This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help with this HijackThis Scan log

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello All,
I use opera and firefox as my browsers, and at some point the links i clicked on through firefox were being hijacked. Opera however remained unharm for a stretch, until it too became corrupted.

My HiJackThis log is posted below. Any help would be greatly appreciated!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:34:55 AM, on 6/11/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\StacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Razer\Krait\razerhid.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Razer\Krait\razerofa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Creative\MediaSource5\MtdAcqu.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5070117
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5070117
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://google.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 84.16.244.15 www.google.com
O1 - Hosts: 84.16.244.15 us.search.yahoo.com
O1 - Hosts: 84.16.244.15 uk.search.yahoo.com
O1 - Hosts: 84.16.244.15 search.yahoo.com
O1 - Hosts: 84.16.244.15 www.google.com.br
O1 - Hosts: 84.16.244.15 www.google.it
O1 - Hosts: 84.16.244.15 www.google.es
O1 - Hosts: 84.16.244.15 www.google.co.jp
O1 - Hosts: 84.16.244.15 www.google.com.mx
O1 - Hosts: 84.16.244.15 www.google.ca
O1 - Hosts: 84.16.244.15 www.google.com.au
O1 - Hosts: 84.16.244.15 www.google.nl
O1 - Hosts: 84.16.244.15 www.google.co.za
O1 - Hosts: 84.16.244.15 www.google.be
O1 - Hosts: 84.16.244.15 www.google.gr
O1 - Hosts: 84.16.244.15 www.google.at
O1 - Hosts: 84.16.244.15 www.google.se
O1 - Hosts: 84.16.244.15 www.google.ch
O1 - Hosts: 84.16.244.15 www.google.pt
O1 - Hosts: 84.16.244.15 www.google.dk
O1 - Hosts: 84.16.244.15 www.google.fi
O1 - Hosts: 84.16.244.15 www.google.ie
O1 - Hosts: 84.16.244.15 www.google.no
O1 - Hosts: 84.16.244.15 www.google.de
O1 - Hosts: 84.16.244.15 www.google.fr
O1 - Hosts: 84.16.244.15 www.google.co.uk
O1 - Hosts: 84.16.244.15 www.bing.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Krait] C:\Program Files\Razer\Krait\razerhid.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s
O4 - HKCU\..\Run: [50e417e0-e461-474b-96e2-077b80325612_35] rundll32.exe "C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_35.avi", start
O4 - HKUS\S-1-5-21-3491102713-3858514695-1758640463-1005\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User 'admin')
O4 - HKUS\S-1-5-21-3491102713-3858514695-1758640463-1005\..\Run: [SetDefaultMIDI] MIDIDef.exe (User 'admin')
O4 - HKUS\S-1-5-21-3491102713-3858514695-1758640463-1005\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe" /SCB (User 'admin')
O4 - HKUS\S-1-5-21-3491102713-3858514695-1758640463-1005\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'admin')
O4 - HKUS\S-1-5-21-3491102713-3858514695-1758640463-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'admin')
O4 - HKUS\S-1-5-21-3491102713-3858514695-1758640463-500\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User 'Administrator')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1239120594750
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nyscjc.local
O17 - HKLM\Software\..\Telephony: DomainName = nyscjc.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = nyscjc.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nyscjc.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nyscjc.local
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\0047.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 14828 bytes

Thanks for your time and assistance, and i look forward to hearing back from you.
Hello,

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 4 days) and you need an explanation. If that's the case, just send me a message on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /180
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:



Scanning with GMER

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)
3. The log that was produced after running GMER
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hi SweetTech,

Thanks for your help so far! Here are the requested logs:

Extras.TXT

OTL Extras logfile created on: 6/13/2010 3:16:01 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\sluo\Desktop\Warcraft III
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 578.00 Mb Available Physical Memory | 57.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.48 Gb Total Space | 29.38 Gb Free Space | 42.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SCJCNY-DCS8CDC1
Current User Name: sluo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AllAlertsDisabled" = 1
"TermService" = 1
"DisableMonitoring" = 1
"AntiVirusDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Symantec AntiVirus\Smc.exe" = C:\Program Files\Symantec AntiVirus\Smc.exe:*:Enabled:SMC Service – File not found
"C:\Program Files\Symantec AntiVirus\SNAC.EXE" = C:\Program Files\Symantec AntiVirus\SNAC.EXE:*:Enabled:SNAC Service – File not found
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dell\MediaDirect\PCMService.exe" = C:\Program Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program – (CyberLink Corp.)
"C:\Documents and Settings\sluo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" = C:\Documents and Settings\sluo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome – File not found
"C:\Program Files\Broodwar\starcraft.exe" = C:\Program Files\Broodwar\starcraft.exe:*:Enabled:Starcraft – (Blizzard Entertainment)
"C:\Program Files\Diablo\Diablo.exe" = C:\Program Files\Diablo\Diablo.exe:*:Enabled:Diablo – File not found
"C:\Program Files\Firaxis Games\Sid Meier's Alpha Centauri\terran.exe" = C:\Program Files\Firaxis Games\Sid Meier's Alpha Centauri\terran.exe:*:Enabled:terran – File not found
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper – (Microsoft Corporation)
"C:\Program Files\Garena\Garena.exe" = C:\Program Files\Garena\Garena.exe:*:Enabled:Garena – (Garena Online PTE LTD)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – (Flagship Industries, Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC – (mIRC Co. Ltd.)
"C:\Program Files\3DO\Heroes 3 Complete\HEROES3.ICD" = C:\Program Files\3DO\Heroes 3 Complete\HEROES3.ICD:*:Enabled:Heroes of Might and Magic® III – File not found
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Warcraft III\war3.exe" = C:\Program Files\Warcraft III\war3.exe:*:Enabled:Warcraft III – (Blizzard Entertainment)
"C:\Documents and Settings\sluo\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\sluo\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – File not found
"C:\Program Files\Steam\steamapps\[removed]\counter-strike\hl.exe" = C:\Program Files\Steam\steamapps\[removed]\counter-strike\hl.exe:*:Enabled:Half-Life Launcher – File not found
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\StarCraft II Beta\StarCraft II.exe" = C:\Program Files\StarCraft II Beta\StarCraft II.exe:*:Enabled:Blizzard Launcher – File not found
"C:\Program Files\StarCraft II Beta\Versions\Base15250\SC2.exe" = C:\Program Files\StarCraft II Beta\Versions\Base15250\SC2.exe:*:Enabled:StarCraft II – File not found
"C:\Program Files\StarCraft II Beta\Versions\Base14093\SC2.exe" = C:\Program Files\StarCraft II Beta\Versions\Base14093\SC2.exe:*:Enabled:StarCraft II – File not found
"C:\Games\StarCraft II Beta\StarCraft II.exe" = C:\Games\StarCraft II Beta\StarCraft II.exe:*:Enabled:Blizzard Launcher – File not found
"C:\Games\StarCraft II Beta\Versions\Base15250\SC2.exe" = C:\Games\StarCraft II Beta\Versions\Base15250\SC2.exe:*:Enabled:StarCraft II – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{21199F32-B676-4FE2-A443-EF7DB6B8FD4F}" = Opera 10.10
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 15
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46C73DE4-E96D-4F7C-8371-F28052183B12}" = Advanced Decoder Patch
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{64658686-0CD4-4CF6-983D-0A6BE32007DB}" = Business Complete Care Services Agreement
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8CD1F21C-D3A2-4B07-8493-31752E93A3E4}" = Skype Setup
"{8D2AE3F6-79DF-423C-91CB-389F6FB5837B}" = Andrea VoiceCenter
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B702CCCE-3176-4DBF-B932-D1B8F402F330}" = Digital Content Portal
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CEE2252C-4035-4B27-8EC6-0B085DD3A413}" = Dell Support 3.2.1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E6DA58C0-4EC5-4F5E-B73E-2F22ED30ACFC}" = Razer Krait
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Creative Audio Pack" = Creative Audio Pack
"CTMBDemo_Audigy" = Sound Blaster Audigy ADVANCED MB Demo
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DotA Client Build 2.4 Beta_is1" = DotA Client Build 2.4 Beta
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ForceBindIP" = ForceBindIP
"Garena" = Garena 2010
"ICCup Launcher_is1" = ICCup Launcher
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"LogMeIn Hamachi" = LogMeIn Hamachi
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"mIRC" = mIRC
"MIXERLITE" = Mixer
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ProInst" = Intel® PROSet/Wireless Software
"QcDrv" = Logitech® Camera Driver
"RealVNC_is1" = VNC Free Edition 4.1.1
"SAMB_ADVMB_FILTER_DRV" = Sound Blaster ADVANCED MB Drivers
"SearchAssist" = SearchAssist
"Sound Blaster Audigy ADVANCED MB Product Registration" = Sound Blaster Audigy ADVANCED MB Product Registration
"StarCraft Brood War by Monikon 1.16.1" = StarCraft Brood War by Monikon 1.16.1
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 4" = TeamViewer 4
"VLC media player" = VLC media player 1.0.2
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/12/2010 8:47:41 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/12/2010 8:47:41 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 6/12/2010 8:54:12 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/12/2010 8:54:12 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 6/12/2010 1:54:44 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/12/2010 1:54:44 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 6/13/2010 8:40:12 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/13/2010 8:40:12 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 6/13/2010 2:56:34 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/13/2010 2:56:34 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

[ Application Events ]
Error - 6/12/2010 8:47:41 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/12/2010 8:47:41 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 6/12/2010 8:54:12 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/12/2010 8:54:12 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 6/12/2010 1:54:44 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/12/2010 1:54:44 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 6/13/2010 8:40:12 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/13/2010 8:40:12 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 6/13/2010 2:56:34 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 6/13/2010 2:56:34 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

[ System Events ]
Error - 6/13/2010 8:40:13 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 6/13/2010 8:40:13 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 6/13/2010 8:55:17 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 6/13/2010 9:09:11 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 6/13/2010 9:09:15 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 6/13/2010 9:24:20 AM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 6/13/2010 2:56:33 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain nyscjc due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 6/13/2010 2:56:34 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 6/13/2010 2:56:34 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 6/13/2010 3:11:39 PM | Computer Name = SCJCNY-DCS8CDC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.


< End of report >
OTL.txt

OTL logfile created on: 6/13/2010 3:16:01 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\sluo\Desktop\Warcraft III
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 578.00 Mb Available Physical Memory | 57.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.48 Gb Total Space | 29.38 Gb Free Space | 42.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SCJCNY-DCS8CDC1
Current User Name: sluo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\sluo\Desktop\Warcraft III\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Razer\Krait\razerofa.exe (Razer Inc.)
PRC - C:\Program Files\Razer\Krait\razerhid.exe ()
PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Creative\MediaSource5\MtdAcqu.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\sluo\Desktop\Warcraft III\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\0047.DLL ()
MOD - C:\WINDOWS\system32\wsock32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Hamachi2Svc) – C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (STacSV) – C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)


========== Driver Services (SafeList) ==========

DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (LVUVC) QuickCam for Dell Notebooks(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (lvselsus) – C:\WINDOWS\system32\drivers\lvselsus.sys (Logitech Inc.)
DRV - (lvpopflt) – C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (lvmvdrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (Lvckap) – C:\WINDOWS\system32\drivers\Lvckap.sys ()
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (LVPrcMon) – C:\WINDOWS\system32\drivers\LVPrcMon.sys ()
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (DSproct) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (krait03) – C:\WINDOWS\system32\drivers\krait.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\WINDOWS\system32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (FsVga) – C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=5070117
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/hws/sb/dell-usuk-rel…html?channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=5070117

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=5070117
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk-rel…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/03 19:25:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/05 19:55:00 | 000,000,000 | —D | M]

[2009/11/08 22:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\Mozilla\Extensions
[2010/06/13 15:07:02 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\Mozilla\Firefox\Profiles\ccwh12un.default\extensions
[2009/11/10 15:17:35 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\sluo\Application Data\Mozilla\Firefox\Profiles\ccwh12un.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/03/27 20:41:34 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/06/13 15:06:52 | 000,000,765 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 84.16.244.15 www.google.com
O1 - Hosts: 84.16.244.15 us.search.yahoo.com
O1 - Hosts: 84.16.244.15 uk.search.yahoo.com
O1 - Hosts: 84.16.244.15 search.yahoo.com
O1 - Hosts: 84.16.244.15 www.google.com.br
O1 - Hosts: 84.16.244.15 www.google.it
O1 - Hosts: 84.16.244.15 www.google.es
O1 - Hosts: 84.16.244.15 www.google.co.jp
O1 - Hosts: 84.16.244.15 www.google.com.mx
O1 - Hosts: 84.16.244.15 www.google.ca
O1 - Hosts: 84.16.244.15 www.google.com.au
O1 - Hosts: 84.16.244.15 www.google.nl
O1 - Hosts: 84.16.244.15 www.google.co.za
O1 - Hosts: 84.16.244.15 www.google.be
O1 - Hosts: 84.16.244.15 www.google.gr
O1 - Hosts: 84.16.244.15 www.google.at
O1 - Hosts: 84.16.244.15 www.google.se
O1 - Hosts: 84.16.244.15 www.google.ch
O1 - Hosts: 84.16.244.15 www.google.pt
O1 - Hosts: 84.16.244.15 www.google.dk
O1 - Hosts: 84.16.244.15 www.google.fi
O1 - Hosts: 84.16.244.15 www.google.ie
O1 - Hosts: 84.16.244.15 www.google.no
O1 - Hosts: 84.16.244.15 www.google.de
O1 - Hosts: 84.16.244.15 www.google.fr
O1 - Hosts: 2 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Krait] C:\Program Files\Razer\Krait\razerhid.exe ()
O4 - HKLM..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe File not found
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [MtdAcqu] C:\Program Files\Creative\MediaSource5\MtdAcqu.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1239120594750 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nyscjc.local
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\0047.DLL) - C:\WINDOWS\system32\0047.DLL ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 19:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun
O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun
O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{3cb578ab-637d-11de-b894-00188bb24a3a}\Shell\AutoRun\command - "" = E:\sources\sperr32.exe – File not found
O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell - "" = AutoRun
O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\DTVP_Launcher.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/08/11 19:02:12 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56871556046913536)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/11 10:34:15 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/06/11 00:08:36 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/06/09 00:29:12 | 000,000,000 | —D | C] – C:\Program Files\Garena
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/13 15:16:54 | 000,000,765 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/13 15:16:53 | 000,045,290 | -HS- | M] () – C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_36.avi
[2010/06/13 14:56:45 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/13 14:56:44 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/13 14:56:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/13 14:56:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/13 14:56:19 | 1063,452,672 | -HS- | M] () – C:\hiberfil.sys
[2010/06/13 14:56:17 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/06/13 09:34:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/13 08:47:12 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\wupd.dat
[2010/06/12 17:50:30 | 004,456,448 | —- | M] () – C:\Documents and Settings\sluo\ntuser.dat
[2010/06/12 17:50:08 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\sluo\ntuser.ini
[2010/06/12 17:37:01 | 000,007,680 | —- | M] () – C:\Documents and Settings\sluo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/11 10:34:51 | 000,002,445 | —- | M] () – C:\Documents and Settings\sluo\Desktop\HiJackThis.lnk
[2010/06/11 03:22:29 | 000,286,112 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 03:05:58 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/09 00:29:22 | 000,000,654 | —- | M] () – C:\Documents and Settings\sluo\Desktop\Garena.lnk
[2010/06/04 02:21:15 | 000,118,185 | —- | M] () – C:\Documents and Settings\sluo\Desktop\week_1_anecdote.docx
[2010/05/27 23:30:28 | 000,037,376 | —- | M] () – C:\WINDOWS\System32\0047.DLL
[2010/05/27 23:30:27 | 000,043,008 | -H– | M] () – C:\WINDOWS\System32\wexe.exe
[2010/05/26 20:32:16 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0045.DLL
[2010/05/26 20:32:16 | 000,005,861 | —- | M] () – C:\WINDOWS\System32\WORK.DAT
[2010/05/25 23:23:39 | 000,025,600 | —- | M] () – C:\WINDOWS\System32\0041.DLL
[2010/05/22 17:52:55 | 006,867,008 | -H– | M] () – C:\Documents and Settings\sluo\Local Settings\Application Data\IconCache.db
[2010/05/17 07:52:00 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0042.DLL
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/13 08:57:01 | 000,045,290 | -HS- | C] () – C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_36.avi
[2010/06/09 00:29:22 | 000,000,654 | —- | C] () – C:\Documents and Settings\sluo\Desktop\Garena.lnk
[2010/06/04 02:21:15 | 000,118,185 | —- | C] () – C:\Documents and Settings\sluo\Desktop\week_1_anecdote.docx
[2010/05/27 23:30:28 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0047.DLL
[2010/05/25 23:23:38 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0041.DLL
[2010/05/24 17:35:09 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0045.DLL
[2010/05/17 07:52:00 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0042.DLL
[2010/02/22 02:44:04 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0035.DLL
[2010/02/10 04:04:39 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/01/02 01:23:55 | 000,000,876 | —- | C] () – C:\WINDOWS\System32\krl32mainweq.dll
[2010/01/02 01:23:03 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\H8SRTmkepjoaqok.dll
[2010/01/02 01:22:52 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\H8SRTjnkvdktlex.dll
[2010/01/02 01:22:39 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\H8SRTamixgiljwt.dll
[2009/11/23 19:23:32 | 000,000,347 | —- | C] () – C:\WINDOWS\CTWave32.INI
[2009/11/23 19:23:23 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2009/08/27 23:12:38 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/28 09:28:17 | 000,721,904 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/06/27 22:04:56 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2009/06/27 22:04:56 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2009/06/27 22:04:56 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2007/01/17 21:19:42 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/01/17 21:17:09 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/01/17 21:12:25 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/01/17 21:02:53 | 000,000,719 | R— | C] () – C:\WINDOWS\System32\InstExec.ini
[2007/01/17 21:02:46 | 000,042,594 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/01/17 21:00:14 | 000,000,040 | —- | C] () – C:\WINDOWS\System32\mes2046.dll
[2007/01/17 20:59:55 | 000,022,629 | —- | C] () – C:\WINDOWS\System32\CiFilter.ini
[2007/01/17 20:34:30 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2007/01/17 20:33:23 | 000,000,386 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/17 16:51:48 | 001,678,368 | —- | C] () – C:\WINDOWS\System32\drivers\Lvckap.sys
[2006/05/04 11:07:38 | 000,016,768 | —- | C] () – C:\WINDOWS\System32\drivers\LVPrcMon.sys
[2005/11/10 03:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/11 19:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 19:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini

========== LOP Check ==========

[2009/07/04 23:30:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/06/28 09:32:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010/02/23 00:22:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/09/18 12:49:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/07/04 23:31:28 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\DAEMON Tools Lite
[2009/06/28 09:36:58 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\DAEMON Tools Pro
[2009/07/04 23:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\Leadertech
[2010/02/25 01:20:55 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\Opera
[2009/06/30 20:41:49 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\TeamViewer

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/11 19:15:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/09/18 11:37:46 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2009/04/19 18:01:03 | 000,547,496 | —- | M] (Google Inc.) – C:\ChromeSetup.exe
[2004/08/11 19:15:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/01/17 20:37:46 | 000,006,496 | RH– | M] () – C:\dell.sdr
[2009/07/06 22:02:01 | 021,128,536 | —- | M] (DivX, Inc.) – C:\DivXInstaller.exe
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/06/13 14:56:19 | 1063,452,672 | -HS- | M] () – C:\hiberfil.sys
[2008/09/18 11:16:38 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2004/08/11 19:15:00 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2004/08/11 19:15:00 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/18 12:24:37 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/06/13 14:56:17 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2009/04/07 13:25:45 | 078,424,937 | —- | M] () – C:\setup.exe
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2010/01/24 18:02:19 | 003,823,704 | —- | M] () – C:\veetle-0.9.15.exe
[2009/11/10 16:12:37 | 000,000,000 | —- | M] () – C:\wang_lee_hom_Da_Cheng_Xiao_Ai__Big_City__Little_Love_.mp3
[2009/11/10 16:13:01 | 006,137,344 | —- | M] () – C:\____-__________2__KTV__________.mp3

< %systemroot%\*. /mp /s >

< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 20:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 20:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004/08/11 19:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/11 19:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/11 19:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /180 >
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2009/12/31 12:50:03 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\srv.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

========== Files - Unicode (All) ==========
[2008/09/22 17:01:16 | 000,897,536 | —- | C] ()(C:\Documents and Settings\sluo\My Documents\???1.pps) – C:\Documents and Settings\sluo\My Documents\平安夜1.pps
[2006/12/22 10:26:40 | 000,897,536 | —- | M] ()(C:\Documents and Settings\sluo\My Documents\???1.pps) – C:\Documents and Settings\sluo\My Documents\平安夜1.pps

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
gmer.log

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-13 17:01:59
Windows 5.1.2600 Service Pack 3
Running: hmxqgzdj.exe; Driver: C:\DOCUME~1\sluo\LOCALS~1\Temp\ugryqfog.sys


—- System - GMER 1.0.15 —-

SSDT spdp.sys ZwCreateKey [0xF747D0E0]
SSDT spdp.sys ZwEnumerateKey [0xF749BCA4]
SSDT spdp.sys ZwEnumerateValueKey [0xF749C032]
SSDT spdp.sys ZwOpenKey [0xF747D0C0]
SSDT spdp.sys ZwQueryKey [0xF749C10A]
SSDT spdp.sys ZwQueryValueKey [0xF749BF8A]
SSDT spdp.sys ZwSetValueKey [0xF749C19C]

INT 0x62 ? 87168BF8
INT 0x74 ? 86ECEBF8
INT 0x82 ? 87168BF8
INT 0x84 ? 86ECEBF8
INT 0x94 ? 86ECEBF8

—- Kernel code sections - GMER 1.0.15 —-

? spdp.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F66928AC 5 Bytes JMP 86ECE1D8
.text a447i39c.SYS F6590386 35 Bytes [00, 00, 00, 00, 00, 00, 20, …]
.text a447i39c.SYS F65903AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text a447i39c.SYS F65903C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text a447i39c.SYS F65903C9 1 Byte [30]
.text a447i39c.SYS F65903C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, …] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text …
init C:\WINDOWS\system32\drivers\monfilt.sys entry point in "init" section [0xAA5E6280]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[2844] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2844] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DE7E48 C:\WINDOWS\system32\0047.DLL
.text C:\Program Files\Mozilla Firefox\firefox.exe[2844] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DE7AF4 C:\WINDOWS\system32\0047.DLL

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F747E042] spdp.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F747E13E] spdp.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F747E0C0] spdp.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F747E800] spdp.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F747E6D6] spdp.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F748DE9C] spdp.sys
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!READ_PORT_UCHAR] 1C8D9E88
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!KfRaiseIrql] 00001CA9
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!HalTranslateBusAddress] 8186C636
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!KfReleaseSpinLock] 1C8386C6
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!READ_PORT_USHORT] 001C8E86
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CAA
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\a447i39c.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB19E

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 871671F8

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\usbuhci \Device\USBPDO-0 86F841F8
Device \Driver\usbuhci \Device\USBPDO-1 86F841F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 871D81F8
Device \Driver\dmio \Device\DmControl\DmConfig 871D81F8
Device \Driver\dmio \Device\DmControl\DmPnP 871D81F8
Device \Driver\dmio \Device\DmControl\DmInfo 871D81F8
Device \Driver\usbuhci \Device\USBPDO-2 86F841F8
Device \Driver\usbuhci \Device\USBPDO-3 86F841F8
Device \Driver\usbehci \Device\USBPDO-4 86EB71F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 871691F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 871691F8
Device \Driver\Cdrom \Device\CdRom0 86E64500
Device \Driver\Cdrom \Device\CdRom1 86E64500
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F73D1B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F73D1B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F73D1B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F73D1B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 871691F8
Device \Driver\Ftdisk \Device\HarddiskVolume4 871691F8
Device \Driver\sptd \Device\202651928 spdp.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{AAD5AD08-480D-4A5D-A315-49D2B62D7A8E} 85D79368
Device \Driver\NetBT \Device\NetBt_Wins_Export 85D79368
Device \Driver\NetBT \Device\NetbiosSmb 85D79368
Device \Driver\PCI_PNP3178 \Device\0000004e spdp.sys
Device \Driver\usbuhci \Device\USBFDO-0 86F841F8
Device \Driver\usbuhci \Device\USBFDO-1 86F841F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 85CCF368
Device \Driver\usbuhci \Device\USBFDO-2 86F841F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{CA1A1DEC-9AEA-4150-96EB-D2C61FDE6664} 85D79368
Device \FileSystem\MRxSmb \Device\LanmanRedirector 85CCF368
Device \Driver\usbuhci \Device\USBFDO-3 86F841F8
Device \Driver\usbehci \Device\USBFDO-4 86EB71F8
Device \Driver\Ftdisk \Device\FtControl 871691F8
Device \Driver\a447i39c \Device\Scsi\a447i39c1 86F1D500
Device \Driver\a447i39c \Device\Scsi\a447i39c1Port2Path0Target0Lun0 86F1D500
Device \FileSystem\Fastfat \Fat 85DA9500
Device \FileSystem\Fastfat \Fat A83F1297

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 86E68500
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTycpylvmpfv.sys
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTycpylvmpfv.sys
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTamixgiljwt.dll
Reg HKLM\SYSTEM\ControlSet001\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTkdwtaelrbq.dat
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xB4 0x6D 0x90 0x02 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0xE6 0xF8 0x4A …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xB1 0xFF 0x5A 0x90 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x6A 0x18 0x5F 0xC4 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xB4 0x6D 0x90 0x02 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0xE6 0xF8 0x4A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xB1 0xFF 0x5A 0x90 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xCB 0x72 0xBE 0x94 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xB4 0x6D 0x90 0x02 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0xE6 0xF8 0x4A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xB1 0xFF 0x5A 0x90 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xCB 0x72 0xBE 0x94 …

—- EOF - GMER 1.0.15 —-
Those are the logs. My links are still being hijacked, and for some reason I can no longer access gmail on either of my browsers. When I attempt to do so the following error message pops up: Not Found The requested URL /accounts/ServiceLogin was not found on this server. Apache/2.2.3 (CentOS) Server at www.google.com Port 443 I suspect that this is probably related to the malware issue! Any additional comments or suggestions are greatly appreciated. Thanks again for your time!
Hello,

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    MOD - C:\WINDOWS\system32\0047.DLL ()
    IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [KernelFaultCheck] File not found
    O20 - AppInit_DLLs: (C:\WINDOWS\system32\0047.DLL) - C:\WINDOWS\system32\0047.DLL ()
    O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
    O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun
    O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun
    O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{3cb578ab-637d-11de-b894-00188bb24a3a}\Shell\AutoRun\command - "" = E:\sources\sperr32.exe – File not found
    O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell - "" = AutoRun
    O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\DTVP_Launcher.exe – File not found
    [2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2010/06/13 15:16:53 | 000,045,290 | -HS- | M] () – C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_36.avi
    [2010/05/27 23:30:27 | 000,043,008 | -H– | M] () – C:\WINDOWS\System32\wexe.exe
    [2010/05/26 20:32:16 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0045.DLL
    [2010/05/26 20:32:16 | 000,005,861 | —- | M] () – C:\WINDOWS\System32\WORK.DAT
    [2010/05/25 23:23:39 | 000,025,600 | —- | M] () – C:\WINDOWS\System32\0041.DLL
    [2010/05/17 07:52:00 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0042.DLL
    [2010/05/27 23:30:28 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0047.DLL
    [2010/05/25 23:23:38 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0041.DLL
    [2010/05/24 17:35:09 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0045.DLL
    [2010/05/17 07:52:00 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0042.DLL
    [2010/02/22 02:44:04 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0035.DLL
    [2010/01/02 01:23:55 | 000,000,876 | —- | C] () – C:\WINDOWS\System32\krl32mainweq.dll
    [2010/01/02 01:23:03 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\H8SRTmkepjoaqok.dll
    [2010/01/02 01:22:52 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\H8SRTjnkvdktlex.dll
    [2010/01/02 01:22:39 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\H8SRTamixgiljwt.dll
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
hi sweet, sorry i have had a hectic schedule and have not gotten around to applying the steps in your latest post. i will do so as soon as possible (likely tomorrow or wednesday), just letting you know so this doesn't get deleted! thanks
here is the latest OTL report:

OTL logfile created on: 6/17/2010 11:58:33 PM - Run 2
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\sluo\Desktop\Warcraft III
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 535.00 Mb Available Physical Memory | 53.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.48 Gb Total Space | 29.29 Gb Free Space | 42.16% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SCJCNY-DCS8CDC1
Current User Name: sluo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\sluo\Desktop\Warcraft III\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Razer\Krait\razerofa.exe (Razer Inc.)
PRC - C:\Program Files\Razer\Krait\razerhid.exe ()
PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Creative\MediaSource5\MtdAcqu.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\sluo\Desktop\Warcraft III\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\0047.DLL ()
MOD - C:\WINDOWS\system32\wsock32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Hamachi2Svc) – C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (STacSV) – C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)


========== Driver Services (SafeList) ==========

DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (LVUVC) QuickCam for Dell Notebooks(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (lvselsus) – C:\WINDOWS\system32\drivers\lvselsus.sys (Logitech Inc.)
DRV - (lvpopflt) – C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (lvmvdrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (Lvckap) – C:\WINDOWS\system32\drivers\Lvckap.sys ()
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (LVPrcMon) – C:\WINDOWS\system32\drivers\LVPrcMon.sys ()
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (DSproct) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (krait03) – C:\WINDOWS\system32\drivers\krait.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\WINDOWS\system32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (FsVga) – C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=5070117
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/hws/sb/dell-usuk-rel…html?channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=5070117

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=5070117
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk-rel…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/03 19:25:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/05 19:55:00 | 000,000,000 | —D | M]

[2009/11/08 22:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\Mozilla\Extensions
[2010/06/16 23:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\sluo\Application Data\Mozilla\Firefox\Profiles\ccwh12un.default\extensions
[2009/11/10 15:17:35 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\sluo\Application Data\Mozilla\Firefox\Profiles\ccwh12un.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/03/27 20:41:34 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/06/17 23:54:20 | 000,000,765 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 84.16.244.15 www.google.com
O1 - Hosts: 84.16.244.15 us.search.yahoo.com
O1 - Hosts: 84.16.244.15 uk.search.yahoo.com
O1 - Hosts: 84.16.244.15 search.yahoo.com
O1 - Hosts: 84.16.244.15 www.google.com.br
O1 - Hosts: 84.16.244.15 www.google.it
O1 - Hosts: 84.16.244.15 www.google.es
O1 - Hosts: 84.16.244.15 www.google.co.jp
O1 - Hosts: 84.16.244.15 www.google.com.mx
O1 - Hosts: 84.16.244.15 www.google.ca
O1 - Hosts: 84.16.244.15 www.google.com.au
O1 - Hosts: 84.16.244.15 www.google.nl
O1 - Hosts: 84.16.244.15 www.google.co.za
O1 - Hosts: 84.16.244.15 www.google.be
O1 - Hosts: 84.16.244.15 www.google.gr
O1 - Hosts: 84.16.244.15 www.google.at
O1 - Hosts: 84.16.244.15 www.google.se
O1 - Hosts: 84.16.244.15 www.google.ch
O1 - Hosts: 84.16.244.15 www.google.pt
O1 - Hosts: 84.16.244.15 www.google.dk
O1 - Hosts: 84.16.244.15 www.google.fi
O1 - Hosts: 84.16.244.15 www.google.ie
O1 - Hosts: 84.16.244.15 www.google.no
O1 - Hosts: 84.16.244.15 www.google.de
O1 - Hosts: 84.16.244.15 www.google.fr
O1 - Hosts: 2 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [Krait] C:\Program Files\Razer\Krait\razerhid.exe ()
O4 - HKLM..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe File not found
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [MtdAcqu] C:\Program Files\Creative\MediaSource5\MtdAcqu.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1239120594750 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nyscjc.local
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\0047.DLL) - C:\WINDOWS\system32\0047.DLL ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 19:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun
O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun
O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{3cb578ab-637d-11de-b894-00188bb24a3a}\Shell\AutoRun\command - "" = E:\sources\sperr32.exe – File not found
O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell - "" = AutoRun
O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\DTVP_Launcher.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/17 23:25:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Camera Bits, Inc
[2010/06/17 23:24:52 | 000,000,000 | —D | C] – C:\Documents and Settings\sluo\Application Data\Camera Bits, Inc
[2010/06/17 23:24:36 | 000,090,112 | —- | C] (MindVision Software) – C:\WINDOWS\unvise32.exe
[2010/06/17 23:24:13 | 000,000,000 | —D | C] – C:\Program Files\Camera Bits
[2010/06/11 10:34:15 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/06/11 00:08:36 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/06/09 00:29:12 | 000,000,000 | —D | C] – C:\Program Files\Garena
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/17 23:54:22 | 000,045,287 | -HS- | M] () – C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_38.avi
[2010/06/17 23:54:20 | 000,000,765 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/17 23:47:48 | 004,456,448 | —- | M] () – C:\Documents and Settings\sluo\ntuser.dat
[2010/06/17 23:40:03 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/17 23:40:02 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/17 23:24:14 | 000,000,818 | —- | M] () – C:\Documents and Settings\sluo\Desktop\Photo Mechanic 4.6.lnk
[2010/06/17 23:23:20 | 027,452,240 | —- | M] () – C:\Documents and Settings\sluo\My Documents\PMSetup4.6.4.exe
[2010/06/17 23:15:15 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\wupd.dat
[2010/06/17 23:14:06 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/17 23:13:47 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/17 23:13:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/17 23:13:41 | 1063,452,672 | -HS- | M] () – C:\hiberfil.sys
[2010/06/17 23:13:40 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/06/17 17:09:19 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\sluo\ntuser.ini
[2010/06/12 17:37:01 | 000,007,680 | —- | M] () – C:\Documents and Settings\sluo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/11 10:34:51 | 000,002,445 | —- | M] () – C:\Documents and Settings\sluo\Desktop\HiJackThis.lnk
[2010/06/11 03:22:29 | 000,286,112 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 03:05:58 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/09 00:29:22 | 000,000,654 | —- | M] () – C:\Documents and Settings\sluo\Desktop\Garena.lnk
[2010/06/04 02:21:15 | 000,118,185 | —- | M] () – C:\Documents and Settings\sluo\Desktop\week_1_anecdote.docx
[2010/05/27 23:30:28 | 000,037,376 | —- | M] () – C:\WINDOWS\System32\0047.DLL
[2010/05/27 23:30:27 | 000,043,008 | -H– | M] () – C:\WINDOWS\System32\wexe.exe
[2010/05/26 20:32:16 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0045.DLL
[2010/05/26 20:32:16 | 000,005,861 | —- | M] () – C:\WINDOWS\System32\WORK.DAT
[2010/05/25 23:23:39 | 000,025,600 | —- | M] () – C:\WINDOWS\System32\0041.DLL
[2010/05/22 17:52:55 | 006,867,008 | -H– | M] () – C:\Documents and Settings\sluo\Local Settings\Application Data\IconCache.db
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/17 23:24:14 | 000,000,818 | —- | C] () – C:\Documents and Settings\sluo\Desktop\Photo Mechanic 4.6.lnk
[2010/06/17 23:24:12 | 000,045,287 | -HS- | C] () – C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_38.avi
[2010/06/17 23:20:43 | 027,452,240 | —- | C] () – C:\Documents and Settings\sluo\My Documents\PMSetup4.6.4.exe
[2010/06/09 00:29:22 | 000,000,654 | —- | C] () – C:\Documents and Settings\sluo\Desktop\Garena.lnk
[2010/06/04 02:21:15 | 000,118,185 | —- | C] () – C:\Documents and Settings\sluo\Desktop\week_1_anecdote.docx
[2010/05/27 23:30:28 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0047.DLL
[2010/05/25 23:23:38 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0041.DLL
[2010/05/24 17:35:09 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0045.DLL
[2010/05/17 07:52:00 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0042.DLL
[2010/03/25 08:48:18 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\SDL.dll
[2010/02/22 02:44:04 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0035.DLL
[2010/02/10 04:04:39 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/01/02 01:23:55 | 000,000,876 | —- | C] () – C:\WINDOWS\System32\krl32mainweq.dll
[2010/01/02 01:23:03 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\H8SRTmkepjoaqok.dll
[2010/01/02 01:22:52 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\H8SRTjnkvdktlex.dll
[2010/01/02 01:22:39 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\H8SRTamixgiljwt.dll
[2009/11/23 19:23:32 | 000,000,347 | —- | C] () – C:\WINDOWS\CTWave32.INI
[2009/11/23 19:23:23 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2009/08/27 23:12:38 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/28 09:28:17 | 000,721,904 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/06/27 22:04:56 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2009/06/27 22:04:56 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2009/06/27 22:04:56 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2007/01/17 21:19:42 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/01/17 21:17:09 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/01/17 21:12:25 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/01/17 21:02:53 | 000,000,719 | R— | C] () – C:\WINDOWS\System32\InstExec.ini
[2007/01/17 21:02:46 | 000,042,594 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/01/17 21:00:14 | 000,000,040 | —- | C] () – C:\WINDOWS\System32\mes2046.dll
[2007/01/17 20:59:55 | 000,022,629 | —- | C] () – C:\WINDOWS\System32\CiFilter.ini
[2007/01/17 20:34:30 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2007/01/17 20:33:23 | 000,000,386 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/17 16:51:48 | 001,678,368 | —- | C] () – C:\WINDOWS\System32\drivers\Lvckap.sys
[2006/05/04 11:07:38 | 000,016,768 | —- | C] () – C:\WINDOWS\System32\drivers\LVPrcMon.sys
[2005/11/10 03:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/11 19:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 19:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini

========== Custom Scans ==========


< :Services >

< :OTL >

< MOD - C:\WINDOWS\system32\0047.DLL () >

< IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found >

< O4 - HKLM..\Run: [] File not found >

< O4 - HKLM..\Run: [KernelFaultCheck] File not found >

< O20 - AppInit_DLLs: (C:\WINDOWS\system32\0047.DLL) - C:\WINDOWS\system32\0047.DLL () >

< O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found >

< O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun >

< O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play; >

< O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found >

< O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun >

< O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play; >

< O33 - MountPoints2\{3cb578ab-637d-11de-b894-00188bb24a3a}\Shell\AutoRun\command - "" = E:\sources\sperr32.exe – File not found >

< O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell - "" = AutoRun >

< O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play; >

< O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\DTVP_Launcher.exe – File not found >

< [2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] >

< [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] >

< [2010/06/13 15:16:53 | 000,045,290 | -HS- | M] () – C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_36.avi >
Invalid Switch: 13 15:16:53 | 000,045,290 | -HS- | M] () – C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_36.avi

< [2010/05/27 23:30:27 | 000,043,008 | -H– | M] () – C:\WINDOWS\System32\wexe.exe >
Invalid Switch: 27 23:30:27 | 000,043,008 | -H– | M] () – C:\WINDOWS\System32\wexe.exe


< [2010/05/26 20:32:16 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0045.DLL >
Invalid Switch: 26 20:32:16 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0045.DLL


< [2010/05/26 20:32:16 | 000,005,861 | —- | M] () – C:\WINDOWS\System32\WORK.DAT >
Invalid Switch: 26 20:32:16 | 000,005,861 | —- | M] () – C:\WINDOWS\System32\WORK.DAT


< [2010/05/25 23:23:39 | 000,025,600 | —- | M] () – C:\WINDOWS\System32\0041.DLL >
Invalid Switch: 25 23:23:39 | 000,025,600 | —- | M] () – C:\WINDOWS\System32\0041.DLL


< [2010/05/17 07:52:00 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0042.DLL >
Invalid Switch: 17 07:52:00 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0042.DLL


< [2010/05/27 23:30:28 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0047.DLL >
Invalid Switch: 27 23:30:28 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0047.DLL


< [2010/05/25 23:23:38 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0041.DLL >
Invalid Switch: 25 23:23:38 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0041.DLL


< [2010/05/24 17:35:09 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0045.DLL >
Invalid Switch: 24 17:35:09 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0045.DLL


< [2010/05/17 07:52:00 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0042.DLL >
Invalid Switch: 17 07:52:00 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0042.DLL


< [2010/02/22 02:44:04 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0035.DLL >
Invalid Switch: 22 02:44:04 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0035.DLL


< [2010/01/02 01:23:55 | 000,000,876 | —- | C] () – C:\WINDOWS\System32\krl32mainweq.dll >
Invalid Switch: 02 01:23:55 | 000,000,876 | —- | C] () – C:\WINDOWS\System32\krl32mainweq.dll


< [2010/01/02 01:23:03 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\H8SRTmkepjoaqok.dll >
Invalid Switch: 02 01:23:03 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\H8SRTmkepjoaqok.dll


< [2010/01/02 01:22:52 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\H8SRTjnkvdktlex.dll >
Invalid Switch: 02 01:22:52 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\H8SRTjnkvdktlex.dll


< [2010/01/02 01:22:39 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\H8SRTamixgiljwt.dll >
Invalid Switch: 02 01:22:39 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\H8SRTamixgiljwt.dll


< >

< :Reg >

< >

< :Files >

< >

< :Commands >

< [purity] >

< [resethosts] >

< [emptytemp] >

< [EMPTYFLASH] >

< [start explorer] >

< [Reboot] >

========== Files - Unicode (All) ==========
[2008/09/22 17:01:16 | 000,897,536 | —- | C] ()(C:\Documents and Settings\sluo\My Documents\???1.pps) – C:\Documents and Settings\sluo\My Documents\平安夜1.pps
[2006/12/22 10:26:40 | 000,897,536 | —- | M] ()(C:\Documents and Settings\sluo\My Documents\???1.pps) – C:\Documents and Settings\sluo\My Documents\平安夜1.pps

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
when i looked up combofix.txt, this is the log i found: ComboFix 10-06-17.02 - sluo 06/18/2010 0:14:25.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.720 [GMT -4:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} i am wondering if i have to run the process again, or if that's what the log is supposed to look like. i followed your instructions, but on the last step of the process (there was a blue dialog box, and within it it said "preparing log, do not run other programs while combofix is running"), nothing happened for over an hour. eventually, with nothing else responding, i powered down and restarted my laptop .
Hello,

I need for you to re-run these instructions below. It seems you ran a scan with OTL rather than ran a Fix. Please make sure you read my instructions carefully.

Please try running these instructions below again.

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    MOD - C:\WINDOWS\system32\0047.DLL ()
    IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [KernelFaultCheck] File not found
    O20 - AppInit_DLLs: (C:\WINDOWS\system32\0047.DLL) - C:\WINDOWS\system32\0047.DLL ()
    O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
    O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun
    O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{38b500d8-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell - "" = AutoRun
    O33 - MountPoints2\{38b500d9-6913-11de-b89b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{3cb578ab-637d-11de-b894-00188bb24a3a}\Shell\AutoRun\command - "" = E:\sources\sperr32.exe – File not found
    O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell - "" = AutoRun
    O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{4441a2e0-aaf0-11de-b90b-00188bb24a3a}\Shell\AutoRun\command - "" = F:\DTVP_Launcher.exe – File not found
    [2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2010/06/13 15:16:53 | 000,045,290 | -HS- | M] () – C:\Documents and Settings\sluo\Application Data\50e417e0-e461-474b-96e2-077b80325612_36.avi
    [2010/05/27 23:30:27 | 000,043,008 | -H– | M] () – C:\WINDOWS\System32\wexe.exe
    [2010/05/26 20:32:16 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0045.DLL
    [2010/05/26 20:32:16 | 000,005,861 | —- | M] () – C:\WINDOWS\System32\WORK.DAT
    [2010/05/25 23:23:39 | 000,025,600 | —- | M] () – C:\WINDOWS\System32\0041.DLL
    [2010/05/17 07:52:00 | 000,025,088 | —- | M] () – C:\WINDOWS\System32\0042.DLL
    [2010/05/27 23:30:28 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0047.DLL
    [2010/05/25 23:23:38 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0041.DLL
    [2010/05/24 17:35:09 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0045.DLL
    [2010/05/17 07:52:00 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\0042.DLL
    [2010/02/22 02:44:04 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\0035.DLL
    [2010/01/02 01:23:55 | 000,000,876 | —- | C] () – C:\WINDOWS\System32\krl32mainweq.dll
    [2010/01/02 01:23:03 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\H8SRTmkepjoaqok.dll
    [2010/01/02 01:22:52 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\H8SRTjnkvdktlex.dll
    [2010/01/02 01:22:39 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\H8SRTamixgiljwt.dll
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
will do. please excuse me if this takes some time again, the middle of the week is brutal for me. although it seems that i have google back, and my browsing isn't being hijacked anymore!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI