This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Multiple infections

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:11:13 PM, on 8/9/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\twc\medicsp2\bin\sprtcmd.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SecCopy\SecCopy.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Citrix\Secure Access Client\nsverctl.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\V9NVEJG5\HiJackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
F2 - REG:system.ini: Shell=Explorer.exe logon.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [medicsp2] C:\Program Files\twc\medicsp2\bin\sprtcmd.exe /P medicsp2
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [jrjrshfg] C:\Documents and Settings\Mike\Local Settings\Application Data\vwufesntv\aavewittssd.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Second Copy] "C:\Program Files\SecCopy\SecCopy.exe"
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [jrjrshfg] C:\Documents and Settings\Mike\Local Settings\Application Data\vwufesntv\aavewittssd.exe
O4 - HKLM\..\Policies\Explorer\Run: [RTHDBPL] C:\DOCUME~1\Mike\LOCALS~1\Temp\svchost.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Second Copy 7.lnk = C:\Program Files\SecCopy\SecCopy.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.ccf.org
O15 - Trusted Zone: *.clevelandclinic.org
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://intranet.cchs.net/onlinelearning/in…rs7/awswaxd.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.my-etrust.com/Extern/RoadRunner…an/pestscan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1164907403531
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {EBC1356E-7D5E-44EC-831D-847882F06FE5} (Gateway Client for MetaFrame) - https://secure.ccf.org/ccf-msam/cds/CGC/en/CSGProxy.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15112/CTPID.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ccf.org
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ccf.org
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Citrix Secure Access Client Service (nsverctl) - Citrix Systems, Inc - C:\Program Files\Citrix\Secure Access Client\nsverctl.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (medicsp2) (sprtsvc_medicsp2) - SupportSoft, Inc. - C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 9727 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Please do the following.

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.




[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • MBRCheck log
  • Both OTL logs
  • GMER log
I hope I did everything properly.
MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d

Kernel Drivers (total 132):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EE000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF75A8000 ACPI.sys
0xF7989000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7597000 pci.sys
0xF75F7000 isapnp.sys
0xF7A4F000 pciide.sys
0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF798B000 intelide.sys
0xF7607000 MountMgr.sys
0xF74D8000 ftdisk.sys
0xF798D000 dmload.sys
0xF74B2000 dmio.sys
0xF770F000 PartMgr.sys
0xF7617000 VolSnap.sys
0xF749A000 atapi.sys
0xF7627000 disk.sys
0xF7637000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF747A000 fltmgr.sys
0xF7647000 PxHelp20.sys
0xF7463000 KSecDD.sys
0xF7B52000 Ntfs.sys
0xF7436000 NDIS.sys
0xF741C000 Mup.sys
0xF7657000 agp440.sys
0xBA748000 \SystemRoot\system32\DRIVERS\SMBios.sys
0xF7687000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB9382000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xB936E000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB9350000 \SystemRoot\system32\DRIVERS\e1000325.sys
0xF779F000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB932C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF77A7000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB9FC8000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF77AF000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF77B7000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF77BF000 \SystemRoot\system32\DRIVERS\fdc.sys
0xB9FB8000 \SystemRoot\system32\DRIVERS\serial.sys
0xF794B000 \SystemRoot\system32\DRIVERS\serenum.sys
0xB9318000 \SystemRoot\system32\DRIVERS\parport.sys
0xB9FA8000 \SystemRoot\system32\DRIVERS\imapi.sys
0xB9F98000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xB9F88000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB92F5000 \SystemRoot\system32\DRIVERS\ks.sys
0xF77C7000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0xB9267000 \SystemRoot\system32\drivers\smwdm.sys
0xB9243000 \SystemRoot\system32\drivers\portcls.sys
0xB9F78000 \SystemRoot\system32\drivers\drmk.sys
0xB922B000 \SystemRoot\system32\drivers\aeaudio.sys
0xF77CF000 \SystemRoot\system32\drivers\sf.sys
0xB9F68000 \SystemRoot\system32\DRIVERS\ctxva51.sys
0xB920C000 \SystemRoot\system32\DRIVERS\dne2000.sys
0xF7ABD000 \SystemRoot\system32\DRIVERS\audstub.sys
0xB9F58000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA7F8000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB91F5000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xB9F48000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xB9F38000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF77D7000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB91E4000 \SystemRoot\system32\DRIVERS\psched.sys
0xF7697000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF77DF000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF77E7000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB9164000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF76A7000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF79AF000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB90DE000 \SystemRoot\system32\DRIVERS\update.sys
0xBA7E0000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF76B7000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF76C7000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF79B5000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF77EF000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xB7F41000 \??\C:\Program Files\Symantec AntiVirus\savrt.sys
0xB7F24000 \??\C:\Program Files\Symantec\SYMEVENT.SYS
0xB7F10000 \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys
0xF77FF000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xF79B9000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7AAA000 \SystemRoot\System32\Drivers\Null.SYS
0xF7927000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xF79BB000 \SystemRoot\System32\Drivers\Beep.SYS
0xF780F000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xF7817000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF781F000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xF773F000 \SystemRoot\System32\drivers\vga.sys
0xF79C3000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79C5000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF7747000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF774F000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF793B000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xB7D7D000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xB7D24000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xB7CE4000 \SystemRoot\System32\Drivers\SYMTDI.SYS
0xB7CBE000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF76E7000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF76F7000 \SystemRoot\system32\drivers\usbaudio.sys
0xB7BF6000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF7943000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF7587000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xB7BAC000 \SystemRoot\System32\drivers\afd.sys
0xF7577000 \SystemRoot\system32\DRIVERS\netbios.sys
0xB7B74000 \??\C:\WINDOWS\System32\DRIVERS\tcpip7x.sys
0xB7B49000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xB7AD9000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF7567000 \SystemRoot\System32\Drivers\Fips.SYS
0xB7A7B000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0xF7547000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB7A63000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF79C9000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB90CE000 \SystemRoot\System32\drivers\Dxapi.sys
0xF777F000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA0FC000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xB681F000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xB5ACE000 \SystemRoot\system32\drivers\wdmaud.sys
0xB5B4B000 \SystemRoot\system32\drivers\sysaudio.sys
0xB5724000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF79FD000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xB5693000 \??\C:\Program Files\Common Files\Deterministic Networks\Common Files\cag.sys
0xB53D0000 \SystemRoot\system32\DRIVERS\srv.sys
0xF7787000 \SystemRoot\System32\Drivers\TDTCP.SYS
0xB5155000 \SystemRoot\System32\Drivers\RDPWD.SYS
0xB4F34000 \SystemRoot\System32\Drivers\HTTP.sys
0xB4D0C000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11010.sys
0xB4BC0000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100806.002\navex15.sys
0xB4BAC000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100806.002\naveng.sys
0xB1720000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 38):
0 System Idle Process
4 System
1232 C:\WINDOWS\system32\smss.exe
1284 csrss.exe
1308 C:\WINDOWS\system32\winlogon.exe
1368 C:\WINDOWS\system32\services.exe
1388 C:\WINDOWS\system32\lsass.exe
1668 C:\WINDOWS\system32\svchost.exe
1768 svchost.exe
220 C:\WINDOWS\system32\svchost.exe
316 svchost.exe
428 svchost.exe
620 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
732 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
260 C:\WINDOWS\explorer.exe
468 C:\WINDOWS\system32\spoolsv.exe
1220 svchost.exe
120 C:\WINDOWS\system32\netdde.exe
1864 C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
1872 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
2016 C:\WINDOWS\system32\CTSVCCDA.EXE
2068 C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
2076 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
2084 C:\PROGRA~1\SYMANT~1\VPTray.exe
2092 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
2100 C:\Program Files\twc\medicsp2\bin\sprtcmd.exe
2132 C:\WINDOWS\system32\ctfmon.exe
2140 C:\Program Files\SecCopy\SecCopy.exe
2160 C:\Program Files\Symantec AntiVirus\DefWatch.exe
2224 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
2240 C:\Program Files\Java\jre6\bin\jqs.exe
2996 C:\Program Files\Citrix\Secure Access Client\nsverctl.exe
3052 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
3068 C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
3208 C:\WINDOWS\system32\svchost.exe
3260 C:\Program Files\Symantec AntiVirus\Rtvscan.exe
1704 alg.exe
3976 C:\Documents and Settings\Mike\Desktop\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
\\.\E: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive1 Model Number: ST3200827AS, Rev: 3.AAD
PhysicalDrive0 Model Number: Maxtor33073H3, Rev: YAH814Y0

Size Device Name MBR Status
——————————————–
186 GB \\.\PhysicalDrive1 MBR Code Faked (known infection: Whistler / Black Internet)!
SHA1: 4C73F18103C9BEEC7A59697F7C30E616317435F9
28 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.

Enter your choice:

OTL logfile created on: 8/13/2010 9:58:56 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Mike\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 112.66 Gb Free Space | 60.47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 28.62 Gb Total Space | 0.01 Gb Free Space | 0.04% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ORGANIZA-A99F9C
Current User Name: Mike
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Mike\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Citrix\Secure Access Client\nsverctl.exe (Citrix Systems, Inc)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\twc\medicsp2\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\twc\medicsp2\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\SecCopy\SecCopy.exe (Centered Systems)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Mike\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\twc\medicsp2\bin\sprthook.dll (SupportSoft, Inc.)
MOD - C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll (Nuance Communications, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (nsverctl) – C:\Program Files\Citrix\Secure Access Client\nsverctl.exe (Citrix Systems, Inc)
SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (sprtsvc_medicsp2) SupportSoft Sprocket Service (medicsp2) – C:\Program Files\twc\medicsp2\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (Net6IM) – C:\WINDOWS\System32\DRIVERS\net6im51.sys File not found
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100806.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100806.002\NAVENG.SYS (Symantec Corporation)
DRV - (tcpip7x) – C:\WINDOWS\system32\drivers\tcpip7x.sys ()
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (ctxva51) – C:\WINDOWS\system32\drivers\ctxva51.sys (Citrix Systems, Inc.)
DRV - (cag) – C:\Program Files\Common Files\Deterministic Networks\Common Files\cag.sys (Citrix Systems, Inc.)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (APL531) – C:\WINDOWS\system32\drivers\FilmScan.sys (Omnivision Technologies, Inc.)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (Jukebox3) – C:\WINDOWS\system32\drivers\ctpdusb.sys (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (SMBios) Intel ® – C:\WINDOWS\system32\drivers\SMBios.sys (Intel Corporation)
DRV - (sf) – C:\WINDOWS\system32\drivers\sf.sys (Sonic Focus, Inc)
DRV - (MidiSyn) – C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08}:5.7
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {9CE11043-9A15-4207-A565-0C94C42D590D}:2.0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/08/14 02:11:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{33F9B22C-BBE1-4BBA-BF16-E5365B0EEB32}: C:\Documents and Settings\Mike\Local Settings\Application Data\{33F9B22C-BBE1-4BBA-BF16-E5365B0EEB32}\ [2010/06/29 06:43:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4C5B6BAF-30EA-4AFB-AA02-E0AD501D2F05}: C:\Documents and Settings\Mike\Local Settings\Application Data\{4C5B6BAF-30EA-4AFB-AA02-E0AD501D2F05}\ [2010/07/02 07:00:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{EF7C98E7-F97B-4989-BAB7-DB05993A22B2}: C:\Documents and Settings\Mike\Local Settings\Application Data\{EF7C98E7-F97B-4989-BAB7-DB05993A22B2}\ [2010/07/04 09:07:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4A49A3CE-837D-475F-ACD6-D6F15D925D71}: C:\Documents and Settings\Mike\Local Settings\Application Data\{4A49A3CE-837D-475F-ACD6-D6F15D925D71}\ [2010/07/06 07:55:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{F461B815-8A18-4CDF-BD5F-D0AF62D3E509}: C:\Documents and Settings\Mike\Local Settings\Application Data\{F461B815-8A18-4CDF-BD5F-D0AF62D3E509} [2010/07/06 08:16:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.4\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/25 23:04:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.4\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/25 23:04:33 | 000,000,000 | —D | M]

[2009/10/15 14:25:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Extensions
[2010/08/12 21:57:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\knqk8jei.default\extensions
[2009/08/17 17:49:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\knqk8jei.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/18 13:27:55 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\knqk8jei.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/02/22 22:31:18 | 000,000,000 | —D | M] (Sothink Web Video Downloader for Firefox) – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\knqk8jei.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}
[2010/08/06 16:52:43 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/31 14:02:39 | 000,000,000 | —D | M] (Firefox security) – C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}
[2007/08/14 02:11:25 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/08/16 17:42:02 | 000,070,456 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/08/16 17:42:12 | 000,091,448 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/08/16 17:42:08 | 000,020,800 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2008/05/21 08:41:08 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 08:41:08 | 000,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 08:41:08 | 000,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2008/08/16 17:44:46 | 000,427,312 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2008/08/16 17:42:04 | 000,023,864 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll

O1 HOSTS File: ([2010/06/15 12:37:08 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [jrjrshfg] C:\Documents and Settings\Mike\Local Settings\Application Data\vwufesntv\aavewittssd.exe File not found
O4 - HKLM..\Run: [medicsp2] C:\Program Files\twc\medicsp2\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [jrjrshfg] C:\Documents and Settings\Mike\Local Settings\Application Data\vwufesntv\aavewittssd.exe File not found
O4 - HKCU..\Run: [Second Copy] C:\Program Files\SecCopy\SecCopy.exe (Centered Systems)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Mike\Start Menu\Programs\Startup\Second Copy 7.lnk = C:\Program Files\SecCopy\SecCopy.exe (Centered Systems)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: RTHDBPL = C:\DOCUME~1\Mike\LOCALS~1\Temp\svchost.exe File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ccf.org ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: ccf.org ([secure] http in Internet)
O15 - HKCU\..Trusted Domains: ccf.org ([secure] https in Internet)
O15 - HKCU\..Trusted Domains: clevelandclinic.org ([]* in Trusted sites)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://activation.rr.com/install/downloads/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} http://intranet.cchs.net/onlinelearning/in…rs7/awswaxd.cab (Macromedia Authorware Web Player Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/0/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} http://www.my-etrust.com/Extern/RoadRunner…an/pestscan.cab (PSFormX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1164907403531 (WUWebControl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EBC1356E-7D5E-44EC-831D-847882F06FE5} https://secure.ccf.org/ccf-msam/cds/CGC/en/CSGProxy.cab (Gateway Client for MetaFrame)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15112/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (logon.exe) - File not found
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - File not found
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/11/30 09:35:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{d3bfd7b4-1a32-11df-8907-000cf1f56664}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d3bfd7b4-1a32-11df-8907-000cf1f56664}\Shell\Explore\command - "" = autorun.exe
O33 - MountPoints2\{d3bfd7b4-1a32-11df-8907-000cf1f56664}\Shell\Open\command - "" = autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (SsiEfr.e) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.MP42 - C:\WINDOWS\System32\MPG4c32.dll (Microsoft Corporation)
Drivers32: vidc.MP43 - C:\WINDOWS\System32\MPG4c32.dll (Microsoft Corporation)
Drivers32: vidc.MPG4 - C:\WINDOWS\System32\MPG4c32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
Unable to start service SrService!

========== Files/Folders - Created Within 30 Days ==========

[2010/08/13 09:57:03 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mike\Desktop\OTL.exe
[2010/08/03 07:52:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Mike\Local Settings\Application Data\vwufesntv
[2010/07/31 14:02:40 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Mike\Application Data\SystemProc
[2010/07/14 17:40:06 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/13 09:57:04 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mike\Desktop\OTL.exe
[2010/08/13 09:48:13 | 000,080,384 | —- | M] () – C:\Documents and Settings\Mike\Desktop\MBRCheck.exe
[2010/08/13 08:47:48 | 000,110,592 | —- | M] () – C:\Documents and Settings\Mike\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/13 08:24:11 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/12 07:06:00 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/12 07:04:19 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/12 07:04:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/12 07:03:57 | 2146,222,080 | -HS- | M] () – C:\hiberfil.sys
[2010/08/12 06:57:00 | 000,192,976 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 03:23:16 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Mike\ntuser.ini
[2010/08/12 03:07:31 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/12 03:06:35 | 000,505,784 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/12 03:06:35 | 000,444,484 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/12 03:06:35 | 000,072,234 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/08 09:23:36 | 000,000,691 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/08 09:23:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/08 09:23:35 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/08 09:19:12 | 006,291,456 | -H– | M] () – C:\Documents and Settings\Mike\NTUSER.DAT
[2010/08/08 07:22:43 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/27 02:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2010/07/16 09:03:51 | 000,002,497 | —- | M] () – C:\Documents and Settings\Mike\Desktop\Microsoft Office Word 2003.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,001,744 | -H– | C] () – C:\WINDOWS\System32\japetuni
[2010/08/13 09:48:12 | 000,080,384 | —- | C] () – C:\Documents and Settings\Mike\Desktop\MBRCheck.exe
[2010/07/18 14:10:35 | 000,000,012 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\uzkrij.dat
[2010/06/25 09:51:13 | 000,228,864 | —- | C] () – C:\WINDOWS\System32\drivers\tcpip7x.sys
[2010/06/09 11:00:45 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2010/06/09 11:00:45 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2009/09/10 03:02:51 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/09/08 07:38:16 | 000,000,744 | —- | C] () – C:\WINDOWS\System32\wininit.dll
[2009/07/22 15:16:52 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/07/22 15:16:52 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/02/24 12:15:53 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2009/02/24 12:14:27 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/10/27 18:07:15 | 000,000,356 | —- | C] () – C:\WINDOWS\System32\CNCASv51.ini
[2008/09/27 22:23:58 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/09/27 22:23:58 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/09/15 20:14:24 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/09/15 20:12:02 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/09/15 20:12:02 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/09/15 20:11:10 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/06/14 15:24:00 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\JpgLib.dll
[2007/07/31 07:51:21 | 001,936,528 | —- | C] () – C:\WINDOWS\System32\ltmm15.dll
[2006/12/04 22:40:29 | 000,000,054 | —- | C] () – C:\WINDOWS\webica.ini
[2006/12/01 12:24:17 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\PdeSrvps.dll
[2006/11/30 21:01:35 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/11/30 17:01:40 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\CNMVSyf.DLL
[2006/11/30 17:01:19 | 000,000,599 | —- | C] () – C:\WINDOWS\System32\CNCMP51.INI
[2006/11/30 16:56:32 | 000,000,021 | —- | C] () – C:\WINDOWS\PS_setup.ini
[2006/11/30 15:12:13 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2006/11/30 13:27:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/11/30 09:45:33 | 000,126,976 | R— | C] () – C:\WINDOWS\System32\e1000msg.dll
[2006/11/02 14:28:20 | 000,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/02/24 12:08:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/08/09 12:06:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2009/02/24 12:14:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/07/31 16:47:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/04/02 08:40:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\temp
[2010/01/06 13:21:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/08 12:07:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Canon
[2007/06/06 18:45:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\DVD Profiler
[2007/07/31 07:50:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\GetRightToGo
[2009/08/09 12:06:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\ICAClient
[2009/03/03 12:26:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\NewSoft
[2009/01/02 11:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\ri4mupdater
[2010/03/02 13:43:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\RipIt4Me
[2009/02/24 12:14:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\ScanSoft
[2010/07/31 14:02:40 | 000,000,000 | -HSD | M] – C:\Documents and Settings\Mike\Application Data\SystemProc

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/03/27 18:17:08 | 000,232,177 | —- | M] () – C:\69.jpg
[2010/06/05 21:59:46 | 000,000,002 | —- | M] () – C:\AGClientInstall.log
[2010/05/02 15:46:34 | 000,071,272 | —- | M] () – C:\AGClientUpgrade.log
[2006/11/30 09:35:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/08 09:23:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2002/11/26 19:03:32 | 000,159,232 | —- | M] (Microsoft Corporation) – C:\cewmdm.dll
[2006/11/30 09:35:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/20 22:36:09 | 000,000,021 | —- | M] () – C:\CTSUFile.txt
[2009/06/14 08:53:12 | 000,000,081 | —- | M] () – C:\CTX.DAT
[2003/08/13 14:06:30 | 000,011,926 | —- | M] () – C:\eula.txt
[2010/08/12 07:03:57 | 2146,222,080 | -HS- | M] () – C:\hiberfil.sys
[2006/11/30 09:35:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/11/30 09:35:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2002/11/26 19:03:32 | 000,052,224 | —- | M] (Microsoft Corporation) – C:\mspmsnsv.dll
[2002/11/26 19:03:32 | 000,201,728 | —- | M] (Microsoft Corporation) – C:\mspmsp.dll
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/22 11:54:04 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/12 07:03:56 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2007/08/31 16:07:03 | 000,000,273 | —- | M] () – C:\sap.log
[2003/07/24 01:55:50 | 000,229,376 | —- | M] (Microsoft Corporation) – C:\setup_wm.exe
[2003/08/25 15:58:56 | 000,010,317 | —- | M] () – C:\WMDMDist.CAT
[2003/08/21 16:17:38 | 000,001,626 | —- | M] () – C:\WMDMDist.inf
[2003/08/22 12:30:18 | 000,001,560 | —- | M] () – C:\WMDMDist9x.inf
[2002/11/26 20:03:32 | 000,027,136 | —- | M] (Microsoft Corporation) – C:\WMDMLOG.dll
[2002/11/26 20:03:32 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\WMDMPS.dll
[2010/06/06 06:20:32 | 000,017,326 | —- | M] () – C:\XenAppWebInstall.log

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/11/30 09:35:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/22 01:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD95.DLL
[2003/09/05 06:00:00 | 000,016,384 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDyf.DLL
[2007/05/22 01:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP95.DLL
[2003/09/05 05:00:00 | 000,048,128 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPyf.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/18 18:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2007/03/12 12:18:32 | 000,001,594 | -H– | M] () – C:\Documents and Settings\Mike\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2007/07/31 07:50:38 | 003,655,608 | —- | M] () – C:\Program Files\FLV PlayerRCATSetup.exe
[2007/07/31 07:49:24 | 000,411,248 | —- | M] (Applian Technologies Inc.) – C:\Program Files\FLV PlayerRCSetup.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/11/30 04:24:56 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/11/30 04:24:55 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/11/30 04:24:55 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 20:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 20:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/13 20:12:10 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\system32\ws2help.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-13 04:28:23

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 207 bytes -> C:\Documents and Settings\All Users\Application Data\temp:0AA053B7
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\temp:f7b65412
< End of report >
OTL Extras logfile created on: 8/13/2010 9:58:56 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Mike\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 112.66 Gb Free Space | 60.47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 28.62 Gb Total Space | 0.01 Gb Free Space | 0.04% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ORGANIZA-A99F9C
Current User Name: Mike
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"4025:TCP" = 4025:TCP:*:Enabled:Services
"6550:TCP" = 6550:TCP:*:Enabled:Services
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"4025:TCP" = 4025:TCP:*:Enabled:Services
"6550:TCP" = 6550:TCP:*:Enabled:Services
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Citrix\Secure Access Client\nsload.exe" = C:\Program Files\Citrix\Secure Access Client\nsload.exe:*:Enabled:Citrix Access Gateway Plug-in – (Citrix Systems, Inc)
"C:\Program Files\Citrix\Secure Access Client\nsepa.exe" = C:\Program Files\Citrix\Secure Access Client\nsepa.exe:*:Enabled:Citrix Access Gateway Endpoint Analysis – (Citrix Systems, Inc)
"C:\WINDOWS\TEMP\alg.exe" = C:\WINDOWS\TEMP\alg.exe:*:Enabled:Application Layer Gateway Service – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sports Medicine\Safran\jvm\bin\java.exe" = C:\Program Files\Sports Medicine\Safran\jvm\bin\java.exe:*:Enabled:java – ()
"C:\Program Files\RipIt4Me\RipIt4Me.exe" = C:\Program Files\RipIt4Me\RipIt4Me.exe:*:Enabled:RipIt4Me – ()
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Citrix\Secure Access Client\nsload.exe" = C:\Program Files\Citrix\Secure Access Client\nsload.exe:*:Enabled:Citrix Access Gateway Plug-in – (Citrix Systems, Inc)
"C:\Program Files\Citrix\Secure Access Client\nsepa.exe" = C:\Program Files\Citrix\Secure Access Client\nsepa.exe:*:Enabled:Citrix Access Gateway Endpoint Analysis – (Citrix Systems, Inc)
"C:\WINDOWS\TEMP\alg.exe" = C:\WINDOWS\TEMP\alg.exe:*:Enabled:Application Layer Gateway Service – File not found
"" = :*:Enabled:ldrsoft
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX700_series" = Canon MX700 series
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{230CCBE9-14B0-4008-97AF-30C10F99E42C}" = ArcSoft PhotoStudio 5.5
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{3248E093-5288-4CA9-B3AB-11A675FEA1F9}" = Symantec AntiVirus
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9501CD08-4582-47A3-92BD-3E7FAF9F343C}_is1" = Sothink FLV Converter
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B0DE8E93-8382-4418-92A2-BCED061F1D17}" = Sports Medicine
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CAAB0192-5704-469F-A0BE-2D842D70E93B}_is1" = Sothink FLV Player
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.16
"{D944236D-7992-41D6-8257-930B5832F1CC}" = Creative Zen Micro
"{EA23971F-2CEE-48FC-B64D-7F74A6EF90F0}" = XMLinst
"{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}" = Citrix XenApp Web Plugin
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{EF901A4B-A25A-4962-83C6-C6691D062ED9}" = Nero Mega Plugin Pack
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F3C5F53A-78EA-413C-843B-8EC03115B339}" = Citrix Access Gateway Plug-in
"{F3CF9967-7631-4DE5-9FAF-A9712D450C2B}" = 35mm Film Scanner X86
"35mm Film Scanner" = Uninstall 35mm Film Scanner
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Anvsoft DVD Menu Template Package 1" = Menu Template Package 1 Ver 1.10
"Audacity_is1" = Audacity 1.2.6
"Canon MX700 series User Registration" = Canon MX700 series User Registration
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Citrix ICA Web Client" = Citrix ICA Web Client
"Creative Jukebox Driver" = Creative Jukebox Driver
"Creative Removable Disk Manager" = Creative Removable Disk Manager
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"EZ Vinyl Converter by MixMeister_is1" = EZ Vinyl Converter 2.0.0 by MixMeister
"ffdshow_is1" = ffdshow [rev 1723] [2007-12-24]
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.4)" = Mozilla Firefox (3.6.4)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"OLYMPUS CAMEDIA Master 1.11" = OLYMPUS CAMEDIA Master 1.11
"Photo DVD Maker Professional" = Photo DVD Maker Professional 7.35
"Picasa 3" = Picasa 3
"PROSet" = Intel® PRO Network Adapters and Drivers
"RipIt4Me" = RipIt4Me
"Road Runner Install_is1" = Road Runner Install
"RoadRunnerMedic6.1_is1" = Road Runner Medic 6.1
"Second Copy (7.0)" = Second Copy (7.0)
"SysInfo" = Creative System Information
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/6/2010 8:09:54 PM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan.Gen in File: c:\documents and settings\Mike\application
data\systemproc\lsass.exe by: Manual scan. Action: Leave Alone succeeded. Action
Description: The file was left unchanged.

Error - 8/7/2010 2:03:30 AM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Trojan.Gen in File: C:\Documents and Settings\Mike\Application
Data\SystemProc\lsass.exe by: Auto-Protect scan. Action: Clean failed : Quarantine
failed. Action Description: The file was left unchanged.

Error - 8/7/2010 2:03:33 AM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan.Gen in File: C:\Documents and Settings\Mike\Application
Data\SystemProc\lsass.exe by: Auto-Protect scan. Action: Clean failed : Quarantine
failed : Access denied. Action Description: Quarantine was partially successful.

Error - 8/8/2010 7:23:16 AM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Trojan.Gen in File: C:\DOCUME~1\Mike\LOCALS~1\Temp\svchost.exe
by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The
file was quarantined successfully.

Error - 8/8/2010 7:23:16 AM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan.Gen in File: C:\Documents and Settings\Mike\Local
Settings\Temp\svchost.exe by: Auto-Protect scan. Action: Quarantine succeeded
: Access denied. Action Description: The file was quarantined successfully.

Error - 8/8/2010 7:23:20 AM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan.Gen in File: C:\DOCUME~1\Mike\LOCALS~1\Temp\svchost.exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 8/8/2010 9:13:43 AM | Computer Name = ORGANIZA-A99F9C | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/9/2010 2:48:31 PM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Trojan.FakeAV in File: C:\DOCUME~1\Mike\LOCALS~1\Temp\078881~1.EXE
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was deleted successfully.

Error - 8/9/2010 2:48:31 PM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan.FakeAV in File: C:\Documents and Settings\Mike\Local
Settings\Temp\0.7888193939059844.exe by: Auto-Protect scan. Action: Clean failed
: Quarantine failed : Delete succeeded : Access denied. Action Description: The
file was deleted successfully.

Error - 8/9/2010 2:48:36 PM | Computer Name = ORGANIZA-A99F9C | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan.FakeAV in File: C:\DOCUME~1\Mike\LOCALS~1\Temp\078881~1.EXE
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Delete succeeded
: Access denied. Action Description: The file was deleted successfully.

[ System Events ]
Error - 8/11/2010 5:23:20 PM | Computer Name = ORGANIZA-A99F9C | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/12/2010 7:05:38 AM | Computer Name = ORGANIZA-A99F9C | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Net.Tcp Port Sharing
Service service to connect.

Error - 8/12/2010 7:05:38 AM | Computer Name = ORGANIZA-A99F9C | Source = Service Control Manager | ID = 7000
Description = The Net.Tcp Port Sharing Service service failed to start due to the
following error: %%1053

Error - 8/12/2010 7:05:52 AM | Computer Name = ORGANIZA-A99F9C | Source = System Error | ID = 1003
Description = Error code 1000007f, parameter1 00000008, parameter2 80042000, parameter3
00000000, parameter4 00000000.

Error - 8/12/2010 7:06:16 AM | Computer Name = ORGANIZA-A99F9C | Source = System Error | ID = 1003
Description = Error code 1000007f, parameter1 00000008, parameter2 80042000, parameter3
00000000, parameter4 00000000.

Error - 8/13/2010 8:43:57 AM | Computer Name = ORGANIZA-A99F9C | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/13/2010 8:44:05 AM | Computer Name = ORGANIZA-A99F9C | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/13/2010 8:44:12 AM | Computer Name = ORGANIZA-A99F9C | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/13/2010 9:59:17 AM | Computer Name = ORGANIZA-A99F9C | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 8/13/2010 9:59:17 AM | Computer Name = ORGANIZA-A99F9C | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-13 12:06:21
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mike\LOCALS~1\Temp\pxryakog.sys


—- System - GMER 1.0.15 —-

SSDT 8A407120 ZwConnectPort

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\netdde.exe[120] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00D1B634
.text C:\WINDOWS\system32\netdde.exe[120] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00D1B1D1
.text C:\WINDOWS\system32\netdde.exe[120] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00D1B4E6
.text C:\WINDOWS\system32\netdde.exe[120] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00D1B2B2
.text C:\WINDOWS\system32\netdde.exe[120] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00D1B385
.text C:\WINDOWS\Explorer.exe[260] kernel32.dll!IsDebuggerPresent 7C813133 6 Bytes JMP 0414C550
.text C:\WINDOWS\Explorer.exe[260] USER32.dll!ChangeDisplaySettingsExA 7E42384E 5 Bytes JMP 04151F60
.text C:\WINDOWS\Explorer.exe[260] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 5 Bytes JMP 04151F90
.text C:\WINDOWS\Explorer.exe[260] USER32.dll!DisplayExitWindowsWarnings 7E459F91 5 Bytes JMP 01A12758
.text C:\WINDOWS\Explorer.exe[260] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0192B634
.text C:\WINDOWS\Explorer.exe[260] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0192B1D1
.text C:\WINDOWS\Explorer.exe[260] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0192B4E6
.text C:\WINDOWS\Explorer.exe[260] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0192B2B2
.text C:\WINDOWS\Explorer.exe[260] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0192B385
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[620] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 006AB634
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[620] WS2_32.dll!send 71AB4C27 5 Bytes JMP 006AB1D1
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[620] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 006AB4E6
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[620] WS2_32.dll!recv 71AB676F 5 Bytes JMP 006AB2B2
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[620] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 006AB385
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[732] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00CFB634
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[732] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00CFB1D1
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[732] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00CFB4E6
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[732] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00CFB2B2
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[732] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00CFB385
.text C:\WINDOWS\system32\winlogon.exe[1308] Secur32.dll!LsaLogonUser 77FE33F1 5 Bytes JMP 00DE2946
.text C:\WINDOWS\System32\alg.exe[1704] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C2B634
.text C:\WINDOWS\System32\alg.exe[1704] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C2B1D1
.text C:\WINDOWS\System32\alg.exe[1704] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C2B4E6
.text C:\WINDOWS\System32\alg.exe[1704] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C2B2B2
.text C:\WINDOWS\System32\alg.exe[1704] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C2B385
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2076] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0127B634
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2076] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0127B1D1
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2076] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0127B4E6
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2076] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0127B2B2
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2076] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0127B385
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[2084] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00BBB634
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[2084] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BBB1D1
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[2084] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00BBB4E6
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[2084] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00BBB2B2
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[2084] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00BBB385
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[2092] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00EDB634
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[2092] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00EDB1D1
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[2092] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00EDB4E6
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[2092] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00EDB2B2
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[2092] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00EDB385
.text C:\Program Files\twc\medicsp2\bin\sprtcmd.exe[2100] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0265B634
.text C:\Program Files\twc\medicsp2\bin\sprtcmd.exe[2100] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0265B1D1
.text C:\Program Files\twc\medicsp2\bin\sprtcmd.exe[2100] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0265B4E6
.text C:\Program Files\twc\medicsp2\bin\sprtcmd.exe[2100] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0265B2B2
.text C:\Program Files\twc\medicsp2\bin\sprtcmd.exe[2100] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0265B385
.text C:\Program Files\SecCopy\SecCopy.exe[2140] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 012DB634
.text C:\Program Files\SecCopy\SecCopy.exe[2140] WS2_32.dll!send 71AB4C27 5 Bytes JMP 012DB1D1
.text C:\Program Files\SecCopy\SecCopy.exe[2140] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 012DB4E6
.text C:\Program Files\SecCopy\SecCopy.exe[2140] WS2_32.dll!recv 71AB676F 5 Bytes JMP 012DB2B2
.text C:\Program Files\SecCopy\SecCopy.exe[2140] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 012DB385
.text C:\Program Files\Citrix\Secure Access Client\nsverctl.exe[2996] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00FAB634
.text C:\Program Files\Citrix\Secure Access Client\nsverctl.exe[2996] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00FAB1D1
.text C:\Program Files\Citrix\Secure Access Client\nsverctl.exe[2996] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00FAB4E6
.text C:\Program Files\Citrix\Secure Access Client\nsverctl.exe[2996] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00FAB2B2
.text C:\Program Files\Citrix\Secure Access Client\nsverctl.exe[2996] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00FAB385
.text C:\Program Files\twc\medicsp2\bin\sprtsvc.exe[3068] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01EAB634
.text C:\Program Files\twc\medicsp2\bin\sprtsvc.exe[3068] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01EAB1D1
.text C:\Program Files\twc\medicsp2\bin\sprtsvc.exe[3068] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01EAB4E6
.text C:\Program Files\twc\medicsp2\bin\sprtsvc.exe[3068] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01EAB2B2
.text C:\Program Files\twc\medicsp2\bin\sprtsvc.exe[3068] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01EAB385
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[3260] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 021BB634
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[3260] WS2_32.dll!send 71AB4C27 5 Bytes JMP 021BB1D1
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[3260] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 021BB4E6
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[3260] WS2_32.dll!recv 71AB676F 5 Bytes JMP 021BB2B2
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[3260] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 021BB385

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

AttachedDevice SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-

Thank you for your assistance
Please download HelpAsst_mebroot_fix.exe and save it to your desktop.
Close out all other open programs and windows.

Double click the file to run it and follow any prompts.

If the tool detects an mbr infection, please allow it to run mbr -f and shutdown your computer.

Upon restarting, please wait about 5 minutes, click Start>Run and type the following bolded command, then hit Enter.

helpasst -mbrt

Make sure you leave a space between helpasst and -mbrt !

When it completes, a log will open.

Please post the contents of that log.

*In the event the tool does not detect an mbr infection and completes, click Start>Run and type the following bolded command, then hit Enter.

mbr -f

Now, please do the Start>Run>mbr -f command a second time.

Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.

Give it about 5 minutes, then click Start>Run and type the following bolded command, then hit Enter.

helpasst -mbrt

Make sure you leave a space between helpasst and -mbrt !

When it completes, a log will open.

Please post the contents of that log.


**Important note to Dell users - fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not allow the tool to execute mbr -f nor execute the command manually, and you will either need to restore your computer to a factory state or allow your computer to remain having an infected mbr (the latter not recommended).





Next

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Here is the log for helpasst_mebroot_fix
C:\Documents and Settings\Mike\Desktop\HelpAsst_mebroot_fix.exe
Sun 08/15/2010 at 8:34:12.07

HelpAssistant account is Active ~ attempting to de-activate

Account active Yes
Local Group Memberships *Administrators

HelpAssistant successfully set Inactive

~~ Checking for termsrv32.dll ~~

termsrv32.dll present! ~ attempting to remove
Remove on reboot: C:\WINDOWS\system32\termsrv32.dll

~~ Checking firewall ports ~~

backing up DomainProfile\GloballyOpenPorts\List registry key
closing rogue ports

HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
"65533:TCP"=-
"52344:TCP"=-
"4025:TCP"=-
"6550:TCP"=-
"3389:TCP"=-

backing up StandardProfile\GloballyOpenPorts\List registry key
closing rogue ports

HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
"65533:TCP"=-
"52344:TCP"=-
"4025:TCP"=-
"6550:TCP"=-
"3389:TCP"=-

~~ Checking profile list ~~

HelpAssistant profile found in registry ~ backing up and removing S-1-5-21-776561741-299502267-839522115-1000
HelpAssistant profile directory exists at C:\Documents and Settings\HelpAssistant ~ attempting to remove
~ All C:\Documents and Settings\HelpAssistant files successfully removed ~

~~ Checking mbr ~~

user & kernel MBR OK

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on Sun 08/15/2010 at 8:44:47.30

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x87DD378A]<<
kernel: MBR read successfully
user & kernel MBR OK

~~ Checking for termsrv32.dll ~~

termsrv32.dll present!


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

none found

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~

I also downloaded ComboFix - had Microsoft Windows Recovery Console installed - and accepted the EULA then clicked on yes to continue scanning. It seemed to be working for a couple of minutes - but after that there was no activity for three hours. I had to restart my computer which took several attempts just to post this first log. I have no idea what to do at this point - will wait for response from you. Thank you.
Please do the following.

Delete the copy of Combofix you have and download a fresh one from one of the links below,follow the instructions to rename it.Don't run it yet

Download Combofix from either of the links below. You must rename it to combo.com before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.


  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.



Next boot into safe mode

To get into the Windows 2000 / XP Safe mode, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu". Use your arrow keys to move to "Safe Mode" and press your Enter key.

Now run Combofix

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI