This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Redirected with Google search

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello there

As the topic states i keep getting redirected to various website when i do i google search if i have a website in my favourites i can seem to navigate there with no problems i have enclosed my mbam log and hijack this log

look forward to hearing from you
regards in advance stuart

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:17:09, on 13/07/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\ini.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\STUART~1\LOCALS~1\Temp\Xsh.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wexe.exe
C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mytalktalk.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ini.exe,
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EWABQAF7KL] C:\DOCUME~1\STUART~1\LOCALS~1\Temp\Xsh.exe
O4 - HKCU\..\Run: [{D4B1BE1A-EAFC-796C-C572-9CF389D97DF7}] "C:\Documents and Settings\Stuart Wright\Application Data\Etpi\poyw.exe"
O4 - HKCU\..\Run: [{0D581A06-3ED2-5DD6-E845-29CCD152C95A}] "C:\Documents and Settings\Stuart Wright\Application Data\Ceimme\icfu.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-24-0.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1186342685781
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O17 - HKLM\System\CS5\Services\Tcpip\Parameters: NameServer = 93.188.162.228,93.188.166.208
O20 - AppInit_DLLs: C:\WINDOWS\system32\0052.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

–
End of file - 7327 bytes




Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

13/07/2010 15:13:58
mbam-log-2010-07-13 (15-13-58).txt

Scan type: Quick scan
Objects scanned: 135002
Time elapsed: 8 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\appinit_dlls (Trojan.Witkinat) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\crntdll (Trojan.Witkinat) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.228,93.188.166.208 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4edfe091-a67b-4dcb-b3ed-a219a3f0959b}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.228,93.188.166.208 -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\wupd.dat (Malware.Trace) -> Quarantined and deleted successfully.
Hello,

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:



Scanning with GMER

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)
3. The log that was produced after running GMER
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hello sweetech ,

Thanks for helping me with this problem heres the results of my scans , i have been on a few website and dont seem to be getting redirected YET!!!!

OTL logfile created on: 16/07/2010 19:01:39 - Run 2
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Stuart Wright\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 527.00 Mb Available Physical Memory | 52.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 102.32 Gb Free Space | 70.90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOMEPC
Current User Name: Stuart Wright
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Stuart Wright\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\wexe.exe ()
PRC - C:\Documents and Settings\Stuart Wright\Local Settings\temp\Xsh.exe ()
PRC - C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe ()
PRC - C:\WINDOWS\system32\ini.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\pctspk.exe (PCtel, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Stuart Wright\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\0052.DLL ()
MOD - C:\WINDOWS\system32\wsock32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (aswUpdSv) – File not found
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (dlcc_device) – C:\WINDOWS\System32\dlcccoms.exe ()
SRV - (Pctspk) – C:\WINDOWS\system32\pctspk.exe (PCtel, Inc.)


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (vsdatant) – C:\WINDOWS\System32\vsdatant.sys File not found
DRV - (USBAAPL) – C:\WINDOWS\System32\Drivers\usbaapl.sys File not found
DRV - (szkg) – C:\WINDOWS\System32\DRIVERS\szkg.sys File not found
DRV - (catchme) – C:\DOCUME~1\STUART~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (AR5523) – C:\WINDOWS\System32\DRIVERS\WG11TND5.sys File not found
DRV - (adiusbaw) – C:\WINDOWS\System32\DRIVERS\adiusbaw.sys File not found
DRV - (ADILOADER) General Purpose USB Driver (adildr.sys) – C:\WINDOWS\System32\Drivers\adildr.sys File not found
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (IrBus) – C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Changer) – C:\WINDOWS\System32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) – C:\WINDOWS\System32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (s3017unic) Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM) – C:\WINDOWS\system32\drivers\s3017unic.sys (MCCI Corporation)
DRV - (s3017obex) – C:\WINDOWS\system32\drivers\s3017obex.sys (MCCI Corporation)
DRV - (s3017mgmt) Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s3017mgmt.sys (MCCI Corporation)
DRV - (s3017nd5) Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS) – C:\WINDOWS\system32\drivers\s3017nd5.sys (MCCI Corporation)
DRV - (s3017mdm) – C:\WINDOWS\system32\drivers\s3017mdm.sys (MCCI Corporation)
DRV - (s3017mdfl) – C:\WINDOWS\system32\drivers\s3017mdfl.sys (MCCI Corporation)
DRV - (s3017bus) Sony Ericsson Device 3017 driver (WDM) – C:\WINDOWS\system32\drivers\s3017bus.sys (MCCI Corporation)
DRV - (EC168BDA) – C:\WINDOWS\system32\drivers\ec168bda.sys (e3C, Inc.)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (sea1unic) Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM) – C:\WINDOWS\system32\drivers\sea1unic.sys (MCCI)
DRV - (sea1obex) – C:\WINDOWS\system32\drivers\sea1obex.sys (MCCI)
DRV - (sea1nd5) Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS) – C:\WINDOWS\system32\drivers\sea1nd5.sys (MCCI)
DRV - (sea1mgmt) Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\sea1mgmt.sys (MCCI)
DRV - (sea1mdm) – C:\WINDOWS\system32\drivers\sea1mdm.sys (MCCI)
DRV - (sea1mdfl) – C:\WINDOWS\system32\drivers\sea1mdfl.sys (MCCI)
DRV - (sea1bus) Sony Ericsson Device 0A1 driver (WDM) – C:\WINDOWS\system32\drivers\sea1bus.sys (MCCI)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (se44unic) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM) – C:\WINDOWS\system32\drivers\se44unic.sys (MCCI)
DRV - (se44obex) – C:\WINDOWS\system32\drivers\se44obex.sys (MCCI)
DRV - (se44nd5) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS) – C:\WINDOWS\system32\drivers\se44nd5.sys (MCCI)
DRV - (se44mgmt) Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\se44mgmt.sys (MCCI)
DRV - (se44mdm) – C:\WINDOWS\system32\drivers\se44mdm.sys (MCCI)
DRV - (se44mdfl) – C:\WINDOWS\system32\drivers\se44mdfl.sys (MCCI)
DRV - (se44bus) Sony Ericsson Device 068 driver (WDM) – C:\WINDOWS\system32\drivers\se44bus.sys (MCCI)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys (McAfee, Inc.)
DRV - (vaxscsi) – C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (SE27obex) – C:\WINDOWS\system32\drivers\se27obex.sys (MCCI)
DRV - (SE27mgmt) Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\se27mgmt.sys (MCCI)
DRV - (SE27mdm) – C:\WINDOWS\system32\drivers\se27mdm.sys (MCCI)
DRV - (SE27mdfl) – C:\WINDOWS\system32\drivers\se27mdfl.sys (MCCI)
DRV - (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) – C:\WINDOWS\system32\drivers\se27bus.sys (MCCI)
DRV - (se27nd5) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS) – C:\WINDOWS\system32\drivers\se27nd5.sys (MCCI)
DRV - (se27unic) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM) – C:\WINDOWS\system32\drivers\se27unic.sys (MCCI)
DRV - (hcwPP2) – C:\WINDOWS\system32\drivers\hcwPP2.sys (Hauppauge Computer Works, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\CTUSFSYN.SYS (Creative Technology Ltd.)
DRV - (sigfilt) – C:\WINDOWS\system32\drivers\sigfilt.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\CTOSS2K.SYS (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\intelc53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\intelc52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\intelc51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\modemcsa.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (Vpctcom) – C:\WINDOWS\system32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Vvoice) – C:\WINDOWS\system32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\system32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (Ptserli) – C:\WINDOWS\system32\drivers\ptserli.sys (PCTEL, INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"



[2009/05/18 15:59:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Mozilla\Firefox\Profiles\7lnmtz7j.default\extensions
[2007/08/07 20:06:39 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Stuart Wright\Application Data\Mozilla\Firefox\Profiles\7lnmtz7j.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

O1 HOSTS File: ([2010/06/15 13:20:19 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\ScriptCl.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKCU..\Run: [{0D581A06-3ED2-5DD6-E845-29CCD152C95A}] C:\Documents and Settings\Stuart Wright\Application Data\Ceimme\icfu.exe ()
O4 - HKCU..\Run: [{D4B1BE1A-EAFC-796C-C572-9CF389D97DF7}] C:\Documents and Settings\Stuart Wright\Application Data\Etpi\poyw.exe ()
O4 - HKCU..\Run: [EWABQAF7KL] C:\Documents and Settings\Stuart Wright\Local Settings\temp\Xsh.exe ()
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1186342685781 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.228,93.188.166.208
O20 - AppInit_DLLs: (C:\WINDOWS\system32\0052.DLL) - C:\WINDOWS\system32\0052.DLL ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\ini.exe) - C:\WINDOWS\system32\ini.exe ()
O24 - Desktop WallPaper: C:\Documents and Settings\Stuart Wright\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Stuart Wright\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - Unable to open key or key not present!
O32 - AutoRun File - [2005/08/16 05:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi5 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer5 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecx.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave6 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave7 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (5600190677385216)

========== Files/Folders - Created Within 30 Days ==========

[2010/07/16 19:00:52 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Stuart Wright\Desktop\OTL.exe
[2010/07/16 18:00:34 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/07/16 18:00:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/16 18:00:28 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/07/13 14:53:15 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware(2)
[57 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[20 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/16 19:01:20 | 071,878,688 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2010/07/16 19:00:55 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Stuart Wright\Desktop\OTL.exe
[2010/07/16 18:55:06 | 000,000,304 | -H– | M] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/07/16 18:05:16 | 000,050,688 | —- | M] () – C:\WINDOWS\System32\ernel32.dll
[2010/07/16 18:02:56 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\wupd.dat
[2010/07/16 18:02:25 | 000,000,322 | -HS- | M] () – C:\WINDOWS\tasks\OYEJUBTQQ.job
[2010/07/16 18:02:25 | 000,000,296 | -H– | M] () – C:\WINDOWS\tasks\e4564d1c.job
[2010/07/16 18:02:25 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/16 18:02:24 | 000,044,032 | -H– | M] () – C:\WINDOWS\System32\wexe.exe
[2010/07/16 18:02:24 | 000,037,888 | —- | M] () – C:\WINDOWS\System32\0052.DLL
[2010/07/16 18:02:14 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/16 18:02:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/16 18:02:07 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2010/07/16 18:01:24 | 000,846,224 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2010/07/13 14:40:58 | 018,128,896 | —- | M] () – C:\Documents and Settings\Stuart Wright\ntuser.dat
[2010/07/13 14:36:15 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Stuart Wright\ntuser.ini
[2010/07/13 14:35:40 | 000,556,080 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/13 14:35:40 | 000,483,978 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/13 14:35:40 | 000,082,672 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/13 14:29:05 | 000,037,376 | —- | M] () – C:\WINDOWS\System32\0050.DLL
[2010/07/12 14:59:49 | 000,000,004 | —- | M] () – C:\Documents and Settings\Stuart Wright\proxy_port
[2010/07/06 09:05:31 | 000,037,376 | —- | M] () – C:\WINDOWS\System32\0051.DLL
[2010/07/05 21:24:54 | 000,179,200 | —- | M] () – C:\WINDOWS\Xmerea.exe
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe
[2010/07/05 21:24:11 | 000,084,480 | RHS- | M] () – C:\WINDOWS\System32\ati2cqagj.dll
[2010/07/05 21:23:26 | 000,044,544 | —- | M] () – C:\WINDOWS\System32\ini.exe
[57 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[20 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/13 15:15:45 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\wupd.dat
[2010/07/13 14:40:57 | 018,128,896 | —- | C] () – C:\Documents and Settings\Stuart Wright\ntuser.dat
[2010/07/13 14:11:46 | 000,044,032 | -H– | C] () – C:\WINDOWS\System32\wexe.exe
[2010/07/12 14:59:49 | 000,000,004 | —- | C] () – C:\Documents and Settings\Stuart Wright\proxy_port
[2010/07/12 14:59:13 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\0052.DLL
[2010/07/06 09:19:33 | 1071,796,224 | -HS- | C] () – C:\hiberfil.sys
[2010/07/05 21:25:05 | 000,179,200 | —- | C] () – C:\WINDOWS\Xmerea.exe
[2010/07/05 21:25:05 | 000,000,304 | -H– | C] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/07/05 21:24:50 | 000,050,688 | —- | C] () – C:\WINDOWS\System32\ernel32.dll
[2010/07/05 21:24:48 | 000,000,296 | -H– | C] () – C:\WINDOWS\tasks\e4564d1c.job
[2010/07/05 21:24:47 | 000,050,688 | —- | C] () – C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe
[2010/07/05 21:24:12 | 000,000,322 | -HS- | C] () – C:\WINDOWS\tasks\OYEJUBTQQ.job
[2010/07/05 21:24:11 | 000,084,480 | RHS- | C] () – C:\WINDOWS\System32\ati2cqagj.dll
[2010/07/05 21:23:34 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0051.DLL
[2010/07/05 21:23:26 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\ini.exe
[2010/07/05 21:23:26 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0050.DLL
[2010/02/28 20:06:15 | 000,000,107 | —- | C] () – C:\WINDOWS\IfoEdit.INI
[2009/10/01 20:57:42 | 000,000,122 | —- | C] () – C:\WINDOWS\kaillera.ini
[2009/09/08 20:46:11 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/09/08 20:46:09 | 000,881,664 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/09/08 20:46:09 | 000,205,824 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/09/08 20:46:08 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/09/08 20:46:07 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/09/08 20:46:06 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/12/09 18:32:26 | 000,000,014 | —- | C] () – C:\WINDOWS\System32\systeminfo.dll
[2008/12/09 18:30:41 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2008/10/21 13:13:29 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/02/18 17:57:29 | 000,966,765 | —- | C] () – C:\WINDOWS\System32\acAuth.dll
[2008/02/18 17:57:29 | 000,356,352 | —- | C] () – C:\WINDOWS\System32\SCMLib.dll
[2008/02/09 18:45:07 | 000,000,034 | —- | C] () – C:\WINDOWS\C_it.ini
[2008/01/26 17:13:53 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/01/05 22:29:59 | 000,000,518 | —- | C] () – C:\WINDOWS\SCRABOUT.INI
[2007/10/19 13:09:00 | 000,000,280 | —- | C] () – C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2007/09/11 08:29:33 | 000,001,658 | —- | C] () – C:\WINDOWS\disney.ini
[2007/07/30 19:59:20 | 000,010,752 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2007/06/24 15:28:58 | 000,000,011 | —- | C] () – C:\WINDOWS\vf86.sys
[2007/06/24 15:28:50 | 000,000,928 | —- | C] () – C:\WINDOWS\MP3Weasel.INI
[2007/05/17 13:58:10 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2007/04/24 20:31:12 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\ucinst32.dll
[2007/04/22 20:19:43 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcccfg.dll
[2007/01/10 20:26:10 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/10/19 21:05:36 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/10/19 21:05:30 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/09/19 15:23:37 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/08/21 20:57:42 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\cygz.dll
[2006/07/08 13:49:49 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2006/05/01 22:17:30 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/05/01 21:52:45 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\pCastCtl.dll
[2006/04/22 21:50:32 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\133339E4A9.sys
[2006/04/22 21:50:24 | 000,005,278 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/03/23 20:12:41 | 000,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/03/20 22:19:01 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/20 21:53:48 | 000,000,930 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/03/20 21:05:52 | 000,000,046 | —- | C] () – C:\WINDOWS\adiras.ini
[2006/03/20 20:37:49 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/03/16 01:45:19 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/16 01:42:26 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/03/16 01:33:57 | 000,005,811 | —- | C] () – C:\WINDOWS\System32\CTSBMB.INI
[2006/03/16 01:08:52 | 000,004,969 | —- | C] () – C:\WINDOWS\System32\Sigfilt.ini
[2006/03/16 01:08:52 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/03/16 01:08:34 | 001,345,520 | —- | C] () – C:\WINDOWS\System32\CTMBHA.DLL
[2006/03/16 01:08:10 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\hcwXDS.dll
[2006/03/16 01:07:42 | 000,000,475 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/16 05:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/02 15:00:16 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlccplc.ini
[2005/07/22 20:48:28 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlccinsr.dll
[2005/07/22 20:48:24 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcccur.dll
[2005/07/22 20:48:06 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlccjswr.dll
[2005/07/22 20:47:20 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlccinsb.dll
[2005/07/22 20:47:14 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcccub.dll
[2005/07/22 20:47:08 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcccu.dll
[2005/07/22 20:47:06 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccins.dll
[2005/07/22 20:45:22 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlccutil.dll
[2005/06/21 21:27:56 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlccpmui.dll
[2005/06/21 21:27:02 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlccserv.dll
[2005/06/21 21:22:06 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcclmpm.dll
[2005/06/21 21:21:40 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcccomm.dll
[2005/06/21 21:19:48 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlccpplc.dll
[2005/06/21 21:18:58 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcccomc.dll
[2005/06/21 21:18:24 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccprox.dll
[2005/06/21 21:12:48 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlccusb1.dll
[2005/06/21 21:09:22 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcchbn3.dll
[2005/04/27 13:40:30 | 000,002,574 | —- | C] () – C:\WINDOWS\WINDVDBOOTRECDOE.sys
[2005/03/30 16:19:58 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlccvs.dll

========== LOP Check ==========

[2006/03/20 21:20:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\.MicroAntivirus
[2006/12/15 12:12:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\BitTorrent
[2010/06/10 22:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Ceimme
[2007/05/17 19:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Datalayer
[2008/12/26 16:44:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Disney Mix It Plug-in
[2009/10/08 14:10:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\EA
[2010/03/29 10:47:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Etpi
[2007/05/28 18:39:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\GetRightToGo
[2008/03/29 16:08:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\GrabIt
[2007/03/10 12:09:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Kontiki
[2006/03/20 20:57:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Leadertech
[2008/03/27 21:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\NewzToolz-EZ
[2007/05/17 19:41:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Nokia
[2007/06/18 18:08:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Nokia Multimedia Player
[2006/08/10 21:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Opera
[2006/03/25 21:38:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Otto
[2007/05/17 18:26:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\PC Suite
[2007/06/30 11:30:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\SecondLife
[2009/05/14 19:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Solveig Multimedia
[2009/02/05 09:39:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Sony
[2007/11/14 21:04:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\SpinTop
[2009/11/12 11:32:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Sports Interactive
[2006/07/28 19:34:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\STOPzilla!
[2007/05/20 13:58:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Teleca
[2010/07/16 19:00:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Uftori
[2007/12/03 17:50:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Uniblue
[2010/06/19 17:51:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\uTorrent
[2008/11/05 23:05:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\VitySoft
[2009/10/20 11:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Vso
[2010/07/13 15:23:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Ypryu
[2010/07/16 18:02:25 | 000,000,296 | -H– | M] () – C:\WINDOWS\Tasks\e4564d1c.job
[2010/07/16 18:02:25 | 000,000,322 | -HS- | M] () – C:\WINDOWS\Tasks\OYEJUBTQQ.job
[2010/07/16 18:55:06 | 000,000,304 | -H– | M] () – C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/02/16 16:05:25 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/16 18:02:07 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2006/07/31 20:35:23 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/31 20:35:23 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/20 18:56:59 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/07/16 18:02:00 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2009/05/04 20:04:58 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/05/24 22:51:53 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/05/26 21:18:34 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/03/24 18:51:18 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/04/28 07:44:20 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/04/29 21:17:22 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/05/01 17:08:07 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/05/02 20:18:09 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/05/07 22:31:41 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/03/24 22:59:33 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/03/29 20:41:57 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/04/03 20:07:07 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/04/03 22:32:53 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/04/04 21:11:38 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/04/10 22:15:08 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/04/13 21:05:46 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/04/19 19:34:23 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/04/20 20:29:48 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/04/21 13:49:46 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/04/27 20:56:09 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/05/04 20:04:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/05/24 22:51:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/05/26 21:18:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/03/24 18:51:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/04/28 07:44:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/04/29 21:17:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/05/01 17:08:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/05/02 20:18:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/05/07 22:31:41 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/03/24 22:59:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/03/29 20:41:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/04/03 20:07:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/04/03 22:32:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/04/04 21:11:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/04/10 22:15:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/04/13 21:05:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/04/19 19:34:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/04/20 20:29:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/04/21 13:49:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/04/27 20:56:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 05:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\17w317.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\3179y17o.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\3oC9sKUO.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\3y79oCE9.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\555sK.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\55k55.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\cEIQGMY7c.dll
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(2).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(3).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(4).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(5).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(6).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\gM1gM3g7i.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\k31gMY1c9.dll
[2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\q5wS5.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2010/07/05 21:24:11 | 000,084,480 | RHS- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\ati2cqagj.dll
[2009/03/08 04:31:44 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[57 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >
[2010/07/16 18:02:25 | 000,000,322 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\Tasks\OYEJUBTQQ.job

< %systemroot%\System32\config\*.sav >
[2005/08/16 05:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 05:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 05:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 01:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll
[57 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 01:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll
[57 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 01:12:10 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\system32\ws2help.dll
[57 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-13 13:35:53

========== Alternate Data Streams ==========

@Alternate Data Stream - 38 bytes -> C:\Documents and Settings\All Users\Desktop:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EP
PJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV
< End of report >


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-07-16 19:20:30
Windows 5.1.2600 Service Pack 3
Running: ndmjnzpq.exe; Driver: C:\DOCUME~1\STUART~1\LOCALS~1\Temp\uwtdipow.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xBA1944FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xBA19450F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xBA19453B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xBA1944E7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xBA194525]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xBA194551]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xBA194567]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

—- EOF - GMER 1.0.15 —-
Hello,

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    PRC - C:\WINDOWS\system32\wexe.exe ()
    PRC - C:\Documents and Settings\Stuart Wright\Local Settings\temp\Xsh.exe ()
    PRC - C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe ()
    PRC - C:\WINDOWS\system32\ini.exe ()
    MOD - C:\WINDOWS\system32\0052.DLL ()
    DRV - (catchme) – C:\DOCUME~1\STUART~1\LOCALS~1\Temp\catchme.sys File not found
    O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
    O4 - HKCU..\Run: [{0D581A06-3ED2-5DD6-E845-29CCD152C95A}] C:\Documents and Settings\Stuart Wright\Application Data\Ceimme\icfu.exe ()
    O4 - HKCU..\Run: [{D4B1BE1A-EAFC-796C-C572-9CF389D97DF7}] C:\Documents and Settings\Stuart Wright\Application Data\Etpi\poyw.exe ()
    O4 - HKCU..\Run: [EWABQAF7KL] C:\Documents and Settings\Stuart Wright\Local Settings\temp\Xsh.exe ()
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.228,93.188.166.208
    O20 - AppInit_DLLs: (C:\WINDOWS\system32\0052.DLL) - C:\WINDOWS\system32\0052.DLL ()
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\ini.exe) - C:\WINDOWS\system32\ini.exe ()
    [2010/07/16 18:55:06 | 000,000,304 | -H– | M] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
    [2010/07/16 18:05:16 | 000,050,688 | —- | M] () – C:\WINDOWS\System32\ernel32.dll
    [2010/07/16 18:02:56 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\wupd.dat
    [2010/07/16 18:02:25 | 000,000,322 | -HS- | M] () – C:\WINDOWS\tasks\OYEJUBTQQ.job
    [2010/07/16 18:02:25 | 000,000,296 | -H– | M] () – C:\WINDOWS\tasks\e4564d1c.job
    [2010/07/16 18:02:24 | 000,044,032 | -H– | M] () – C:\WINDOWS\System32\wexe.exe
    [2010/07/16 18:02:24 | 000,037,888 | —- | M] () – C:\WINDOWS\System32\0052.DLL
    [2010/07/13 14:29:05 | 000,037,376 | —- | M] () – C:\WINDOWS\System32\0050.DLL
    [2010/07/06 09:05:31 | 000,037,376 | —- | M] () – C:\WINDOWS\System32\0051.DLL
    [2010/07/05 21:24:54 | 000,179,200 | —- | M] () – C:\WINDOWS\Xmerea.exe
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe
    [2010/07/05 21:24:11 | 000,084,480 | RHS- | M] () – C:\WINDOWS\System32\ati2cqagj.dll
    [2010/07/05 21:23:26 | 000,044,544 | —- | M] () – C:\WINDOWS\System32\ini.exe
    [2010/07/13 15:15:45 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\wupd.dat
    [2010/07/13 14:11:46 | 000,044,032 | -H– | C] () – C:\WINDOWS\System32\wexe.exe
    [2010/07/12 14:59:13 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\0052.DLL
    [2010/07/05 21:25:05 | 000,179,200 | —- | C] () – C:\WINDOWS\Xmerea.exe
    [2010/07/05 21:25:05 | 000,000,304 | -H– | C] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
    [2010/07/05 21:24:50 | 000,050,688 | —- | C] () – C:\WINDOWS\System32\ernel32.dll
    [2010/07/05 21:24:48 | 000,000,296 | -H– | C] () – C:\WINDOWS\tasks\e4564d1c.job
    [2010/07/05 21:24:47 | 000,050,688 | —- | C] () – C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe
    [2010/07/05 21:24:12 | 000,000,322 | -HS- | C] () – C:\WINDOWS\tasks\OYEJUBTQQ.job
    [2010/07/05 21:24:11 | 000,084,480 | RHS- | C] () – C:\WINDOWS\System32\ati2cqagj.dll
    [2010/07/05 21:23:34 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0051.DLL
    [2010/07/05 21:23:26 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\ini.exe
    [2010/07/05 21:23:26 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\0050.DLL
    [2010/07/16 19:00:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Uftori
    [2010/07/13 15:23:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Ypryu
    [2010/07/16 18:02:25 | 000,000,296 | -H– | M] () – C:\WINDOWS\Tasks\e4564d1c.job
    [2010/07/16 18:02:25 | 000,000,322 | -HS- | M] () – C:\WINDOWS\Tasks\OYEJUBTQQ.job
    [2010/07/16 18:55:06 | 000,000,304 | -H– | M] () – C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\17w317.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\3179y17o.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\3oC9sKUO.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\3y79oCE9.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\555sK.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\55k55.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\cEIQGMY7c.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\gM1gM3g7i.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\k31gMY1c9.dll
    [2010/07/05 21:24:47 | 000,050,688 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\q5wS5.dll
    [2010/07/05 21:24:11 | 000,084,480 | RHS- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\ati2cqagj.dll
    [2010/07/16 18:02:25 | 000,000,322 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\Tasks\OYEJUBTQQ.job
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:


Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
Hi Sweettech heres the info you require
thanks again



All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named wexe.exe was found!
No active process named Xsh.exe was found!
No active process named e4564d1c.exe was found!
No active process named ini.exe was found!
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\DOCUME~1\STUART~1\LOCALS~1\Temp\catchme.sys File not found not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{0D581A06-3ED2-5DD6-E845-29CCD152C95A} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D581A06-3ED2-5DD6-E845-29CCD152C95A}\ not found.
C:\Documents and Settings\Stuart Wright\Application Data\Ceimme\icfu.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{D4B1BE1A-EAFC-796C-C572-9CF389D97DF7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4B1BE1A-EAFC-796C-C572-9CF389D97DF7}\ not found.
C:\Documents and Settings\Stuart Wright\Application Data\Etpi\poyw.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EWABQAF7KL deleted successfully.
C:\Documents and Settings\Stuart Wright\Local Settings\temp\Xsh.exe moved successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\0052.DLL deleted successfully.
C:\WINDOWS\system32\0052.DLL moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\WINDOWS\system32\ini.exe deleted successfully.
C:\WINDOWS\system32\ini.exe moved successfully.
C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job moved successfully.
C:\WINDOWS\system32\ernel32.dll moved successfully.
C:\WINDOWS\system32\wupd.dat moved successfully.
C:\WINDOWS\tasks\OYEJUBTQQ.job moved successfully.
C:\WINDOWS\tasks\e4564d1c.job moved successfully.
C:\WINDOWS\system32\wexe.exe moved successfully.
File C:\WINDOWS\System32\0052.DLL not found.
C:\WINDOWS\system32\0050.DLL moved successfully.
C:\WINDOWS\system32\0051.DLL moved successfully.
C:\WINDOWS\Xmerea.exe moved successfully.
C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe moved successfully.
C:\WINDOWS\system32\ati2cqagj.dll moved successfully.
File C:\WINDOWS\System32\ini.exe not found.
File C:\WINDOWS\System32\wupd.dat not found.
File C:\WINDOWS\System32\wexe.exe not found.
File C:\WINDOWS\System32\0052.DLL not found.
File C:\WINDOWS\Xmerea.exe not found.
File C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job not found.
File C:\WINDOWS\System32\ernel32.dll not found.
File C:\WINDOWS\tasks\e4564d1c.job not found.
File C:\Documents and Settings\Stuart Wright\Application Data\e4564d1c.exe not found.
File C:\WINDOWS\tasks\OYEJUBTQQ.job not found.
File C:\WINDOWS\System32\ati2cqagj.dll not found.
File C:\WINDOWS\System32\0051.DLL not found.
File C:\WINDOWS\System32\ini.exe not found.
File C:\WINDOWS\System32\0050.DLL not found.
C:\Documents and Settings\Stuart Wright\Application Data\Uftori folder moved successfully.
C:\Documents and Settings\Stuart Wright\Application Data\Ypryu folder moved successfully.
File C:\WINDOWS\Tasks\e4564d1c.job not found.
File C:\WINDOWS\Tasks\OYEJUBTQQ.job not found.
File C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job not found.
C:\WINDOWS\system32\spool\prtprocs\w32x86\17w317.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\3179y17o.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\3oC9sKUO.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\3y79oCE9.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\555sK.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\55k55.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\cEIQGMY7c.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\gM1gM3g7i.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\k31gMY1c9.dll moved successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\q5wS5.dll moved successfully.
File C:\WINDOWS\system32\ati2cqagj.dll not found.
File C:\WINDOWS\Tasks\OYEJUBTQQ.job not found.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Stuart Wright\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Stuart Wright\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: audiences

User: codecs

User: common

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: dell

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 171754 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 442502 bytes
->Flash cache emptied: 5960 bytes

User: plugins

User: Stuart Wright
->Temp folder emptied: 86765848 bytes
->Temporary Internet Files folder emptied: 22959624 bytes
->Java cache emptied: 7577662 bytes
->FireFox cache emptied: 4259902 bytes
->Apple Safari cache emptied: 14416169 bytes
->Flash cache emptied: 719754 bytes

User: tools

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 32380336 bytes
%systemroot%\System32\dllcache .tmp files removed: 8176384 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 151018 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 170.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: audiences

User: codecs

User: common

User: Default User

User: dell

User: LocalService

User: NetworkService
->Flash cache emptied: 0 bytes

User: plugins

User: Stuart Wright
->Flash cache emptied: 0 bytes

User: tools

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.9.0 log created on 07172010_191603

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…



ComboFix 10-07-16.01 - Stuart Wright 17/07/2010 19:24:27.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.675 [GMT 1:00]
Running from: D:\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Stuart Wright\Application Data\Ceimme\icfu.exe
c:\documents and settings\Stuart Wright\Application Data\Etpi\poyw.exe
c:\documents and settings\Stuart Wright\proxy_port
c:\windows\system32\spool\prtprocs\w32x86\mYW17yW.dll
c:\windows\system32\wupd.dat

c:\windows\system32\drivers\cdrom.sys was missing
Restored copy from - c:\windows\ServicePackFiles\i386\cdrom.sys

.
((((((((((((((((((((((((( Files Created from 2010-06-17 to 2010-07-17 )))))))))))))))))))))))))))))))
.

2010-07-17 18:31 . 2008-04-13 19:40 62976 —-a-w- c:\windows\system32\drivers\cdrom.sys
2010-07-17 18:31 . 2008-04-13 19:40 62976 —-a-w- c:\windows\system32\dllcache\cdrom.sys
2010-07-17 18:16 . 2010-07-17 18:16 ——– d—–w- C:\_OTL
2010-07-16 17:00 . 2010-07-16 17:00 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-16 17:00 . 2010-07-16 17:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-16 17:00 . 2010-07-16 17:00 ——– d—–w- c:\program files\ESET
2010-07-13 13:53 . 2010-07-16 17:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware(2)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-17 18:32 . 2009-02-04 16:20 71966752 –sha-w- c:\windows\system32\drivers\fidbox.dat
2010-07-17 18:18 . 2009-02-04 16:20 846944 –sha-w- c:\windows\system32\drivers\fidbox.idx
2010-07-17 18:16 . 2010-06-10 21:00 ——– d—–w- c:\documents and settings\Stuart Wright\Application Data\Ceimme
2010-07-17 18:16 . 2010-03-29 09:47 ——– d—–w- c:\documents and settings\Stuart Wright\Application Data\Etpi
2010-07-13 12:53 . 2006-05-06 21:38 ——– d—–w- c:\program files\Paint Shop Pro 5
2010-06-19 16:51 . 2008-02-18 15:08 ——– d—–w- c:\documents and settings\Stuart Wright\Application Data\uTorrent
2010-06-16 17:48 . 2009-11-13 20:37 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-09 19:04 . 2010-06-09 19:04 388096 —-a-r- c:\documents and settings\Stuart Wright\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-09 18:30 . 2010-06-09 18:30 ——– d—–w- c:\program files\Trend Micro
2010-06-09 10:45 . 2008-02-18 15:08 ——– d—–w- c:\program files\uTorrent
2010-05-06 10:41 . 2005-08-16 04:18 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2008-10-14 12:40 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 14:39 . 2009-09-24 08:57 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2009-09-24 08:57 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-26 09:25 . 2010-04-26 08:39 1216 —-a-w- c:\windows\eReg.dat
2010-04-20 05:30 . 2005-08-16 04:18 285696 —-a-w- c:\windows\system32\atmfd.dll
2006-07-30 18:45 . 2006-04-22 20:50 104 –sh–r- c:\windows\system32\133339E4A9.sys
2006-05-03 09:06 . 2009-09-25 11:56 163328 –sh–r- c:\windows\system32\flvDX.dll
2006-07-30 18:45 . 2006-04-22 20:50 5278 –sha-w- c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47 . 2009-09-25 11:56 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-09-25 11:56 216064 –sh–r- c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 1937408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DSLMON.lnk]
backup=c:\windows\pss\DSLMON.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^Stuart Wright^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Stuart Wright\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 22:16 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-08-05 21:05 344064 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 01:12 110592 —-a-w- c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-02 18:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-09-15 09:47 57344 ——w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 10:44 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 14:39 1090952 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfeeUpdaterUI]
2006-12-19 10:27 136768 —-a-w- c:\program files\McAfee\Common Framework\UdaterUI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2005-01-04 14:17 1937408 ——w- c:\program files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
2006-11-03 10:01 319488 ——w- c:\windows\PixArt\PAC7302\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShStatEXE]
2007-02-22 19:50 112216 —-a-w- c:\program files\McAfee\VirusScan Enterprise\shstat.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ehSched"=2 (0x2)
"ehRecvr"=2 (0x2)
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dlcccoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Documents and Settings\\Stuart Wright\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2690:TCP"= 2690:TCP:ppLive
"2776:UDP"= 2776:UDP:ppLive

S3 EC168BDA;EC168BDA service;c:\windows\system32\drivers\ec168bda.sys [09/12/2008 18:30 107264]
S3 Ptserli;PCTEL Serial Device Driver for INTEL;c:\windows\system32\drivers\ptserli.sys [14/02/2007 20:31 128286]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [18/02/2008 17:57 194304]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\drivers\s3017bus.sys [31/10/2008 22:31 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\drivers\s3017mdfl.sys [31/10/2008 22:31 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\drivers\s3017mdm.sys [31/10/2008 22:31 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s3017mgmt.sys [31/10/2008 22:31 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\drivers\s3017nd5.sys [31/10/2008 22:31 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\drivers\s3017obex.sys [31/10/2008 22:31 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\drivers\s3017unic.sys [31/10/2008 22:31 110120]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [10/05/2007 20:29 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [10/05/2007 20:29 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [10/05/2007 20:29 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [10/05/2007 20:29 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [10/05/2007 20:30 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [10/05/2007 20:29 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [10/05/2007 20:29 90800]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [22/09/2006 20:04 223128]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [22/09/2006 20:02 642560]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://www.mytalktalk.net/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-{0D581A06-3ED2-5DD6-E845-29CCD152C95A} - c:\documents and settings\Stuart Wright\Application Data\Ceimme\icfu.exe
HKCU-Run-{D4B1BE1A-EAFC-796C-C572-9CF389D97DF7} - c:\documents and settings\Stuart Wright\Application Data\Etpi\poyw.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-17 19:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1128806670-1401086586-2387256340-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5927D483-7E8F-E771-8746-11116D998CE7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jajkdoochdnfgpgcdlhd"=hex:6b,61,63,65,61,69,66,6b,6c,6f,67,6f,6e,70,6b,68,68,
66,6e,65,6b,6b,00,00
"iahappecgdocmoembm"=hex:6b,61,6e,64,68,68,61,68,65,6c,67,6b,6c,70,6d,63,64,63,
63,6b,6e,6c,00,00
"hanjbjcdkefmpcek"=hex:61,61,00,00
"hanjbjcddpcbblbj"=hex:61,61,00,00

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2010-07-17 19:35:43
ComboFix-quarantined-files.txt 2010-07-17 18:35

Pre-Run: 109,239,623,680 bytes free
Post-Run: 109,200,957,440 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 832FF50AE08BB99E11A4F0A05C1574A6
Hello,

ComboFix Script
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::
Folder::
c:\documents and settings\Stuart Wright\Application Data\Ceimme
c:\documents and settings\Stuart Wright\Application Data\Etpi

RegLock::
[HKEY_USERS\S-1-5-21-1128806670-1401086586-2387256340-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5927D483-7E8F-E771-8746-11116D998CE7}*]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. If ComboFix prompts you to update to the newest version, please allow it to do so. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT:



Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



Kaspersky Online Scanner
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



NEXT:



OTL Custom Scan

We need to run an OTL Custom Scan
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following bolded text into the [external image: Posted Image] textbox.


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Push [external image: Posted Image]
  • A report will open. Copy and Paste that report in your next reply.





Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that is produced after running the ComboFix scrpt.
3. The log that is produced after running the MalwareBytes' Anti-Malware scan.
4. The log that is produced after running the Kaspersk Online Virus Scanner.
5. The log that is produced after running the SecurityCheck scan.
6. The log that is produced after running the OTL scan.
7. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.

Cheers,
SweetTech.
Hi sweettech,

I couldnt run the kapinsky online scanner, my computer just kept freezing

for some reason i couldnt run Mbam heres the message (below) i got when i tried to run it
[external image: Posted Image]

Computer doesnt seem to be redircting at the moment

but the combofix, security checker and otl ran fine (logs below)

ComboFix 10-07-16.01 - Stuart Wright 18/07/2010 15:28:19.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.657 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Stuart Wright\Desktop\CFScript.txt
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Stuart Wright\Application Data\Ceimme
c:\documents and settings\Stuart Wright\Application Data\Etpi

.
((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.

2010-07-17 18:31 . 2008-04-13 19:40 62976 —-a-w- c:\windows\system32\drivers\cdrom.sys
2010-07-17 18:31 . 2008-04-13 19:40 62976 —-a-w- c:\windows\system32\dllcache\cdrom.sys
2010-07-17 18:16 . 2010-07-17 18:16 ——– d—–w- C:\_OTL
2010-07-16 17:00 . 2010-07-16 17:00 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-16 17:00 . 2010-07-16 17:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-16 17:00 . 2010-07-16 17:00 ——– d—–w- c:\program files\ESET
2010-07-13 13:53 . 2010-07-16 17:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware(2)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-18 14:37 . 2009-02-04 16:20 72185888 –sha-w- c:\windows\system32\drivers\fidbox.dat
2010-07-18 14:36 . 2009-02-04 16:20 850064 –sha-w- c:\windows\system32\drivers\fidbox.idx
2010-07-13 12:53 . 2006-05-06 21:38 ——– d—–w- c:\program files\Paint Shop Pro 5
2010-06-19 16:51 . 2008-02-18 15:08 ——– d—–w- c:\documents and settings\Stuart Wright\Application Data\uTorrent
2010-06-16 17:48 . 2009-11-13 20:37 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-09 19:04 . 2010-06-09 19:04 388096 —-a-r- c:\documents and settings\Stuart Wright\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-09 18:30 . 2010-06-09 18:30 ——– d—–w- c:\program files\Trend Micro
2010-06-09 10:45 . 2008-02-18 15:08 ——– d—–w- c:\program files\uTorrent
2010-05-06 10:41 . 2005-08-16 04:18 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2008-10-14 12:40 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 14:39 . 2009-09-24 08:57 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2009-09-24 08:57 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-26 09:25 . 2010-04-26 08:39 1216 —-a-w- c:\windows\eReg.dat
2010-04-20 05:30 . 2005-08-16 04:18 285696 —-a-w- c:\windows\system32\atmfd.dll
2006-07-30 18:45 . 2006-04-22 20:50 104 –sh–r- c:\windows\system32\133339E4A9.sys
2006-05-03 09:06 . 2009-09-25 11:56 163328 –sh–r- c:\windows\system32\flvDX.dll
2006-07-30 18:45 . 2006-04-22 20:50 5278 –sha-w- c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47 . 2009-09-25 11:56 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-09-25 11:56 216064 –sh–r- c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 1937408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DSLMON.lnk]
backup=c:\windows\pss\DSLMON.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^Stuart Wright^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Stuart Wright\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 22:16 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-08-05 21:05 344064 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 01:12 110592 —-a-w- c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-02 18:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-09-15 09:47 57344 ——w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 10:44 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 14:39 1090952 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfeeUpdaterUI]
2006-12-19 10:27 136768 —-a-w- c:\program files\McAfee\Common Framework\UdaterUI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2005-01-04 14:17 1937408 ——w- c:\program files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
2006-11-03 10:01 319488 ——w- c:\windows\PixArt\PAC7302\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShStatEXE]
2007-02-22 19:50 112216 —-a-w- c:\program files\McAfee\VirusScan Enterprise\shstat.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ehSched"=2 (0x2)
"ehRecvr"=2 (0x2)
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dlcccoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Documents and Settings\\Stuart Wright\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2690:TCP"= 2690:TCP:ppLive
"2776:UDP"= 2776:UDP:ppLive

S3 EC168BDA;EC168BDA service;c:\windows\system32\drivers\ec168bda.sys [09/12/2008 18:30 107264]
S3 Ptserli;PCTEL Serial Device Driver for INTEL;c:\windows\system32\drivers\ptserli.sys [14/02/2007 20:31 128286]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [18/02/2008 17:57 194304]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\drivers\s3017bus.sys [31/10/2008 22:31 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\drivers\s3017mdfl.sys [31/10/2008 22:31 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\drivers\s3017mdm.sys [31/10/2008 22:31 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s3017mgmt.sys [31/10/2008 22:31 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\drivers\s3017nd5.sys [31/10/2008 22:31 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\drivers\s3017obex.sys [31/10/2008 22:31 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\drivers\s3017unic.sys [31/10/2008 22:31 110120]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [10/05/2007 20:29 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [10/05/2007 20:29 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [10/05/2007 20:29 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [10/05/2007 20:29 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [10/05/2007 20:30 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [10/05/2007 20:29 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [10/05/2007 20:29 90800]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [22/09/2006 20:04 223128]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [22/09/2006 20:02 642560]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://www.mytalktalk.net/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-18 15:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1128806670-1401086586-2387256340-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5927D483-7E8F-E771-8746-11116D998CE7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jajkdoochdnfgpgcdlhd"=hex:6b,61,63,65,61,69,66,6b,6c,6f,67,6f,6e,70,6b,68,68,
66,6e,65,6b,6b,00,00
"iahappecgdocmoembm"=hex:6b,61,6e,64,68,68,61,68,65,6c,67,6b,6c,70,6d,63,64,63,
63,6b,6e,6c,00,00
"hanjbjcdkefmpcek"=hex:61,61,00,00
"hanjbjcddpcbblbj"=hex:61,61,00,00

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(604)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\windows\system32\pctspk.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\system32\fxssvc.exe
.
**************************************************************************
.
Completion time: 2010-07-18 15:48:02 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-18 14:47
ComboFix2.txt 2010-07-17 18:35

Pre-Run: 104,784,785,408 bytes free
Post-Run: 104,767,639,552 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - F285575558DC28D2DCCE31F1D5FD807E



Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
ESET Online Scanner v3
McAfee VirusScan Enterprise
Antivirus up to date! (On Access scanning disabled!)
```````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
Malwarebytes' Anti-Malware
HijackThis 2.0.2
Java™ 6 Update 11
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Out of date Java installed!
Adobe Flash Player 10.0.12.36
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe is disabled!
McAfee VirusScan Enterprise Mcshield.exe
McAfee VirusScan Enterprise VsTskMgr.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````



OTL logfile created on: 18/07/2010 15:59:59 - Run 3
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Stuart Wright\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 599.00 Mb Available Physical Memory | 59.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 97.61 Gb Free Space | 67.63% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOMEPC
Current User Name: Stuart Wright
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Stuart Wright\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\pctspk.exe (PCtel, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Stuart Wright\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (aswUpdSv) – File not found
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (dlcc_device) – C:\WINDOWS\System32\dlcccoms.exe ()
SRV - (Pctspk) – C:\WINDOWS\system32\pctspk.exe (PCtel, Inc.)


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (vsdatant) – C:\WINDOWS\System32\vsdatant.sys File not found
DRV - (USBAAPL) – C:\WINDOWS\System32\Drivers\usbaapl.sys File not found
DRV - (szkg) – C:\WINDOWS\System32\DRIVERS\szkg.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (AR5523) – C:\WINDOWS\System32\DRIVERS\WG11TND5.sys File not found
DRV - (adiusbaw) – C:\WINDOWS\System32\DRIVERS\adiusbaw.sys File not found
DRV - (ADILOADER) General Purpose USB Driver (adildr.sys) – C:\WINDOWS\System32\Drivers\adildr.sys File not found
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (IrBus) – C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Changer) – C:\WINDOWS\System32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) – C:\WINDOWS\System32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (s3017unic) Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM) – C:\WINDOWS\system32\drivers\s3017unic.sys (MCCI Corporation)
DRV - (s3017obex) – C:\WINDOWS\system32\drivers\s3017obex.sys (MCCI Corporation)
DRV - (s3017mgmt) Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s3017mgmt.sys (MCCI Corporation)
DRV - (s3017nd5) Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS) – C:\WINDOWS\system32\drivers\s3017nd5.sys (MCCI Corporation)
DRV - (s3017mdm) – C:\WINDOWS\system32\drivers\s3017mdm.sys (MCCI Corporation)
DRV - (s3017mdfl) – C:\WINDOWS\system32\drivers\s3017mdfl.sys (MCCI Corporation)
DRV - (s3017bus) Sony Ericsson Device 3017 driver (WDM) – C:\WINDOWS\system32\drivers\s3017bus.sys (MCCI Corporation)
DRV - (EC168BDA) – C:\WINDOWS\system32\drivers\ec168bda.sys (e3C, Inc.)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (sea1unic) Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM) – C:\WINDOWS\system32\drivers\sea1unic.sys (MCCI)
DRV - (sea1obex) – C:\WINDOWS\system32\drivers\sea1obex.sys (MCCI)
DRV - (sea1nd5) Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS) – C:\WINDOWS\system32\drivers\sea1nd5.sys (MCCI)
DRV - (sea1mgmt) Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\sea1mgmt.sys (MCCI)
DRV - (sea1mdm) – C:\WINDOWS\system32\drivers\sea1mdm.sys (MCCI)
DRV - (sea1mdfl) – C:\WINDOWS\system32\drivers\sea1mdfl.sys (MCCI)
DRV - (sea1bus) Sony Ericsson Device 0A1 driver (WDM) – C:\WINDOWS\system32\drivers\sea1bus.sys (MCCI)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (se44unic) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM) – C:\WINDOWS\system32\drivers\se44unic.sys (MCCI)
DRV - (se44obex) – C:\WINDOWS\system32\drivers\se44obex.sys (MCCI)
DRV - (se44nd5) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS) – C:\WINDOWS\system32\drivers\se44nd5.sys (MCCI)
DRV - (se44mgmt) Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\se44mgmt.sys (MCCI)
DRV - (se44mdm) – C:\WINDOWS\system32\drivers\se44mdm.sys (MCCI)
DRV - (se44mdfl) – C:\WINDOWS\system32\drivers\se44mdfl.sys (MCCI)
DRV - (se44bus) Sony Ericsson Device 068 driver (WDM) – C:\WINDOWS\system32\drivers\se44bus.sys (MCCI)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys (McAfee, Inc.)
DRV - (vaxscsi) – C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (SE27obex) – C:\WINDOWS\system32\drivers\se27obex.sys (MCCI)
DRV - (SE27mgmt) Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\se27mgmt.sys (MCCI)
DRV - (SE27mdm) – C:\WINDOWS\system32\drivers\se27mdm.sys (MCCI)
DRV - (SE27mdfl) – C:\WINDOWS\system32\drivers\se27mdfl.sys (MCCI)
DRV - (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) – C:\WINDOWS\system32\drivers\se27bus.sys (MCCI)
DRV - (se27nd5) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS) – C:\WINDOWS\system32\drivers\se27nd5.sys (MCCI)
DRV - (se27unic) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM) – C:\WINDOWS\system32\drivers\se27unic.sys (MCCI)
DRV - (hcwPP2) – C:\WINDOWS\system32\drivers\hcwPP2.sys (Hauppauge Computer Works, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\CTUSFSYN.SYS (Creative Technology Ltd.)
DRV - (sigfilt) – C:\WINDOWS\system32\drivers\sigfilt.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\CTOSS2K.SYS (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\intelc53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\intelc52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\intelc51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\modemcsa.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (Vpctcom) – C:\WINDOWS\system32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Vvoice) – C:\WINDOWS\system32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\system32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (Ptserli) – C:\WINDOWS\system32\drivers\ptserli.sys (PCTEL, INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"



[2009/05/18 15:59:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Mozilla\Firefox\Profiles\7lnmtz7j.default\extensions
[2007/08/07 20:06:39 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Stuart Wright\Application Data\Mozilla\Firefox\Profiles\7lnmtz7j.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

O1 HOSTS File: ([2010/07/18 15:37:26 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\ScriptCl.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1186342685781 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Stuart Wright\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Stuart Wright\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 05:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi5 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer5 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecx.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave6 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave7 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/07/18 15:48:05 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/07/17 21:44:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Wright\Desktop\mmm
[2010/07/17 19:31:43 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cdrom.sys
[2010/07/17 19:20:57 | 000,000,000 | —D | C] – C:\Qoobox
[2010/07/17 19:16:03 | 000,000,000 | —D | C] – C:\_OTL
[2010/07/16 19:00:52 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Stuart Wright\Desktop\OTL.exe
[2010/07/16 18:00:34 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/07/16 18:00:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/16 18:00:28 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/07/13 14:53:15 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware(2)

========== Files - Modified Within 30 Days ==========

[2010/07/18 16:00:39 | 072,214,560 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2010/07/18 15:57:36 | 000,867,892 | —- | M] () – C:\Documents and Settings\Stuart Wright\Desktop\SecurityCheck.exe
[2010/07/18 15:57:08 | 000,011,902 | —- | M] () – C:\Documents and Settings\Stuart Wright\Desktop\Image2.jpg
[2010/07/18 15:37:46 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/07/18 15:37:26 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/18 15:37:16 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/18 15:37:10 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/18 15:37:07 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2010/07/18 15:36:29 | 000,850,064 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2010/07/18 15:36:20 | 018,128,896 | —- | M] () – C:\Documents and Settings\Stuart Wright\ntuser.dat
[2010/07/18 15:36:20 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Stuart Wright\ntuser.ini
[2010/07/18 05:36:23 | 000,000,987 | —- | M] () – C:\WINDOWS\win.ini
[2010/07/17 21:40:28 | 002,566,144 | —- | M] () – C:\Documents and Settings\Stuart Wright\Desktop\Karaoke Tracklisting & CD Lists & Dance Music.xls
[2010/07/17 21:37:43 | 000,141,824 | —- | M] () – C:\Documents and Settings\Stuart Wright\Desktop\Zoom_Platinum_001-130_Track_List.xls
[2010/07/17 19:50:51 | 000,000,104 | —- | M] () – C:\Documents and Settings\Stuart Wright\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
[2010/07/17 19:11:58 | 003,738,205 | R— | M] () – C:\Documents and Settings\Stuart Wright\Desktop\ComboFix.exe
[2010/07/16 19:19:08 | 000,293,376 | —- | M] () – C:\Documents and Settings\Stuart Wright\Desktop\ndmjnzpq.exe
[2010/07/16 19:00:55 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Stuart Wright\Desktop\OTL.exe
[2010/07/16 18:02:14 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/13 14:35:40 | 000,556,080 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/13 14:35:40 | 000,483,978 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/13 14:35:40 | 000,082,672 | —- | M] () – C:\WINDOWS\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2010/07/18 15:57:32 | 000,867,892 | —- | C] () – C:\Documents and Settings\Stuart Wright\Desktop\SecurityCheck.exe
[2010/07/18 15:57:08 | 000,011,902 | —- | C] () – C:\Documents and Settings\Stuart Wright\Desktop\Image2.jpg
[2010/07/17 21:37:42 | 000,141,824 | —- | C] () – C:\Documents and Settings\Stuart Wright\Desktop\Zoom_Platinum_001-130_Track_List.xls
[2010/07/17 20:20:20 | 002,566,144 | —- | C] () – C:\Documents and Settings\Stuart Wright\Desktop\Karaoke Tracklisting & CD Lists & Dance Music.xls
[2010/07/17 19:50:51 | 000,000,104 | —- | C] () – C:\Documents and Settings\Stuart Wright\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
[2010/07/17 19:14:54 | 003,738,205 | R— | C] () – C:\Documents and Settings\Stuart Wright\Desktop\ComboFix.exe
[2010/07/16 19:19:07 | 000,293,376 | —- | C] () – C:\Documents and Settings\Stuart Wright\Desktop\ndmjnzpq.exe
[2010/07/13 14:40:57 | 018,128,896 | —- | C] () – C:\Documents and Settings\Stuart Wright\ntuser.dat
[2010/07/06 09:19:33 | 1071,796,224 | -HS- | C] () – C:\hiberfil.sys
[2010/02/28 20:06:15 | 000,000,107 | —- | C] () – C:\WINDOWS\IfoEdit.INI
[2009/10/01 20:57:42 | 000,000,122 | —- | C] () – C:\WINDOWS\kaillera.ini
[2009/09/08 20:46:11 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/09/08 20:46:09 | 000,881,664 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/09/08 20:46:09 | 000,205,824 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/09/08 20:46:08 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/09/08 20:46:07 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/09/08 20:46:06 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/12/09 18:32:26 | 000,000,014 | —- | C] () – C:\WINDOWS\System32\systeminfo.dll
[2008/12/09 18:30:41 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2008/10/21 13:13:29 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/02/18 17:57:29 | 000,966,765 | —- | C] () – C:\WINDOWS\System32\acAuth.dll
[2008/02/18 17:57:29 | 000,356,352 | —- | C] () – C:\WINDOWS\System32\SCMLib.dll
[2008/02/09 18:45:07 | 000,000,034 | —- | C] () – C:\WINDOWS\C_it.ini
[2008/01/26 17:13:53 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/01/05 22:29:59 | 000,000,518 | —- | C] () – C:\WINDOWS\SCRABOUT.INI
[2007/10/19 13:09:00 | 000,000,280 | —- | C] () – C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2007/09/11 08:29:33 | 000,001,658 | —- | C] () – C:\WINDOWS\disney.ini
[2007/07/30 19:59:20 | 000,010,752 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2007/06/24 15:28:58 | 000,000,011 | —- | C] () – C:\WINDOWS\vf86.sys
[2007/06/24 15:28:50 | 000,000,928 | —- | C] () – C:\WINDOWS\MP3Weasel.INI
[2007/05/17 13:58:10 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2007/04/24 20:31:12 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\ucinst32.dll
[2007/04/22 20:19:43 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcccfg.dll
[2007/01/10 20:26:10 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/10/19 21:05:36 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/10/19 21:05:30 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/09/19 15:23:37 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/08/21 20:57:42 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\cygz.dll
[2006/07/08 13:49:49 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2006/05/01 22:17:30 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/05/01 21:52:45 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\pCastCtl.dll
[2006/04/22 21:50:32 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\133339E4A9.sys
[2006/04/22 21:50:24 | 000,005,278 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/03/23 20:12:41 | 000,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/03/20 22:19:01 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/20 21:53:48 | 000,000,930 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/03/20 21:05:52 | 000,000,046 | —- | C] () – C:\WINDOWS\adiras.ini
[2006/03/20 20:37:49 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/03/16 01:45:19 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/16 01:42:26 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/03/16 01:33:57 | 000,005,811 | —- | C] () – C:\WINDOWS\System32\CTSBMB.INI
[2006/03/16 01:08:52 | 000,004,969 | —- | C] () – C:\WINDOWS\System32\Sigfilt.ini
[2006/03/16 01:08:52 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/03/16 01:08:34 | 001,345,520 | —- | C] () – C:\WINDOWS\System32\CTMBHA.DLL
[2006/03/16 01:08:10 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\hcwXDS.dll
[2006/03/16 01:07:42 | 000,000,475 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/16 05:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/02 15:00:16 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlccplc.ini
[2005/07/22 20:48:28 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlccinsr.dll
[2005/07/22 20:48:24 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcccur.dll
[2005/07/22 20:48:06 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlccjswr.dll
[2005/07/22 20:47:20 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlccinsb.dll
[2005/07/22 20:47:14 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcccub.dll
[2005/07/22 20:47:08 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcccu.dll
[2005/07/22 20:47:06 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccins.dll
[2005/07/22 20:45:22 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlccutil.dll
[2005/06/21 21:27:56 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlccpmui.dll
[2005/06/21 21:27:02 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlccserv.dll
[2005/06/21 21:22:06 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcclmpm.dll
[2005/06/21 21:21:40 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcccomm.dll
[2005/06/21 21:19:48 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlccpplc.dll
[2005/06/21 21:18:58 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcccomc.dll
[2005/06/21 21:18:24 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccprox.dll
[2005/06/21 21:12:48 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlccusb1.dll
[2005/06/21 21:09:22 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcchbn3.dll
[2005/04/27 13:40:30 | 000,002,574 | —- | C] () – C:\WINDOWS\WINDVDBOOTRECDOE.sys
[2005/03/30 16:19:58 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlccvs.dll

========== LOP Check ==========

[2006/03/20 21:20:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\.MicroAntivirus
[2006/12/15 12:12:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\BitTorrent
[2007/05/17 19:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Datalayer
[2008/12/26 16:44:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Disney Mix It Plug-in
[2009/10/08 14:10:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\EA
[2007/05/28 18:39:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\GetRightToGo
[2008/03/29 16:08:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\GrabIt
[2007/03/10 12:09:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Kontiki
[2006/03/20 20:57:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Leadertech
[2008/03/27 21:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\NewzToolz-EZ
[2007/05/17 19:41:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Nokia
[2007/06/18 18:08:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Nokia Multimedia Player
[2006/08/10 21:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Opera
[2006/03/25 21:38:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Otto
[2007/05/17 18:26:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\PC Suite
[2007/06/30 11:30:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\SecondLife
[2009/05/14 19:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Solveig Multimedia
[2009/02/05 09:39:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Sony
[2007/11/14 21:04:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\SpinTop
[2009/11/12 11:32:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Sports Interactive
[2006/07/28 19:34:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\STOPzilla!
[2007/05/20 13:58:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Teleca
[2007/12/03 17:50:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Uniblue
[2010/06/19 17:51:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\uTorrent
[2008/11/05 23:05:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\VitySoft
[2009/10/20 11:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Wright\Application Data\Vso

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/02/16 16:05:25 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/07/18 15:48:03 | 000,014,759 | —- | M] () – C:\ComboFix.txt
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/18 15:37:07 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2006/07/31 20:35:23 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/31 20:35:23 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/20 18:56:59 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/07/18 15:37:02 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2009/05/04 20:04:58 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/05/24 22:51:53 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/05/26 21:18:34 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/03/24 18:51:18 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/04/28 07:44:20 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/04/29 21:17:22 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/05/01 17:08:07 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/05/02 20:18:09 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/05/07 22:31:41 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/03/24 22:59:33 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/03/29 20:41:57 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/04/03 20:07:07 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/04/03 22:32:53 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/04/04 21:11:38 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/04/10 22:15:08 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/04/13 21:05:46 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/04/19 19:34:23 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/04/20 20:29:48 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/04/21 13:49:46 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/04/27 20:56:09 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/05/04 20:04:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/05/24 22:51:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/05/26 21:18:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/03/24 18:51:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/04/28 07:44:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/04/29 21:17:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/05/01 17:08:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/05/02 20:18:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/05/07 22:31:41 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/03/24 22:59:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/03/29 20:41:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/04/03 20:07:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/04/03 22:32:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/04/04 21:11:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/04/10 22:15:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/04/13 21:05:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/04/19 19:34:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/04/20 20:29:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/04/21 13:49:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/04/27 20:56:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 05:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(2).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(3).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(4).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(5).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C(6).DLL
[2005/08/26 08:42:56 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 04:31:44 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/08/16 05:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 05:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 05:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 01:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 01:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 01:12:10 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\system32\ws2help.dll

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-18 04:40:47

========== Alternate Data Streams ==========

@Alternate Data Stream - 38 bytes -> C:\Documents and Settings\All Users\Desktop:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EP
PJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV
< End of report >
Hello,

Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "JDK 6 Update 21 (JDK or JRE)".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586.exe to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
– Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
– Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


Note:
The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
Click Ok and reboot your computer.


NEXT



Clean Java Cache & Temporary Files
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT:



Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location and post it in your next reply.


NEXT:



Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.



NEXT:



MalwareBytes' Anti-Malware Uninstall
1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
2. Restart your computer (very important).
3. Download and run this utility. http://www.malwarebytes.org/mbam-clean.exe
4. It will ask to restart your computer (please allow it to).
5. After the computer restarts, install the latest version from here.



NEXT:



Try to run the Kaspersky Online Scanner now. If it still won't let you run it then run the scan below:

AVP Tool by Kaspersky

IMPORTANT: Save these instructions so you can have access to them while in Safe Mode.

Download the AVP Tool by Kaspersky from Here & save it to your desktop. Be aware that this is a large file…. approximately 60mb.
  • Reboot your computer into Safe Mode

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears
    Use your up arrow key to highlight Safe Mode then press Enter


  • Double click the setup file to run it
  • Click Next to continue
  • Accept the License agreement then click Next
  • It will by default install to your desktop folder. Click Next
  • Once installed it will open a box. Click the Automatic scan tab
  • Under Automatic scan make sure the following are checked:

  • Hidden Startup Objects
  • System Memory
  • Disk Boot Sectors
  • My Computer
  • Also any other drives (Removable that you may have)

Leave the rest of the settings as they appear

  • Click on Scan at the top right hand corner
  • It will automatically neutralize any objects found
  • If some objects are left un-neutralized, click on Neutralize all
  • If you receive a message that an item cannot be neutralized then choose the Delete option when prompted
  • Once finished click the Reports button at the bottom
  • Name the file Kas & save it somewhere convenient like your desktop
  • Copy/paste only the detected Virus\malware from the report. It will be at the very top under Detected & post those results in your next reply

    Note: This program will self uninstall when you close it so save the log before closing it

Hi sweetech heres the logs ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, July 18, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, July 18, 2010 11:46:32 Records in database: 4231423 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ Scan statistics: Objects scanned: 57711 Threats found: 10 Infected objects found: 22 Suspicious objects found: 0 Scan duration: 02:32:25 File name / Threat / Threats count C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000019.DLL Infected: Trojan-Spy.Win32.Brospa.ab 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000020.DLL Infected: Trojan-Spy.Win32.Brospa.ai 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000032.DLL Infected: Trojan-Spy.Win32.Brospa.ab 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP3\A0000192.DLL Infected: Trojan-Spy.Win32.Brospa.ab 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP3\A0000194.DLL Infected: Trojan-Spy.Win32.Brospa.aj 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP3\A0000207.DLL Infected: Trojan-Spy.Win32.Brospa.ab 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP3\A0000212.exe Infected: Trojan-Spy.Win32.Insain.afc 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP4\A0001207.DLL Infected: Trojan-Spy.Win32.Brospa.ab 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP5\A0001258.exe Infected: Trojan-Spy.Win32.Insain.afc 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP5\A0001264.DLL Infected: Trojan-Spy.Win32.Brospa.aj 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP5\A0001313.DLL Infected: Trojan-Spy.Win32.Brospa.aj 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP6\A0002312.DLL Infected: Trojan-Spy.Win32.Brospa.ab 1 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP6\A0002314.exe Infected: Trojan-Spy.Win32.Insain.afe 1 C:\_OTL\MovedFiles\07172010_191603\C_Documents and Settings\Stuart Wright\Application Data\Ceimme\icfu.exe Infected: Packed.Win32.Krap.hm 1 C:\_OTL\MovedFiles\07172010_191603\C_Documents and Settings\Stuart Wright\Application Data\Etpi\poyw.exe Infected: Packed.Win32.Krap.hm 1 C:\_OTL\MovedFiles\07172010_191603\C_Documents and Settings\Stuart Wright\Local Settings\temp\Xsh.exe Infected: Packed.Win32.Katusha.n 1 C:\_OTL\MovedFiles\07172010_191603\C_WINDOWS\system32\0050.DLL Infected: Trojan-Spy.Win32.Brospa.ab 1 C:\_OTL\MovedFiles\07172010_191603\C_WINDOWS\system32\0051.DLL Infected: Trojan-Spy.Win32.Brospa.ad 1 C:\_OTL\MovedFiles\07172010_191603\C_WINDOWS\system32\0052.DLL Infected: Trojan-Spy.Win32.Brospa.ak 1 C:\_OTL\MovedFiles\07172010_191603\C_WINDOWS\system32\ini.exe Infected: Trojan-Spy.Win32.Insain.aeu 1 C:\_OTL\MovedFiles\07172010_191603\C_WINDOWS\system32\wexe.exe Infected: Trojan-Spy.Win32.Insain.afe 1 C:\_OTL\MovedFiles\07172010_191603\C_WINDOWS\Xmerea.exe Infected: Packed.Win32.Katusha.n 1 Selected area has been scanned.
Hello,

I'd like for you to try and run an updated scan with MBAM now. I'll provide instructions below.

Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:


Please provide me with an update on how things are currently running.
Hi Sweettech, Computer seems to be running fine no redirects to report thanks Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 19/07/2010 11:37:55 mbam-log-2010-07-19 (11-37-55).txt Scan type: Quick scan Objects scanned: 136395 Time elapsed: 9 minute(s), 54 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Your still using an outdated database version of MBAM. The current database version is 4325, and you are using 4052. Please try to update it again, and post the log.
I'm not able to see the current image that you've posted for me to look at. Can you please try attaching the image to your next post?

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Add to insert the attachment into your post

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI