This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Again, I come bowing to your greatness

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 07:02:50 PM, on 2010-08-11
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Windows\sttray.exe
C:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Common Files\Teleca Shared\logger.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\DbgOut.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\White\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avp] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Mobile Connectivity Suite] "C:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O18 - Protocol: intu-qt2008 - {05E53CE9-66C8-4A9E-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe

–
End of file - 9184 bytes
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: MP061
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 158):
0x8444C000 \SystemRoot\system32\ntkrnlpa.exe
0x84419000 \SystemRoot\system32\hal.dll
0x80409000 \SystemRoot\system32\kdcom.dll
0x80410000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x80480000 \SystemRoot\system32\PSHED.dll
0x80491000 \SystemRoot\system32\BOOTVID.dll
0x80499000 \SystemRoot\system32\CLFS.SYS
0x804DA000 \SystemRoot\system32\CI.dll
0x80609000 \SystemRoot\system32\drivers\Wdf01000.sys
0x80685000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80692000 \SystemRoot\system32\drivers\acpi.sys
0x806D8000 \SystemRoot\system32\drivers\WMILIB.SYS
0x806E1000 \SystemRoot\system32\drivers\msisadrv.sys
0x806E9000 \SystemRoot\system32\drivers\pci.sys
0x80710000 \SystemRoot\System32\drivers\partmgr.sys
0x8071F000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x80722000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8072C000 \SystemRoot\system32\drivers\volmgr.sys
0x8073B000 \SystemRoot\System32\drivers\volmgrx.sys
0x80785000 \SystemRoot\system32\drivers\intelide.sys
0x8078C000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8079A000 \SystemRoot\system32\DRIVERS\pciide.sys
0x807A1000 \SystemRoot\System32\drivers\mountmgr.sys
0x807B1000 \SystemRoot\system32\drivers\atapi.sys
0x807B9000 \SystemRoot\system32\drivers\ataport.SYS
0x805BA000 \SystemRoot\system32\drivers\fltmgr.sys
0x807D7000 \SystemRoot\system32\drivers\fileinfo.sys
0x807E7000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x84A02000 \SystemRoot\System32\Drivers\ksecdd.sys
0x84A73000 \SystemRoot\system32\drivers\ndis.sys
0x84B7E000 \SystemRoot\system32\drivers\msrpc.sys
0x84BA9000 \SystemRoot\system32\drivers\NETIO.SYS
0x8A00F000 \SystemRoot\System32\drivers\tcpip.sys
0x8A0F9000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8A20B000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8A31B000 \SystemRoot\system32\drivers\volsnap.sys
0x8A354000 \SystemRoot\System32\Drivers\spldr.sys
0x8A35C000 \SystemRoot\System32\Drivers\mup.sys
0x8A36B000 \SystemRoot\system32\drivers\klbg.sys
0x8A378000 \SystemRoot\System32\drivers\ecache.sys
0x8A39F000 \SystemRoot\system32\drivers\disk.sys
0x8A3B0000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8A3D1000 \SystemRoot\system32\drivers\crcdisk.sys
0x8A200000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8A114000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8A11D000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8A12C000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8A3FA000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8E207000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8E8B5000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8E956000 \SystemRoot\System32\drivers\watchdog.sys
0x8E962000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8A135000 \SystemRoot\system32\DRIVERS\bcmwl6.sys
0x8E9EF000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8A1BB000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8A000000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x84BE4000 \SystemRoot\system32\DRIVERS\bcm4sbxp.sys
0x807F0000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x805EC000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8EA0B000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x8EA25000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x8EA33000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x8EA47000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8EA98000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EAAB000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8EAD6000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8EAD8000 \SystemRoot\system32\DRIVERS\klmouflt.sys
0x8EAE1000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8EAEC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8EAF7000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8EB17000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8EB46000 \SystemRoot\system32\DRIVERS\storport.sys
0x8EB87000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8EB92000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8EBA9000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8EBB4000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8EBD7000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8EBE6000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8EE0A000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8EE1F000 \SystemRoot\System32\Drivers\pcouffin.sys
0x8EE2B000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8EE3B000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8EE3D000 \SystemRoot\system32\DRIVERS\ks.sys
0x8EE67000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8EE71000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8EE7E000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8EEB3000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8EEC4000 \SystemRoot\system32\drivers\stwrt.sys
0x8EF67000 \SystemRoot\system32\drivers\portcls.sys
0x8EF94000 \SystemRoot\system32\drivers\drmk.sys
0x8EFB9000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys
0x8F20E000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x8F311000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x8F3C5000 \SystemRoot\system32\drivers\modem.sys
0x8F404000 \SystemRoot\system32\DRIVERS\klif.sys
0x8F455000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8F45E000 \SystemRoot\System32\Drivers\Null.SYS
0x8F465000 \SystemRoot\System32\Drivers\Beep.SYS
0x8F475000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8F47C000 \SystemRoot\System32\drivers\vga.sys
0x8F488000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8F4A9000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8F4B1000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8F4B9000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8F4C4000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8F4D2000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8F4DB000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8F80C000 \SystemRoot\system32\DRIVERS\kl1.sys
0x8FD2C000 \SystemRoot\system32\DRIVERS\smb.sys
0x8FD40000 \SystemRoot\system32\drivers\afd.sys
0x8FD88000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8FDBA000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8FDD0000 \SystemRoot\system32\DRIVERS\klim6.sys
0x8FDD7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8FDE5000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8F4F1000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8F800000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8F52D000 \SystemRoot\System32\Drivers\dfsc.sys
0x8F544000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8F54D000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8FDF8000 \SystemRoot\system32\DRIVERS\NuidFltr.sys
0x8F55D000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8F565000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8F572000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8F57D000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x99A60000 \SystemRoot\System32\win32k.sys
0x8F585000 \SystemRoot\System32\drivers\Dxapi.sys
0x8F58F000 \SystemRoot\system32\DRIVERS\monitor.sys
0x99C80000 \SystemRoot\System32\TSDDD.dll
0x99CA0000 \SystemRoot\System32\cdd.dll
0x8F59E000 \SystemRoot\system32\drivers\luafv.sys
0xAB40E000 \SystemRoot\system32\drivers\spsys.sys
0xAB4BE000 \SystemRoot\system32\DRIVERS\lltdio.sys
0xAB4CE000 \SystemRoot\system32\DRIVERS\nwifi.sys
0xAB4F8000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xAB502000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xAB515000 \SystemRoot\system32\drivers\HTTP.sys
0xAB582000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAB59F000 \SystemRoot\system32\DRIVERS\bowser.sys
0xAB5B8000 \SystemRoot\System32\drivers\mpsdrv.sys
0xAB5CD000 \SystemRoot\system32\drivers\mrxdav.sys
0x8F5C1000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xABE07000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xABE40000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xABE58000 \SystemRoot\System32\DRIVERS\srv2.sys
0xABE7F000 \SystemRoot\System32\DRIVERS\srv.sys
0xABECD000 \??\C:\Program Files\DellSupport\Drivers\dsunidrv.sys
0xABECF000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xABED3000 \SystemRoot\system32\drivers\peauth.sys
0xABFB1000 \SystemRoot\System32\Drivers\fastfat.SYS
0xABFD9000 \SystemRoot\System32\Drivers\secdrv.SYS
0xABFE3000 \SystemRoot\System32\drivers\tcpipreg.sys
0xABFEF000 \SystemRoot\system32\DRIVERS\xaudio.sys
0x8F5E0000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xABFF7000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xABE02000 \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
0xAB400000 \SystemRoot\system32\DRIVERS\serscan.sys
0x77BC0000 \Windows\System32\ntdll.dll

Processes (total 83):
0 System Idle Process
4 System
516 C:\Windows\System32\smss.exe
584 csrss.exe
628 C:\Windows\System32\wininit.exe
636 csrss.exe
680 C:\Windows\System32\services.exe
708 C:\Windows\System32\winlogon.exe
724 C:\Windows\System32\lsass.exe
744 C:\Windows\System32\lsm.exe
928 C:\Windows\System32\svchost.exe
996 C:\Windows\System32\svchost.exe
1040 C:\Windows\System32\svchost.exe
1140 C:\Windows\System32\svchost.exe
1208 C:\Windows\System32\svchost.exe
1236 C:\Windows\System32\svchost.exe
1344 C:\Windows\System32\audiodg.exe
1372 C:\Windows\System32\svchost.exe
1404 C:\Windows\System32\SLsvc.exe
1428 C:\Windows\System32\svchost.exe
1780 C:\Windows\System32\spoolsv.exe
1816 C:\Windows\System32\svchost.exe
2008 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
124 C:\Windows\System32\svchost.exe
360 C:\Windows\System32\svchost.exe
384 C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
828 C:\Windows\System32\svchost.exe
1628 C:\Windows\System32\svchost.exe
1872 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2096 C:\Windows\System32\svchost.exe
2140 C:\Windows\System32\svchost.exe
2224 C:\Windows\System32\SearchIndexer.exe
2724 C:\Windows\System32\taskeng.exe
1220 C:\Windows\System32\svchost.exe
3604 C:\Windows\System32\dwm.exe
1852 C:\Windows\explorer.exe
2120 C:\Windows\System32\taskeng.exe
1012 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
2732 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1716 C:\Windows\System32\igfxpers.exe
3164 C:\Windows\System32\hkcmd.exe
2348 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
3032 C:\Windows\System32\WLTRAY.EXE
3068 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
2856 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
3152 C:\Windows\sttray.exe
864 C:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
3244 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3188 C:\Program Files\Windows Sidebar\sidebar.exe
2932 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
2720 C:\Windows\ehome\ehtray.exe
3968 C:\Program Files\DellSupport\DSAgnt.exe
4052 C:\Program Files\Windows Media Player\wmpnscfg.exe
3676 C:\Program Files\Digital Line Detect\DLG.exe
2336 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
3772 C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
2904 C:\Windows\ehome\ehmsas.exe
3692 C:\Program Files\Windows Media Player\wmpnetwk.exe
2148 C:\Windows\System32\wbem\unsecapp.exe
3688 WmiPrvSE.exe
1812 C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
896 C:\Program Files\Common Files\Teleca Shared\logger.exe
4120 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
4192 C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
4460 C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
4552 C:\Program Files\Common Files\Teleca Shared\Generic.exe
4804 C:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
4840 C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
4912 C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\dbgout.exe
5716 C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
5860 C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
5592 C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
2476 C:\Program Files\HTC\HTC Sync\Sync Manager\SyncIndicator.exe
5268 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
4444 C:\Windows\System32\svchost.exe
3512 C:\Program Files\Internet Explorer\iexplore.exe
1440 C:\Program Files\Internet Explorer\iexplore.exe
4148 C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
4116 C:\Program Files\Windows Live\Toolbar\wltuser.exe
4732
2692
796 C:\Users\White\Desktop\WTT - Aug 11 2010\MBRCheck.exe
5228 C:\Windows\System32\conime.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000002`83000000 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x00000000`03000000 (NTFS)

PhysicalDrive0 Model Number: SAMSUNGHM120JI, Rev: YF100-15

Size Device Name MBR Status
——————————————–
111 GB \\.\PhysicalDrive0 Windows Vista MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!




DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 15:43:27.03 on 2010-08-15
Internet Explorer: 8.0.6001.18943
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2038.1015 [GMT -4:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Windows\sttray.exe
C:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Teleca Shared\logger.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\DbgOut.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\HTC\HTC Sync\Sync Manager\syncindicator.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\White\Desktop\WTT - Aug 11 2010\dds.com
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
uSearchURL,(Default) = hxxp://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [Mobile Connectivity Suite] "c:\program files\htc\htc sync\application launcher\Application Launcher.exe" /startoptions
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\white\appdata\roaming\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\quicktax 2007\ic2007pp.dll
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - c:\program files\quicktax 2008\ic2008pp.dll
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
Notify: igfxcui - igfxdev.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~2\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~2\kloehk.dll

============= SERVICES / DRIVERS ===============

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2009-9-14 21520]
R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-10-20 340456]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-19 21504]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2010-4-21 24576]
S3 mr97310c;CIF Dual-Mode Camera;c:\windows\system32\drivers\mr97310c.sys [2008-3-27 116992]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-7-5 27192]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

============== File Associations ===============

regfile=regedit.exe "%1" %*
scrfile="%1" %*

=============== Created Last 30 ================

2010-08-10 20:17:43 2037760 —-a-w- c:\windows\system32\win32k.sys
2010-08-10 20:17:40 36864 —-a-w- c:\windows\system32\rtutils.dll
2010-08-10 20:17:36 3600768 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-10 20:17:35 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-08-10 20:17:30 1248768 —-a-w- c:\windows\system32\msxml3.dll
2010-08-10 20:17:27 302080 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-10 20:17:27 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-08-10 20:17:23 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys

==================== Find3M ====================

2010-07-29 21:52:58 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 21:52:58 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-07-17 09:00:04 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-26 06:05:49 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02:15 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02:15 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25:02 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-06-11 16:16:20 274944 —-a-w- c:\windows\system32\schannel.dll
2010-05-27 20:08:17 81920 —-a-w- c:\windows\system32\iccvid.dll
2010-05-26 17:06:41 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47:41 289792 —-a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14:28 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-04-21 23:20:55 51200 —-a-w- c:\windows\inf\infpub.dat
2010-04-21 23:20:54 143360 —-a-w- c:\windows\inf\infstrng.dat
2010-04-21 23:20:54 143360 —-a-w- c:\windows\inf\infstor.dat
2010-02-22 08:27:45 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-01-13 03:26:41 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-04-13 10:40:55 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2010-04-13 10:40:55 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2010-04-13 10:40:55 32768 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2010-02-06 05:14:41 16384 –sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\low\history.ie5\index.dat
2010-02-06 05:14:41 32768 –sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\index.dat
2010-02-06 05:14:41 16384 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\cookies\low\index.dat
2010-01-29 23:34:23 6813216 –sha-w- c:\windows\system32\drivers\fidbox.dat
2010-01-29 23:34:23 1294368 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2007-02-05 18:48:42 8192 –sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 15:45:55.09 ===============




UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 2007-02-05 05:56:17 AM
System Uptime: 2010-08-15 02:19:40 AM (13 hours ago)

Motherboard: Dell Inc. | | 0FF049
Processor: Intel® Core™2 CPU T5200 @ 1.60GHz | Microprocessor | 1600/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 100 GiB total, 19.408 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 6.011 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Photosmart C7200 series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Photosmart C7200 series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:

==== System Restore Points ===================

RP1616: 2010-08-11 06:51:54 PM - Installed HiJackThis
RP1617: 2010-08-11 06:58:36 PM - Removed HiJackThis
RP1618: 2010-08-12 07:28:19 AM - Scheduled Checkpoint
RP1619: 2010-08-13 12:31:06 AM - Scheduled Checkpoint
RP1620: 2010-08-13 01:52:28 AM - Windows Update
RP1621: 2010-08-14 12:00:03 AM - Scheduled Checkpoint
RP1622: 2010-08-15 09:59:02 AM - Scheduled Checkpoint

==== Installed Programs ======================

2007 Microsoft Office Suite Service Pack 2 (SP2)
32 Bit HP CIO Components Installer
Acrobat.com
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Adobe Shockwave Player
Adobe® Photoshop® Album Starter Edition 3.2
AIO_Scan
AnswerWorks 5.0 English Runtime
Any Video Converter 2.6.7
Art Explosion Greeting Card Factory Express
AutoCAD 2000
BufferChm
C7200
c7200_Help
Caillou's Colors Shapes
Cards_Calendar_OrderGift_DoMorePlugout
Conexant HDA D110 MDC V.92 Modem
Copy
Coupon Printer for Windows
CSI-Dark Motives
CustomerResearchQFolder
Dell Support Center (Support Software)
Dell Wireless WLAN Card
DellSupport
Destination Component
DeviceDiscovery
DeviceManagementQFolder
Digital Line Detect
Disney's Mickey Mouse Toddler
Disney's Winnie the Pooh Preschool
Disney's Winnie the Pooh Toddler
DocProc
DVD-CLONER V7.00 Build 990
EGS Recipe Center
ESET Online Scanner v3
eSupportQFolder
Fax
Free Mp3 Wma Converter V 1.8.0
Galaxy of Games Blue Edition
Garmin City Navigator North America NT 2009 Update
Garmin City Navigator North America NT 2010.40
Garmin City Navigator North America NT 2011.10 Update
Garmin Communicator Plugin
Garmin USB Drivers
Garmin WebUpdater
GearDrvs
Google SketchUp 6
Google SketchUp 7
GoToAssist 8.0.0.514
GPBaseService
Guitar Pro 5.0
Hidden Relics
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Participation Program 10.0
HP Imaging Device Functions 10.0
HP Photosmart All-In-One Driver Software 10.0 Rel .2
HP Photosmart Essential 2.5
HP Smart Web Printing
HP Solution Center 10.0
HP Update
HP_Network_UserGuide
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
HPSSupply
HTC Driver
HTC Sync
I am an Air Traffic Controller3
Java Auto Updater
Java™ 6 Update 21
Kaspersky Internet Security 2010
Lernout & Hauspie TruVoice American English TTS Engine
LiveUpdate 3.2 (Symantec Corporation)
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
MarketResearch
Mavis Beacon Teaches Typing 15
MediaDirect
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Search Enhancement Pack
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Modem Diagnostic Tool
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mystery Case Files - Prime Suspects
NetDeviceManager
NetWaiting
NiBiRu
NutriBase
OCR Software by I.R.I.S. 10.0
OpenOffice.org 3.0
OutlookAddinSetup
OverDrive Media Console
PanoStandAlone
Picture Package Music Transfer
PS_AIO_02_ProductContext
PS_AIO_02_Software
PS_AIO_02_Software_Min
PSSWCORE
Quicken 2010
QuickSet
QuickTax 2006
QuickTax 2007
QuickTax 2008
QuickTax 2009
QuickTax Tracker
QuickTime
Revo Uninstaller Pro 2.2.3
Safari
Scan
Security Update for 2007 Microsoft Office System (KB2277947)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office Outlook 2007 (KB980376)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office Publisher 2007 (KB982124)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2251419)
Shop for HP Supplies
SigmaTel Audio
Smart Menus (Windows Live Toolbar)
SmartWebPrintingOC
SolutionCenter
Sonic Activation Module
Sony Picture Utility
Status
Synaptics Pointing Device Driver
Toolbox
TrayApp
UnloadSupport
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb2279264)
User's Guides
VideoToolkit01
WebReg
Winamp Toolbar for Firefox
Windows Installer Clean Up
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Upload Tool
WinRAR archiver
Xilisoft AVI to DVD Converter
Xvid 1.2.2 final uninstall

==== Event Viewer Messages From Past Week ========

2010-08-15 12:33:12 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
2010-08-14 09:31:56 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ASPI32
2010-08-14 09:31:52 AM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
2010-08-14 04:15:11 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
2010-08-11 06:03:14 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect.
2010-08-11 06:03:14 AM, Error: Service Control Manager [7000] - The Windows Media Player Network Sharing Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2010-08-11 04:51:02 AM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
2010-08-11 04:48:12 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Eventlog service.
2010-08-11 04:48:09 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the stisvc service.
2010-08-10 09:23:33 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.

==== End Of File ===========================









GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-15 20:28:38
Windows 6.0.6002 Service Pack 2
Running: uzf7xwf5.exe; Driver: C:\Users\White\AppData\Local\Temp\uglcqpow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0x8F423BD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcConnectPort [0x8F42552C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcCreatePort [0x8F425782]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcSendWaitReceivePort [0x8F4259FC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwClose [0x8F424450]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwConnectPort [0x8F424B32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateEvent [0x8F424F3C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateFile [0x8F4245F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateMutant [0x8F424E14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0x8F4237D6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreatePort [0x8F424CD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSection [0x8F423992]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSemaphore [0x8F42506E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0x8F426CB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThread [0x8F4240EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateWaitablePort [0x8F424D72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDebugActiveProcess [0x8F4266A2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDuplicateObject [0x8F427672]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwFsControlFile [0x8F424752]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwLoadDriver [0x8F426734]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwMapViewOfSection [0x8F426D64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenEvent [0x8F424FDE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenFile [0x8F4244D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenMutant [0x8F424EAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenProcess [0x8F423DD6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSection [0x8F426CDA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSemaphore [0x8F425110]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenThread [0x8F423CFA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryDirectoryObject [0x8F425C3E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQuerySection [0x8F42707C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueueApcThread [0x8F4269CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyPort [0x8F42549A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0x8F425360]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0x8F426442]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwResumeThread [0x8F427554]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSecureConnectPort [0x8F42486C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetContextThread [0x8F42430C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetInformationToken [0x8F425CF2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSecurityObject [0x8F42682E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSystemInformation [0x8F4271BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendProcess [0x8F4272A0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendThread [0x8F4273C8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSystemDebugControl [0x8F4265CE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateProcess [0x8F423F4E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateThread [0x8F423EA4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0x8F426F32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0x8F42402E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThreadEx [0x8F4241EE]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 119 844F887C 4 Bytes [D0, 3B, 42, 8F]
.text ntkrnlpa.exe!KeSetEvent + 13D 844F88A0 8 Bytes [2C, 55, 42, 8F, 82, 57, 42, …]
.text ntkrnlpa.exe!KeSetEvent + 181 844F88E4 4 Bytes [FC, 59, 42, 8F]
.text ntkrnlpa.exe!KeSetEvent + 1A9 844F890C 4 Bytes [50, 44, 42, 8F]
.text ntkrnlpa.exe!KeSetEvent + 1C1 844F8924 4 Bytes [32, 4B, 42, 8F]
.text …

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!SetWindowsHookExW 76F887AD 5 Bytes JMP 6E5F9AD5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!CallNextHookEx 76F88E3B 5 Bytes JMP 6E5ED135 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!UnhookWindowsHookEx 76F898DB 5 Bytes JMP 6E564666 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!CreateWindowExW 76F91305 5 Bytes JMP 6E5FDB24 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!DialogBoxParamW 76FB10B0 5 Bytes JMP 6E525501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!DialogBoxIndirectParamW 76FB2EF5 5 Bytes JMP 6E6F4B4F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!DialogBoxParamA 76FC8152 5 Bytes JMP 6E6F4AEC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!DialogBoxIndirectParamA 76FC847D 5 Bytes JMP 6E6F4BB2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!MessageBoxIndirectA 76FDD4D9 5 Bytes JMP 6E6F4A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!MessageBoxIndirectW 76FDD5D3 5 Bytes JMP 6E6F4A16 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!MessageBoxExA 76FDD639 5 Bytes JMP 6E6F49B4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!MessageBoxExW 76FDD65D 5 Bytes JMP 6E6F4952 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ole32.dll!OleLoadFromStream 77A91E12 5 Bytes JMP 6E6F4ED0 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ole32.dll!CoCreateInstance 77AC9EA6 5 Bytes JMP 6E5FDB80 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!closesocket 77DF330C 5 Bytes JMP 65FF41DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!recv 77DF343A 5 Bytes JMP 65FF4549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!socket 77DF36D1 5 Bytes JMP 65FF354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!connect 77DF40D9 5 Bytes JMP 65FF35DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!getaddrinfo 77DF418A 5 Bytes JMP 65FF3704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!send 77DF659B 5 Bytes JMP 65FF3B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2008] C:\Windows\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2008] C:\Windows\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2008] USER32.dll!SetScrollInfo + 7A8 76F97980 4 Bytes [70, 11, 33, 6D]
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2856] C:\Windows\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2856] C:\Windows\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2856] USER32.dll!SetScrollInfo + 7A8 76F97980 4 Bytes [70, 11, 33, 6D]
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!CreateWindowExW 76F91305 5 Bytes JMP 6E5FDB24 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!DialogBoxParamW 76FB10B0 5 Bytes JMP 6E525501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!DialogBoxIndirectParamW 76FB2EF5 5 Bytes JMP 6E6F4B4F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!DialogBoxParamA 76FC8152 5 Bytes JMP 6E6F4AEC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!DialogBoxIndirectParamA 76FC847D 5 Bytes JMP 6E6F4BB2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!MessageBoxIndirectA 76FDD4D9 5 Bytes JMP 6E6F4A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!MessageBoxIndirectW 76FDD5D3 5 Bytes JMP 6E6F4A16 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!MessageBoxExA 76FDD639 5 Bytes JMP 6E6F49B4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!MessageBoxExW 76FDD65D 5 Bytes JMP 6E6F4952 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[5592] kernel32.dll!SetUnhandledExceptionFilter 779BA84F 4 Bytes JMP 64645164 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[5592] ole32.dll!OleLoadFromStream 77A91E12 5 Bytes JMP 650F9D32 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\tdx \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\tdx \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi

Please do the following:


Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 10-08-16.04 - White 2010-08-17 8:18.8.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2038.1135 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\pswi_preloaded.exe
c:\users\White\AppData\Roaming\inst.exe
c:\users\White\GoToAssistDownloadHelper.exe
c:\windows\system32\AutoRun.inf

.
((((((((((((((((((((((((( Files Created from 2010-07-17 to 2010-08-17 )))))))))))))))))))))))))))))))
.

2010-08-17 12:33 . 2010-08-17 12:33 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-08-11 11:09 . 2010-08-11 11:09 ——– d—–w- c:\program files\Common Files\Java
2010-08-10 20:17 . 2010-06-21 13:37 2037760 —-a-w- c:\windows\system32\win32k.sys
2010-08-10 20:17 . 2010-06-18 17:31 36864 —-a-w- c:\windows\system32\rtutils.dll
2010-08-10 20:17 . 2010-06-08 17:35 3600768 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-10 20:17 . 2010-06-08 17:35 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-08-10 20:17 . 2010-06-11 16:15 1248768 —-a-w- c:\windows\system32\msxml3.dll
2010-08-10 20:17 . 2010-06-18 15:04 302080 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-10 20:17 . 2010-06-18 15:04 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-08-10 20:17 . 2010-06-16 16:04 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 18:00 . 2009-02-08 19:16 ——– d—–w- c:\programdata\Kaspersky Lab
2010-08-14 20:15 . 2007-06-09 12:04 ——– d—–w- c:\program files\ACAD2000
2010-08-11 11:04 . 2007-02-05 11:05 ——– d—–w- c:\program files\Java
2010-08-11 08:09 . 2007-04-06 16:15 ——– d—–w- c:\programdata\Microsoft Help
2010-08-11 07:20 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-07-29 21:52 . 2009-02-08 19:18 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 21:52 . 2009-02-08 19:18 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-07-17 09:00 . 2010-07-04 20:15 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-13 21:57 . 2010-07-13 21:53 ——– d—–w- c:\program files\Dvd-cloner
2010-07-09 16:23 . 2009-08-31 18:33 ——– d—–w- c:\program files\Crosstrainer
2010-07-09 16:10 . 2007-12-26 04:33 ——– d—–w- c:\program files\Oberon Media
2010-07-09 15:41 . 2007-02-12 23:52 160624 —-a-w- c:\users\White\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-08 19:46 . 2007-10-26 22:53 ——– d—–w- c:\program files\Google
2010-07-06 10:27 . 2007-02-05 11:12 ——– d—–w- c:\program files\Common Files\Roxio Shared
2010-07-06 10:23 . 2007-02-05 11:15 ——– d—–w- c:\programdata\Roxio
2010-07-05 21:04 . 2010-07-05 21:04 ——– d—–w- c:\program files\VS Revo Group
2010-07-05 12:57 . 2010-07-05 12:57 ——– d—–w- c:\program files\ESET
2010-07-05 12:30 . 2010-07-05 12:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-04 22:04 . 2010-07-04 21:53 ——– d—–w- c:\programdata\NOS
2010-07-04 21:59 . 2007-03-18 23:56 ——– d—–w- c:\program files\Common Files\Adobe
2010-07-04 21:55 . 2010-07-04 21:55 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-07-04 21:53 . 2010-07-04 21:53 71680 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2010-07-04 21:53 . 2010-07-04 21:53 ——– d—–w- c:\program files\NOS
2010-07-04 21:01 . 2007-02-27 23:59 ——– d—–w- c:\program files\Mozilla Thunderbird
2010-06-26 07:06 . 2010-01-01 20:49 ——– d—–w- c:\program files\Microsoft.NET
2010-06-26 06:05 . 2010-08-10 20:18 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-10 20:18 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-06-26 06:02 . 2010-08-10 20:18 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-06-26 04:25 . 2010-08-10 20:18 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-06-24 23:04 . 2010-05-21 23:47 ——– d—–w- c:\programdata\Deadtime Stories
2010-06-16 12:45 . 2010-06-16 12:45 133648 —-a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-16 12:45 . 2010-06-16 12:45 133720 —-a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-11 16:16 . 2010-08-10 20:18 274944 —-a-w- c:\windows\system32\schannel.dll
2010-05-27 20:08 . 2010-08-10 20:18 81920 —-a-w- c:\windows\system32\iccvid.dll
2010-05-26 17:06 . 2010-06-09 22:10 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-09 22:10 289792 —-a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14 . 2009-10-02 18:51 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-01-29 23:34 . 2009-02-08 19:16 6813216 –sha-w- c:\windows\System32\drivers\fidbox.dat
2010-01-29 23:34 . 2009-02-08 19:16 1294368 –sha-w- c:\windows\System32\drivers\fidbox2.dat
2007-02-05 18:48 . 2007-02-05 18:48 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2006-11-12 446976]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-15 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-15 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-15 106496]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-21 340456]
"SigmatelSysTrayApp"="sttray.exe" [2007-01-12 303104]
"Mobile Connectivity Suite"="c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe" [2009-05-27 598016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\users\White\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-6-16 385024]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-2-5 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~2\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~2\kloehk.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"VistaSp2"=hex(B):e6,50,e3,e8,3c,b3,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2010-04-21 24576]
R3 mr97310c;CIF Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310c.sys [2008-03-27 116992]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-15 36880]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2009-09-14 21520]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-03 19472]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uSearchURL,(Default) = hxxp://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-17 08:33
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-17 08:39:57
ComboFix-quarantined-files.txt 2010-08-17 12:39

Pre-Run: 18,152,656,896 bytes free
Post-Run: 19,155,361,792 bytes free

- - End Of File - - 07A8B8141490902DCE5D1C0C56623D18
Hi

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


**Vista users - right click on the IE icon and run as administrator

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4439 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18943 2010-08-17 09:54:25 AM mbam-log-2010-08-17 (09-54-25).txt Scan type: Quick scan Objects scanned: 140403 Time elapsed: 19 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I scanned using ESET for 4 hours and only got up to 50% complete. If you need a complete scan I can restart it again tonight.
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=572dc58ee3e74a4fbd5a7d36da3f88b1 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-08-17 05:51:41 # local_time=2010-08-17 01:51:41 (-0500, Eastern Daylight Time) # country="Canada" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 72034703 72034703 0 0 # compatibility_mode=1280 16777215 100 0 17163401 17163401 0 0 # compatibility_mode=5892 16776573 100 100 0 118661293 0 0 # compatibility_mode=8192 67108863 100 0 2797545 2797545 0 0 # scanned=83940 # found=0 # cleaned=0 # scan_time=13737 # version=7 # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=572dc58ee3e74a4fbd5a7d36da3f88b1 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-08-20 05:51:49 # local_time=2010-08-20 01:51:49 (-0500, Eastern Daylight Time) # country="Canada" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 72243323 72243323 0 0 # compatibility_mode=1280 16777215 100 0 17372021 17372021 0 0 # compatibility_mode=5892 16776574 100 100 0 118869913 0 0 # compatibility_mode=8192 67108863 100 0 3006165 3006165 0 0 # scanned=217144 # found=0 # cleaned=0 # scan_time=21125
Just housekeeping to do now

please do the following:

You can delete the MBRCheck, DDS and GMER logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI