This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Computer notgood

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I continuosly have pop up for fake virus alerts and i cannot run executables. exe helper runs but did not work the file it generated has the exe helper title and version in it but does not stay open long enough to copy the text, there is no other text in it. when i open it iit opens for a second then closes and a security warning stating that notepad.exe is infected opens
Hello there, whittgr

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)

——————————————————————————————————


——————————————————————————————————
Hi,

If you have an active internet connection, copy/paste the links below into your browser, don't click them or the rogue might redirect. If you don't have an active internet connection, download the tools from another machine, and transfer them to the affected machine via USB flash drive.


Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.


http://download.bleepingcomputer.com/grinler/rkill.exe
http://download.bleepingcomputer.com/grinler/rkill.com
http://download.bleepingcomputer.com/grinler/rkill.scr


Note:

You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message. Run rkill repeatedly until it's able to do it's job. This may take a few tries. You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

At this point, you should now be able to run analysis tools.

Once the tool has run, do NOT reboot the machine, and then try once again to run OTL and GMER.

If for some reason the machine reboots, repeat the process. Again, try not to restart the machine.

===================================================

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
ok so after I posted the topic her my computer completly froze up. i was able to perform a roll back with my system suite software and now I am able to access the computer again. things seem to be working properly except a very slow internet connection. I didn't want to peform the tasks that you asked me to do untill I told you of this change do you still want me to do those or something difeerent, I am not sure that the computer is clean from whateveer nasty virus that I had.
I ran OTL an the log follows, but when I run GMER my computer freezes up or crashes before it can finish.

OTL.txt

OTL logfile created on: 5/19/2010 11:01:44 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = D:\Documents and Settings\John\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 111.78 Gb Total Space | 17.56 Gb Free Space | 15.71% Space Free | Partition Type: NTFS
Drive D: | 465.75 Gb Total Space | 162.07 Gb Free Space | 34.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TRINITY
Current User Name: John
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - D:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\MediaMall\MediaMallServer.exe (MediaMall Technologies, Inc.)
PRC - D:\Program Files\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
PRC - D:\Program Files\Orb Networks\Orb\bin\OrbLauncher.exe (Orb Networks)
PRC - D:\Program Files\Orb Networks\Orb\bin\OrbMediaService.exe (Orb Networks)
PRC - D:\Program Files\Orb Networks\Orb\bin\Orb.exe (Orb Networks, Inc.)
PRC - D:\Program Files\Avanquest\SystemSuite\MXTask2.exe (Avanquest North America, Inc.)
PRC - D:\Program Files\Avanquest\SystemSuite\MXTask.exe (Avanquest North America, Inc.)
PRC - D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - D:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - D:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - D:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - D:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe (Logitech Inc.)
PRC - D:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - D:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
PRC - D:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - D:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe (Logitech Inc.)
PRC - D:\Program Files\Common Files\AntiVirus\SBAMSvc.exe (Sunbelt Software)
PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
PRC - D:\Program Files\Microsoft Broadband Networking\MSBNTray.exe (Microsoft Corporation)
PRC - D:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)


========== Modules (SafeList) ==========

MOD - D:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
MOD - D:\Program Files\Avanquest\SystemSuite\WinHook.dll (Avanquest North America, Inc.)
MOD - D:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (DAUpdaterSvc) – D:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (MediaMall Server) – D:\Program Files\MediaMall\MediaMallServer.exe (MediaMall Technologies, Inc.)
SRV - (OrbMediaService) – D:\Program Files\Orb Networks\Orb\bin\OrbMediaService.exe (Orb Networks)
SRV - (FLEXnet Licensing Service) – D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (SystemSuite Task Manager) – D:\Program Files\Avanquest\SystemSuite\MXTask.exe (Avanquest North America, Inc.)
SRV - (IntuitUpdateService) – D:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (YahooAUService) – D:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (SBAMSvc) – D:\Program Files\Common Files\AntiVirus\SBAMSvc.exe (Sunbelt Software)
SRV - (Adobe Version Cue CS4) – D:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – D:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (sptd) – D:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (nv) – D:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (hotcore3) – D:\WINDOWS\system32\DRIVERS\hotcore3.sys (Paragon Software Group)
DRV - (Uim_IM) – D:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (UimBus) – D:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (LMouFilt) – D:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – D:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (SBRE) – D:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (sbtis) – D:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software)
DRV - (TFilter) – D:\Program Files\Avanquest\SystemSuite\TFilter.sys (Avanquest North America, Inc.)
DRV - (nvgts) – D:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (adfs) – D:\WINDOWS\system32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (sbapifs) – D:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – D:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (gameenum) – D:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – D:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (nvnetbus) – D:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – D:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (RTLWUSB) – D:\WINDOWS\system32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (nvata) – D:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (AmdK8) – D:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (SjyPkt) – D:\WINDOWS\system32\drivers\SjyPkt.sys (Windows ® 2000 DDK provider)
DRV - (SI3132) – D:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (SiFilter) – D:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (MTsensor) – D:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (MSW_USB) – D:\WINDOWS\system32\drivers\MN510-51.sys (Microsoft, Inc.)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – D:\WINDOWS\system32\drivers\sfman.sys (Creative Technology Ltd.)
DRV - (ctljystk) – D:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! series(WDM) – D:\WINDOWS\system32\drivers\emu10k1f.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – D:\WINDOWS\system32\drivers\ctlface.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - D:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - D:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {e1170235-2845-420c-acc3-42261a29dd46}:4.0.1
FF - prefs.js..extensions.enabledItems: {4d855a8a-1536-4aa8-bf99-da2362910205}:[removed]
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: [removed]:2.2.0
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2
FF - prefs.js..extensions.enabledItems: paypalfirefoxplugin@orbiscom:[removed]
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.7.3
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&query;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: D:\Program Files\Avanquest\SystemSuite\Firefox [2009/04/07 06:11:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4d855a8a-1536-4aa8-bf99-da2362910205}: D:\Program Files\Avanquest\SystemSuite\Firefox3DV [2009/04/07 06:15:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\paypalfirefoxplugin@orbiscom: D:\Program Files\PayPal\PayPal Plug-In [2010/02/19 08:45:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/05/07 15:03:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/04/05 18:32:15 | 000,000,000 | —D | M]

[2009/04/07 05:53:19 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\Mozilla\Extensions
[2010/05/19 12:53:21 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions
[2009/12/30 19:29:08 | 000,000,000 | —D | M] (FaceFun) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
[2010/04/26 20:19:24 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/16 05:26:22 | 000,000,000 | —D | M] (PDF Download) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2009/12/30 19:44:33 | 000,000,000 | —D | M] (Dogpile Bundle Toolbar) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{517ca167-b6e8-4397-a0b4-a0074bbe3d5b}
[2009/06/04 18:11:03 | 000,000,000 | —D | M] (IE Tab) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2010/03/18 18:49:15 | 000,000,000 | —D | M] (Zynga Toolbar) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/04/07 06:44:38 | 000,000,000 | —D | M] (FireFTP) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2009/08/06 18:34:02 | 000,000,000 | —D | M] (Password Exporter) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2010/01/22 06:12:54 | 000,000,000 | —D | M] (Clipmarks) – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2009/10/09 07:13:07 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\[removed]
[2010/03/02 19:29:48 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\[removed]
[2010/02/19 08:34:57 | 000,004,546 | —- | M] () – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\searchplugins\aim-search.xml
[2009/12/30 20:51:21 | 000,001,070 | —- | M] () – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\searchplugins\dogpile-search.xml
[2009/10/15 17:41:55 | 000,002,138 | —- | M] () – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\searchplugins\MySpace.xml
[2009/04/18 17:31:54 | 000,001,368 | —- | M] () – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\searchplugins\nextag.xml
[2010/04/28 17:35:54 | 000,002,363 | —- | M] () – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\searchplugins\search-the-web.xml
[2009/04/18 17:20:30 | 000,001,088 | —- | M] () – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\searchplugins\thottbot-wow.xml
[2009/05/08 16:36:13 | 000,000,945 | —- | M] () – D:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\searchplugins\youtube-video-search.xml
[2010/05/19 12:53:21 | 000,000,000 | —D | M] – D:\Program Files\Mozilla Firefox\extensions
[2009/09/05 11:30:03 | 000,238,776 | —- | M] (Pando Networks) – D:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll

O1 HOSTS File: ([2009/04/24 14:31:24 | 000,305,725 | R— | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 10527 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {0347C33E-8762-4905-BF09-768834316C61} - No CLSID value found.
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - D:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (PlaySushi) - {21608B66-026F-4DCB-9244-0DACA328DCED} - D:\Program Files\PlaySushi\PSText.dll ()
O2 - BHO: (XPL LinkScannerIE) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll (Exploit Prevention Labs, Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (DataVault Object) - {8373ADC0-6330-11DD-9D77-22C856D89593} - D:\Program Files\Avanquest\SystemSuite\IE_ContextMenu_Vault.dll (Avanquest North America, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - D:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O2 - BHO: (OToolbarHelper Class) - {EAD3A971-6A23-4246-8691-C9244E858967} - D:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll ()
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - D:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (no name) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - D:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - D:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (PayPal Plug-In) - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - D:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (TextAloud) - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - D:\Program Files\TextAloud\TAForIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - D:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe_ID0ENQBO] D:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] D:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] D:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Launch LCDMon] D:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] D:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LgDevAgt] D:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [Orb] D:\Program Files\Orb Networks\Orb\bin\OrbLauncher.exe (Orb Networks)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Messenger (Yahoo!)] D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Orb] D:\Program Files\Orb Networks\Orb\bin\OrbTray.exe File not found
O4 - HKCU..\Run: [PlayOn] D:\Program Files\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [uTorrent] D:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Broadband Networking.lnk = D:\WINDOWS\Installer\{8CC15633-2327-43F4-BA85-B83FDB4B59BE}\_18be6784.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Go PlaySushi! - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - D:\Program Files\PlaySushi\PSText.dll ()
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1239115665796 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1240094785812 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - D:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - D:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - D:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - D:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: D:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/07 04:52:36 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{c0ef2030-2356-11de-a40b-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{c0ef2030-2356-11de-a40b-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c0ef2030-2356-11de-a40b-806d6172696f}\Shell\AutoRun\command - "" = F:\.\Bin\Assetup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - D:\WINDOWS\system32\ias [2009/04/07 00:35:16 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - D:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/05/19 23:00:24 | 000,571,904 | —- | C] (OldTimer Tools) – D:\Documents and Settings\John\Desktop\OTL.exe
[2010/05/19 21:13:27 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Gosu
[2010/05/15 20:24:49 | 000,000,000 | —D | C] – D:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/05/15 20:24:48 | 000,000,000 | —D | C] – D:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/05/14 21:17:52 | 000,000,000 | —D | C] – D:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/05/14 19:53:36 | 000,000,000 | —D | C] – D:\spoolerlogs
[2010/05/14 19:46:50 | 000,000,000 | —D | C] – D:\Documents and Settings\John\Local Settings\Application Data\nsgsnudvf
[2010/05/14 19:46:21 | 000,000,000 | —D | C] – D:\Documents and Settings\John\Application Data\ATManager
[2010/05/14 19:46:12 | 000,000,000 | —D | C] – D:\Documents and Settings\John\Application Data\05797CE6939488349FA88E7597AA38E6
[2010/05/13 23:50:27 | 000,000,000 | —D | C] – D:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/05/13 23:50:26 | 000,000,000 | —D | C] – D:\Documents and Settings\John\Local Settings\Application Data\Temp
[2010/05/13 23:50:21 | 000,000,000 | —D | C] – D:\Program Files\Common Files\DivX Shared
[2010/05/13 23:50:18 | 000,000,000 | —D | C] – D:\Documents and Settings\John\Local Settings\Application Data\Google
[2010/05/13 23:50:16 | 000,000,000 | —D | C] – D:\Program Files\Google
[2010/05/13 23:50:13 | 000,000,000 | —D | C] – D:\Program Files\DivX
[2010/05/13 23:50:06 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\DivX
[2010/05/09 20:13:55 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\WEBREG
[2010/05/08 10:53:53 | 000,000,000 | —D | C] – D:\Documents and Settings\John\Application Data\HP
[2010/05/08 10:46:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2010/05/08 10:46:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\HP
[2010/05/08 10:46:06 | 000,000,000 | —D | C] – D:\Program Files\Common Files\HP
[2010/05/08 10:45:31 | 000,000,000 | —D | C] – D:\Program Files\HP
[2010/05/08 10:45:19 | 000,000,000 | -H-D | C] – D:\Config.Msi
[2010/05/08 10:37:23 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2010/05/08 10:37:15 | 000,271,704 | R— | C] (Hewlett-Packard) – D:\WINDOWS\System32\hpzids01.dll
[2010/05/08 10:37:11 | 000,117,760 | —- | C] (Hewlett-Packard Company) – D:\WINDOWS\System32\hpzll5mu.dll
[2010/04/28 18:10:18 | 000,000,000 | —D | C] – D:\Documents and Settings\John\Application Data\Facebook
[2010/04/28 18:10:12 | 002,114,184 | —- | C] (Facebook, Inc.) – D:\Documents and Settings\John\Desktop\Install_Facebook_Plug-In_1.0.3.exe
[2010/04/26 18:04:42 | 000,353,592 | —- | C] (DivX, Inc.) – D:\WINDOWS\System32\DivXControlPanelApplet.cpl
[2009/04/07 04:57:24 | 000,059,392 | —- | C] ( ) – D:\WINDOWS\System32\a3d.dll
[7 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[6 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/19 23:00:24 | 000,571,904 | —- | M] (OldTimer Tools) – D:\Documents and Settings\John\Desktop\OTL.exe
[2010/05/19 23:00:00 | 000,000,882 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/19 22:58:58 | 000,002,355 | —- | M] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Broadband Networking.lnk
[2010/05/19 22:58:57 | 000,215,383 | —- | M] () – D:\WINDOWS\System32\nvapps.xml
[2010/05/19 22:58:55 | 000,000,878 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/19 22:58:55 | 000,000,278 | -H– | M] () – D:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/05/19 21:37:38 | 000,000,310 | —- | M] () – D:\WINDOWS\tasks\Orb Index when idle.job
[2010/05/19 21:15:01 | 007,864,320 | -H– | M] () – D:\Documents and Settings\John\NTUSER.DAT
[2010/05/19 21:12:39 | 000,000,006 | -H– | M] () – D:\WINDOWS\tasks\SA.DAT
[2010/05/19 21:12:37 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2010/05/19 20:51:57 | 000,013,646 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2010/05/14 19:46:30 | 000,003,072 | —- | M] () – D:\Documents and Settings\John\Application Data\mtl.dll
[2010/05/14 19:46:21 | 000,000,975 | —- | M] () – D:\Documents and Settings\John\Desktop\ATManager.lnk
[2010/05/14 19:46:20 | 001,882,240 | —- | M] () – D:\WINDOWS\System32\download.exe
[2010/05/14 19:46:05 | 000,174,592 | —- | M] () – D:\WINDOWS\Fvuvia.exe
[2010/05/13 23:51:22 | 000,001,817 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/05/13 23:51:18 | 000,001,450 | —- | M] () – D:\Documents and Settings\John\Desktop\DivX Movies.lnk
[2010/05/10 07:48:00 | 000,000,284 | —- | M] () – D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/09 21:59:55 | 000,000,069 | —- | M] () – D:\WINDOWS\NeroDigital.ini
[2010/05/08 10:54:12 | 000,157,204 | —- | M] () – D:\WINDOWS\hphins26.dat
[2010/05/08 10:53:44 | 000,000,000 | —- | M] () – D:\Documents and Settings\John\Ÿ9Ÿ9
[2010/05/08 10:48:07 | 000,001,862 | —- | M] () – D:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 2.5.lnk
[2010/05/08 10:47:35 | 000,001,964 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Shop for HP Supplies.lnk
[2010/05/08 10:46:45 | 000,001,812 | —- | M] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/05/08 10:46:31 | 000,000,988 | —- | M] () – D:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk
[2010/05/02 20:14:14 | 000,093,639 | —- | M] () – D:\Documents and Settings\John\Desktop\Spring Massive.pdf
[2010/04/28 18:10:12 | 002,114,184 | —- | M] (Facebook, Inc.) – D:\Documents and Settings\John\Desktop\Install_Facebook_Plug-In_1.0.3.exe
[2010/04/26 18:04:42 | 000,353,592 | —- | M] (DivX, Inc.) – D:\WINDOWS\System32\DivXControlPanelApplet.cpl
[2010/04/20 17:26:45 | 186,578,211 | —- | M] () – D:\Documents and Settings\John\Desktop\Arsam - April 2010 Mix.mp3
[7 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[6 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/14 19:46:30 | 000,003,072 | —- | C] () – D:\Documents and Settings\John\Application Data\mtl.dll
[2010/05/14 19:46:21 | 000,000,975 | —- | C] () – D:\Documents and Settings\John\Desktop\ATManager.lnk
[2010/05/14 19:46:16 | 001,882,240 | —- | C] () – D:\WINDOWS\System32\download.exe
[2010/05/14 19:46:11 | 000,174,592 | —- | C] () – D:\WINDOWS\Fvuvia.exe
[2010/05/14 19:46:10 | 000,000,278 | -H– | C] () – D:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/05/13 23:51:22 | 000,001,817 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/05/13 23:51:18 | 000,001,450 | —- | C] () – D:\Documents and Settings\John\Desktop\DivX Movies.lnk
[2010/05/13 23:50:20 | 000,000,882 | —- | C] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/13 23:50:20 | 000,000,878 | —- | C] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/08 10:53:44 | 000,000,000 | —- | C] () – D:\Documents and Settings\John\Ÿ9Ÿ9
[2010/05/08 10:48:07 | 000,001,862 | —- | C] () – D:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 2.5.lnk
[2010/05/08 10:47:35 | 000,001,964 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Shop for HP Supplies.lnk
[2010/05/08 10:46:45 | 000,001,812 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/05/08 10:46:31 | 000,000,988 | —- | C] () – D:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk
[2010/05/08 10:37:28 | 000,157,204 | —- | C] () – D:\WINDOWS\hphins26.dat
[2010/05/08 10:37:28 | 000,001,128 | —- | C] () – D:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/05/08 10:37:28 | 000,000,787 | —- | C] () – D:\WINDOWS\hphmdl26.dat
[2010/05/02 20:14:14 | 000,093,639 | —- | C] () – D:\Documents and Settings\John\Desktop\Spring Massive.pdf
[2010/04/20 17:23:54 | 186,578,211 | —- | C] () – D:\Documents and Settings\John\Desktop\Arsam - April 2010 Mix.mp3
[2010/04/20 06:11:48 | 007,864,320 | -H– | C] () – D:\Documents and Settings\John\NTUSER.DAT
[2010/02/28 15:44:15 | 000,484,352 | —- | C] () – D:\WINDOWS\System32\lame_enc.dll
[2009/09/22 18:28:42 | 000,354,816 | —- | C] () – D:\WINDOWS\System32\psisdecd.dll
[2009/09/20 06:11:42 | 000,122,368 | —- | C] () – D:\WINDOWS\lua5.1.dll
[2009/08/29 15:17:06 | 000,043,520 | —- | C] () – D:\WINDOWS\System32\CmdLineExt03.dll
[2009/07/13 03:04:28 | 009,277,440 | —- | C] () – D:\WINDOWS\avcodec-52.dll
[2009/07/13 03:04:28 | 000,751,104 | —- | C] () – D:\WINDOWS\avformat-52.dll
[2009/07/13 03:04:28 | 000,218,624 | —- | C] () – D:\WINDOWS\swscale-0.dll
[2009/07/13 03:04:28 | 000,070,144 | —- | C] () – D:\WINDOWS\avutil-50.dll
[2009/04/22 00:19:06 | 000,172,173 | —- | C] () – D:\WINDOWS\System32\xlive.dll.cat
[2009/04/14 15:22:09 | 000,000,069 | —- | C] () – D:\WINDOWS\NeroDigital.ini
[2009/04/07 11:56:40 | 000,717,296 | —- | C] () – D:\WINDOWS\System32\drivers\sptd.sys
[2009/04/07 05:42:11 | 000,000,962 | R— | C] () – D:\WINDOWS\System32\AsusSetup.ini
[2009/04/07 05:42:11 | 000,000,403 | R— | C] () – D:\WINDOWS\System32\raidmgmt.ini
[2009/04/07 05:39:37 | 000,034,695 | —- | C] () – D:\WINDOWS\Ascd_log.ini
[2009/04/07 05:39:19 | 000,034,389 | —- | C] () – D:\WINDOWS\Ascd_tmp.ini
[2009/04/07 05:39:00 | 000,010,288 | —- | C] () – D:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/04/07 04:57:23 | 000,286,720 | —- | C] () – D:\WINDOWS\System32\nvnt4cpl.dll
[2009/04/07 04:57:21 | 000,005,810 | —- | C] () – D:\WINDOWS\System32\drivers\ASACPI.sys
[2009/03/27 10:03:00 | 001,724,416 | —- | C] () – D:\WINDOWS\System32\nvwdmcpl.dll
[2009/03/27 10:03:00 | 001,503,232 | —- | C] () – D:\WINDOWS\System32\nview.dll
[2009/03/27 10:03:00 | 001,101,824 | —- | C] () – D:\WINDOWS\System32\nvwimg.dll
[2009/03/27 10:03:00 | 000,466,944 | —- | C] () – D:\WINDOWS\System32\nvshell.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – D:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – D:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 08:00:00 | 000,002,304 | —- | C] () – D:\WINDOWS\System32\isaxbox.sys
[2004/02/20 16:36:34 | 000,416,256 | —- | C] () – D:\WINDOWS\exchndl.dll

========== LOP Check ==========

[2010/02/19 08:33:10 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2009/04/07 06:12:54 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Avanquest
[2009/04/07 12:13:23 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Avanquest software
[2010/01/22 17:06:32 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\BioWare
[2009/04/07 06:11:14 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/04/07 12:00:28 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/11/27 20:18:49 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\ElectricSheep
[2009/04/07 05:10:47 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\EPSON
[2009/10/08 19:46:42 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Fallout3
[2010/05/19 21:13:30 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Gosu
[2010/05/19 21:13:18 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\MediaMall
[2009/04/20 04:30:16 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\OrbNetworks
[2009/09/05 11:32:57 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\PMB Files
[2009/04/18 20:51:50 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Team MediaPortal
[2010/02/28 17:06:25 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\TEMP
[2009/04/07 11:43:11 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009/04/07 11:43:02 | 000,000,000 | -HSD | M] – D:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2010/05/14 19:46:12 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\05797CE6939488349FA88E7597AA38E6
[2010/05/14 19:46:25 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\ATManager
[2009/04/07 06:12:58 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\Avanquest
[2009/04/07 12:20:59 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\DAEMON Tools
[2009/04/08 17:34:16 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\DAEMON Tools Lite
[2009/04/07 12:20:59 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\DAEMON Tools Pro
[2010/04/28 18:10:19 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\Facebook
[2010/02/28 15:44:16 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\FreeAudioPack
[2009/04/07 09:09:18 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\KeePass
[2010/02/11 19:42:16 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\runic games
[2009/04/07 07:01:59 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\TuneUp Software
[2009/09/05 12:36:22 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\Turbine
[2010/05/19 22:59:08 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\uTorrent
[2009/05/10 16:45:20 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\VTExtra
[2009/04/28 00:43:57 | 000,000,000 | —D | M] – D:\Documents and Settings\John\Application Data\Wizards of the Coast
[2010/05/19 21:37:38 | 000,000,310 | —- | M] () – D:\WINDOWS\Tasks\Orb Index when idle.job
[2010/05/19 22:58:55 | 000,000,278 | -H– | M] () – D:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – D:\install.exe


< MD5 for: AGP440.SYS >
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – D:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/04/07 11:08:45 | 023,852,652 | —- | M] () .cab file – D:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/04/07 11:08:45 | 023,852,652 | —- | M] () .cab file – D:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – D:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – D:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – D:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/04/07 11:08:45 | 023,852,652 | —- | M] () .cab file – D:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/04/07 11:08:45 | 023,852,652 | —- | M] () .cab file – D:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – D:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – D:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – D:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 08:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – D:\WINDOWS\system32\ReinstallBackups\0052\DriverFiles\i386\atapi.sys
[2004/08/04 08:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – D:\WINDOWS\system32\ReinstallBackups\0055\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – D:\WINDOWS\system32\ReinstallBackups\0056\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – D:\WINDOWS\system32\ReinstallBackups\0057\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – D:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – D:\WINDOWS\system32\eventlog.dll
[2004/08/04 08:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – D:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – D:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – D:\WINDOWS\system32\netlogon.dll
[2004/08/04 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – D:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATA.SYS >
[2006/08/21 14:24:28 | 000,105,344 | R— | M] (NVIDIA Corporation) MD5=4D6C6B46B3EDF6F2E219A86B61D104AE – D:\WINDOWS\system32\drivers\nvata.sys

< MD5 for: NVGTS.SYS >
[2008/08/18 18:54:24 | 000,145,952 | —- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E – D:\WINDOWS\system32\drivers\nvgts.sys
[2008/08/18 18:54:24 | 000,145,952 | —- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E – D:\WINDOWS\system32\ReinstallBackups\0053\DriverFiles\nvgts.sys
[2008/08/18 18:54:24 | 000,145,952 | —- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E – D:\WINDOWS\system32\ReinstallBackups\0054\DriverFiles\nvgts.sys
[2008/08/18 18:54:24 | 000,145,952 | —- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E – D:\WINDOWS\system32\ReinstallBackups\0111\DriverFiles\nvgts.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 08:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – D:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – D:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – D:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[6 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009/04/07 11:56:40 | 000,717,296 | —- | M] () Unable to obtain MD5 – D:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2009/04/07 00:38:33 | 000,094,208 | —- | M] () – D:\WINDOWS\system32\config\default.sav
[2009/04/07 00:38:33 | 000,634,880 | —- | M] () – D:\WINDOWS\system32\config\software.sav
[2009/04/07 00:38:33 | 000,937,984 | —- | M] () – D:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
< End of report >



Extras.txt


OTL Extras logfile created on: 5/19/2010 11:01:44 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = D:\Documents and Settings\John\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 111.78 Gb Total Space | 17.56 Gb Free Space | 15.71% Space Free | Partition Type: NTFS
Drive D: | 465.75 Gb Total Space | 162.07 Gb Free Space | 34.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TRINITY
Current User Name: John
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "D:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "D:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – D:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"56258:TCP" = 56258:TCP:*:Enabled:Pando Media Booster
"56258:UDP" = 56258:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS4 Server
"3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51000:TCP" = 51000:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51001:TCP" = 51001:TCP:*:Enabled:Adobe Version Cue CS4 Server
"56258:TCP" = 56258:TCP:*:Enabled:Pando Media Booster
"56258:UDP" = 56258:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\Program Files\Windows Live\Messenger\wlcsdk.exe" = D:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"D:\Program Files\Pando Networks\Media Booster\PMB.exe" = D:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Program Files\uTorrent\uTorrent.exe" = D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"D:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = D:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"D:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" = D:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:*:Enabled:Adobe Version Cue CS4 Server – (Adobe Systems Incorporated)
"D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"D:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = D:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"D:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = D:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"D:\DOCUME~1\John\LOCALS~1\Temp\IXP003.TMP\update.exe" = D:\DOCUME~1\John\LOCALS~1\Temp\IXP003.TMP\update.exe:*:Enabled:Windows UDP Control Center – File not found
"D:\Program Files\Windows Live\Messenger\wlcsdk.exe" = D:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"D:\Program Files\Microsoft Broadband Networking\MSBNUtil.exe" = D:\Program Files\Microsoft Broadband Networking\MSBNUtil.exe:*:Enabled:Microsoft Broadband Network Utility – (Microsoft Corporation)
"D:\Program Files\Microsoft Broadband Networking\MSBNTray.exe" = D:\Program Files\Microsoft Broadband Networking\MSBNTray.exe:*:Enabled:Microsoft Broadband Networking Tray – (Microsoft Corporation)
"D:\Program Files\Microsoft Broadband Networking\MSBNCfg.exe" = D:\Program Files\Microsoft Broadband Networking\MSBNCfg.exe:*:Enabled:Microsoft Broadband Networking Setup – (Microsoft Corporation)
"D:\Program Files\Microsoft Broadband Networking\MSBNUpdate.exe" = D:\Program Files\Microsoft Broadband Networking\MSBNUpdate.exe:*:Enabled:Microsoft Broadband Networking Update – (Microsoft Corporation)
"F:\RECYCLER\S-1-6-22-2434476501-1644491937-600003330-1213\svchost.exe" = F:\RECYCLER\S-1-6-22-2434476501-1644491937-600003330-1213\svchost.exe:*:Enabled:1 – File not found
"D:\Program Files\Pando Networks\Media Booster\PMB.exe" = D:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"D:\Program Files\Velvet Assassin\Launcher.exe" = D:\Program Files\Velvet Assassin\Launcher.exe:*:Enabled:Velvet_Assassin-1 – ()
"D:\Program Files\Velvet Assassin\replay.exe" = D:\Program Files\Velvet Assassin\replay.exe:*:Enabled:Velvet_Assassin-2 – (cd)
"D:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" = D:\Program Files\Orb Networks\Orb\bin\OrbTray.exe:*:Enabled:OrbTray – File not found
"D:\Program Files\Orb Networks\Orb\bin\xmltv.exe" = D:\Program Files\Orb Networks\Orb\bin\xmltv.exe:*:Enabled:OrbTVGuide – File not found
"D:\Program Files\Orb Networks\Orb\bin\Orb.exe" = D:\Program Files\Orb Networks\Orb\bin\Orb.exe:*:Enabled:Orb – (Orb Networks, Inc.)
"D:\Program Files\Orb Networks\Orb\bin\OrbLauncher.exe" = D:\Program Files\Orb Networks\Orb\bin\OrbLauncher.exe:*:Enabled:OrbLauncher – (Orb Networks)
"D:\Program Files\Orb Networks\Orb\bin\OrbSetupWizard.exe" = D:\Program Files\Orb Networks\Orb\bin\OrbSetupWizard.exe:*:Enabled:OrbSetupWizard – ()
"D:\Program Files\Orb Networks\Orb\bin\OrbControlPanel.exe" = D:\Program Files\Orb Networks\Orb\bin\OrbControlPanel.exe:*:Enabled:OrbControlPanel – ()
"D:\Program Files\Orb Networks\Orb\bin\OrbStreamerClient.exe" = D:\Program Files\Orb Networks\Orb\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client – ()
"D:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = D:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"D:\Program Files\Dragon Age\bin_ship\daorigins.exe" = D:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Origins Game – (BioWare)
"D:\Program Files\Dragon Age\DAOriginsLauncher.exe" = D:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Origins Launcher – (BioWare)
"D:\Program Files\AIM\aim.exe" = D:\Program Files\AIM\aim.exe:*:Enabled:AIM – File not found
"D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"D:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe" = D:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater – (BioWare)
"D:\Program Files\MediaMall\MediaMallServer.exe" = D:\Program Files\MediaMall\MediaMallServer.exe:*:Enabled:MediaMall Server – (MediaMall Technologies, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20CFBF87-73BD-4EC5-80B4-9C894126BD14}" = TurboTax 2008 wvaiper
"{2133CB3F-F891-4081-8681-FEE2B2419FF4}" = Orb Runtime libraries
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 14
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C5F1B30-B10B-4579-86DD-D00F662E1033}" = Nero 8 Ultra Edition HD
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{48D7FBA8-624C-4160-8A1D-D62619C2A693}" = NextUp.com-NeoSpeech Paul16 Voice
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{63A80153-E563-42D6-B8B5-AD96B1737F78}" = PlayOn 2.59.3525
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A615007-721D-4063-B226-EA41EB6604B9}" = SystemSuite 9 Professional
"{73317C31-2B6E-4B88-9865-B97C1331A39D}" = PayPal Plug-In
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B3F4499-32E6-470D-8586-E6C03420F889}" = ASUS WiFi-AP Solo
"{8CC15633-2327-43F4-BA85-B83FDB4B59BE}" = Microsoft Broadband Networking
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B5B156B-9A4B-48FB-AA59-47B221495A7B}" = Logitech GamePanel Software 3.01
"{9DF0BE48-16F0-4E36-814D-9B4FDFFAF25F}" = PayPal Plug-In
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A1416622-0DDE-45B5-B06C-DFC3ED94C53B}" = The Godfather™ II
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{AF7733C1-FB0B-4FED-9730-E0433AF7A2EF}" = Magic Online III
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8013DD1-574B-4921-A473-88A2F7A34D16}" = Avanquest Perfect Image 12
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"15b35190-c6f9-11d9-9669-0800200c9a66_is1" = Dungeons & Dragons Online ®: Eberron Unlimited ™ v01.09.03.800
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"AIM Toolbar" = AIM Toolbar
"Army Men" = Army Men
"AudioConverter Studio_is1" = AudioConverter Studio 6.0
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"dBpoweramp [Calculate Audio CRC] Codec" = dBpoweramp [Calculate Audio CRC] Codec
"dBpoweramp Dalet Codec" = dBpoweramp Dalet Codec
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp FLAC Codec" = dBpoweramp FLAC Codec
"dBpoweramp Monkeys Audio Codec" = dBpoweramp Monkeys Audio Codec
"dBpoweramp Mp2 and BwfMp2 codec" = dBpoweramp Mp2 and BwfMp2 codec
"dBpoweramp mp3 (Fraunhofer IIS) Codec" = dBpoweramp mp3 (Fraunhofer IIS) Codec
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"dBpoweramp Ogg Vorbis Codec" = dBpoweramp Ogg Vorbis Codec
"dBpoweramp Real Audio (Helix) Encoder" = dBpoweramp Real Audio (Helix) Encoder
"dBPoweramp tooLame MP2 codec" = dBPoweramp tooLame MP2 codec
"dBpoweramp Wave64 Codec" = dBpoweramp Wave64 Codec
"dBpoweramp WavPack Codec" = dBpoweramp WavPack Codec
"DebtFree™ for Windows Personal 5.1b" = DebtFree™ for Windows Personal 5.1b
"Electricsheep Screensaver" = Electricsheep Screensaver 2.7b20
"ENTERPRISER" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"Fallout 3 - The Pitt" = Fallout 3 - The Pitt
"FLAC" = FLAC 1.2.1b (remove only)
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 1.9
"Hired Guns1.07.000" = Hired Guns
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"KeePass Password Safe_is1" = KeePass Password Safe 1.15
"Magic M4A to MP3 Converter_is1" = Magic M4A to MP3 Converter 3.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"Orb" = Orb
"Playsushi" = Playsushi
"Runic Games Torchlight" = Torchlight
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"TextAloud MP3_is1" = TextAloud
"TurboTax 2008" = TurboTax 2008
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/18/2010 3:33:53 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/18/2010 3:33:55 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 5/18/2010 5:34:04 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/18/2010 7:34:09 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/19/2010 5:09:04 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/19/2010 5:09:05 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 5/19/2010 6:34:36 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/19/2010 7:35:57 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 5/19/2010 7:36:00 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 5/19/2010 8:34:42 PM | Computer Name = TRINITY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

[ System Events ]
Error - 5/19/2010 10:59:09 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:09 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:09 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:10 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:10 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:10 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:10 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:10 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:18 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 5/19/2010 10:59:23 PM | Computer Name = TRINITY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

[ TuneUp Events ]
Error - 4/18/2009 10:10:21 PM | Computer Name = TRINITY | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 4/24/2009 2:18:37 PM | Computer Name = TRINITY | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 4/24/2009 2:47:47 PM | Computer Name = TRINITY | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 5/24/2009 10:12:18 PM | Computer Name = TRINITY | Source = TuneUp Program Statistics | ID = 131840
Description =


< End of report >
Hi,

Run Defogger first and then give GMER another shot.

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

===================================================

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (PlaySushi) - {21608B66-026F-4DCB-9244-0DACA328DCED} - D:\Program Files\PlaySushi\PSText.dll ()
    O4 - HKLM..\Run: [] File not found
    O9 - Extra Button: Go PlaySushi! - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - D:\Program Files\PlaySushi\PSText.dll ()
    O33 - MountPoints2\{c0ef2030-2356-11de-a40b-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{c0ef2030-2356-11de-a40b-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{c0ef2030-2356-11de-a40b-806d6172696f}\Shell\AutoRun\command - "" = F:\.\Bin\Assetup.exe – File not found
    D:\Documents and Settings\John\Application Data\mtl.dll
    
    :Files
     D:\Program Files\PlaySushi
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
jotti.org
Kaspersky Virus File Scanner
Virus Total

click on Browse, and upload the following file for analysis:
D:\WINDOWS\System32\download.exe
D:\WINDOWS\Fvuvia.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

===================================================

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :dir
    D:\Documents and Settings\John\Application Data\05797CE6939488349FA88E7597AA38E6 /s
    D:\Documents and Settings\John\Application Data\ATManager /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

===================================================

On your next reply please post :
GMER log
OTL log
SystemLook log

Good Day!
Gmer.exe will still not run without crashing before finishing. OTL.exe log All processes killed Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! ========== FILES ========== D:\Program Files\PlaySushi folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Admin ->Temp folder emptied: 3080997 bytes ->Temporary Internet Files folder emptied: 64817646 bytes ->FireFox cache emptied: 76588772 bytes ->Google Chrome cache emptied: 856432 bytes ->Flash cache emptied: 21326 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: John ->Temp folder emptied: 216129723 bytes ->Temporary Internet Files folder emptied: 58163216 bytes ->Java cache emptied: 31386659 bytes ->FireFox cache emptied: 41322516 bytes ->Google Chrome cache emptied: 6334271 bytes ->Flash cache emptied: 64883 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 2679767 bytes ->Flash cache emptied: 986 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 655762 bytes ->Flash cache emptied: 5447 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2518635 bytes %systemroot%\System32 .tmp files removed: 654865 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 123042256 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 1130968 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33223 bytes RecycleBin emptied: 3956764525 bytes Total Files Cleaned = 4,374.00 mb OTL by OldTimer - Version 3.2.5.0 log created on 05222010_093649 Files\Folders moved on Reboot… File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\1CAGNAZ7XCA0K3U9FCAHCXLVWCABYXC2KCAF3EMQOCAWFZFLZCAWG07U9CAYZCKSMCATIN5I1CA KI5U1VCAY8NRQ0CAWMIMV9CAUBCR6JCA2Q2HZYCA2IPLUGCANBBE13CAX5Q1QFCAY22J9VCAW4FFANCAE F7TGXCAT3NX2LCAGEP4PF not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\6CAH83Q2CCACEVH0YCATF5GL8CAQU0C0KCAP5W7EVCA5IC1CDCA994WTSCACY5XJWCAVOVXQNCA Z512V2CA3OZND1CAQ8WV8ICA7IDW4RCANVR69NCARTIOQGCA2GAPV4CAITL9QNCAOVD2IYCAO11UDTCAC G6142CAI75FPMCA64O6J4 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\ECARCA7UGCA3VWXIVCAQZLQ56CAXO4M2NCA9F5N23CABBH1KPCAQ8GIZ6CA3HJH04CAA7TSQICA JYKOI6CAKW6XU2CAJHESLTCA7HOS22CARECHEKCAV4LIF1CA7JFZ5DCAU7BUN5CAU631A2CAIOTVRYCAI 8PLXCCADXBBRQCA3EDERR not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\FCAEECBXZCA9MX7QCCAE21L4LCAXE46W6CAYFPUCQCAKMS3B8CAF0A40UCAMUTJ9CCABM0F2LCA F3U2YACARL1C4ZCAX06EL8CAXAQPPECA9VMN9YCAH5YF58CANPXR7FCAS5Z5BXCADM0W0JCA49TR5CCAP XUHU2CAA1N99ECA9ZHBNX not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\FCAFZBMS7CAPB44ZHCAUUHHJXCA78SPMPCAUF3Z6KCAQ0RF4GCAB2Q365CAACOP55CAWB5D04CA G7MK0TCAC5G8C8CALQ0F7BCAQLJ0K0CA9Q6M9ZCA74AK4FCAAJ627KCAV94R9JCAK9EI1RCA487F1BCAZ U22T2CAHJ8BLCCA4XZPEW not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\ICA4H21XHCAGVFXNPCAICEQ2BCAUDERVKCA6MP4CECAII4WKYCAW38MB8CAPZFNZJCA6FZEAKCA NUVGFXCA7RT4QECA4CMGCRCAV2LWKSCAPDJH0ACA6B6A1OCA5BZE88CATSYO0PCAP2VS4ECA9CLA3HCA5 YK87WCA7KN0O5CAYLGIIP not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\KCACK0YL5CAM4MW6TCAXMH3GMCAHRLL6OCAZN7RBDCA79C3FHCA6YFJC7CAYY9IDVCAF7X8UACA X8Y9X7CAV3Z5LOCAQOX4UICAQZ7DLLCAEEOCQ0CASEANPRCAO8TR2ZCASA6N0BCA38YLEWCAEWUTJNCAX J4SPXCAD54030CANB97HN not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\TCAEQ21TSCAPGQ88TCAZXMAGOCAQAISFECAI3FI0ICADUGNZ3CA3YWA5DCA5FGZM3CARU5YJ9CA 1FFXDGCASKWW7ACA5I8W49CAFPR5VNCA6BXJKJCAD00VYACAXGX5SKCASLH2I6CADX8Y99CAY2OMZ8CA1 S2676CACJW8IFCAC7X1NF not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\UAREJC0N\XCAULYINDCAIMHGQBCAFSZ9YVCAJE0J6NCAKD1NFVCAUCDDDECAIPD4TCCATPNX2MCAELCPNOCA E6ER40CAZNE0C8CA2OHRTGCAC4HSPYCAG42EV9CA3IGFBBCAOP2F4PCAPQJTZDCA67O6S4CA4S3R4UCAO WKJ63CA5B0B2WCAPE32Y3 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\OIEEBMOF\3CAH8KQWLCA1JBQRYCAJ849SCCAH4RDNVCAK3T2RDCA3JT6QQCAZ6CBMSCABYED88CACCUVLGCA ZSV3NLCA51K34QCAJMRNB8CAUL1RBLCA45HZ0HCAX7JUP0CAJE5AP4CAPWX895CATEMYEWCA3LPIPZCAY WHJZLCAF2PU70CAOLIICU not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\OIEEBMOF\3CAPS6PPVCAWL2539CA7Y988VCAUTWWMACAMKN1JZCANXP63QCABIBZ1WCAKCZY0QCAR63AQVCA APO3FKCANJ45J8CA6DD73WCAEZU2TDCAEYC0EFCANAPUNKCA6YV7JGCAKHZBK8CAFQQR2CCA09447RCAU S1O05CAQWJOXVCASMIIIE not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\OIEEBMOF\6CAHGN6CZCA4M8M3ECAB8S9SZCAROU0WYCACWR9SACAS8TN0QCA3R35T0CAO62C1MCA1Y595TCA M9Y7BHCA5KRGPSCADA68R1CAL88V3WCA2V9B7TCA1DRP4LCA3UAGQGCA9ILZ34CACMIVQ7CADST9Y2CAD 6V6VZCAYLY95WCAC3656K not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\0CA00QTUNCAQHA9P1CAY9KYN0CAC77JV9CA20D0KHCA3J5Q0ICAA15PH0CA68VZXSCAAL03ETCAAM LL2CCA5R8SOWCA6H0GW0CATZSE9LCA72UDGTCAXBNKB0CA6DVIE7CARH61ELCAAJC2QXCAXZT4M1CA5ZR EHQCA8Y38BGCA98QB3D not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\2CASH1NODCA0Q4AN6CAM3FAUTCAA19HX3CAFXZZLGCATW1D7ACA1NQEQFCASAJHD3CAUAHJYGCA V3ZWS3CAPYV5E5CAAVZPMQCAGC1MJPCA0N2WO6CAJ44JY3CA2F0SNWCADF448XCA4Y91CCCAVV1KQ3CAH OOK9GCAK8UHVOCAE2X1H5 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\4CAGU52Y4CAEC736ICA9539NECALY201NCA01FJDQCA6VT606CAANP86SCA7T2GXKCAYH6WSHCA B60NNECAGGF3IPCAFB76RJCAIHC9CDCA063IH5CANOTJWHCA58S2YPCAY7GUPBCAFF0008CA8T9Q7ICAD CYDPDCAAFLFTACA95722W not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\4CATPHLX8CAG6EYUICAHOW2RWCA9XELC2CAQ8XREECAB4X643CA1CXBHLCAHG3K18CAI6YWXZCA Q2Y6FGCAUZVOOACAHR4FSUCAR7T89VCAIOVWKUCAQIX95HCA799NMCCATI68W5CAU4AR6HCALJAFUHCAU WOF5ICAVYJX7WCAK2CTL3 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\5CA15MJF6CA2CXFDZCAJYJ99KCAW4VLLLCAFSEH2RCA3RJ3XKCAY14H73CAN590Y5CAFI9RHZCA 803SLACAS5J6CICAC7NB45CA74KKK2CAV2SO8JCAGHVXSMCALA5AR5CALFLPRYCAETH01ICA4FFV8RCAA 2242ECAOFOFLQCALJ3KET not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\5CACCP0DBCA9KXSEYCARTCVN7CAN8C814CAA3XI39CAR6T1MGCAK4O3GTCAYFROL3CACNHVZYCA LAQK9XCAY7LTNKCAEQQBU1CA1FTAV4CA99YB1KCAE0LH6ICA2G9P8LCAX09KENCAO5KHOJCAFRX1O0CAZ NSUIVCADIX0O8CAUZFRGU not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\6CA460LFBCAOXSMTXCAV6HF9JCAO7OWNPCALLI1U1CA60Z2FFCA0N56OBCAAV1JJFCARM0Y9GCA QRX5LMCAXUT9HHCAY6VGJRCAVT2BJ5CAP5PV9PCAG6B4EKCAO1OC4LCA324UULCAIVTE1JCAZTXDOOCAM 6A3XICAW776BACAMCZOM3 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\7CAT258ZHCARPPGERCAT4JEC3CAC54TLLCAFPQSQYCA261PB3CAIU6DXPCAN9L97ACAJE1J9ZCA BPX1WICAQXYUWKCA91PWZDCAYX7TZLCAO7YUP9CATBKL0XCAWFCHP9CA3JR1C9CAMH1LLNCA2GPA2DCA5 70YPKCAL1QY60CAHORVIM not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\DCAU1K7U6CAE1R2SNCA13TMA7CAN875SQCAXX9HUGCATZ5F2UCAEN5YSZCAZJF67JCAU07K1HCA AMH7QUCARI02WICAN2F9PCCAHW5KXCCASY4VZ2CAM31QRGCAMC60I4CA0P7O48CAV8V5C6CA4LW1CACAW 6YF9ICA62PL3XCAEHB5U9 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\ECAIWQ4B1CAK1DSM1CAVNWSKICABTCRTWCA78MC9OCA1UK6KMCASZ9P0PCAZLSL12CAEV1T1OCA TJG0NYCAY2FM7RCA4LOCQMCAJAZI42CA2ZF3WTCADBE529CA88NSTTCAWOKC2TCAUMIMSWCALX6BKKCAC 1QAAQCAEQU353CA664S5I not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\JCAYUDE3TCA3Y88WVCAL0GYO7CAC6SIS6CA0YXCIFCA0G5N2WCA199S59CAT24GTACAHGG7J5CA 7Q6VJQCAWR5LO7CAYOAITSCAKIJPN1CAF423EQCAAQ7EGUCAD5BN3KCAVYZKP1CAYK3S2QCAZ9NU7PCA7 0U0LACAJOQSTNCAY8V9DI not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\KCAQXJ04DCA7DJSM1CA2H4NF6CA4PVJ7NCA14RXZ8CASTDEAVCA1F2L34CA34KR4NCAPUS4DICA 0KMTCLCAKPAB91CAXFF28GCARM32V0CAV1EIDMCA0QCN2SCA7VTEP7CAHNY6MBCA2U4CPACAOFE4O9CAN DPVU1CAFFX079CABC658U not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\SCAJVA12UCASAUV9ACABSPYOACA4F4AFACA9VA37RCA77VRRJCAVAO2XACA6TPELQCAY6S7B3CA VA4MYGCAGVJ307CA80E3NMCA8SUXICCA2YOPHSCAO9YK8SCA0DJLY7CASUR7OECAAHB9L7CA18U3R9CA2 2X2WICACO5OBCCAPXR5A5 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\WCA3SKF2CCAQFA0W8CAD2LDPCCABLYMCDCAGITK9NCAXXV6GTCATOPSTYCANOE0HBCAVCT90QCA 07RW9DCAO9YP37CAGJOTRBCA4UCCO0CAN1L0G0CABI1SLJCAZNN51QCAOIQHCBCAFPW11NCAIU11CTCA1 35E1NCAW6GSV2CA5RP827 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\YCA2CL2LQCAAMCEC0CAI07XKZCAIFBBTVCAJ7BT3MCA9Y4VXJCALU7LRHCA090F81CAGMC3O0CA WBMWAKCA45QJAJCACC2S5QCAIB92VPCA1BA0I0CAXDM27YCA4IF1K5CA3HC5EWCAIN2FI8CAQ1W069CAZ DFYNMCAQP4E1DCANVP337 not found! File\Folder D:\Documents and Settings\John\Local Settings\Temp\Temporary Internet Files\Content.IE5\CYORT6PV\YCAXRSJRQCACCMTCPCAZR9EOZCALV7ERQCA8UCWVXCAVPURNGCAFEOPW9CAC5BFK4CAD43G9ACA TMMNHHCA0YUQ9MCAKHOBRRCAVMWSYOCAO6MVG9CA2L2ZJUCA1ZLUD3CAX39A19CA156NA3CAX8U9WNCAY 9ZGERCA3PAY2ECA89729B not found! Registry entries deleted on Reboot… defogger log defogger_disable by jpshortstuff (23.02.10.1) Log created at 09:31 on 22/05/2010 (John) Checking for autostart values… HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. HKCU:DAEMON Tools Lite -> Removed Checking for services/drivers… Unable to read sptd.sys SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- systemlook log SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 09:54 on 22/05/2010 by John (Administrator - Elevation successful) ========== dir ========== D:\Documents and Settings\John\Application Data\05797CE6939488349FA88E7597AA38E6 - Parameters: "/s" —Files— None found. No folders found. D:\Documents and Settings\John\Application Data\ATManager - Parameters: "/s" —Files— apmanager.exe –a— 1893888 bytes [17:29 12/05/2010] [17:29 12/05/2010] files –a— 10 bytes [23:46 14/05/2010] [00:16 15/05/2010] iplog –a— 76 bytes [23:46 14/05/2010] [23:46 14/05/2010] ispinfo –a— 132 bytes [23:46 14/05/2010] [23:46 14/05/2010] settings.ini –a— 165 bytes [17:32 12/05/2010] [13:40 17/05/2010] uninstall.exe –a— 298994 bytes [23:46 14/05/2010] [23:46 14/05/2010] wallpaper.jpg –a— 871379 bytes [15:52 29/03/2010] [15:52 29/03/2010] D:\Documents and Settings\John\Application Data\ATManager\languages d—– [23:46 14/05/2010] Czech.lng –a— 5810 bytes [15:50 29/03/2010] [15:50 29/03/2010] Danish.lng –a— 5932 bytes [15:50 29/03/2010] [15:50 29/03/2010] Dutch.lng –a— 6444 bytes [15:50 29/03/2010] [15:50 29/03/2010] English.lng –a— 5666 bytes [17:25 12/05/2010] [17:25 12/05/2010] French.lng –a— 6654 bytes [15:50 29/03/2010] [15:50 29/03/2010] German.lng –a— 6796 bytes [15:50 29/03/2010] [15:50 29/03/2010] Italian.lng –a— 6692 bytes [15:51 29/03/2010] [15:51 29/03/2010] Portuguese.lng –a— 5654 bytes [15:51 29/03/2010] [15:51 29/03/2010] Slovak.lng –a— 5862 bytes [15:51 29/03/2010] [15:51 29/03/2010] Spanish.lng –a— 6674 bytes [15:51 29/03/2010] [15:51 29/03/2010] template.lng –a— 456 bytes [15:51 29/03/2010] [15:51 29/03/2010] D:\Documents and Settings\John\Application Data\ATManager\metafiles d—– [23:46 14/05/2010] e7e2135bcdfc87179deacdb1cdac8b7a.torrent –a— 83 bytes [16:45 10/05/2010] [00:16 15/05/2010] -=End Of File=- download.exe scan results [ArcaVir] 2010-05-21 Fraudtool.Agent.Asn [G DATA] 2010-05-22 Found nothing [Avast! antivirus] 2010-05-22 Found nothing [Ikarus] 2010-05-22 Trojan.PrivacyProtector [Grisoft AVG Anti-Virus] 2010-05-22 Generic2_c.ABMP [Kaspersky Anti-Virus] 2010-05-22 not-a-virus:FraudTool.Win32.Agent.asn [Avira AntiVir] 2010-05-21 TR/DotTorrent.A.746 [ESET NOD32] 2010-05-22 Win32/Adware.Antipiracy [Softwin BitDefender] 2010-05-22 Found nothing [Panda Antivirus] 2010-05-21 Found nothing [ClamAV] 2010-05-22 Found nothing [Quick Heal] 2010-05-21 Found nothing [CPsecure] 2010-05-22 Found nothing [Sophos] 2010-05-22 Mal/Generic-L [Dr.Web] 2010-05-22 Trojan.Fakealert.15679 [VirusBlokAda VBA32] 2010-05-21 Found nothing [Frisk F-Prot Antivirus] 2010-05-21 Found nothing [VirusBuster] 2010-05-21 FraudTool.Agent.VUZM [F-Secure Anti-Virus] 2010-05-22 not-a-virus:FraudTool.Win32.Agent.asn Fvuvia.exe scan results [ArcaVir] 2010-05-21 Found nothing [G DATA] 2010-05-22 Gen:Variant.Renos.14 [Avast! antivirus] 2010-05-22 Win32:MalOb-AS [Ikarus] 2010-05-22 Found nothing [Grisoft AVG Anti-Virus] 2010-05-22 FakeAV.BPP [Kaspersky Anti-Virus] 2010-05-22 Found nothing [Avira AntiVir] 2010-05-21 TR/Fake.bpp.174592 [ESET NOD32] 2010-05-22 Win32/TrojanDownloader.FakeAlert.AQI [Softwin BitDefender] 2010-05-22 Gen:Variant.Renos.14 [Panda Antivirus] 2010-05-21 Adware/MSAntiSpyware2009 [ClamAV] 2010-05-22 Found nothing [Quick Heal] 2010-05-21 TrojanDownloader.Renos.kf [CPsecure] 2010-05-22 Found nothing [Sophos] 2010-05-22 Mal/FakeAV-CX [Dr.Web] 2010-05-22 Found nothing [VirusBlokAda VBA32] 2010-05-21 Found nothing [Frisk F-Prot Antivirus] 2010-05-21 Found nothing [VirusBuster] 2010-05-21 Trojan.Codecpack.Gen.6 [F-Secure Anti-Virus] 2010-05-22 Found nothing
Hi,

Please download this file, and save it to your Desktop. Once you have downloaded it, save and close all other programs and run it by double-clicking on the file named "RootRepeal.exe".

Once the main window shows up, please click on the "Report" button on the bottom of the window. Next, please click the "Scan" button.

Another window will pop up asking you to select what to include in the scan. Please uncheck everything except for the "Stealth Code" checkbox, and then click OK.

Once the program has finished scanning, the results will appear. Click on the "Save Report" button, and save the report to your desktop.

Finally, please open this report with Notepad, and post it here.

===================================================

Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

===================================================

On your next reply please post :
RootRepeal log
Combofix log

Good Day!
Rootrepeal log


ROOTREPEAL © AD, 2007-2010
==================================================
Report Save Time: 2010/05/24 16:08
Program Version: Version 2.0.0.0
Windows Version: Windows XP SP3
==================================================

STEALTH CODE
——————-





Combofix log


ComboFix 10-05-24.03 - John 05/24/2010 16:14:15.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1316 [GMT -4:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Avanquest SystemSuite *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
d:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
d:\documents and settings\John\Application Data\ATManager
d:\documents and settings\John\Application Data\ATManager\apmanager.exe
d:\documents and settings\John\Application Data\ATManager\files
d:\documents and settings\John\Application Data\ATManager\iplog
d:\documents and settings\John\Application Data\ATManager\ispinfo
d:\documents and settings\John\Application Data\ATManager\languages\Czech.lng
d:\documents and settings\John\Application Data\ATManager\languages\Danish.lng
d:\documents and settings\John\Application Data\ATManager\languages\Dutch.lng
d:\documents and settings\John\Application Data\ATManager\languages\English.lng
d:\documents and settings\John\Application Data\ATManager\languages\French.lng
d:\documents and settings\John\Application Data\ATManager\languages\German.lng
d:\documents and settings\John\Application Data\ATManager\languages\Italian.lng
d:\documents and settings\John\Application Data\ATManager\languages\Portuguese.lng
d:\documents and settings\John\Application Data\ATManager\languages\Slovak.lng
d:\documents and settings\John\Application Data\ATManager\languages\Spanish.lng
d:\documents and settings\John\Application Data\ATManager\languages\template.lng
d:\documents and settings\John\Application Data\ATManager\metafiles\e7e2135bcdfc87179deacdb1cdac8b7a.torrent
d:\documents and settings\John\Application Data\ATManager\settings.ini
d:\documents and settings\John\Application Data\ATManager\uninstall.exe
d:\documents and settings\John\Application Data\ATManager\wallpaper.jpg
d:\documents and settings\John\Application Data\mtl.dll
d:\documents and settings\John\Local Settings\Application Data\nsgsnudvf
d:\documents and settings\John\Local Settings\Application Data\nsgsnudvf\viwifsjtssd.exe
D:\install.exe
d:\windows\Fvuvia.exe
d:\windows\pthreadGC2.dll
d:\windows\system32\AbaleZip.dll

—– BITS: Possible infected sites —–

hxxp://download.yimg.com
.
((((((((((((((((((((((((( Files Created from 2010-04-24 to 2010-05-24 )))))))))))))))))))))))))))))))
.

2010-05-24 07:57 . 2010-05-24 07:57 ——– d—–w- d:\documents and settings\All Users\Application Data\Gosu
2010-05-22 13:36 . 2010-05-22 13:36 ——– d—–w- D:\_OTL
2010-05-20 01:15 . 2010-05-20 01:15 ——– d-sh–w- d:\documents and settings\Admin\IECompatCache
2010-05-16 00:15 . 2010-05-16 00:15 ——– d—–w- d:\documents and settings\Admin\Application Data\Avanquest
2010-05-15 01:17 . 2010-05-15 01:17 ——– d—–w- d:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-05-15 00:06 . 2010-05-15 00:06 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Google
2010-05-15 00:05 . 2010-05-15 00:05 ——– d—–w- d:\documents and settings\Admin\Application Data\Malwarebytes
2010-05-14 23:53 . 2010-05-14 23:53 ——– d—–w- D:\spoolerlogs
2010-05-14 23:46 . 2010-05-14 23:46 1882240 —-a-w- d:\windows\system32\download.exe
2010-05-14 23:46 . 2010-05-14 23:46 ——– d—–w- d:\documents and settings\John\Application Data\05797CE6939488349FA88E7597AA38E6
2010-05-14 23:46 . 2010-05-14 23:46 74240 —-a-w- d:\windows\system32\Spool\prtprocs\w32x86\b00004b82.dll
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\program files\Google
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\program files\DivX
2010-05-14 03:50 . 2010-05-14 03:50 144696 —-a-w- d:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\documents and settings\All Users\Application Data\DivX
2010-05-10 11:48 . 2010-05-10 11:48 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Apple
2010-05-10 00:13 . 2010-05-10 00:13 ——– d—–w- d:\documents and settings\All Users\Application Data\WEBREG
2010-05-09 06:54 . 2010-05-09 06:54 73304 —-a-w- d:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-08 15:21 . 2010-05-08 15:21 ——– d—–w- d:\documents and settings\Admin\Application Data\HP
2010-05-08 14:53 . 2010-05-08 14:53 ——– d—–w- d:\documents and settings\John\Application Data\HP
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\documents and settings\All Users\Application Data\HP Product Assistant
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\documents and settings\All Users\Application Data\HP
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\program files\Common Files\HP
2010-05-08 14:45 . 2010-05-08 14:46 ——– d—–w- d:\program files\HP
2010-05-08 14:37 . 2010-05-08 14:54 157204 —-a-w- d:\windows\hphins26.dat
2010-05-08 14:37 . 2007-12-13 00:01 787 ——w- d:\windows\hphmdl26.dat
2010-05-08 14:37 . 2010-05-08 14:37 ——– d—–w- d:\documents and settings\All Users\Application Data\Hewlett-Packard
2010-05-08 14:37 . 2007-11-08 14:59 271704 —-a-r- d:\windows\system32\hpzids01.dll
2010-05-08 14:37 . 2007-10-20 22:25 117760 —-a-w- d:\windows\system32\hpzll5mu.dll
2010-05-08 14:37 . 2007-10-20 22:21 278016 —-a-w- d:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2010-05-07 19:03 . 2010-05-07 19:03 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Mozilla
2010-05-07 13:14 . 2010-05-07 13:14 ——– d-sh–w- d:\documents and settings\Admin\PrivacIE
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Yahoo
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\AIM Toolbar
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Application Data\Yahoo!
2010-04-28 22:10 . 2010-04-28 22:10 50354 —-a-w- d:\documents and settings\John\Application Data\Facebook\uninstall.exe
2010-04-28 22:10 . 2010-04-28 22:10 ——– d—–w- d:\documents and settings\John\Application Data\Facebook

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-24 07:57 . 2009-09-16 17:02 ——– d—–w- d:\documents and settings\All Users\Application Data\MediaMall
2010-05-22 15:56 . 2009-04-07 10:29 ——– d—–w- d:\documents and settings\John\Application Data\uTorrent
2010-05-20 01:18 . 2010-02-19 12:37 ——– d—–w- d:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-05-16 00:30 . 2009-04-07 10:12 ——– d—–w- d:\windows\system32\config\systemprofile\Application Data\Avanquest
2010-05-14 03:56 . 2010-05-14 03:56 57344 —-a-w- d:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-14 03:51 . 2010-05-14 03:51 56766 —-a-w- d:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 56978 —-a-w- d:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 57409 —-a-w- d:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 53600 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 52963 —-a-w- d:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-14 03:50 . 2010-05-14 03:50 ——– d—–w- d:\program files\Common Files\DivX Shared
2010-05-14 03:50 . 2010-05-14 03:50 54073 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-14 03:50 . 2010-05-14 03:51 754984 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-04-27 19:51 . 2010-05-14 03:51 1180952 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-16 19:08 . 2010-01-22 20:40 ——– d—–w- d:\program files\Dragon Age
2010-04-05 22:32 . 2010-04-05 22:31 ——– d—–w- d:\program files\QuickTime
2010-04-05 22:31 . 2010-04-05 22:31 ——– d—–w- d:\documents and settings\All Users\Application Data\Apple Computer
2010-03-30 02:01 . 2009-04-07 10:29 ——– d—–w- d:\program files\uTorrent
2010-03-16 19:18 . 2010-03-18 22:49 52224 —-a-w- d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-03-16 19:18 . 2010-03-18 22:49 101376 —-a-w- d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
2010-03-06 05:30 . 2010-03-06 05:30 847040 —-a-w- d:\documents and settings\John\Application Data\Facebook\axfbootloader.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- d:\documents and settings\John\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-02-28 21:14 . 2010-02-28 21:14 1844 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Mp2 and BwfMp2 codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 1224 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Wave64 Codec.dat
2010-02-28 21:14 . 2010-02-28 21:13 510840 —-a-w- d:\windows\system32\SpoonUninstall.exe
2010-02-28 21:14 . 2010-02-28 21:14 2228 —-a-w- d:\windows\system32\SpoonUninstall-dBPoweramp tooLame MP2 codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 11473 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.dat
2010-02-28 21:14 . 2010-02-28 21:14 1206 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Dalet Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3008 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3065 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3153 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp mp3 (Fraunhofer IIS) Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3107 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 2987 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 2843 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp [Calculate Audio CRC] Codec.dat
2010-02-28 21:13 . 2010-02-28 21:13 11024 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat
2010-02-28 21:13 . 2010-02-28 21:13 15607 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2010-03-20 319792]
"SpybotSD TeaTimer"="d:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"PlayOn"="d:\program files\MediaMall\PlayOn.exe" [2009-11-23 53248]
"Messenger (Yahoo!)"="d:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"Launch LgDevAgt"="d:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2008-11-06 358920]
"Launch LCDMon"="d:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2008-11-06 1548296]
"Launch LGDCore"="d:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2008-11-06 2816520]
"AdobeCS4ServiceManager"="d:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"Orb"="d:\program files\Orb Networks\Orb\bin\OrbLauncher.exe" [2009-10-07 573904]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2010-03-18 421888]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - d:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Broadband Networking.lnk - d:\windows\Installer\{8CC15633-2327-43F4-BA85-B83FDB4B59BE}\_18be6784.exe [2009-7-4 25214]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNUtil.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNTray.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNCfg.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNUpdate.exe"=
"d:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"d:\\Program Files\\Velvet Assassin\\Launcher.exe"=
"d:\\Program Files\\Velvet Assassin\\replay.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbLauncher.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbSetupWizard.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbControlPanel.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"d:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"d:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"d:\\Program Files\\MediaMall\\MediaMallServer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
"56258:TCP"= 56258:TCP:Pando Media Booster
"56258:UDP"= 56258:UDP:Pando Media Booster

R0 hotcore3;Hotcore helper;d:\windows\system32\drivers\hotcore3.sys [4/7/2009 12:17 PM 40496]
R1 sbaphd;sbaphd;d:\windows\system32\drivers\sbaphd.sys [4/7/2009 6:12 AM 13360]
R1 sbtis;sbtis;d:\windows\system32\drivers\sbtis.sys [4/7/2009 9:58 AM 202928]
R2 MediaMall Server;MediaMall Server;d:\program files\MediaMall\MediaMallServer.exe [10/1/2009 9:24 AM 3013632]
R2 SBAMSvc;SystemSuite;d:\program files\Common Files\AntiVirus\SBAMSvc.exe [10/28/2008 4:28 PM 886056]
R2 sbapifs;sbapifs;d:\windows\system32\drivers\sbapifs.sys [4/7/2009 6:12 AM 68912]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;d:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
S3 asbp2poa;asbp2poa;\??\d:\docume~1\John\LOCALS~1\Temp\asbp2poa.sys –> d:\docume~1\John\LOCALS~1\Temp\asbp2poa.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12/15/2009 4:07 PM 25832]
S3 MailScan;MailScan;\??\d:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys –> d:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys [?]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;d:\windows\system32\drivers\RTL8187.sys [4/7/2009 5:42 AM 176128]
S3 SBRE;SBRE;d:\windows\system32\drivers\SBREDrv.sys [10/23/2008 4:09 AM 92464]
S3 SjyPkt;SjyPkt;d:\windows\system32\drivers\SjyPkt.sys [4/7/2009 5:42 AM 13532]
S3 TFilter;TFilter;d:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [9/22/2008 7:21 PM 20225]
S4 sptd;sptd;d:\windows\system32\drivers\sptd.sys [4/7/2009 11:56 AM 717296]
.
Contents of the 'Scheduled Tasks' folder

2010-05-24 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-05-24 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-05-14 03:50]

2010-05-24 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-05-14 03:50]

2010-05-24 d:\windows\Tasks\Orb Index when idle.job
- d:\program files\Orb Networks\Orb\bin\OrbLauncher.exe [2009-10-07 23:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Append Link Target to Existing PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&query;=
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: d:\program files\Avanquest\SystemSuite\Firefox3DV\components\VaultComponent.dll
FF - component: d:\program files\PayPal\PayPal Plug-In\components\PayPalPlugin.dll
FF - plugin: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Orb - d:\program files\Orb Networks\Orb\bin\OrbTray.exe
HKU-Default-RunOnce-FlashPlayerUpdate - d:\windows\system32\Macromed\Flash\FlashUtil10c.exe
AddRemove-Adobe_b2d6abde968e6f277ddbfd501383e02 - d:\program files\Common Files\Adobe\Installers\b2d6abde968e6f277ddbfd501383e02\Setup.exe
AddRemove-Army Men - d:\program files\The 3DO Company\Army Men\Uninst.isu
AddRemove-Playsushi - d:\program files\PlaySushi\psuninst.exe
AddRemove-{76E41F43-59D2-4F30-BA42-9A762EE1E8DE} - d:\program files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\setup.exe
AddRemove-{AF7733C1-FB0B-4FED-9730-E0433AF7A2EF} - d:\program files\InstallShield Installation Information\{AF7733C1-FB0B-4FED-9730-E0433AF7A2EF}\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-24 16:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a7,0c,9c,33,9c,4d,2a,4a,90,d0,89,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a7,0c,9c,33,9c,4d,2a,4a,90,d0,89,\

[HKEY_USERS\S-1-5-21-329068152-688789844-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2B791A15-425D-1A69-A4B8-722EBBC9915F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iadakihapnlihmgilb"=hex:6a,61,65,66,6c,67,6c,64,69,69,65,70,67,6f,64,6c,70,62,
64,6b,00,00
"habacbnaklmkmokf"=hex:6a,61,65,66,6c,67,6c,64,69,69,65,70,67,6f,64,6c,70,62,
64,6b,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(672)
d:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2010-05-24 16:21:36
ComboFix-quarantined-files.txt 2010-05-24 20:21

Pre-Run: 177,900,466,176 bytes free
Post-Run: 177,854,115,840 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(1)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 45B46979C2CA9B85D5D18694B7D519F9
Hi,

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
jotti.org
VirScan
Virus Total

click on Browse, and upload the following file for analysis:
d:\documents and settings\John\LOCAL settings\Temp\asbp2poa.sys
d:\program files\AVANQUEST\SYSTEM~1\MailScan.sys
d:\windows\system32\download.exe
d:\windows\system32\Spool\prtprocs\w32x86\b00004b82.dll


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

===================================================

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DirLook::
d:\documents and settings\John\Application Data\05797CE6939488349FA88E7597AA38E6


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

===================================================

On your next reply please post :
Online file anaylsis
Combofix log

Good Day!
Download.txt scan results

[ArcaVir]
2010-05-26 Fraudtool.Agent.Asn
[G DATA]
2010-05-26 Found nothing
[Avast! antivirus]
2010-05-26 Found nothing
[Ikarus]
2010-05-26 Trojan.PrivacyProtector
[Grisoft AVG Anti-Virus]
2010-05-26 Generic2_c.ABMP
[Kaspersky Anti-Virus]
2010-05-26 not-a-virus:FraudTool.Win32.Agent.asn
[Avira AntiVir]
2010-05-26 TR/DotTorrent.A.746
[ESET NOD32]
2010-05-26 Win32/Adware.Antipiracy
[Softwin BitDefender]
2010-05-26 Found nothing
[Panda Antivirus]
2010-05-26 Found nothing
[ClamAV]
2010-05-26 Found nothing
[Quick Heal]
2010-05-26 Found nothing
[CPsecure]
2010-05-26 FraudTool.W32.Agent.asn
[Sophos]
2010-05-26 Mal/Generic-L
[Dr.Web]
2010-05-26 Trojan.Fakealert.15679
[VirusBlokAda VBA32]
2010-05-26 Found nothing
[Frisk F-Prot Antivirus]
2010-05-26 Found nothing
[VirusBuster]
2010-05-26 FraudTool.Agent.VUZM
[F-Secure Anti-Virus]
2010-05-26 not-a-virus:FraudTool.Win32.Agent.asn




b00004b82 scan results

[ArcaVir]
2010-05-26 Found nothing
[G DATA]
2010-05-26 Gen:Variant.Alureon.2
[Avast! antivirus]
2010-05-26 Found nothing
[Ikarus]
2010-05-26 Trojan.Win32.Alureon
[Grisoft AVG Anti-Virus]
2010-05-26 Generic_r.DP
[Kaspersky Anti-Virus]
2010-05-26 Found nothing
[Avira AntiVir]
2010-05-26 Found nothing
[ESET NOD32]
2010-05-26 Win32/Kryptik.EJF
[Softwin BitDefender]
2010-05-26 Gen:Variant.Alureon.2
[Panda Antivirus]
2010-05-26 Found nothing
[ClamAV]
2010-05-26 Found nothing
[Quick Heal]
2010-05-26 Found nothing
[CPsecure]
2010-05-26 Found nothing
[Sophos]
2010-05-26 Sus/EncPk-PI
[Dr.Web]
2010-05-26 Found nothing
[VirusBlokAda VBA32]
2010-05-26 Found nothing
[Frisk F-Prot Antivirus]
2010-05-26 Found nothing
[VirusBuster]
2010-05-26 Found nothing
[F-Secure Anti-Virus]
2010-05-26 Found nothing

the othe files you asked me to scan were not there

Combofix log

ComboFix 10-05-26.01 - John 05/26/2010 16:10:19.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1307 [GMT -4:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\John\Desktop\CFScript.txt
AV: Avanquest SystemSuite *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
.

((((((((((((((((((((((((( Files Created from 2010-04-26 to 2010-05-26 )))))))))))))))))))))))))))))))
.

2010-05-26 16:18 . 2010-05-26 16:18 127903 —-a-w- d:\documents and settings\John\Application Data\Move Networks\uninstall.exe
2010-05-26 16:18 . 2010-05-26 16:18 1685856 —-a-w- d:\documents and settings\John\Application Data\Move Networks\MoveMediaPlayerWin_071502000008.exe
2010-05-26 07:57 . 2010-05-26 07:57 ——– d—–w- d:\documents and settings\All Users\Application Data\Gosu
2010-05-22 13:36 . 2010-05-22 13:36 ——– d—–w- D:\_OTL
2010-05-20 01:15 . 2010-05-20 01:15 ——– d-sh–w- d:\documents and settings\Admin\IECompatCache
2010-05-16 00:15 . 2010-05-16 00:15 ——– d—–w- d:\documents and settings\Admin\Application Data\Avanquest
2010-05-15 01:17 . 2010-05-15 01:17 ——– d—–w- d:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-05-15 00:06 . 2010-05-15 00:06 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Google
2010-05-15 00:05 . 2010-05-15 00:05 ——– d—–w- d:\documents and settings\Admin\Application Data\Malwarebytes
2010-05-14 23:53 . 2010-05-14 23:53 ——– d—–w- D:\spoolerlogs
2010-05-14 23:46 . 2010-05-14 23:46 1882240 —-a-w- d:\windows\system32\download.exe
2010-05-14 23:46 . 2010-05-14 23:46 ——– d—–w- d:\documents and settings\John\Application Data\05797CE6939488349FA88E7597AA38E6
2010-05-14 23:46 . 2010-05-14 23:46 74240 —-a-w- d:\windows\system32\Spool\prtprocs\w32x86\b00004b82.dll
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\program files\Google
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\program files\DivX
2010-05-14 03:50 . 2010-05-14 03:50 144696 —-a-w- d:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\documents and settings\All Users\Application Data\DivX
2010-05-10 11:48 . 2010-05-10 11:48 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Apple
2010-05-10 00:13 . 2010-05-10 00:13 ——– d—–w- d:\documents and settings\All Users\Application Data\WEBREG
2010-05-09 06:54 . 2010-05-09 06:54 73304 —-a-w- d:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-08 15:21 . 2010-05-08 15:21 ——– d—–w- d:\documents and settings\Admin\Application Data\HP
2010-05-08 14:53 . 2010-05-08 14:53 ——– d—–w- d:\documents and settings\John\Application Data\HP
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\documents and settings\All Users\Application Data\HP Product Assistant
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\documents and settings\All Users\Application Data\HP
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\program files\Common Files\HP
2010-05-08 14:45 . 2010-05-08 14:46 ——– d—–w- d:\program files\HP
2010-05-08 14:37 . 2010-05-08 14:54 157204 —-a-w- d:\windows\hphins26.dat
2010-05-08 14:37 . 2007-12-13 00:01 787 ——w- d:\windows\hphmdl26.dat
2010-05-08 14:37 . 2010-05-08 14:37 ——– d—–w- d:\documents and settings\All Users\Application Data\Hewlett-Packard
2010-05-08 14:37 . 2007-11-08 14:59 271704 —-a-r- d:\windows\system32\hpzids01.dll
2010-05-08 14:37 . 2007-10-20 22:25 117760 —-a-w- d:\windows\system32\hpzll5mu.dll
2010-05-08 14:37 . 2007-10-20 22:21 278016 —-a-w- d:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2010-05-07 19:03 . 2010-05-07 19:03 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Mozilla
2010-05-07 13:14 . 2010-05-07 13:14 ——– d-sh–w- d:\documents and settings\Admin\PrivacIE
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Yahoo
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\AIM Toolbar
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Application Data\Yahoo!
2010-04-28 22:10 . 2010-04-28 22:10 50354 —-a-w- d:\documents and settings\John\Application Data\Facebook\uninstall.exe
2010-04-28 22:10 . 2010-04-28 22:10 ——– d—–w- d:\documents and settings\John\Application Data\Facebook

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-26 19:54 . 2009-04-09 21:08 ——– d—–w- d:\documents and settings\John\Application Data\Move Networks
2010-05-26 16:18 . 2009-05-27 23:29 4183416 —-a-w- d:\documents and settings\John\Application Data\Move Networks\plugins\npqmp071502000008.dll
2010-05-26 07:57 . 2009-09-16 17:02 ——– d—–w- d:\documents and settings\All Users\Application Data\MediaMall
2010-05-25 19:57 . 2009-04-07 10:29 ——– d—–w- d:\documents and settings\John\Application Data\uTorrent
2010-05-20 01:18 . 2010-02-19 12:37 ——– d—–w- d:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-05-16 00:30 . 2009-04-07 10:12 ——– d—–w- d:\windows\system32\config\systemprofile\Application Data\Avanquest
2010-05-14 03:56 . 2010-05-14 03:56 57344 —-a-w- d:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-14 03:51 . 2010-05-14 03:51 56766 —-a-w- d:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 56978 —-a-w- d:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 57409 —-a-w- d:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 53600 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 52963 —-a-w- d:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-14 03:50 . 2010-05-14 03:50 ——– d—–w- d:\program files\Common Files\DivX Shared
2010-05-14 03:50 . 2010-05-14 03:50 54073 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-14 03:50 . 2010-05-14 03:51 754984 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-04-27 19:51 . 2010-05-14 03:51 1180952 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-16 19:08 . 2010-01-22 20:40 ——– d—–w- d:\program files\Dragon Age
2010-04-05 22:32 . 2010-04-05 22:31 ——– d—–w- d:\program files\QuickTime
2010-04-05 22:31 . 2010-04-05 22:31 ——– d—–w- d:\documents and settings\All Users\Application Data\Apple Computer
2010-03-30 02:01 . 2009-04-07 10:29 ——– d—–w- d:\program files\uTorrent
2010-03-16 19:18 . 2010-03-18 22:49 52224 —-a-w- d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-03-16 19:18 . 2010-03-18 22:49 101376 —-a-w- d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
2010-03-06 05:30 . 2010-03-06 05:30 847040 —-a-w- d:\documents and settings\John\Application Data\Facebook\axfbootloader.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- d:\documents and settings\John\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-02-28 21:14 . 2010-02-28 21:14 1844 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Mp2 and BwfMp2 codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 1224 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Wave64 Codec.dat
2010-02-28 21:14 . 2010-02-28 21:13 510840 —-a-w- d:\windows\system32\SpoonUninstall.exe
2010-02-28 21:14 . 2010-02-28 21:14 2228 —-a-w- d:\windows\system32\SpoonUninstall-dBPoweramp tooLame MP2 codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 11473 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.dat
2010-02-28 21:14 . 2010-02-28 21:14 1206 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Dalet Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3008 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3065 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3153 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp mp3 (Fraunhofer IIS) Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3107 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 2987 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 2843 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp [Calculate Audio CRC] Codec.dat
2010-02-28 21:13 . 2010-02-28 21:13 11024 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat
2010-02-28 21:13 . 2010-02-28 21:13 15607 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of d:\documents and settings\John\Application Data\05797CE6939488349FA88E7597AA38E6 —-



((((((((((((((((((((((((((((( SnapShot@2010-05-24_20.19.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-25 19:56 . 2010-05-25 19:56 16384 d:\windows\Temp\Perflib_Perfdata_6d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2010-03-20 319792]
"SpybotSD TeaTimer"="d:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"PlayOn"="d:\program files\MediaMall\PlayOn.exe" [2009-11-23 53248]
"Messenger (Yahoo!)"="d:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"Launch LgDevAgt"="d:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2008-11-06 358920]
"Launch LCDMon"="d:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2008-11-06 1548296]
"Launch LGDCore"="d:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2008-11-06 2816520]
"AdobeCS4ServiceManager"="d:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"Orb"="d:\program files\Orb Networks\Orb\bin\OrbLauncher.exe" [2009-10-07 573904]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2010-03-18 421888]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - d:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Broadband Networking.lnk - d:\windows\Installer\{8CC15633-2327-43F4-BA85-B83FDB4B59BE}\_18be6784.exe [2009-7-4 25214]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNUtil.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNTray.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNCfg.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNUpdate.exe"=
"d:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"d:\\Program Files\\Velvet Assassin\\Launcher.exe"=
"d:\\Program Files\\Velvet Assassin\\replay.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbLauncher.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbSetupWizard.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbControlPanel.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"d:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"d:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"d:\\Program Files\\MediaMall\\MediaMallServer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
"56258:TCP"= 56258:TCP:Pando Media Booster
"56258:UDP"= 56258:UDP:Pando Media Booster

R0 hotcore3;Hotcore helper;d:\windows\system32\drivers\hotcore3.sys [4/7/2009 12:17 PM 40496]
R1 sbaphd;sbaphd;d:\windows\system32\drivers\sbaphd.sys [4/7/2009 6:12 AM 13360]
R1 sbtis;sbtis;d:\windows\system32\drivers\sbtis.sys [4/7/2009 9:58 AM 202928]
R2 MediaMall Server;MediaMall Server;d:\program files\MediaMall\MediaMallServer.exe [10/1/2009 9:24 AM 3013632]
R2 SBAMSvc;SystemSuite;d:\program files\Common Files\AntiVirus\SBAMSvc.exe [10/28/2008 4:28 PM 886056]
R2 sbapifs;sbapifs;d:\windows\system32\drivers\sbapifs.sys [4/7/2009 6:12 AM 68912]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;d:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
S3 asbp2poa;asbp2poa;\??\d:\docume~1\John\LOCALS~1\Temp\asbp2poa.sys –> d:\docume~1\John\LOCALS~1\Temp\asbp2poa.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12/15/2009 4:07 PM 25832]
S3 MailScan;MailScan;\??\d:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys –> d:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys [?]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;d:\windows\system32\drivers\RTL8187.sys [4/7/2009 5:42 AM 176128]
S3 SBRE;SBRE;d:\windows\system32\drivers\SBREDrv.sys [10/23/2008 4:09 AM 92464]
S3 SjyPkt;SjyPkt;d:\windows\system32\drivers\SjyPkt.sys [4/7/2009 5:42 AM 13532]
S3 TFilter;TFilter;d:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [9/22/2008 7:21 PM 20225]
S4 sptd;sptd;d:\windows\system32\drivers\sptd.sys [4/7/2009 11:56 AM 717296]
.
Contents of the 'Scheduled Tasks' folder

2010-05-24 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-05-26 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-05-14 03:50]

2010-05-26 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-05-14 03:50]

2010-05-26 d:\windows\Tasks\Orb Index when idle.job
- d:\program files\Orb Networks\Orb\bin\OrbLauncher.exe [2009-10-07 23:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Append Link Target to Existing PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&query;=
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: d:\program files\Avanquest\SystemSuite\Firefox3DV\components\VaultComponent.dll
FF - component: d:\program files\PayPal\PayPal Plug-In\components\PayPalPlugin.dll
FF - plugin: d:\documents and settings\John\Application Data\Move Networks\plugins\npqmp071502000008.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-26 16:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a7,0c,9c,33,9c,4d,2a,4a,90,d0,89,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a7,0c,9c,33,9c,4d,2a,4a,90,d0,89,\

[HKEY_USERS\S-1-5-21-329068152-688789844-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2B791A15-425D-1A69-A4B8-722EBBC9915F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iadakihapnlihmgilb"=hex:6a,61,65,66,6c,67,6c,64,69,69,65,70,67,6f,64,6c,70,62,
64,6b,00,00
"habacbnaklmkmokf"=hex:6a,61,65,66,6c,67,6c,64,69,69,65,70,67,6f,64,6c,70,62,
64,6b,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(672)
d:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(2284)
d:\windows\system32\WININET.dll
d:\progra~1\AVANQU~1\SYSTEM~1\WinHook.dll
d:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
d:\progra~1\WINDOW~2\wmpband.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\wmp.dll
d:\windows\system32\wmploc.dll
d:\windows\system32\wmpps.dll
d:\windows\system32\jscript.dll
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-05-26 16:17:40
ComboFix-quarantined-files.txt 2010-05-26 20:17
ComboFix2.txt 2010-05-24 20:21

Pre-Run: 177,673,551,872 bytes free
Post-Run: 177,632,190,464 bytes free

- - End Of File - - 903F8F7E21B6CB4B2B43B13FD06EFE90
Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

http://forums.whatthetech.com/index.php?s=&showtopic=112103&view=findpost&p=655591

Driver::
asbp2poa

File::
d:\docume~1\John\LOCALS~1\Temp\asbp2poa.sys

Collect::
d:\windows\system32\download.exe
d:\windows\system32\Spool\prtprocs\w32x86\b00004b82.dll

Folder::
d:\documents and settings\John\Application Data\05797CE6939488349FA88E7597AA38E6


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]
Combofix.txt log


ComboFix 10-05-26.01 - John 05/27/2010 19:01:14.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1382 [GMT -4:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\John\Desktop\CFScript.txt
AV: Avanquest SystemSuite *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
* Created a new restore point

FILE ::
"d:\docume~1\John\LOCALS~1\Temp\asbp2poa.sys"

file zipped: d:\windows\system32\download.exe
file zipped: d:\windows\system32\Spool\prtprocs\w32x86\b00004b82.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\documents and settings\John\Application Data\05797CE6939488349FA88E7597AA38E6
d:\windows\system32\download.exe
d:\windows\system32\Spool\prtprocs\w32x86\b00004b82.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ASBP2POA
——-\Service_asbp2poa


((((((((((((((((((((((((( Files Created from 2010-04-27 to 2010-05-27 )))))))))))))))))))))))))))))))
.

2010-05-27 23:09 . 2010-05-27 23:09 ——– d—–w- d:\documents and settings\All Users\Application Data\Gosu
2010-05-22 13:36 . 2010-05-22 13:36 ——– d—–w- D:\_OTL
2010-05-20 01:15 . 2010-05-20 01:15 ——– d-sh–w- d:\documents and settings\Admin\IECompatCache
2010-05-16 00:15 . 2010-05-16 00:15 ——– d—–w- d:\documents and settings\Admin\Application Data\Avanquest
2010-05-15 01:17 . 2010-05-15 01:17 ——– d—–w- d:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-05-15 00:06 . 2010-05-15 00:06 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Google
2010-05-15 00:05 . 2010-05-15 00:05 ——– d—–w- d:\documents and settings\Admin\Application Data\Malwarebytes
2010-05-14 23:53 . 2010-05-14 23:53 ——– d—–w- D:\spoolerlogs
2010-05-14 03:50 . 2010-05-14 03:50 ——– d—–w- d:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-05-14 03:50 . 2010-05-14 03:55 ——– d—–w- d:\documents and settings\John\Local Settings\Application Data\Temp
2010-05-14 03:50 . 2010-05-14 03:50 ——– d—–w- d:\program files\Common Files\DivX Shared
2010-05-14 03:50 . 2010-05-14 03:56 ——– d—–w- d:\documents and settings\John\Local Settings\Application Data\Google
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\program files\Google
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\program files\DivX
2010-05-14 03:50 . 2010-05-14 03:51 ——– d—–w- d:\documents and settings\All Users\Application Data\DivX
2010-05-10 11:48 . 2010-05-10 11:48 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Apple
2010-05-10 00:13 . 2010-05-10 00:13 ——– d—–w- d:\documents and settings\All Users\Application Data\WEBREG
2010-05-09 06:54 . 2010-05-09 06:54 73304 —-a-w- d:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-08 15:21 . 2010-05-08 15:21 ——– d—–w- d:\documents and settings\Admin\Application Data\HP
2010-05-08 14:53 . 2010-05-08 14:53 ——– d—–w- d:\documents and settings\John\Application Data\HP
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\documents and settings\All Users\Application Data\HP Product Assistant
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\documents and settings\All Users\Application Data\HP
2010-05-08 14:46 . 2010-05-08 14:46 ——– d—–w- d:\program files\Common Files\HP
2010-05-08 14:45 . 2010-05-08 14:46 ——– d—–w- d:\program files\HP
2010-05-08 14:37 . 2010-05-08 14:54 157204 —-a-w- d:\windows\hphins26.dat
2010-05-08 14:37 . 2007-12-13 00:01 787 ——w- d:\windows\hphmdl26.dat
2010-05-08 14:37 . 2010-05-08 14:37 ——– d—–w- d:\documents and settings\All Users\Application Data\Hewlett-Packard
2010-05-08 14:37 . 2007-11-08 14:59 271704 —-a-r- d:\windows\system32\hpzids01.dll
2010-05-08 14:37 . 2007-10-20 22:25 117760 —-a-w- d:\windows\system32\hpzll5mu.dll
2010-05-08 14:37 . 2007-10-20 22:21 278016 —-a-w- d:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2010-05-07 19:03 . 2010-05-07 19:03 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Mozilla
2010-05-07 13:14 . 2010-05-07 13:14 ——– d-sh–w- d:\documents and settings\Admin\PrivacIE
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\Yahoo
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Local Settings\Application Data\AIM Toolbar
2010-05-07 13:14 . 2010-05-07 13:14 ——– d—–w- d:\documents and settings\Admin\Application Data\Yahoo!
2010-04-28 22:10 . 2010-04-28 22:10 ——– d—–w- d:\documents and settings\John\Application Data\Facebook

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-27 23:19 . 2009-04-07 10:29 ——– d—–w- d:\documents and settings\John\Application Data\uTorrent
2010-05-27 07:58 . 2009-09-16 17:02 ——– d—–w- d:\documents and settings\All Users\Application Data\MediaMall
2010-05-26 23:09 . 2010-04-28 22:10 50354 —-a-w- d:\documents and settings\John\Application Data\Facebook\uninstall.exe
2010-05-26 19:54 . 2009-04-09 21:08 ——– d—–w- d:\documents and settings\John\Application Data\Move Networks
2010-05-26 16:18 . 2010-05-26 16:18 127903 —-a-w- d:\documents and settings\John\Application Data\Move Networks\uninstall.exe
2010-05-26 16:18 . 2009-05-27 23:29 4183416 —-a-w- d:\documents and settings\John\Application Data\Move Networks\plugins\npqmp071502000008.dll
2010-05-26 16:18 . 2010-05-26 16:18 1685856 —-a-w- d:\documents and settings\John\Application Data\Move Networks\MoveMediaPlayerWin_071502000008.exe
2010-05-20 01:18 . 2010-02-19 12:37 ——– d—–w- d:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-05-16 00:30 . 2009-04-07 10:12 ——– d—–w- d:\windows\system32\config\systemprofile\Application Data\Avanquest
2010-05-14 03:56 . 2010-05-14 03:56 57344 —-a-w- d:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-14 03:51 . 2010-05-14 03:51 56766 —-a-w- d:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 56978 —-a-w- d:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 57409 —-a-w- d:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 53600 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-05-14 03:51 . 2010-05-14 03:51 52963 —-a-w- d:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-14 03:50 . 2010-05-14 03:50 54073 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-14 03:50 . 2010-05-14 03:50 144696 —-a-w- d:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-14 03:50 . 2010-05-14 03:51 754984 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-04-27 19:51 . 2010-05-14 03:51 1180952 —-a-w- d:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-16 19:08 . 2010-01-22 20:40 ——– d—–w- d:\program files\Dragon Age
2010-04-05 22:32 . 2010-04-05 22:31 ——– d—–w- d:\program files\QuickTime
2010-04-05 22:31 . 2010-04-05 22:31 ——– d—–w- d:\documents and settings\All Users\Application Data\Apple Computer
2010-03-30 02:01 . 2009-04-07 10:29 ——– d—–w- d:\program files\uTorrent
2010-03-16 19:18 . 2010-03-18 22:49 52224 —-a-w- d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-03-16 19:18 . 2010-03-18 22:49 101376 —-a-w- d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
2010-03-06 05:30 . 2010-03-06 05:30 847040 —-a-w- d:\documents and settings\John\Application Data\Facebook\axfbootloader.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- d:\documents and settings\John\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-02-28 21:14 . 2010-02-28 21:14 1844 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Mp2 and BwfMp2 codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 1224 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Wave64 Codec.dat
2010-02-28 21:14 . 2010-02-28 21:13 510840 —-a-w- d:\windows\system32\SpoonUninstall.exe
2010-02-28 21:14 . 2010-02-28 21:14 2228 —-a-w- d:\windows\system32\SpoonUninstall-dBPoweramp tooLame MP2 codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 11473 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.dat
2010-02-28 21:14 . 2010-02-28 21:14 1206 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Dalet Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3008 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3065 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3153 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp mp3 (Fraunhofer IIS) Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 3107 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 2987 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2010-02-28 21:14 . 2010-02-28 21:14 2843 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp [Calculate Audio CRC] Codec.dat
2010-02-28 21:13 . 2010-02-28 21:13 11024 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat
2010-02-28 21:13 . 2010-02-28 21:13 15607 —-a-w- d:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
.

((((((((((((((((((((((((((((( SnapShot@2010-05-24_20.19.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-27 23:09 . 2010-05-27 23:09 11214 d:\windows\Temp\res22-a.dat
+ 2010-05-27 23:09 . 2010-05-27 23:09 16384 d:\windows\Temp\Perflib_Perfdata_6b4.dat
+ 2010-05-27 03:06 . 2010-05-27 03:06 32768 d:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-07 08:54 . 2010-05-27 03:06 32768 d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-04-07 08:54 . 2010-05-16 00:30 32768 d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-05-27 03:06 . 2010-05-27 03:06 16384 d:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-04-07 08:54 . 2010-05-16 00:30 16384 d:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2010-03-20 319792]
"SpybotSD TeaTimer"="d:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"PlayOn"="d:\program files\MediaMall\PlayOn.exe" [2009-11-23 53248]
"Messenger (Yahoo!)"="d:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"Launch LgDevAgt"="d:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2008-11-06 358920]
"Launch LCDMon"="d:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2008-11-06 1548296]
"Launch LGDCore"="d:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2008-11-06 2816520]
"AdobeCS4ServiceManager"="d:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"Orb"="d:\program files\Orb Networks\Orb\bin\OrbLauncher.exe" [2009-10-07 573904]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2010-03-18 421888]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - d:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Broadband Networking.lnk - d:\windows\Installer\{8CC15633-2327-43F4-BA85-B83FDB4B59BE}\_18be6784.exe [2009-7-4 25214]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNUtil.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNTray.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNCfg.exe"=
"d:\\Program Files\\Microsoft Broadband Networking\\MSBNUpdate.exe"=
"d:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"d:\\Program Files\\Velvet Assassin\\Launcher.exe"=
"d:\\Program Files\\Velvet Assassin\\replay.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbLauncher.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbSetupWizard.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbControlPanel.exe"=
"d:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"d:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"d:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"d:\\Program Files\\MediaMall\\MediaMallServer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
"56258:TCP"= 56258:TCP:Pando Media Booster
"56258:UDP"= 56258:UDP:Pando Media Booster

R0 hotcore3;Hotcore helper;d:\windows\system32\drivers\hotcore3.sys [4/7/2009 12:17 PM 40496]
R1 sbaphd;sbaphd;d:\windows\system32\drivers\sbaphd.sys [4/7/2009 6:12 AM 13360]
R1 sbtis;sbtis;d:\windows\system32\drivers\sbtis.sys [4/7/2009 9:58 AM 202928]
R2 MediaMall Server;MediaMall Server;d:\program files\MediaMall\MediaMallServer.exe [10/1/2009 9:24 AM 3013632]
R2 SBAMSvc;SystemSuite;d:\program files\Common Files\AntiVirus\SBAMSvc.exe [10/28/2008 4:28 PM 886056]
R2 sbapifs;sbapifs;d:\windows\system32\drivers\sbapifs.sys [4/7/2009 6:12 AM 68912]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;d:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12/15/2009 4:07 PM 25832]
S3 MailScan;MailScan;\??\d:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys –> d:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys [?]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;d:\windows\system32\drivers\RTL8187.sys [4/7/2009 5:42 AM 176128]
S3 SBRE;SBRE;d:\windows\system32\drivers\SBREDrv.sys [10/23/2008 4:09 AM 92464]
S3 SjyPkt;SjyPkt;d:\windows\system32\drivers\SjyPkt.sys [4/7/2009 5:42 AM 13532]
S3 TFilter;TFilter;d:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [9/22/2008 7:21 PM 20225]
S4 sptd;sptd;d:\windows\system32\drivers\sptd.sys [4/7/2009 11:56 AM 717296]
.
Contents of the 'Scheduled Tasks' folder

2010-05-24 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-05-27 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-05-14 03:50]

2010-05-27 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-05-14 03:50]

2010-05-27 d:\windows\Tasks\Orb Index when idle.job
- d:\program files\Orb Networks\Orb\bin\OrbLauncher.exe [2009-10-07 23:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Append Link Target to Existing PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&query;=
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - component: d:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\efoa129p.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: d:\program files\Avanquest\SystemSuite\Firefox3DV\components\VaultComponent.dll
FF - component: d:\program files\PayPal\PayPal Plug-In\components\PayPalPlugin.dll
FF - plugin: d:\documents and settings\John\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: d:\documents and settings\John\Application Data\Move Networks\plugins\npqmp071502000008.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true.
- - - - ORPHANS REMOVED - - - -

BHO-{21608B66-026F-4DCB-9244-0DACA328DCED} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-27 19:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a7,0c,9c,33,9c,4d,2a,4a,90,d0,89,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a7,0c,9c,33,9c,4d,2a,4a,90,d0,89,\

[HKEY_USERS\S-1-5-21-329068152-688789844-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2B791A15-425D-1A69-A4B8-722EBBC9915F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iadakihapnlihmgilb"=hex:6a,61,65,66,6c,67,6c,64,69,69,65,70,67,6f,64,6c,70,62,
64,6b,00,00
"habacbnaklmkmokf"=hex:6a,61,65,66,6c,67,6c,64,69,69,65,70,67,6f,64,6c,70,62,
64,6b,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(676)
d:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(2480)
d:\windows\system32\WININET.dll
d:\progra~1\AVANQU~1\SYSTEM~1\WinHook.dll
d:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
d:\progra~1\WINDOW~2\wmpband.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
d:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
d:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\windows\system32\nvsvc32.exe
d:\program files\Orb Networks\Orb\bin\OrbMediaService.exe
d:\windows\system32\IoctlSvc.exe
d:\windows\system32\devldr32.exe
d:\progra~1\AVANQU~1\SYSTEM~1\MXTask.exe
d:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
d:\progra~1\AVANQU~1\SYSTEM~1\mxtask2.exe
d:\windows\system32\wscntfy.exe
d:\program files\Microsoft Broadband Networking\MSBNTray.exe
d:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
d:\program files\Orb Networks\Orb\bin\Orb.exe
.
**************************************************************************
.
Completion time: 2010-05-27 19:23:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-27 23:23
ComboFix2.txt 2010-05-26 20:17
ComboFix3.txt 2010-05-24 20:21

Pre-Run: 177,630,572,544 bytes free
Post-Run: 177,519,198,208 bytes free

- - End Of File - - EC98AA471EE1CFE95FDA7A11ABE1816D
Kaspersky Online Scanner in IE

I recommend you to leave your computer on for the whole night as the scanning will take longer than you expected.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Please go to Kaspersky website and click on Kaspersky Online Scanner to perform an online scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

    [external image: Posted Image]
  • Please post this log in your next reply.

**Note

For clearer guidance, here's the animated tutorial :-

Click here

To optimize scanning time and produce a more sensible report for review:
  • Close any open programs.
  • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan. Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

===================================================

Re-run Malwarebytes' Anti-Malware
  • Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
    • Go to Update tab to update Malwarebytes' Anti-Malware
  • Then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

Re-run OTL again and post it in your next reply without copy paste the custom scans given previously.

===================================================

On your next reply please post :
Kaspersky report
MBAM log
OTL log
How is the computer behaving now?

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI