\tasks\At17.job moved successfully. C:\WINDOWS\tasks\At18.job moved successfully. C:\WINDOWS\tasks\At19.job moved successfully. C:\WINDOWS\tasks\At2.job moved successfully. C:\WINDOWS\tasks\At20.job moved successfully. C:\WINDOWS\tasks\At21.job moved successfully. C:\WINDOWS\tasks\At22.job moved successfully. C:\WINDOWS\tasks\At23.job moved successfully. C:\WINDOWS\tasks\At24.job moved successfully. C:\WINDOWS\tasks\At3.job moved successfully. C:\WINDOWS\tasks\At4.job moved successfully. C:\WINDOWS\tasks\At5.job moved successfully. C:\WINDOWS\tasks\At6.job moved successfully. C:\WINDOWS\tasks\At7.job moved successfully. C:\WINDOWS\tasks\At8.job moved successfully. C:\WINDOWS\tasks\At9.job moved successfully. C:\sqmnoopt00.sqm moved successfully. C:\sqmnoopt01.sqm moved successfully. C:\sqmnoopt02.sqm moved successfully. C:\sqmnoopt03.sqm moved successfully. C:\sqmnoopt04.sqm moved successfully. C:\sqmnoopt05.sqm moved successfully. C:\sqmnoopt06.sqm moved successfully. C:\sqmnoopt07.sqm moved successfully. C:\sqmnoopt08.sqm moved successfully. C:\sqmnoopt09.sqm moved successfully. C:\sqmnoopt10.sqm moved successfully. C:\sqmnoopt11.sqm moved successfully. C:\sqmnoopt12.sqm moved successfully. C:\sqmnoopt13.sqm moved successfully. C:\sqmnoopt14.sqm moved successfully. C:\sqmnoopt15.sqm moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41044 bytes User: LocalService ->Temp folder emptied: 115136 bytes ->Temporary Internet Files folder emptied: 20875511 bytes User: NetworkService ->Temp folder emptied: 2921072 bytes ->Temporary Internet Files folder emptied: 7842144 bytes ->Flash cache emptied: 2280 bytes User: Steven ->Temp folder emptied: 1306788026 bytes ->Temporary Internet Files folder emptied: 24778969 bytes ->Java cache emptied: 58350579 bytes ->FireFox cache emptied: 120837841 bytes ->Google Chrome cache emptied: 161181425 bytes ->Flash cache emptied: 1480600 bytes User: Tang Family ->Temp folder emptied: 21656797 bytes ->Temporary Internet Files folder emptied: 7314646 bytes ->Java cache emptied: 43629489 bytes ->FireFox cache emptied: 35733464 bytes ->Flash cache emptied: 1072 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2296155 bytes %systemroot%\System32 .tmp files removed: 1172113 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3070109 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 5647745 bytes Total Files Cleaned = 1,741.00 mb [EMPTYFLASH] User: All Users User: Default User ->Flash cache emptied: 0 bytes User: LocalService User: NetworkService ->Flash cache emptied: 0 bytes User: Steven ->Flash cache emptied: 0 bytes User: Tang Family ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.3.0 log created on 04292010_204951 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_1a8.dat not found! File\Folder C:\Documents and Settings\Tang Family\Local Settings\Temp\Perflib_Perfdata_f94.dat not found! C:\WINDOWS\temp\Perflib_Perfdata_614.dat moved successfully. File\Folder C:\WINDOWS\temp\Perflib_Perfdata_764.dat not found! Registry entries deleted on Reboot…
And the combofix log

ComboFix 10-04-29.04 - Tang Family 29/04/2010 21:42:27.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1370 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 100429-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Tang Family\nwiz .exe
c:\documents and settings\Tang Family\rundll32 .exe
c:\documents and settings\Tang Family\rundll32.exe
c:\documents and settings\Tang Family\stsystra .exe
c:\documents and settings\Tang Family\wdbtnmgr .exe
c:\program files\Internet Explorer\js.mui
c:\program files\Internet Explorer\wmpscfgs.exe
c:\windows\system32\ctfmon .exe
.
—- Previous Run ——-
.
c:\documents and settings\Steven\Application Data\EA818B4DCAA69039D050124A526A961C
c:\documents and settings\Steven\Application Data\EA818B4DCAA69039D050124A526A961C\enemies-names.txt
c:\documents and settings\Steven\Application Data\EA818B4DCAA69039D050124A526A961C\newupdate1142c.exe
c:\documents and settings\Steven\Start Menu\Programs\Antimalware Doctor
c:\documents and settings\Steven\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
c:\documents and settings\Steven\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
c:\documents and settings\Steven\Start Menu\Programs\Startup\Antimalware Doctor.lnk
c:\documents and settings\Tang Family\nwiz .exe
c:\documents and settings\Tang Family\rundll32 .exe
c:\documents and settings\Tang Family\rundll32.exe
c:\documents and settings\Tang Family\stsystra .exe
c:\documents and settings\Tang Family\wdbtnmgr .exe
c:\program files\INSTALL.LOG
c:\program files\Internet Explorer\js.mui
c:\program files\Internet Explorer\wmpscfgs.exe
c:\windows\system32\ctfmon .exe
c:\windows\system32\nwiz .exe
c:\windows\system32\regsvr32 .exe
c:\windows\system32\rundll32 .exe
c:\windows\system32\stsystra .exe
c:\windows\system32\wdbtnmgr .exe

.
((((((((((((((((((((((((( Files Created from 2010-03-28 to 2010-04-30 )))))))))))))))))))))))))))))))
.

2010-04-30 00:49 . 2010-04-30 00:49 ——– d—–w- C:\_OTL
2010-04-29 17:27 . 2010-04-29 17:27 ——– d—–w- c:\program files\ClamWinPortable
2010-04-28 22:14 . 2010-04-28 22:14 ——– d—–w- c:\documents and settings\Tang Family\Local Settings\Application Data\Apple
2010-04-28 17:51 . 2010-04-28 17:51 ——– d—–w- c:\documents and settings\Tang Family\Application Data\Malwarebytes
2010-04-28 17:51 . 2010-03-30 04:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-28 17:51 . 2010-04-28 17:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-28 17:51 . 2010-04-28 21:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-28 17:51 . 2010-03-30 04:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-27 17:33 . 2010-04-27 17:33 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-04-27 17:24 . 2010-04-30 01:38 36864 —-a-w- c:\documents and settings\Tang Family\wdbtnmgr.exe
2010-04-27 17:24 . 2010-04-30 01:38 36864 —-a-w- c:\documents and settings\Tang Family\nwiz.exe
2010-04-27 17:24 . 2010-04-30 01:38 36864 —-a-w- c:\documents and settings\Tang Family\stsystra.exe
2010-04-27 16:57 . 2008-04-13 18:40 34688 -c–a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-04-27 16:57 . 2008-04-13 18:40 34688 —-a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-04-27 16:57 . 2008-04-13 18:41 8576 -c–a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-04-27 16:57 . 2008-04-13 18:41 8576 —-a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-04-27 16:57 . 2008-04-13 18:40 8192 -c–a-w- c:\windows\system32\dllcache\changer.sys
2010-04-27 16:57 . 2008-04-13 18:40 8192 —-a-w- c:\windows\system32\drivers\changer.sys
2010-04-27 16:47 . 2008-04-13 16:39 142592 -c–a-w- c:\windows\system32\dllcache\aec.sys
2010-04-27 16:47 . 2008-04-13 16:39 142592 —-a-w- c:\windows\system32\drivers\aec.sys
2010-04-27 16:46 . 2010-04-30 01:22 36864 —-a-w- c:\windows\system32\stsystra.exe
2010-04-15 01:30 . 2010-04-15 01:30 56380 —ha-w- c:\windows\system32\mlfcache.dat
2010-04-05 21:07 . 2010-04-05 21:12 ——– d—–w- c:\documents and settings\All Users\Application Data\ADInstruments
2010-04-05 21:06 . 2010-04-05 21:06 ——– d—–w- c:\documents and settings\Steven\Application Data\ADInstruments
2010-04-05 21:06 . 2010-04-05 21:06 ——– d—–w- c:\program files\ADInstruments
2010-04-05 21:06 . 2010-04-05 21:07 ——– d—–w- c:\program files\Common Files\ADInstruments
2010-04-02 01:16 . 2010-04-02 01:16 ——– d—–w- c:\program files\MSECache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-30 01:38 . 2010-03-10 17:23 ——– d—–w- c:\program files\iTunes
2010-04-30 01:38 . 2010-03-10 17:20 ——– d—–w- c:\program files\QuickTime
2010-04-30 01:38 . 2008-09-06 09:59 ——– d—–w- c:\program files\Windows Defender
2010-04-30 01:38 . 2006-02-24 22:34 ——– d—–w- c:\program files\MSN Messenger
2010-04-30 01:36 . 2010-02-13 02:50 ——– d—–w- c:\program files\Common Files\Akamai
2010-04-30 01:22 . 2007-09-01 23:02 36864 —-a-w- c:\windows\system32\wdbtnmgr.exe
2010-04-30 01:22 . 2005-12-10 08:06 36864 —-a-w- c:\windows\system32\nwiz.exe
2010-04-30 00:46 . 2006-02-24 17:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-04-28 21:54 . 2009-10-13 19:41 ——– d—–w- c:\program files\Pando Networks
2010-04-28 21:54 . 2006-03-20 15:41 ——– d—–w- c:\program files\Canon
2010-04-28 21:53 . 2008-08-18 18:46 ——– d—–w- c:\program files\Download Manager
2010-04-28 21:14 . 2008-09-06 19:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-04-27 17:24 . 2006-02-24 17:04 72840 —-a-w- c:\documents and settings\Tang Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-27 17:06 . 2009-11-24 09:17 ——– d—–w- c:\documents and settings\Steven\Application Data\Keybreeze data
2010-04-27 16:45 . 2008-04-26 19:11 ——– d—–w- c:\program files\Ida
2010-04-21 22:52 . 2010-03-25 22:04 ——– d—–w- c:\program files\Heroes of Newerth
2010-04-18 18:12 . 2007-05-28 20:32 ——– d—–w- c:\program files\Starcraft
2010-04-17 21:05 . 2008-06-04 02:57 ——– d—–w- c:\program files\Garena
2010-04-11 01:26 . 2008-03-29 06:13 ——– d—–w- c:\documents and settings\Steven\Application Data\Skype
2010-04-10 20:11 . 2006-05-20 17:44 ——– d—–w- c:\program files\Warcraft III
2010-04-08 19:46 . 2008-08-17 22:42 ——– d—–w- c:\documents and settings\Steven\Application Data\uTorrent
2010-04-03 04:43 . 2006-04-23 03:16 72840 —-a-w- c:\documents and settings\Steven\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-28 00:48 . 2009-11-10 23:23 79488 —-a-w- c:\documents and settings\Steven\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-25 03:42 . 2008-08-29 20:47 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2010-03-10 17:39 . 2006-02-25 00:05 ——– d—–w- c:\documents and settings\Steven\Application Data\Apple Computer
2010-03-10 17:32 . 2010-03-10 17:32 2272 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-03-10 17:24 . 2010-03-10 17:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-03-10 17:23 . 2010-03-10 17:23 ——– d—–w- c:\program files\iPod
2010-03-10 17:23 . 2008-03-24 01:34 ——– d—–w- c:\program files\Common Files\Apple
2010-03-10 17:21 . 2010-03-10 17:21 ——– d—–w- c:\program files\Bonjour
2010-03-10 17:12 . 2010-03-10 17:12 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-03-01 08:13 . 2010-03-01 08:09 ——– d—–w- c:\documents and settings\Steven\Application Data\Command and Conquer 4 Beta
2010-03-01 07:41 . 2010-03-01 07:41 3206928 —-a-w- c:\documents and settings\All Users\Application Data\Electronic Arts Inc\CNC4BetaPatch\LauncherUpdate_R15b.exe
2010-03-01 07:41 . 2010-03-01 07:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Electronic Arts Inc
2010-03-01 06:57 . 2008-09-18 15:09 ——– d—–w- c:\program files\Electronic Arts
2010-02-24 14:16 . 2009-10-03 06:04 181632 ——w- c:\windows\system32\MpSigStub.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\Canon\MyPrinter\bjmyprt .exe
c:\program files\Canon\SolutionMenu\cnslmain .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\InstallShield\UpdateService\issch .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\Microsoft Shared\DW\dwtrig20 .exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate .exe
c:\program files\Download Manager\dlm .exe
c:\program files\Ida\idalaunch .exe
c:\program files\Intel\Intel Matrix Storage Manager\iaanotif .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Linksys\Linksys Wireless Manager\linksyswirelessmanager .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\MSN Messenger\msnmsgr .exe
c:\program files\Nero\Nero PhotoShow 4\data\Xtras\mssysm~1 .exe
c:\program files\QuickTime\qttask		.exe
c:\program files\QuickTime\qttask	   .exe
c:\program files\QuickTime\qttask	  .exe
c:\program files\QuickTime\qttask	 .exe
c:\program files\QuickTime\qttask	.exe
c:\program files\QuickTime\qttask   .exe
c:\program files\QuickTime\qttask  .exe
c:\program files\QuickTime\qttask .exe
c:\program files\ScanSoft\OmniPageSE4\opwarese4 .exe
c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer .exe
c:\program files\Windows Defender\msascui .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2010-04-30 36864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\quicktime\qttask .exe -atboottime" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2010-04-30 36864]
"SigmatelSysTrayApp"="stsystra.exe" [2010-04-30 36864]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2010-04-30 36864]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2010-04-30 36864]
"nwiz"="nwiz.exe" [2010-04-30 36864]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-30 36864]
"WD Button Manager"="WDBtnMgr.exe" [2010-04-30 36864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2010-04-30 36864]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2010-04-30 36864]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2010-04-30 36864]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-04-30 36864]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2010-04-30 36864]
"Linksys Wireless Manager"="c:\program files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2010-04-30 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-30 36864]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-04-30 36864]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-30 36864]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-04-30 36864]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 20:28 352256 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\booyakashaka\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\booyakashaka\\source sdk base\\hl2.exe"=
"c:\\Program Files\\Warcraft III\\Frozen Throne.exe"=
"c:\\Program Files\\Warcraft III\\w3l.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ida\\Ida.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\Garena.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Valve\\Steam\\Steam.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\dragon age origins\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\dragon age origins\\bin_ship\\DAOrigins.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\dragon age origins\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\left 4 dead 2\\left4dead2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Warcraft
"2303:UDP"= 2303:UDP:battlelan
"2573:UDP"= 2573:UDP:Battlelan
"8395:TCP"= 8395:TCP:League of Legends Launcher
"8395:UDP"= 8395:UDP:League of Legends Launcher
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"8397:TCP"= 8397:TCP:League of Legends Launcher
"8397:UDP"= 8397:UDP:League of Legends Launcher
"8398:TCP"= 8398:TCP:League of Legends Launcher
"8398:UDP"= 8398:UDP:League of Legends Launcher
"8399:TCP"= 8399:TCP:League of Legends Launcher
"8399:UDP"= 8399:UDP:League of Legends Launcher
"8380:TCP"= 8380:TCP:League of Legends Launcher
"8380:UDP"= 8380:UDP:League of Legends Launcher
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"8382:TCP"= 8382:TCP:League of Legends Launcher
"8382:UDP"= 8382:UDP:League of Legends Launcher

R0 IABFilt;Iomega Snapshot Volume Filter;c:\windows\system32\drivers\IABFilt.sys [03/03/2005 12:23 PM 23040]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [25/02/2009 6:29 PM 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [03/09/2008 2:07 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [03/09/2008 2:07 PM 55024]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [04/08/2004 8:00 AM 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [25/02/2009 6:29 PM 20560]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 7:19 PM 13592]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Valve\Steam\SteamApps\common\dragon age origins\bin_ship\daupdatersvc.service.exe [05/11/2009 3:15 AM 25832]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Steven\LOCALS~1\Temp\ICJ494B.tmp –> c:\docume~1\Steven\LOCALS~1\Temp\ICJ494B.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS –> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [30/09/2009 5:02 PM 627072]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [22/05/2006 12:57 AM 639224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder

2010-04-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-04-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1614895754-839522115-1003Core.job
- c:\documents and settings\Steven\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-19 16:46]

2010-04-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1614895754-839522115-1003UA.job
- c:\documents and settings\Steven\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-19 16:46]

2010-04-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.15.0.cab
FF - ProfilePath - c:\documents and settings\Tang Family\Application Data\Mozilla\Firefox\Profiles\3bgkpl36.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.torrentpond.com/|http://www.google.ca/|http://login.live.com/login.srf?id=2|http://www.facebook.com/|http://commondreams.org/|http://www.yousendit.com/
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

AddRemove-MegauploadToolbar - c:\program files\MegauploadToolbar\uninstall.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\UninstFl.exe
AddRemove-Xfire - c:\program files\Xfire\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-29 21:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Steven\LOCALS~1\Temp\ICJ494B.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(936)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2010-04-29 21:55:43
ComboFix-quarantined-files.txt 2010-04-30 01:55

Pre-Run: 23,708,381,184 bytes free
Post-Run: 23,674,748,928 bytes free

- - End Of File - - A11EF1C0B46F553997F2D80332CE9096
Hey, so with the combofix once it finished my computer actually crashed so the log didn't get made but i ran it again after i restarted just in case which worked fine and thats what i posted. Things seem to be fine now so thank you very much for your help definitely saved me alot of trouble so again thanks alot. ive also gotten access to system restore again so should i turn it off and turn it back on again? And is there anything else you recommend i do to make sure its not just lurking and is completely gone?
Hi

We another infection to deal with.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :filefind
    reader_sl.exe
    bjmyprt.exe
    cnslmain.exe
    adobearm.exe
    issch.exe
    isuspm.exe
    dwtrig20.exe
    nmctxth.exe
    realsched.exe
    ssbkgdupdate.exe
    dlm.exe
    idalaunch.exe
    iaanotif.exe
    ituneshelper.exe
    jusched.exe
    linksyswirelessmanager.exe
    mbam.exe
    msnmsgr.exe
    mssysm~1.exe
    qttask.exe
    opwarese4.exe
    veohwebplayer.exe
    msascui.exe
    wdbtnmgr.exe
    nwiz.exe
    stsystra.exe
    ctfmon.exe
    nwiz.exe
    regsvr32.exe
    rundll32.exe
    * .exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hey, here is the system look log, and yah ive still been having attempted attacks that avast has been blocking. Thanks SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 17:42 on 30/04/2010 by Tang Family (Administrator - Elevation successful) ========== filefind ========== Searching for "reader_sl.exe" C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe –a— 36864 bytes [08:08 03/10/2009] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "bjmyprt.exe" No files found. Searching for "cnslmain.exe" No files found. Searching for "adobearm.exe" C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm.exe –a— 36864 bytes [16:08 04/09/2009] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "issch.exe" C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe –a— 36864 bytes [21:50 27/07/2004] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "isuspm.exe" C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe –a— 36864 bytes [16:46 27/04/2010] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "dwtrig20.exe" C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20.exe –a— 36864 bytes [19:38 13/03/2007] [00:44 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B Searching for "nmctxth.exe" C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe –a— 36864 bytes [22:06 12/12/2008] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "realsched.exe" C:\Program Files\Common Files\Real\Update_OB\realsched.exe –a— 36864 bytes [01:59 17/04/2006] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "ssbkgdupdate.exe" C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate.exe –a— 36864 bytes [13:03 25/10/2006] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "dlm.exe" C:\Program Files\Download Manager\dlm.exe –a— 36864 bytes [02:29 30/04/2010] [03:35 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B Searching for "idalaunch.exe" C:\Program Files\Ida\idalaunch.exe –a— 36864 bytes [00:14 31/12/2007] [03:35 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B Searching for "iaanotif.exe" C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe –a— 36864 bytes [19:50 24/02/2006] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "ituneshelper.exe" C:\Program Files\iTunes\iTunesHelper.exe –a— 142120 bytes [19:06 28/04/2010] [19:06 28/04/2010] A244E67F073377DE0E53D3068932B040 Searching for "jusched.exe" C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe –a— 36975 bytes [00:58 25/02/2006] [08:48 13/04/2005] BD902D0D7ED7C2D5FC327567CE96B97C C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe –a— 83608 bytes [14:35 02/05/2007] [07:43 14/03/2007] 9C1C80BBF8E6044980890E2D2D91091C C:\Program Files\Java\jre6\bin\jusched.exe –a— 36864 bytes [02:55 31/05/2009] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "linksyswirelessmanager.exe" C:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager.exe –a— 36864 bytes [03:35 30/04/2010] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "mbam.exe" No files found. Searching for "msnmsgr.exe" C:\Program Files\MSN Messenger\msnmsgr.exe –a— 36864 bytes [16:54 19/01/2007] [01:38 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B Searching for "mssysm~1.exe" No files found. Searching for "qttask.exe" C:\Program Files\QuickTime\QTTask.exe –a— 421888 bytes [01:53 18/03/2010] [01:53 18/03/2010] ED7A6D40B20DC34BE06F4AE196AE7D50 Searching for "opwarese4.exe" C:\Program Files\ScanSoft\OmniPageSE4\opwarese4.exe –a— 36864 bytes [16:02 04/02/2007] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "veohwebplayer.exe" C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe –a— 36864 bytes [02:29 30/04/2010] [03:35 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B Searching for "msascui.exe" No files found. Searching for "wdbtnmgr.exe" C:\WINDOWS\system32\wdbtnmgr.exe –a— 36864 bytes [23:02 01/09/2007] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "nwiz.exe" C:\WINDOWS\system32\nwiz.exe –a— 36864 bytes [08:06 10/12/2005] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "stsystra.exe" C:\DELL\drivers\R97752\WDM\stsystra.exe –a— 339968 bytes [19:53 24/02/2006] [22:20 22/03/2005] 0F869E88FA4489FBE231A42646488CE8 C:\Program Files\SigmaTel\C-Major Audio\wdm\stsystra.exe —— 339968 bytes [19:53 24/02/2006] [22:20 22/03/2005] 0F869E88FA4489FBE231A42646488CE8 C:\WINDOWS\stsystra.exe –a— 339968 bytes [19:53 24/02/2006] [22:20 22/03/2005] 0F869E88FA4489FBE231A42646488CE8 C:\WINDOWS\system32\stsystra.exe –a— 36864 bytes [16:46 27/04/2010] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "ctfmon.exe" C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe —–c 15360 bytes [19:36 29/08/2008] [12:00 04/08/2004] 24232996A38C0B0CF151C2140AE29FC8 C:\WINDOWS\ERDNT\cache\ctfmon.exe –a— 15360 bytes [01:54 30/04/2010] [00:12 14/04/2008] 5F1D5F88303D4A4DBC8E5F97BA967CC3 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe —— 15360 bytes [19:27 29/08/2008] [00:12 14/04/2008] 5F1D5F88303D4A4DBC8E5F97BA967CC3 C:\WINDOWS\system32\ctfmon.exe –a— 15360 bytes [12:00 04/08/2004] [00:12 14/04/2008] 5F1D5F88303D4A4DBC8E5F97BA967CC3 C:\WINDOWS\system32\dllcache\ctfmon.exe –a–c 15360 bytes [12:00 04/08/2004] [00:12 14/04/2008] 5F1D5F88303D4A4DBC8E5F97BA967CC3 Searching for "nwiz.exe" C:\WINDOWS\system32\nwiz.exe –a— 36864 bytes [08:06 10/12/2005] [03:35 30/04/2010] (Unable to calculate MD5) Searching for "regsvr32.exe" C:\WINDOWS\$NtServicePackUninstall$\regsvr32.exe —–c 11776 bytes [19:35 29/08/2008] [12:00 04/08/2004] 9709EAD856A690333138AC40804F914E C:\WINDOWS\ServicePackFiles\i386\regsvr32.exe —— 11776 bytes [19:27 29/08/2008] [00:12 14/04/2008] FBDB9D0935B9907B809B381FDDF1627F C:\WINDOWS\system32\dllcache\regsvr32.exe –a–c 11776 bytes [12:00 04/08/2004] [00:12 14/04/2008] FBDB9D0935B9907B809B381FDDF1627F C:\WINDOWS\system32\regsvr32.exe –a— 11776 bytes [12:00 04/08/2004] [00:12 14/04/2008] FBDB9D0935B9907B809B381FDDF1627F Searching for "rundll32.exe" C:\WINDOWS\$NtServicePackUninstall$\rundll32.exe —–c 33280 bytes [19:35 29/08/2008] [12:00 04/08/2004] DA285490BBD8A1D0CE6623577D5BA1FF C:\WINDOWS\ServicePackFiles\i386\rundll32.exe —— 33280 bytes [19:27 29/08/2008] [00:12 14/04/2008] 037B1E7798960E0420003D05BB577EE6 C:\WINDOWS\system32\dllcache\rundll32.exe –a–c 33280 bytes [12:00 04/08/2004] [00:12 14/04/2008] 037B1E7798960E0420003D05BB577EE6 C:\WINDOWS\system32\rundll32.exe –a— 33280 bytes [12:00 04/08/2004] [00:12 14/04/2008] 037B1E7798960E0420003D05BB577EE6 Searching for "* .exe" C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Update\googleupdate .exe –a— 133104 bytes [19:13 19/10/2009] [19:13 19/10/2009] 626A24ED1228580B9518C01930936DF9 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl .exe –a— 35696 bytes [08:08 03/10/2009] [08:08 03/10/2009] 33E5A8FC8EB0EE42478F8538D0215D8F C:\Program Files\Canon\MyPrinter\bjmyprt .exe –a— 1603152 bytes [20:40 29/08/2008] [16:50 03/04/2007] 2F0F0E6AA6F5874E13E792996077138B C:\Program Files\Canon\SolutionMenu\cnslmain .exe –a— 644696 bytes [20:39 29/08/2008] [16:01 14/05/2007] FEDB6110D3E0A7EFE6996F93CD8C48E7 C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm .exe –a— 952768 bytes [16:08 04/09/2009] [18:17 24/03/2010] DB1DB28467111A24664933AB8908CBCE C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe –a— 81920 bytes [21:50 27/07/2004] [19:30 11/08/2005] 7D58C9BDF9C0A3955BDCDE7387AD12AC C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe –a— 36864 bytes [16:46 27/04/2010] [16:46 27/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20 .exe –a— 39264 bytes [19:38 13/03/2007] [19:38 13/03/2007] 6D787FDF93DE266CE25378FB362DF011 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth .exe –a— 642856 bytes [22:06 12/12/2008] [22:06 12/12/2008] D6633A7A634E6803CB13543808B4C935 C:\Program Files\Common Files\Real\Update_OB\realsched .exe –a— 180269 bytes [01:59 17/04/2006] [01:59 17/04/2006] 1AC2C58B587C70DE64582AD41EE79FBA C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate .exe –a— 210472 bytes [13:03 25/10/2006] [13:03 25/10/2006] 846965AE55A2662B1576C0F392DD1D6E C:\Program Files\Download Manager\dlm .exe –a— 1103216 bytes [20:36 01/08/2008] [20:36 01/08/2008] CF0CE2D62B3B39A186F003A19A07AF2F C:\Program Files\Ida\idalaunch .exe –a— 32136 bytes [00:14 31/12/2007] [00:14 31/12/2007] E519FA8F4AE589C71434A27747F944AE C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe –a— 139264 bytes [19:50 24/02/2006] [13:50 25/04/2005] B04E826B086568DCBE80DBC2841BE2B2 C:\Program Files\iTunes\ituneshelper .exe –a— 141608 bytes [23:07 15/02/2010] [23:07 15/02/2010] 8DC7685764B22DB97891012026FA7ED1 C:\Program Files\Java\jre6\bin\jusched .exe –a— 148888 bytes [02:55 31/05/2009] [02:55 31/05/2009] A2D390F1F2408B94EF34BFE3A00C29D3 C:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager .exe -ra— 1358384 bytes [21:04 30/09/2009] [09:44 16/02/2009] AB347BDF952A41BA18196B40C0381407 C:\Program Files\Malwarebytes' Anti-Malware\mbam .exe –a— 1086856 bytes [17:51 28/04/2010] [04:46 30/03/2010] 6FD614E7109CC0A3DAFE65F9D394F66E C:\Program Files\MSN Messenger\msnmsgr .exe –a— 5674352 bytes [16:54 19/01/2007] [16:54 19/01/2007] C4281AD865739E71FD1E4DAC19A68D60 C:\Program Files\Pando Networks\Media Booster\pmb .exe –a— 36864 bytes [02:29 30/04/2010] [02:29 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\QuickTime\qttask .exe –a— 417792 bytes [04:08 11/11/2009] [04:08 11/11/2009] 55D7A219AD8D0DB8980528944152A6FD C:\Program Files\QuickTime\qttask .exe –a— 36864 bytes [04:08 11/11/2009] [02:34 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\QuickTime\qttask .exe –a— 36864 bytes [04:08 11/11/2009] [02:30 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\QuickTime\qttask .exe –a— 36864 bytes [04:08 11/11/2009] [01:22 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\QuickTime\qttask .exe –a— 36864 bytes [04:08 11/11/2009] [00:44 30/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\QuickTime\qttask .exe –a— 36864 bytes [04:08 11/11/2009] [15:26 29/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\QuickTime\qttask .exe –a— 36864 bytes [04:08 11/11/2009] [04:54 29/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\QuickTime\qttask .exe –a— 36864 bytes [04:08 11/11/2009] [21:17 28/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\QuickTime\qttask .exe –a— 36864 bytes [04:08 11/11/2009] [17:25 27/04/2010] 7EE17207B0DAA9E4504830825FB7CB3B C:\Program Files\ScanSoft\OmniPageSE4\opwarese4 .exe –a— 79400 bytes [16:02 04/02/2007] [16:02 04/02/2007] F8D427DAE2984A4968E2D1CB53634784 C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer .exe –a— 3558648 bytes [00:28 26/03/2009] [00:28 26/03/2009] 35CDD72F5BE29C97E8321472B321D5B1 C:\Program Files\Windows Defender\msascui .exe –a— 866584 bytes [23:20 03/11/2006] [23:20 03/11/2006] 77C03BF23AE56B0A31AE4D5BB4B3D0AC -=End Of File=-
Hi TangJuice,

Sorry it took so long.

Let's see if we can get all at once. If there is a reboot after the OTL portion of the fix you may recieve a file not found error or some programs may not work, don't worry we will replace the files with the second part of the fix.

Please read these instruction before starting the fix. It is important to do the steps in the order posted.


First I need you to create this batch file.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad.
Do Not copy the word CODE

ren "C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl .exe" "C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe"
ren "C:\Program Files\Canon\MyPrinter\bjmyprt .exe" "C:\Program Files\Canon\MyPrinter\bjmyprt.exe"
ren "C:\Program Files\Canon\SolutionMenu\cnslmain .exe" "C:\Program Files\Canon\SolutionMenu\cnslmain.exe"
ren "C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm .exe" "C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm.exe" 
ren "C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe" "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe"
ren "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe"
ren "C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20 .exe" "C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20.exe"
ren "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth .exe" "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
ren "C:\Program Files\Common Files\Real\Update_OB\realsched .exe" "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
ren "C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate .exe" "C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate.exe"
ren "C:\Program Files\Download Manager\dlm .exe" "C:\Program Files\Download Manager\dlm.exe"
ren "C:\Program Files\Ida\idalaunch .exe" "C:\Program Files\Ida\idalaunch.exe" 
ren "C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe" "C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe"
ren "C:\Program Files\Java\jre6\bin\jusched .exe" "C:\Program Files\Java\jre6\bin\jusched.exe"
ren "C:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager .exe" "C:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager.exe"
ren "C:\Program Files\Malwarebytes' Anti-Malware\mbam .exe" "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"
ren "C:\Program Files\MSN Messenger\msnmsgr .exe" "C:\Program Files\MSN Messenger\msnmsgr.exe"
ren "C:\Program Files\ScanSoft\OmniPageSE4\opwarese4 .exe" "C:\Program Files\ScanSoft\OmniPageSE4\opwarese4.exe"
ren "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer .exe" "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
ren "C:\Program Files\Windows Defender\msascui .exe" "C:\Program Files\Windows Defender\msascui.exe"
ren "C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Update\googleupdate .exe" "C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Update\googleupdate.exe"
copy "C:\WINDOWS\stsystra.exe" "C:\WINDOWS\system32\stsystra.exe"
copy "C:\WINDOWS\stsystra.exe" "c:\documents and settings\Tang Family\stsystra.exe"
In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "myfix.bat"
  • Click save

You will have a new file on your desktop called myfix.bat with an icon that looks like this 📎bat.PNG

Do not run the batch file yet.

Next

Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\iTunes\ituneshelper .exe (Apple Inc.)
PRC - c:\Program Files\Java\jre6\bin\jusched .exe (Sun Microsystems, Inc.)
PRC - c:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager .exe (Linksys, LLC)
PRC - c:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth .exe (Cisco Systems, Inc.)
PRC - c:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc .exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\wdbtnmgr .exe (Western Digital Technologies, Inc.)
PRC - c:\Program Files\ScanSoft\OmniPageSE4\opwarese4 .exe (Nuance Communications, Inc.)
PRC - c:\Program Files\Windows Defender\msascui .exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Nero PhotoShow 4\data\Xtras\mssysmgr .exe (Nero AG / Nero Inc.)
PRC - c:\Program Files\Common Files\InstallShield\UpdateService\issch .exe (Macrovision Corporation)
PRC - c:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe (Intel Corporation)

:Reg

:Files
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe 
C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate.exe
C:\Program Files\Download Manager\dlm.exe
C:\Program Files\Ida\idalaunch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\iTunes\ituneshelper .exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\program files\QuickTime\qttask		.exe
c:\program files\QuickTime\qttask	   .exe
c:\program files\QuickTime\qttask	  .exe
c:\program files\QuickTime\qttask	 .exe
c:\program files\QuickTime\qttask	.exe
c:\program files\QuickTime\qttask   .exe
c:\program files\QuickTime\qttask  .exe
c:\program files\QuickTime\qttask .exe
C:\Program Files\ScanSoft\OmniPageSE4\opwarese4.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Update\googleupdate.exe
C:\WINDOWS\system32\wdbtnmgr.exe
C:\WINDOWS\system32\nwiz.exe
C:\WINDOWS\system32\stsystra.exe
C:\Program Files\Pando Networks\Media Booster\pmb .exe
c:\documents and settings\Tang Family\wdbtnmgr.exe
c:\documents and settings\Tang Family\nwiz.exe
c:\documents and settings\Tang Family\stsystra.exe
C:\WINDOWS\System32\nwiz.exe.delme129
C:\WINDOWS\System32\stsystra.exe.delme122
C:\WINDOWS\System32\wdbtnmgr.exe.delme132

:Commands
[start explorer]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Next

Locate myfix.bat on your desktop, double click it to run.


When it's finished, reboot your computer.

Next open windows explorer (right click the start button, click explore) and navigate to this folder C:\Qoobox . In the right hand panel locate this file ComboFix-quarantined-files.txt and post it's contents in you next reply.

Please post back with
  • OTL fix log
  • ComboFix-quarantined-files.txt
  • new OTL scan log (there will only be an OTL.txt this time)
How is the computer?

Thanks
Hey, here is the OTL log, one thing to note is that when i ran the search avast started picking up on the files as they were searched and i wasn't sure what to do so i ended up deleteing some and sending some to quarantine, hope that was ok. ========== SERVICES/DRIVERS ========== ========== OTL ========== Process explorer.exe killed successfully! No active process named ituneshelper .exe was found! No active process named jusched .exe was found! Process linksyswirelessmanager .exe killed successfully! No active process named nmctxth .exe was found! No active process named pifsvc .exe was found! No active process named wdbtnmgr .exe was found! No active process named opwarese4 .exe was found! No active process named msascui .exe was found! No active process named mssysmgr .exe was found! No active process named issch .exe was found! No active process named iaanotif .exe was found! ========== REGISTRY ========== ========== FILES ========== C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe moved successfully. C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm.exe moved successfully. C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe moved successfully. C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe moved successfully. File\Folder C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20.exe not found. C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe moved successfully. C:\Program Files\Common Files\Real\Update_OB\realsched.exe moved successfully. C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate.exe moved successfully. C:\Program Files\Download Manager\dlm.exe moved successfully. C:\Program Files\Ida\idalaunch.exe moved successfully. C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe moved successfully. C:\Program Files\iTunes\ituneshelper .exe moved successfully. C:\Program Files\Java\jre6\bin\jusched.exe moved successfully. File\Folder C:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager.exe not found. File\Folder C:\Program Files\MSN Messenger\msnmsgr.exe not found. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. C:\Program Files\ScanSoft\OmniPageSE4\opwarese4.exe moved successfully. C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe moved successfully. C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Update\googleupdate.exe moved successfully. C:\WINDOWS\system32\wdbtnmgr.exe moved successfully. C:\WINDOWS\system32\nwiz.exe moved successfully. C:\WINDOWS\system32\stsystra.exe moved successfully. C:\Program Files\Pando Networks\Media Booster\pmb .exe moved successfully. File\Folder c:\documents and settings\Tang Family\wdbtnmgr.exe not found. File\Folder c:\documents and settings\Tang Family\nwiz.exe not found. File\Folder c:\documents and settings\Tang Family\stsystra.exe not found. File\Folder C:\WINDOWS\System32\nwiz.exe.delme129 not found. C:\WINDOWS\System32\stsystra.exe.delme122 moved successfully. C:\WINDOWS\System32\wdbtnmgr.exe.delme132 moved successfully. ========== COMMANDS ========== OTL by OldTimer - Version 3.2.3.0 log created on 05012010_132015 Here is the Qoobox files Hey, here is the OTL log, one thing to note is that when i ran the search avast started picking up on the files as they were searched and i wasn't sure what to do so i ended up deleteing some and sending some to quarantine, hope that was ok. ========== SERVICES/DRIVERS ========== ========== OTL ========== Process explorer.exe killed successfully! No active process named ituneshelper .exe was found! No active process named jusched .exe was found! Process linksyswirelessmanager .exe killed successfully! No active process named nmctxth .exe was found! No active process named pifsvc .exe was found! No active process named wdbtnmgr .exe was found! No active process named opwarese4 .exe was found! No active process named msascui .exe was found! No active process named mssysmgr .exe was found! No active process named issch .exe was found! No active process named iaanotif .exe was found! ========== REGISTRY ========== ========== FILES ========== C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe moved successfully. C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm.exe moved successfully. C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe moved successfully. C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe moved successfully. File\Folder C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20.exe not found. C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe moved successfully. C:\Program Files\Common Files\Real\Update_OB\realsched.exe moved successfully. C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate.exe moved successfully. C:\Program Files\Download Manager\dlm.exe moved successfully. C:\Program Files\Ida\idalaunch.exe moved successfully. C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe moved successfully. C:\Program Files\iTunes\ituneshelper .exe moved successfully. C:\Program Files\Java\jre6\bin\jusched.exe moved successfully. File\Folder C:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager.exe not found. File\Folder C:\Program Files\MSN Messenger\msnmsgr.exe not found. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. C:\Program Files\ScanSoft\OmniPageSE4\opwarese4.exe moved successfully. C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe moved successfully. C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Update\googleupdate.exe moved successfully. C:\WINDOWS\system32\wdbtnmgr.exe moved successfully. C:\WINDOWS\system32\nwiz.exe moved successfully. C:\WINDOWS\system32\stsystra.exe moved successfully. C:\Program Files\Pando Networks\Media Booster\pmb .exe moved successfully. File\Folder c:\documents and settings\Tang Family\wdbtnmgr.exe not found. File\Folder c:\documents and settings\Tang Family\nwiz.exe not found. File\Folder c:\documents and settings\Tang Family\stsystra.exe not found. File\Folder C:\WINDOWS\System32\nwiz.exe.delme129 not found. C:\WINDOWS\System32\stsystra.exe.delme122 moved successfully. C:\WINDOWS\System32\wdbtnmgr.exe.delme132 moved successfully. ========== COMMANDS ========== OTL by OldTimer - Version 3.2.3.0 log created on 05012010_132015 Here is the Qoobox files Hey, here is the OTL log, one thing to note is that when i ran the search avast started picking up on the files as they were searched and i wasn't sure what to do so i ended up deleteing some and sending some to quarantine, hope that was ok. ========== SERVICES/DRIVERS ========== ========== OTL ========== Process explorer.exe killed successfully! No active process named ituneshelper .exe was found! No active process named jusched .exe was found! Process linksyswirelessmanager .exe killed successfully! No active process named nmctxth .exe was found! No active process named pifsvc .exe was found! No active process named wdbtnmgr .exe was found! No active process named opwarese4 .exe was found! No active process named msascui .exe was found! No active process named mssysmgr .exe was found! No active process named issch .exe was found! No active process named iaanotif .exe was found! ========== REGISTRY ========== ========== FILES ========== C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe moved successfully. C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm.exe moved successfully. C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe moved successfully. C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe moved successfully. File\Folder C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20.exe not found. C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe moved successfully. C:\Program Files\Common Files\Real\Update_OB\realsched.exe moved successfully. C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\ssbkgdupdate.exe moved successfully. C:\Program Files\Download Manager\dlm.exe moved successfully. C:\Program Files\Ida\idalaunch.exe moved successfully. C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe moved successfully. C:\Program Files\iTunes\ituneshelper .exe moved successfully. C:\Program Files\Java\jre6\bin\jusched.exe moved successfully. File\Folder C:\Program Files\Linksys\Linksys Wireless Manager\linksyswirelessmanager.exe not found. File\Folder C:\Program Files\MSN Messenger\msnmsgr.exe not found. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. c:\program files\QuickTime\qttask .exe moved successfully. C:\Program Files\ScanSoft\OmniPageSE4\opwarese4.exe moved successfully. C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe moved successfully. C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Update\googleupdate.exe moved successfully. C:\WINDOWS\system32\wdbtnmgr.exe moved successfully. C:\WINDOWS\system32\nwiz.exe moved successfully. C:\WINDOWS\system32\stsystra.exe moved successfully. C:\Program Files\Pando Networks\Media Booster\pmb .exe moved successfully. File\Folder c:\documents and settings\Tang Family\wdbtnmgr.exe not found. File\Folder c:\documents and settings\Tang Family\nwiz.exe not found. File\Folder c:\documents and settings\Tang Family\stsystra.exe not found. File\Folder C:\WINDOWS\System32\nwiz.exe.delme129 not found. C:\WINDOWS\System32\stsystra.exe.delme122 moved successfully. C:\WINDOWS\System32\wdbtnmgr.exe.delme132 moved successfully. ========== COMMANDS ========== OTL by OldTimer - Version 3.2.3.0 log created on 05012010_132015 Here is the Qoobox files 2010-04-30 02:30:22 . 2010-04-30 03:35:47 36,864 —-a-w- C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\wmpscfgs.exe.vir 2010-04-30 02:30:22 . 2010-04-30 03:35:47 36,864 —-a-w- C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\js.mui.vir 2010-04-30 01:55:03 . 2010-04-30 01:55:03 658 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-Xfire.reg.dat 2010-04-30 01:55:02 . 2010-04-30 01:55:02 1,312 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-ShockwaveFlash.reg.dat 2010-04-30 01:55:02 . 2010-04-30 01:55:02 626 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-MegauploadToolbar.reg.dat 2010-04-30 01:38:39 . 2010-04-30 01:38:39 36,864 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tang Family\rundll32 .exe.vir 2010-04-30 01:38:39 . 2010-04-30 01:38:47 36,864 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tang Family\rundll32.exe.vir 2010-04-30 01:31:49 . 2010-04-30 08:33:05 10,024 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2010-04-30 00:57:53 . 2010-04-30 08:23:40 204 —-a-w- C:\Qoobox\Quarantine\catchme.log 2010-04-27 17:24:44 . 2010-04-30 00:55:14 36,864 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tang Family\wdbtnmgr .exe.vir 2010-04-27 17:24:42 . 2010-04-30 00:55:12 36,864 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tang Family\nwiz .exe.vir 2010-04-27 17:24:38 . 2010-04-30 00:55:08 36,864 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tang Family\stsystra .exe.vir 2010-04-27 16:46:39 . 2010-04-27 16:46:39 1,201 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Steven\Start Menu\Programs\Startup\Antimalware Doctor.lnk.vir 2010-04-27 16:46:39 . 2010-04-27 16:46:39 2,215 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Steven\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk.vir 2010-04-27 16:46:39 . 2010-04-27 16:46:39 1,201 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Steven\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk.vir 2010-04-27 16:46:18 . 2010-04-30 01:22:13 36,864 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\stsystra .exe.vir 2010-04-27 16:45:52 . 2010-04-27 16:45:52 28,842 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Steven\Application Data\EA818B4DCAA69039D050124A526A961C\enemies-names.txt.vir 2010-04-27 16:45:38 . 2010-04-27 16:46:15 36,864 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Steven\Application Data\EA818B4DCAA69039D050124A526A961C\newupdate1142c.exe.vir 2007-10-20 18:57:59 . 2008-01-12 17:27:11 20,733 —-a-w- C:\Qoobox\Quarantine\C\Program Files\install.log.vir 2007-09-01 23:02:26 . 2010-04-30 01:22:22 36,864 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\wdbtnmgr .exe.vir 2005-12-10 08:06:00 . 2010-04-30 01:22:20 36,864 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\nwiz .exe.vir 2004-08-04 12:00:00 . 2008-04-14 00:12:16 15,360 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\ctfmon .exe.vir 2004-08-04 12:00:00 . 2008-04-14 00:12:32 11,776 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\regsvr32 .exe.vir 2004-08-04 12:00:00 . 2008-04-14 00:12:33 33,280 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\rundll32 .exe.vir 2004-08-04 12:00:00 . 2001-08-17 18:51:52 3,328 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\pciide.sys.vir Thanks again.
Hi TangJuice,

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    C:\Qoobox\Quarantine\C\WINDOWS\system32\nwiz .exe.vir

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

Please post back with
  • Virscan results
  • OTL.txt

How is the computer?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI