This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Redirects, Slowdowns, Rootkit, ETC

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Not sure what to do. Have ran Malware and Spybot. They both find problems but can't remove.

Here are the requested logs. Thanks A Lot!

Jaimes


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:13:07.93 on Tue 05/11/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2403 [GMT -4:00]

AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iWin Games\iWinTrusted.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Documents and Settings\Shawn\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - c:\program files\comcasttb\comcastdx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\shawn\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: &Download all 4shared files
IE: &Download using 4shared Desktop
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\shawn\applic~1\mozilla\firefox\profiles\coozz5tc.default\
FF - prefs.js: browser.search.selectedEngine - Comcast Search
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-2-5 162768]
R1 ccbd;ccbd;c:\windows\system32\ccbd.sys [2010-4-19 75264]
R2 AntiSpywareService;Comcast AntiSpyware;c:\program files\comcasttb\comcastspywarescan\ComcastAntiSpyService.exe [2009-6-17 616408]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-2-5 19024]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-2-5 40384]
R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2010-4-14 78104]
R2 k;k;c:\windows\system32\o.sys [2010-4-23 4736]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2010-2-5 10384]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-2-5 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-2-5 40384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-24 135664]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 TFilter;TFilter;\??\c:\progra~1\avanqu~1\system~1\tfilter.sys –> c:\progra~1\avanqu~1\system~1\TFilter.sys [?]

=============== Created Last 30 ================

2010-05-11 10:23 –d—– c:\docume~1\shawn\applic~1\HillStoneAnimationStudios_MBV
2010-05-10 11:11 –d—– c:\program files\My Beautiful Vacation
2010-05-09 18:49 42,717 a——- c:\windows\system32\ifarmed.html
2010-05-09 13:39 38 a——- c:\windows\system32\online_{fc88e0f3-c6de-49e6-a074-e6b09246d093}
2010-05-09 13:39 38 a——- c:\windows\system32\{fc88e0f3-c6de-49e6-a074-e6b09246d093}
2010-05-09 12:02 –d—– c:\docume~1\shawn\applic~1\SecretIslandEng
2010-05-09 09:38 –d—– c:\docume~1\shawn\applic~1\Boolat Games
2010-05-09 09:38 –d—– c:\docume~1\alluse~1\applic~1\AlawarGameBox
2010-05-09 09:31 –d—– c:\docume~1\alluse~1\applic~1\DreamFarm
2010-05-09 09:31 –d—– c:\docume~1\alluse~1\applic~1\AlawarWrapper
2010-05-09 09:31 –d—– c:\program files\Alawar
2010-05-08 15:42 –d—– c:\program files\Big Fish Games
2010-05-07 16:35 –d—– c:\program files\Cold Case Files
2010-05-07 15:33 –d—– c:\docume~1\alluse~1\applic~1\Gogii
2010-05-07 13:13 –d—– c:\program files\Escape the Lost Kingdom
2010-05-07 13:07 –d—– c:\program files\Life Quest
2010-05-05 17:05 –d—– c:\docume~1\shawn\applic~1\Lazy Turtle Games
2010-05-05 15:32 –d—– c:\docume~1\alluse~1\applic~1\Deadtime Stories
2010-05-05 15:32 –d—– c:\program files\Deadtime Stories
2010-05-05 15:28 –d—– c:\program files\Eternity
2010-05-05 15:24 –d—– c:\docume~1\shawn\applic~1\Magic3
2010-05-05 15:23 –d—– c:\program files\Magic Encyclopedia - Illusions
2010-05-05 06:38 –d—– c:\program files\common files\DivX Shared
2010-05-05 06:38 –d—– c:\program files\DivX
2010-05-05 06:37 –d—– c:\docume~1\alluse~1\applic~1\DivX
2010-05-02 21:31 –d—– c:\docume~1\alluse~1\applic~1\media center programs
2010-05-02 21:30 –d—– c:\program files\Funcom
2010-04-27 17:15 –d—– C:\Combo-Fix21040C
2010-04-27 15:41 –d—– c:\docume~1\shawn\applic~1\Aisle 5 Games, Inc
2010-04-27 11:28 –d—– C:\Combo-Fix23756C
2010-04-27 10:33 –d—– c:\docume~1\shawn\applic~1\Deadly Sin
2010-04-27 08:13 –d—– c:\program files\Dream Day Wedding Bella Italia
2010-04-27 08:10 –d—– c:\program files\Deadly Sin
2010-04-27 08:09 –d—– c:\docume~1\shawn\applic~1\GAMESHASTRA
2010-04-27 08:09 –d—– c:\docume~1\alluse~1\applic~1\GAMESHASTRA
2010-04-26 21:19 –d—– c:\docume~1\shawn\applic~1\Little Worlds Online
2010-04-26 21:09 –d—– c:\docume~1\alluse~1\applic~1\Avanquest
2010-04-26 18:04 353,592 a——- c:\windows\system32\DivXControlPanelApplet.cpl
2010-04-26 17:43 –d–r– C:\_Backup.RC
2010-04-26 17:42 –d—– C:\_Backup
2010-04-26 17:42 –d—– c:\docume~1\shawn\applic~1\Avanquest
2010-04-26 17:42 –d—– c:\program files\Avanquest update
2010-04-26 17:42 –d—– c:\program files\common files\AntiVirus
2010-04-26 17:41 –d—– c:\program files\Avanquest
2010-04-26 17:00 –d—– c:\docume~1\shawn\applic~1\RunningPillow
2010-04-26 16:53 –d—– c:\program files\iWin Games
2010-04-26 14:04 –d—– C:\Combo-Fix24871C
2010-04-26 12:05 a-dshr– C:\cmdcons
2010-04-26 12:03 256,512 a——- c:\windows\PEV.exe
2010-04-26 12:03 161,792 a——- c:\windows\SWREG.exe
2010-04-26 12:03 98,816 a——- c:\windows\sed.exe
2010-04-26 12:03 77,312 a——- c:\windows\MBR.exe
2010-04-26 12:03 –d—– C:\Combo-Fix
2010-04-26 10:45 –d—– c:\program files\Master Wu and the Glory of the Ten Powers
2010-04-25 11:19 –d—– c:\program files\Little Noir Stories
2010-04-24 14:39 –d—– c:\docume~1\shawn\applic~1\Little Noir Stories
2010-04-24 14:38 –d—– c:\program files\Little Noir Stories - The Case of the Missing Girl
2010-04-23 21:29 –d—– c:\program files\G.H.O.S.T Chronicles - Phantom of the Renaissance Faire
2010-04-23 21:27 –d—– c:\program files\Drawn - The Painted Tower
2010-04-23 21:24 –d—– c:\program files\Rangy Lil's Wild West Adventure
2010-04-23 21:18 –d—– c:\program files\Nancy Drew Dossier - Resorting to Danger
2010-04-23 21:13 –d—– c:\program files\Mystery Case Files - Return to Ravenhearst
2010-04-23 21:11 –d—– c:\program files\The Three Musketeers - Queen Anne's Diamonds
2010-04-23 19:51 –d—– C:\!KillBox
2010-04-23 19:43 –d—– c:\docume~1\alluse~1\applic~1\RegCure
2010-04-23 19:08 4,736 a——- c:\windows\system32\o.sys
2010-04-23 17:01 112 a——- c:\docume~1\alluse~1\applic~1\4vTQSmxp.dat
2010-04-23 16:09 –d—– c:\docume~1\shawn\applic~1\Ubisoft
2010-04-23 13:54 –d—– c:\docume~1\alluse~1\applic~1\GameHouse
2010-04-23 13:48 –d—– c:\program files\Trymedia
2010-04-23 13:48 31,744 a——- c:\windows\Luxury Liner Tycoon Uninstaller.exe
2010-04-23 12:59 –d—– c:\docume~1\shawn\applic~1\Freeze Tag
2010-04-22 16:50 –d—– c:\docume~1\shawn\applic~1\V-Games
2010-04-22 16:32 444,952 a——- c:\windows\system32\wrap_oal.dll
2010-04-22 16:32 109,080 a——- c:\windows\system32\OpenAL32.dll
2010-04-22 16:32 –d—– c:\program files\OpenAL
2010-04-22 15:47 –d—– c:\docume~1\shawn\applic~1\VendelGAMES
2010-04-21 20:40 –d—– c:\docume~1\shawn\applic~1\FreezeTag
2010-04-21 20:40 –d—– c:\docume~1\alluse~1\applic~1\Trymedia
2010-04-21 20:39 –d—– C:\Games
2010-04-21 20:04 –d—– c:\windows\system32\MpEngineStore
2010-04-21 19:59 –d—– C:\407b46b6ed987a9ec1
2010-04-21 19:41 15,086 a——- c:\windows\ComcastEmail.ico
2010-04-21 19:41 7,982 a——- c:\windows\ComcastSecurity.ico
2010-04-21 19:41 –d—– c:\docume~1\shawn\applic~1\CallingID
2010-04-21 19:41 –d—– c:\program files\common files\scanner
2010-04-21 19:40 –d—– c:\program files\CA
2010-04-21 19:40 –d—– c:\windows\Downloaded Installations
2010-04-21 19:40 –d—– c:\docume~1\shawn\applic~1\comcasttb
2010-04-21 19:40 –d—– c:\program files\comcasttb
2010-04-21 19:38 –d—– c:\program files\Comcast
2010-04-21 19:30 948 a——- C:\net_save.dna
2010-04-21 19:30 –d—– c:\program files\support.com
2010-04-21 19:30 –d—– c:\program files\common files\SupportSoft
2010-04-20 17:47 3,519 a——- c:\windows\system32\gzdjl
2010-04-20 13:27 –d—– c:\docume~1\alluse~1\applic~1\XLab
2010-04-19 20:01 75,264 ——– c:\windows\system32\ccbd.sys
2010-04-19 14:58 –d—– c:\docume~1\shawn\applic~1\DivoGames
2010-04-19 13:34 –d—– c:\docume~1\shawn\applic~1\she_is_a_shadow
2010-04-19 13:26 –d—– c:\windows\Youda Legend - The Golden Bird of Paradise
2010-04-16 18:22 –d—– c:\docume~1\shawn\applic~1\FlyWheelGames
2010-04-14 16:47 –d—– c:\docume~1\shawn\applic~1\Ludia
2010-04-14 16:47 –d—– c:\docume~1\alluse~1\applic~1\Ludia
2010-04-13 20:03 218,808 a——- c:\windows\system32\PnkBstrB.xtr
2010-04-13 19:53 137,256 a——- c:\windows\system32\drivers\PnkBstrK.sys
2010-04-13 19:53 218,808 a——- c:\windows\system32\PnkBstrB.exe
2010-04-13 19:53 2,434,856 a——- c:\windows\system32\pbsvc_bc2.exe
2010-04-13 19:53 75,064 a——- c:\windows\system32\PnkBstrA.exe
2010-04-13 19:52 –d—– c:\windows\system32\LogFiles
2010-04-12 20:14 –d—– c:\program files\SystemRequirementsLab
2010-04-11 19:26 –d—– c:\docume~1\shawn\applic~1\NVIDIA
2010-04-11 19:24 –d—– C:\56fef41366a71b0f673eb23d195c9b
2010-04-11 19:17 –d—– C:\923a83beb5f878f7f5e960
2010-04-11 19:15 –d—– c:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP

==================== Find3M ====================

2010-05-10 17:57 578,560 a——- c:\windows\system32\user32.dll
2010-04-29 15:39 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 15:39 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-04-24 15:54 96,512 a——- c:\windows\system32\drivers\atapi.sys
2010-03-30 21:58 44,944 a——- c:\windows\system32\drivers\PxHelp20.sys
2010-03-30 21:58 133,616 ——– c:\windows\system32\pxafs.dll
2010-03-30 21:58 125,424 ——– c:\windows\system32\pxinsi64.exe
2010-03-30 21:58 123,888 ——– c:\windows\system32\pxcpyi64.exe
2010-03-30 21:58 9,200 ——– c:\windows\system32\drivers\cdralw2k.sys
2010-03-30 21:58 9,072 ——– c:\windows\system32\drivers\cdr4_xp.sys
2010-03-16 03:37 13,670,504 a——- c:\windows\system32\nvcpl.dll
2010-03-16 03:37 278,120 a——- c:\windows\system32\nvmccs.dll
2010-03-16 03:37 154,216 a——- c:\windows\system32\nvsvc32.exe
2010-03-16 03:37 145,000 a——- c:\windows\system32\nvcolor.exe
2010-03-16 03:37 110,696 a——- c:\windows\system32\nvmctray.dll
2010-03-16 03:37 81,920 a——- c:\windows\system32\nvwddi.dll
2010-03-12 11:26 600,680 a——- c:\windows\system32\NVUNINST.EXE
2010-03-10 02:15 420,352 a——- c:\windows\system32\vbscript.dll
2010-03-08 13:59 94,208 a——- c:\windows\system32\dpl100.dll
2010-03-06 16:30 13,836 a—h— c:\windows\system32\mlfcache.dat
2010-03-03 16:41 96,264 a——- C:\GameuxInstallHelper.dll
2010-02-25 02:24 916,480 a——- c:\windows\system32\wininet.dll
2010-02-21 15:08 4,096 a——- c:\windows\d3dx.dat
2010-02-19 15:27 720,384 a——- c:\windows\system32\DivX.dll
2010-02-19 15:27 856,064 a——- c:\windows\system32\divx_xx0c.dll
2010-02-19 15:27 856,064 a——- c:\windows\system32\divx_xx07.dll
2010-02-19 15:27 847,872 a——- c:\windows\system32\divx_xx0a.dll
2010-02-19 15:27 843,776 a——- c:\windows\system32\divx_xx16.dll
2010-02-19 15:27 839,680 a——- c:\windows\system32\divx_xx11.dll
2010-02-16 10:08 2,146,304 a——- c:\windows\system32\ntoskrnl.exe
2010-02-16 09:25 2,024,448 a——- c:\windows\system32\ntkrnlpa.exe
2010-02-15 10:17 77,423 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-02-12 18:42 411,368 a——- c:\windows\system32\deploytk.dll
2010-02-12 00:33 100,864 a——- c:\windows\system32\6to4svc.dll

============= FINISH: 11:13:28.67 ===============





GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-11 11:23:38
Windows 5.1.2600 Service Pack 3
Running: k8frfps2.exe; Driver: C:\DOCUME~1\Shawn\LOCALS~1\Temp\uxtyiaog.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB43F050A]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB43F032E]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB43F0468]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- EOF - GMER 1.0.15 —-

Attachments:

[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Below is the ComboFix log results.

The computer is running very slow at times, as if it is infected, but I cannot find anything using Malwarebytes or Spybot. I was using Avast, but noticed that the icon no longer appeared in the system tray but that the program was running when I checked my processes. I tried stopping the process but was given the "Restricted" window, so I uninstalled it for the time being so that I could run ComboFix. (Wouldn't let me run it with Avast running.)

Hope you can find something I cannot! Appreciate all the help.




ComboFix 10-05-10.05 - Shawn 05/11/2010 18:28:11.6.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2679 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((( Files Created from 2010-04-11 to 2010-05-11 )))))))))))))))))))))))))))))))
.

2010-05-11 20:18 . 2010-05-11 20:18 ——– d—–w- c:\program files\Yahoo! Games
2010-05-11 15:09 . 2010-05-11 15:09 ——– d—–w- c:\program files\ERUNT
2010-05-11 14:23 . 2010-05-11 14:23 ——– d—–w- c:\documents and settings\Shawn\Application Data\HillStoneAnimationStudios_MBV
2010-05-10 22:19 . 2010-05-10 22:19 ——– d—–w- c:\documents and settings\HelpAssistant\UserData
2010-05-10 22:19 . 2010-05-10 22:19 ——– d—–w- c:\documents and settings\HelpAssistant\Saved Games
2010-05-10 22:12 . 2010-05-11 22:19 ——– d—–w- c:\documents and settings\HelpAssistant
2010-05-10 15:11 . 2010-05-10 15:11 ——– d—–w- c:\program files\My Beautiful Vacation
2010-05-09 17:04 . 2010-05-09 17:11 ——– d—–w- c:\documents and settings\Shawn\Local Settings\Application Data\bqdqkhmoa
2010-05-09 16:02 . 2010-05-09 16:02 ——– d—–w- c:\documents and settings\Shawn\Application Data\SecretIslandEng
2010-05-09 13:38 . 2010-05-09 13:38 ——– d—–w- c:\documents and settings\Shawn\Application Data\Boolat Games
2010-05-09 13:38 . 2010-05-09 16:01 ——– d—–w- c:\documents and settings\All Users\Application Data\AlawarGameBox
2010-05-09 13:31 . 2010-05-09 13:32 ——– d—–w- c:\documents and settings\All Users\Application Data\DreamFarm
2010-05-09 13:31 . 2010-05-09 13:38 ——– d—–w- c:\documents and settings\All Users\Application Data\AlawarWrapper
2010-05-09 13:31 . 2010-05-09 15:59 ——– d—–w- c:\program files\Alawar
2010-05-08 19:42 . 2010-05-09 22:09 ——– d—–w- c:\program files\Big Fish Games
2010-05-07 20:35 . 2010-05-07 20:36 ——– d—–w- c:\program files\Cold Case Files
2010-05-07 19:33 . 2010-05-07 19:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Gogii
2010-05-07 17:13 . 2010-05-07 19:33 ——– d—–w- c:\program files\Escape the Lost Kingdom
2010-05-07 17:07 . 2010-05-08 17:51 ——– d—–w- c:\program files\Life Quest
2010-05-07 17:06 . 2010-05-07 17:46 ——– d—–w- c:\documents and settings\Shawn\Local Settings\Application Data\Deadtime Stories
2010-05-05 21:05 . 2010-05-05 21:05 ——– d—–w- c:\documents and settings\Shawn\Application Data\Lazy Turtle Games
2010-05-05 19:32 . 2010-05-11 20:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Deadtime Stories
2010-05-05 19:32 . 2010-05-08 18:43 ——– d—–w- c:\program files\Deadtime Stories
2010-05-05 19:28 . 2010-05-05 19:28 ——– d—–w- c:\program files\Eternity
2010-05-05 19:24 . 2010-05-06 17:34 ——– d—–w- c:\documents and settings\Shawn\Application Data\Magic3
2010-05-05 19:23 . 2010-05-05 19:24 ——– d—–w- c:\program files\Magic Encyclopedia - Illusions
2010-05-05 10:38 . 2010-05-05 10:38 54073 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-05 10:38 . 2010-05-05 10:38 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-05-05 10:38 . 2010-05-05 10:38 56969 —-a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-05-05 10:38 . 2010-05-05 10:39 ——– d—–w- c:\program files\DivX
2010-05-05 10:37 . 2010-05-05 10:37 144696 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-05 10:37 . 2010-05-05 10:39 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-05-05 00:53 . 2010-05-05 00:53 1925088 —-a-w- c:\documents and settings\Shawn\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2010-05-03 01:31 . 2010-05-03 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\media center programs
2010-05-03 01:30 . 2010-05-03 01:30 ——– d—–w- c:\program files\Funcom
2010-04-27 21:15 . 2010-04-27 21:21 ——– d—–w- C:\Combo-Fix21040C
2010-04-27 19:41 . 2010-04-27 19:41 ——– d—–w- c:\documents and settings\Shawn\Application Data\Aisle 5 Games, Inc
2010-04-27 15:28 . 2010-04-27 15:35 ——– d—–w- C:\Combo-Fix23756C
2010-04-27 14:33 . 2010-04-27 14:44 ——– d—–w- c:\documents and settings\Shawn\Application Data\Deadly Sin
2010-04-27 12:13 . 2010-04-27 12:13 ——– d—–w- c:\program files\Dream Day Wedding Bella Italia
2010-04-27 12:10 . 2010-04-27 14:33 ——– d—–w- c:\program files\Deadly Sin
2010-04-27 12:09 . 2010-04-27 12:09 ——– d—–w- c:\documents and settings\Shawn\Application Data\GAMESHASTRA
2010-04-27 12:09 . 2010-04-27 12:09 ——– d—–w- c:\documents and settings\All Users\Application Data\GAMESHASTRA
2010-04-27 01:19 . 2010-04-27 01:19 ——– d—–w- c:\documents and settings\Shawn\Application Data\Little Worlds Online
2010-04-27 01:09 . 2010-04-27 16:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Avanquest
2010-04-26 21:43 . 2010-04-26 21:43 ——– d—–r- C:\_Backup.RC
2010-04-26 21:42 . 2010-04-27 21:26 ——– d—–w- C:\_Backup
2010-04-26 21:42 . 2010-04-26 21:42 ——– d—–w- c:\documents and settings\Shawn\Application Data\Avanquest
2010-04-26 21:42 . 2010-04-27 01:09 ——– d—–w- c:\documents and settings\All Users\Application Data\BVRP Software
2010-04-26 21:42 . 2010-04-26 21:42 ——– d—–w- c:\program files\Avanquest update
2010-04-26 21:42 . 2010-04-26 21:42 ——– d—–w- c:\documents and settings\Shawn\Application Data\InstallShield
2010-04-26 21:42 . 2010-04-27 21:26 ——– d—–w- c:\program files\Common Files\AntiVirus
2010-04-26 21:41 . 2010-04-26 21:41 ——– d—–w- c:\program files\Avanquest
2010-04-26 21:00 . 2010-04-26 21:00 ——– d—–w- c:\documents and settings\Shawn\Application Data\RunningPillow
2010-04-26 20:53 . 2010-04-27 15:33 ——– d—–w- c:\program files\iWin Games
2010-04-26 18:04 . 2010-04-26 18:08 ——– d—–w- C:\Combo-Fix24871C
2010-04-26 16:03 . 2010-04-26 16:21 ——– d—–w- C:\Combo-Fix
2010-04-26 14:45 . 2010-04-26 14:46 ——– d—–w- c:\program files\Master Wu and the Glory of the Ten Powers
2010-04-25 15:19 . 2010-04-25 15:21 ——– d—–w- c:\program files\Little Noir Stories
2010-04-25 03:04 . 2010-04-25 03:04 ——– d-sh–w- c:\documents and settings\NetworkService\PrivacIE
2010-04-25 03:04 . 2010-04-25 03:04 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Yahoo
2010-04-25 03:04 . 2010-04-25 03:04 ——– d—–w- c:\documents and settings\NetworkService\Application Data\comcasttb
2010-04-25 03:04 . 2010-04-25 03:04 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Yahoo!
2010-04-24 20:24 . 2010-04-25 03:04 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-04-24 20:24 . 2010-04-24 20:24 ——– d—–w- c:\documents and settings\Shawn\Local Settings\Application Data\Temp
2010-04-24 20:19 . 2010-04-24 20:19 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-04-24 18:39 . 2010-04-24 18:39 ——– d—–w- c:\documents and settings\Shawn\Application Data\Little Noir Stories
2010-04-24 18:38 . 2010-04-24 18:39 ——– d—–w- c:\program files\Little Noir Stories - The Case of the Missing Girl
2010-04-24 01:29 . 2010-04-24 01:30 ——– d—–w- c:\program files\G.H.O.S.T Chronicles - Phantom of the Renaissance Faire
2010-04-24 01:27 . 2010-04-24 01:28 ——– d—–w- c:\program files\Drawn - The Painted Tower
2010-04-24 01:24 . 2010-04-24 01:25 ——– d—–w- c:\program files\Rangy Lil's Wild West Adventure
2010-04-24 01:18 . 2010-04-24 01:24 ——– d—–w- c:\program files\Nancy Drew Dossier - Resorting to Danger
2010-04-24 01:13 . 2010-04-24 01:13 ——– d—–w- c:\program files\Mystery Case Files - Return to Ravenhearst
2010-04-24 01:11 . 2010-04-24 01:11 ——– d—–w- c:\program files\The Three Musketeers - Queen Anne's Diamonds
2010-04-23 23:51 . 2010-04-23 23:51 ——– d—–w- C:\!KillBox
2010-04-23 23:43 . 2010-04-24 00:05 ——– d—–w- c:\documents and settings\All Users\Application Data\RegCure
2010-04-23 23:08 . 2010-04-23 23:08 4736 —-a-w- c:\windows\system32\o.sys
2010-04-23 20:09 . 2010-04-23 20:09 ——– d—–w- c:\documents and settings\Shawn\Application Data\Ubisoft
2010-04-23 17:54 . 2010-04-23 17:54 ——– d—–w- c:\documents and settings\All Users\Application Data\GameHouse
2010-04-23 17:48 . 2010-04-23 17:48 ——– d—–w- c:\program files\Trymedia
2010-04-23 17:48 . 2004-07-08 17:19 31744 —-a-w- c:\windows\Luxury Liner Tycoon Uninstaller.exe
2010-04-23 16:59 . 2010-04-23 16:59 ——– d—–w- c:\documents and settings\Shawn\Application Data\Freeze Tag
2010-04-22 20:50 . 2010-04-22 20:50 ——– d—–w- c:\documents and settings\Shawn\Application Data\V-Games
2010-04-22 20:32 . 2010-04-22 20:32 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-04-22 20:32 . 2010-04-22 20:32 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-04-22 20:32 . 2010-04-22 20:32 ——– d—–w- c:\program files\OpenAL
2010-04-22 19:47 . 2010-04-22 19:47 ——– d—–w- c:\documents and settings\Shawn\Application Data\VendelGAMES
2010-04-22 00:40 . 2010-04-22 17:29 ——– d—–w- c:\documents and settings\Shawn\Application Data\FreezeTag
2010-04-22 00:40 . 2010-04-22 00:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Trymedia
2010-04-22 00:39 . 2010-04-24 00:10 ——– d—–w- C:\Games
2010-04-22 00:04 . 2010-04-22 01:48 ——– d—–w- c:\windows\system32\MpEngineStore
2010-04-21 23:59 . 2010-04-22 00:00 ——– d—–w- C:\407b46b6ed987a9ec1
2010-04-21 23:49 . 2009-05-26 22:08 554456 —-a-w- c:\documents and settings\Shawn\Application Data\Mozilla\Firefox\Profiles\coozz5tc.default\extensions\{4E77EDAD-9566-4089-88D1-C81498CEE770}\dtband.dll
2010-04-21 23:49 . 2009-05-26 22:08 554456 —-a-w- c:\documents and settings\Shawn\Application Data\Mozilla\Firefox\Profiles\coozz5tc.default\extensions\{4E77EDAD-9566-4089-88D1-C81498CEE770}\comcasttb.dll
2010-04-21 23:46 . 2010-04-24 20:21 ——– d—–w- c:\documents and settings\Shawn\Local Settings\Application Data\Google
2010-04-21 23:41 . 2010-05-06 14:51 ——– d—–w- c:\documents and settings\Shawn\Application Data\CallingID
2010-04-21 23:41 . 2010-04-21 23:41 ——– d—–w- c:\program files\Common Files\scanner
2010-04-21 23:40 . 2010-04-21 23:40 ——– d—–w- c:\program files\CA
2010-04-21 23:40 . 2010-04-21 23:40 ——– d—–w- c:\windows\Downloaded Installations
2010-04-21 23:40 . 2010-04-21 23:48 ——– d—–w- c:\documents and settings\Shawn\Application Data\comcasttb
2010-04-21 23:40 . 2010-04-21 23:41 ——– d—–w- c:\program files\comcasttb
2010-04-21 23:39 . 2010-04-21 23:39 ——– d—–w- c:\documents and settings\All Users\Application Data\SupportSoft
2010-04-21 23:38 . 2010-04-21 23:38 ——– d—–w- c:\program files\Comcast
2010-04-21 23:30 . 2010-04-21 23:30 ——– d—–w- c:\program files\support.com
2010-04-21 23:30 . 2010-04-21 23:30 ——– d—–w- c:\documents and settings\Shawn\Local Settings\Application Data\SupportSoft
2010-04-21 23:30 . 2010-04-21 23:38 ——– d—–w- c:\program files\Common Files\SupportSoft
2010-04-20 17:27 . 2010-04-20 17:27 ——– d—–w- c:\documents and settings\All Users\Application Data\XLab
2010-04-20 00:01 . 2010-04-20 00:01 75264 ——w- c:\windows\system32\ccbd.sys
2010-04-19 18:58 . 2010-04-19 18:58 ——– d—–w- c:\documents and settings\Shawn\Application Data\DivoGames
2010-04-19 17:34 . 2010-04-19 17:34 ——– d—–w- c:\documents and settings\Shawn\Application Data\she_is_a_shadow
2010-04-19 17:26 . 2010-04-19 17:26 ——– d—–w- c:\windows\Youda Legend - The Golden Bird of Paradise
2010-04-17 00:04 . 2010-04-17 00:04 ——– d—–w- c:\documents and settings\Shawn\Application Data\Notepad++
2010-04-17 00:04 . 2010-04-17 00:04 ——– d—–w- c:\program files\Notepad++
2010-04-16 22:22 . 2010-04-16 22:22 ——– d—–w- c:\documents and settings\Shawn\Application Data\FlyWheelGames
2010-04-14 20:47 . 2010-04-14 20:47 ——– d—–w- c:\documents and settings\Shawn\Application Data\Ludia
2010-04-14 20:47 . 2010-04-14 20:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Ludia
2010-04-14 00:03 . 2010-04-14 00:03 ——– d—–w- c:\documents and settings\Shawn\Local Settings\Application Data\PunkBuster
2010-04-13 23:53 . 2010-05-11 01:37 137256 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-04-13 23:53 . 2010-05-11 01:44 218808 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-04-13 23:53 . 2010-04-13 23:53 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-04-13 23:53 . 2010-04-13 23:53 2434856 —-a-w- c:\windows\system32\pbsvc_bc2.exe
2010-04-13 23:52 . 2010-04-13 23:52 ——– d—–w- c:\windows\system32\LogFiles
2010-04-13 23:38 . 2010-04-13 23:38 ——– d—–w- c:\program files\Electronic Arts
2010-04-13 00:14 . 2010-04-13 00:14 ——– d—–w- c:\program files\SystemRequirementsLab
2010-04-13 00:14 . 2010-04-13 00:14 290816 —-a-w- c:\documents and settings\Shawn\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-11 22:03 . 2010-02-21 06:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-11 16:52 . 2010-02-13 16:13 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-10 21:57 . 2004-08-04 10:00 578560 —-a-w- c:\windows\system32\user32.dll
2010-05-10 21:38 . 2010-02-16 01:09 ——– d—–w- c:\documents and settings\Shawn\Application Data\LimeWire
2010-05-10 15:07 . 2010-02-26 00:42 ——– d—–w- c:\program files\Games
2010-05-09 17:08 . 2010-02-16 01:08 ——– d—–w- c:\program files\LimeWire
2010-05-07 20:38 . 2010-02-13 17:28 ——– d—–w- c:\documents and settings\Shawn\Application Data\Big Fish Games
2010-05-05 10:42 . 2010-05-05 10:39 ——– d—–w- c:\documents and settings\Shawn\Application Data\DivX
2010-04-29 19:39 . 2010-02-21 06:47 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-02-21 06:47 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-27 21:26 . 2010-02-06 00:11 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-04-27 21:24 . 2010-04-23 21:01 112 —-a-w- c:\documents and settings\All Users\Application Data\4vTQSmxp.dat
2010-04-27 18:56 . 2010-03-29 05:02 ——– d—–w- c:\program files\SmartDraw 2010
2010-04-27 12:06 . 2010-02-13 16:06 ——– d—–w- c:\program files\bfgclient
2010-04-27 01:22 . 2010-03-04 15:28 ——– d—–w- c:\program files\iWin.com
2010-04-26 21:42 . 2010-02-06 00:32 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-25 16:35 . 2010-02-28 18:34 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-24 23:46 . 2010-03-21 03:53 ——– d—–w- c:\program files\Steam
2010-04-24 20:19 . 2010-03-31 02:01 ——– d—–w- c:\program files\Google
2010-04-24 19:54 . 2004-08-04 10:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-04-24 11:50 . 2010-04-06 23:44 ——– d—–w- c:\program files\Turbine
2010-04-24 00:12 . 2010-03-31 01:59 ——– d—–w- c:\program files\RealArcade
2010-04-22 17:05 . 2010-04-10 18:00 ——– d—–w- c:\program files\iWin.com Games
2010-04-21 23:47 . 2010-03-13 23:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-04-20 15:50 . 2010-02-14 20:56 ——– d—–w- c:\documents and settings\Shawn\Application Data\Merscom
2010-04-20 15:50 . 2010-02-14 20:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Merscom
2010-04-19 16:43 . 2010-02-27 15:21 ——– d—–w- c:\documents and settings\Shawn\Application Data\YoudaGames
2010-04-16 20:54 . 2010-03-20 22:35 ——– d—–w- c:\program files\Common Files\Motive
2010-04-14 15:35 . 2010-02-13 16:28 ——– d—–w- c:\documents and settings\Shawn\Application Data\PlayFirst
2010-04-14 15:35 . 2010-02-13 16:28 ——– d—–w- c:\documents and settings\All Users\Application Data\PlayFirst
2010-04-13 00:11 . 2010-02-05 00:58 13104 —-a-w- c:\documents and settings\Shawn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-13 00:11 . 2010-02-12 00:29 ——– d—–w- c:\program files\Cryptic Studios
2010-04-11 23:24 . 2010-03-31 07:15 62304 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-04-10 21:58 . 2010-04-10 21:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Sandlot Games
2010-04-10 18:04 . 2010-04-10 18:03 ——– d—–w- c:\documents and settings\Shawn\Application Data\Mysteryville2
2010-04-10 12:55 . 2010-04-10 12:55 0 —-a-w- c:\windows\nsreg.dat
2010-04-09 15:52 . 2010-04-09 15:51 ——– d—–w- c:\program files\Royal Envoy Collectors Edition
2010-04-09 06:24 . 2010-04-09 06:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-08 19:09 . 2010-02-06 01:02 ——– d—–w- c:\program files\NVIDIA Corporation
2010-04-07 15:36 . 2010-04-07 15:36 ——– d—–w- c:\documents and settings\Shawn\Application Data\Alawar Entertainment
2010-04-07 15:36 . 2010-04-07 15:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Alawar Entertainment
2010-04-07 14:32 . 2010-04-07 14:32 ——– d—–w- c:\documents and settings\Shawn\Application Data\BigFish Janes Realty2
2010-04-07 14:21 . 2010-04-07 14:20 ——– d—–w- c:\program files\Royal Envoy Collector's Edition
2010-04-06 23:56 . 2010-04-06 23:56 128 —-a-w- c:\documents and settings\Shawn\Local Settings\Application Data\fusioncache.dat
2010-04-06 21:57 . 2010-04-06 21:57 ——– d—–w- c:\program files\KingsIsle Entertainment
2010-04-05 06:56 . 2010-04-05 06:56 ——– d—–w- c:\documents and settings\Shawn\Application Data\Trick or Travel
2010-04-04 02:04 . 2010-02-27 03:37 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2010-04-03 17:23 . 2010-04-03 17:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Fenomen Games
2010-04-03 14:26 . 2010-03-06 06:22 ——– d—–w- c:\program files\World of Warcraft
2010-04-02 14:31 . 2010-03-25 14:38 ——– d—–w- c:\documents and settings\All Users\Application Data\incredible express
2010-04-01 19:05 . 2010-04-01 19:05 ——– d—–w- c:\documents and settings\Shawn\Application Data\Settlement. Colossus
2010-04-01 16:25 . 2010-04-01 16:25 ——– d—–w- c:\documents and settings\Shawn\Application Data\dingogames
2010-04-01 16:25 . 2010-04-01 16:25 ——– d—–w- c:\documents and settings\All Users\Application Data\dingogames
2010-04-01 15:22 . 2010-02-25 23:02 ——– d—–w- c:\documents and settings\Shawn\Application Data\Artogon
2010-03-31 21:23 . 2010-03-13 22:02 120 —-a-w- c:\windows\Umivofihutafuzac.dat
2010-03-31 13:38 . 2010-03-31 02:01 ——– d—–w- c:\documents and settings\Shawn\Application Data\HdO Adventure
2010-03-31 10:04 . 2010-03-13 22:02 0 —-a-w- c:\windows\Wvezuyic.bin
2010-03-31 01:58 . 2010-05-05 10:39 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2010-03-31 01:58 . 2010-05-05 10:39 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2010-03-31 01:58 . 2010-05-05 10:39 44944 —-a-w- c:\windows\system32\drivers\PxHelp20.sys
2010-03-31 01:58 . 2010-05-05 10:39 123888 ——w- c:\windows\system32\pxcpyi64.exe
2010-03-31 01:58 . 2010-05-05 10:39 133616 ——w- c:\windows\system32\pxafs.dll
2010-03-31 01:58 . 2010-05-05 10:39 125424 ——w- c:\windows\system32\pxinsi64.exe
2010-03-30 21:36 . 2010-03-30 21:36 ——– d—–w- c:\documents and settings\Shawn\Application Data\GOA
2010-03-30 21:36 . 2010-03-30 21:36 ——– d—–w- c:\documents and settings\All Users\Application Data\GOA
2010-03-30 00:03 . 2010-03-30 00:03 ——– d—–w- c:\documents and settings\Shawn\Application Data\Sony Online Entertainment
2010-03-30 00:03 . 2010-03-30 00:03 241977 —-a-w- c:\documents and settings\Shawn\Application Data\Sony Online Entertainment\npsoeact.dll
2010-03-30 00:03 . 2010-03-30 00:03 ——– d—–w- c:\program files\Sony Online Entertainment
2010-03-29 17:47 . 2010-03-29 17:47 ——– d—–w- c:\documents and settings\Shawn\Application Data\GameMill Entertainment
2010-03-29 05:03 . 2010-03-29 05:03 ——– d—–w- c:\documents and settings\Shawn\Application Data\SmartDraw
2010-03-29 02:41 . 2010-03-29 02:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Particles
2010-03-29 02:41 . 2010-03-29 02:41 ——– d—–w- c:\documents and settings\Shawn\Application Data\Specialbit
2010-03-27 03:15 . 2010-03-12 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\1bcf3
2010-03-26 16:45 . 2010-03-26 16:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Happyville__
2010-03-25 16:49 . 2010-03-25 16:49 ——– d—–w- c:\documents and settings\Shawn\Application Data\Meridian93
2010-03-25 16:05 . 2010-03-25 16:05 ——– d—–w- c:\documents and settings\Shawn\Application Data\Top Evidence
2010-03-25 16:05 . 2010-03-25 16:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Top Evidence
2010-03-24 15:27 . 2010-03-24 15:27 ——– d—–w- c:\documents and settings\Shawn\Application Data\Gameinvest
2010-03-24 06:47 . 2010-03-24 06:47 ——– d—–w- c:\documents and settings\Shawn\Application Data\AzuazGames
2010-03-24 02:13 . 2010-03-24 02:12 ——– d—–w- c:\documents and settings\Shawn\Application Data\TitanicMystery
2010-03-24 01:12 . 2010-03-24 01:12 ——– d—–w- c:\documents and settings\Shawn\Application Data\LegacyInteractive
2010-03-22 23:03 . 2010-03-22 23:03 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE
2010-03-22 18:24 . 2010-03-22 18:24 ——– d—–w- c:\documents and settings\Shawn\Application Data\Jetdogs Studios
2010-03-21 14:11 . 2010-03-21 14:11 ——– d—–w- c:\documents and settings\All Users\Application Data\WOP
2010-03-21 14:09 . 2010-03-21 14:09 ——– d—–w- c:\documents and settings\Shawn\Application Data\The Creative Assembly
2010-03-21 04:59 . 2010-02-19 02:39 ——– d—–w- c:\program files\Fallen Earth
2010-03-20 22:35 . 2010-03-20 22:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Motive
2010-03-17 15:14 . 2010-03-17 15:14 3085800 —-a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\Unpack\bfgsetup_s1_l1.exe
2010-03-17 15:14 . 2010-02-13 16:05 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2010-03-16 07:37 . 2010-03-16 07:37 278120 —-a-w- c:\windows\system32\nvmccs.dll
2010-03-16 07:37 . 2010-03-16 07:37 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2010-03-16 07:37 . 2010-03-16 07:37 145000 —-a-w- c:\windows\system32\nvcolor.exe
2010-03-16 07:37 . 2010-03-16 07:37 13670504 —-a-w- c:\windows\system32\nvcpl.dll
2010-03-16 07:37 . 2010-03-16 07:37 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-03-16 07:37 . 2010-03-16 07:37 81920 —-a-w- c:\windows\system32\nvwddi.dll
2010-03-15 23:52 . 2010-03-15 23:52 ——– d—–w- c:\documents and settings\Shawn\Application Data\Nevosoft
2010-03-14 23:17 . 2010-03-13 21:58 ——– d—–w- c:\documents and settings\All Users\Application Data\false
2010-03-14 14:23 . 2010-03-13 23:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-03-14 14:23 . 2010-03-13 23:10 ——– d—–w- c:\program files\Yahoo!
2010-03-14 05:53 . 2010-02-06 00:32 ——– d—–w- c:\program files\Realtek
.
c:\program files\Comcast\Desktop Doctor\bin\sprtcmd .exe
c:\program files\comcasttb\ComcastSpywareScan\ComcastAntispy .exe
c:\program files\Common Files\Java\Java Update\jusched .exe
c:\program files\Pando Networks\Media Booster\PMB .exe

((((((((((((((((((((((((((((( SnapShot@2010-04-26_16.19.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-11 22:27 . 2010-05-11 22:27 16384 c:\windows\Temp\Perflib_Perfdata_73c.dat
+ 2010-05-05 10:39 . 2010-03-31 01:58 68080 c:\windows\system32\pxinsa64.exe
+ 2010-05-05 10:39 . 2010-03-31 01:58 72176 c:\windows\system32\pxhpinst.exe
+ 2010-05-05 10:39 . 2010-03-31 01:58 68080 c:\windows\system32\pxcpya64.exe
+ 2010-02-16 01:08 . 2010-05-05 00:54 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2010-03-08 17:59 . 2010-03-08 17:59 94208 c:\windows\system32\dpl100.dll
+ 2010-02-05 00:55 . 2010-05-09 17:04 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-02-05 00:55 . 2010-04-25 20:40 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-02-05 00:55 . 2010-05-09 17:04 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-02-05 00:55 . 2010-04-25 20:40 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-07 05:19 . 2007-11-07 05:19 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
- 2007-11-07 10:19 . 2007-11-07 10:19 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
- 2007-11-07 10:19 . 2007-11-07 10:19 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2007-11-07 05:19 . 2007-11-07 05:19 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2007-11-07 00:23 . 2007-11-07 00:23 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
- 2007-11-07 05:23 . 2007-11-07 05:23 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2010-05-05 10:39 . 2010-03-31 01:58 100848 c:\windows\system32\vxblock.dll
+ 2010-02-04 23:07 . 2010-02-04 23:07 295424 c:\windows\system32\termsrv32.dll
+ 2010-05-05 10:39 . 2010-03-31 01:58 440816 c:\windows\system32\pxwave.dll
+ 2010-05-05 10:39 . 2010-03-31 01:58 219632 c:\windows\system32\pxmas.dll
+ 2010-05-05 10:39 . 2010-03-31 01:58 559600 c:\windows\system32\pxdrv.dll
+ 2010-05-05 10:39 . 2010-03-31 01:58 678384 c:\windows\system32\px.dll
+ 2010-01-27 01:07 . 2010-01-27 01:07 256280 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2010-02-06 00:33 . 2008-04-13 12:39 142592 c:\windows\system32\drivers\aec.sys
- 2010-02-06 00:33 . 2008-04-13 16:39 142592 c:\windows\system32\drivers\aec.sys
+ 2004-08-04 10:00 . 2010-05-10 21:57 578560 c:\windows\system32\dllcache\user32.dll
+ 2004-08-04 10:00 . 2008-04-13 19:20 182656 c:\windows\system32\dllcache\ndis.sys
+ 2010-02-06 00:33 . 2008-04-13 12:39 142592 c:\windows\system32\dllcache\aec.sys
+ 2010-02-19 19:27 . 2010-02-19 19:27 843776 c:\windows\system32\divx_xx16.dll
+ 2010-02-19 19:27 . 2010-02-19 19:27 839680 c:\windows\system32\divx_xx11.dll
+ 2010-02-19 19:27 . 2010-02-19 19:27 856064 c:\windows\system32\divx_xx0c.dll
+ 2010-02-19 19:27 . 2010-02-19 19:27 847872 c:\windows\system32\divx_xx0a.dll
+ 2010-02-19 19:27 . 2010-02-19 19:27 856064 c:\windows\system32\divx_xx07.dll
+ 2010-02-19 19:27 . 2010-02-19 19:27 720384 c:\windows\system32\DivX.dll
+ 2010-05-11 22:20 . 2010-05-11 22:20 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2010-05-05 10:39 . 2010-05-05 10:39 169472 c:\windows\Installer\e4f6c32.msi
+ 2010-05-11 15:35 . 2010-05-11 15:35 253952 c:\windows\ERDNT\AutoBackup\5-11-2010\Users\00000002\UsrClass.dat
+ 2010-05-11 15:35 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\5-11-2010\ERDNT.EXE
+ 2010-05-11 15:10 . 2010-05-11 15:10 253952 c:\windows\ERDNT\5-11-2010\Users\00000002\UsrClass.dat
+ 2010-05-11 15:10 . 2005-10-20 16:02 163328 c:\windows\ERDNT\5-11-2010\ERDNT.EXE
+ 2010-05-05 10:39 . 2010-03-31 01:58 2083312 c:\windows\system32\pxsfs.dll
+ 2010-01-27 01:07 . 2010-01-27 01:07 3884312 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2010-05-11 15:35 . 2010-05-11 15:35 6488064 c:\windows\ERDNT\AutoBackup\5-11-2010\Users\00000001\NTUSER.DAT
+ 2010-05-11 15:10 . 2010-05-11 15:10 6488064 c:\windows\ERDNT\5-11-2010\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-03-16 13670504]

c:\documents and settings\Shawn\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-5 813584]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 20:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^Shawn^Start Menu^Programs^Startup^CurseClientStartup.ccip]
backup=c:\windows\pss\CurseClientStartup.ccipStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Shawn^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-06 00:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-03-21 03:53 1217872 —-a-w- c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iWinTrusted"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\gPotato.com\\Allods Online\\bin\\Launcher1.exe"=
"c:\\gPotato.com\\Allods Online\\bin\\Launcher2.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\wings of prey demo\\launcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\napoleon total war demo\\Napoleon.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"5668:TCP"= 5668:TCP:Services
"9836:TCP"= 9836:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"8917:TCP"= 8917:TCP:Services
"8918:TCP"= 8918:TCP:Services

R1 ccbd;ccbd;c:\windows\system32\ccbd.sys [4/19/2010 8:01 PM 75264]
R2 AntiSpywareService;Comcast AntiSpyware;c:\program files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [6/17/2009 1:49 PM 616408]
R2 k;k;c:\windows\system32\o.sys [4/23/2010 7:08 PM 4736]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2/5/2010 9:35 PM 10384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/24/2010 4:19 PM 135664]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 TFilter;TFilter;\??\c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [?]
S4 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [4/14/2010 10:16 AM 78104]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 12:32 128512 —-a-w- c:\windows\system32\advpack.dll

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EC5738BF-72C3-416F-9D09-24A21222BE58}]
fycwdn11.dll [N/A]
.
Contents of the 'Scheduled Tasks' folder

2010-05-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]

2010-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-24 20:19]

2010-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-24 20:19]

2010-05-11 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2010-03-29 16:21]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: &Download all 4shared files
IE: &Download using 4shared Desktop
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\Shawn\Application Data\Mozilla\Firefox\Profiles\coozz5tc.default\
FF - prefs.js: browser.search.selectedEngine - Comcast Search
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-11 18:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,96,ba,4a,7a,39,b9,93,46,bc,b7,b5,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,96,ba,4a,7a,39,b9,93,46,bc,b7,b5,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(716)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\CA\PPRT\bin\CACheck.dll
c:\program files\CA\PPRT\bin\CAHook.dll
c:\program files\CA\PPRT\bin\CAServer.dll
.
Completion time: 2010-05-11 18:35:20
ComboFix-quarantined-files.txt 2010-05-11 22:35
ComboFix2.txt 2010-05-10 22:19
ComboFix3.txt 2010-04-27 21:21
ComboFix4.txt 2010-04-27 15:35
ComboFix5.txt 2010-05-11 22:24

Pre-Run: 94,771,851,264 bytes free
Post-Run: 94,733,152,256 bytes free

- - End Of File - - 00FE72EE20CDB7C9210CA71400C6F5CC
Yes, you're infected

Please download HelpAsst_mebroot_fix.exe and save it to your desktop.
Close out all other open programs and windows.
Double click the file to run it and follow any prompts.
If the tool detects an mbr infection, please allow it to run mbr -f and shutdown your computer.
Upon restarting, please wait about 5 minutes, click Start>Run and type the following bolded command, then hit Enter.

helpasst -mbrt

Make sure you leave a space between helpasst and -mbrt !
When it completes, a log will open.
Please post the contents of that log.


*In the event the tool does not detect an mbr infection and completes, click Start>Run and type the following bolded command, then hit Enter.

mbr -f

Now, please do the Start>Run>mbr -f command a second time.
Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.
Give it about 5 minutes, then click Start>Run and type the following bolded command, then hit Enter.

helpasst -mbrt

Make sure you leave a space between helpasst and -mbrt !
When it completes, a log will open.
Please post the contents of that log.

**Important note to Dell users - fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not allow the tool to execute mbr -f nor execute the command manually, and you will either need to restore your computer to a factory state or allow your computer to remain having an infected mbr (the latter not recommended).
============================================================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI