This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect/Other popup problems.

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, ive been having lots of problems with my computer lately. Recently a torrent was downloaded on this computer and i figured that might be the culprit. ive been aiming to destroy the virus ever since i got it.. and ive tried several programs and nothing has worked. When browsing on the internet, a random tab will open up and either go to a random website, or redirect to google. When clicking links on google it just sends me to some spam website or even a blank page. :/ i have tried tons and i cant figure it out. here's the log..:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:17:13 AM, on 7/22/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\program files\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Udenifu] rundll32.exe "C:\WINDOWS\opixenibek.dll",Startup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

–
End of file - 8380 bytes


thanks for the help.
Hello,

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:



Scanning with GMER

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)
3. The log that was produced after running GMER
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
For some reason it wouldnt let me post on my original computer.. my appologies for the slow reply.

OTL logfile created on: 7/22/2010 10:38:31 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Austin\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 362.18 Gb Free Space | 77.76% Space Free | Partition Type: NTFS
Drive D: | 3.07 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: QUADCOREAMD
Current User Name: Austin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Austin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe (Microsoft Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Austin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeEngineService) – C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)


========== Driver Services (SafeList) ==========

DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (amdide) – C:\WINDOWS\system32\DRIVERS\amdide.sys (Advanced Micro Devices)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {1E4D63C9-7584-47F2-8FC6-A47AE8873100}:1.9.1

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E4D63C9-7584-47F2-8FC6-A47AE8873100}: C:\Documents and Settings\Austin\Local Settings\Application Data\{1E4D63C9-7584-47F2-8FC6-A47AE8873100} [2010/07/21 01:53:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/21 02:28:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/21 02:28:15 | 000,000,000 | —D | M]

[2010/05/23 02:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Austin\Application Data\Mozilla\Extensions
[2010/07/22 00:10:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Austin\Application Data\Mozilla\Firefox\Profiles\9pm2ppcc.default\extensions
[2010/06/17 13:28:29 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Austin\Application Data\Mozilla\Firefox\Profiles\9pm2ppcc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/22 00:10:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/21 01:55:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2008/09/29 08:07:00 | 000,022,576 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2010/07/18 02:15:04 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/05/23 05:13:52 | 000,395,292 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13652 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [itype] c:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [Udenifu] C:\WINDOWS\opixenibek.DLL File not found
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\Austin\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Austin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Austin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/23 02:40:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/03/11 18:08:16 | 000,006,257 | R— | M] () - D:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2009/03/13 00:30:46 | 000,263,480 | R— | M] (Firaxis Games) - D:\autorun.exe – [ UDF ]
O32 - AutoRun File - [2009/04/02 15:13:09 | 000,000,000 | R–D | M] - D:\Autorun – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17465059307421696)

========== Files/Folders - Created Within 30 Days ==========

[2010/07/22 10:37:21 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Austin\Desktop\OTL.exe
[2010/07/22 03:16:45 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/07/22 01:30:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Application Data\SUPERAntiSpyware.com
[2010/07/22 01:30:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/07/22 01:30:44 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/07/22 01:29:49 | 009,157,960 | —- | C] (SUPERAntiSpyware.com) – C:\Documents and Settings\Austin\Desktop\SUPERAntiSpyware.exe
[2010/07/22 00:06:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Application Data\Malwarebytes
[2010/07/22 00:06:18 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/22 00:06:16 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/22 00:06:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/22 00:06:15 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/22 00:05:53 | 006,153,376 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Austin\Desktop\mbam-setup-1.46.exe
[2010/07/21 15:27:12 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/07/21 02:27:50 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/07/21 02:25:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Application Data\InstallShield
[2010/07/21 02:23:41 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2010/07/21 02:23:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Local Settings\Application Data\PunkBuster
[2010/07/21 02:23:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2010/07/21 01:56:14 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/07/21 01:12:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010/07/21 01:11:47 | 000,000,000 | –SD | C] – C:\Documents and Settings\Austin\UserData
[2010/07/20 22:48:52 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/20 22:48:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/20 22:48:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/19 22:18:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Local Settings\Application Data\{1E4D63C9-7584-47F2-8FC6-A47AE8873100}
[2010/07/18 13:39:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Desktop\minecraft
[2010/07/18 02:15:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Application Data\.minecraft
[2010/07/18 02:15:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/07/18 02:15:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/07/18 02:15:18 | 000,423,656 | —- | C] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/07/18 02:15:18 | 000,153,376 | —- | C] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/07/18 02:15:18 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/07/18 02:15:18 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/07/18 02:15:18 | 000,073,728 | —- | C] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/07/18 02:14:59 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/07/18 02:14:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Application Data\Sun
[2010/07/17 18:46:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\My Documents\My Games
[2010/07/17 18:46:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Local Settings\Application Data\My Games
[2010/07/17 18:35:36 | 000,000,000 | —D | C] – C:\Program Files\2K Games
[2010/07/17 01:45:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Desktop\Quantums Little Config
[2010/07/17 01:09:45 | 000,000,000 | —D | C] – C:\Fraps
[2010/07/13 19:37:17 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/10 19:05:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Desktop\pictures
[2010/07/09 10:44:06 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2010/07/09 10:44:06 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2010/07/09 02:32:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Tracing
[2010/07/09 02:31:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2010/07/08 17:39:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\My Documents\BFBC2
[2010/07/08 17:39:44 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Austin\Application Data\SecuROM
[2010/07/08 13:46:28 | 000,000,000 | —D | C] – C:\Program Files\Electronic Arts
[2010/07/08 13:46:26 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_5.dll
[2010/07/08 13:46:26 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_5.dll
[2010/07/08 13:46:25 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dcsx_42.dll
[2010/07/08 13:46:25 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_42.dll
[2010/07/08 13:46:24 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_42.dll
[2010/07/08 13:46:24 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_42.dll
[2010/07/08 13:46:24 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx11_42.dll
[2010/07/08 13:46:23 | 001,846,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_41.dll
[2010/07/08 13:46:23 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_41.dll
[2010/07/08 13:46:21 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_40.dll
[2010/07/08 13:46:21 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_40.dll
[2010/07/08 13:46:20 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_40.dll
[2010/07/08 13:46:19 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_3.dll
[2010/07/08 13:46:19 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_3.dll
[2010/07/08 13:46:19 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_2.dll
[2010/07/08 13:46:19 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_5.dll
[2010/07/08 13:46:17 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_2.dll
[2010/07/08 01:07:20 | 000,000,000 | —D | C] – C:\QUARANTINE
[2010/07/06 02:50:32 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_41.dll
[2010/07/06 02:50:32 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_4.dll
[2010/07/06 02:50:32 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_3.dll
[2010/07/06 02:50:31 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_4.dll
[2010/07/06 02:50:31 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_6.dll
[2010/06/25 15:52:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Application Data\skypePM
[2010/06/25 15:43:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Local Settings\Application Data\Google
[2010/06/25 15:43:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2010/06/25 15:43:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Austin\Application Data\Skype
[2010/06/25 15:43:43 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/06/25 15:43:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/06/25 15:43:14 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/06/25 15:43:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2010/06/22 12:08:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Blizzard Entertainment
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/22 10:37:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Austin\Desktop\OTL.exe
[2010/07/22 03:16:46 | 000,001,986 | —- | M] () – C:\Documents and Settings\Austin\Desktop\HiJackThis.lnk
[2010/07/22 03:16:13 | 001,402,880 | —- | M] () – C:\Documents and Settings\Austin\Desktop\HiJackThis.msi
[2010/07/22 03:12:11 | 000,499,522 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/22 03:12:11 | 000,401,968 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/22 03:12:11 | 000,085,614 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/22 03:11:15 | 004,868,816 | —- | M] () – C:\Documents and Settings\Austin\Desktop\RegistryPatrol_Trial.exe
[2010/07/22 03:07:25 | 000,276,202 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/07/22 03:07:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/22 03:07:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/22 02:36:11 | 008,220,672 | —- | M] () – C:\Documents and Settings\Austin\NTUSER.DAT
[2010/07/22 02:35:33 | 003,774,418 | -H– | M] () – C:\Documents and Settings\Austin\Local Settings\Application Data\IconCache.db
[2010/07/22 01:30:46 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/22 01:30:36 | 009,157,960 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Austin\Desktop\SUPERAntiSpyware.exe
[2010/07/22 01:27:59 | 000,000,000 | —- | M] () – C:\WINDOWS\Qbege.bin
[2010/07/22 00:06:20 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/22 00:06:03 | 006,153,376 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Austin\Desktop\mbam-setup-1.46.exe
[2010/07/21 23:59:01 | 000,000,120 | —- | M] () – C:\WINDOWS\Nzipuzimocinexi.dat
[2010/07/21 23:58:08 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Austin\ntuser.ini
[2010/07/21 03:50:23 | 000,001,824 | —- | M] () – C:\eg_AppID_CLSID.reg
[2010/07/21 02:29:28 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/21 02:29:18 | 000,270,984 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/21 00:43:59 | 000,012,540 | —- | M] () – C:\WINDOWS\System32\wpa.bak
[2010/07/20 22:48:52 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/20 19:36:06 | 000,070,024 | —- | M] () – C:\Documents and Settings\Austin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/20 01:08:31 | 000,000,161 | —- | M] () – C:\Documents and Settings\Austin\Desktop\Alien Swarm.url
[2010/07/19 00:37:17 | 000,137,256 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/07/19 00:37:08 | 000,218,808 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2010/07/18 02:15:02 | 000,153,376 | —- | M] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/07/18 02:15:02 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/07/18 02:15:02 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/07/18 02:15:02 | 000,073,728 | —- | M] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/07/18 02:15:01 | 000,423,656 | —- | M] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/07/18 02:13:38 | 000,232,396 | —- | M] () – C:\Documents and Settings\Austin\Desktop\Minecraft.exe
[2010/07/17 19:31:20 | 000,002,338 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Sid Meier's Civilization 4 - Beyond the Sword.lnk
[2010/07/17 18:45:53 | 000,002,227 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Sid Meier's Civilization 4 - Warlords.lnk
[2010/07/17 18:45:52 | 000,002,125 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Sid Meier's Civilization 4.lnk
[2010/07/16 23:28:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/10 11:56:51 | 000,000,552 | —- | M] () – C:\WINDOWS\win.ini
[2010/07/08 18:05:03 | 000,002,439 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Mouse.lnk
[2010/07/08 14:01:30 | 000,138,056 | —- | M] () – C:\Documents and Settings\Austin\Application Data\PnkBstrK.sys
[2010/07/08 14:01:12 | 002,434,856 | —- | M] () – C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/07/08 14:00:30 | 000,001,923 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Battlefield Bad Company 2.lnk
[2010/07/06 10:58:00 | 000,000,181 | —- | M] () – C:\Documents and Settings\Austin\Desktop\Defense Grid The Awakening.url
[2010/07/05 16:21:13 | 000,015,304 | —- | M] () – C:\Documents and Settings\Austin\Desktop\Sea_Of_Treachery_-_At_Daggers_Drawn_(V0_Quality)_[VAULT_RELEASE].4163463.TPB.torrent
[2010/06/28 16:01:52 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/06/25 15:52:35 | 000,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/06/24 22:20:21 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/22 16:30:05 | 000,000,745 | —- | M] () – C:\Documents and Settings\Austin\Desktop\SUCKING DICKS.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/22 03:16:46 | 000,001,986 | —- | C] () – C:\Documents and Settings\Austin\Desktop\HiJackThis.lnk
[2010/07/22 03:16:10 | 001,402,880 | —- | C] () – C:\Documents and Settings\Austin\Desktop\HiJackThis.msi
[2010/07/22 03:11:03 | 004,868,816 | —- | C] () – C:\Documents and Settings\Austin\Desktop\RegistryPatrol_Trial.exe
[2010/07/22 01:30:46 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/22 00:06:20 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/21 03:50:23 | 000,001,824 | —- | C] () – C:\eg_AppID_CLSID.reg
[2010/07/19 22:18:26 | 000,000,120 | —- | C] () – C:\WINDOWS\Nzipuzimocinexi.dat
[2010/07/19 22:18:26 | 000,000,000 | —- | C] () – C:\WINDOWS\Qbege.bin
[2010/07/19 17:21:06 | 000,000,161 | —- | C] () – C:\Documents and Settings\Austin\Desktop\Alien Swarm.url
[2010/07/18 02:13:38 | 000,232,396 | —- | C] () – C:\Documents and Settings\Austin\Desktop\Minecraft.exe
[2010/07/17 18:45:53 | 000,002,338 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Sid Meier's Civilization 4 - Beyond the Sword.lnk
[2010/07/17 18:45:53 | 000,002,227 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Sid Meier's Civilization 4 - Warlords.lnk
[2010/07/17 18:45:52 | 000,002,125 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Sid Meier's Civilization 4.lnk
[2010/07/08 17:40:08 | 000,218,808 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2010/07/08 14:01:32 | 000,137,256 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/07/08 14:01:30 | 000,138,056 | —- | C] () – C:\Documents and Settings\Austin\Application Data\PnkBstrK.sys
[2010/07/08 14:01:13 | 000,218,808 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2010/07/08 14:01:12 | 002,434,856 | —- | C] () – C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/07/08 14:01:12 | 000,075,064 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2010/07/08 14:00:30 | 000,001,923 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Battlefield Bad Company 2.lnk
[2010/07/06 02:32:45 | 000,000,181 | —- | C] () – C:\Documents and Settings\Austin\Desktop\Defense Grid The Awakening.url
[2010/07/05 16:21:12 | 000,015,304 | —- | C] () – C:\Documents and Settings\Austin\Desktop\Sea_Of_Treachery_-_At_Daggers_Drawn_(V0_Quality)_[VAULT_RELEASE].4163463.TPB.torrent
[2010/06/27 12:44:14 | 000,160,344 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/06/25 15:52:35 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/06/25 15:43:16 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/06/10 18:04:59 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini

========== LOP Check ==========

[2010/06/04 02:28:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\KeyText
[2010/05/24 01:50:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/06/04 02:22:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/23 09:00:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/07/20 02:05:23 | 000,000,000 | -HSD | M] – C:\Documents and Settings\Austin\Application Data\.#
[2010/07/18 02:16:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Austin\Application Data\.minecraft
[2010/07/21 02:25:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Austin\Application Data\BitTorrent
[2010/05/24 02:36:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Austin\Application Data\LolClient

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/05/23 02:40:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/05/23 02:35:57 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/05/23 02:40:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/21 03:50:23 | 000,001,824 | —- | M] () – C:\eg_AppID_CLSID.reg
[2010/05/23 02:40:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/23 02:40:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/05/23 03:04:43 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/07/22 03:07:16 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/05/23 02:40:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2010/05/22 18:23:04 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/05/22 18:23:04 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/05/22 18:23:04 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 05:42:10 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 05:42:12 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 05:42:12 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-14 08:01:02

========== Alternate Data Streams ==========

@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D48F2BA9
< End of report >
and here's Extras.Txt

OTL Extras logfile created on: 7/22/2010 10:38:33 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Austin\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 362.18 Gb Free Space | 77.76% Space Free | Partition Type: NTFS
Drive D: | 3.07 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: QUADCOREAMD
Current User Name: Austin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{11E94FDB-C895-45F1-B756-1C9B8C36C8F1}" = Microsoft IntelliType Pro 7.1
"{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}" = McAfee VirusScan Enterprise
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{30D1F3D2-54CF-481D-A005-F94B0E98FEEC}" = Sid Meier's Civilization 4 Complete
"{32E4F0D2-C135-475E-A841-1D59A0D22989}" = Sid Meier's Civilization 4 - Beyond the Sword
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46F8CF66-AB83-38A7-99B2-A5BE507EE472}" = Microsoft Visual C++ 2010 Express - ENU
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{7057ABC2-EFF3-4E43-9806-8BCB6EEA9FE6}" = Microsoft IntelliPoint 7.1
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C5F81D-0779-4932-BE83-32AAF814F4B9}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A638557B-1F13-40A0-9627-C892FBCA6960}" = McAfee Agent
"{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALUpdate_is1" = ALTools Update
"ALZip_is1" = ALZip
"AutoHotkey" = AutoHotkey 1.0.48.05
"BitTorrent" = BitTorrent
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft Visual C++ 2010 Express - ENU" = Microsoft Visual C++ 2010 Express - ENU
"Mozilla Firefox (3.6.7)" = Mozilla Firefox (3.6.7)
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"PowerISO" = PowerISO
"PunkBusterSvc" = PunkBuster Services
"Quantums Little Config v2.7" = Quantums Little Config v2.7
"Steam App 18500" = Defense Grid: The Awakening
"Steam App 240" = Counter-Strike: Source
"Steam App 25980" = Majesty 2
"Steam App 400" = Portal
"Steam App 440" = Team Fortress 2
"Steam App 630" = Alien Swarm
"Windows XP Service Pack" = Windows XP Service Pack 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/27/2010 6:11:10 AM | Computer Name = QUADCOREAMD | Source = Application Error | ID = 1000
Description = Faulting application pvptool.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 6/27/2010 6:16:44 AM | Computer Name = QUADCOREAMD | Source = Application Error | ID = 1000
Description = Faulting application d.exe, version 0.0.0.0, faulting module , version
0.0.0.0, fault address 0x00000000.

Error - 6/29/2010 6:55:42 PM | Computer Name = QUADCOREAMD | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(BZDN1641351607-QkxaMDAwMjg5RCRIOEE4NEYyOENBNXUwNzk2OEVfODI=._bzdn._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 7/1/2010 7:52:01 AM | Computer Name = QUADCOREAMD | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/1/2010 7:52:01 AM | Computer Name = QUADCOREAMD | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1969

Error - 7/1/2010 7:52:01 AM | Computer Name = QUADCOREAMD | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1969

Error - 7/1/2010 7:52:03 AM | Computer Name = QUADCOREAMD | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/1/2010 7:52:03 AM | Computer Name = QUADCOREAMD | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3938

Error - 7/1/2010 7:52:03 AM | Computer Name = QUADCOREAMD | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3938

Error - 7/4/2010 10:31:48 PM | Computer Name = QUADCOREAMD | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

[ System Events ]
Error - 7/21/2010 6:24:34 PM | Computer Name = QUADCOREAMD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips mfehidk Processor SCDEmu

Error - 7/22/2010 3:58:08 AM | Computer Name = QUADCOREAMD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 7/22/2010 3:59:14 AM | Computer Name = QUADCOREAMD | Source = Service Control Manager | ID = 7023
Description = The Windows Firewall/Internet Connection Sharing (ICS) service terminated
with the following error: %%2

Error - 7/22/2010 5:28:16 AM | Computer Name = QUADCOREAMD | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 7/22/2010 5:28:16 AM | Computer Name = QUADCOREAMD | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 7/22/2010 5:28:20 AM | Computer Name = QUADCOREAMD | Source = Service Control Manager | ID = 7023
Description = The Windows Firewall/Internet Connection Sharing (ICS) service terminated
with the following error: %%2

Error - 7/22/2010 5:28:53 AM | Computer Name = QUADCOREAMD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
PCIIde

Error - 7/22/2010 7:07:47 AM | Computer Name = QUADCOREAMD | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 7/22/2010 7:07:47 AM | Computer Name = QUADCOREAMD | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 7/22/2010 7:08:09 AM | Computer Name = QUADCOREAMD | Source = Service Control Manager | ID = 7023
Description = The Windows Firewall/Internet Connection Sharing (ICS) service terminated
with the following error: %%2


< End of report >
the log took extremely long to do.. so i left my computer on to scan and i guess my computer restarted when i wasnt here. :/ i need to scan again so let me do that asap.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-22 20:03:23
Windows 5.1.2600 Service Pack 3
Running: s61jdtt3.exe; Driver: C:\DOCUME~1\Austin\LOCALS~1\Temp\pxryqpob.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB250F620]

Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB7DE3086]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcess [0xB7DE3020]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB7DE3034]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB7DE309A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB7DE30C6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwEnumerateKey [0xB7DE3134]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xB7DE311E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwLoadKey2 [0xB7DE314A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB7DE3176]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB7DE3072]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB7DE2FE4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB7DE2FF8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryKey [0xB7DE31B2]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB7DE3108]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryValueKey [0xB7DE30F2]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB7DE30B0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwReplaceKey [0xB7DE319E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRestoreKey [0xB7DE318A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetContextThread [0xB7DE305E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB7DE304A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB7DE30DC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB7DE300C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnloadKey [0xB7DE3160]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntkrnlpa.exe!NtOpenProcess 805CB3FA 5 Bytes JMP B7DE2FE8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB686 5 Bytes JMP B7DE2FFC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE44 5 Bytes JMP B7DE304E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP B7DE3038 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11EA 5 Bytes JMP B7DE3024 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D16F4 5 Bytes JMP B7DE3062 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D2982 5 Bytes JMP B7DE3010 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 806219EC 7 Bytes JMP B7DE30F6 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80621D3A 7 Bytes JMP B7DE30E0 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80622064 7 Bytes JMP B7DE3164 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 80622916 7 Bytes JMP B7DE310C mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231EA 7 Bytes JMP B7DE30B4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806237C8 5 Bytes JMP B7DE308A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C64 7 Bytes JMP B7DE309E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623E34 7 Bytes JMP B7DE30CA mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 80624014 7 Bytes JMP B7DE3138 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8062427E 7 Bytes JMP B7DE3122 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 80624BA6 5 Bytes JMP B7DE3076 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 80624EE8 7 Bytes JMP B7DE31B6 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 806251A8 5 Bytes JMP B7DE318E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwLoadKey2 806255F8 7 Bytes JMP B7DE314E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8062589C 5 Bytes JMP B7DE31A2 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 806259B6 5 Bytes JMP B7DE317A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB4F5B380, 0x566445, 0xE8000020]
.rsrc C:\WINDOWS\system32\DRIVERS\tcpip.sys entry point in ".rsrc" section [0xB2663A94]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\wuauclt.exe[792] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0084000A
.text C:\WINDOWS\system32\wuauclt.exe[792] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0085000A
.text C:\WINDOWS\system32\wuauclt.exe[792] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003E000C
.text C:\WINDOWS\System32\svchost.exe[1176] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 007F000A
.text C:\WINDOWS\System32\svchost.exe[1176] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0080000A
.text C:\WINDOWS\System32\svchost.exe[1176] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 007E000C
.text C:\WINDOWS\System32\svchost.exe[1176] ole32.dll!CoCreateInstance 7750057E 3 Bytes JMP 00DC000A
.text C:\WINDOWS\System32\svchost.exe[1176] ole32.dll!CoCreateInstance + 4 77500582 1 Byte [89]
.text C:\WINDOWS\Explorer.EXE[1936] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A2000A
.text C:\WINDOWS\Explorer.EXE[1936] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B0000A
.text C:\WINDOWS\Explorer.EXE[1936] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A1000C

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device -> \Driver\atapi \Device\Harddisk0\DR0 89902EC5

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\DRIVERS\tcpip.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-22 20:03:23
Windows 5.1.2600 Service Pack 3
Running: s61jdtt3.exe; Driver: C:\DOCUME~1\Austin\LOCALS~1\Temp\pxryqpob.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB250F620]

Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB7DE3086]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcess [0xB7DE3020]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB7DE3034]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB7DE309A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB7DE30C6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwEnumerateKey [0xB7DE3134]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xB7DE311E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwLoadKey2 [0xB7DE314A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB7DE3176]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB7DE3072]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB7DE2FE4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB7DE2FF8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryKey [0xB7DE31B2]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB7DE3108]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryValueKey [0xB7DE30F2]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB7DE30B0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwReplaceKey [0xB7DE319E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRestoreKey [0xB7DE318A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetContextThread [0xB7DE305E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB7DE304A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB7DE30DC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB7DE300C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnloadKey [0xB7DE3160]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntkrnlpa.exe!NtOpenProcess 805CB3FA 5 Bytes JMP B7DE2FE8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB686 5 Bytes JMP B7DE2FFC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE44 5 Bytes JMP B7DE304E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP B7DE3038 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11EA 5 Bytes JMP B7DE3024 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D16F4 5 Bytes JMP B7DE3062 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D2982 5 Bytes JMP B7DE3010 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 806219EC 7 Bytes JMP B7DE30F6 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80621D3A 7 Bytes JMP B7DE30E0 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80622064 7 Bytes JMP B7DE3164 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 80622916 7 Bytes JMP B7DE310C mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231EA 7 Bytes JMP B7DE30B4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806237C8 5 Bytes JMP B7DE308A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C64 7 Bytes JMP B7DE309E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623E34 7 Bytes JMP B7DE30CA mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 80624014 7 Bytes JMP B7DE3138 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8062427E 7 Bytes JMP B7DE3122 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 80624BA6 5 Bytes JMP B7DE3076 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 80624EE8 7 Bytes JMP B7DE31B6 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 806251A8 5 Bytes JMP B7DE318E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwLoadKey2 806255F8 7 Bytes JMP B7DE314E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8062589C 5 Bytes JMP B7DE31A2 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 806259B6 5 Bytes JMP B7DE317A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB4F5B380, 0x566445, 0xE8000020]
.rsrc C:\WINDOWS\system32\DRIVERS\tcpip.sys entry point in ".rsrc" section [0xB2663A94]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\wuauclt.exe[792] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0084000A
.text C:\WINDOWS\system32\wuauclt.exe[792] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0085000A
.text C:\WINDOWS\system32\wuauclt.exe[792] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003E000C
.text C:\WINDOWS\System32\svchost.exe[1176] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 007F000A
.text C:\WINDOWS\System32\svchost.exe[1176] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0080000A
.text C:\WINDOWS\System32\svchost.exe[1176] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 007E000C
.text C:\WINDOWS\System32\svchost.exe[1176] ole32.dll!CoCreateInstance 7750057E 3 Bytes JMP 00DC000A
.text C:\WINDOWS\System32\svchost.exe[1176] ole32.dll!CoCreateInstance + 4 77500582 1 Byte [89]
.text C:\WINDOWS\Explorer.EXE[1936] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A2000A
.text C:\WINDOWS\Explorer.EXE[1936] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B0000A
.text C:\WINDOWS\Explorer.EXE[1936] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A1000C

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device -> \Driver\atapi \Device\Harddisk0\DR0 89902EC5

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\DRIVERS\tcpip.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hello,

No worries on the double post. I'll remove it in a little bit.


Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
ComboFix 10-07-22.06 - Austin 07/23/2010 11:16:51.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2869 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Austin\Application Data\.#
c:\documents and settings\Austin\Application Data\.#\MBX@514@B148E0.###
c:\documents and settings\Austin\Application Data\.#\MBX@514@B148F0.###
c:\documents and settings\Austin\Application Data\.#\MBX@98C@B148E0.###
c:\documents and settings\Austin\Application Data\.#\MBX@98C@B148F0.###
c:\documents and settings\Austin\Local Settings\Application Data\{1E4D63C9-7584-47F2-8FC6-A47AE8873100}
c:\documents and settings\Austin\Local Settings\Application Data\{1E4D63C9-7584-47F2-8FC6-A47AE8873100}\chrome.manifest
c:\documents and settings\Austin\Local Settings\Application Data\{1E4D63C9-7584-47F2-8FC6-A47AE8873100}\chrome\content\_cfg.js
c:\documents and settings\Austin\Local Settings\Application Data\{1E4D63C9-7584-47F2-8FC6-A47AE8873100}\chrome\content\overlay.xul
c:\documents and settings\Austin\Local Settings\Application Data\{1E4D63C9-7584-47F2-8FC6-A47AE8873100}\install.rdf

Infected copy of c:\windows\system32\drivers\tcpip.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.

2010-07-22 11:16 . 2010-07-22 11:16 388096 —-a-r- c:\documents and settings\Austin\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-22 11:16 . 2010-07-22 11:16 ——– d—–w- c:\program files\Trend Micro
2010-07-22 09:31 . 2010-07-22 09:31 63488 —-a-w- c:\documents and settings\Austin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-22 09:31 . 2010-07-22 09:31 52224 —-a-w- c:\documents and settings\Austin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-22 09:31 . 2010-07-22 09:31 117760 —-a-w- c:\documents and settings\Austin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-22 09:30 . 2010-07-22 09:30 ——– d—–w- c:\documents and settings\Austin\Application Data\SUPERAntiSpyware.com
2010-07-22 09:30 . 2010-07-22 09:30 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-22 09:30 . 2010-07-22 09:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-07-22 08:06 . 2010-07-22 08:06 ——– d—–w- c:\documents and settings\Austin\Application Data\Malwarebytes
2010-07-22 08:06 . 2010-04-29 23:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-22 08:06 . 2010-07-22 08:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-22 08:06 . 2010-04-29 23:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-22 08:06 . 2010-07-22 08:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-21 23:27 . 2010-07-21 23:27 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-07-21 11:50 . 2010-07-21 11:50 1824 —-a-w- C:\eg_AppID_CLSID.reg
2010-07-21 10:28 . 2010-07-21 10:28 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-21 10:27 . 2010-07-21 10:27 ——– d—–w- c:\windows\Sun
2010-07-21 10:25 . 2010-07-21 10:25 ——– d—–w- c:\documents and settings\Austin\Application Data\InstallShield
2010-07-21 10:23 . 2010-07-21 10:23 ——– d—–w- c:\program files\Common Files\Windows Live
2010-07-21 10:23 . 2010-07-21 10:23 ——– d—–w- c:\documents and settings\Austin\Local Settings\Application Data\PunkBuster
2010-07-21 09:11 . 2010-07-21 10:28 ——– d-s—w- c:\documents and settings\Austin\UserData
2010-07-21 08:26 . 2010-07-21 10:28 ——– d-s—w- c:\documents and settings\LocalService\UserData
2010-07-21 06:48 . 2010-07-21 09:53 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-21 01:17 . 2010-07-21 10:28 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-07-20 06:18 . 2010-07-22 09:27 0 —-a-w- c:\windows\Qbege.bin
2010-07-20 06:18 . 2010-07-22 07:59 120 —-a-w- c:\windows\Nzipuzimocinexi.dat
2010-07-18 10:14 . 2010-07-18 10:14 ——– d—–w- c:\program files\Java
2010-07-18 02:46 . 2010-07-18 02:46 ——– d—–w- c:\documents and settings\Austin\Local Settings\Application Data\My Games
2010-07-18 02:35 . 2010-07-18 02:35 ——– d—–w- c:\program files\2K Games
2010-07-17 09:09 . 2010-07-21 10:28 ——– d—–w- C:\Fraps
2010-07-14 03:37 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-09 18:44 . 2009-08-07 03:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-07-09 18:44 . 2009-08-07 03:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-07-09 10:32 . 2010-07-21 10:23 ——– d—–w- c:\documents and settings\Austin\Tracing
2010-07-09 01:39 . 2010-07-09 01:39 ——– d–h–r- c:\documents and settings\Austin\Application Data\SecuROM
2010-07-08 22:01 . 2010-07-19 08:37 137256 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-07-08 22:01 . 2010-07-08 22:01 138056 —-a-w- c:\documents and settings\Austin\Application Data\PnkBstrK.sys
2010-07-08 22:01 . 2010-07-19 08:37 218808 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-07-08 22:01 . 2010-07-08 22:01 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-07-08 22:01 . 2010-07-08 22:01 2434856 —-a-w- c:\windows\system32\pbsvc_bc2.exe
2010-07-08 09:07 . 2010-07-23 19:16 ——– d—–w- C:\QUARANTINE
2010-07-06 10:50 . 2009-09-05 01:44 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2010-07-06 10:50 . 2009-03-16 22:18 517448 —-a-w- c:\windows\system32\XAudio2_4.dll
2010-07-06 10:50 . 2009-03-09 23:27 4178264 —-a-w- c:\windows\system32\D3DX9_41.dll
2010-07-06 10:50 . 2009-03-16 22:18 235352 —-a-w- c:\windows\system32\xactengine3_4.dll
2010-07-06 10:50 . 2009-03-16 22:18 22360 —-a-w- c:\windows\system32\X3DAudio1_6.dll
2010-06-27 20:44 . 2010-07-10 20:02 160344 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-06-25 23:52 . 2010-06-25 23:52 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-06-25 23:52 . 2010-07-21 10:16 ——– d—–w- c:\documents and settings\Austin\Application Data\skypePM
2010-06-25 23:43 . 2010-06-25 23:43 ——– d—–w- c:\documents and settings\Austin\Local Settings\Application Data\Google
2010-06-25 23:43 . 2010-07-21 10:18 ——– d—–w- c:\documents and settings\Austin\Application Data\Skype
2010-06-25 23:43 . 2010-06-25 23:43 ——– d—–w- c:\program files\Google
2010-06-25 23:43 . 2010-06-25 23:43 ——– d—–w- c:\program files\Common Files\Skype
2010-06-25 23:43 . 2010-07-21 10:23 ——– d—–r- c:\program files\Skype
2010-06-25 23:43 . 2010-06-25 23:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 19:02 . 2010-05-23 13:14 ——– d—–w- c:\program files\Steam
2010-07-21 10:25 . 2010-05-27 05:46 ——– d—–w- c:\documents and settings\Austin\Application Data\BitTorrent
2010-07-21 10:25 . 2010-05-23 11:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-21 10:24 . 2010-05-23 11:23 ——– d—–w- c:\program files\Microsoft Works
2010-07-21 06:48 . 2010-05-23 13:18 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-21 03:36 . 2010-05-23 17:01 70024 —-a-w- c:\documents and settings\Austin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-20 10:05 . 2010-05-24 10:32 ——– d—–w- c:\program files\Graal
2010-07-20 05:26 . 2010-07-18 10:15 195072 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\OpenAL64.dll
2010-07-20 05:26 . 2010-07-18 10:15 108032 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\OpenAL32.dll
2010-07-20 05:26 . 2010-07-18 10:15 65024 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\jinput-dx8_64.dll
2010-07-20 05:26 . 2010-07-18 10:15 62464 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\jinput-raw_64.dll
2010-07-20 05:26 . 2010-07-18 10:15 61952 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\jinput-dx8.dll
2010-07-20 05:26 . 2010-07-18 10:15 59392 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\jinput-raw.dll
2010-07-20 05:26 . 2010-07-18 10:15 273920 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\lwjgl64.dll
2010-07-20 05:26 . 2010-07-18 10:15 193024 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\lwjgl.dll
2010-07-18 10:16 . 2010-07-18 10:15 ——– d—–w- c:\documents and settings\Austin\Application Data\.minecraft
2010-07-18 10:15 . 2010-07-18 10:15 503808 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5af08cb4-n\msvcp71.dll
2010-07-18 10:15 . 2010-07-18 10:15 499712 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5af08cb4-n\jmc.dll
2010-07-18 10:15 . 2010-07-18 10:15 348160 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5af08cb4-n\msvcr71.dll
2010-07-18 10:15 . 2010-07-18 10:15 61440 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4567c716-n\decora-sse.dll
2010-07-18 10:15 . 2010-07-18 10:15 12800 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4567c716-n\decora-d3d.dll
2010-07-18 10:15 . 2010-07-18 10:15 ——– d—–w- c:\program files\Common Files\Java
2010-07-18 10:15 . 2010-07-18 10:15 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-18 03:30 . 2010-05-23 10:48 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-08 21:46 . 2010-07-08 21:46 ——– d—–w- c:\program files\Electronic Arts
2010-07-06 10:30 . 2010-05-23 17:01 ——– d—–w- c:\documents and settings\Austin\Application Data\Apple Computer
2010-06-30 22:33 . 2010-06-11 00:52 ——– d—–w- c:\program files\World of Warcraft
2010-06-24 21:26 . 2010-06-11 06:34 ——– d—–w- c:\documents and settings\Austin\Application Data\Ventrilo
2010-06-22 20:08 . 2010-06-22 20:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2010-06-18 03:52 . 2010-06-18 03:42 ——– d—–w- c:\program files\Copy of Steam
2010-06-15 01:47 . 2010-06-15 01:47 86016 —-a-w- c:\windows\system32\frapsvid.dll
2010-06-14 14:31 . 2010-05-23 10:38 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-11 02:05 . 2010-06-11 02:05 ——– d—–w- c:\program files\Ventrilo
2010-06-11 01:50 . 2010-05-23 11:23 ——– d—–w- c:\program files\MSBuild
2010-06-11 01:48 . 2010-06-11 01:48 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-06-10 21:58 . 2010-05-23 16:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-06-10 21:50 . 2010-06-10 03:27 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2010-06-10 03:29 . 2010-06-10 03:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2010-06-09 08:35 . 2010-06-09 08:29 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-06-09 08:07 . 2010-06-05 08:25 1530066 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1004336348-1770027372-725345543-1004-0.dat
2010-06-09 08:07 . 2010-06-05 08:25 274490 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2010-06-05 08:35 . 2010-05-23 11:19 ——– d—–w- c:\documents and settings\Austin\Application Data\ESTsoft
2010-06-05 08:23 . 2010-06-04 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Estsoft
2010-06-05 08:06 . 2010-06-05 08:06 ——– d—–w- c:\documents and settings\Austin\Application Data\Microsoft Corporation
2010-06-05 07:49 . 2010-06-05 07:49 ——– d—–w- c:\program files\Microsoft Synchronization Services
2010-06-05 07:49 . 2010-06-05 07:49 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2010-06-05 07:49 . 2010-06-05 07:49 112832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
2010-06-05 07:48 . 2010-06-05 07:47 ——– d—–w- c:\program files\Microsoft Visual Studio 10.0
2010-06-05 07:47 . 2010-06-05 07:34 ——– d—–w- c:\program files\Microsoft.NET
2010-06-05 07:47 . 2010-06-05 07:47 ——– d—–w- c:\program files\Microsoft SDKs
2010-06-05 07:47 . 2010-06-05 07:47 ——– d—–w- c:\program files\Microsoft Help Viewer
2010-06-05 07:47 . 2010-06-05 07:47 ——– d—–w- c:\program files\Common Files\Merge Modules
2010-06-05 07:46 . 2010-06-05 07:46 ——– d—–w- c:\program files\Reference Assemblies
2010-06-04 11:11 . 2010-06-04 11:10 ——– d—–w- c:\program files\AutoHotkey
2010-06-04 10:28 . 2010-06-04 10:21 ——– d—–w- c:\documents and settings\All Users\Application Data\KeyText
2010-06-04 10:22 . 2010-06-04 10:21 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-27 05:46 . 2010-05-27 05:46 ——– d—–w- c:\program files\BitTorrent
2010-05-27 02:36 . 2010-05-27 02:36 ——– d—–w- c:\program files\Microsoft IntelliType Pro
2010-05-24 10:29 . 2010-05-24 10:28 38784 —-a-w- c:\documents and settings\Austin\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-05-23 11:08 . 2010-05-23 10:40 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-23 10:59 . 2010-05-23 10:59 0 —-a-w- c:\windows\nsreg.dat
2010-05-23 10:38 . 2010-05-23 10:38 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-05-02 05:22 . 2004-08-04 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-28 23:45 . 2010-04-28 23:45 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2008-09-29 16:07 . 2010-05-23 11:11 22576 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
"Steam"="c:\program files\steam\steam.exe" [2010-06-18 1238352]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-19 2403568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-26 18081280]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2008-03-14 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-04 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-04 13670504]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-11-12 1505144]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-12 1468256]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\Austin\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-5-23 576000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [9/29/2008 8:07 AM 19456]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [5/23/2010 3:11 AM 67904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [5/23/2010 3:11 AM 64432]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder

2010-07-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 19:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Austin\Application Data\Mozilla\Firefox\Profiles\9pm2ppcc.default\
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKLM-Run-nwiz - nwiz.exe
HKLM-Run-Udenifu - c:\windows\opixenibek.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-23 11:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1004336348-1770027372-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:44,59,45,9f,9f,53,37,df,91,db,ce,fb,e8,c6,76,cf,a2,35,4e,9e,7f,
9d,14,23,dd,0e,1f,62,ba,3e,d8,d1,e3,7b,ba,1f,3d,28,5f,c5,ec,13,c5,66,42,fa,\
"rkeysecu"=hex:22,f1,85,b5,92,23,a8,60,91,60,7d,77,cb,75,32,bf
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(840)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2010-07-23 11:27:01
ComboFix-quarantined-files.txt 2010-07-23 19:26

Pre-Run: 389,331,365,888 bytes free
Post-Run: 390,310,060,032 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - AE9E80547B849D4D1B5763AEB6EDB112



hmmm.. my computer seems to be running at full speed again.. im not entirely sure though. is there a way to test?
Hello,

A way to test is to do a quick google search and see if you are being redirected.

ComboFix Script
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=113409&view=findpost&p=669572
KillAll::
Collect::
c:\windows\Qbege.bin
c:\windows\Nzipuzimocinexi.dat

Suspect::[100]
C:\eg_AppID_CLSID.reg
c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1004336348-1770027372-725345543-1004-0.dat
c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. If ComboFix prompts you to update to the newest version, please allow it to do so. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT:



Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
I just want to thank you so much, i would have never been able to fix my computer without you. :) thank you again!!!! sooo much!

this is the log.

ComboFix 10-07-22.06 - Austin 07/23/2010 11:46:11.2.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2680 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Austin\Desktop\CFScript.txt
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}

file zipped: c:\windows\Nzipuzimocinexi.dat
file zipped: c:\windows\Qbege.bin
file zipped: c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1004336348-1770027372-725345543-1004-0.dat
file zipped: c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
file zipped: C:\eg_AppID_CLSID.reg
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Nzipuzimocinexi.dat
c:\windows\Qbege.bin

.
((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.

2010-07-22 11:16 . 2010-07-22 11:16 388096 —-a-r- c:\documents and settings\Austin\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-22 11:16 . 2010-07-22 11:16 ——– d—–w- c:\program files\Trend Micro
2010-07-22 09:31 . 2010-07-22 09:31 63488 —-a-w- c:\documents and settings\Austin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-22 09:31 . 2010-07-22 09:31 52224 —-a-w- c:\documents and settings\Austin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-22 09:31 . 2010-07-22 09:31 117760 —-a-w- c:\documents and settings\Austin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-22 09:30 . 2010-07-22 09:30 ——– d—–w- c:\documents and settings\Austin\Application Data\SUPERAntiSpyware.com
2010-07-22 09:30 . 2010-07-22 09:30 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-22 09:30 . 2010-07-22 09:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-07-22 08:06 . 2010-07-22 08:06 ——– d—–w- c:\documents and settings\Austin\Application Data\Malwarebytes
2010-07-22 08:06 . 2010-04-29 23:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-22 08:06 . 2010-07-22 08:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-22 08:06 . 2010-04-29 23:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-22 08:06 . 2010-07-22 08:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-21 23:27 . 2010-07-21 23:27 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-07-21 11:50 . 2010-07-21 11:50 1824 —-a-w- C:\eg_AppID_CLSID.reg
2010-07-21 10:28 . 2010-07-21 10:28 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-21 10:27 . 2010-07-21 10:27 ——– d—–w- c:\windows\Sun
2010-07-21 10:25 . 2010-07-21 10:25 ——– d—–w- c:\documents and settings\Austin\Application Data\InstallShield
2010-07-21 10:23 . 2010-07-21 10:23 ——– d—–w- c:\program files\Common Files\Windows Live
2010-07-21 10:23 . 2010-07-21 10:23 ——– d—–w- c:\documents and settings\Austin\Local Settings\Application Data\PunkBuster
2010-07-21 09:11 . 2010-07-21 10:28 ——– d-s—w- c:\documents and settings\Austin\UserData
2010-07-21 08:26 . 2010-07-21 10:28 ——– d-s—w- c:\documents and settings\LocalService\UserData
2010-07-21 06:48 . 2010-07-21 09:53 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-21 01:17 . 2010-07-21 10:28 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-07-18 10:14 . 2010-07-18 10:14 ——– d—–w- c:\program files\Java
2010-07-18 02:46 . 2010-07-18 02:46 ——– d—–w- c:\documents and settings\Austin\Local Settings\Application Data\My Games
2010-07-18 02:35 . 2010-07-18 02:35 ——– d—–w- c:\program files\2K Games
2010-07-17 09:09 . 2010-07-21 10:28 ——– d—–w- C:\Fraps
2010-07-14 03:37 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-09 18:44 . 2009-08-07 03:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-07-09 18:44 . 2009-08-07 03:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-07-09 10:32 . 2010-07-21 10:23 ——– d—–w- c:\documents and settings\Austin\Tracing
2010-07-09 01:39 . 2010-07-09 01:39 ——– d–h–r- c:\documents and settings\Austin\Application Data\SecuROM
2010-07-08 22:01 . 2010-07-19 08:37 137256 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-07-08 22:01 . 2010-07-08 22:01 138056 —-a-w- c:\documents and settings\Austin\Application Data\PnkBstrK.sys
2010-07-08 22:01 . 2010-07-19 08:37 218808 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-07-08 22:01 . 2010-07-08 22:01 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-07-08 22:01 . 2010-07-08 22:01 2434856 —-a-w- c:\windows\system32\pbsvc_bc2.exe
2010-07-08 09:07 . 2010-07-23 19:16 ——– d—–w- C:\QUARANTINE
2010-07-06 10:50 . 2009-09-05 01:44 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2010-07-06 10:50 . 2009-03-16 22:18 517448 —-a-w- c:\windows\system32\XAudio2_4.dll
2010-07-06 10:50 . 2009-03-09 23:27 4178264 —-a-w- c:\windows\system32\D3DX9_41.dll
2010-07-06 10:50 . 2009-03-16 22:18 235352 —-a-w- c:\windows\system32\xactengine3_4.dll
2010-07-06 10:50 . 2009-03-16 22:18 22360 —-a-w- c:\windows\system32\X3DAudio1_6.dll
2010-06-27 20:44 . 2010-07-10 20:02 160344 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-06-25 23:52 . 2010-06-25 23:52 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-06-25 23:52 . 2010-07-21 10:16 ——– d—–w- c:\documents and settings\Austin\Application Data\skypePM
2010-06-25 23:43 . 2010-06-25 23:43 ——– d—–w- c:\documents and settings\Austin\Local Settings\Application Data\Google
2010-06-25 23:43 . 2010-07-21 10:18 ——– d—–w- c:\documents and settings\Austin\Application Data\Skype
2010-06-25 23:43 . 2010-06-25 23:43 ——– d—–w- c:\program files\Google
2010-06-25 23:43 . 2010-06-25 23:43 ——– d—–w- c:\program files\Common Files\Skype
2010-06-25 23:43 . 2010-07-21 10:23 ——– d—–r- c:\program files\Skype
2010-06-25 23:43 . 2010-06-25 23:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 19:49 . 2010-05-23 13:14 ——– d—–w- c:\program files\Steam
2010-07-21 10:25 . 2010-05-27 05:46 ——– d—–w- c:\documents and settings\Austin\Application Data\BitTorrent
2010-07-21 10:25 . 2010-05-23 11:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-21 10:24 . 2010-05-23 11:23 ——– d—–w- c:\program files\Microsoft Works
2010-07-21 06:48 . 2010-05-23 13:18 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-21 03:36 . 2010-05-23 17:01 70024 —-a-w- c:\documents and settings\Austin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-20 10:05 . 2010-05-24 10:32 ——– d—–w- c:\program files\Graal
2010-07-20 05:26 . 2010-07-18 10:15 195072 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\OpenAL64.dll
2010-07-20 05:26 . 2010-07-18 10:15 108032 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\OpenAL32.dll
2010-07-20 05:26 . 2010-07-18 10:15 65024 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\jinput-dx8_64.dll
2010-07-20 05:26 . 2010-07-18 10:15 62464 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\jinput-raw_64.dll
2010-07-20 05:26 . 2010-07-18 10:15 61952 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\jinput-dx8.dll
2010-07-20 05:26 . 2010-07-18 10:15 59392 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\jinput-raw.dll
2010-07-20 05:26 . 2010-07-18 10:15 273920 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\lwjgl64.dll
2010-07-20 05:26 . 2010-07-18 10:15 193024 —-a-w- c:\documents and settings\Austin\Application Data\.minecraft\bin\natives\lwjgl.dll
2010-07-18 10:16 . 2010-07-18 10:15 ——– d—–w- c:\documents and settings\Austin\Application Data\.minecraft
2010-07-18 10:15 . 2010-07-18 10:15 503808 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5af08cb4-n\msvcp71.dll
2010-07-18 10:15 . 2010-07-18 10:15 499712 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5af08cb4-n\jmc.dll
2010-07-18 10:15 . 2010-07-18 10:15 348160 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5af08cb4-n\msvcr71.dll
2010-07-18 10:15 . 2010-07-18 10:15 61440 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4567c716-n\decora-sse.dll
2010-07-18 10:15 . 2010-07-18 10:15 12800 —-a-w- c:\documents and settings\Austin\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4567c716-n\decora-d3d.dll
2010-07-18 10:15 . 2010-07-18 10:15 ——– d—–w- c:\program files\Common Files\Java
2010-07-18 10:15 . 2010-07-18 10:15 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-18 03:30 . 2010-05-23 10:48 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-08 21:46 . 2010-07-08 21:46 ——– d—–w- c:\program files\Electronic Arts
2010-07-06 10:30 . 2010-05-23 17:01 ——– d—–w- c:\documents and settings\Austin\Application Data\Apple Computer
2010-06-30 22:33 . 2010-06-11 00:52 ——– d—–w- c:\program files\World of Warcraft
2010-06-24 21:26 . 2010-06-11 06:34 ——– d—–w- c:\documents and settings\Austin\Application Data\Ventrilo
2010-06-22 20:08 . 2010-06-22 20:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2010-06-18 03:52 . 2010-06-18 03:42 ——– d—–w- c:\program files\Copy of Steam
2010-06-15 01:47 . 2010-06-15 01:47 86016 —-a-w- c:\windows\system32\frapsvid.dll
2010-06-14 14:31 . 2010-05-23 10:38 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-11 02:05 . 2010-06-11 02:05 ——– d—–w- c:\program files\Ventrilo
2010-06-11 01:50 . 2010-05-23 11:23 ——– d—–w- c:\program files\MSBuild
2010-06-11 01:48 . 2010-06-11 01:48 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-06-10 21:58 . 2010-05-23 16:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-06-10 21:50 . 2010-06-10 03:27 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2010-06-10 03:29 . 2010-06-10 03:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2010-06-09 08:35 . 2010-06-09 08:29 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-06-09 08:07 . 2010-06-05 08:25 1530066 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1004336348-1770027372-725345543-1004-0.dat
2010-06-09 08:07 . 2010-06-05 08:25 274490 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2010-06-05 08:35 . 2010-05-23 11:19 ——– d—–w- c:\documents and settings\Austin\Application Data\ESTsoft
2010-06-05 08:23 . 2010-06-04 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Estsoft
2010-06-05 08:06 . 2010-06-05 08:06 ——– d—–w- c:\documents and settings\Austin\Application Data\Microsoft Corporation
2010-06-05 07:49 . 2010-06-05 07:49 ——– d—–w- c:\program files\Microsoft Synchronization Services
2010-06-05 07:49 . 2010-06-05 07:49 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2010-06-05 07:49 . 2010-06-05 07:49 112832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
2010-06-05 07:48 . 2010-06-05 07:47 ——– d—–w- c:\program files\Microsoft Visual Studio 10.0
2010-06-05 07:47 . 2010-06-05 07:34 ——– d—–w- c:\program files\Microsoft.NET
2010-06-05 07:47 . 2010-06-05 07:47 ——– d—–w- c:\program files\Microsoft SDKs
2010-06-05 07:47 . 2010-06-05 07:47 ——– d—–w- c:\program files\Microsoft Help Viewer
2010-06-05 07:47 . 2010-06-05 07:47 ——– d—–w- c:\program files\Common Files\Merge Modules
2010-06-05 07:46 . 2010-06-05 07:46 ——– d—–w- c:\program files\Reference Assemblies
2010-06-04 11:11 . 2010-06-04 11:10 ——– d—–w- c:\program files\AutoHotkey
2010-06-04 10:28 . 2010-06-04 10:21 ——– d—–w- c:\documents and settings\All Users\Application Data\KeyText
2010-06-04 10:22 . 2010-06-04 10:21 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-27 05:46 . 2010-05-27 05:46 ——– d—–w- c:\program files\BitTorrent
2010-05-27 02:36 . 2010-05-27 02:36 ——– d—–w- c:\program files\Microsoft IntelliType Pro
2010-05-24 10:29 . 2010-05-24 10:28 38784 —-a-w- c:\documents and settings\Austin\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-05-23 11:08 . 2010-05-23 10:40 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-23 10:59 . 2010-05-23 10:59 0 —-a-w- c:\windows\nsreg.dat
2010-05-23 10:38 . 2010-05-23 10:38 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-05-02 05:22 . 2004-08-04 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-28 23:45 . 2010-04-28 23:45 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2008-09-29 16:07 . 2010-05-23 11:11 22576 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-07-23_19.25.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-23 19:49 . 2010-07-23 19:49 16384 c:\windows\temp\Perflib_Perfdata_444.dat
+ 2004-08-04 12:00 . 2010-07-23 19:28 86310 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2010-07-23 19:28 501370 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
"Steam"="c:\program files\steam\steam.exe" [2010-06-18 1238352]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-19 2403568]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-26 18081280]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2008-03-14 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-04 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-04 13670504]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-11-12 1505144]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-12 1468256]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\Austin\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-5-23 576000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [9/29/2008 8:07 AM 19456]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [5/23/2010 3:11 AM 67904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [5/23/2010 3:11 AM 64432]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder

2010-07-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 19:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Austin\Application Data\Mozilla\Firefox\Profiles\9pm2ppcc.default\
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-23 11:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1004336348-1770027372-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:44,59,45,9f,9f,53,37,df,91,db,ce,fb,e8,c6,76,cf,a2,35,4e,9e,7f,
9d,14,23,dd,0e,1f,62,ba,3e,d8,d1,e3,7b,ba,1f,3d,28,5f,c5,ec,13,c5,66,42,fa,\
"rkeysecu"=hex:22,f1,85,b5,92,23,a8,60,91,60,7d,77,cb,75,32,bf
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(844)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL

- - - - - - - > 'explorer.exe'(1660)
c:\windows\system32\msi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Microsoft IntelliType Pro\dpupdchk.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-23 11:55:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-23 19:55
ComboFix2.txt 2010-07-23 19:27

Pre-Run: 390,295,134,208 bytes free
Post-Run: 390,280,486,912 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - DA0B5DE06F6172D51E493E9084505B8B
annnnd here's the malware scanner's log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4342 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 7/23/2010 12:02:47 PM mbam-log-2010-07-23 (12-02-47).txt Scan type: Quick scan Objects scanned: 127065 Time elapsed: 4 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI