This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

goggle hijack

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My searches get redirected to shopping sites or another faux search engine. Often when I actually get to a web page that I am looking for, a second, uninvited page will pop up on a second tab. They are never porn sites; always shopping or search engines.

Thanks for any help!

-Stuart

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:20:04 PM, on 6/19/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [BHR] C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1262617144187
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1262617741375
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

–
End of file - 6500 bytes
Hi stusouth60, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Make sure these settings are correct.

Open Internet Explorer
  • at the top click Tools
  • Click Internet Options
  • Click Connections tab
  • Click Lan Settings button
  • Make sure the box beside "Use a proxy sever for your Lan" is UNchecked
  • OK your way out.

Next

Open hijackthis, do a system scan only and checkmark these lines, if present

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.


Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode



Next

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
Thanks
OTL Extras logfile created on: 6/20/2010 5:12:49 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Stuart Southerland\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 79.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 713.44 Gb Free Space | 76.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 298.08 Gb Total Space | 264.52 Gb Free Space | 88.74% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STUART-OF1P8HQI
Current User Name: Stuart Southerland
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager – (Electronic Arts)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Steam\steamapps\common\painkiller black edition\Bin\Painkiller.exe" = C:\Program Files\Steam\steamapps\common\painkiller black edition\Bin\Painkiller.exe:*:Enabled:Painkiller: Black Edition – (People Can Fly)
"C:\Program Files\Steam\steamapps\common\the witcher enhanced edition\System\witcher.exe" = C:\Program Files\Steam\steamapps\common\the witcher enhanced edition\System\witcher.exe:*:Enabled:The Witcher: Enhanced Edition – (CD Projekt Red)
"C:\Program Files\Steam\steamapps\common\the witcher enhanced edition\System\djinni!.exe" = C:\Program Files\Steam\steamapps\common\the witcher enhanced edition\System\djinni!.exe:*:Enabled:The Witcher: Enhanced Edition – (CD Projekt Red)
"C:\Program Files\Steam\steamapps\common\stalker shadow of chernobyl\bin\XR_3DA.exe" = C:\Program Files\Steam\steamapps\common\stalker shadow of chernobyl\bin\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R.: Shadow of Chernobyl – ()
"C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe" = C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade – (THQ Canada Inc.)
"C:\Program Files\Steam\steamapps\common\company of heroes\RelicCOH.exe" = C:\Program Files\Steam\steamapps\common\company of heroes\RelicCOH.exe:*:Enabled:Company of Heroes – (THQ Canada Inc.)
"C:\Program Files\Steam\steamapps\common\company of heroes\help.htm" = C:\Program Files\Steam\steamapps\common\company of heroes\help.htm:*:Enabled:Company of Heroes – ()
"C:\Program Files\Steam\steamapps\common\company of heroes\RelicDownloader\RelicDownloader.exe" = C:\Program Files\Steam\steamapps\common\company of heroes\RelicDownloader\RelicDownloader.exe:*:Enabled:Relic Patch Download Manager – (THQ Canada Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\THQ\Dawn Of War\W40k.exe" = C:\Program Files\THQ\Dawn Of War\W40k.exe:*:Enabled:W40k – (THQ Canada Inc.)
"C:\Program Files\Steam\steamapps\common\the secret of monkey island special edition\MISE.exe" = C:\Program Files\Steam\steamapps\common\the secret of monkey island special edition\MISE.exe:*:Enabled:The Secret of Monkey Island: Special Edition – ()
"C:\Program Files\Mass Effect 2\Binaries\MassEffect2.exe" = C:\Program Files\Mass Effect 2\Binaries\MassEffect2.exe:*:Enabled:Mass Effect 2 Game – (BioWare)
"C:\Program Files\Mass Effect 2\MassEffect2Launcher.exe" = C:\Program Files\Mass Effect 2\MassEffect2Launcher.exe:*:Enabled:Mass Effect 2 Launcher – (BioWare)
"C:\Program Files\2K Games\BioShock 2\SP\Builds\Binaries\Bioshock2.exe" = C:\Program Files\2K Games\BioShock 2\SP\Builds\Binaries\Bioshock2.exe:*:Enabled:BioShock 2 – (Take-Two Interactive Software)
"C:\Program Files\2K Games\BioShock 2\MP\Builds\Binaries\Bioshock2.exe" = C:\Program Files\2K Games\BioShock 2\MP\Builds\Binaries\Bioshock2.exe:*:Enabled:BioShock 2 Multiplayer – (2K Games)
"C:\Program Files\Steam\steamapps\common\mass effect\Binaries\MassEffect.exe" = C:\Program Files\Steam\steamapps\common\mass effect\Binaries\MassEffect.exe:*:Enabled:Mass Effect – (BioWare)
"D:\Setup.exe" = D:\Setup.exe:*:Enabled:Setup – File not found
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD_Demo.exe" = C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD_Demo.exe:*:Enabled:Serious Sam HD: The First Encounter Demo – (Croteam)
"C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD.exe" = C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD.exe:*:Enabled:Serious Sam HD: The First Encounter – (Croteam)
"C:\Program Files\Steam\steamapps\common\torchlight\Torchlight.exe" = C:\Program Files\Steam\steamapps\common\torchlight\Torchlight.exe:*:Enabled:Torchlight Demo – (Runic Games, Inc.)
"C:\Program Files\Steam\steamapps\common\dawn of war 2\DOW2.exe" = C:\Program Files\Steam\steamapps\common\dawn of war 2\DOW2.exe:*:Enabled:Warhammer® 40,000â„¢: Dawn of War® II – (THQ Canada Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero Burning ROM Help
"{0B25271C-C90B-056F-B4B1-84DFCC905497}" = ATI Catalyst Install Manager
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP600" = Canon MP600
"{141C141A-0DB8-E6E5-59AA-27576C20B75D}" = CCC Help English
"{1648DB98-AE62-6E92-F418-8A9ECCA078A9}" = Catalyst Control Center Graphics Previews Common
"{17200570-C3A0-DAAB-8232-491FEC0C1DF4}" = Catalyst Control Center Graphics Full Existing
"{17E83691-BC8E-BA2A-DE9B-AE845E1C2457}" = Catalyst Control Center Graphics Light
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F698102-5739-441E-96F0-74F4EA540F06}" = Attansic Ethernet Utility
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{29D851C2-048C-4B5E-8D1F-25D473342BB5}" = ScanSoft OmniPage SE 4.0
"{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE
"{310BC5E2-31AF-49BB-904D-E71EB93645DC}" = AI Suite
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3BD76F20-EAA2-012B-AE7F-000000000000}" = TurboTax 2009 wokiper
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3D74A25E-F4A1-DD65-3327-FEE3C85A2565}" = Catalyst Control Center HydraVision Full
"{3F64C088-9A45-41B3-8B99-71AFAB720A56}" = Sherlock Holmes versus Jack the Ripper
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A8B461A-9336-4CF9-98F4-14DD38E673F0}" = BioShock 2
"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1
"{5454085C-840F-4070-8FAA-441000018301}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000018302}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000018303}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000018304}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000028301}" = BioShock 2
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5e08ecd1-c98e-4711-bf65-8fd736b3f969}" = Nero RescueAgent Help
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{605BE2E8-D0D4-C157-68FD-40A318258E54}" = ccc-core-preinstall
"{60c731fb-c951-41ce-ad41-8e54c8594609}" = Nero Disc Copy Gadget Help
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{71E8DEC6-8785-B293-FA6D-7A37A3D3E773}" = ccc-core-static
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{77e33d87-255e-413e-9c8d-eed2a7f9bebf}" = Nero Live Help
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{7F3AD00A-1819-4B15-BB7D-08B3586336D7}" = 3DMark06
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83F12F73-D52E-40C0-93B1-463C311C4E17}" = Warhammer 40,000: Dawn Of War - Gold Edition
"{85243696-5e58-4357-9cf8-3498c609941d}" = NeroLiveGadget Help
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{88713CAC-8759-6FE4-D577-A823E5865CB9}" = ccc-utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91B323B5-A79C-4D23-BD6D-046C565F9BCF}" = MadOnion.com/3DMark2001 SE
"{94A065E8-455D-41C1-AF1F-F0C1AF8F50F3}" = Microsoft IntelliType Pro 7.0
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98a67610-a3b5-4098-a423-3708040026d3}" = "Nero SoundTrax Help
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A93FE10A-42C3-B498-2856-2BBE22481A7A}" = Catalyst Control Center Graphics Full New
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{B2BAD2AF-A391-4306-96A3-BA1139630D84}" = Catalyst Control Center InstallProxy
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed
"{e8631efb-6b9a-426c-b1ce-e7173ca26bf8}" = Nero WaveEditor Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F029DBBC-FBBD-20CD-7038-6A703578EC79}" = Catalyst Control Center Core Implementation
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FC47C7A5-BE63-11D5-B7C9-005004566E4D}" = ViewSonic Windows XP Signed Files
"{fc803937-97f8-4004-8ad1-7c6063e2712d}" = Nero 9 Trial
"{FF39FC01-819B-42E4-AE49-1968AF12DDD4}" = Dawn of War - Dark Crusade
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Abuse" = Abuse
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 5.0 Limited Edition" = Adobe Photoshop 5.0 Limited Edition
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AtcL1" = Attansic L1 Gigabit Ethernet Driver
"AudioCS" = Creative Audio Console
"BitTorrent" = BitTorrent
"CanonMyPrinter" = Canon My Printer
"Convert_is1" = Convert 1.0 beta
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.53
"Creative Jukebox Driver" = Creative Jukebox Driver
"Creative NOMAD II Driver" = Creative NOMAD II Driver
"Creative PlayCenter 2.0" = Creative PlayCenter 2
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Darkness Within: In Pursuit of Loath Nolder_is1" = Darkness Within: In Pursuit of Loath Nolder 1.00
"EADM" = EA Download Manager
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"ffdshow_is1" = ffdshow [rev 589] [2006-11-26]
"Gabriel Knight 2 - The Beast Within_is1" = Gabriel Knight 2 - The Beast Within
"Gabriel Knight 3 - Blood of the Sacred, Blood of~B6A61117_is1" = Gabriel Knight 3 - Blood of the Sacred, Blood of the Damned
"GameSpy Arcade" = GameSpy Arcade
"Giants – Citizen Kabuto_is1" = Giants – Citizen Kabuto
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MP Navigator 3.0" = Canon MP Navigator 3.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenAL" = OpenAL
"Picasa 3" = Picasa 3
"RealPlayer 12.0" = RealPlayer
"ScummVM_is1" = ScummVM 1.0.0
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"Steam App 17460" = Mass Effect
"Steam App 20900" = The Witcher: Enhanced Edition
"Steam App 220" = Half-Life 2
"Steam App 280" = Half-Life: Source
"Steam App 32360" = The Secret of Monkey Island: Special Edition
"Steam App 360" = Half-Life Deathmatch: Source
"Steam App 380" = Half-Life 2: Episode One
"Steam App 39530" = Painkiller: Black Edition
"Steam App 41020" = Serious Sam HD: The First Encounter Demo
"Steam App 41510" = Torchlight Demo
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 4500" = S.T.A.L.K.E.R.: Shadow of Chernobyl
"Steam App 4560" = Company of Heroes
"The Penal Zone" = Sam and Max - The Devil's Playhouse - The Penal Zone
"The Tomb of Sammun-Mak" = Sam and Max - The Devil's Playhouse - The Tomb of Sammun-Mak
"TotalRecorder" = Total Recorder 8.0
"TurboTax 2009" = TurboTax 2009
"Under a Killing Moon_is1" = Under a Killing Moon
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Application Detect

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/21/2010 10:22:58 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.

Error - 2/21/2010 10:41:54 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.

Error - 2/21/2010 11:39:47 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.

Error - 2/21/2010 11:52:41 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.

Error - 2/21/2010 11:58:43 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.

Error - 2/21/2010 12:29:39 PM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.

Error - 2/21/2010 12:35:44 PM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.

Error - 2/21/2010 1:21:08 PM | Computer Name = STUART-OF1P8HQI | Source = MsiInstaller | ID = 11316
Description = Product: Microsoft Games for Windows - LIVE Redistributable – Error
1316. A network error occurred while attempting to read from the file: c:\17a73b708cb6ce6b89e692096d80746a\pkg\XLiveUpdate.msi

Error - 2/21/2010 7:43:49 PM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x0038777f.

Error - 2/21/2010 8:45:42 PM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.

[ System Events ]
Error - 6/19/2010 7:33:30 AM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 6/19/2010 8:24:32 AM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 6/19/2010 8:24:32 AM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 6/19/2010 4:44:15 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 6/19/2010 4:44:15 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 6/20/2010 8:08:36 AM | Computer Name = STUART-OF1P8HQI | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the machine that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.

Error - 6/20/2010 4:09:54 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 6/20/2010 4:09:54 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 6/20/2010 6:08:13 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 6/20/2010 6:08:13 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.


< End of report >
OTL logfile created on: 6/20/2010 5:12:49 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Stuart Southerland\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 79.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 713.44 Gb Free Space | 76.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 298.08 Gb Total Space | 264.52 Gb Free Space | 88.74% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STUART-OF1P8HQI
Current User Name: Stuart Southerland
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Stuart Southerland\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Stuart Southerland\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (LPDSVC) – C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (TotRec8) – C:\WINDOWS\system32\drivers\TotRec8.sys (High Criteria inc.)
DRV - (TotRec7) – C:\WINDOWS\system32\drivers\TotRec7.sys (High Criteria inc.)
DRV - (hap17v2k) – C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) – C:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX) – C:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) – C:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX) – C:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) – C:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX) – C:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) – C:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX) – C:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (cpuz132) – C:\WINDOWS\system32\drivers\cpuz132_x32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\atl01_xp.sys (Attansic Technology corporation.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/17 07:11:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/17 18:29:19 | 000,000,000 | —D | M]

[2010/06/17 07:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Extensions
[2010/06/19 21:30:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Firefox\Profiles\kxaxo6e7.default\extensions
[2010/06/18 22:07:12 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Firefox\Profiles\kxaxo6e7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/19 21:30:07 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/01/13 17:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/06/17 20:20:07 | 000,000,686 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [BHR] C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe File not found
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1262617144187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1262617741375 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Zapotec.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Zapotec.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/01/04 09:53:27 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\CDStart.exe – File not found
O33 - MountPoints2\D\Shell\Install\Command - "" = D:\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/01/04 03:41:23 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/19 20:53:38 | 000,000,000 | —D | C] – C:\Program Files\ffdshow
[2010/06/19 20:53:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windows media
[2010/06/19 20:53:07 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Components
[2010/06/19 20:52:50 | 000,000,000 | —D | C] – C:\Program Files\Convert
[2010/06/19 20:52:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\Desktop\H.264 to WMV-AVI Convert
[2010/06/19 03:29:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/06/18 22:03:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\My Documents\Symantec
[2010/06/17 20:19:23 | 000,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2010/06/17 20:17:37 | 000,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2010/06/17 20:05:03 | 000,000,000 | —D | C] – C:\SDFix
[2010/06/17 18:56:23 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/06/17 18:41:19 | 000,000,000 | —D | C] – C:\Program Files\Hitman Pro 3.5
[2010/06/17 18:41:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/06/17 18:16:08 | 000,244,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSFLXGRD.OCX
[2010/06/17 18:16:08 | 000,203,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2010/06/17 18:16:08 | 000,140,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\COMDLG32.OCX
[2010/06/17 18:16:08 | 000,132,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSINET.OCX
[2010/06/17 18:04:49 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/06/17 07:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\Application Data\MSN6
[2010/06/17 07:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MSN6
[2010/06/11 21:27:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/06/06 17:46:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/06 17:45:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/06 17:12:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\Local Settings\Application Data\diwpdegos
[2010/06/01 20:57:20 | 000,000,000 | —D | C] – C:\Program Files\Darkness Within
[2010/05/31 06:44:29 | 000,000,000 | —D | C] – C:\Program Files\DotEmu
[2010/05/31 06:43:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\My Documents\PDF documents
[2010/05/22 08:19:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ATI
[2009/06/23 12:49:14 | 000,010,752 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/20 17:07:48 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/20 17:07:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/20 06:22:42 | 000,002,473 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\HiJackThis.lnk
[2010/06/19 20:54:59 | 000,000,788 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\Windows Media Player.lnk
[2010/06/19 20:54:38 | 004,718,592 | -H– | M] () – C:\Documents and Settings\Stuart Southerland\NTUSER.DAT
[2010/06/19 20:52:51 | 000,000,616 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Convert.lnk
[2010/06/19 20:43:36 | 000,000,161 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Application Data\default.rss
[2010/06/19 20:43:31 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/19 20:30:11 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/19 15:43:06 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:43:06 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:43:06 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:43:06 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:43:06 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:42:59 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Stuart Southerland\ntuser.ini
[2010/06/19 15:42:52 | 004,931,715 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000001-00001102-00000004-20021102}.CDF
[2010/06/19 15:42:52 | 004,931,715 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000001-00001102-00000004-20021102}.BAK
[2010/06/19 03:29:14 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/18 22:02:21 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/17 20:42:05 | 000,000,848 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/17 20:29:51 | 000,000,611 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/17 20:29:51 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/17 20:29:51 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/06/17 20:20:07 | 000,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/06/17 20:19:23 | 000,578,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2010/06/17 18:41:28 | 000,015,944 | —- | M] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/06/17 07:11:54 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/16 15:14:06 | 000,001,740 | -H– | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\Default.rdp
[2010/06/14 21:07:50 | 000,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/06/10 08:39:38 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/06/03 21:59:38 | 000,002,393 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/06/03 18:39:24 | 000,019,968 | —- | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\Record of homeowner's.doc
[2010/06/02 21:12:27 | 000,021,504 | —- | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\BC Clark Jewelers.doc
[2010/06/01 21:02:13 | 000,000,761 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Darkness Within.lnk
[2010/05/31 09:44:18 | 000,000,588 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/05/31 09:44:18 | 000,000,588 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/05/31 06:44:31 | 000,001,599 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\Play Abuse.lnk
[2010/05/22 08:18:44 | 002,646,860 | -H– | M] () – C:\Documents and Settings\Stuart Southerland\Local Settings\Application Data\IconCache.db
[2010/05/22 07:31:56 | 000,001,234 | —- | M] () – C:\Documents and Settings\All Users\Desktop\The Tomb of Sammun-Mak.lnk
[2010/05/21 22:01:20 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Gabriel Knight 3 - Blood of the Sacred, Blood of the Damned.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/19 20:54:59 | 000,000,788 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\Windows Media Player.lnk
[2010/06/19 20:53:39 | 000,005,120 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/06/19 20:53:39 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010/06/19 20:52:51 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\H264VDEC.dll
[2010/06/19 20:52:51 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\Mpeg4SrcFlt.ax
[2010/06/19 20:52:51 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Mpeg4null.ax
[2010/06/19 20:52:51 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\Mp3Decdll.dll
[2010/06/19 20:52:51 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\HIKM4DEC.dll
[2010/06/19 20:52:51 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\Mpeg4DecA.ax
[2010/06/19 20:52:51 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\Mpeg4DecV.ax
[2010/06/19 20:52:51 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\Mpeg4Splitter.ax
[2010/06/19 20:52:51 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\G722ADEC.dll
[2010/06/19 20:52:51 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\BSPVDEC.dll
[2010/06/19 20:52:51 | 000,000,616 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Convert.lnk
[2010/06/19 20:52:22 | 013,992,463 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\H.264 to WMV-AVI Convert.zip
[2010/06/19 03:29:14 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/17 18:41:28 | 000,015,944 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/06/17 18:04:49 | 000,002,473 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\HiJackThis.lnk
[2010/06/17 07:11:54 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/16 12:34:02 | 000,001,740 | -H– | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\Default.rdp
[2010/06/03 18:37:40 | 000,019,968 | —- | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\Record of homeowner's.doc
[2010/06/02 21:12:27 | 000,021,504 | —- | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\BC Clark Jewelers.doc
[2010/06/01 21:02:13 | 000,000,761 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Darkness Within.lnk
[2010/05/31 06:44:31 | 000,001,599 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\Play Abuse.lnk
[2010/05/22 07:31:56 | 000,001,234 | —- | C] () – C:\Documents and Settings\All Users\Desktop\The Tomb of Sammun-Mak.lnk
[2010/05/21 22:01:20 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Gabriel Knight 3 - Blood of the Sacred, Blood of the Damned.lnk
[2010/02/13 20:00:24 | 000,281,504 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2010/02/13 20:00:23 | 000,025,888 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2010/01/29 21:38:16 | 000,001,769 | —- | C] () – C:\WINDOWS\Language_trs.ini
[2010/01/24 22:44:48 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/01/24 20:21:45 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/01/22 08:17:43 | 000,000,419 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2010/01/20 21:05:59 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/01/16 19:11:29 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/09 15:50:11 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2010/01/09 15:50:11 | 000,000,149 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2010/01/08 08:05:00 | 000,036,864 | R— | C] () – C:\WINDOWS\System32\ctrldll.dll
[2010/01/07 21:15:09 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2010/01/05 09:41:16 | 000,004,767 | —- | C] () – C:\WINDOWS\Irremote.ini
[2010/01/05 08:19:48 | 000,000,040 | —- | C] () – C:\WINDOWS\nero.INI
[2010/01/04 19:06:19 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2010/01/04 19:06:19 | 000,012,400 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2010/01/04 19:06:18 | 000,011,832 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2010/01/04 19:06:18 | 000,010,216 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2010/01/04 11:09:37 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/01/04 09:56:35 | 000,013,552 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/01/04 09:56:35 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/01/04 09:56:26 | 000,010,288 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/11/06 11:58:04 | 000,178,975 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/08/03 01:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 01:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 01:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2009/06/23 13:29:50 | 000,049,719 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2009/06/23 13:29:48 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2009/06/23 12:51:00 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CTBurst.dll
[2007/08/13 21:45:02 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\ctmmactl.dll
[2006/10/02 18:25:18 | 000,000,307 | —- | C] () – C:\WINDOWS\System32\kill.ini

========== LOP Check ==========

[2010/01/04 11:11:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/01/04 20:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2010/06/17 18:41:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/01/05 19:37:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2010/01/22 08:17:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/02/14 12:06:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tages
[2010/01/14 22:34:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/03 06:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/04 20:56:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/27 20:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Bioshock2
[2010/06/05 07:27:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\BitTorrent
[2010/06/09 19:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Canon
[2010/01/04 11:28:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\com.gog.downloader.87F90EC6C28C7E479115BE2E026DB87A08BC420D.1
[2010/02/13 22:34:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Games
[2010/02/12 21:10:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\LucasArts
[2010/05/15 18:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\runic games
[2010/01/22 08:17:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\ScanSoft
[2010/02/15 09:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\ScummVM
[2010/01/04 21:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\TotalRecorder

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2008/04/11 08:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[1 C:\*.tmp files -> C:\*.tmp -> ]


< MD5 for: AGP440.SYS >
[2010/01/04 10:13:44 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/01/04 10:24:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2010/01/04 10:13:44 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010/01/04 10:24:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2003/03/31 07:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2010/01/04 10:13:44 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/01/04 10:24:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2010/01/04 10:13:44 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010/01/04 10:24:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0013\DriverFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2010/04/06 20:46:42 | 000,446,464 | —- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – C:\WINDOWS\system32\ATIDEMGX.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2010/01/04 03:43:23 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/01/04 03:43:23 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/01/04 03:43:23 | 000,438,272 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/06 21:42:04 | 004,687,872 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\drivers\ati2mtag.sys
[2010/06/17 18:41:28 | 000,015,944 | —- | M] () – C:\WINDOWS\system32\drivers\hitmanpro35.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/04/16 08:33:36 | 000,041,472 | —- | M] (Apple, Inc.) – C:\WINDOWS\system32\drivers\usbaapl.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73B0434
< End of report >
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-20 17:04:32
Windows 5.1.2600 Service Pack 3
Running: nibp2usj.exe; Driver: C:\DOCUME~1\STUART~1\LOCALS~1\Temp\kwldapob.sys


—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\WINDOWS\System32\DRIVERS\intelppm.sys entry point in ".rsrc" section [0xF764D494]
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6245000, 0x235F87, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0x9ED0E300, 0x3B638, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF77D7300, 0x1BEE, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[1156] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\svchost.exe[1156] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\svchost.exe[1156] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\System32\svchost.exe[1156] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00F9000A
.text C:\WINDOWS\system32\wuauclt.exe[1888] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\wuauclt.exe[1888] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\wuauclt.exe[1888] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\Explorer.EXE[1960] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[1960] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C5000A
.text C:\WINDOWS\Explorer.EXE[1960] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C

—- Devices - GMER 1.0.15 —-

Device -> \Driver\atapi \Device\Harddisk0\DR0 8A411EC5

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IWKPJMSY\1x1pixel[1].gif 0 bytes
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PHD49P98\rt-arrow[1].png 219 bytes
File C:\WINDOWS\System32\DRIVERS\intelppm.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-


Thanks!
Hi stusouth60,

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
Thank you so much for all of your help. So far, so good, but I have to go to work. I'll have to experiment later. Here is the requested log file:

ComboFix 10-06-20.06 - Stuart Southerland 06/21/2010 6:18.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1668 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Install.exe

Infected copy of c:\windows\system32\drivers\intelppm.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-05-21 to 2010-06-21 )))))))))))))))))))))))))))))))
.

2010-06-20 01:53 . 2006-10-05 00:04 5120 —-a-w- c:\windows\system32\ff_vfw.dll
2010-06-20 01:53 . 2010-06-20 01:53 ——– d—–w- c:\program files\ffdshow
2010-06-20 01:53 . 2010-06-20 01:53 ——– d—–w- c:\windows\system32\windows media
2010-06-20 01:53 . 2010-06-20 01:53 ——– d—–w- c:\program files\Windows Media Components
2010-06-20 01:52 . 2007-06-13 14:02 180224 —-a-w- c:\windows\system32\H264VDEC.dll
2010-06-20 01:52 . 2007-06-13 13:55 49152 —-a-w- c:\windows\system32\BSPVDEC.dll
2010-06-20 01:52 . 2007-01-30 13:55 98304 —-a-w- c:\windows\system32\Mp3Decdll.dll
2010-06-20 01:52 . 2007-01-11 15:42 90112 —-a-w- c:\windows\system32\HIKM4DEC.dll
2010-06-20 01:52 . 2007-01-11 14:41 49152 —-a-w- c:\windows\system32\G722ADEC.dll
2010-06-20 01:52 . 2010-06-20 01:52 ——– d—–w- c:\program files\Convert
2010-06-19 12:54 . 2010-06-19 12:54 388096 —-a-r- c:\documents and settings\Stuart Southerland\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-19 08:29 . 2010-06-19 08:29 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-18 01:19 . 2010-06-18 01:19 578560 -c–a-w- c:\windows\system32\dllcache\user32.dll
2010-06-18 01:17 . 2010-06-18 01:17 ——– d—–w- c:\windows\ERUNT
2010-06-18 01:05 . 2010-06-18 01:28 ——– d—–w- C:\SDFix
2010-06-17 23:56 . 2010-06-17 23:56 ——– d—–w- c:\program files\Windows Sidebar
2010-06-17 23:41 . 2010-06-17 23:41 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-06-17 23:41 . 2010-06-17 23:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-06-17 23:41 . 2010-06-17 23:41 ——– d—–w- c:\program files\Hitman Pro 3.5
2010-06-17 23:04 . 2010-06-17 23:04 ——– d—–w- c:\program files\Trend Micro
2010-06-17 12:07 . 2010-06-17 12:07 ——– d—–w- c:\documents and settings\Stuart Southerland\Application Data\MSN6
2010-06-17 12:07 . 2010-06-17 12:07 ——– d—–w- c:\documents and settings\All Users\Application Data\MSN6
2010-06-12 02:27 . 2010-06-12 02:29 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-06-06 22:12 . 2010-06-18 00:30 ——– d—–w- c:\documents and settings\Stuart Southerland\Local Settings\Application Data\diwpdegos
2010-06-02 01:57 . 2010-06-02 02:18 ——– d—–w- c:\program files\Darkness Within
2010-05-31 11:44 . 2010-05-31 11:44 ——– d—–w- c:\program files\DotEmu
2010-05-22 13:19 . 2010-05-22 13:19 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-20 21:09 . 2010-01-04 16:13 ——– d—–w- c:\program files\Steam
2010-06-19 12:24 . 2010-02-13 19:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-06-17 23:55 . 2010-02-13 19:57 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-06-15 02:07 . 2010-01-25 03:44 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll
2010-06-10 00:16 . 2010-01-22 12:57 ——– d—–w- c:\documents and settings\Stuart Southerland\Application Data\Canon
2010-06-06 22:20 . 2010-01-11 05:07 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-06 22:19 . 2010-01-30 14:19 3504176 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-06-05 12:27 . 2010-01-05 13:44 ——– d—–w- c:\documents and settings\Stuart Southerland\Application Data\BitTorrent
2010-06-02 03:56 . 2010-05-13 12:17 ——– d—–w- c:\program files\Darkness Within Demo
2010-05-25 00:06 . 2010-01-04 15:49 ——– d—–w- c:\program files\ATI
2010-05-22 13:12 . 2010-01-04 15:49 ——– d—–w- c:\program files\ATI Technologies
2010-05-22 02:58 . 2010-01-05 00:30 ——– d—–w- c:\program files\GOG.com
2010-05-22 02:16 . 2010-01-04 16:27 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-05-22 02:16 . 2010-01-04 16:27 38784 —-a-w- c:\documents and settings\Stuart Southerland\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-05-15 23:27 . 2010-05-15 23:27 ——– d—–w- c:\documents and settings\Stuart Southerland\Application Data\runic games
2010-05-08 22:25 . 2010-01-05 01:56 ——– d—–w- c:\documents and settings\Stuart Southerland\Application Data\Apple Computer
2010-05-08 22:23 . 2010-05-08 22:23 4 —-a-w- C:\timestmp.tmp
2010-05-08 22:23 . 2010-05-08 22:23 ——– d—–w- c:\program files\Dracula
2010-05-03 11:33 . 2010-05-03 11:33 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-03 11:33 . 2010-01-05 01:56 ——– d—–w- c:\program files\iTunes
2010-05-03 11:33 . 2010-05-03 11:33 ——– d—–w- c:\program files\iPod
2010-05-03 11:33 . 2010-01-05 01:55 ——– d—–w- c:\program files\Common Files\Apple
2010-05-03 11:31 . 2010-05-03 11:31 ——– d—–w- c:\program files\QuickTime
2010-05-03 11:30 . 2010-05-03 11:30 ——– d—–w- c:\program files\Bonjour
2010-05-03 11:28 . 2010-05-03 11:28 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-02 22:27 . 2010-05-02 22:27 ——– d–h–r- c:\documents and settings\Stuart Southerland\Application Data\SecuROM
2010-05-02 13:31 . 2010-05-02 13:31 ——– d—–w- c:\program files\Telltale Games
2010-04-29 20:39 . 2010-01-06 11:19 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39 . 2010-01-06 11:19 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-16 13:33 . 2010-01-05 01:55 41472 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-16 13:33 . 2010-01-05 01:55 3003680 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-04-09 20:48 . 2010-04-09 20:48 3600384 —-a-w- c:\windows\system32\GPhotos.scr
2010-04-08 18:20 . 2010-04-08 18:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-04-08 18:20 . 2010-04-08 18:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-04-07 02:42 . 2010-01-04 15:12 4687872 —-a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-04-07 02:02 . 2010-01-04 15:50 45056 —-a-w- c:\windows\system32\aticalrt.dll
2010-04-07 02:02 . 2010-01-04 15:50 45056 —-a-w- c:\windows\system32\aticalcl.dll
2010-04-07 02:01 . 2010-01-04 15:50 311296 —-a-w- c:\windows\system32\atiiiexx.dll
2010-04-07 02:00 . 2010-01-04 15:50 3981312 —-a-w- c:\windows\system32\aticaldd.dll
2010-04-07 01:52 . 2010-01-04 15:50 14356480 —-a-w- c:\windows\system32\atioglxx.dll
2010-04-07 01:46 . 2010-01-04 15:50 446464 —-a-w- c:\windows\system32\ATIDEMGX.dll
2010-04-07 01:45 . 2010-01-04 15:12 300544 —-a-w- c:\windows\system32\ati2dvag.dll
2010-04-07 01:41 . 2010-01-04 15:12 3620288 —-a-w- c:\windows\system32\ati3duag.dll
2010-04-07 01:31 . 2010-01-04 15:50 208896 —-a-w- c:\windows\system32\atipdlxx.dll
2010-04-07 01:30 . 2010-01-04 15:50 155648 —-a-w- c:\windows\system32\Oemdspif.dll
2010-04-07 01:30 . 2010-01-04 15:50 26112 —-a-w- c:\windows\system32\Ati2mdxx.exe
2010-04-07 01:30 . 2010-01-04 15:50 43520 —-a-w- c:\windows\system32\ati2edxx.dll
2010-04-07 01:30 . 2010-01-04 15:50 159744 —-a-w- c:\windows\system32\ati2evxx.dll
2010-04-07 01:28 . 2010-01-04 15:50 602112 —-a-w- c:\windows\system32\ati2evxx.exe
2010-04-07 01:28 . 2010-01-04 15:12 2220928 —-a-w- c:\windows\system32\ativvaxx.dll
2010-04-07 01:27 . 2010-01-04 15:50 887724 —-a-w- c:\windows\system32\ativva6x.dat
2010-04-07 01:27 . 2010-01-04 15:50 3 —-a-w- c:\windows\system32\ativva5x.dat
2010-04-07 01:27 . 2010-01-04 15:50 53248 —-a-w- c:\windows\system32\ATIDDC.DLL
2010-04-07 01:26 . 2010-02-21 17:33 143360 —-a-w- c:\windows\system32\atiapfxx.exe
2010-04-07 01:23 . 2010-01-04 15:50 585728 —-a-w- c:\windows\system32\atikvmag.dll
2010-04-07 01:21 . 2010-01-04 15:50 393216 —-a-w- c:\windows\system32\atiok3x2.dll
2010-04-07 01:21 . 2010-01-04 15:50 184320 —-a-w- c:\windows\system32\atiadlxx.dll
2010-04-07 01:20 . 2010-01-04 15:50 17408 —-a-w- c:\windows\system32\atitvo32.dll
2010-04-07 01:15 . 2010-01-04 15:12 638976 —-a-w- c:\windows\system32\ati2cqag.dll
2010-04-07 01:15 . 2010-01-04 15:50 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll
2010-04-07 01:14 . 2010-01-04 15:50 65024 —-a-w- c:\windows\system32\atimpc32.dll
2010-04-07 01:14 . 2010-01-04 15:50 65024 —-a-w- c:\windows\system32\amdpcom32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2009-06-23 19456]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-07 102400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=DrvTrNTm.dll
"wave"=DrvTrNTm.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ai Nap]
2008-01-28 18:55 1413120 —-a-w- c:\program files\ASUS\AI Suite\AiNap\AiNap.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2010-02-09 00:44 64032 —-a-w- c:\windows\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Energy Saving]
2008-01-28 16:42 1352704 —-a-w- c:\program files\ASUS\AI Suite\EnergySaving\PwSave.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2006-03-22 01:30 1191936 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpu Level Up help]
2007-12-01 02:03 881152 —-a-w- c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPU Power Monitor]
2008-01-09 16:17 627200 —-a-w- c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
2009-06-23 17:48 19456 —-a-w- c:\windows\system32\CtHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
2009-09-03 21:17 3342336 —-a-w- c:\program files\Electronic Arts\EADM\Core.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2009-06-01 19:51 1468296 —-a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-04-28 20:06 142120 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
2009-06-01 19:43 1501064 —-a-w- c:\program files\Microsoft IntelliType Pro\itype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 16:16 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2006-03-21 19:19 69632 —-a-w- c:\program files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 02:53 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2000-10-16 14:37 32768 ——r- c:\windows\system32\rmctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2010-02-09 00:45 18790432 —-a-w- c:\windows\RTHDCPL.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-09-30 06:14 155648 —-a-r- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2010-04-07 02:25 102400 —-a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-07 02:09 1238352 —-a-w- c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 21:21 246504 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-01-25 01:20 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\painkiller black edition\\Bin\\Painkiller.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\the witcher enhanced edition\\System\\witcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\the witcher enhanced edition\\System\\djinni!.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\stalker shadow of chernobyl\\bin\\XR_3DA.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\RelicCOH.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\help.htm"=
"c:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\RelicDownloader\\RelicDownloader.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\THQ\\Dawn Of War\\W40k.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\the secret of monkey island special edition\\MISE.exe"=
"c:\\Program Files\\Mass Effect 2\\Binaries\\MassEffect2.exe"=
"c:\\Program Files\\Mass Effect 2\\MassEffect2Launcher.exe"=
"c:\\Program Files\\2K Games\\BioShock 2\\SP\\Builds\\Binaries\\Bioshock2.exe"=
"c:\\Program Files\\2K Games\\BioShock 2\\MP\\Builds\\Binaries\\Bioshock2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\mass effect\\Binaries\\MassEffect.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\serious sam hd the first encounter\\Bin\\SamHD_Demo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\serious sam hd the first encounter\\Bin\\SamHD.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\torchlight\\Torchlight.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dawn of war 2\\DOW2.exe"=

R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [1/4/2010 9:57 AM 38656]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/23/2009 2:34 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/23/2009 2:34 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/23/2009 2:34 PM 566296]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [1/4/2010 8:50 PM 130640]
R3 TotRec8;Total Recorder WDM audio filter driver;c:\windows\system32\drivers\TotRec8.sys [1/4/2010 8:50 PM 89680]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2/21/2010 7:53 PM 1691480]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/23/2009 2:34 PM 99352]
S3 cpuz130;cpuz130;\??\c:\docume~1\STUART~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys –> c:\docume~1\STUART~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2/21/2010 8:11 PM 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/23/2009 2:34 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/23/2009 2:35 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/23/2009 2:35 PM 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/23/2009 2:34 PM 566296]
S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 16:14 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride =
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
Trusted Zone: intuit.com\ttlc
FF - ProfilePath - c:\documents and settings\Stuart Southerland\Application Data\Mozilla\Firefox\Profiles\kxaxo6e7.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-BHR - c:\program files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe
MSConfigStartUp-NewsUpd - c:\program files\Creative\News\NewsUpd.EXE
MSConfigStartUp-ukpqsmql - c:\documents and settings\Stuart Southerland\Local Settings\Application Data\diwpdegos\iekumxrtssd.exe
MSConfigStartUp-yahoo! - c:\docume~1\STUART~1\LOCALS~1\Temp\44816484525don.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-21 06:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1614895754-1659004503-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:a7,84,c3,7d,9a,27,84,c3,1b,67,ef,9f,b6,db,22,7e,9f,41,8d,77,74,
b0,00,12,80,79,63,52,01,b5,3f,6e,f7,93,d6,8b,35,e3,e3,74,9f,eb,9a,84,62,87,\
"rkeysecu"=hex:b2,f3,48,6e,39,0f,17,d4,d0,31,43,dc,58,fe,ec,f3
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
Completion time: 2010-06-21 06:25:21
ComboFix-quarantined-files.txt 2010-06-21 11:25

Pre-Run: 769,576,914,944 bytes free
Post-Run: 769,725,853,696 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 89DDB1D72536929C8654CF6AA8515D2D

Thanks again, and I'll get back to you…

-Stuart
Hi stusouth60,

BitTorrent
You have BitTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall BitTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.



Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now



Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
c:\documents and settings\Stuart Southerland\Local Settings\Application Data\diwpdegos

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • OTL fix log
  • MBAM log
How's the computer now?

Thanks
Here you go. I'm off to work; I will run Malwarebyte's while I'm gone. I haven't used bittorrent in a while. That's good advice, I will dump it. All processes killed Error: Unable to interpret in the current context! ========== FILES ========== c:\documents and settings\Stuart Southerland\Local Settings\Application Data\diwpdegos folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41620 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32835 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 23314 bytes ->Flash cache emptied: 44335 bytes User: Stuart Southerland ->Temp folder emptied: 10246579 bytes ->Temporary Internet Files folder emptied: 89407840 bytes ->Java cache emptied: 2722759 bytes ->FireFox cache emptied: 59879571 bytes ->Flash cache emptied: 132339 bytes %systemdrive% .tmp files removed: 4 bytes %systemroot% .tmp files removed: 1327303 bytes %systemroot%\System32 .tmp files removed: 2775569 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 51006 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 159.00 mb OTL by OldTimer - Version 3.2.6.0 log created on 06212010_073845 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Stuart Southerland\Local Settings\Temp\Perflib_Perfdata_310.dat not found! Registry entries deleted on Reboot… Is that good? Thanks again…. Stuart
sMalwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4220 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 6/21/2010 8:25:17 AM mbam-log-2010-06-21 (08-25-17).txt Scan type: Full scan (C:\|) Objects scanned: 209248 Time elapsed: 39 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) So… am I clean? -Stuart
Hi stusouth60,

Is that good?

So far so good.

So… am I clean?

We'll see after this next scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Next
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window. There will only be a OTL.tx this time.

Please post back with
  • Kaspersky log
  • OTL.txt
Thanks
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, June 22, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, June 22, 2010 01:58:38
Records in database: 4308889
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Objects scanned: 145151
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 02:15:34


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\intelppm.sys.vir Infected: Rootkit.Win32.TDSS.ap 1

Selected area has been scanned.

and….

OTL logfile created on: 6/22/2010 6:11:24 AM - Run 2
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Stuart Southerland\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 85.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 716.21 Gb Free Space | 76.89% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 298.08 Gb Total Space | 98.13 Gb Free Space | 32.92% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STUART-OF1P8HQI
Current User Name: Stuart Southerland
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Stuart Southerland\Local Settings\temp\jkos-Stuart Southerland\binaries\ScanningProcess.exe (Kaspersky Lab.)
PRC - C:\Documents and Settings\Stuart Southerland\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Stuart Southerland\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (LPDSVC) – C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (TotRec8) – C:\WINDOWS\system32\drivers\TotRec8.sys (High Criteria inc.)
DRV - (TotRec7) – C:\WINDOWS\system32\drivers\TotRec7.sys (High Criteria inc.)
DRV - (hap17v2k) – C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) – C:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX) – C:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) – C:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX) – C:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) – C:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX) – C:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) – C:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX) – C:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (cpuz132) – C:\WINDOWS\system32\drivers\cpuz132_x32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\atl01_xp.sys (Attansic Technology corporation.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/17 07:11:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/21 07:36:52 | 000,000,000 | —D | M]

[2010/06/17 07:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Extensions
[2010/06/21 22:29:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Firefox\Profiles\kxaxo6e7.default\extensions
[2010/06/18 22:07:12 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Firefox\Profiles\kxaxo6e7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/21 22:29:49 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/21 07:36:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/21 07:36:44 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/13 17:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/06/21 06:23:44 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1262617144187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1262617741375 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Zapotec.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Zapotec.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/01/04 09:53:27 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/21 07:38:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/06/21 07:38:45 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/21 07:37:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/06/21 07:36:52 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/06/21 07:36:52 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/06/21 07:36:52 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/06/21 07:36:52 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/06/21 07:36:52 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/06/21 06:42:07 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/06/21 06:40:22 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/06/21 06:15:00 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/06/21 06:12:31 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/06/21 06:12:31 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/06/21 06:12:31 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/06/21 06:12:31 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/06/21 06:12:19 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/06/21 06:11:57 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/19 20:53:38 | 000,000,000 | —D | C] – C:\Program Files\ffdshow
[2010/06/19 20:53:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windows media
[2010/06/19 20:53:07 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Components
[2010/06/19 20:52:50 | 000,000,000 | —D | C] – C:\Program Files\Convert
[2010/06/19 03:29:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/06/18 22:03:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\My Documents\Symantec
[2010/06/17 20:19:23 | 000,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2010/06/17 20:17:37 | 000,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2010/06/17 20:05:03 | 000,000,000 | —D | C] – C:\SDFix
[2010/06/17 18:56:23 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/06/17 18:41:19 | 000,000,000 | —D | C] – C:\Program Files\Hitman Pro 3.5
[2010/06/17 18:41:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/06/17 18:16:08 | 000,244,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSFLXGRD.OCX
[2010/06/17 18:16:08 | 000,203,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2010/06/17 18:16:08 | 000,140,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\COMDLG32.OCX
[2010/06/17 18:16:08 | 000,132,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSINET.OCX
[2010/06/17 18:04:49 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/06/17 07:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\Application Data\MSN6
[2010/06/17 07:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MSN6
[2010/06/11 21:27:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/06/06 17:46:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/06 17:45:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/01 20:57:20 | 000,000,000 | —D | C] – C:\Program Files\Darkness Within
[2010/05/31 06:44:29 | 000,000,000 | —D | C] – C:\Program Files\DotEmu
[2010/05/31 06:43:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\My Documents\PDF documents
[2009/06/23 12:49:14 | 000,010,752 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2010/06/22 06:11:19 | 004,718,592 | -H– | M] () – C:\Documents and Settings\Stuart Southerland\NTUSER.DAT
[2010/06/21 18:47:48 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/21 18:33:07 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/21 18:33:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/21 18:33:02 | 000,123,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/21 18:32:15 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/21 18:32:15 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/21 18:32:15 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/21 18:32:15 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/21 18:32:15 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/21 18:32:10 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Stuart Southerland\ntuser.ini
[2010/06/21 18:32:03 | 004,931,715 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000001-00001102-00000004-20021102}.CDF
[2010/06/21 18:32:03 | 004,931,715 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000001-00001102-00000004-20021102}.BAK
[2010/06/21 18:30:25 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/21 18:28:43 | 000,488,794 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/21 18:28:43 | 000,432,686 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/06/21 18:28:43 | 000,067,516 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/06/21 18:04:08 | 000,020,792 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/21 07:36:44 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/06/21 07:36:44 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/06/21 07:36:44 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/06/21 07:36:44 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/06/21 07:36:43 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/06/21 06:23:48 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/21 06:23:44 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/21 06:15:08 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/06/21 06:08:59 | 003,717,597 | R— | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\jgh.exe
[2010/06/20 06:22:42 | 000,002,473 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\HiJackThis.lnk
[2010/06/19 20:54:59 | 000,000,788 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\Windows Media Player.lnk
[2010/06/19 20:52:51 | 000,000,616 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Convert.lnk
[2010/06/19 20:43:36 | 000,000,161 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Application Data\default.rss
[2010/06/19 20:43:31 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/19 03:29:14 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/18 22:02:21 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/17 20:42:05 | 000,000,848 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/17 20:29:51 | 000,000,611 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/17 20:29:51 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/17 20:19:23 | 000,578,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2010/06/17 18:41:28 | 000,015,944 | —- | M] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/06/17 07:11:54 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/16 15:14:06 | 000,001,740 | -H– | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\Default.rdp
[2010/06/14 21:07:50 | 000,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/06/10 08:39:38 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/06/03 21:59:38 | 000,002,393 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/06/03 18:39:24 | 000,019,968 | —- | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\Record of homeowner's.doc
[2010/06/02 21:12:27 | 000,021,504 | —- | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\BC Clark Jewelers.doc
[2010/06/01 21:02:13 | 000,000,761 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Darkness Within.lnk
[2010/05/31 09:44:18 | 000,000,588 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/05/31 09:44:18 | 000,000,588 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/05/31 06:44:31 | 000,001,599 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\Play Abuse.lnk

========== Files Created - No Company Name ==========

[2010/06/21 06:42:34 | 000,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/21 06:15:07 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/06/21 06:15:02 | 000,260,272 | —- | C] () – C:\cmldr
[2010/06/21 06:12:31 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/06/21 06:12:31 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/06/21 06:12:31 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/06/21 06:12:31 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/06/21 06:12:31 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/06/21 06:09:26 | 003,717,597 | R— | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\jgh.exe
[2010/06/19 20:54:59 | 000,000,788 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\Windows Media Player.lnk
[2010/06/19 20:53:39 | 000,005,120 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/06/19 20:53:39 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010/06/19 20:52:51 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\H264VDEC.dll
[2010/06/19 20:52:51 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\Mpeg4SrcFlt.ax
[2010/06/19 20:52:51 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Mpeg4null.ax
[2010/06/19 20:52:51 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\Mp3Decdll.dll
[2010/06/19 20:52:51 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\HIKM4DEC.dll
[2010/06/19 20:52:51 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\Mpeg4DecA.ax
[2010/06/19 20:52:51 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\Mpeg4DecV.ax
[2010/06/19 20:52:51 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\Mpeg4Splitter.ax
[2010/06/19 20:52:51 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\G722ADEC.dll
[2010/06/19 20:52:51 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\BSPVDEC.dll
[2010/06/19 20:52:51 | 000,000,616 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Convert.lnk
[2010/06/19 20:52:22 | 013,992,463 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\H.264 to WMV-AVI Convert.zip
[2010/06/19 03:29:14 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/17 18:41:28 | 000,015,944 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/06/17 18:04:49 | 000,002,473 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\HiJackThis.lnk
[2010/06/17 07:11:54 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/16 12:34:02 | 000,001,740 | -H– | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\Default.rdp
[2010/06/03 18:37:40 | 000,019,968 | —- | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\Record of homeowner's.doc
[2010/06/02 21:12:27 | 000,021,504 | —- | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\BC Clark Jewelers.doc
[2010/06/01 21:02:13 | 000,000,761 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Darkness Within.lnk
[2010/05/31 06:44:31 | 000,001,599 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\Play Abuse.lnk
[2010/02/13 20:00:24 | 000,281,504 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2010/02/13 20:00:23 | 000,025,888 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2010/01/29 21:38:16 | 000,001,769 | —- | C] () – C:\WINDOWS\Language_trs.ini
[2010/01/24 22:44:48 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/01/24 20:21:45 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/01/22 08:17:43 | 000,000,419 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2010/01/20 21:05:59 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/01/16 19:11:29 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/09 15:50:11 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2010/01/09 15:50:11 | 000,000,149 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2010/01/08 08:05:00 | 000,036,864 | R— | C] () – C:\WINDOWS\System32\ctrldll.dll
[2010/01/07 21:15:09 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2010/01/05 09:41:16 | 000,004,767 | —- | C] () – C:\WINDOWS\Irremote.ini
[2010/01/05 08:19:48 | 000,000,040 | —- | C] () – C:\WINDOWS\nero.INI
[2010/01/04 19:06:19 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2010/01/04 19:06:19 | 000,012,400 | —- | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2010/01/04 19:06:18 | 000,011,832 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2010/01/04 19:06:18 | 000,010,216 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2010/01/04 11:09:37 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/01/04 09:56:35 | 000,013,552 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/01/04 09:56:35 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/01/04 09:56:26 | 000,010,288 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/11/06 11:58:04 | 000,178,975 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/08/03 01:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 01:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 01:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2009/06/23 13:29:50 | 000,049,719 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2009/06/23 13:29:48 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2009/06/23 12:51:00 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CTBurst.dll
[2007/08/13 21:45:02 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\ctmmactl.dll
[2006/10/02 18:25:18 | 000,000,307 | —- | C] () – C:\WINDOWS\System32\kill.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73B0434
< End of report >

Thanks again! For what it's worth, the computer is running fine, as far as I can tell.


-Stuart
Hi stusouth60,

Looks good.

The Kaspersky detection is a file we have already quarantined. It will be removed when we remove the tools.

If no other problems, we can clean up our tools.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER (nibp2usj.exe)

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK

Combofix /uninstall


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep MBAM updated and use it regularly.


Important, I do not see an active antivirus program. Please download and install one of these free ones.

Avast
Help and support can be found here Avast Forum
AVG
Help and support can be found here AVG Forum
Antivir PersonalEditionClassic
Help and support can be found here Avira Personal Support Forum


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

For resident antispyware I suggest either

Windows Defender
OR
Winpatrol

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware,IMO)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879


We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI