This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware?

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I use windows vista and I'm not sure if it's malware or not. But my sd card reader wants to format every sd card I put in the slot and will not open. Also it won't recognize any device I plug into my usb. I've been to the property tab and it says the driver is not working properly. So I go in as admin to update the driver and says my driver is up to date and current. Again, I"m not sure if this is malware or not but All of this started at the same time, which was about 45 days ago. Before that I never had any problem with any of this. Also, there's a safely remove hardware icon in my notification area. And it's giving me the option to remove my sd reader which is a WDC WD50 SCSI Disc Device. I've never had malware attack my hardware before. Is this even possible? Thanks in advance for any help.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:23:12 AM, on 6/15/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\Dwm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskeng.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\RtHDVCpl.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\WINDOWS\system32\wbem\unsecapp.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify2?&.src=ym
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\WINDOWS\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvvsvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 7491 bytes
This may not be malware related but let's check,

please run the following:


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT




Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
CatByte, Thank you so much for your help. I ran DDS and have attached the info. However, when I ran the GMER rootkit scanner it caused a system crash and gave me this error message: PFN_list_corrupt. I'll run it again and try to get the file for you. Thanks again.
Here is the GMER file with "Sections" and drive C checked.

I"ll try a full scan again too.

Thanks.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-16 13:03:19
Windows 6.0.6001 Service Pack 1
Running: 5mbjo7ki.exe; Driver: C:\Users\KEVINT~1\AppData\Local\Temp\agldypoc.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys section is writeable [0x90401340, 0x3DB197, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[2092] kernel32.dll!SetUnhandledExceptionFilter 771E6E2D 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!SetWindowsHookExW 76D07B69 5 Bytes JMP 6D209A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!CallNextHookEx 76D08C33 5 Bytes JMP 6D1FD101 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!DialogBoxIndirectParamW 76D0BD25 5 Bytes JMP 6D30473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!CreateWindowExW 76D13D67 5 Bytes JMP 6D20DAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!DialogBoxParamW 76D21FD5 5 Bytes JMP 6D135505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!UnhookWindowsHookEx 76D308BE 5 Bytes JMP 6D17466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!DialogBoxParamA 76D480B2 5 Bytes JMP 6D3046DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!DialogBoxIndirectParamA 76D483DD 5 Bytes JMP 6D3047A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!MessageBoxIndirectA 76D5D471 5 Bytes JMP 6D304671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!MessageBoxIndirectW 76D5D56B 5 Bytes JMP 6D304606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!MessageBoxExA 76D5D5D1 5 Bytes JMP 6D3045A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] USER32.dll!MessageBoxExW 76D5D5F5 5 Bytes JMP 6D304542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] ole32.dll!OleLoadFromStream 778D9726 5 Bytes JMP 6D304AA7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2168] ole32.dll!CoCreateInstance 7790E188 5 Bytes JMP 6D20DB20 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!SetWindowsHookExW 76D07B69 5 Bytes JMP 6D209A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!CallNextHookEx 76D08C33 5 Bytes JMP 6D1FD101 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!DialogBoxIndirectParamW 76D0BD25 5 Bytes JMP 6D30473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!CreateWindowExW 76D13D67 5 Bytes JMP 6D20DAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!DialogBoxParamW 76D21FD5 5 Bytes JMP 6D135505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!UnhookWindowsHookEx 76D308BE 5 Bytes JMP 6D17466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!DialogBoxParamA 76D480B2 5 Bytes JMP 6D3046DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!DialogBoxIndirectParamA 76D483DD 5 Bytes JMP 6D3047A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!MessageBoxIndirectA 76D5D471 5 Bytes JMP 6D304671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!MessageBoxIndirectW 76D5D56B 5 Bytes JMP 6D304606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!MessageBoxExA 76D5D5D1 5 Bytes JMP 6D3045A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] USER32.dll!MessageBoxExW 76D5D5F5 5 Bytes JMP 6D304542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] ole32.dll!OleLoadFromStream 778D9726 5 Bytes JMP 6D304AA7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4536] ole32.dll!CoCreateInstance 7790E188 5 Bytes JMP 6D20DB20 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!DialogBoxIndirectParamW 76D0BD25 5 Bytes JMP 6D30473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!CreateWindowExW 76D13D67 5 Bytes JMP 6D20DAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!DialogBoxParamW 76D21FD5 5 Bytes JMP 6D135505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!DialogBoxParamA 76D480B2 5 Bytes JMP 6D3046DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!DialogBoxIndirectParamA 76D483DD 5 Bytes JMP 6D3047A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!MessageBoxIndirectA 76D5D471 5 Bytes JMP 6D304671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!MessageBoxIndirectW 76D5D56B 5 Bytes JMP 6D304606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!MessageBoxExA 76D5D5D1 5 Bytes JMP 6D3045A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5424] USER32.dll!MessageBoxExW 76D5D5F5 5 Bytes JMP 6D304542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 10-06-15.04 - Kevin Taylor 06/16/2010 14:22:16.6.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3454.2364 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 4.0 *enabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-05-16 to 2010-06-16 )))))))))))))))))))))))))))))))
.

2010-06-16 19:27 . 2010-06-16 19:27 ——– d—–w- c:\users\Kevin Taylor\AppData\Local\temp
2010-06-16 19:27 . 2010-06-16 19:27 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-06-16 19:27 . 2010-06-16 19:27 ——– d—–w- c:\users\Mcx2\AppData\Local\temp
2010-06-16 19:27 . 2010-06-16 19:27 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2010-06-16 19:27 . 2010-06-16 19:27 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-06-15 06:16 . 2010-06-15 06:16 388096 —-a-r- c:\users\Kevin Taylor\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-13 15:52 . 2010-06-13 15:52 ——– d—–w- c:\windows\BBSTORE
2010-06-13 15:51 . 2010-06-13 15:51 ——– d—–w- c:\program files\Mattel Interactive
2010-06-10 20:31 . 2010-06-10 20:31 12124624 —-a-w- c:\users\Kevin Taylor\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airinstaller2x0\airinstaller2x0.exe
2010-06-04 23:31 . 2010-06-04 23:31 ——– dc—-w- C:\PerfLogs
2010-06-04 23:07 . 2010-06-04 22:45 47560 —-a-w- c:\windows\system32\SPReview.exe
2010-06-04 23:07 . 2010-06-04 22:45 152576 —-a-w- c:\windows\system32\SPWizUI.dll
2010-06-04 22:53 . 2008-01-19 04:33 193024 —-a-w- c:\windows\system32\recdisc.exe
2010-06-04 22:53 . 2008-01-19 04:36 6656 —-a-w- c:\windows\system32\sdspres.dll
2010-06-04 22:53 . 2008-01-19 04:33 599552 —-a-w- c:\windows\system32\vsp1cln.exe
2010-06-04 22:52 . 2008-01-19 04:36 28160 —-a-w- c:\windows\system32\sxproxy.dll
2010-06-04 22:52 . 2008-01-19 04:36 142336 —-a-w- c:\windows\system32\spp.dll
2010-06-04 22:50 . 2008-01-19 04:36 1186304 —-a-w- c:\windows\system32\AuxiliaryDisplayCpl.dll
2010-06-04 22:47 . 2008-01-19 04:33 44032 —-a-w- c:\windows\system32\cbsra.exe
2010-06-04 21:04 . 2009-03-08 11:33 18944 —-a-w- c:\windows\system32\corpol.dll
2010-06-04 21:04 . 2009-03-08 11:32 72704 —-a-w- c:\windows\system32\admparse.dll
2010-06-04 21:04 . 2009-03-08 11:31 34816 —-a-w- c:\windows\system32\imgutil.dll
2010-06-04 21:04 . 2009-03-08 11:31 48128 —-a-w- c:\windows\system32\mshtmler.dll
2010-06-04 21:04 . 2009-03-08 11:22 156160 —-a-w- c:\windows\system32\msls31.dll
2010-06-04 20:48 . 2010-06-04 20:48 499712 —-a-w- c:\windows\system32\kerberos.dll
2010-06-04 20:48 . 2010-06-04 20:48 270848 —-a-w- c:\windows\system32\schannel.dll
2010-05-24 18:59 . 2010-05-24 18:59 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-05-24 18:59 . 2010-05-24 18:59 78848 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-05-24 18:59 . 2010-05-24 18:59 105984 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-05-24 18:59 . 2010-05-24 18:59 3598216 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-05-24 18:59 . 2010-05-24 18:59 3545992 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-05-24 18:56 . 2010-05-24 18:56 171520 —-a-w- c:\windows\system32\wintrust.dll
2010-05-24 18:55 . 2010-05-24 18:55 898952 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-05-24 18:55 . 2010-05-24 18:55 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-05-24 18:55 . 2010-05-24 18:55 190464 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-05-24 18:55 . 2010-05-24 18:55 15360 —-a-w- c:\windows\system32\drivers\TUNMP.SYS
2010-05-24 18:55 . 2010-05-24 18:55 98304 —-a-w- c:\windows\system32\cabview.dll
2010-05-24 18:30 . 2010-05-24 18:30 ——– d—–w- c:\program files\ESET
2010-05-24 07:54 . 2009-05-18 18:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-05-24 07:54 . 2008-04-17 17:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-05-24 07:53 . 2010-05-24 07:53 ——– d—–w- c:\program files\iPod
2010-05-24 07:53 . 2010-05-24 07:54 ——– d—–w- c:\program files\iTunes
2010-05-24 07:52 . 2010-05-24 07:52 ——– d—–w- c:\program files\Apple Software Update
2010-05-24 07:28 . 2010-05-24 07:29 ——– d—–w- c:\program files\Safari
2010-05-24 07:05 . 2009-06-05 21:19 458752 —-a-w- c:\windows\system\CoreFoundation.dll
2010-05-24 07:01 . 2010-05-24 07:01 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Uniblue
2010-05-22 17:26 . 2010-05-22 17:26 ——– d—–w- c:\users\Kevin Taylor\AppData\Local\Mozilla
2010-05-20 15:45 . 2010-05-20 15:45 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Unity
2010-05-20 15:44 . 2010-05-20 15:44 ——– d—–w- c:\users\Kevin Taylor\AppData\Local\Unity
2010-05-20 15:44 . 2010-05-20 15:44 ——– d—–w- c:\program files\Unity
2010-05-19 22:10 . 2010-05-19 22:11 ——– d—–w- c:\users\Kevin Taylor\{998487e1-5017-4694-b606-0d6ac021c245}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-16 19:28 . 2010-03-18 00:16 ——– d—–w- c:\program files\Common Files\Akamai
2010-06-16 03:48 . 2010-03-11 04:10 439816 —-a-w- c:\users\Kevin Taylor\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-06-12 00:42 . 2010-06-12 00:42 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2010-06-11 23:45 . 2009-08-17 20:32 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Azureus
2010-06-09 22:51 . 2008-02-12 18:45 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\DVD Flick
2010-06-06 18:18 . 2008-01-12 04:02 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Canon
2010-06-04 23:33 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2010-06-04 23:33 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2010-06-04 23:33 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-06-04 23:33 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2010-06-04 23:33 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2010-06-04 23:33 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2010-06-04 23:33 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2010-06-04 23:31 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2010-06-04 23:18 . 2006-11-02 10:32 101888 —-a-w- c:\windows\system32\ifxcardm.dll
2010-06-04 23:18 . 2006-11-02 10:32 82432 —-a-w- c:\windows\system32\axaltocm.dll
2010-06-04 20:49 . 2008-01-11 00:32 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-02 02:15 . 2008-02-10 08:03 ——– d—–w- c:\programdata\Nero
2010-05-24 18:59 . 2007-10-11 20:13 ——– d—–w- c:\programdata\Microsoft Help
2010-05-24 07:53 . 2009-12-26 22:34 ——– d—–w- c:\program files\Common Files\Apple
2010-05-24 06:58 . 2010-01-22 04:57 ——– d—–w- c:\program files\WinUtilities
2010-05-24 05:48 . 2009-09-29 14:58 182 —-a-w- c:\users\Kevin Taylor\AppData\Roaming\Azureus\restart.bat
2010-05-24 05:46 . 2009-08-17 20:32 ——– d—–w- c:\program files\Vuze
2010-05-19 19:19 . 2009-01-28 01:35 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\vlc
2010-05-19 19:19 . 2010-05-07 02:45 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\FreeAudioPack
2010-05-19 19:19 . 2010-05-04 17:42 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Facebook
2010-05-19 19:19 . 2010-05-08 01:45 ——– d—–w- c:\programdata\FLEXnet
2010-05-19 19:19 . 2010-04-20 17:38 ——– d—–w- c:\program files\Nick Jr. Arcade
2010-05-19 19:19 . 2009-02-13 03:46 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-05-19 19:19 . 2010-05-07 02:45 ——– d—–w- c:\program files\Free Audio Pack
2010-05-12 16:21 . 2009-10-03 09:00 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-08 01:49 . 2008-01-05 08:17 117872 —-a-w- c:\users\Kevin Taylor\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-08 01:22 . 2010-05-08 01:22 ——– d—–w- c:\programdata\ALM
2010-05-08 01:21 . 2007-10-11 20:11 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-08 01:13 . 2010-05-08 01:13 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2010-05-04 17:42 . 2010-05-04 17:42 50354 —-a-w- c:\users\Kevin Taylor\AppData\Roaming\Facebook\uninstall.exe
2010-05-02 18:01 . 2010-04-20 17:39 ——– d—–w- c:\program files\Microsoft
2010-04-28 20:45 . 2010-04-28 20:45 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-04-28 18:17 . 2009-12-26 22:40 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Apple Computer
2010-04-28 18:16 . 2010-04-28 18:04 ——– d—–w- c:\programdata\Norton
2010-04-28 18:16 . 2010-04-28 18:04 ——– d—–w- c:\programdata\Symantec
2010-04-28 18:13 . 2010-04-28 18:12 ——– d—–w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-28 18:07 . 2010-04-28 18:07 ——– d—–w- c:\program files\QuickTime
2010-04-28 18:04 . 2010-04-28 18:04 ——– d—–w- c:\programdata\NortonInstaller
2010-04-28 18:02 . 2010-04-28 18:02 ——– d—–w- c:\program files\Bonjour
2010-04-28 17:51 . 2010-04-28 17:33 ——– d—–w- c:\program files\Bing Bar Installer
2010-04-16 23:11 . 2009-09-02 21:39 75 —-a-w- c:\users\Kevin Taylor\jagex_runescape_preferences2.dat
2010-04-16 23:07 . 2009-04-26 00:21 41 —-a-w- c:\users\Kevin Taylor\jagex_runescape_preferences.dat
2010-04-16 13:33 . 2010-04-16 13:33 41472 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-16 13:33 . 2010-04-16 13:33 3003680 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-04-08 18:20 . 2010-04-08 18:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-04-08 18:20 . 2010-04-08 18:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-04-03 22:33 . 2010-04-03 22:33 0 —-a-w- c:\users\Kevin Taylor\jagex__preferences3.dat
2010-03-22 23:58 . 2010-03-22 23:58 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-03-22 23:58 . 2010-03-22 23:58 289792 —-a-w- c:\windows\system32\atmfd.dll
2010-03-22 23:58 . 2010-03-22 23:58 23552 —-a-w- c:\windows\system32\lpk.dll
2010-03-22 23:58 . 2010-03-22 23:58 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-03-22 23:58 . 2010-03-22 23:58 10240 —-a-w- c:\windows\system32\dciman32.dll
2010-03-22 23:58 . 2010-03-22 23:58 72704 —-a-w- c:\windows\system32\fontsub.dll
2010-03-22 23:55 . 2010-03-22 23:55 98304 —-a-w- c:\windows\system32\drivers\srvnet.sys
2010-03-22 23:55 . 2010-03-22 23:55 301568 —-a-w- c:\windows\system32\drivers\srv.sys
2010-03-22 23:55 . 2010-03-22 23:55 17920 —-a-w- c:\windows\system32\netevent.dll
2010-03-22 23:55 . 2010-03-22 23:55 9728 —-a-w- c:\windows\system32\TCPSVCS.EXE
2010-03-22 23:55 . 2010-03-22 23:55 11264 —-a-w- c:\windows\system32\MRINFO.EXE
2010-03-22 23:55 . 2010-03-22 23:55 8704 —-a-w- c:\windows\system32\HOSTNAME.EXE
2010-03-22 23:55 . 2010-03-22 23:55 27136 —-a-w- c:\windows\system32\NETSTAT.EXE
2010-03-22 23:55 . 2010-03-22 23:55 19968 —-a-w- c:\windows\system32\ARP.EXE
2010-03-22 23:55 . 2010-03-22 23:55 17920 —-a-w- c:\windows\system32\ROUTE.EXE
2010-03-22 23:55 . 2010-03-22 23:55 104960 —-a-w- c:\windows\system32\netiohlp.dll
2010-03-22 23:55 . 2010-03-22 23:55 10240 —-a-w- c:\windows\system32\finger.exe
2010-03-22 23:53 . 2010-03-22 23:53 98816 —-a-w- c:\windows\system32\mfps.dll
2010-03-22 23:53 . 2010-03-22 23:53 53248 —-a-w- c:\windows\system32\rrinstaller.exe
2010-03-22 23:53 . 2010-03-22 23:53 2868224 —-a-w- c:\windows\system32\mf.dll
2010-03-22 23:53 . 2010-03-22 23:53 24576 —-a-w- c:\windows\system32\mfpmp.exe
2010-03-22 23:53 . 2010-03-22 23:53 2048 —-a-w- c:\windows\system32\mferror.dll
2010-03-22 23:52 . 2010-03-22 23:52 376832 —-a-w- c:\windows\system32\winhttp.dll
2010-03-22 23:52 . 2010-03-22 23:52 71680 —-a-w- c:\windows\system32\atl.dll
2010-03-22 23:52 . 2010-03-22 23:52 562176 —-a-w- c:\windows\system32\msdtcprx.dll
2010-03-22 23:52 . 2010-03-22 23:52 38912 —-a-w- c:\windows\system32\xolehlp.dll
2010-03-22 23:51 . 2010-03-22 23:51 160256 —-a-w- c:\windows\system32\wkssvc.dll
2010-03-22 23:51 . 2010-03-22 23:51 53248 —-a-w- c:\windows\system32\tsgqec.dll
2010-03-22 23:51 . 2010-03-22 23:51 2066432 —-a-w- c:\windows\system32\mstscax.dll
2010-03-22 23:51 . 2010-03-22 23:51 136192 —-a-w- c:\windows\system32\aaclient.dll
2010-03-22 23:49 . 2010-03-22 23:49 428544 —-a-w- c:\windows\system32\EncDec.dll
2010-03-22 23:49 . 2010-03-22 23:49 293376 —-a-w- c:\windows\system32\psisdecd.dll
2010-03-22 23:49 . 2010-03-22 23:49 2048 —-a-w- c:\windows\system32\tzres.dll
2010-03-22 23:49 . 2010-03-22 23:49 636928 —-a-w- c:\windows\system32\localspl.dll
2010-03-22 23:47 . 2010-03-22 23:47 551424 —-a-w- c:\windows\system32\rpcss.dll
2010-03-22 23:47 . 2010-03-22 23:47 666624 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2010-03-22 23:47 . 2010-03-22 23:47 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2010-03-22 23:47 . 2010-03-22 23:47 129024 —-a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2010-03-22 23:47 . 2010-03-22 23:47 615424 —-a-w- c:\windows\system32\wbem\fastprox.dll
2010-03-22 23:47 . 2010-03-22 23:47 54784 —-a-w- c:\windows\system32\iasads.dll
2010-03-22 23:47 . 2010-03-22 23:47 499200 —-a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2010-03-22 23:47 . 2010-03-22 23:47 44032 —-a-w- c:\windows\system32\iasdatastore.dll
2010-03-22 23:47 . 2010-03-22 23:47 247296 —-a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2010-03-22 23:47 . 2010-03-22 23:47 17408 —-a-w- c:\windows\system32\iashost.exe
2010-03-22 23:47 . 2010-03-22 23:47 98304 —-a-w- c:\windows\system32\iasrecst.dll
2010-03-22 23:47 . 2010-03-22 23:47 183296 —-a-w- c:\windows\system32\sdohlp.dll
2010-03-22 23:45 . 2010-03-22 23:45 40960 —-a-w- c:\windows\AppPatch\apihex86.dll
2008-01-07 09:12 . 2008-01-07 09:12 397312 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6000.16480_none_ef1b6bb652cf8744\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-11-16 2054360]
"RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 4349952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix]
2006-11-16 23:04 2348584 —-a-w- c:\program files\BigFix\bigfix.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTCheck]
2007-11-06 17:08 397312 ——w- c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ddoctorv2]
2008-04-24 18:25 202560 —-a-w- c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2008-11-06 03:59 4347120 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 02:53 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 22:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-01-21 16:55 185872 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"ShowWnd"=ShowWnd.exe
"ModPS2"=ModPS2Key.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2908862468-2916969662-1638312087-1000]
"EnableNotificationsRef"=dword:00000001

R1 DnsFilter;DnsFilter;c:\windows\system32\drivers\DnsFilter.sys [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 135664]
R2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2006-11-02 9216]
R2 SBSDWSCService;SBSD Security Center Service; [x]
R3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]
R3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM106.sys [2007-12-14 1373696]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-01-27 717296]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-11-16 735960]
S3 AVer88xHD;AVerMedia 23888 AvStream Video Capture;c:\windows\system32\drivers\AVer88xHD.sys [2007-04-09 401408]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
ddnsfilter REG_MULTI_SZ ddnsfilter
Akamai REG_MULTI_SZ Akamai

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 19:24 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 02:30]

2010-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 02:30]

2010-06-16 c:\windows\Tasks\User_Feed_Synchronization-{ED4E2BAB-F02A-4EFA-9AB3-B5B4BBD2A292}.job
- c:\windows\system32\msfeedssync.exe [2010-06-04 04:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://login.yahoo.com/config/login_verify2?&.src=ym
mStart Page = hxxp://www.comcast.net/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyOverride = cdn;*.local
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Kevin Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\x7wepz0n.default\
FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\users\Kevin Taylor\AppData\Local\Yahoo!\BrowserPlus\2.8.1\Plugins\npybrowserplus_2.8.1.dll
FF - plugin: c:\users\Kevin Taylor\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-16 14:27
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-06-16 14:30:16
ComboFix-quarantined-files.txt 2010-06-16 19:30
ComboFix2.txt 2010-02-14 01:16

Pre-Run: 14,607,564,800 bytes free
Post-Run: 14,713,069,568 bytes free

- - End Of File - - AD583D28865F5B2228DEE5A070CD54A1
Hi

That was the sixth run of ComboFix, have you been running it on your own, or working with another forum?

Please do the following:


Click Start>Run and copy/paste the following bolded text into the Run box and click OK:

C:\Qoobox\ComboFix-quarantined-files.txt

A report should pop open for you. Please post the contents in your next reply.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
No and No. I've been here serveral times before but not anywehere else. I had to re-start combofix because some program crashed again while it was running the first time but that's it. I'll post my results soon. Thanks.
Combofix quarantined files:

2010-06-16 18:39:46 . 2010-06-16 19:26:11 4,597 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2010-06-16 18:22:02 . 2010-06-16 19:22:16 124 -c–a-w- C:\Qoobox\Quarantine\catchme.log
2010-05-15 22:51:34 . 2010-05-15 22:51:34 100 —-a-w- C:\Qoobox\Quarantine\C\Users\Kevin Taylor\AppData\Local\Windows Server\flags.ini.vir
2010-05-15 22:51:34 . 2010-05-17 20:05:35 50 —-a-w- C:\Qoobox\Quarantine\C\Users\Kevin Taylor\AppData\Local\Windows Server\uses32.dat.vir
2009-08-28 18:46:37 . 2009-08-28 18:46:37 1 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\ex23567.dat.vir


mbam:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18904

6/16/2010 5:17:26 PM
mbam-log-2010-06-16 (17-17-26).txt

Scan type: Quick scan
Objects scanned: 143034
Time elapsed: 5 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsFilter (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ddnsfilter (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\0535251103110107106.yux (KoobFace.Trace) -> Quarantined and deleted successfully.


It got 3! perhaps that was it. We'll see.


Kaspersky:

I ran this. It took me 14 hours. It found nothing but when I clicked on report it went back to the home page and no report was ever shown and it is nowhere to be found. I can run it again if you need the report.
Hi

Please do the following:



Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    c:\users\Kevin Taylor\{998487e1-5017-4694-b606-0d6ac021c245} /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


NEXT


Please post a fresh DDS Log and Attach.txt and advise how your computer is running now and if there are any outstanding issues
SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 10:58 on 17/06/2010 by Kevin Taylor (Administrator - Elevation successful) ========== dir ========== c:\users\Kevin Taylor\{998487e1-5017-4694-b606-0d6ac021c245} - Parameters: "/s" —Files— USBAAPL.CAT –a— 10996 bytes [13:33 16/04/2010] [13:33 16/04/2010] No folders found. -=End Of File=- Even though mbam removed some stuff, My card reader and usb ports still won't read.
Hi

Your computer appears to be clean of malware, so your issues does not appear to be malware related.

I will cleanup our tools and give you my closing recommendations, then i suggest you post a new topic in our Hardware forum as this would appear to be a hardware issue.

Link back to this topic so the techs can see what we have done.

I'm sure our expert techs will be able to assist you in resolving this matter.

Please do the following:



Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.



    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI