This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32: Malware-gen

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

XP servicepack 3, IE8.

"Explorer.exe" and "generic host process" are shut down, sometimes Windows "code execution protection" (not sure of exact name, but something like it) comes first.

Avast realtime protection shuts down all the time.
Avast quarentined several files with reference to "Win32:Malware-gen", they are quarantined but just appear again in some other file.

Safetyscanner at onecare.live.com finds several problems, but hangs before results are shown.

spybot s&d found some cookies, nothing more.

One or two trojans blocked by avast. (IE tried to open new tab)

Hijackthis logfile below, thanks in advance for any help.

/Henrik

******************************************************************

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:56:54, on 2010-07-30
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program\Bonjour\mDNSResponder.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program\Delade filer\Java\Java Update\jusched.exe
C:\Program\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program\Dell\Media Experience\DMXLauncher.exe
C:\Program\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe
C:\Program\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program\iTunes\iTunesHelper.exe
C:\Program\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Spybot 162\TeaTimer.exe
C:\Program\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Program\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\Spybot 162\SDHelper.dll
O2 - BHO: (no name) - {A37FFAEE-584B-48DE-BDAB-A9BC9ABBE7F3} - c:\windows\system32\zuotsxo.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Delade filer\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program\Delade filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DMXLauncher] C:\Program\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MimBoot] C:\Program\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast5] C:\Program\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot 162\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: ymetray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\Spybot 162\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\Spybot 162\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/…trolLite_EN.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6087.cab
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://danverk.dyndns.org/Remote/msrdp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe

–
End of file - 8013 bytes
Hello there, XaPh

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
jotti.org
VirScan
Virus Total

click on Browse, and upload the following file for analysis:
c:\windows\system32\zuotsxo.dll

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

===================================================

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
File scanner report
OTL log
GMER log
Tell me what are the file directories of the quarantined files in Avast

Good Day!
Hello Conspire,

thanks a lot for helping out!

Before your first post I swept the computer once more with Avast bootscan and also Malwarebytes. Both found some things that were cleaned.
I'm sorry if this messes up something for you. A good thing though that after that Avast realtime does not close, and "Explorer.exe" and "Generic host process" does not crash. Avast has after that blocked IE when it spontaneously tried to open some strange pages. I have also uninstalled everything related to Java in control panel, and then installed latest version. Again, sorry if thes messes up your scheme…

Avast "Chest" seem to be located at:
C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\chest
The actual files are not shown in an ordinary way here, but the number of objects correspond to the number of objects when looking at the quarantine from within Avast.

The file "c:\windows\system32\zuotsxo.dll" is not there anymore, I think that was quarantined and deleted by Avast (When I got that running) well before my first post. Avast said that file was infected with "Win32:Malware-gen".

When I did the otl-scan Avast suddenly found a lot of things, maybe I should have disabled the realtime-protection.
I'll try and post pictures of the chest before and after the otl-scan.

Gmer hanged several times, after disabling realtime protection it worked.

Below logs from Malwarebytes and hopefulle pictures from Avast chest, no 1 before otl-scan, no 2 after.

While writing this Avast is blocking more things. Avast seem to be unable to move theese to the chest, and the Avast log says:

2010-08-01 11:29:59 C:\Documents and Settings\NetworkService\Lokala inställningar\Temporary Internet Files\Content.IE5\8EW2ZAMU\exemple[1].htm [L] HTML:Downloader-F [Trj] (0)
Ett fel uppstod vid flyttning till karantän: Det går inte att komma åt filen eftersom den
Ett fel uppstod vid radering av fil: Det går inte att komma åt filen eftersom den
2010-08-01 11:30:16 C:\Documents and Settings\NetworkService\Lokala inställningar\Temporary Internet Files\Content.IE5\8EW2ZAMU\ff2b1d[1].pdf [L] JS:Pdfka-AFJ [Expl] (0)
Ett fel uppstod vid flyttning till karantän: Det går inte att komma åt filen eftersom den
Ett fel uppstod vid radering av fil: Det går inte att komma åt filen eftersom den

The above in English would be something like "Could not move to chest" and "Could not delete" but the explanation is truncated, it says "Cannot get hold of file because" but gives no reason.

Gmer och otl-logs in coming posts. 2 logfiles from Malwarebytes and a fresh hijackthis-log below.

Please notice - I am going away for several days in just a couple of hours. (Maybe even the hole week, out boating, with no internet)

Again - thanks a bunch for helping out!!!

Best regards / Henrik

*************************************
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Databasversion: 4371

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2010-07-30 21:22:55
mbam-log-2010-07-30 (21-22-55).txt

Skanningstyp: Snabbskanning
Antal skannade objekt: 139647
Förfluten tid: 5 minut(er), 32 sekund(er)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 0
Infekterade registervärden: 0
Infekterade registerdataposter: 1
Infekterade mappar: 0
Infekterade filer: 1

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
(Inga illasinnade poster hittades)

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
*******************************************************

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Databasversion: 4371

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2010-07-30 22:35:57
mbam-log-2010-07-30 (22-35-57).txt

Skanningstyp: Fullständig skanning (C:\|)
Antal skannade objekt: 196266
Förfluten tid: 38 minut(er), 4 sekund(er)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 0
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 1

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
(Inga illasinnade poster hittades)

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:\WINDOWS\Fonts\qLmnn.com (Malware.Generic) -> Quarantined and deleted successfully.
**********************************************
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:51:04, on 2010-08-01
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program\Bonjour\mDNSResponder.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\Program\Adobe\Acrobat 5.0\Acrobat\Acrobat.exe
C:\Program\Delade filer\Adobe\Web\AOM.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program\Internet Explorer\iexplore.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/ig?hl=sv
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\Spybot 162\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [avast5] C:\Program\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\Spybot 162\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\Spybot 162\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: *.pandasoftware.com
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/…trolLite_EN.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6087.cab
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://danverk.dyndns.org/Remote/msrdp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe

–
End of file - 6398 bytes
PART 1 - OTL
*****************
OTL logfile created on: 2010-07-31 19:33:15 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\helu\Skrivbord
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

1 014,00 Mb Total Physical Memory | 600,00 Mb Available Physical Memory | 59,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program
Drive C: | 146,22 Gb Total Space | 11,35 Gb Free Space | 7,76% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 372,61 Gb Total Space | 3,21 Gb Free Space | 0,86% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VIDSTIGE
Current User Name: helu
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\helu\Skrivbord\OTL.exe (OldTimer Tools)
PRC - C:\Program\Delade filer\Java\Java Update\jusched.exe ()
PRC - C:\Program\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program\iTunes\iTunesHelper .exe (Apple Inc.)
PRC - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
PRC - C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program\Delade filer\Acronis\Schedule2\schedhlp .exe (Acronis)
PRC - C:\Program\Musicmatch\Musicmatch Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program\Musicmatch\Musicmatch Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program\Dell\Media Experience\DMXLauncher .exe ()
PRC - C:\Program\CyberLink\PowerDVD\DVDLauncher .exe (CyberLink Corp.)
PRC - C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program\Adobe\Acrobat 5.0\Distillr\AcroTray.exe (Adobe Systems Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\helu\Skrivbord\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (avast! Web Scanner) – C:\Program\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (Apple Mobile Device) – C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AcrSch2Svc) – C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (IDriverT) – C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ose) – C:\Program\Delade filer\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) – C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (ATMsrvc) – C:\WINDOWS\SYSTEM32\ATMsrvc.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV - (PavSRK.sys) – C:\WINDOWS\System32\PavSRK.sys File not found
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (GcKernel) – C:\WINDOWS\SYSTEM32\DRIVERS\gckernel.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\SYSTEM32\DRIVERS\tifsfilt.sys (Acronis)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (senfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (HIDSwvd) – C:\WINDOWS\SYSTEM32\DRIVERS\HIDSwvd.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/ig?hl=sv
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2004-08-04 13:00:00 | 000,000,710 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\Spybot 162\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe File not found
O4 - HKLM..\Run: [avast5] C:\Program\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DMXLauncher] C:\Program\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [DVDLauncher] C:\Program\CyberLink\PowerDVD\DVDLauncher.exe File not found
O4 - HKLM..\Run: [iTunesHelper] C:\Program\iTunes\iTunesHelper.exe File not found
O4 - HKLM..\Run: [Media Codec Update Service] C:\Program\Essentials Codec Pack\update.exe File not found
O4 - HKLM..\Run: [MimBoot] C:\Program\Musicmatch\Musicmatch Jukebox\mimboot.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\SYSTEM32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [QuickTime Task] C:\Program\QuickTime\qttask .exe File not found
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [MSMSGS] C:\Program\Messenger\msmsgs.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start-meny\Program\Autostart\Acrobat Assistant.lnk = C:\Program\Adobe\Acrobat 5.0\Distillr\AcroTray.exe (Adobe Systems Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\Spybot 162\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKCU\..Trusted Domains: pandasoftware.com ([]* in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://downloadcenter.samsung.com/content/…trolLite_EN.cab (DjVuCtl Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} https://danverk.dyndns.org/Remote/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program\Delade filer\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program\Delade filer\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program\Delade filer\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program\Delade filer\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Min aktuella startsida) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Sommar.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Sommar.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004-09-16 10:55:54 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4c7cf221-39cd-11df-8e62-00123f362fc3}\Shell\AutoRun\command - "" = F:\hbcd\wintools\autorun.exe – File not found
O33 - MountPoints2\{4c7cf221-39cd-11df-8e62-00123f362fc3}\Shell\Option1\Command - "" = F:\hbcd\wintools\autorun.exe – File not found
O33 - MountPoints2\{833d74ee-d1ed-11d9-a2f0-00123f362fc3}\Shell\AutoRun\command - "" = G:\hbcd\wintools\autorun.exe – File not found
O33 - MountPoints2\{833d74ee-d1ed-11d9-a2f0-00123f362fc3}\Shell\Option1\Command - "" = G:\hbcd\wintools\autorun.exe – File not found
O33 - MountPoints2\{97a2b47a-c4d8-11de-8e4b-00123f362fc3}\Shell\AutoRun\command - "" = G:\hbcd\wintools\autorun.exe – File not found
O33 - MountPoints2\{97a2b47a-c4d8-11de-8e4b-00123f362fc3}\Shell\Option1\Command - "" = G:\hbcd\wintools\autorun.exe – File not found
O33 - MountPoints2\{de7fda36-0d0c-11df-8e56-00123f362fc3}\Shell\AutoRun\command - "" = F:\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk /r \??\G:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (aswBoot.exe /M:27ae2712ba08) - C:\WINDOWS\System32\aswBoot.exe (AVAST Software)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: cidfeahf - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\MSG711.ACM (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\MSG723.ACM (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\MSGSM32.ACM (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\MSACM32.DRV (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - ffdshow.ax File not found
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Part 2 OTL
**************

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (70663829905735680)

========== Files/Folders - Created Within 30 Days ==========

[2010-07-31 19:27:29 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\helu\Skrivbord\OTL.exe
[2010-07-30 22:56:32 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010-07-30 22:56:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010-07-30 22:56:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010-07-30 22:56:32 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010-07-30 22:48:51 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010-07-30 21:15:30 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-07-30 21:15:29 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010-07-30 21:15:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010-07-30 21:15:28 | 000,000,000 | —D | C] – C:\Program\Malwarebytes' Anti-Malware
[2010-07-30 12:03:49 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010-07-30 12:03:48 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010-07-29 17:57:36 | 000,000,000 | —D | C] – C:\Program\Trend Micro
[2010-07-29 16:44:54 | 000,000,000 | —D | C] – C:\Program\Spybot 162
[2010-07-28 13:22:47 | 000,000,000 | —D | C] – C:\Program\TeaTimer (Spybot - Search & Destroy)
[2010-07-28 13:22:47 | 000,000,000 | —D | C] – C:\Program\SDHelper (Spybot - Search & Destroy)
[2010-07-28 13:18:32 | 000,165,456 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010-07-28 13:18:32 | 000,017,744 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010-07-28 13:18:31 | 000,023,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010-07-28 13:18:30 | 000,046,672 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010-07-28 13:18:29 | 000,100,176 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010-07-28 13:18:29 | 000,094,544 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010-07-28 13:18:29 | 000,028,880 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010-07-28 13:18:12 | 000,165,032 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010-07-28 13:18:12 | 000,038,848 | —- | C] (ALWIL Software) – C:\WINDOWS\avastSS.scr
[2010-07-28 12:54:20 | 000,043,008 | —- | C] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\drivers\ydialibe.sys
[2010-07-27 23:43:19 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010-07-27 23:21:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010-07-27 23:09:08 | 000,000,000 | -HSD | C] – C:\Documents and Settings\helu\IECompatCache
[2010-07-27 23:08:48 | 000,000,000 | -HSD | C] – C:\Documents and Settings\helu\PrivacIE
[2010-07-27 22:58:35 | 000,000,000 | -HSD | C] – C:\Documents and Settings\helu\IETldCache
[2010-07-27 22:51:34 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010-07-27 22:51:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2010-07-27 22:39:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010-07-27 22:37:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010-07-27 22:36:50 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010-07-27 22:15:42 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MpEngineStore
[2010-07-27 21:56:16 | 000,000,000 | —D | C] – C:\Documents and Settings\helu\Application Data\5D999A2E3B0D33633D0DE059A6BB8598
[2010-07-27 21:38:25 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2004-11-24 21:25:52 | 000,335,872 | —- | C] ( ) – C:\WINDOWS\System32\drvc.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010-07-31 19:27:31 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\helu\Skrivbord\OTL.exe
[2010-07-31 19:23:33 | 000,107,028 | —- | M] () – C:\Documents and Settings\helu\Skrivbord\avast-quarantine.jpg
[2010-07-31 18:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2010-07-31 17:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2010-07-31 17:00:12 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{39C1EB2E-5972-44CA-A1D9-98BA8BDCEA3D}.job
[2010-07-31 16:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2010-07-31 15:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2010-07-31 14:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2010-07-31 13:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2010-07-31 12:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2010-07-31 11:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2010-07-31 10:51:25 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\TWoNVCNEv.dat
[2010-07-31 10:50:46 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010-07-31 10:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2010-07-31 10:46:24 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010-07-31 10:46:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010-07-31 09:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2010-07-31 08:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2010-07-31 07:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2010-07-31 06:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2010-07-31 05:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2010-07-31 04:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2010-07-31 03:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2010-07-31 02:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2010-07-31 01:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2010-07-31 00:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010-07-30 23:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2010-07-30 22:56:15 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010-07-30 22:56:14 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010-07-30 22:56:14 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010-07-30 22:56:14 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010-07-30 22:56:14 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010-07-30 22:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2010-07-30 22:44:36 | 000,000,023 | —- | M] () – C:\WINDOWS\KA.INI
[2010-07-30 21:47:39 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2010-07-30 21:47:39 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2010-07-30 21:47:39 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2010-07-30 21:15:33 | 000,000,664 | —- | M] () – C:\Documents and Settings\All Users\Skrivbord\Malwarebytes' Anti-Malware.lnk
[2010-07-30 00:07:34 | 008,388,608 | -H– | M] () – C:\Documents and Settings\helu\ntuser.dat
[2010-07-30 00:07:34 | 000,000,304 | -HS- | M] () – C:\Documents and Settings\helu\NTUSER.INI
[2010-07-28 13:18:32 | 000,001,644 | —- | M] () – C:\Documents and Settings\All Users\Skrivbord\avast! Free Antivirus.lnk
[2010-07-28 13:18:29 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010-07-28 12:54:20 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\drivers\ydialibe.sys
[2010-07-27 23:05:13 | 000,000,783 | —- | M] () – C:\Documents and Settings\helu\Application Data\Microsoft\Internet Explorer\Quick Launch\Starta webbläsaren Internet Explorer.lnk
[2010-07-27 22:53:18 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010-07-27 22:53:17 | 000,000,861 | —- | M] () – C:\WINDOWS\System32\spupdsvc.inf
[2010-07-27 22:47:27 | 000,000,174 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[2010-07-27 22:39:35 | 054,835,272 | —- | M] () – C:\Documents and Settings\helu\Skrivbord\setup_av_free.exe
[2010-07-07 13:02:05 | 000,000,272 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010-07-31 19:23:33 | 000,107,028 | —- | C] () – C:\Documents and Settings\helu\Skrivbord\avast-quarantine.jpg
[2010-07-30 21:49:02 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TWoNVCNEv.dat
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At9.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At8.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At7.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At6.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At5.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At24.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At23.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At22.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At21.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At20.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At19.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At18.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At17.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At16.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At15.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At14.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At13.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At12.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At11.job
[2010-07-30 21:47:39 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At10.job
[2010-07-30 21:47:38 | 000,000,336 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2010-07-30 21:15:33 | 000,000,664 | —- | C] () – C:\Documents and Settings\All Users\Skrivbord\Malwarebytes' Anti-Malware.lnk
[2010-07-28 13:18:32 | 000,001,644 | —- | C] () – C:\Documents and Settings\All Users\Skrivbord\avast! Free Antivirus.lnk
[2010-07-27 23:40:19 | 000,003,088 | —- | C] () – C:\Documents and Settings\helu\Lokala inställningar\Application Data\A37FFAEE-584B-48DE-BDAB-A9BC9ABBE7F3.txt
[2010-07-27 23:40:06 | 000,002,670 | —- | C] () – C:\Documents and Settings\NetworkService\Lokala inställningar\Application Data\A37FFAEE-584B-48DE-BDAB-A9BC9ABBE7F3.txt
[2010-07-27 23:09:06 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{39C1EB2E-5972-44CA-A1D9-98BA8BDCEA3D}.job
[2010-07-27 22:53:17 | 000,000,861 | —- | C] () – C:\WINDOWS\System32\spupdsvc.inf
[2010-07-27 22:47:27 | 000,000,174 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010-07-27 22:39:36 | 054,835,272 | —- | C] () – C:\Documents and Settings\helu\Skrivbord\setup_av_free.exe
[2008-06-17 00:20:59 | 000,006,850 | R— | C] () – C:\WINDOWS\Disktool.INI
[2008-06-17 00:20:59 | 000,006,057 | R— | C] () – C:\WINDOWS\fwupgrade.ini
[2008-06-17 00:20:59 | 000,003,677 | R— | C] () – C:\WINDOWS\PlaySnd.INI
[2007-03-05 13:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006-12-15 18:42:46 | 000,000,038 | —- | C] () – C:\WINDOWS\AviSplitter.INI
[2006-08-17 22:27:43 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2006-08-17 22:27:41 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\adistres.dll
[2005-10-12 18:41:26 | 000,000,023 | —- | C] () – C:\WINDOWS\KA.INI
[2005-06-04 00:14:24 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005-05-31 20:40:19 | 000,000,385 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005-05-18 23:56:13 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005-05-18 23:49:54 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005-05-18 23:17:26 | 000,000,394 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005-01-28 09:08:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004-09-16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004-09-16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004-08-04 13:00:00 | 000,003,529 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2003-01-07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
Part 3 OTL
*************

========== LOP Check ==========

[2006-07-30 15:37:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2010-07-28 13:11:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010-07-30 22:49:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2008-10-30 20:02:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2005-06-03 21:59:02 | 000,000,000 | —D | M] – C:\Documents and Settings\helu\Application Data\.BitTornado
[2010-07-27 22:25:27 | 000,000,000 | —D | M] – C:\Documents and Settings\helu\Application Data\5D999A2E3B0D33633D0DE059A6BB8598
[2006-08-15 23:07:46 | 000,000,000 | —D | M] – C:\Documents and Settings\helu\Application Data\Allume Systems
[2006-08-17 22:26:16 | 000,000,000 | —D | M] – C:\Documents and Settings\helu\Application Data\InterTrust
[2006-07-30 15:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\helu\Application Data\IsolatedStorage
[2005-05-31 18:12:44 | 000,000,000 | —D | M] – C:\Documents and Settings\helu\Application Data\Leadertech
[2006-02-07 15:19:38 | 000,000,000 | —D | M] – C:\Documents and Settings\helu\Application Data\Musicmatch
[2005-05-30 23:16:12 | 000,000,000 | —D | M] – C:\Documents and Settings\helu\Application Data\Template
[2010-07-31 00:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2010-07-31 09:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2010-07-31 10:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2010-07-31 11:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2010-07-31 12:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2010-07-31 13:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2010-07-31 14:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2010-07-31 15:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2010-07-31 16:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2010-07-31 17:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2010-07-31 18:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2010-07-31 01:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2010-07-30 21:47:39 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2010-07-30 21:47:39 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2010-07-30 21:47:39 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2010-07-30 22:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2010-07-30 23:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2010-07-31 02:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2010-07-31 03:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2010-07-31 04:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2010-07-31 05:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2010-07-31 06:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2010-07-31 07:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2010-07-31 08:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\At9.job
[2010-07-31 17:00:12 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{39C1EB2E-5972-44CA-A1D9-98BA8BDCEA3D}.job
Part 4 OTL
************

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004-09-16 10:55:54 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005-05-28 23:41:00 | 000,000,211 | -HS- | M] () – C:\BOOT.INI
[2004-08-04 13:00:00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[2004-09-16 10:55:54 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005-05-18 23:28:00 | 000,003,912 | RH– | M] () – C:\DELL.SDR
[2004-12-20 00:04:00 | 000,013,824 | —- | M] () – C:\dmg2iso.exe
[2004-09-16 11:05:30 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004-09-16 10:55:54 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2008-04-13 20:20:53 | 000,145,743 | —- | M] () – C:\list.txt
[2006-02-12 15:12:53 | 000,003,328 | —- | M] () – C:\madonna.nra
[2004-09-16 10:55:54 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004-08-04 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008-09-01 23:21:55 | 000,250,560 | RHS- | M] () – C:\NTLDR
[2010-07-31 10:46:11 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2004-03-23 00:17:06 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004-09-16 10:55:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\*. /mp /s >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >
[2010-06-28 22:57:33 | 000,038,848 | —- | M] (ALWIL Software) – C:\WINDOWS\avastSS.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
Part 5 - OTL
**********

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004-09-16 10:48:18 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004-09-16 10:48:18 | 000,634,880 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004-09-16 10:48:18 | 000,413,696 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %systemroot%\system32\user32.dll /md5 >
[2008-04-14 18:04:53 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=E3CF0EC59316EA8E856DB1E1F442CD57 – C:\WINDOWS\SYSTEM32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008-04-14 18:04:55 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=45C8F895EE6D409FC3C5911C7749D60E – C:\WINDOWS\SYSTEM32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008-04-14 18:04:55 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=0E81CCBC5FCBFFFD9A2876AA215D629C – C:\WINDOWS\SYSTEM32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
Last part of the otl-log? Dont know why I'm having trobles posting the otl log….. The last lines with registry keys will not post no matter how i try. (Or how i "rewrite them")
Hello there,

***Read through this entire procedure and if you have any questions, please ask them before you begin. Then either print out, or copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.


Ensure all your real time protections are disabled for the mean time while following the instructions.

You have ( BitLord ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
jotti.org
VirScan
Virus Total

click on Browse, and upload the following file for analysis:
C:\WINDOWS\System32\drivers\ydialibe.sys

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

===================================================
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2010-07-31 00:47:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\At*.job
    O4 - HKCU..\Run: [MSMSGS] C:\Program\Messenger\msmsgs.exe File not found
    O4 - HKLM..\Run: [QuickTime Task] C:\Program\QuickTime\qttask .exe File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
    O33 - MountPoints2\{4c7cf221-39cd-11df-8e62-00123f362fc3}\Shell\AutoRun\command - "" = F:\hbcd\wintools\autorun.exe – File not found
    O33 - MountPoints2\{4c7cf221-39cd-11df-8e62-00123f362fc3}\Shell\Option1\Command - "" = F:\hbcd\wintools\autorun.exe – File not found
    O33 - MountPoints2\{833d74ee-d1ed-11d9-a2f0-00123f362fc3}\Shell\AutoRun\command - "" = G:\hbcd\wintools\autorun.exe – File not found
    O33 - MountPoints2\{833d74ee-d1ed-11d9-a2f0-00123f362fc3}\Shell\Option1\Command - "" = G:\hbcd\wintools\autorun.exe – File not found
    O33 - MountPoints2\{97a2b47a-c4d8-11de-8e4b-00123f362fc3}\Shell\AutoRun\command - "" = G:\hbcd\wintools\autorun.exe – File not found
    O33 - MountPoints2\{97a2b47a-c4d8-11de-8e4b-00123f362fc3}\Shell\Option1\Command - "" = G:\hbcd\wintools\autorun.exe – File not found
    O33 - MountPoints2\{de7fda36-0d0c-11df-8e56-00123f362fc3}\Shell\AutoRun\command - "" = F:\Setup.exe – File not found
    C:\Documents and Settings\All Users\Application Data\TWoNVCNEv.dat
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

===================================================

Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

===================================================

On your next reply please post :
Online file scan results
OTL log
Combofix log

Good Day!
Hello Conspire, back from vacation. Filescan results below. OTL and ComboFix logs in the next post. Best regards / Henrik *** Jotti's malware scan *** Filename: ydialibe.sys Status: Scan finished. 0 out of 19 scanners reported malware. Scan taken on: Mon 9 Aug 2010 21:22:34 (CET) Permalink Additional info File size: 43008 bytes Filetype: PE32 executable for MS Windows (native) Intel 80386 32-bit MD5: 95b4fb835e28aa1336ceeb07fd5b9398 SHA1: 09a537bc79f5d5e813b9a81d44c5cb12fdd0b8b5 Packer (Kaspersky): PE_Patch ****************************
ComboFix 10-08-09.01 - helu 2010-08-09 22:50:55.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.1014.609 [GMT 2:00]
Körs från: c:\documents and settings\helu\Skrivbord\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\helu\Application Data\5D999A2E3B0D33633D0DE059A6BB8598
c:\documents and settings\helu\Application Data\5D999A2E3B0D33633D0DE059A6BB8598\enemies-names.txt
c:\windows\system32\drivers\iycsljjh.sys

.
(((((((((((((((((((((((( Filer Skapade från 2010-07-09 till 2010-08-09 ))))))))))))))))))))))))))))))
.

2010-08-09 19:32 . 2010-08-09 19:32 ——– d—–w- C:\_OTL
2010-08-01 09:09 . 2010-08-01 09:09 ——– d—–w- c:\documents and settings\helu\Application Data\Malwarebytes
2010-07-30 19:15 . 2010-07-30 19:15 ——– d—–w- c:\documents and settings\moed\Application Data\Malwarebytes
2010-07-30 19:15 . 2010-04-29 13:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-30 19:15 . 2010-07-30 19:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-30 19:15 . 2010-04-29 13:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 19:15 . 2010-07-30 19:15 ——– d—–w- c:\program\Malwarebytes' Anti-Malware
2010-07-30 10:54 . 2010-07-30 10:54 388096 —-a-r- c:\documents and settings\moed\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-30 10:03 . 2010-07-30 10:03 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-07-29 15:57 . 2010-07-29 15:57 ——– d—–w- c:\program\Trend Micro
2010-07-29 14:44 . 2010-08-09 20:49 ——– d—–w- c:\program\Spybot 162
2010-07-29 14:38 . 2010-07-29 14:38 ——– d-sh–w- c:\documents and settings\moed\PrivacIE
2010-07-28 11:25 . 2010-07-28 11:25 61440 —-a-w- c:\documents and settings\moed\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-692de837-n\decora-sse.dll
2010-07-28 11:25 . 2010-07-28 11:25 503808 —-a-w- c:\documents and settings\moed\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-71f702a4-n\msvcp71.dll
2010-07-28 11:25 . 2010-07-28 11:25 499712 —-a-w- c:\documents and settings\moed\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-71f702a4-n\jmc.dll
2010-07-28 11:25 . 2010-07-28 11:25 348160 —-a-w- c:\documents and settings\moed\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-71f702a4-n\msvcr71.dll
2010-07-28 11:25 . 2010-07-28 11:25 12800 —-a-w- c:\documents and settings\moed\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-692de837-n\decora-d3d.dll
2010-07-28 11:22 . 2010-07-28 11:22 ——– d—–w- c:\program\TeaTimer (Spybot - Search & Destroy)
2010-07-28 11:22 . 2010-07-28 11:22 ——– d—–w- c:\program\SDHelper (Spybot - Search & Destroy)
2010-07-28 11:18 . 2010-06-28 20:37 165456 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-07-28 11:18 . 2010-06-28 20:32 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-07-28 11:18 . 2010-06-28 20:33 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-07-28 11:18 . 2010-06-28 20:37 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-07-28 11:18 . 2010-06-28 20:32 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-07-28 11:18 . 2010-06-28 20:32 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-07-28 11:18 . 2010-06-28 20:32 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-07-28 11:18 . 2010-06-28 20:57 38848 —-a-w- c:\windows\avastSS.scr
2010-07-28 11:18 . 2010-06-28 20:57 165032 —-a-w- c:\windows\system32\aswBoot.exe
2010-07-28 11:16 . 2010-07-28 11:16 ——– d-sh–w- c:\documents and settings\moed\IETldCache
2010-07-28 10:54 . 2010-07-28 10:54 43008 —-a-w- c:\windows\system32\drivers\ydialibe.sys
2010-07-27 21:43 . 2010-07-27 21:43 ——– d—–r- c:\documents and settings\NetworkService\Favoriter
2010-07-27 21:15 . 2010-07-27 21:15 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-07-27 21:09 . 2010-07-27 21:09 ——– d-sh–w- c:\documents and settings\helu\IECompatCache
2010-07-27 21:08 . 2010-07-27 21:08 ——– d-sh–w- c:\documents and settings\helu\PrivacIE
2010-07-27 20:58 . 2010-07-27 20:58 ——– d-sh–w- c:\documents and settings\helu\IETldCache
2010-07-27 20:51 . 2010-07-27 20:53 ——– dc-h–w- c:\windows\ie8
2010-07-27 20:39 . 2010-07-28 11:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-27 20:36 . 2010-07-27 20:36 503808 —-a-w- c:\documents and settings\helu\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-35c0d16c-n\msvcp71.dll
2010-07-27 20:36 . 2010-07-27 20:36 499712 —-a-w- c:\documents and settings\helu\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-35c0d16c-n\jmc.dll
2010-07-27 20:36 . 2010-07-27 20:36 348160 —-a-w- c:\documents and settings\helu\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-35c0d16c-n\msvcr71.dll
2010-07-27 20:36 . 2010-07-27 20:36 61440 —-a-w- c:\documents and settings\helu\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6ee611c5-n\decora-sse.dll
2010-07-27 20:36 . 2010-07-27 20:36 12800 —-a-w- c:\documents and settings\helu\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6ee611c5-n\decora-d3d.dll
2010-07-27 20:36 . 2010-07-30 20:56 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-27 20:26 . 2010-07-27 20:26 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-27 20:15 . 2010-07-28 11:12 ——– d—–w- c:\windows\system32\MpEngineStore
2010-07-27 19:38 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-09 20:49 . 2005-05-31 20:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-31 17:33 . 2008-09-23 21:02 ——– d—–w- c:\program\QuickTime
2010-07-31 17:33 . 2008-10-30 18:02 ——– d—–w- c:\program\iTunes
2010-07-31 08:51 . 2010-07-30 19:49 112 —-a-w- c:\documents and settings\All Users\Application Data\TWoNVCNEv.dat
2010-07-30 21:22 . 2008-10-05 17:45 ——– d—–w- c:\program\Windows Live Safety Center
2010-07-30 20:56 . 2005-05-18 21:46 ——– d—–w- c:\program\Java
2010-07-30 20:52 . 2005-05-18 21:48 ——– d—–w- c:\program\Jasc Software Inc
2010-07-30 20:49 . 2008-03-20 21:06 ——– d—–w- c:\documents and settings\All Users\Application Data\YAHOO
2010-07-30 20:49 . 2008-03-20 21:05 ——– d—–w- c:\program\Yahoo!
2010-07-30 20:47 . 2007-06-26 09:35 ——– d—–w- c:\program\Levande Böcker
2010-07-30 20:47 . 2005-05-18 21:47 ——– d–h–w- c:\program\InstallShield Installation Information
2010-07-30 20:47 . 2006-12-26 14:25 ——– d—–w- c:\program\OnTrade
2010-07-30 20:45 . 2005-05-18 21:47 ——– d—–w- c:\program\Sonic
2010-07-30 20:45 . 2005-05-18 21:47 ——– d—–w- c:\program\Delade filer\Sonic Shared
2010-07-30 20:44 . 2008-04-22 20:03 ——– d—–w- c:\program\MediaMonkey
2010-07-30 20:44 . 2007-01-08 20:32 ——– d—–w- c:\program\Keyfinder Advanced 2007 (Trial Version)
2010-07-30 20:43 . 2007-06-27 14:44 ——– d—–w- c:\program\KAN SJÄLV
2010-07-30 20:41 . 2005-05-18 21:46 ——– d—–w- c:\program\Delade filer\Java
2010-07-29 14:43 . 2005-05-31 20:41 ——– d—–w- c:\program\Spybot - Search & Destroy
2010-07-27 20:39 . 2006-11-19 21:29 ——– d—–w- c:\program\Alwil Software
2010-06-14 14:31 . 2004-08-04 11:00 744448 —-a-w- c:\windows\PCHEALTH\HELPCTR\BINARIES\helpsvc.exe
.
c:\program\CyberLink\PowerDVD\DVDLauncher .exe
c:\program\Delade filer\Acronis\Schedule2\schedhlp .exe
c:\program\Delade filer\Java\Java Update\jusched .exe
c:\program\Delade filer\Sonic\Update Manager\sgtray .exe
c:\program\Dell\Media Experience\DMXLauncher .exe
c:\program\iTunes\iTunesHelper .exe
c:\program\Messenger\msmsgs .exe
c:\program\Musicmatch\Musicmatch Jukebox\mimboot .exe
c:\program\QuickTime\qttask  .exe

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TrueImageMonitor.exe"="c:\program\Acronis\TrueImage\TrueImageMonitor.exe" [2005-11-28 988701]
"Media Codec Update Service"="c:\program\Essentials Codec Pack\update.exe" [N/A]
"avast5"="c:\program\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start-meny\Program\Autostart\
Acrobat Assistant.lnk - c:\program\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-8-17 49254]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\g:\0autocheck autochk *\0aswBoot.exe /M:27ae2712ba08

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program\\BitLord\\BitLord.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program\\Bonjour\\mDNSResponder.exe"=
"c:\\Program\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25516:TCP"= 25516:TCP:@xpsp2res.dll,-22009

R1 aswSP;aswSP;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [2010-07-28 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [2010-07-28 17744]
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys –> c:\windows\system32\PavSRK.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
cidfeahf
.
Innehållet i mappen 'Schemalagda aktiviteter':

2010-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-08-09 c:\windows\Tasks\User_Feed_Synchronization-{39C1EB2E-5972-44CA-A1D9-98BA8BDCEA3D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
——- Extra genomsökning ——-
.
uStart Page = hxxp://www.google.se/ig?hl=sv
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\program\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: pandasoftware.com
Trusted Zone: musicmatch.com\online
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-09 22:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLer som "laddats" under processer som körs ———————

- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\relog_ap.dll
.
Sluttid: 2010-08-09 22:57:31
ComboFix-quarantined-files.txt 2010-08-09 20:57

Före genomsökningen: 12 033 806 336 byte ledigt
Efter genomsökningen: 11 988 566 016 byte ledigt

- - End Of File - - 395E21B457722C8C1E163E3FF4C20071

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI