This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Links redirected in Firefox

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can someone please look at my HijackThis and tell me if they see anything wrong with it? Whenever I do a Google search in Firefox and click on a link I almost always get redirected to a completely different site. So if I click on a link that's supposed to take me to www.wikipedia.com it instead takes me to http://www.kdirectory.co.uk/results….a19_68101-5002 . This only happens in Firefox (I'm guessing due to Firefox's increasing popularity) and does not happen in other browsers like Opera or Chrome. I don't use IE.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:53:52, on 6/13/2010
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe
C:\Program Files\EDIMAX\Common\RaUI.exe
C:\Users\Maha\AppData\Roaming\Dropbox\bin\Dropbox.exe
D:\my-documents\maha\irc&im\NoNameScript\mIRC\mirc.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Opera\Opera.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\my-documents\games\Steam\steam.exe
C:\Windows\system32\DeviceDisplayObjectProvider.exe
D:\my-documents\maha\computer-stuff\diagnostics-solutions-fixes\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Ext2 Volume Manager] C:\Program Files\Ext2Fsd\Ext2Mgr.exe -quiet
O4 - HKCU\..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DS3 Tool] C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe -mini
O4 - Startup: DeskSpace.lnk = C:\Program Files\DeskSpace\deskspace.exe
O4 - Startup: Dropbox.lnk = Maha\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless Utility.lnk = C:\Program Files\EDIMAX\Common\RaUI.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF59BE5D-7566-46BB-AD9E-484E898B646B}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files\EDIMAX\Common\RaRegistry.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 8415 bytes

If you need anymore info to help me, please let me know. Otherwise, thank you for your time.
Hello MahaSMB and welcome to WhatTheTech. Please follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) Please download GooredFixfrom one of the locations below and save it to your desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).
🖼Click to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please include the following in your next post:
  • DDS and Attach.txt logs
  • GooredFix log
Thank you very much for your help and your quick reply.


GooredFix.txt
GooredFix by jpshortstuff (08.01.10.1)
Log created at 04:01 on 16/06/2010 (Maha)
Firefox version 3.6.3 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [18:56 25/04/2010]
{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} [22:20 25/04/2010]
{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [22:52 25/04/2010]
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [05:39 26/04/2010]

C:\Users\Maha\Application Data\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\
[removed] [19:32 25/04/2010]
[removed] [19:03 25/04/2010]
{340c2bbc-ce74-4362-90b5-7c26312808ef} [07:27 16/06/2010]
{64161300-e22b-11db-8314-0800200c9a66} [19:32 25/04/2010]
{9BAE5926-8513-417d-8E47-774955A7C60D} [19:32 25/04/2010]
{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} [19:03 25/04/2010]
{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} [06:33 13/06/2010]
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} [19:32 25/04/2010]
{dc572301-7619-498c-a57d-39143191b318} [06:33 13/06/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG9\Firefox" [20:59 25/04/2010]
"avg@igeared"="C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared" [21:00 25/04/2010]

———- Old Logs ———-

-=E.O.F=-

DDS.txt
DDS (Ver_10-03-17.01) - NTFSx86  
Run by [removed] at  4:04:07.72 on 06/16/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Ultimate   6.1.7600.0.1252.2.1033.18.2046.518 [GMT -4:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\EDIMAX\Common\RaRegistry.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WerFault.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe
C:\Program Files\EDIMAX\Common\RaUI.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Users\Maha\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\my-documents\maha\irc&im\NoNameScript\mIRC\mirc.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Windows\system32\AUDIODG.EXE
C:\Program Files\AVG\AVG9\avgcfgex.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wscript.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Maha\Desktop\dds.scr
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GR469A~1.DLL
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
uRun: [Pidgin] c:\program files\pidgin\pidgin.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [DS3 Tool] c:\program files\motioninjoy\ds3\DS3_Tool.exe -mini
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Ext2 Volume Manager] c:\program files\ext2fsd\Ext2Mgr.exe -quiet
StartupFolder: c:\users\maha\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\maha\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\maha\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wirele~1.lnk - c:\program files\edimax\common\RaUI.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
TCP: {DF59BE5D-7566-46BB-AD9E-484E898B646B} = 8.8.8.8,8.8.4.4
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GRA32A~1.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: avgrsstx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GR469A~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\maha\appdata\roaming\mozilla\firefox\profiles\3vdlk487.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\users\maha\appdata\roaming\mozilla\firefox\profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\winnt_x86-msvc\components\WeaveCrypto.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency",   1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug",			false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight",	   2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize",	   1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight",   25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight",	 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pre
f", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-6-13 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-4-25 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-4-25 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-4-25 242896]
R1 Ext2Fsd;Linux ext2 file system driver;c:\windows\system32\drivers\ext2fsd.sys [2010-4-26 659592]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-4-25 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-4-25 308064]
R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\edimax\common\RaRegistry.exe [2010-4-25 185632]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\drivers\MijXfilt.sys [2010-5-12 48640]
R3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\drivers\netr28.sys [2010-4-25 616960]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-26 135664]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-4-25 369920]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1352320]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]

=============== Created Last 30 ================

2010-06-15 09:59:21	0	d—–w-	c:\users\maha\KeeperData
2010-06-15 09:59:05	0	d—–w-	c:\program files\Callpod
2010-06-14 00:00:58	64288	—-a-w-	c:\windows\system32\drivers\Lbd.sys
2010-06-13 23:59:06	524288	–sha-w-	c:\users\maha\ntuser.dat{980154e1-7746-11df-97a5-db0b745a7654}.TMContainer00000000000000000002.regtrans-ms
2010-06-13 23:59:06	524288	–sha-w-	c:\users\maha\ntuser.dat{980154e1-7746-11df-97a5-db0b745a7654}.TMContainer00000000000000000001.regtrans-ms
2010-06-13 23:59:05	65536	–sha-w-	c:\users\maha\ntuser.dat{980154e1-7746-11df-97a5-db0b745a7654}.TM.blf
2010-06-12 07:58:17	0	d—–w-	c:\windows\system32\xlive
2010-06-12 07:58:17	0	d—–w-	c:\program files\Microsoft Games for Windows - LIVE
2010-06-12 06:42:54	113	—-a-w-	c:\users\maha\kvirc.ini
2010-06-12 06:42:53	0	d—–w-	c:\users\maha\download
2010-06-12 06:42:53	0	d—–w-	c:\users\maha\appdata\roaming\KVIrc
2010-06-12 06:39:45	0	d—–w-	c:\program files\KVIrc
2010-05-18 01:59:13	65536	–sha-w-	c:\users\maha\ntuser.dat{b5aecc69-621f-11df-b798-f77805ae3f67}.TM.blf
2010-05-18 01:59:13	524288	–sha-w-	c:\users\maha\ntuser.dat{b5aecc69-621f-11df-b798-f77805ae3f67}.TMContainer00000000000000000002.regtrans-ms
2010-05-18 01:59:13	524288	–sha-w-	c:\users\maha\ntuser.dat{b5aecc69-621f-11df-b798-f77805ae3f67}.TMContainer00000000000000000001.regtrans-ms
2010-05-18 01:51:05	65536	–sha-w-	c:\users\maha\ntuser.dat{ab4002fa-621e-11df-ac47-ec3f2a927965}.TM.blf
2010-05-18 01:51:05	524288	–sha-w-	c:\users\maha\ntuser.dat{ab4002fa-621e-11df-ac47-ec3f2a927965}.TMContainer00000000000000000002.regtrans-ms
2010-05-18 01:51:05	524288	–sha-w-	c:\users\maha\ntuser.dat{ab4002fa-621e-11df-ac47-ec3f2a927965}.TMContainer00000000000000000001.regtrans-ms
2010-05-18 01:43:41	65536	–sha-w-	c:\users\maha\ntuser.dat{eb05f11b-621c-11df-b2aa-8110548f4541}.TM.blf
2010-05-18 01:43:41	524288	–sha-w-	c:\users\maha\ntuser.dat{eb05f11b-621c-11df-b2aa-8110548f4541}.TMContainer00000000000000000002.regtrans-ms
2010-05-18 01:43:41	524288	–sha-w-	c:\users\maha\ntuser.dat{eb05f11b-621c-11df-b2aa-8110548f4541}.TMContainer00000000000000000001.regtrans-ms

==================== Find3M  ====================

2010-06-11 23:01:08	242896	—-a-w-	c:\windows\system32\drivers\avgtdix.sys
2010-05-18 06:28:04	6656	—-a-w-	c:\windows\system32\drivers\RDPCDD.sys
2010-05-13 01:53:24	0	—ha-w-	c:\windows\system32\drivers\Msft_Kernel_xusb21_01009.Wdf
2010-05-13 01:53:23	0	—ha-w-	c:\windows\system32\drivers\Msft_Kernel_MijXfilt_01009.Wdf
2010-05-08 22:36:00	15880	—-a-w-	c:\windows\system32\lsdelete.exe
2010-04-27 00:19:26	409088	—-a-w-	c:\windows\system32\systemcpl.dll
2010-04-27 00:19:26	13824	—-a-w-	c:\windows\system32\slwga.dll
2010-04-27 00:19:22	811520	—-a-w-	c:\windows\system32\user32.dll
2010-04-26 19:58:12	256512	—-a-w-	c:\windows\PEV.exe
2010-04-26 07:51:35	6144	——w-	c:\windows\system32\drivers\NTIDrvr.sys
2010-04-26 07:16:56	691696	——w-	c:\windows\system32\drivers\sptd.sys
2010-04-26 06:58:17	95024	——w-	c:\windows\system32\drivers\SBREDrv.sys
2010-04-26 05:21:08	56	—ha-w-	c:\programdata\ezsidmv.dat
2010-04-25 21:01:00	12464	——w-	c:\windows\system32\avgrsstx.dll
2010-04-25 21:00:53	216200	—-a-w-	c:\windows\system32\drivers\avgldx86.sys
2010-04-25 14:29:13	0	——w-	c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-04-12 21:29:19	411368	——w-	c:\windows\system32\deployJava1.dll
2009-07-14 04:56:42	31548	—-a-w-	c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42	31548	—-a-w-	c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42	291294	—-a-w-	c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42	291294	—-a-w-	c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57	174	–sha-w-	c:\program files\desktop.ini
2009-07-14 00:34:40	291294	—-a-w-	c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40	291294	—-a-w-	c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38	31548	—-a-w-	c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38	31548	—-a-w-	c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35	9633792	–sha-r-	c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45	396800	–sha-w-	c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH:  4:04:29.67 ===============

Attachments:

MahaSMB,

Please run these for me:

🖼Click to load external image (Posted Image) Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck everything except "Sections" and "C:\"
  • If you still can't run it, try in the Safe Mode
Please include the following in your next post:
  • GMER log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-16 18:24:01
Windows 6.1.7600 
Running: x2b97uiw.exe; Driver: C:\Users\Maha\AppData\Local\Temp\kwlyqaob.sys


—- System - GMER 1.0.15 —-

INT 0x1F		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A34AF8
INT 0x37		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A34104
INT 0xC1		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A343F4
INT 0xD1		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A1D2D8
INT 0xD2		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A1C898
INT 0xDF		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A341DC
INT 0xE1		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A34958
INT 0xE3		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A346F8
INT 0xFD		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A34F2C
INT 0xFE		\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)															82A351A8

—- Kernel code sections - GMER 1.0.15 —-

.text		   ntkrnlpa.exe!ZwSaveKeyEx + 13AD																													 82A94579 1 Byte  [06]
.text		   ntkrnlpa.exe!KiDispatchInterrupt + 5A2																											  82AB8F52 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET; MOV ECX, CR3}
.text		   peauth.sys																																		  9C470C9D 28 Bytes  [04, 1D, 44, 96, 6C, DA, 11, …]
.text		   peauth.sys																																		  9C470CC1 28 Bytes  [04, 1D, 44, 96, 6C, DA, 11, …]
PAGE			peauth.sys																																		  9C476B9B 72 Bytes  [60, 2E, 5A, EE, 29, 66, 94, …]
PAGE			peauth.sys																																		  9C476BEC 111 Bytes  [EE, 98, 7B, AF, A8, 77, EB, …]
PAGE			peauth.sys																																		  9C476E20 68 Bytes  [09, 1C, 1E, 1F, 9E, 0E, 98, …]
PAGE			…																																				 

—- User code sections - GMER 1.0.15 —-

.text		   C:\Windows\system32\svchost.exe[1056] ntdll.dll!NtProtectVirtualMemory																			  77BC5360 5 Bytes  JMP 001D000A 
.text		   C:\Windows\system32\svchost.exe[1056] ntdll.dll!NtWriteVirtualMemory																				77BC5EE0 5 Bytes  JMP 001E000A 
.text		   C:\Windows\system32\svchost.exe[1056] ntdll.dll!KiUserExceptionDispatcher																		   77BC6448 5 Bytes  JMP 0013000A 
.text		   C:\Windows\system32\svchost.exe[1056] ole32.dll!CoCreateInstance																					764C57FC 5 Bytes  JMP 0027000A 
.text		   C:\Windows\system32\svchost.exe[1056] USER32.dll!GetCursorPos																					   765DC198 5 Bytes  JMP 00FE000A 
.text		   C:\Windows\Explorer.EXE[2284] ntdll.dll!NtProtectVirtualMemory																					  77BC5360 5 Bytes  JMP 003F000A 
.text		   C:\Windows\Explorer.EXE[2284] ntdll.dll!NtWriteVirtualMemory																						77BC5EE0 5 Bytes  JMP 0040000A 
.text		   C:\Windows\Explorer.EXE[2284] ntdll.dll!KiUserExceptionDispatcher																				   77BC6448 5 Bytes  JMP 003E000A 
.text		   C:\Windows\system32\wuauclt.exe[4908] ntdll.dll!NtProtectVirtualMemory																			  77BC5360 5 Bytes  JMP 0013000A 
.text		   C:\Windows\system32\wuauclt.exe[4908] ntdll.dll!NtWriteVirtualMemory																				77BC5EE0 5 Bytes  JMP 0014000A 
.text		   C:\Windows\system32\wuauclt.exe[4908] ntdll.dll!KiUserExceptionDispatcher																		   77BC6448 5 Bytes  JMP 0012000A 
.text		   C:\Program Files\Opera\opera.exe[5384] ntdll.dll!NtProtectVirtualMemory																			 77BC5360 5 Bytes  JMP 002F000A 
.text		   C:\Program Files\Opera\opera.exe[5384] ntdll.dll!NtWriteVirtualMemory																			   77BC5EE0 5 Bytes  JMP 0030000A 
.text		   C:\Program Files\Opera\opera.exe[5384] ntdll.dll!KiUserExceptionDispatcher																		  77BC6448 5 Bytes  JMP 002E000A 

—- Devices - GMER 1.0.15 —-

AttachedDevice  \Driver\tdx \Device\Tcp																															 avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1																											  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2																											  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3																											  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4																											  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume5																											  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume6																											  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume7																											  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume8																											  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device		  \Driver\ACPI_HAL \Device\0000004b																												   halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice  \Driver\tdx \Device\Udp																															 avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\tdx \Device\RawIp																														   avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \FileSystem\fastfat \Fat																															fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device		   -> \Driver\atapi \Device\Harddisk0\DR0																											 858A5AC8

—- Registry - GMER 1.0.15 —-

Reg			 HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4e00105068b4																		 
Reg			 HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4e00105068b4@0022a5f053be															0xE3 0xA4 0xC5 0x27 …
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC																	
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0																 C:\Program Files\DAEMON Tools Lite\
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0																 0xD4 0xC3 0x97 0x02 …
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0																 0
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12															  0x02 0x56 0x7D 0xF6 …
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001														   
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0														0x20 0x01 0x00 0x00 …
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12													 0x7D 0xB1 0x99 0xD4 …
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0													  
Reg			 HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12												0x33 0x29 0xED 0x68 …
Reg			 HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4e00105068b4 (not active ControlSet)													 
Reg			 HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4e00105068b4@0022a5f053be																0xE3 0xA4 0xC5 0x27 …
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)												
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0																	 C:\Program Files\DAEMON Tools Lite\
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0																	 0xD4 0xC3 0x97 0x02 …
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0																	 0
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12																  0x02 0x56 0x7D 0xF6 …
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)									   
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0															0x20 0x01 0x00 0x00 …
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12														 0x7D 0xB1 0x99 0xD4 …
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)								  
Reg			 HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12													0x33 0x29 0xED 0x68 …
Reg			 HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFD4E303-F5AB-6CB0-6EB8-E0E44EEB4DC4}									 
Reg			 HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFD4E303-F5AB-6CB0-6EB8-E0E44EEB4DC4}@paaphbglbkfpfpoehlhpbfpofipmgkkp	0x6A 0x61 0x66 0x70 …
Reg			 HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFD4E303-F5AB-6CB0-6EB8-E0E44EEB4DC4}@abgofpbbjmegkimnollecfocoeimiadbom  0x69 0x61 0x6D 0x70 …

—- Files - GMER 1.0.15 —-

File			C:\Windows\system32\drivers\atapi.sys																											   suspicious modification

—- EOF - GMER 1.0.15 —-
MahaSMB,

🖼Click to load external image (Posted Image) Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
Please include the following in your next post:
  • comboFix log
ComboFix 10-06-16.02 - Maha 06/16/2010  20:27:27.2.2 - x86
Microsoft Windows 7 Ultimate   6.1.7600.0.1252.2.1033.18.2046.1029 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.

(((((((((((((((((((((((((   Files Created from 2010-05-17 to 2010-06-17  )))))))))))))))))))))))))))))))
.

2010-06-17 00:33 . 2010-06-17 00:34	——–	d—–w-	c:\users\Maha\AppData\Local\temp
2010-06-17 00:33 . 2010-06-17 00:33	——–	d—–w-	c:\users\Public\AppData\Local\temp
2010-06-17 00:33 . 2010-06-17 00:33	——–	d—–w-	c:\users\Default\AppData\Local\temp
2010-06-16 21:32 . 2010-06-16 21:32	2157	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\omega.contacts.msn.com
2010-06-16 21:32 . 2010-06-16 21:32	2095	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\login.live.com
2010-06-16 21:32 . 2010-06-16 21:32	1089	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\login.yahoo.com
2010-06-16 21:30 . 2010-06-16 21:30	3304	——w-	C:\bootsqm.dat
2010-06-16 07:27 . 2010-06-09 13:58	85464	—-a-w-	c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
2010-06-16 07:27 . 2010-06-09 13:58	38872	—-a-w-	c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINCE\components\WeaveCrypto.dll
2010-06-15 09:59 . 2010-06-15 10:00	——–	d—–w-	c:\users\Maha\KeeperData
2010-06-15 09:59 . 2010-06-15 09:59	——–	d—–w-	c:\program files\Callpod
2010-06-14 00:00 . 2010-06-13 23:33	64288	—-a-w-	c:\windows\system32\drivers\Lbd.sys
2010-06-13 03:50 . 2010-06-14 02:37	——–	d—–w-	c:\users\Maha\AppData\Roaming\dvdcss
2010-06-12 07:58 . 2010-06-12 07:58	——–	d—–w-	c:\program files\Microsoft Games for Windows - LIVE
2010-06-12 07:58 . 2010-06-12 07:58	——–	d—–w-	c:\windows\system32\xlive
2010-06-12 06:42 . 2010-06-12 06:43	——–	d—–w-	c:\users\Maha\AppData\Roaming\KVIrc
2010-06-12 06:42 . 2010-06-12 06:42	——–	d—–w-	c:\users\Maha\download
2010-06-12 06:39 . 2010-06-12 06:42	——–	d—–w-	c:\program files\KVIrc
2010-06-11 23:02 . 2010-06-11 23:02	48648	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2010-06-11 23:02 . 2010-06-11 23:02	573760	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2010-06-11 23:02 . 2010-06-11 23:02	737072	—-a-w-	c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2010-06-11 23:01 . 2010-06-11 23:01	29512	—-a-w-	c:\programdata\avg9\update\backup\avgmfx86.sys
2010-06-11 23:01 . 2010-06-11 23:01	242896	—-a-w-	c:\programdata\avg9\update\backup\avgtdix.sys

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-17 00:22 . 2010-04-26 05:20	——–	d—–w-	c:\users\Maha\AppData\Roaming\Skype
2010-06-17 00:21 . 2010-04-25 21:42	——–	d—–w-	c:\users\Maha\AppData\Roaming\.purple
2010-06-17 00:20 . 2009-07-14 00:01	6656	—-a-w-	c:\windows\system32\drivers\RDPCDD.sys
2010-06-16 21:32 . 2010-05-13 02:52	——–	d—–w-	c:\users\Maha\AppData\Roaming\Dropbox
2010-06-16 21:32 . 2010-04-26 05:21	——–	d—–w-	c:\users\Maha\AppData\Roaming\skypePM
2010-06-16 21:10 . 2010-04-25 22:43	——–	d—–w-	c:\users\Maha\AppData\Roaming\Azureus
2010-06-15 04:25 . 2010-04-26 07:00	——–	d—–w-	c:\users\Maha\AppData\Roaming\vlc
2010-06-14 02:34 . 2010-04-25 23:47	——–	d—–w-	c:\programdata\Zoom Player
2010-06-14 00:41 . 2010-04-27 01:04	65	—-a-w-	c:\windows\system32\bd7020.dat
2010-06-12 23:14 . 2010-04-26 02:12	——–	d—–w-	c:\program files\Brother
2010-06-12 23:14 . 2010-04-25 15:10	——–	d–h–w-	c:\program files\InstallShield Installation Information
2010-06-12 07:52 . 2010-04-25 20:31	——–	d—–w-	c:\program files\Common Files\Steam
2010-06-11 23:10 . 2010-04-25 23:28	——–	d—–w-	c:\program files\Google
2010-06-11 23:01 . 2010-04-25 21:00	242896	—-a-w-	c:\windows\system32\drivers\avgtdix.sys
2010-06-11 23:01 . 2010-04-25 21:00	29584	—-a-w-	c:\windows\system32\drivers\avgmfx86.sys
2010-05-18 01:54 . 2009-07-14 02:37	——–	d—–w-	c:\program files\Windows Mail
2010-05-18 01:54 . 2010-05-14 10:30	——–	d—–w-	c:\programdata\Spybot - Search & Destroy
2010-05-18 01:54 . 2010-05-14 10:30	——–	d—–w-	c:\program files\Spybot - Search & Destroy
2010-05-18 01:53 . 2010-05-14 08:55	——–	d—–w-	c:\users\Maha\AppData\Roaming\OpenOffice.org
2010-05-18 01:53 . 2010-05-13 01:51	——–	d—–w-	c:\program files\MotioninJoy
2010-05-14 08:58 . 2010-05-14 08:58	1	—-a-w-	c:\users\Maha\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-13 05:28 . 2010-04-25 22:43	——–	d—–w-	c:\program files\Vuze
2010-05-13 05:28 . 2010-04-26 23:37	174	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\restart.bat
2010-05-13 04:46 . 2010-05-13 04:46	——–	d—–w-	c:\users\Maha\AppData\Roaming\KeePass
2010-05-13 04:45 . 2010-05-13 04:45	——–	d—–w-	c:\program files\KeePass Password Safe 2
2010-05-13 02:52 . 2010-05-13 02:52	89831	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\Uninstall.exe
2010-05-13 01:53 . 2010-05-13 01:53	0	—ha-w-	c:\windows\system32\drivers\Msft_Kernel_xusb21_01009.Wdf
2010-05-13 01:53 . 2010-05-13 01:53	0	—ha-w-	c:\windows\system32\drivers\Msft_Kernel_MijXfilt_01009.Wdf
2010-05-13 01:51 . 2010-05-13 01:51	——–	d—–w-	c:\users\Maha\AppData\Roaming\MotioninJoy
2010-05-13 01:51 . 2010-05-13 01:51	——–	d—–w-	c:\programdata\MotioninJoy
2010-05-12 04:44 . 2010-04-26 00:23	——–	d—–w-	c:\programdata\Microsoft Help
2010-05-09 00:39 . 2010-05-09 00:39	——–	d—–w-	c:\users\Maha\AppData\Roaming\OtakuSoftware
2010-05-08 22:36 . 2010-05-08 08:18	15880	—-a-w-	c:\windows\system32\lsdelete.exe
2010-05-08 10:06 . 2010-05-08 10:06	——–	d—–w-	c:\users\Maha\AppData\Roaming\360desktop
2010-05-08 09:20 . 2010-05-08 09:20	——–	d—–w-	c:\users\Maha\AppData\Roaming\BMG
2010-05-02 08:33 . 2010-05-02 08:33	——–	d—–w-	c:\program files\Gabest
2010-05-02 06:41 . 2010-05-02 06:41	15884	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\azitunes\libProcessAccess.dll
2010-05-02 06:41 . 2010-05-02 06:41	102400	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll
2010-05-02 06:41 . 2010-05-02 06:41	7282688	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe
2010-05-02 06:41 . 2010-05-02 06:41	4141117	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe
2010-05-02 06:10 . 2010-05-02 06:10	——–	d—–w-	c:\users\Maha\AppData\Roaming\AnvSoft
2010-05-02 06:10 . 2010-05-02 06:10	——–	d—–w-	c:\program files\AnvSoft
2010-05-02 00:37 . 2010-05-01 21:44	——–	d—–w-	c:\users\Maha\AppData\Roaming\WinFF
2010-05-01 21:44 . 2010-05-01 21:44	——–	d—–w-	c:\program files\WinFF
2010-05-01 21:14 . 2010-04-25 18:54	——–	d—–w-	c:\program files\Opera
2010-05-01 19:16 . 2010-05-01 19:16	——–	d—–w-	c:\users\Maha\AppData\Roaming\AVS4YOU
2010-05-01 19:16 . 2010-04-25 21:00	——–	d—–w-	c:\programdata\AVG Security Toolbar
2010-05-01 19:16 . 2010-05-01 19:14	——–	d—–w-	c:\programdata\AVS4YOU
2010-05-01 19:15 . 2010-05-01 19:14	——–	d—–w-	c:\program files\AVS4YOU
2010-05-01 19:15 . 2010-05-01 19:14	——–	d—–w-	c:\program files\Common Files\AVSMedia
2010-04-27 02:50 . 2010-04-27 02:50	48648	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2010-04-27 02:50 . 2010-04-27 02:50	573760	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-04-27 02:50 . 2010-04-27 02:50	737072	—-a-w-	c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2010-04-27 02:24 . 2010-04-27 02:23	——–	d—–w-	c:\program files\DVDStyler
2010-04-27 02:23 . 2010-04-27 02:23	——–	d—–w-	c:\program files\Burn To DVD
2010-04-27 01:38 . 2010-04-27 01:38	——–	d—–r-	c:\users\Maha\AppData\Roaming\Brother
2010-04-27 00:19 . 2010-04-25 22:41	——–	d—–w-	c:\users\Maha\AppData\Roaming\uTorrent
2010-04-27 00:19 . 2009-07-13 23:40	409088	—-a-w-	c:\windows\system32\systemcpl.dll
2010-04-27 00:19 . 2009-07-13 23:36	13824	—-a-w-	c:\windows\system32\slwga.dll
2010-04-27 00:19 . 2009-07-13 23:24	811520	—-a-w-	c:\windows\system32\user32.dll
2010-04-26 20:40 . 2010-04-26 20:40	——–	d—–w-	c:\users\Maha\AppData\Roaming\Media Player Classic
2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\AIM Toolbar
2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\AIM
2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\Common Files\AOL
2010-04-26 08:08 . 2010-04-25 23:21	——–	d—–w-	c:\program files\NVIDIA Corporation
2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTIMPEG2.dll
2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTIMP3.dll
2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTICDMK7.dll
2010-04-26 07:51 . 2010-04-26 07:51	6144	——w-	c:\windows\system32\drivers\NTIDrvr.sys
2010-04-26 07:33 . 2010-04-25 23:37	——–	d—–w-	c:\program files\Ext2Fsd
2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\DCoder Image Source
2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\7-Zip
2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\FFMPEG Core Files
2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\SHOUTcast Source
2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\MONOGRAM AMR SplitterDecoder
2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\CD Audio Reader Filter
2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource AVI Splitter
2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\Gabest MPEG Splitter
2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource DTSAC3DD+ Source Filter
2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\RealMedia
2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\DScaler5
2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\AC3Filter
2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource Flash Video Splitter
2010-04-26 07:28 . 2010-04-26 07:28	——–	d—–w-	c:\program files\DirectVobSub
2010-04-26 07:28 . 2010-04-26 07:28	——–	d—–w-	c:\program files\Haali
2010-04-26 07:28 . 2010-04-25 23:48	——–	d—–w-	c:\program files\Bass Audio Decoder
2010-04-26 07:27 . 2010-04-25 23:47	——–	d—–w-	c:\program files\Zoom Player
2010-04-26 07:23 . 2010-04-25 22:45	——–	d—–w-	c:\users\Maha\AppData\Roaming\DAEMON Tools Lite
2010-04-26 07:18 . 2010-04-25 22:45	——–	d—–w-	c:\program files\PowerISO
2010-04-26 07:17 . 2010-04-26 07:17	——–	d—–w-	c:\program files\DAEMON Tools Toolbar
2010-04-26 07:17 . 2010-04-25 22:46	——–	d—–w-	c:\program files\DAEMON Tools Lite
2010-04-26 07:16 . 2010-04-26 07:16	691696	——w-	c:\windows\system32\drivers\sptd.sys
2010-04-26 07:15 . 2010-04-25 23:13	——–	d—–w-	c:\program files\Audacity
2010-04-26 06:58 . 2010-04-26 06:58	95024	——w-	c:\windows\system32\drivers\SBREDrv.sys
2010-04-26 06:56 . 2010-04-25 23:27	——–	dc-h–w-	c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-26 06:47 . 2010-04-25 22:43	113712	—-a-w-	c:\users\Maha\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-26 06:42 . 2010-04-25 23:30	——–	d—–w-	c:\program files\Combined Community Codec Pack
2010-04-26 06:37 . 2010-04-25 22:08	——–	d—–w-	c:\program files\Common Files\Adobe
2010-04-26 06:32 . 2010-04-25 15:09	——–	d—–w-	c:\program files\Common Files\InstallShield
2010-04-26 05:44 . 2010-04-26 05:44	——–	d—–w-	c:\programdata\Adobe Systems
2009-06-10 21:26 . 2009-07-14 02:04	9633792	–sha-r-	c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42	396800	–sha-w-	c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

——- Sigcheck ——-

[-] 2010-04-27 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
.
(((((((((((((((((((((((((((((   SnapShot@2010-05-13_05.56.32   )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-12 07:56 . 2009-09-04 21:44	69464			  c:\windows\System32\XAPOFX1_3.dll
- 2010-04-26 04:46 . 2008-07-30 10:20	68616			  c:\windows\System32\XAPOFX1_1.dll
+ 2010-06-12 07:56 . 2008-07-31 14:41	68616			  c:\windows\System32\XAPOFX1_1.dll
+ 2010-06-12 07:56 . 2009-03-16 18:18	22360			  c:\windows\System32\X3DAudio1_6.dll
+ 2010-04-25 20:52 . 2010-06-17 00:28	30494			  c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-06-17 00:28	35376			  c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-04-26 07:07 . 2010-04-26 03:00	67584			  c:\windows\System32\LogFiles\Srt\bootstat.dat
+ 2010-04-26 07:07 . 2010-05-18 01:36	67584			  c:\windows\System32\LogFiles\Srt\bootstat.dat
+ 2010-06-14 00:00 . 2010-06-13 23:33	64288			  c:\windows\System32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys
- 2009-07-14 04:50 . 2010-05-13 01:54	86016			  c:\windows\System32\DriverStore\infpub.dat
+ 2009-07-14 04:50 . 2010-06-12 23:14	86016			  c:\windows\System32\DriverStore\infpub.dat
+ 2010-04-25 14:27 . 2010-06-16 23:32	49152			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-04-25 14:27 . 2010-05-13 05:49	49152			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-04-27 05:23 . 2010-05-13 05:11	32768			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
+ 2010-04-27 05:23 . 2010-06-16 13:59	32768			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
+ 2010-06-14 05:54 . 2010-06-14 05:26	32768			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012010061420100615\index.dat
+ 2009-07-14 04:41 . 2010-06-16 23:32	49152			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2010-05-13 05:49	49152			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-05-08 21:08 . 2010-05-13 04:49	32768			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2010-05-08 21:08 . 2010-06-13 04:37	32768			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
- 2010-04-25 15:02 . 2010-05-13 05:51	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-25 15:02 . 2010-06-17 00:29	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-25 15:02 . 2010-06-17 00:29	32768			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-25 15:02 . 2010-05-13 05:51	32768			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-25 15:02 . 2010-06-17 00:29	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-04-25 15:02 . 2010-05-13 05:51	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-04-25 15:02 . 2010-05-13 05:49	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-25 15:02 . 2010-06-17 00:26	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-25 17:58 . 2010-06-17 00:05	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-25 17:58 . 2010-05-13 05:04	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-25 17:58 . 2010-05-13 05:04	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2010-04-25 17:58 . 2010-06-17 00:05	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2010-04-25 17:58 . 2010-06-17 00:05	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2010-04-25 17:58 . 2010-05-13 05:04	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2010-04-25 15:02 . 2010-06-17 00:26	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-25 15:02 . 2010-05-13 05:49	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-25 15:02 . 2010-06-17 00:26	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-04-25 15:02 . 2010-05-13 05:49	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-15 01:35 . 2010-06-15 01:35	25088			  c:\windows\Installer\5858781.msi
+ 2010-06-11 23:10 . 2010-06-11 23:10	25214			  c:\windows\Installer\{F7B0939E-58DF-11DF-B3A6-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2010-06-11 23:10 . 2010-06-11 23:10	25214			  c:\windows\Installer\{F7B0939E-58DF-11DF-B3A6-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2010-06-11 23:10 . 2010-06-11 23:10	25214			  c:\windows\Installer\{F7B0939E-58DF-11DF-B3A6-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2010-06-11 23:10 . 2010-06-11 23:10	25214			  c:\windows\Installer\{F7B0939E-58DF-11DF-B3A6-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2010-06-11 23:10 . 2010-06-11 23:10	25214			  c:\windows\Installer\{F7B0939E-58DF-11DF-B3A6-005056806466}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2010-06-11 23:10 . 2010-06-11 23:10	25214			  c:\windows\Installer\{F7B0939E-58DF-11DF-B3A6-005056806466}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2010-06-11 23:10 . 2010-06-11 23:10	25214			  c:\windows\Installer\{F7B0939E-58DF-11DF-B3A6-005056806466}\ARPPRODUCTICON.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	90112			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	90112			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	45056			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	45056			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	22528			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	22528			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	30720			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	30720			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	16384			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	16384			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	34304			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	34304			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	81920			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	81920			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
- 2010-04-26 04:45 . 2010-04-26 04:45	12800			  c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	12800			  c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	53248			  c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	53248			  c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2010-04-25 20:11 . 2010-06-17 00:28	6430			  c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1037914879-3900162407-3989981119-1001_UserData.bin
+ 2010-06-16 22:10 . 2010-06-16 22:10	8192			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P1VDLGW1\HottieRegion_installer[1].exe
+ 2010-06-17 00:26 . 2010-06-17 00:26	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-05-13 05:49 . 2010-05-13 05:49	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-06-17 00:26 . 2010-06-17 00:26	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-05-13 05:49 . 2010-05-13 05:49	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-04-26 05:03 . 2010-04-26 05:03	3584			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	3584			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	8192			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	8192			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	2560			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	2560			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2009-08-07 23:35 . 2009-08-07 23:35	134144			  c:\windows\System32\xlive\sqmapi.dll
+ 2010-06-12 07:56 . 2009-09-04 21:44	515416			  c:\windows\System32\XAudio2_5.dll
+ 2010-06-12 07:56 . 2009-03-16 18:18	517448			  c:\windows\System32\XAudio2_4.dll
+ 2010-06-12 07:56 . 2008-07-31 14:40	509448			  c:\windows\System32\XAudio2_2.dll
- 2010-04-26 04:46 . 2008-07-30 10:20	509448			  c:\windows\System32\XAudio2_2.dll
+ 2010-06-12 07:56 . 2009-09-04 21:44	238936			  c:\windows\System32\xactengine3_5.dll
+ 2010-06-12 07:56 . 2009-03-16 18:18	235352			  c:\windows\System32\xactengine3_4.dll
+ 2010-06-12 07:56 . 2008-07-31 14:41	238088			  c:\windows\System32\xactengine3_2.dll
- 2010-04-26 04:46 . 2008-07-30 10:20	238088			  c:\windows\System32\xactengine3_2.dll
- 2009-07-14 02:05 . 2010-05-13 05:54	619206			  c:\windows\System32\perfh009.dat
+ 2009-07-14 02:05 . 2010-06-17 00:31	619206			  c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-05-13 05:54	107388			  c:\windows\System32\perfc009.dat
+ 2009-07-14 02:05 . 2010-06-17 00:31	107388			  c:\windows\System32\perfc009.dat
+ 2010-04-27 01:04 . 2008-06-17 19:33	167936			  c:\windows\System32\NSSearch.dll
+ 2010-06-13 06:24 . 2010-06-13 06:24	231888			  c:\windows\System32\Macromed\Flash\FlashUtil10h_Plugin.exe
+ 2009-07-14 04:50 . 2010-06-12 23:14	143360			  c:\windows\System32\DriverStore\infstrng.dat
- 2009-07-14 04:50 . 2010-05-13 01:54	143360			  c:\windows\System32\DriverStore\infstrng.dat
- 2009-07-14 04:50 . 2010-05-13 01:53	143360			  c:\windows\System32\DriverStore\infstor.dat
+ 2009-07-14 04:50 . 2010-06-12 23:14	143360			  c:\windows\System32\DriverStore\infstor.dat
+ 2010-06-12 07:56 . 2009-09-04 21:29	235344			  c:\windows\System32\d3dx11_42.dll
+ 2010-06-12 07:56 . 2009-09-04 21:29	453456			  c:\windows\System32\d3dx10_42.dll
+ 2010-06-12 07:56 . 2009-03-09 19:27	453456			  c:\windows\System32\d3dx10_41.dll
+ 2010-06-12 07:56 . 2008-10-15 10:22	452440			  c:\windows\System32\d3dx10_40.dll
- 2010-04-26 04:46 . 2008-10-10 08:52	452440			  c:\windows\System32\d3dx10_40.dll
- 2010-04-25 14:32 . 2010-05-13 05:11	245760			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2010-04-25 14:32 . 2010-06-17 00:05	245760			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2010-04-25 15:02 . 2010-04-25 15:02	245760			  c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2010-04-25 15:02 . 2010-05-18 01:01	245760			  c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 04:47 . 2010-05-18 08:14	435528			  c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:47 . 2010-05-13 05:38	435528			  c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2010-04-26 05:03 . 2010-04-26 05:03	114688			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	114688			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2010-04-26 05:03 . 2010-05-14 08:36	167936			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
- 2010-04-26 05:03 . 2010-04-26 05:03	167936			  c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2010-06-12 07:56 . 2010-06-12 07:56	223232			  c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	223232			  c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	178176			  c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	178176			  c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	364544			  c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	364544			  c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	159232			  c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	159232			  c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	145920			  c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	145920			  c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	578560			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	578560			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	578560			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	578560			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	577536			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	577536			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	577536			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	577536			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	577024			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	577024			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	576000			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	576000			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	567296			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	567296			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	563712			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	563712			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	473600			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	473600			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-07-14 02:03 . 2010-06-16 21:20	7340032			  c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:03 . 2010-05-13 01:49	7340032			  c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2007-08-27 19:41 . 2007-08-27 19:41	1089440			  c:\windows\System32\msidcrl40.dll
+ 2010-01-27 01:07 . 2010-06-13 06:24	5612496			  c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2010-06-12 07:56 . 2009-09-04 21:29	1892184			  c:\windows\System32\D3DX9_42.dll
+ 2010-06-12 07:56 . 2009-03-09 19:27	4178264			  c:\windows\System32\D3DX9_41.dll
- 2010-04-26 04:46 . 2008-10-10 08:52	4379984			  c:\windows\System32\D3DX9_40.dll
+ 2010-06-12 07:56 . 2008-10-15 10:22	4379984			  c:\windows\System32\D3DX9_40.dll
+ 2010-06-12 07:56 . 2009-09-04 21:29	5501792			  c:\windows\System32\d3dcsx_42.dll
+ 2010-06-12 07:56 . 2009-09-04 21:29	1974616			  c:\windows\System32\D3DCompiler_42.dll
+ 2010-06-12 07:56 . 2009-03-09 19:27	1846632			  c:\windows\System32\D3DCompiler_41.dll
+ 2010-06-12 07:56 . 2008-10-15 10:22	2036576			  c:\windows\System32\D3DCompiler_40.dll
- 2010-04-26 04:46 . 2008-10-10 08:52	2036576			  c:\windows\System32\D3DCompiler_40.dll
+ 2010-04-25 14:27 . 2010-06-16 23:32	1622016			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-28 00:42 . 2010-05-18 08:14	2560724			  c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1037914879-3900162407-3989981119-1001-8192.dat
+ 2010-05-06 07:26 . 2010-05-06 07:26	1265664			  c:\windows\Installer\db0e1.msi
+ 2009-08-11 01:51 . 2009-08-11 01:51	5230080			  c:\windows\Installer\1f0ddf0.msi
+ 2010-06-12 07:56 . 2010-06-12 07:56	2846720			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	2846720			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-04-26 04:45 . 2010-04-26 04:45	2676224			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-06-12 07:56 . 2010-06-12 07:56	2676224			  c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-08-07 23:51 . 2009-08-07 23:51	13642888			  c:\windows\System32\xlivefnt.dll
+ 2009-08-07 23:51 . 2009-08-07 23:51	15308424			  c:\windows\System32\xlive.dll
+ 2010-05-14 09:14 . 2010-05-14 09:14	31570432			  c:\windows\Installer\5e0f567.msi
+ 2009-08-08 00:58 . 2009-08-08 00:58	23406592			  c:\windows\Installer\1f0dde8.msi
- 2010-05-01 19:46 . 2010-05-08 05:03	134252032			  c:\windows\System32\config\systemprofile\AppData\LocalLow\Google\GoogleEarth\dbCache1.dat
+ 2010-05-01 19:46 . 2010-05-14 18:42	134252032			  c:\windows\System32\config\systemprofile\AppData\LocalLow\Google\GoogleEarth\dbCache1.dat
.
– Snapshot reset to current date –
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 18:04	1664256	—-a-w-	c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pidgin"="c:\program files\Pidgin\pidgin.exe" [2010-02-16 45603]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"DS3 Tool"="c:\program files\MotioninJoy\ds3\DS3_Tool.exe" [2010-01-19 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"Ext2 Volume Manager"="c:\program files\Ext2Fsd\Ext2Mgr.exe" [2009-07-30 1216648]

c:\users\Maha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Maha\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2010-4-25 1576960]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 06:12	483328	—-a-w-	c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-07-27 02:37	180224	—-a-w-	c:\program files\PowerISO\PWRISOVM.EXE

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 135664]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-02-23 369920]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-16 1352832]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R4 Gagpfcqauv;Gagpfcqauv; [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-04-26 691696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-13 64288]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-04-25 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-06-11 242896]
S1 Ext2Fsd;Linux ext2 file system driver; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-04-25 916760]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-04-25 308064]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [2010-03-18 48640]
S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [2009-08-04 616960]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]

.
Contents of the 'Scheduled Tasks' folder

2010-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:56]

2010-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:56]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {DF59BE5D-7566-46BB-AD9E-484E898B646B} = 8.8.8.8,8.8.4.4
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pre
f", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x858A7AC8]<< 
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xd46a624f
user & kernel MBR OK 

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1037914879-3900162407-3989981119-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFD4E303-F5AB-6CB0-6EB8-E0E44EEB4DC4}*]
"paaphbglbkfpfpoehlhpbfpofipmgkkp"=hex:6a,61,66,70,6a,62,62,6d,70,62,69,6a,64,
   67,69,66,70,62,62,65,00,b9
"abgofpbbjmegkimnollecfocoeimiadbom"=hex:69,61,6d,70,6f,62,6c,64,66,6c,6a,68,
   6a,6c,6c,69,6c,6f,00,00

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-06-16  20:35:40
ComboFix-quarantined-files.txt  2010-06-17 00:35
ComboFix2.txt  2010-05-13 05:58

Pre-Run: 62,203,367,424 bytes free
Post-Run: 62,245,224,448 bytes free

- - End Of File - - CB6869A2499DD4EC6A3E86359AB7B2CA
MahaSMB,

🖼Click to load external image (Posted Image) P2P - I see you have P2P software (Vuze) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Malware authors use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

🖼Click to load external image (Posted Image) Download TDSSKiller and save it to your Desktop.
  • Extract the file and run it.
  • Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)
  • Please post the content of that log TDSSKiller
🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above KillAll::

KillAll::
Driver::
Gagpfcqauv
RegLockDel::
[HKEY_USERS\S-1-5-21-1037914879-3900162407-3989981119-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFD4E303-F5AB-6CB0-6EB8-E0E44EEB4DC4}*]

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
Please include the following in your next post:
  • TDSSKiller log
  • ComboFix log
I uninstalled Vuze.

TDSSKiller.2.3.2.0_17.06.2010_02.06.33_log
02:06:33:424 3468	TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48

02:06:33:424 3468	===========================================================================
=====

02:06:33:424 3468	SystemInfo:



02:06:33:424 3468	OS Version: 6.1.7600 ServicePack: 0.0

02:06:33:424 3468	Product type: Workstation

02:06:33:424 3468	ComputerName: MAHA-WINDESK

02:06:33:426 3468	UserName: Maha

02:06:33:426 3468	Windows directory: C:\Windows

02:06:33:426 3468	Processor architecture: Intel x86

02:06:33:426 3468	Number of processors: 2

02:06:33:426 3468	Page size: 0x1000

02:06:33:426 3468	Boot type: Normal boot

02:06:33:426 3468	===========================================================================
=====

02:06:33:634 3468	Initialize success

02:06:33:634 3468	

02:06:33:634 3468	Scanning	Services …

02:06:34:589 3468	Raw services enum returned 466 services

02:06:34:599 3468	

02:06:34:599 3468	Scanning	Drivers …

02:06:35:566 3468	1394ohci		(6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys

02:06:35:644 3468	ACPI			(f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys

02:06:35:671 3468	AcpiPmi		 (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys

02:06:35:694 3468	adp94xx		 (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys

02:06:35:716 3468	adpahci		 (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys

02:06:35:746 3468	adpu320		 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys

02:06:35:789 3468	AFD			 (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys

02:06:35:816 3468	agp440		  (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys

02:06:35:834 3468	aic78xx		 (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys

02:06:35:856 3468	aliide		  (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys

02:06:35:879 3468	amdagp		  (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys

02:06:35:901 3468	amdide		  (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys

02:06:35:919 3468	AmdK8		   (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys

02:06:35:941 3468	AmdPPM		  (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys

02:06:35:954 3468	amdsata		 (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys

02:06:35:971 3468	amdsbs		  (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys

02:06:35:991 3468	amdxata		 (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys

02:06:36:014 3468	AppID		   (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys

02:06:36:034 3468	arc			 (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys

02:06:36:054 3468	arcsas		  (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys

02:06:36:071 3468	AsyncMac		(add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys

02:06:36:089 3468	atapi		   (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys

02:06:36:131 3468	AvgLdx86		(9c0a7e6d3cb9a8a7ad4e4575d9a42e94) C:\Windows\system32\Drivers\avgldx86.sys

02:06:36:156 3468	AvgMfx86		(53b3f979930a786a614d29cafe99f645) C:\Windows\system32\Drivers\avgmfx86.sys

02:06:36:189 3468	AvgTdiX		 (6e11bbc8dc5af836adc9c5f682fa3186) C:\Windows\system32\Drivers\avgtdix.sys

02:06:36:219 3468	b06bdrv		 (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys

02:06:36:249 3468	b57nd60x		(bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys

02:06:36:274 3468	Beep			(505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys

02:06:36:301 3468	blbdrive		(2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys

02:06:36:321 3468	bowser		  (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys

02:06:36:341 3468	BrFiltLo		(9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys

02:06:36:356 3468	BrFiltUp		(56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys

02:06:36:386 3468	Brserid		 (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys

02:06:36:406 3468	BrSerWdm		(203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys

02:06:36:436 3468	BrUsbMdm		(bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys

02:06:36:464 3468	BrUsbSer		(af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys

02:06:36:496 3468	BthEnum		 (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\DRIVERS\BthEnum.sys

02:06:36:524 3468	BTHMODEM		(ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys

02:06:36:554 3468	BthPan		  (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys

02:06:36:586 3468	BTHPORT		 (4a34888e13224678dd062466afec4240) C:\Windows\system32\Drivers\BTHport.sys

02:06:36:616 3468	BTHUSB		  (fa04c63916fa221dbb91fce153d07a55) C:\Windows\system32\Drivers\BTHUSB.sys

02:06:36:699 3468	cdfs			(77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys

02:06:36:759 3468	cdrom		   (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys

02:06:36:786 3468	circlass		(3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys

02:06:36:819 3468	CLFS			(635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys

02:06:36:841 3468	CmBatt		  (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys

02:06:36:861 3468	cmdide		  (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys

02:06:36:911 3468	CNG			 (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys

02:06:36:939 3468	Compbatt		(a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys

02:06:36:959 3468	CompositeBus	(f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys

02:06:36:976 3468	crcdisk		 (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys

02:06:37:044 3468	CSC			 (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys

02:06:37:089 3468	DfsC			(8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys

02:06:37:114 3468	discache		(1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys

02:06:37:139 3468	Disk			(565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys

02:06:37:166 3468	drmkaud		 (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys

02:06:37:201 3468	DXGKrnl		 (39806cfeddcc55e686a49bccd2972f23) C:\Windows\System32\drivers\dxgkrnl.sys

02:06:37:301 3468	ebdrv		   (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys

02:06:37:391 3468	EL90Xbc		 (fd3821285b943648a32adc39dacc4e11) C:\Windows\system32\DRIVERS\el90Xbc5.SYS

02:06:37:426 3468	elxstor		 (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys

02:06:37:454 3468	ErrDev		  (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys

02:06:37:476 3468	exfat		   (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys

02:06:37:514 3468	Ext2Fsd		 (0f8f910c369d8b45facfda04cbb8008e) C:\Windows\system32\drivers\Ext2Fsd.sys

02:06:37:536 3468	fastfat		 (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys

02:06:37:559 3468	fdc			 (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys

02:06:37:604 3468	FileInfo		(6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys

02:06:37:621 3468	Filetrace	   (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys

02:06:37:639 3468	flpydisk		(87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys

02:06:37:679 3468	FltMgr		  (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys

02:06:37:704 3468	FsDepends	   (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys

02:06:37:724 3468	Fs_Rec		  (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys

02:06:37:774 3468	fvevol		  (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys

02:06:37:809 3468	gagp30kx		(65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys

02:06:37:841 3468	hcw85cir		(c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys

02:06:37:869 3468	HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys

02:06:37:896 3468	HDAudBus		(717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys

02:06:37:916 3468	HidBatt		 (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys

02:06:37:939 3468	HidBth		  (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys

02:06:37:964 3468	HidIr		   (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys

02:06:37:981 3468	HidUsb		  (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys

02:06:37:996 3468	HpSAMD		  (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys

02:06:38:024 3468	HTTP			(c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys

02:06:38:054 3468	hwpolicy		(8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys

02:06:38:071 3468	i8042prt		(f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys

02:06:38:091 3468	iaStorV		 (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys

02:06:38:119 3468	iirsp		   (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys

02:06:38:136 3468	intelide		(a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys

02:06:38:154 3468	intelppm		(3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys

02:06:38:166 3468	IpFilterDriver  (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys

02:06:38:186 3468	IPMIDRV		 (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys

02:06:38:214 3468	IPNAT		   (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys

02:06:38:234 3468	IRENUM		  (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys

02:06:38:256 3468	isapnp		  (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys

02:06:38:279 3468	iScsiPrt		(ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys

02:06:38:311 3468	kbdclass		(adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys

02:06:38:331 3468	kbdhid		  (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys

02:06:38:359 3468	klmd23		  (67e1faa88fb397b3d56909d7e04f4dd3) C:\Windows\system32\drivers\klmd.sys

02:06:38:394 3468	KSecDD		  (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys

02:06:38:434 3468	KSecPkg		 (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys

02:06:38:469 3468	Lbd			 (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys

02:06:38:489 3468	lltdio		  (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys

02:06:38:519 3468	LSI_FC		  (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys

02:06:38:541 3468	LSI_SAS		 (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys

02:06:38:571 3468	LSI_SAS2		(dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys

02:06:38:591 3468	LSI_SCSI		(0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys

02:06:38:614 3468	luafv		   (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys

02:06:38:636 3468	megasas		 (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys

02:06:38:656 3468	MegaSR		  (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys

02:06:38:679 3468	Modem		   (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys

02:06:38:696 3468	monitor		 (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys

02:06:38:719 3468	MotioninJoyXFilter (ff9cf969e122a19a6948a4e483ccded8) C:\Windows\system32\DRIVERS\MijXfilt.sys

02:06:38:739 3468	mouclass		(fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys

02:06:38:754 3468	mouhid		  (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys

02:06:38:784 3468	mountmgr		(921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys

02:06:38:804 3468	mpio			(2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys

02:06:38:821 3468	mpsdrv		  (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys

02:06:38:839 3468	MRxDAV		  (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys

02:06:38:869 3468	mrxsmb		  (f4a054be78af7f410129c4b64b07dc9b) C:\Windows\system32\DRIVERS\mrxsmb.sys

02:06:38:891 3468	mrxsmb10		(deffa295bd1895c6ed8e3078412ac60b) C:\Windows\system32\DRIVERS\mrxsmb10.sys

02:06:38:916 3468	mrxsmb20		(24d76abe5dcad22f19d105f76fdf0ce1) C:\Windows\system32\DRIVERS\mrxsmb20.sys

02:06:38:934 3468	msahci		  (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys

02:06:38:949 3468	msdsm		   (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys

02:06:38:966 3468	Msfs			(daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys

02:06:38:984 3468	mshidkmdf	   (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys

02:06:39:001 3468	msisadrv		(0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys

02:06:39:026 3468	MSKSSRV		 (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys

02:06:39:046 3468	MSPCLOCK		(3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys

02:06:39:069 3468	MSPQM		   (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys

02:06:39:089 3468	MsRPC		   (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys

02:06:39:124 3468	mssmbios		(fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys

02:06:39:141 3468	MSTEE		   (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys

02:06:39:156 3468	MTConfig		(33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys

02:06:39:201 3468	Mup			 (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys

02:06:39:229 3468	NativeWifiP	 (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys

02:06:39:299 3468	NDIS			(23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys

02:06:39:339 3468	NdisCap		 (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys

02:06:39:361 3468	NdisTapi		(e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys

02:06:39:376 3468	Ndisuio		 (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys

02:06:39:399 3468	NdisWan		 (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys

02:06:39:419 3468	NDProxy		 (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys

02:06:39:451 3468	NetBIOS		 (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys

02:06:39:489 3468	NetBT		   (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys

02:06:39:534 3468	netr28		  (a03fe2ea906e7172290d9888b894903a) C:\Windows\system32\DRIVERS\netr28.sys

02:06:39:571 3468	nfrd960		 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys

02:06:39:589 3468	Npfs			(1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys

02:06:39:611 3468	nsiproxy		(e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys

02:06:39:654 3468	Ntfs			(3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys

02:06:39:709 3468	NTIDrvr		 (7f1c1f78d709c4a54cbb46ede7e0b48d) C:\Windows\system32\DRIVERS\NTIDrvr.sys

02:06:39:726 3468	Null			(f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys

02:06:39:956 3468	nvlddmkm		(c8cb6135884cbc2a10225c4c3cef0f95) C:\Windows\system32\DRIVERS\nvlddmkm.sys

02:06:40:026 3468	nvraid		  (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys

02:06:40:046 3468	nvstor		  (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys

02:06:40:071 3468	nv_agp		  (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys

02:06:40:094 3468	ohci1394		(08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys

02:06:40:114 3468	Parport		 (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys

02:06:40:146 3468	partmgr		 (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys

02:06:40:169 3468	Parvdm		  (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys

02:06:40:201 3468	pci			 (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys

02:06:40:226 3468	pciide		  (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys

02:06:40:249 3468	pcmcia		  (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys

02:06:40:276 3468	pcw			 (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys

02:06:40:301 3468	PEAUTH		  (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys

02:06:40:336 3468	PptpMiniport	(631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys

02:06:40:359 3468	Processor	   (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys

02:06:40:394 3468	Psched		  (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys

02:06:40:441 3468	ql2300		  (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys

02:06:40:494 3468	ql40xx		  (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys

02:06:40:519 3468	QWAVEdrv		(584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys

02:06:40:539 3468	RasAcd		  (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys

02:06:40:569 3468	RasAgileVpn	 (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys

02:06:40:589 3468	Rasl2tp		 (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys

02:06:40:609 3468	RasPppoe		(0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys

02:06:40:626 3468	RasSstp		 (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys

02:06:40:654 3468	rdbss		   (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys

02:06:40:681 3468	rdpbus		  (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys

02:06:40:694 3468	RDPCDD		  (8b4cbb570649f3600f11eafd2c2ccc5f) C:\Windows\system32\DRIVERS\RDPCDD.sys

02:06:40:694 3468	Suspicious file (Forged): C:\Windows\system32\DRIVERS\RDPCDD.sys. Real md5: 8b4cbb570649f3600f11eafd2c2ccc5f, Fake md5: 1e016846895b15a99f9a176a05029075

02:06:40:694 3468	File "C:\Windows\system32\DRIVERS\RDPCDD.sys" infected by TDSS rootkit … 02:06:40:849 3468	Backup copy found, using it..

02:06:40:864 3468	will be cured on next reboot

02:06:40:906 3468	RDPDR		   (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys

02:06:40:921 3468	RDPENCDD		(5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys

02:06:40:936 3468	RDPREFMP		(44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys

02:06:40:961 3468	RDPWD		   (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys

02:06:41:019 3468	rdyboost		(4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys

02:06:41:044 3468	RFCOMM		  (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys

02:06:41:064 3468	rspndr		  (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys

02:06:41:096 3468	RTL8167		 (7dfd48e24479b68b258d8770121155a0) C:\Windows\system32\DRIVERS\Rt86win7.sys

02:06:41:119 3468	s3cap		   (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys

02:06:41:139 3468	sbp2port		(34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys

02:06:41:171 3468	SCDEmu		  (23aa53256ce05b975398b78a33474265) C:\Windows\system32\drivers\SCDEmu.sys

02:06:41:181 3468	scfilter		(a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys

02:06:41:199 3468	secdrv		  (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys

02:06:41:216 3468	Serenum		 (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys

02:06:41:241 3468	Serial		  (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys

02:06:41:261 3468	sermouse		(79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys

02:06:41:279 3468	sffdisk		 (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys

02:06:41:301 3468	sffp_mmc		(932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys

02:06:41:324 3468	sffp_sd		 (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys

02:06:41:344 3468	sfloppy		 (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys

02:06:41:364 3468	sisagp		  (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys

02:06:41:384 3468	SiSRaid2		(a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys

02:06:41:406 3468	SiSRaid4		(3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys

02:06:41:429 3468	Smb			 (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys

02:06:41:449 3468	spldr		   (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys

02:06:41:496 3468	sptd			(cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys

02:06:41:539 3468	srv			 (2ba4ebc7dfba845a1edbe1f75913be33) C:\Windows\system32\DRIVERS\srv.sys

02:06:41:566 3468	srv2			(dce7e10feaabd4cae95948b3de5340bb) C:\Windows\system32\DRIVERS\srv2.sys

02:06:41:591 3468	srvnet		  (b5665baa2120b8a54e22e9cd07c05106) C:\Windows\system32\DRIVERS\srvnet.sys

02:06:41:614 3468	stexstor		(db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys

02:06:41:644 3468	StillCam		(edb05bd63148796f23ea78506404a538) C:\Windows\system32\DRIVERS\serscan.sys

02:06:41:674 3468	storflt		 (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys

02:06:41:701 3468	storvsc		 (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys

02:06:41:716 3468	swenum		  (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys

02:06:41:816 3468	Tcpip		   (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\drivers\tcpip.sys

02:06:41:879 3468	TCPIP6		  (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\DRIVERS\tcpip.sys

02:06:41:904 3468	tcpipreg		(e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys

02:06:41:926 3468	TDPIPE		  (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys

02:06:41:944 3468	TDTCP		   (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys

02:06:41:974 3468	tdx			 (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys

02:06:42:014 3468	TermDD		  (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys

02:06:42:031 3468	tssecsrv		(98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys

02:06:42:051 3468	tunnel		  (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys

02:06:42:071 3468	uagp35		  (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys

02:06:42:096 3468	udfs			(09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys

02:06:42:119 3468	uliagpkx		(44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys

02:06:42:139 3468	umbus		   (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys

02:06:42:164 3468	UmPass		  (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys

02:06:42:181 3468	usbccgp		 (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys

02:06:42:206 3468	usbcir		  (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys

02:06:42:224 3468	usbehci		 (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys

02:06:42:251 3468	usbhub		  (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys

02:06:42:276 3468	usbohci		 (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys

02:06:42:299 3468	usbprint		(797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys

02:06:42:329 3468	USBSTOR		 (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS

02:06:42:346 3468	usbuhci		 (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys

02:06:42:374 3468	usb_rndisx	  (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys

02:06:42:401 3468	vdrvroot		(a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys

02:06:42:434 3468	vga			 (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys

02:06:42:459 3468	VgaSave		 (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys

02:06:42:479 3468	vhdmp		   (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys

02:06:42:499 3468	viaagp		  (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys

02:06:42:524 3468	ViaC7		   (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys

02:06:42:541 3468	viaide		  (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys

02:06:42:574 3468	vmbus		   (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys

02:06:42:599 3468	VMBusHID		(ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys

02:06:42:634 3468	volmgr		  (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys

02:06:42:684 3468	volmgrx		 (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys

02:06:42:734 3468	volsnap		 (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys

02:06:42:756 3468	vsmraid		 (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys

02:06:42:776 3468	vwifibus		(90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys

02:06:42:806 3468	vwififlt		(7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys

02:06:42:824 3468	vwifimp		 (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys

02:06:42:844 3468	WacomPen		(de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys

02:06:42:879 3468	WANARP		  (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys

02:06:42:884 3468	Wanarpv6		(692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys

02:06:42:901 3468	Wd			  (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys

02:06:42:964 3468	Wdf01000		(9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys

02:06:42:986 3468	WfpLwf		  (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys

02:06:43:009 3468	WIMMount		(5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys

02:06:43:031 3468	WmiAcpi		 (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys

02:06:43:051 3468	ws2ifsl		 (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys

02:06:43:074 3468	WudfPf		  (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys

02:06:43:101 3468	WUDFRd		  (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys

02:06:43:129 3468	xusb21		  (ee9144207ee0211eb5656ba6808ac4a0) C:\Windows\system32\DRIVERS\xusb21.sys

02:06:43:131 3468	Reboot required for cure complete..

02:06:43:331 3468	Cure on reboot scheduled successfully

02:06:43:331 3468	

02:06:43:331 3468	Completed

02:06:43:331 3468	

02:06:43:331 3468	Results:

02:06:43:331 3468	Registry objects infected / cured / cured on reboot:	0 / 0 / 0

02:06:43:331 3468	File objects infected / cured / cured on reboot:	1 / 0 / 1

02:06:43:331 3468	

02:06:43:334 3468	KLMD(ARK) unloaded successfully

ComboFix Log
ComboFix 10-06-16.02 - Maha 06/17/2010   3:28.4.2 - x86

Microsoft Windows 7 Ultimate   6.1.7600.0.1252.2.1033.18.2046.987 [GMT -4:00]

Running from: c:\users\[removed]\Desktop\ComboFix.exe

Command switches used :: c:\users\Maha\Desktop\CFScript.txt

.



(((((((((((((((((((((((((   Files Created from 2010-05-17 to 2010-06-17  )))))))))))))))))))))))))))))))

.



2010-06-16 21:30 . 2010-06-16 21:30	3304	——w-	C:\bootsqm.dat

2010-06-16 07:27 . 2010-06-09 13:58	85464	—-a-w-	c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll

2010-06-16 07:27 . 2010-06-09 13:58	38872	—-a-w-	c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINCE\components\WeaveCrypto.dll

2010-06-15 09:59 . 2010-06-15 10:00	——–	d—–w-	c:\users\Maha\KeeperData

2010-06-15 09:59 . 2010-06-15 09:59	——–	d—–w-	c:\program files\Callpod

2010-06-14 00:00 . 2010-06-13 23:33	64288	—-a-w-	c:\windows\system32\drivers\Lbd.sys

2010-06-13 03:50 . 2010-06-14 02:37	——–	d—–w-	c:\users\Maha\AppData\Roaming\dvdcss

2010-06-12 07:58 . 2010-06-12 07:58	——–	d—–w-	c:\program files\Microsoft Games for Windows - LIVE

2010-06-12 07:58 . 2010-06-12 07:58	——–	d—–w-	c:\windows\system32\xlive

2010-06-12 06:42 . 2010-06-12 06:43	——–	d—–w-	c:\users\Maha\AppData\Roaming\KVIrc

2010-06-12 06:42 . 2010-06-12 06:42	——–	d—–w-	c:\users\Maha\download

2010-06-12 06:39 . 2010-06-12 06:42	——–	d—–w-	c:\program files\KVIrc

2010-06-11 23:02 . 2010-06-11 23:02	48648	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll

2010-06-11 23:02 . 2010-06-11 23:02	573760	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll

2010-06-11 23:02 . 2010-06-11 23:02	737072	—-a-w-	c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll

2010-06-11 23:01 . 2010-06-11 23:01	29512	—-a-w-	c:\programdata\avg9\update\backup\avgmfx86.sys

2010-06-11 23:01 . 2010-06-11 23:01	242896	—-a-w-	c:\programdata\avg9\update\backup\avgtdix.sys



.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-06-17 07:37 . 2010-04-25 21:42	——–	d—–w-	c:\users\Maha\AppData\Roaming\.purple

2010-06-17 07:36 . 2010-05-13 02:52	——–	d—–w-	c:\users\Maha\AppData\Roaming\Dropbox

2010-06-17 07:25 . 2010-04-26 05:20	——–	d—–w-	c:\users\Maha\AppData\Roaming\Skype

2010-06-17 07:22 . 2009-07-14 02:37	——–	d—–w-	c:\program files\Windows Mail

2010-06-17 06:19 . 2010-06-17 06:19	2165	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\rsi.hotmail.com

2010-06-17 06:19 . 2010-06-17 06:19	2157	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\omega.contacts.msn.com

2010-06-17 06:19 . 2010-06-17 06:19	2095	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\login.live.com

2010-06-17 06:19 . 2010-06-17 06:19	1089	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\login.yahoo.com

2010-06-17 06:19 . 2009-07-14 00:01	6656	—-a-w-	c:\windows\system32\drivers\RDPCDD.sys

2010-06-17 02:06 . 2010-04-25 22:43	——–	d—–w-	c:\program files\Vuze

2010-06-17 01:37 . 2010-04-27 02:50	48648	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll

2010-06-17 01:37 . 2010-04-27 02:50	573760	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll

2010-06-17 01:37 . 2010-04-27 02:50	737072	—-a-w-	c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll

2010-06-16 21:32 . 2010-04-26 05:21	——–	d—–w-	c:\users\Maha\AppData\Roaming\skypePM

2010-06-16 21:10 . 2010-04-25 22:43	——–	d—–w-	c:\users\Maha\AppData\Roaming\Azureus

2010-06-15 04:25 . 2010-04-26 07:00	——–	d—–w-	c:\users\Maha\AppData\Roaming\vlc

2010-06-14 02:34 . 2010-04-25 23:47	——–	d—–w-	c:\programdata\Zoom Player

2010-06-14 00:41 . 2010-04-27 01:04	65	—-a-w-	c:\windows\system32\bd7020.dat

2010-06-12 23:14 . 2010-04-26 02:12	——–	d—–w-	c:\program files\Brother

2010-06-12 23:14 . 2010-04-25 15:10	——–	d–h–w-	c:\program files\InstallShield Installation Information

2010-06-12 07:52 . 2010-04-25 20:31	——–	d—–w-	c:\program files\Common Files\Steam

2010-06-11 23:10 . 2010-04-25 23:28	——–	d—–w-	c:\program files\Google

2010-06-11 23:01 . 2010-04-25 21:00	242896	—-a-w-	c:\windows\system32\drivers\avgtdix.sys

2010-06-11 23:01 . 2010-04-25 21:00	29584	—-a-w-	c:\windows\system32\drivers\avgmfx86.sys

2010-05-18 01:54 . 2010-05-14 10:30	——–	d—–w-	c:\programdata\Spybot - Search & Destroy

2010-05-18 01:54 . 2010-05-14 10:30	——–	d—–w-	c:\program files\Spybot - Search & Destroy

2010-05-18 01:53 . 2010-05-14 08:55	——–	d—–w-	c:\users\Maha\AppData\Roaming\OpenOffice.org

2010-05-18 01:53 . 2010-05-13 01:51	——–	d—–w-	c:\program files\MotioninJoy

2010-05-14 08:58 . 2010-05-14 08:58	1	—-a-w-	c:\users\Maha\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys

2010-05-13 05:28 . 2010-04-26 23:37	174	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\restart.bat

2010-05-13 04:46 . 2010-05-13 04:46	——–	d—–w-	c:\users\Maha\AppData\Roaming\KeePass

2010-05-13 04:45 . 2010-05-13 04:45	——–	d—–w-	c:\program files\KeePass Password Safe 2

2010-05-13 02:52 . 2010-05-13 02:52	89831	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\Uninstall.exe

2010-05-13 01:53 . 2010-05-13 01:53	0	—ha-w-	c:\windows\system32\drivers\Msft_Kernel_xusb21_01009.Wdf

2010-05-13 01:53 . 2010-05-13 01:53	0	—ha-w-	c:\windows\system32\drivers\Msft_Kernel_MijXfilt_01009.Wdf

2010-05-13 01:51 . 2010-05-13 01:51	——–	d—–w-	c:\users\Maha\AppData\Roaming\MotioninJoy

2010-05-13 01:51 . 2010-05-13 01:51	——–	d—–w-	c:\programdata\MotioninJoy

2010-05-12 04:44 . 2010-04-26 00:23	——–	d—–w-	c:\programdata\Microsoft Help

2010-05-09 00:39 . 2010-05-09 00:39	——–	d—–w-	c:\users\Maha\AppData\Roaming\OtakuSoftware

2010-05-08 22:36 . 2010-05-08 08:18	15880	—-a-w-	c:\windows\system32\lsdelete.exe

2010-05-08 10:06 . 2010-05-08 10:06	——–	d—–w-	c:\users\Maha\AppData\Roaming\360desktop

2010-05-08 09:20 . 2010-05-08 09:20	——–	d—–w-	c:\users\Maha\AppData\Roaming\BMG

2010-05-02 08:33 . 2010-05-02 08:33	——–	d—–w-	c:\program files\Gabest

2010-05-02 06:41 . 2010-05-02 06:41	15884	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\azitunes\libProcessAccess.dll

2010-05-02 06:41 . 2010-05-02 06:41	102400	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll

2010-05-02 06:41 . 2010-05-02 06:41	7282688	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe

2010-05-02 06:41 . 2010-05-02 06:41	4141117	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe

2010-05-02 06:10 . 2010-05-02 06:10	——–	d—–w-	c:\users\Maha\AppData\Roaming\AnvSoft

2010-05-02 06:10 . 2010-05-02 06:10	——–	d—–w-	c:\program files\AnvSoft

2010-05-02 00:37 . 2010-05-01 21:44	——–	d—–w-	c:\users\Maha\AppData\Roaming\WinFF

2010-05-01 21:44 . 2010-05-01 21:44	——–	d—–w-	c:\program files\WinFF

2010-05-01 21:14 . 2010-04-25 18:54	——–	d—–w-	c:\program files\Opera

2010-05-01 19:16 . 2010-05-01 19:16	——–	d—–w-	c:\users\Maha\AppData\Roaming\AVS4YOU

2010-05-01 19:16 . 2010-04-25 21:00	——–	d—–w-	c:\programdata\AVG Security Toolbar

2010-05-01 19:16 . 2010-05-01 19:14	——–	d—–w-	c:\programdata\AVS4YOU

2010-05-01 19:15 . 2010-05-01 19:14	——–	d—–w-	c:\program files\AVS4YOU

2010-05-01 19:15 . 2010-05-01 19:14	——–	d—–w-	c:\program files\Common Files\AVSMedia

2010-04-27 02:24 . 2010-04-27 02:23	——–	d—–w-	c:\program files\DVDStyler

2010-04-27 02:23 . 2010-04-27 02:23	——–	d—–w-	c:\program files\Burn To DVD

2010-04-27 01:38 . 2010-04-27 01:38	——–	d—–r-	c:\users\Maha\AppData\Roaming\Brother

2010-04-27 00:19 . 2010-04-25 22:41	——–	d—–w-	c:\users\Maha\AppData\Roaming\uTorrent

2010-04-27 00:19 . 2009-07-13 23:40	409088	—-a-w-	c:\windows\system32\systemcpl.dll

2010-04-27 00:19 . 2009-07-13 23:36	13824	—-a-w-	c:\windows\system32\slwga.dll

2010-04-27 00:19 . 2009-07-13 23:24	811520	—-a-w-	c:\windows\system32\user32.dll

2010-04-26 20:40 . 2010-04-26 20:40	——–	d—–w-	c:\users\Maha\AppData\Roaming\Media Player Classic

2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\AIM Toolbar

2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\AIM

2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\Common Files\AOL

2010-04-26 08:08 . 2010-04-25 23:21	——–	d—–w-	c:\program files\NVIDIA Corporation

2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTIMPEG2.dll

2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTIMP3.dll

2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTICDMK7.dll

2010-04-26 07:51 . 2010-04-26 07:51	6144	——w-	c:\windows\system32\drivers\NTIDrvr.sys

2010-04-26 07:33 . 2010-04-25 23:37	——–	d—–w-	c:\program files\Ext2Fsd

2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\DCoder Image Source

2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\7-Zip

2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\FFMPEG Core Files

2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\SHOUTcast Source

2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\MONOGRAM AMR SplitterDecoder

2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\CD Audio Reader Filter

2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource AVI Splitter

2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\Gabest MPEG Splitter

2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource DTSAC3DD+ Source Filter

2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\RealMedia

2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\DScaler5

2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\AC3Filter

2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource Flash Video Splitter

2010-04-26 07:28 . 2010-04-26 07:28	——–	d—–w-	c:\program files\DirectVobSub

2010-04-26 07:28 . 2010-04-26 07:28	——–	d—–w-	c:\program files\Haali

2010-04-26 07:28 . 2010-04-25 23:48	——–	d—–w-	c:\program files\Bass Audio Decoder

2010-04-26 07:27 . 2010-04-25 23:47	——–	d—–w-	c:\program files\Zoom Player

2010-04-26 07:23 . 2010-04-25 22:45	——–	d—–w-	c:\users\Maha\AppData\Roaming\DAEMON Tools Lite

2010-04-26 07:18 . 2010-04-25 22:45	——–	d—–w-	c:\program files\PowerISO

2010-04-26 07:17 . 2010-04-26 07:17	——–	d—–w-	c:\program files\DAEMON Tools Toolbar

2010-04-26 07:17 . 2010-04-25 22:46	——–	d—–w-	c:\program files\DAEMON Tools Lite

2010-04-26 07:16 . 2010-04-26 07:16	691696	——w-	c:\windows\system32\drivers\sptd.sys

2010-04-26 07:15 . 2010-04-25 23:13	——–	d—–w-	c:\program files\Audacity

2010-04-26 06:58 . 2010-04-26 06:58	95024	——w-	c:\windows\system32\drivers\SBREDrv.sys

2010-04-26 06:56 . 2010-04-25 23:27	——–	dc-h–w-	c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}

2010-04-26 06:47 . 2010-04-25 22:43	113712	—-a-w-	c:\users\Maha\AppData\Local\GDIPFONTCACHEV1.DAT

2009-06-10 21:26 . 2009-07-14 02:04	9633792	–sha-r-	c:\windows\Fonts\StaticCache.dat

2009-07-14 01:14 . 2009-07-13 23:42	396800	–sha-w-	c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

.



——- Sigcheck ——-



[-] 2010-04-27 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll

.

(((((((((((((((((((((((((((((   SnapShot_2010-06-17_00.34.07   )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-04-25 20:52 . 2010-06-17 07:26	30814			  c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 04:55 . 2010-06-17 07:26	36408			  c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin

- 2010-04-25 14:27 . 2010-06-16 23:32	49152			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-04-25 14:27 . 2010-06-17 07:24	49152			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-07-14 04:41 . 2010-06-16 23:32	49152			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:41 . 2010-06-17 07:24	49152			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-04-25 15:02 . 2010-06-17 00:29	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-04-25 15:02 . 2010-06-17 07:25	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-04-25 15:02 . 2010-06-17 00:29	32768			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-04-25 15:02 . 2010-06-17 07:25	32768			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2010-04-25 15:02 . 2010-06-17 00:29	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-04-25 15:02 . 2010-06-17 07:25	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-04-25 15:02 . 2010-06-17 00:26	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-04-25 15:02 . 2010-06-17 07:25	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-04-25 17:58 . 2010-06-17 07:31	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat

- 2010-04-25 17:58 . 2010-06-17 00:05	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat

+ 2010-04-25 17:58 . 2010-06-17 07:31	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat

- 2010-04-25 17:58 . 2010-06-17 00:05	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat

+ 2010-04-25 17:58 . 2010-06-17 07:31	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat

- 2010-04-25 17:58 . 2010-06-17 00:05	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat

- 2010-04-25 15:02 . 2010-06-17 00:26	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-04-25 15:02 . 2010-06-17 07:31	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-04-25 15:02 . 2010-06-17 07:25	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-04-25 15:02 . 2010-06-17 00:26	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-04-25 20:11 . 2010-06-17 07:26	6718			  c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1037914879-3900162407-3989981119-1001_UserData.bin

+ 2010-06-17 07:23 . 2010-06-17 07:36	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2010-06-17 00:26 . 2010-06-17 00:26	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2010-06-17 07:23 . 2010-06-17 07:36	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2010-06-17 00:26 . 2010-06-17 00:26	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2010-06-17 06:56 . 2009-09-10 06:26	257024			  c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7600.20524_none_7d52c0e5dccc347d\msv1_0.dll

+ 2010-06-17 06:56 . 2009-09-10 05:52	257024			  c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7600.16420_none_7cc522f2c3b22f57\msv1_0.dll

+ 2010-06-17 06:55 . 2010-01-28 02:11	128424			  c:\windows\winsxs\x86_microsoft-windows-s..ologies-webcontrols_31bf3856ad364e35_7.1.7600.16395_none_39bc056e339474f4\WatWeb.dll

+ 2010-06-17 06:55 . 2010-01-28 02:11	114600			  c:\windows\winsxs\x86_microsoft-windows-s..ologies-webcontrols_31bf3856ad364e35_7.1.7600.16395_none_39bc056e339474f4\npWatWeb.dll

+ 2010-06-17 06:55 . 2010-01-28 02:11	249768			  c:\windows\winsxs\x86_microsoft-windows-s..ivationtechnologies_31bf3856ad364e35_7.1.7600.16395_none_2dac82dbc20710f5\WatUX.exe

+ 2010-06-17 07:23 . 2010-06-17 07:23	128424			  c:\windows\winsxs\Temp\PendingRenames\f65ddb0dee0dcb0130000000d8043405.WatWeb.dll

+ 2010-06-17 07:17 . 2010-06-17 07:17	128424			  c:\windows\winsxs\Temp\PendingRenames\ced0b036ed0dcb013400000098042c05.WatWeb.dll

+ 2010-06-17 07:23 . 2010-06-17 07:23	114600			  c:\windows\winsxs\Temp\PendingRenames\96fcd80dee0dcb012f000000d8043405.npWatWeb.dll

+ 2010-06-17 07:17 . 2010-06-17 07:17	114600			  c:\windows\winsxs\Temp\PendingRenames\6e6fae36ed0dcb013300000098042c05.npWatWeb.dll

+ 2010-06-17 07:23 . 2010-06-17 07:23	249768			  c:\windows\winsxs\Temp\PendingRenames\57bfdd0dee0dcb0131000000d8043405.WatUX.exe

+ 2010-06-17 07:17 . 2010-06-17 07:17	249768			  c:\windows\winsxs\Temp\PendingRenames\2e32b336ed0dcb013500000098042c05.WatUX.exe

+ 2009-07-14 02:05 . 2010-06-17 07:28	619206			  c:\windows\System32\perfh009.dat

- 2009-07-14 02:05 . 2010-06-17 00:31	619206			  c:\windows\System32\perfh009.dat

- 2009-07-14 02:05 . 2010-06-17 00:31	107388			  c:\windows\System32\perfc009.dat

+ 2009-07-14 02:05 . 2010-06-17 07:28	107388			  c:\windows\System32\perfc009.dat

- 2009-07-14 04:33 . 2010-05-13 01:39	427432			  c:\windows\System32\FNTCACHE.DAT

+ 2009-07-14 04:33 . 2010-06-17 07:23	427432			  c:\windows\System32\FNTCACHE.DAT

+ 2010-06-17 07:21 . 2010-06-17 07:21	705024			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\f335d7d1029aa934986acece3a635939\Microsoft.MediaCenter.Sports.ni.dll

- 2010-05-13 01:40 . 2010-05-13 01:40	324096			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\e5a6bb7d8f34559e2024c62babee5d86\Microsoft.MediaCenter.Playback.ni.dll

+ 2010-06-17 07:24 . 2010-06-17 07:24	324096			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\e5a6bb7d8f34559e2024c62babee5d86\Microsoft.MediaCenter.Playback.ni.dll

- 2010-05-13 01:40 . 2010-05-13 01:40	229888			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cc61539a8e48c0883a6b3a4ddf845205\Microsoft.MediaCenter.iTv.ni.dll

+ 2010-06-17 07:24 . 2010-06-17 07:24	229888			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cc61539a8e48c0883a6b3a4ddf845205\Microsoft.MediaCenter.iTv.ni.dll

+ 2010-06-17 07:22 . 2010-06-17 07:22	229888			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cbdddbcdca1579a6cc099978cc7296e0\Microsoft.MediaCenter.iTv.ni.dll

+ 2010-06-17 07:22 . 2010-06-17 07:22	142848			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\b71b9c373e27540d6224bc5f01ce9449\Microsoft.MediaCenter.iTv.Media.ni.dll

- 2010-05-13 01:40 . 2010-05-13 01:40	705024			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7289063be214d2d4ce367a298949cae7\Microsoft.MediaCenter.Sports.ni.dll

+ 2010-06-17 07:24 . 2010-06-17 07:24	705024			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7289063be214d2d4ce367a298949cae7\Microsoft.MediaCenter.Sports.ni.dll

+ 2010-06-17 07:24 . 2010-06-17 07:24	142848			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\44402a1799f222acbec11a2730cf1882\Microsoft.MediaCenter.iTv.Media.ni.dll

- 2010-05-13 01:40 . 2010-05-13 01:40	142848			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\44402a1799f222acbec11a2730cf1882\Microsoft.MediaCenter.iTv.Media.ni.dll

+ 2010-06-17 07:21 . 2010-06-17 07:21	326144			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\42a11e7164074f20b499b1bb794b1cfb\Microsoft.MediaCenter.Playback.ni.dll

+ 2010-06-17 07:21 . 2010-06-17 07:21	693248			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\eca169340ae5df7480031aa29e1e213d\ehRecObj.ni.dll

- 2010-05-13 01:40 . 2010-05-13 01:40	693248			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\3ad30d4c99b971d43964139031ab365f\ehRecObj.ni.dll

+ 2010-06-17 07:24 . 2010-06-17 07:24	693248			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\3ad30d4c99b971d43964139031ab365f\ehRecObj.ni.dll

+ 2010-06-17 06:55 . 2010-01-28 02:11	1343400			  c:\windows\winsxs\x86_microsoft-windows-s..ivationtechnologies_31bf3856ad364e35_7.1.7600.16395_none_2dac82dbc20710f5\WatAdminSvc.exe

+ 2010-06-17 07:23 . 2010-06-17 07:23	1343400			  c:\windows\winsxs\Temp\PendingRenames\d639d40dee0dcb012e000000d8043405.WatAdminSvc.exe

+ 2010-06-17 07:17 . 2010-06-17 07:17	1343400			  c:\windows\winsxs\Temp\PendingRenames\adaca936ed0dcb013200000098042c05.WatAdminSvc.exe

- 2009-07-14 02:03 . 2010-06-16 21:20	7340032			  c:\windows\System32\SMI\Store\Machine\schema.dat

+ 2009-07-14 02:03 . 2010-06-17 07:35	7340032			  c:\windows\System32\SMI\Store\Machine\schema.dat

+ 2010-04-25 14:27 . 2010-06-17 07:24	1622016			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2010-04-25 14:27 . 2010-06-16 23:32	1622016			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-06-17 07:28 . 2010-06-17 07:28	7217152			  c:\windows\ERDNT\Hiv-backup\schema.dat

+ 2010-06-17 07:21 . 2010-06-17 07:21	3318784			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\eae730343aec2ba0aa22746cf0e14433\mcepg.ni.dll

- 2010-05-13 01:40 . 2010-05-13 01:40	3317248			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\e9c41a0951e933b0589c708f3bd1fb73\mcepg.ni.dll

+ 2010-06-17 07:24 . 2010-06-17 07:24	3317248			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\e9c41a0951e933b0589c708f3bd1fb73\mcepg.ni.dll

+ 2009-07-14 07:18 . 2010-06-17 06:56	16521150			  c:\windows\winsxs\ManifestCache\e4e8be02b8fae2a7_blobs.bin

+ 2010-06-17 06:56 . 2010-04-30 15:51	32058312			  c:\windows\System32\MRT.exe

+ 2010-06-17 07:22 . 2010-06-17 07:22	18683904			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\d569c1d188cbab71c6ecb9ab354a90b1\ehshell.ni.dll

- 2010-05-13 01:40 . 2010-05-13 01:40	18679296			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\9b3d5ac3c6d0a37e98396f5702964566\ehshell.ni.dll

+ 2010-06-17 07:24 . 2010-06-17 07:24	18679296			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\9b3d5ac3c6d0a37e98396f5702964566\ehshell.ni.dll

.

– Snapshot reset to current date –

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4



[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]



[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]



[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

2010-02-23 18:04	1664256	—-a-w-	c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]



[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]



[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]



[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll



[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Pidgin"="c:\program files\Pidgin\pidgin.exe" [2010-02-16 45603]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]

"DS3 Tool"="c:\program files\MotioninJoy\ds3\DS3_Tool.exe" [2010-01-19 77824]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]

"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]

"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]

"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]

"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]

"Ext2 Volume Manager"="c:\program files\Ext2Fsd\Ext2Mgr.exe" [2009-07-30 1216648]



c:\users\Maha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\Maha\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]

OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]



c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2010-4-25 1576960]



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"



[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk

backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup

backupExtension=.CommonStartup



[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk

backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup

backupExtension=.CommonStartup



[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]

2004-12-14 06:12	483328	—-a-w-	c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe



[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]

2009-07-27 02:37	180224	—-a-w-	c:\program files\PowerISO\PWRISOVM.EXE



R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 135664]

R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-02-23 369920]

R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-16 1352832]

R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]

R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-04-26 691696]

S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-13 64288]

S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-04-25 216200]

S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-06-11 242896]

S1 Ext2Fsd;Linux ext2 file system driver; [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]

S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-04-25 916760]

S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-04-25 308064]

S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [2010-03-18 48640]

S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [2009-08-04 616960]

S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]



.

Contents of the 'Scheduled Tasks' folder



2010-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:56]



2010-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:56]

.

.

——- Supplementary Scan ——-

.

uInternet Settings,ProxyOverride = *.local

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: {DF59BE5D-7566-46BB-AD9E-484E898B646B} = 8.8.8.8,8.8.4.4

Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

FF - ProfilePath - c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\

FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul

FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll

FF - component: c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll



—- FIREFOX POLICIES —-

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pre
f", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

.

.

——————— LOCKED REGISTRY KEYS ———————



[HKEY_USERS\S-1-5-21-1037914879-3900162407-3989981119-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFD4E303-F5AB-6CB0-6EB8-E0E44EEB4DC4}*]

"paaphbglbkfpfpoehlhpbfpofipmgkkp"=hex:6a,61,66,70,6a,62,62,6d,70,62,69,6a,64,

   67,69,66,70,62,62,65,00,b9

"abgofpbbjmegkimnollecfocoeimiadbom"=hex:69,61,6d,70,6f,62,6c,64,66,6c,6a,68,

   6a,6c,6c,69,6c,6f,00,00



[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

——————— DLLs Loaded Under Running Processes ———————



- - - - - - - > 'Explorer.exe'(3696)

c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

.

———————— Other Running Processes ————————

.

c:\windows\system32\AUDIODG.EXE

c:\windows\system32\WLANExt.exe

c:\windows\system32\conhost.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

c:\program files\EDIMAX\Common\RaRegistry.exe

c:\program files\AVG\AVG9\avgnsx.exe

c:\program files\AVG\AVG9\avgcsrvx.exe

c:\windows\system32\WUDFHost.exe

c:\program files\AVG\AVG9\avgchsvx.exe

c:\program files\AVG\AVG9\avgrsx.exe

c:\program files\AVG\AVG9\avgcsrvx.exe

c:\windows\system32\taskhost.exe

c:\windows\system32\conhost.exe

c:\program files\Brother\ControlCenter3\brccMCtl.exe

c:\program files\OpenOffice.org 3\program\soffice.exe

c:\program files\OpenOffice.org 3\program\soffice.bin

c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

c:\program files\Windows Media Player\wmpnetwk.exe

.

**************************************************************************

.

Completion time: 2010-06-17  03:39:00 - machine was rebooted

ComboFix-quarantined-files.txt  2010-06-17 07:38

ComboFix2.txt  2010-06-17 06:35

ComboFix3.txt  2010-06-17 00:35

ComboFix4.txt  2010-05-13 05:58



Pre-Run: 61,610,381,312 bytes free

Post-Run: 61,502,435,328 bytes free



- - End Of File - - 9A494D7D65F221771B94E27BF66B7E0A
MahaSMB,

You have a bad system file that we need to replace. Do you have a Windows 7 installation disk? We will need one if I can't find a replacement on your PC.

🖼Click to load external image (Posted Image) Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *user32*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please include the following in your next post:
  • SystemLook log
Yes, I have a Windows 7 CD.

Two things of note. Although you told me not to install anything since we've started, whenever I've shut down Windows 7 it goes ahead and installs Windows 7 Updates. I don't really know how to disable it. And also my internet's stopped working even though I'm connected to my wifi network just fine. I haven't looked into the internet problem yet (I'm having to log into my Ubuntu, on the same computer, to access the internet) but I just wanted to know if that's to be expected? If it's not, I'll just tinker with it myself to see what the problem is after we're done here.

Thank you for your help thus far.

SystemLook.txt
SystemLook v1.0 by jpshortstuff (11.01.10)

Log created at 18:46 on 17/06/2010 by Maha (Administrator - Elevation successful)



========== filefind ==========



Searching for "	  "

No files found.



Searching for "*user32*"

C:\watcom-1.3\lib386\nt\user32.lib	–a— 358912 bytes	[04:48 02/11/2009]	[04:48 02/11/2009] 10F336798592D84F92CFB656BF383814

C:\Windows\System32\en-US\user32.dll.mui	–a— 17920 bytes	[04:55 14/07/2009]	[02:03 14/07/2009] D448B52149F95F1250100F9BD0ED7152

C:\Windows\System32\manifeststore\user32.amx	–a— 368328 bytes	[23:25 13/07/2009]	[23:25 13/07/2009] 74FA96FC74E0C6B3CCC328A6781D6DFC

C:\Windows\System32\user32.dll	–a— 811520 bytes	[23:24 13/07/2009]	[00:19 27/04/2010] 7BD7F45FF37FA0669CD32CA0EF46E22C

C:\Windows\System32\user32.dll.bak	–a— 811520 bytes	[23:24 13/07/2009]	[01:16 14/07/2009] 34B7E222E81FAFA885F0C5F2CFA56861

C:\Windows\winsxs\Backup\x86_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7600.16385_en-us_3dd44ded8c70cf7e.manifest	–a— 2378 bytes	[04:56 14/07/2009]	[04:56 14/07/2009] 312B257CA3798A27278FBE7CC4E55E92

C:\Windows\winsxs\Backup\x86_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7600.16385_en-us_3dd44ded8c70cf7e_user32.dll.mui_14652dbb	–a— 17920 bytes	[04:56 14/07/2009]	[04:56 14/07/2009] D448B52149F95F1250100F9BD0ED7152

C:\Windows\winsxs\Backup\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3.manifest	–a— 2731 bytes	[02:19 14/07/2009]	[02:18 14/07/2009] FEB66AF751DE4AF556DE1FAF69C49A37

C:\Windows\winsxs\Backup\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3_user32.dll_55f4ed20	–a— 811520 bytes	[02:19 14/07/2009]	[02:18 14/07/2009] 34B7E222E81FAFA885F0C5F2CFA56861

C:\Windows\winsxs\Manifests\x86_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7600.16385_en-us_3dd44ded8c70cf7e.manifest	–a— 2378 bytes	[04:54 14/07/2009]	[02:29 14/07/2009] 312B257CA3798A27278FBE7CC4E55E92

C:\Windows\winsxs\Manifests\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3.manifest	–a— 2731 bytes	[02:03 14/07/2009]	[01:58 14/07/2009] FEB66AF751DE4AF556DE1FAF69C49A37

C:\Windows\winsxs\x86_microsoft-windows-a..structure-manifests_31bf3856ad364e35_6.1.7600.16385_none_9da1bb3614a5f5bf\user32.amx	–a— 368328 bytes	[23:25 13/07/2009]	[23:25 13/07/2009] 74FA96FC74E0C6B3CCC328A6781D6DFC

C:\Windows\winsxs\x86_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7600.16385_en-us_3dd44ded8c70cf7e\user32.dll.mui	–a— 17920 bytes	[04:55 14/07/2009]	[02:03 14/07/2009] D448B52149F95F1250100F9BD0ED7152

C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll	–a— 811520 bytes	[23:24 13/07/2009]	[01:16 14/07/2009] 34B7E222E81FAFA885F0C5F2CFA56861



-=End Of File=-
Hi MahaSMB,

🖼Click to load external image (Posted Image) If your network icon appears on the Windows taskbar, then you can repair it by right-clicking on the icon and selecting Repair.

[external image: Posted Image]

If you have no task bar icon do this:
  • Click on the Start button.
  • Click on the Settings menu option.
  • Click on the Control Panel option.
  • When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
  • You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
  • click on the Repair menu option.

[external image: Posted Image]

Let the repair process perform its tasks and when it has finished, your Internet connection should be working again.

If that doesn't work - try the following:
  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.
In I.E.
  • Check internet options settings.
  • Tools > Internet Options > Connections
  • LAN settings
  • Choose "automatically detect settings"
  • uncheck both proxy settings boxes
In FireFox
  • Click on Advanced -> Network -> Setttings…
  • the No Proxy option should be selected
🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above FCopy::

FCopy::
C:\Windows\System32\user32.dll.bak | C:\Windows\System32\user32.dll

RegNull::
[HKEY_USERS\S-1-5-21-1037914879-3900162407-3989981119-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFD4E303-F5AB-6CB0-6EB8-E0E44EEB4DC4}*]

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
Please include the following in your next post:
  • ComboFix log
ComboFix 10-06-16.02 - Maha 06/18/2010  17:31:11.5.2 - x86

Microsoft Windows 7 Ultimate   6.1.7600.0.1252.2.1033.18.2046.1015 [GMT -4:00]

Running from: c:\users\[removed]\Desktop\ComboFix.exe

Command switches used :: c:\users\Maha\Desktop\CFScript.txt

.



(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.



.

————— FCopy —————



c:\windows\System32\user32.dll.bak –> c:\windows\System32\user32.dll

.

(((((((((((((((((((((((((   Files Created from 2010-05-18 to 2010-06-18  )))))))))))))))))))))))))))))))

.



2010-06-18 21:36 . 2010-06-18 21:36	——–	d—–w-	c:\users\Public\AppData\Local\temp

2010-06-18 21:36 . 2010-06-18 21:36	——–	d—–w-	c:\users\Default\AppData\Local\temp

2010-06-18 21:30 . 2010-06-18 21:30	——–	d—–w-	C:\32788R22FWJFW

2010-06-17 06:19 . 2010-06-17 06:19	2165	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\rsi.hotmail.com

2010-06-17 06:19 . 2010-06-17 06:19	2157	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\omega.contacts.msn.com

2010-06-17 06:19 . 2010-06-17 06:19	2095	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\login.live.com

2010-06-17 06:19 . 2010-06-17 06:19	1089	—-a-w-	c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\login.yahoo.com

2010-06-17 00:35 . 2010-06-18 21:36	——–	d—–w-	c:\users\Maha\AppData\Local\temp

2010-06-16 21:30 . 2010-06-16 21:30	3304	——w-	C:\bootsqm.dat

2010-06-16 07:27 . 2010-06-09 13:58	85464	—-a-w-	c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll

2010-06-16 07:27 . 2010-06-09 13:58	38872	—-a-w-	c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINCE\components\WeaveCrypto.dll

2010-06-15 09:59 . 2010-06-15 10:00	——–	d—–w-	c:\users\Maha\KeeperData

2010-06-15 09:59 . 2010-06-15 09:59	——–	d—–w-	c:\program files\Callpod

2010-06-14 00:00 . 2010-06-13 23:33	64288	—-a-w-	c:\windows\system32\drivers\Lbd.sys

2010-06-13 03:50 . 2010-06-14 02:37	——–	d—–w-	c:\users\Maha\AppData\Roaming\dvdcss

2010-06-12 07:58 . 2010-06-12 07:58	——–	d—–w-	c:\program files\Microsoft Games for Windows - LIVE

2010-06-12 07:58 . 2010-06-12 07:58	——–	d—–w-	c:\windows\system32\xlive

2010-06-12 06:42 . 2010-06-12 06:43	——–	d—–w-	c:\users\Maha\AppData\Roaming\KVIrc

2010-06-12 06:42 . 2010-06-12 06:42	——–	d—–w-	c:\users\Maha\download

2010-06-12 06:39 . 2010-06-12 06:42	——–	d—–w-	c:\program files\KVIrc

2010-06-11 23:02 . 2010-06-11 23:02	48648	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll

2010-06-11 23:02 . 2010-06-11 23:02	573760	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll

2010-06-11 23:02 . 2010-06-11 23:02	737072	—-a-w-	c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll

2010-06-11 23:01 . 2010-06-11 23:01	29512	—-a-w-	c:\programdata\avg9\update\backup\avgmfx86.sys

2010-06-11 23:01 . 2010-06-11 23:01	242896	—-a-w-	c:\programdata\avg9\update\backup\avgtdix.sys



.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-06-18 21:33 . 2010-04-25 21:42	——–	d—–w-	c:\users\Maha\AppData\Roaming\.purple

2010-06-18 21:12 . 2010-04-26 05:20	——–	d—–w-	c:\users\Maha\AppData\Roaming\Skype

2010-06-18 21:12 . 2010-05-13 02:52	——–	d—–w-	c:\users\Maha\AppData\Roaming\Dropbox

2010-06-17 22:41 . 2009-07-14 02:37	——–	d—–w-	c:\program files\Windows Mail

2010-06-17 06:19 . 2009-07-14 00:01	6656	—-a-w-	c:\windows\system32\drivers\RDPCDD.sys

2010-06-17 02:06 . 2010-04-25 22:43	——–	d—–w-	c:\program files\Vuze

2010-06-17 01:37 . 2010-04-27 02:50	48648	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll

2010-06-17 01:37 . 2010-04-27 02:50	573760	—-a-w-	c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll

2010-06-17 01:37 . 2010-04-27 02:50	737072	—-a-w-	c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll

2010-06-16 21:32 . 2010-04-26 05:21	——–	d—–w-	c:\users\Maha\AppData\Roaming\skypePM

2010-06-16 21:10 . 2010-04-25 22:43	——–	d—–w-	c:\users\Maha\AppData\Roaming\Azureus

2010-06-15 04:25 . 2010-04-26 07:00	——–	d—–w-	c:\users\Maha\AppData\Roaming\vlc

2010-06-14 02:34 . 2010-04-25 23:47	——–	d—–w-	c:\programdata\Zoom Player

2010-06-14 00:41 . 2010-04-27 01:04	65	—-a-w-	c:\windows\system32\bd7020.dat

2010-06-12 23:14 . 2010-04-26 02:12	——–	d—–w-	c:\program files\Brother

2010-06-12 23:14 . 2010-04-25 15:10	——–	d–h–w-	c:\program files\InstallShield Installation Information

2010-06-12 07:52 . 2010-04-25 20:31	——–	d—–w-	c:\program files\Common Files\Steam

2010-06-11 23:10 . 2010-04-25 23:28	——–	d—–w-	c:\program files\Google

2010-06-11 23:01 . 2010-04-25 21:00	242896	—-a-w-	c:\windows\system32\drivers\avgtdix.sys

2010-06-11 23:01 . 2010-04-25 21:00	29584	—-a-w-	c:\windows\system32\drivers\avgmfx86.sys

2010-05-18 01:54 . 2010-05-14 10:30	——–	d—–w-	c:\programdata\Spybot - Search & Destroy

2010-05-18 01:54 . 2010-05-14 10:30	——–	d—–w-	c:\program files\Spybot - Search & Destroy

2010-05-18 01:53 . 2010-05-14 08:55	——–	d—–w-	c:\users\Maha\AppData\Roaming\OpenOffice.org

2010-05-18 01:53 . 2010-05-13 01:51	——–	d—–w-	c:\program files\MotioninJoy

2010-05-14 08:58 . 2010-05-14 08:58	1	—-a-w-	c:\users\Maha\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys

2010-05-13 05:28 . 2010-04-26 23:37	174	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\restart.bat

2010-05-13 04:46 . 2010-05-13 04:46	——–	d—–w-	c:\users\Maha\AppData\Roaming\KeePass

2010-05-13 04:45 . 2010-05-13 04:45	——–	d—–w-	c:\program files\KeePass Password Safe 2

2010-05-13 02:52 . 2010-05-13 02:52	89831	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\Uninstall.exe

2010-05-13 01:53 . 2010-05-13 01:53	0	—ha-w-	c:\windows\system32\drivers\Msft_Kernel_xusb21_01009.Wdf

2010-05-13 01:53 . 2010-05-13 01:53	0	—ha-w-	c:\windows\system32\drivers\Msft_Kernel_MijXfilt_01009.Wdf

2010-05-13 01:51 . 2010-05-13 01:51	——–	d—–w-	c:\users\Maha\AppData\Roaming\MotioninJoy

2010-05-13 01:51 . 2010-05-13 01:51	——–	d—–w-	c:\programdata\MotioninJoy

2010-05-12 04:44 . 2010-04-26 00:23	——–	d—–w-	c:\programdata\Microsoft Help

2010-05-09 00:39 . 2010-05-09 00:39	——–	d—–w-	c:\users\Maha\AppData\Roaming\OtakuSoftware

2010-05-08 22:36 . 2010-05-08 08:18	15880	—-a-w-	c:\windows\system32\lsdelete.exe

2010-05-08 10:06 . 2010-05-08 10:06	——–	d—–w-	c:\users\Maha\AppData\Roaming\360desktop

2010-05-08 09:20 . 2010-05-08 09:20	——–	d—–w-	c:\users\Maha\AppData\Roaming\BMG

2010-05-02 08:33 . 2010-05-02 08:33	——–	d—–w-	c:\program files\Gabest

2010-05-02 06:41 . 2010-05-02 06:41	15884	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\azitunes\libProcessAccess.dll

2010-05-02 06:41 . 2010-05-02 06:41	102400	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll

2010-05-02 06:41 . 2010-05-02 06:41	7282688	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe

2010-05-02 06:41 . 2010-05-02 06:41	4141117	—-a-w-	c:\users\Maha\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe

2010-05-02 06:10 . 2010-05-02 06:10	——–	d—–w-	c:\users\Maha\AppData\Roaming\AnvSoft

2010-05-02 06:10 . 2010-05-02 06:10	——–	d—–w-	c:\program files\AnvSoft

2010-05-02 00:37 . 2010-05-01 21:44	——–	d—–w-	c:\users\Maha\AppData\Roaming\WinFF

2010-05-01 21:44 . 2010-05-01 21:44	——–	d—–w-	c:\program files\WinFF

2010-05-01 21:14 . 2010-04-25 18:54	——–	d—–w-	c:\program files\Opera

2010-05-01 19:16 . 2010-05-01 19:16	——–	d—–w-	c:\users\Maha\AppData\Roaming\AVS4YOU

2010-05-01 19:16 . 2010-04-25 21:00	——–	d—–w-	c:\programdata\AVG Security Toolbar

2010-05-01 19:16 . 2010-05-01 19:14	——–	d—–w-	c:\programdata\AVS4YOU

2010-05-01 19:15 . 2010-05-01 19:14	——–	d—–w-	c:\program files\AVS4YOU

2010-05-01 19:15 . 2010-05-01 19:14	——–	d—–w-	c:\program files\Common Files\AVSMedia

2010-04-27 02:24 . 2010-04-27 02:23	——–	d—–w-	c:\program files\DVDStyler

2010-04-27 02:23 . 2010-04-27 02:23	——–	d—–w-	c:\program files\Burn To DVD

2010-04-27 01:38 . 2010-04-27 01:38	——–	d—–r-	c:\users\Maha\AppData\Roaming\Brother

2010-04-27 00:19 . 2010-04-25 22:41	——–	d—–w-	c:\users\Maha\AppData\Roaming\uTorrent

2010-04-27 00:19 . 2009-07-13 23:40	409088	—-a-w-	c:\windows\system32\systemcpl.dll

2010-04-27 00:19 . 2009-07-13 23:36	13824	—-a-w-	c:\windows\system32\slwga.dll

2010-04-26 20:40 . 2010-04-26 20:40	——–	d—–w-	c:\users\Maha\AppData\Roaming\Media Player Classic

2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\AIM Toolbar

2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\AIM

2010-04-26 08:08 . 2010-04-25 21:57	——–	d—–w-	c:\program files\Common Files\AOL

2010-04-26 08:08 . 2010-04-25 23:21	——–	d—–w-	c:\program files\NVIDIA Corporation

2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTIMPEG2.dll

2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTIMP3.dll

2010-04-26 07:51 . 2010-04-26 07:51	1024	——w-	c:\windows\system32\NTICDMK7.dll

2010-04-26 07:51 . 2010-04-26 07:51	6144	——w-	c:\windows\system32\drivers\NTIDrvr.sys

2010-04-26 07:33 . 2010-04-25 23:37	——–	d—–w-	c:\program files\Ext2Fsd

2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\DCoder Image Source

2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\7-Zip

2010-04-26 07:30 . 2010-04-25 23:49	——–	d—–w-	c:\program files\FFMPEG Core Files

2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\SHOUTcast Source

2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\MONOGRAM AMR SplitterDecoder

2010-04-26 07:29 . 2010-04-26 07:29	——–	d—–w-	c:\program files\CD Audio Reader Filter

2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource AVI Splitter

2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\Gabest MPEG Splitter

2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource DTSAC3DD+ Source Filter

2010-04-26 07:29 . 2010-04-25 23:49	——–	d—–w-	c:\program files\RealMedia

2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\DScaler5

2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\AC3Filter

2010-04-26 07:28 . 2010-04-25 23:49	——–	d—–w-	c:\program files\OpenSource Flash Video Splitter

2010-04-26 07:28 . 2010-04-26 07:28	——–	d—–w-	c:\program files\DirectVobSub

2010-04-26 07:28 . 2010-04-26 07:28	——–	d—–w-	c:\program files\Haali

2010-04-26 07:28 . 2010-04-25 23:48	——–	d—–w-	c:\program files\Bass Audio Decoder

2010-04-26 07:27 . 2010-04-25 23:47	——–	d—–w-	c:\program files\Zoom Player

2010-04-26 07:23 . 2010-04-25 22:45	——–	d—–w-	c:\users\Maha\AppData\Roaming\DAEMON Tools Lite

2010-04-26 07:18 . 2010-04-25 22:45	——–	d—–w-	c:\program files\PowerISO

2010-04-26 07:17 . 2010-04-26 07:17	——–	d—–w-	c:\program files\DAEMON Tools Toolbar

2010-04-26 07:17 . 2010-04-25 22:46	——–	d—–w-	c:\program files\DAEMON Tools Lite

2010-04-26 07:16 . 2010-04-26 07:16	691696	——w-	c:\windows\system32\drivers\sptd.sys

2010-04-26 07:15 . 2010-04-25 23:13	——–	d—–w-	c:\program files\Audacity

2010-04-26 06:58 . 2010-04-26 06:58	95024	——w-	c:\windows\system32\drivers\SBREDrv.sys

2010-04-26 06:56 . 2010-04-25 23:27	——–	dc-h–w-	c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}

2010-04-26 06:47 . 2010-04-25 22:43	113712	—-a-w-	c:\users\Maha\AppData\Local\GDIPFONTCACHEV1.DAT

2010-04-26 06:42 . 2010-04-25 23:30	——–	d—–w-	c:\program files\Combined Community Codec Pack

2010-04-26 06:37 . 2010-04-25 22:08	——–	d—–w-	c:\program files\Common Files\Adobe

2010-04-26 06:32 . 2010-04-25 15:09	——–	d—–w-	c:\program files\Common Files\InstallShield

2010-04-26 05:44 . 2010-04-26 05:44	——–	d—–w-	c:\programdata\Adobe Systems

2010-04-26 05:41 . 2010-04-26 05:41	——–	d—–w-	c:\program files\Common Files\Adobe Systems Shared

2009-06-10 21:26 . 2009-07-14 02:04	9633792	–sha-r-	c:\windows\Fonts\StaticCache.dat

2009-07-14 01:14 . 2009-07-13 23:42	396800	–sha-w-	c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

.



(((((((((((((((((((((((((((((   SnapShot_2010-06-17_07.36.52   )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-04-25 20:52 . 2010-06-18 21:13	31244			  c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 04:55 . 2010-06-18 21:13	36456			  c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin

- 2010-04-25 14:27 . 2010-06-17 07:24	49152			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-04-25 14:27 . 2010-06-17 22:42	49152			  c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-07-14 04:41 . 2010-06-17 07:24	49152			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:41 . 2010-06-17 22:42	49152			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-04-25 15:02 . 2010-06-17 07:25	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-04-25 15:02 . 2010-06-18 21:03	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-04-25 15:02 . 2010-06-17 07:25	32768			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-04-25 15:02 . 2010-06-18 21:03	32768			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2010-04-25 15:02 . 2010-06-17 07:25	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-04-25 15:02 . 2010-06-18 21:03	16384			  c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-04-25 15:02 . 2010-06-18 21:03	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-04-25 15:02 . 2010-06-17 07:25	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-04-25 17:58 . 2010-06-17 07:31	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat

+ 2010-04-25 17:58 . 2010-06-18 21:17	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat

+ 2010-04-25 17:58 . 2010-06-18 21:17	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat

- 2010-04-25 17:58 . 2010-06-17 07:31	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat

+ 2010-04-25 17:58 . 2010-06-18 21:17	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat

- 2010-04-25 17:58 . 2010-06-17 07:31	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat

+ 2010-04-25 15:02 . 2010-06-18 21:05	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2010-04-25 15:02 . 2010-06-17 07:31	32768			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2010-04-25 15:02 . 2010-06-17 07:25	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-04-25 15:02 . 2010-06-18 21:03	16384			  c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-04-25 20:11 . 2010-06-18 21:13	6902			  c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1037914879-3900162407-3989981119-1001_UserData.bin

- 2010-06-17 07:23 . 2010-06-17 07:36	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2010-06-18 21:00 . 2010-06-18 21:00	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2010-06-18 21:00 . 2010-06-18 21:00	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2010-06-17 07:23 . 2010-06-17 07:36	2048			  c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2010-06-17 22:36 . 2010-06-17 22:36	128424			  c:\windows\winsxs\Temp\PendingRenames\c9c83a906d0ecb0134000000c4043005.WatWeb.dll

+ 2010-06-17 22:42 . 2010-06-17 22:42	249768			  c:\windows\winsxs\Temp\PendingRenames\a5b5826b6e0ecb0131000000b0043805.WatUX.exe

+ 2010-06-17 22:36 . 2010-06-17 22:36	114600			  c:\windows\winsxs\Temp\PendingRenames\696738906d0ecb0133000000c4043005.npWatWeb.dll

+ 2010-06-17 22:42 . 2010-06-17 22:42	128424			  c:\windows\winsxs\Temp\PendingRenames\4554806b6e0ecb0130000000b0043805.WatWeb.dll

+ 2010-06-17 22:42 . 2010-06-17 22:42	114600			  c:\windows\winsxs\Temp\PendingRenames\4554806b6e0ecb012f000000b0043805.npWatWeb.dll

+ 2010-06-17 22:36 . 2010-06-17 22:36	249768			  c:\windows\winsxs\Temp\PendingRenames\292a3d906d0ecb0135000000c4043005.WatUX.exe

- 2009-07-14 02:05 . 2010-06-17 07:28	619206			  c:\windows\System32\perfh009.dat

+ 2009-07-14 02:05 . 2010-06-18 21:05	619206			  c:\windows\System32\perfh009.dat

- 2009-07-14 02:05 . 2010-06-17 07:28	107388			  c:\windows\System32\perfc009.dat

+ 2009-07-14 02:05 . 2010-06-18 21:05	107388			  c:\windows\System32\perfc009.dat

+ 2009-07-14 04:33 . 2010-06-17 22:42	427432			  c:\windows\System32\FNTCACHE.DAT

- 2009-07-14 04:33 . 2010-06-17 07:23	427432			  c:\windows\System32\FNTCACHE.DAT

+ 2010-06-17 22:40 . 2010-06-17 22:40	705024			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\f335d7d1029aa934986acece3a635939\Microsoft.MediaCenter.Sports.ni.dll

- 2010-06-17 07:21 . 2010-06-17 07:21	705024			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\f335d7d1029aa934986acece3a635939\Microsoft.MediaCenter.Sports.ni.dll

- 2010-06-17 07:24 . 2010-06-17 07:24	324096			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\e5a6bb7d8f34559e2024c62babee5d86\Microsoft.MediaCenter.Playback.ni.dll

+ 2010-06-17 22:43 . 2010-06-17 22:43	324096			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\e5a6bb7d8f34559e2024c62babee5d86\Microsoft.MediaCenter.Playback.ni.dll

+ 2010-06-17 22:43 . 2010-06-17 22:43	229888			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cc61539a8e48c0883a6b3a4ddf845205\Microsoft.MediaCenter.iTv.ni.dll

- 2010-06-17 07:24 . 2010-06-17 07:24	229888			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cc61539a8e48c0883a6b3a4ddf845205\Microsoft.MediaCenter.iTv.ni.dll

+ 2010-06-17 22:40 . 2010-06-17 22:40	229888			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cbdddbcdca1579a6cc099978cc7296e0\Microsoft.MediaCenter.iTv.ni.dll

- 2010-06-17 07:22 . 2010-06-17 07:22	229888			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cbdddbcdca1579a6cc099978cc7296e0\Microsoft.MediaCenter.iTv.ni.dll

+ 2010-06-17 22:40 . 2010-06-17 22:40	142848			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\b71b9c373e27540d6224bc5f01ce9449\Microsoft.MediaCenter.iTv.Media.ni.dll

- 2010-06-17 07:22 . 2010-06-17 07:22	142848			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\b71b9c373e27540d6224bc5f01ce9449\Microsoft.MediaCenter.iTv.Media.ni.dll

+ 2010-06-17 22:43 . 2010-06-17 22:43	705024			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7289063be214d2d4ce367a298949cae7\Microsoft.MediaCenter.Sports.ni.dll

- 2010-06-17 07:24 . 2010-06-17 07:24	705024			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7289063be214d2d4ce367a298949cae7\Microsoft.MediaCenter.Sports.ni.dll

- 2010-06-17 07:24 . 2010-06-17 07:24	142848			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\44402a1799f222acbec11a2730cf1882\Microsoft.MediaCenter.iTv.Media.ni.dll

+ 2010-06-17 22:43 . 2010-06-17 22:43	142848			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\44402a1799f222acbec11a2730cf1882\Microsoft.MediaCenter.iTv.Media.ni.dll

+ 2010-06-17 22:40 . 2010-06-17 22:40	326144			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\42a11e7164074f20b499b1bb794b1cfb\Microsoft.MediaCenter.Playback.ni.dll

- 2010-06-17 07:21 . 2010-06-17 07:21	326144			  c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\42a11e7164074f20b499b1bb794b1cfb\Microsoft.MediaCenter.Playback.ni.dll

+ 2010-06-18 21:06 . 2010-06-18 21:06	380928			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcupdate\2eeb09776f9810b16fab1d211cee7ed9\mcupdate.ni.exe

+ 2010-06-18 21:06 . 2010-06-18 21:06	371712			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcplayerinterop\538b12512ac230727365602043d4e746\mcplayerinterop.ni.dll

+ 2010-06-18 21:06 . 2010-06-18 21:06	515584			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcGlidHostObj\54b0bdea9ce18978e27fcdbd940a12b8\mcGlidHostObj.ni.dll

+ 2010-06-18 21:06 . 2010-06-18 21:06	107520			  c:\windows\assembly\NativeImages_v2.0.50727_32\MCESidebarCtrl\f092b0c94c7cd26ff5e4e4b4aad42762\MCESidebarCtrl.ni.dll

+ 2010-06-17 22:40 . 2010-06-17 22:40	693248			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\eca169340ae5df7480031aa29e1e213d\ehRecObj.ni.dll

- 2010-06-17 07:21 . 2010-06-17 07:21	693248			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\eca169340ae5df7480031aa29e1e213d\ehRecObj.ni.dll

- 2010-06-17 07:24 . 2010-06-17 07:24	693248			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\3ad30d4c99b971d43964139031ab365f\ehRecObj.ni.dll

+ 2010-06-17 22:43 . 2010-06-17 22:43	693248			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\3ad30d4c99b971d43964139031ab365f\ehRecObj.ni.dll

+ 2010-06-17 22:36 . 2010-06-17 22:36	1343400			  c:\windows\winsxs\Temp\PendingRenames\a8a433906d0ecb0132000000c4043005.WatAdminSvc.exe

+ 2010-06-17 22:42 . 2010-06-17 22:42	1343400			  c:\windows\winsxs\Temp\PendingRenames\84917b6b6e0ecb012e000000b0043805.WatAdminSvc.exe

- 2009-07-14 02:03 . 2010-06-17 07:35	7340032			  c:\windows\System32\SMI\Store\Machine\schema.dat

+ 2009-07-14 02:03 . 2010-06-17 22:49	7340032			  c:\windows\System32\SMI\Store\Machine\schema.dat

- 2010-04-25 14:27 . 2010-06-17 07:24	1622016			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-04-25 14:27 . 2010-06-17 22:42	1622016			  c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-06-17 22:40 . 2010-06-17 22:40	3318784			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\eae730343aec2ba0aa22746cf0e14433\mcepg.ni.dll

- 2010-06-17 07:21 . 2010-06-17 07:21	3318784			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\eae730343aec2ba0aa22746cf0e14433\mcepg.ni.dll

- 2010-06-17 07:24 . 2010-06-17 07:24	3317248			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\e9c41a0951e933b0589c708f3bd1fb73\mcepg.ni.dll

+ 2010-06-17 22:43 . 2010-06-17 22:43	3317248			  c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\e9c41a0951e933b0589c708f3bd1fb73\mcepg.ni.dll

+ 2010-06-17 22:40 . 2010-06-17 22:40	18683904			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\d569c1d188cbab71c6ecb9ab354a90b1\ehshell.ni.dll

- 2010-06-17 07:22 . 2010-06-17 07:22	18683904			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\d569c1d188cbab71c6ecb9ab354a90b1\ehshell.ni.dll

- 2010-06-17 07:24 . 2010-06-17 07:24	18679296			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\9b3d5ac3c6d0a37e98396f5702964566\ehshell.ni.dll

+ 2010-06-17 22:43 . 2010-06-17 22:43	18679296			  c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\9b3d5ac3c6d0a37e98396f5702964566\ehshell.ni.dll

.

– Snapshot reset to current date –

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4



[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]



[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]



[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

2010-02-23 18:04	1664256	—-a-w-	c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]



[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]



[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]



[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19	94208	—-a-w-	c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll



[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Pidgin"="c:\program files\Pidgin\pidgin.exe" [2010-02-16 45603]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]

"DS3 Tool"="c:\program files\MotioninJoy\ds3\DS3_Tool.exe" [2010-01-19 77824]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]

"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]

"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]

"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]

"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]

"Ext2 Volume Manager"="c:\program files\Ext2Fsd\Ext2Mgr.exe" [2009-07-30 1216648]



c:\users\Maha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\Maha\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]

OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]



c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2010-4-25 1576960]



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"



[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk

backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup

backupExtension=.CommonStartup



[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk

backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup

backupExtension=.CommonStartup



[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]

2004-12-14 06:12	483328	—-a-w-	c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe



[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]

2009-07-27 02:37	180224	—-a-w-	c:\program files\PowerISO\PWRISOVM.EXE



R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 135664]

R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-02-23 369920]

R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-16 1352832]

R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-04-26 691696]

S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-13 64288]

S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-04-25 216200]

S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-06-11 242896]

S1 Ext2Fsd;Linux ext2 file system driver; [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]

S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-04-25 916760]

S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-04-25 308064]

S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [2010-03-18 48640]

S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [2009-08-04 616960]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]

S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]



.

Contents of the 'Scheduled Tasks' folder



2010-06-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:56]



2010-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:56]

.

.

——- Supplementary Scan ——-

.

uInternet Settings,ProxyOverride = *.local

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: {DF59BE5D-7566-46BB-AD9E-484E898B646B} = 8.8.8.8,8.8.4.4

Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

FF - ProfilePath - c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\

FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul

FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll

FF - component: c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll



—- FIREFOX POLICIES —-

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pre
f", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

.

.

——————— LOCKED REGISTRY KEYS ———————



[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

——————— DLLs Loaded Under Running Processes ———————



- - - - - - - > 'Explorer.exe'(4328)

c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

.

Completion time: 2010-06-18  17:38:06

ComboFix-quarantined-files.txt  2010-06-18 21:38

ComboFix2.txt  2010-06-17 07:39

ComboFix3.txt  2010-06-17 06:35

ComboFix4.txt  2010-06-17 00:35

ComboFix5.txt  2010-06-18 21:29



Pre-Run: 62,117,363,712 bytes free

Post-Run: 62,064,414,720 bytes free



- - End Of File - - FAD80A4D3E8CC02425AC286654B40D7F
Hi MahaSMB,

Were you able to restore your internet connectivity? Your logs are starting to look better, please run these for me next:

🖼Click to load external image (Posted Image) Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post the results.
🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • MBAM log
  • Kaspersky log
Yes, I got my internet working.

MBAM Log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4214

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

6/20/2010 03:07:36
mbam-log-2010-06-20 (03-07-36).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 467813
Time elapsed: 1 hour(s), 8 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Kaspersky Log
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
 Sunday, June 20, 2010
 Operating system: Microsoft Professional (build 7600)
 Kaspersky Online Scanner version: 7.0.26.13
 Last database update: Friday, June 18, 2010 22:02:01
 Records in database: 4292311
——————————————————————————–

Scan settings:
	scan using the following database: extended
	Scan archives: yes
	Scan e-mail databases: yes

Scan area - My Computer:
	A:\
	C:\
	D:\
	E:\
	F:\
	H:\
	N:\
	P:\
	U:\

Scan statistics:
	Objects scanned: 331691
	Threats found: 4
	Infected objects found: 10
	Suspicious objects found: 0
	Scan duration: 05:02:00


File name / Threat / Threats count
C:\Program Files\mIRC\mirc.exe	Infected: not-a-virus:Client-IRC.Win32.mIRC.g	1
C:\Qoobox\Quarantine\C\Windows\system32\Drivers\RDPCDD.sys.vir	Infected: Rootkit.Win32.TDSS.ap	1
D:\my-documents\maha\computer-stuff\acidmax\acidmax2120.zip	Infected: not-a-virus:Client-IRC.Win32.mIRC.617	1
D:\my-documents\maha\computer-stuff\acidmax\mirc.exe	Infected: not-a-virus:Client-IRC.Win32.mIRC.617	1
D:\my-documents\maha\irc&im\NeXtGenIRC_4104\NeXtGenIRC\mirc.exe	Infected: not-a-virus:Client-IRC.Win32.mIRC.g	1
D:\my-documents\maha\irc&im\NoNameScript\mIRC\backups\mirc.exe	Infected: not-a-virus:Client-IRC.Win32.mIRC.g	1
D:\my-documents\maha\irc&im\NoNameScript\mIRC\mirc.exe	Infected: not-a-virus:Client-IRC.Win32.mIRC.g	1
D:\my-documents\maha\irc&im\NoNameScript\mirc634.exe	Infected: not-a-virus:Client-IRC.Win32.mIRC.g	1
D:\my-documents\maha\irc&im\NoNameScript\mirc635.exe	Infected: not-a-virus:Client-IRC.Win32.mIRC.g	1
D:\my-documents\maha\Phones-PDAs\palm\palm-zire\HandWalletInstall.exe	Infected: not-a-virus:AdWare.Win32.Rabio.wy	1

Selected area has been scanned.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI