This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

JS:Fakewarn - E

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, hope you can help running vista home premium service pack2 32bit. avast has detected js:fakewarn-e and says it's put it in the chest however the laptop still displays symptoms of infection.. false virus warnings, browser redirects and "security suite" displaying in the task bar I cannot access the internet and so i am writing this on my wifes laptop. avast has also detected win32:Tibs.eoe and Java:Agent-BA thanks
Hello Davecl and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier: • Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.



Run OTL

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.


Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
Hi satchfan thanks for your help I can't run anything on the laptop, the malware says any programs are infected and shuts them down Are they ok to run in safe mode? as things seem to work in safe mode
Hello again Davecl

Please try this in normal windows.

• Please download exeHelper to your desktop.
• Double-click on exeHelper.com to run the fix.
• A black window should pop up, press any key to close once the fix is completed.
• Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
When you have done this, see if you can run the other scans that I asked for.

If OTL and Gmer still won’t run, try renaming OTL.exe to OTL.com and Gmer.exe to Gmer.com and try again

Logs to include in next reply:

Exehelperlog.txt
OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
exehelper only runs for a couple of seconds before the malware shuts it down and pops up a warning that exehelper.com is infected

this is the log

exeHelper by Raktor
Build 20100414
Run at 15:30:00 on


tried renaming OTL and Gmer to .com instead of .exe but they still won't run in normal windows
Davecl

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)

NOTE: There are 5 different versions. If one of them won't run then download and try to run the other one.
  • It's better to copy and paste the links into your browse than click on them
  • You only need to get one of them to run, not all of them.
  • You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message.
  • If your security software warns about Rkill, please ignore and allow the download to continue.
  • A command window will open then disappear upon completion, this is normal.
  • You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.
  • Do not reboot your computer after running rkill as the malware programs will start again.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe
When this is complete, try and run OTL and Gmer again.

Satchfan
managed to get OTL to run after using rkill but it only produced OTL.txt .. no Extras.txt I can't post it up yet because GMER is running and I want to run it uninterupted, the thing is it has been scanning for nearly 40 hours now is this normal?? It hasn't "crashed" or hung up because I can see the current file being scanned changing as it goes through them.
Hello Davecl

The Extras.txt log should be located in the same place as OTL.

If not we can get one later but meanwhile, if you can’t find it, send OTL.txt either on its own or with Gmer.txt if successful.

Re Gmer

it has been scanning for nearly 40 hours now is this normal??

No, Gmer shouldn’t take that long. Best stop it.


Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


Ideally, we'd like to run GMER in normal mode, but if it still won't run in normal mode please do the following:

Boot your computer in Safe Mode• Turn the computer on or Restart the computer
• Start tapping the F8 key.
• The Windows Advanced Options Menu appears.
If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
• Use the arrow keys to select the Safe Mode menu option.
• Press Enter.
• The computer then begins to start in Safe mode.
• Log into your usual account
Then try running GMER with just sections and the C:\ drive checked, leave everything else blank. After running it, reboot into normal mode.

If you still can't get it to run, please let me know when you post the OTL. log(s).

Thanks

Satchfan
I ran defogger, it said it was successful but didn't ask me to reboot
booted into safe mode and ran gmer with all unchecked except sections and C: .. it found nothing and produced an empty log file

here is OTL.txt taken in normal windows

OTL logfile created on: 08/09/2010 20:22:03 - Run 4
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Dave\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 42.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.32 Gb Total Space | 116.45 Gb Free Space | 40.39% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 124.70 Mb Total Space | 107.86 Mb Free Space | 86.50% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVE-LAPTOP
Current User Name: Dave
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Dave\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Acer Incorporated)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Dave\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Acer\Acer ePower Management\SysHook.dll (Acer Incorporated)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (NTI IScheduleSvc) – C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (HsfXAudioService) – C:\Windows\System32\XAudio32.dll (Conexant Systems, Inc.)
SRV - (NTISchedulerSvc) – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
SRV - (NTIBackupSvc) – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (Adobe Version Cue CS4) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)


========== Driver Services (SafeList) ==========

DRV - (upperdev) – C:\Windows\System32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (Revoflt) – C:\Windows\System32\drivers\revoflt.sys (VS Revo Group)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (NTIDrvr) – C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (RTHDMIAzAudService) – C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio32.sys (Conexant Systems, Inc.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (ahcix86s) – C:\Windows\system32\DRIVERS\ahcix86s.sys (Advanced Micro Devices, Inc)
DRV - (k57nd60x) Broadcom NetLink ™ – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (adfs) – C:\Windows\System32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (usbfilter) – C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices Inc.)
DRV - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (UBHelper) – C:\Windows\System32\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (UMPass) – C:\Windows\System32\drivers\umpass.sys (Microsoft Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (NSCIRDA) – C:\Windows\System32\drivers\nscirda.sys (National Semiconductor Corporation)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (FTDIBUS) – C:\Windows\System32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (FTSER2K) – C:\Windows\System32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (pgfilter) – C:\Program Files\PeerGuardian2\pgfilter.sys ()
DRV - (DKbFltr) – C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5536
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5536

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {A935FC84-352F-4017-9AE5-7D93536683DD}:1.9.1
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/25 06:28:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/25 06:28:19 | 000,000,000 | —D | M]

[2010/05/17 16:15:08 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Mozilla\Extensions
[2010/02/26 16:49:35 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/02/02 11:32:28 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/09/05 07:18:56 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\yktciq6t.default\extensions
[2010/05/23 18:09:13 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\yktciq6t.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/17 16:22:56 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\yktciq6t.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/05/17 16:14:43 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/01 17:56:49 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/01 17:56:50 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/01 17:56:50 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/01 17:56:50 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/08/20 15:44:09 | 000,417,791 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 14420 more lines…
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe Latest\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll (www.flashget.com)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (FlashGet GetFlash Class) - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll (www.flashget.com)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe Latest\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [wmsdk64_32.exe] C:\Users\Dave\AppData\Local\Temp\wmsdk64_32.exe File not found
O4 - HKCU..\Run: [wtbstawq] C:\Users\Dave\AppData\Local\pocmflcnd\bxkllemshdw.exe (Security Suites Corporation)
O4 - Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O8 - Extra context menu item: &Download; All with FlashGet - C:\Program Files\FlashGet\JC_ALL.HTM ()
O8 - Extra context menu item: &Download; with FlashGet - C:\Program Files\FlashGet\JC_LINK.HTM ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2FD395CB-BD93-4BA9-AA4B-D725754E20D1} http://player.portalarium.com/installers/w…ariumPlayer.cab (Portalarium Player Web Plugin)
O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.systemrequirementslab.co…eqlabdetect.cab (Reg Error: Key error.)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://fb.familylink.com/we_are_related/st…geUploader5.cab (Image Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} http://downloads.virginmedia.com/CST/ver1/vistainstaller.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/09/05 17:07:04 | 000,000,000 | RHSD | M] - F:\autorun.inf – [ FAT ]
O33 - MountPoints2\{588c7944-22e5-11df-a21e-001f16b25d8b}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O34 - HKLM BootExecute: (RwcLkRen C:\Windows\system32\RwcLkCfg) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/09/05 22:31:02 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/09/05 22:31:00 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/09/05 22:31:00 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/05 22:30:00 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Users\Dave\Desktop\mbam-setup-1.46.exe
[2010/09/05 17:11:31 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Dave\Desktop\OTL.exe
[2010/09/05 17:11:30 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Dave\Desktop\HiJackThis.exe
[2010/09/05 07:01:25 | 000,000,000 | —D | C] – C:\Users\Dave\AppData\Local\{A935FC84-352F-4017-9AE5-7D93536683DD}
[2010/09/05 06:58:44 | 000,000,000 | —D | C] – C:\Users\Dave\AppData\Local\pocmflcnd
[2010/09/04 17:58:30 | 000,000,000 | —D | C] – C:\ProgramData\xml_param
[2010/09/04 17:55:33 | 000,000,000 | —D | C] – C:\Users\Dave\Documents\iSkysoft MKV Converter
[2010/09/04 17:55:14 | 000,000,000 | —D | C] – C:\Program Files\iSkysoft
[2010/09/04 15:39:26 | 000,000,000 | —D | C] – C:\Users\Dave\AppData\Roaming\avidemux
[2010/09/04 15:34:01 | 000,000,000 | —D | C] – C:\Users\Dave\AppData\Roaming\Dr. DivX 2.0 OSS
[2010/09/03 17:45:56 | 000,000,000 | —D | C] – C:\Users\Dave\AppData\Roaming\vlc
[2010/09/03 17:43:18 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/09/03 07:46:34 | 000,000,000 | —D | C] – C:\Windows\System32\DefaultDirName
[2010/08/24 14:13:06 | 000,000,000 | —D | C] – C:\ProgramData\HipSoft
[2010/08/24 13:16:09 | 000,000,000 | —D | C] – C:\Windows\Build a lot 3 Passport to Europe
[2010/08/23 12:10:43 | 000,000,000 | —D | C] – C:\Program Files\PeerGuardian2
[2010/08/08 18:09:54 | 000,000,000 | —D | C] – C:\ProgramData\Ipswitch
[2010/08/08 17:08:56 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2010/08/07 22:23:30 | 000,000,000 | —D | C] – C:\Program Files\jv16 PowerTools 2007
[2010/07/24 19:23:27 | 000,000,000 | —D | C] – C:\Program Files\Lame for Audacity
[2010/07/18 18:27:12 | 000,000,000 | —D | C] – C:\Users\Dave\Documents\Tiger Woods PGA TOUR 08
[2010/07/18 18:11:20 | 000,438,272 | —- | C] (On2.com) – C:\Windows\System32\vp6vfw.dll
[2010/07/18 18:11:19 | 000,327,680 | —- | C] (On2.com Inc.) – C:\Windows\System32\vp6dec.ax
[2010/07/18 18:11:19 | 000,118,832 | —- | C] (MicroQuill Software Publishing, Inc.) – C:\Windows\System32\SHW32.DLL
[2010/07/15 07:36:16 | 000,000,000 | —D | C] – C:\Program Files\Virgin Media Ltd
[2010/06/27 18:58:32 | 000,000,000 | —D | C] – C:\Users\Dave\AppData\Roaming\Facebook
[2010/06/23 13:32:29 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2009/10/08 19:19:38 | 000,047,360 | —- | C] (VSO Software) – C:\Users\Dave\AppData\Roaming\pcouffin.sys
[2009/07/18 04:42:23 | 000,049,152 | —- | C] ( ) – C:\Windows\Interop.IWshRuntimeLibrary.dll
[2009/06/07 21:19:02 | 000,106,496 | —- | C] ( ) – C:\Windows\System32\VM_1.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/09/08 20:23:02 | 010,485,760 | -HS- | M] () – C:\Users\Dave\NTUSER.DAT
[2010/09/08 20:18:52 | 000,000,000 | —- | M] () – C:\Users\Dave\defogger_reenable
[2010/09/08 20:18:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/08 20:17:47 | 000,719,510 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/08 20:17:47 | 000,620,426 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/08 20:17:47 | 000,112,906 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/08 20:11:44 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/08 20:11:43 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/08 19:42:42 | 000,050,477 | —- | M] () – C:\Users\Dave\Desktop\Defogger.exe
[2010/09/08 07:18:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/06 22:11:37 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/06 22:11:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/06 22:04:34 | 000,363,520 | —- | M] () – C:\Users\Dave\Desktop\uSeRiNiT.exe
[2010/09/06 22:04:30 | 000,363,520 | —- | M] () – C:\Users\Dave\Desktop\WiNlOgOn.exe
[2010/09/06 22:04:24 | 000,363,520 | —- | M] () – C:\Users\Dave\Desktop\rkill.scr
[2010/09/06 22:04:18 | 000,363,520 | —- | M] () – C:\Users\Dave\Desktop\rkill.com
[2010/09/06 22:04:02 | 000,363,520 | —- | M] () – C:\Users\Dave\Desktop\rkill.exe
[2010/09/06 15:46:01 | 000,524,288 | -HS- | M] () – C:\Users\Dave\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/09/06 15:46:01 | 000,065,536 | -HS- | M] () – C:\Users\Dave\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/09/06 15:45:57 | 001,773,720 | -H– | M] () – C:\Users\Dave\AppData\Local\IconCache.db
[2010/09/06 14:30:14 | 000,294,400 | —- | M] () – C:\Users\Dave\Desktop\exeHelper.com
[2010/09/05 17:37:40 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Users\Dave\Desktop\mbam-setup-1.46.exe
[2010/09/05 16:50:08 | 000,359,929 | —- | M] () – C:\Users\Dave\Desktop\dds.scr
[2010/09/05 16:47:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Dave\Desktop\HiJackThis.exe
[2010/09/05 16:37:01 | 000,002,843 | —- | M] () – C:\Users\Dave\AppData\Local\Vmusigamewob.dat
[2010/09/05 16:32:50 | 000,293,376 | —- | M] () – C:\Users\Dave\Desktop\gmer.com
[2010/09/05 16:31:28 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Dave\Desktop\OTL.exe
[2010/09/05 15:54:31 | 000,001,356 | —- | M] () – C:\Users\Dave\AppData\Local\d3d9caps.dat
[2010/09/05 07:01:25 | 000,000,000 | —- | M] () – C:\Users\Dave\AppData\Local\Lnejipug.bin
[2010/09/05 05:56:05 | 008,294,400 | —- | M] () – C:\Users\Dave\Documents\My Money.mny
[2010/09/05 05:56:04 | 008,296,808 | R— | M] () – C:\Users\Dave\Documents\My Money Backup.mbf
[2010/09/04 19:26:11 | 000,026,112 | —- | M] () – C:\Users\Dave\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/03 16:47:20 | 000,001,057 | —- | M] () – C:\Users\Dave\AppData\Roaming\vso_ts_preview.xml
[2010/09/03 07:47:39 | 000,087,608 | —- | M] () – C:\Users\Dave\AppData\Roaming\inst.exe
[2010/09/03 07:47:39 | 000,047,360 | —- | M] (VSO Software) – C:\Users\Dave\AppData\Roaming\pcouffin.sys
[2010/09/03 07:47:39 | 000,007,887 | —- | M] () – C:\Users\Dave\AppData\Roaming\pcouffin.cat
[2010/09/03 07:47:39 | 000,001,144 | —- | M] () – C:\Users\Dave\AppData\Roaming\pcouffin.inf
[2010/08/29 13:31:05 | 000,000,637 | —- | M] () – C:\Users\Dave\Desktop\HM3.lnk
[2010/08/25 16:20:02 | 000,496,640 | —- | M] () – C:\Windows\System32\xvid.ax
[2010/08/20 15:44:09 | 000,417,791 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/08/18 09:24:18 | 000,000,845 | —- | M] () – C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk
[2010/08/17 11:01:00 | 000,000,045 | —- | M] () – C:\Windows\System32\initdebug.nfo
[2010/08/16 11:11:38 | 000,483,408 | —- | M] () – C:\Users\Dave\Desktop\Focus_ST225_Price_List_August_2010.pdf
[2010/08/11 15:24:43 | 002,498,344 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/08/07 22:23:42 | 000,000,023 | -HS- | M] () – C:\Windows\System32\adcefcdbf_r.dll
[2010/08/07 22:23:42 | 000,000,023 | —- | M] () – C:\Windows\System32\eeaaaaed_r.ocx
[2010/08/06 07:43:28 | 000,416,844 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100820-154408.backup
[2010/08/06 07:15:05 | 000,000,036 | —- | M] () – C:\Users\Dave\AppData\Local\housecall.guid.cache
[2010/07/29 14:14:30 | 000,471,552 | —- | M] () – C:\Users\Dave\Desktop\STOCshowsheet.doc
[2010/06/18 11:59:26 | 001,056,768 | —- | M] () – C:\Users\Dave\Documents\Time Card.accdb
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/08 20:18:52 | 000,000,000 | —- | C] () – C:\Users\Dave\defogger_reenable
[2010/09/08 20:16:46 | 000,050,477 | —- | C] () – C:\Users\Dave\Desktop\Defogger.exe
[2010/09/06 22:12:53 | 000,363,520 | —- | C] () – C:\Users\Dave\Desktop\uSeRiNiT.exe
[2010/09/06 22:12:52 | 000,363,520 | —- | C] () – C:\Users\Dave\Desktop\rkill.scr
[2010/09/06 22:12:52 | 000,363,520 | —- | C] () – C:\Users\Dave\Desktop\rkill.exe
[2010/09/06 22:12:51 | 000,363,520 | —- | C] () – C:\Users\Dave\Desktop\rkill.com
[2010/09/06 22:12:50 | 000,363,520 | —- | C] () – C:\Users\Dave\Desktop\WiNlOgOn.exe
[2010/09/06 15:15:48 | 000,294,400 | —- | C] () – C:\Users\Dave\Desktop\exeHelper.com
[2010/09/05 17:11:32 | 000,293,376 | —- | C] () – C:\Users\Dave\Desktop\gmer.com
[2010/09/05 17:11:29 | 000,359,929 | —- | C] () – C:\Users\Dave\Desktop\dds.scr
[2010/09/05 16:37:01 | 000,002,843 | —- | C] () – C:\Users\Dave\AppData\Local\Vmusigamewob.dat
[2010/09/05 07:01:25 | 000,000,000 | —- | C] () – C:\Users\Dave\AppData\Local\Lnejipug.bin
[2010/09/04 17:55:18 | 000,496,640 | —- | C] () – C:\Windows\System32\xvid.ax
[2010/08/29 13:31:05 | 000,000,637 | —- | C] () – C:\Users\Dave\Desktop\HM3.lnk
[2010/08/17 11:00:33 | 000,000,045 | —- | C] () – C:\Windows\System32\initdebug.nfo
[2010/08/16 11:11:37 | 000,483,408 | —- | C] () – C:\Users\Dave\Desktop\Focus_ST225_Price_List_August_2010.pdf
[2010/08/07 22:23:42 | 000,000,023 | -HS- | C] () – C:\Windows\System32\adcefcdbf_r.dll
[2010/08/07 22:23:42 | 000,000,023 | —- | C] () – C:\Windows\System32\eeaaaaed_r.ocx
[2010/08/06 07:15:05 | 000,000,036 | —- | C] () – C:\Users\Dave\AppData\Local\housecall.guid.cache
[2010/07/29 14:14:29 | 000,471,552 | —- | C] () – C:\Users\Dave\Desktop\STOCshowsheet.doc
[2010/06/23 13:18:57 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2010/06/23 13:18:57 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2010/06/23 13:18:57 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2010/03/27 15:18:53 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2010/03/15 18:30:40 | 000,000,098 | —- | C] () – C:\Windows\MSUTIL.INI
[2010/03/13 17:38:31 | 001,970,176 | —- | C] () – C:\Windows\System32\d3dx9.dll
[2009/12/23 17:13:12 | 000,028,672 | —- | C] () – C:\Windows\System32\nnr.dll
[2009/12/15 01:19:35 | 000,001,356 | —- | C] () – C:\Users\Dave\AppData\Local\d3d9caps.dat
[2009/10/15 08:02:39 | 000,023,888 | —- | C] () – C:\Users\Dave\AppData\Roaming\UserTile.png
[2009/10/11 17:20:02 | 000,000,036 | —- | C] () – C:\Windows\hdd.ini
[2009/10/11 07:25:48 | 000,009,728 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2009/10/09 00:46:53 | 000,026,112 | —- | C] () – C:\Users\Dave\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/08 19:20:36 | 000,001,057 | —- | C] () – C:\Users\Dave\AppData\Roaming\vso_ts_preview.xml
[2009/10/08 19:20:03 | 000,000,033 | —- | C] () – C:\Users\Dave\AppData\Roaming\pcouffin.log
[2009/10/08 19:19:38 | 000,087,608 | —- | C] () – C:\Users\Dave\AppData\Roaming\inst.exe
[2009/10/08 19:19:38 | 000,007,887 | —- | C] () – C:\Users\Dave\AppData\Roaming\pcouffin.cat
[2009/10/08 19:19:38 | 000,001,144 | —- | C] () – C:\Users\Dave\AppData\Roaming\pcouffin.inf
[2009/10/07 19:45:55 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/10/05 16:58:22 | 000,008,118 | —- | C] () – C:\Users\Dave\AppData\Local\MyWinLockerInstaller.txt-20091005.log
[2009/09/07 16:29:44 | 004,455,865 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2009/09/06 15:52:04 | 000,828,611 | —- | C] () – C:\Windows\System32\ff_x264.dll
[2009/09/02 21:23:04 | 000,183,296 | —- | C] () – C:\Windows\System32\ff_samplerate.dll
[2009/09/02 21:22:58 | 000,178,688 | —- | C] () – C:\Windows\System32\ff_libmad.dll
[2009/09/02 21:22:40 | 000,113,152 | —- | C] () – C:\Windows\System32\ff_unrar.dll
[2009/09/02 21:22:10 | 000,257,024 | —- | C] () – C:\Windows\System32\ff_libdts.dll
[2009/09/02 21:22:06 | 000,142,848 | —- | C] () – C:\Windows\System32\ff_liba52.dll
[2009/09/02 17:38:44 | 000,425,040 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2009/09/02 17:35:12 | 000,557,003 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2009/09/02 17:01:48 | 000,146,098 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2009/08/25 19:07:36 | 000,328,334 | —- | C] () – C:\Windows\System32\ff_kernelDeint.dll
[2009/07/18 04:21:45 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2009/07/17 21:19:42 | 000,000,033 | —- | C] () – C:\Windows\LaunApp.ini
[2009/07/17 21:13:56 | 000,000,091 | —- | C] () – C:\ProgramData\PS.log
[2009/07/17 21:00:54 | 000,000,074 | —- | C] () – C:\Windows\PidList.ini
[2009/06/02 18:11:26 | 000,098,304 | —- | C] () – C:\Windows\System32\ff_wmv9.dll
[2009/06/02 18:11:16 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2009/02/23 19:08:37 | 000,006,712 | —- | C] () – C:\ProgramData\ArcadeDeluxe2.log
[2009/02/21 01:26:15 | 000,872,448 | —- | C] () – C:\Windows\iconv.dll
[2009/02/21 01:26:15 | 000,743,424 | —- | C] () – C:\Windows\libxml2.dll
[2009/02/21 01:26:14 | 000,000,061 | —- | C] () – C:\Windows\Prelaunch.ini
[2009/02/21 01:26:14 | 000,000,028 | —- | C] () – C:\Windows\WisLangCode.ini
[2009/01/10 23:17:32 | 000,163,840 | —- | C] () – C:\Windows\System32\ts.dll
[2009/01/10 23:16:56 | 000,148,480 | —- | C] () – C:\Windows\System32\mkx.dll
[2009/01/10 23:16:50 | 000,108,032 | —- | C] () – C:\Windows\System32\avi.dll
[2009/01/10 23:16:14 | 000,141,312 | —- | C] () – C:\Windows\System32\mp4.dll
[2009/01/10 23:15:54 | 000,120,832 | —- | C] () – C:\Windows\System32\ogm.dll
[2009/01/10 23:15:44 | 000,159,744 | —- | C] () – C:\Windows\System32\mmfinfo.dll
[2009/01/10 23:15:32 | 000,102,400 | —- | C] () – C:\Windows\System32\avss.dll
[2009/01/10 23:15:28 | 000,246,784 | —- | C] () – C:\Windows\System32\dxr.dll
[2009/01/10 23:15:12 | 000,097,280 | —- | C] () – C:\Windows\System32\avs.dll
[2009/01/10 23:14:08 | 000,079,360 | —- | C] () – C:\Windows\System32\mkzlib.dll
[2009/01/10 23:14:06 | 000,023,552 | —- | C] () – C:\Windows\System32\mkunicode.dll
[2007/10/13 10:30:20 | 000,000,137 | —- | C] () – C:\Windows\System32\Registration.ini
[2007/07/10 18:10:12 | 000,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2004/07/10 19:55:38 | 000,252,416 | —- | C] () – C:\Windows\System32\wsiShared.dll
[1998/05/06 09:19:58 | 000,210,944 | —- | C] () – C:\Windows\System32\Msvcrt10.dll
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2009/11/20 18:52:38 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\abgx360
[2009/12/04 09:07:19 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\ACD Systems
[2009/02/23 18:45:04 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Acer GameZone Console
[2009/11/02 11:07:46 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Any DVD Converter Professional
[2010/09/03 19:14:40 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Any Video Converter Professional
[2010/09/04 15:50:32 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\avidemux
[2010/08/31 16:22:48 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\BitTorrent
[2010/03/08 13:39:23 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\com.adobe.ExMan
[2010/09/04 15:34:37 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Dr. DivX 2.0 OSS
[2010/06/27 18:58:34 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Facebook
[2009/10/08 15:05:08 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\FlashGet
[2010/05/31 18:41:24 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Grand Ages Rome
[2009/10/12 19:33:41 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\ImgBurn
[2010/09/02 06:25:10 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\MailWasherPro
[2010/03/18 08:53:19 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Mask Pro 3.0
[2010/08/07 22:12:49 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Newsbin
[2010/01/15 15:51:57 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Nokia
[2009/11/30 20:17:22 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\PC Suite
[2009/10/15 08:02:39 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\PeerNetworking
[2010/09/05 15:19:20 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\R-Wipe&Clean;
[2009/11/12 07:19:43 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Sports Interactive
[2010/06/01 13:59:16 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Spotify
[2009/11/22 06:56:08 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Systenance
[2010/02/26 16:49:34 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\TomTom
[2010/02/04 18:11:20 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Tropico 3
[2010/05/26 14:39:35 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Ubisoft
[2010/02/02 11:37:36 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Vivox
[2010/09/03 16:47:21 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Vso
[2009/10/05 18:47:07 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\Windows Live Writer
[2010/08/18 09:24:25 | 000,000,000 | —D | M] – C:\Users\Dave\AppData\Roaming\wsInspector
[2010/09/06 15:46:03 | 000,032,650 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/02/23 15:17:02 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT.rwc

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/03/01 23:15:14 | 000,002,576 | —- | M] () – C:\ASPI.LOG
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/02/06 00:25:41 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.1028.txt
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.1031.txt
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.1033.txt
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.1036.txt
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.1040.txt
[2009/09/11 17:16:42 | 000,009,558 | —- | M] () – C:\eula.1041.txt
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.1042.txt
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.1049.txt
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.2052.txt
[2009/09/11 17:16:42 | 000,020,716 | —- | M] () – C:\eula.3082.txt
[2009/09/11 17:16:42 | 000,000,586 | —- | M] () – C:\globdata.ini
[2009/09/11 17:22:34 | 000,592,208 | —- | M] (Microsoft Corporation) – C:\install.exe
[2009/09/11 17:16:42 | 000,000,659 | —- | M] () – C:\install.ini
[2009/09/11 17:22:40 | 000,032,096 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2009/09/11 17:22:40 | 000,053,072 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2009/09/11 17:22:36 | 000,047,456 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2009/09/11 17:22:38 | 000,053,600 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2009/09/11 17:22:38 | 000,052,064 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2009/09/11 17:22:36 | 000,037,728 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2009/09/11 17:22:36 | 000,036,192 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2009/09/11 17:22:40 | 000,049,488 | —- | M] (Корпорация Майкрософт) – C:\install.res.1049.dll
[2009/09/11 17:22:40 | 000,031,584 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2009/09/11 17:22:38 | 000,052,576 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/10/11 07:20:24 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/11 07:20:24 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/09/06 22:11:19 | 3398,881,280 | -HS- | M] () – C:\pagefile.sys
[2009/07/08 22:38:42 | 000,003,200 | -HS- | M] () – C:\Patch.rev
[2009/02/24 03:31:32 | 000,000,151 | RHS- | M] () – C:\Preload.rev
[2009/07/17 21:00:34 | 000,002,851 | —- | M] () – C:\RHDSetup.log
[2010/09/06 22:18:29 | 000,000,442 | —- | M] () – C:\rkill.log

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/07 19:53:50 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 04:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/09 00:48:05 | 000,000,350 | -HS- | M] () – C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/09/08 19:42:42 | 000,050,477 | —- | M] () – C:\Users\Dave\Desktop\Defogger.exe
[2010/09/05 16:47:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Dave\Desktop\HiJackThis.exe
[2010/09/05 17:37:40 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Users\Dave\Desktop\mbam-setup-1.46.exe
[2010/09/05 16:31:28 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Dave\Desktop\OTL.exe
[2010/09/06 22:04:02 | 000,363,520 | —- | M] () – C:\Users\Dave\Desktop\rkill.exe
[2010/09/06 22:04:34 | 000,363,520 | —- | M] () – C:\Users\Dave\Desktop\uSeRiNiT.exe
[2010/09/06 22:04:30 | 000,363,520 | —- | M] () – C:\Users\Dave\Desktop\WiNlOgOn.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-08 02:05:12

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:5C321E34
< End of report >
just run gmer again, in normal mode, all unchecked except sections and c:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-08 21:03:31
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Dave\AppData\Local\Temp\kxryipow.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8DC08000, 0x258606, 0xE8000020]

—- EOF - GMER 1.0.15 —-
Thanks for the logs Davecl. I have to look over the logs and get my response OK'd by an expert, so you are not likely to get a response this evening, (GMT), but I will reply as quickly as possible. Satchfan
Sorry for the delay Davecl

P2P - I see you have P2P software, (BitTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to infection. If your computer is infected, it likely contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information: Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel >> Add or Remove Programs.

Should you decide to keep it, please don’t use it until we have finished up here.


You do still have some issues with a “rogue” antivirus but we’ll get it cleaned up.


Update Java update and remove old versions.

Your version of Java is out of date. Older versions have vulnerabilities that malware can use to infect the system.

Please follow these steps to update Java components and remove older versions.• Click Start, Control Panel
• Double-click on the Java
• Click on the ‘Update’ tab and then on Update now.
• Still in the Java Control Panel, click on the General tab
• Under Temporary Internet Files, click the Settings button.
• Click on the Delete Files button. There are two options in the window to clear the cache – Leave BOTH of the following checked:
Applications and Applets
Trace and Log Files
• Click OK on Delete Temporary Files Window
• Click OK to leave the Temporary Files Window
• Click OK to leave the Java Control Panel

Next.

Please disable the following programs temporarily as they could interfere with the tools we are using:

Spybot - Search & Destroy’s TeaTimer
Spyware Guard
Windows Defender


See here for how to disable them


Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    C:\Users\Dave\AppData\Local\{A935FC84-352F-4017-9AE5-7D93536683DD}
    C:\Users\Dave\AppData\Local\pocmflcnd
    
    :file
    C:\Users\Dave\AppData\Local\Lnejipug.bin

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
    DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
    DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [] File not found
    O4 - HKCU..\Run: [wmsdk64_32.exe] C:\Users\Dave\AppData\Local\Temp\wmsdk64_32.exe File not found
    O4 - HKCU..\Run: [wtbstawq] C:\Users\Dave\AppData\Local\pocmflcnd\bxkllemshdw.exe (Security Suites Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
    O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.systemrequirementslab.co…eqlabdetect.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    O16 - DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} http://downloads.virginmedia.com/CST/ver1/vistainstaller.cab (Reg Error: Key error.)
    O33 - MountPoints2\{588c7944-22e5-11df-a21e-001f16b25d8b}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe – File not found
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092
    2010/08/06 07:43:28 | 000,416,844 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100820-154408.backup
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Logs to include in reply:

OTL.txt
SystemLook.txt


Let me know if there is any change in your computer’s behaviour.

Satchfan
I followed your instructions and successfully ran system look and the fix in OTL however these caused a lot of problems

the laptop was taking well over 5 mins to boot and when windows eventually appeared there were warnings that various services could not be started and i should study the event log.. when I tried to do this it told me that the event log service could not be started.
windows firewall would not run, windows defender would not run, i had no internet access because the wireless service could not be started.

I have had to do a system restore to the point of updating java and all now seems well

here is the sytem look .txt

SystemLook 04.09.10 by jpshortstuff
Log created at 06:42 on 10/09/2010 by Dave
Administrator - Elevation successful

========== dir ==========

C:\Users\Dave\AppData\Local\{A935FC84-352F-4017-9AE5-7D93536683DD} - Parameters: "(none)"

—Files—
chrome.manifest –a—- 122 bytes [06:01 05/09/2010] [06:01 05/09/2010]
install.rdf –a—- 764 bytes [06:01 05/09/2010] [06:01 05/09/2010]

—Folders—
chrome d—— [06:01 05/09/2010]

C:\Users\Dave\AppData\Local\pocmflcnd - Parameters: "(none)"

—Files—
None found.

—Folders—
None found.

========== file ==========

C:\Users\Dave\AppData\Local\Lnejipug.bin - File found and opened.
MD5: D41D8CD98F00B204E9800998ECF8427E
Created at 06:01 on 05/09/2010
Modified at 06:01 on 05/09/2010
Size: 0 bytes
Attributes: –a—-
No version information available.

-= EOF =-


and the OTL.txt from when i ran the fix as instructed

All processes killed
========== OTL ==========
Service NwlnkFwd stopped successfully!
Service NwlnkFwd deleted successfully!
File C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found not found.
Service NwlnkFlt stopped successfully!
Service NwlnkFlt deleted successfully!
File C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found not found.
Service IpInIp stopped successfully!
Service IpInIp deleted successfully!
File C:\Windows\System32\DRIVERS\ipinip.sys File not found not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wmsdk64_32.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wtbstawq not found.
File C:\Users\Dave\AppData\Local\pocmflcnd\bxkllemshdw.exe not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ deleted successfully.
Starting removal of ActiveX control {40F576AD-8680-4F9E-9490-99D069CD665F}
C:\Windows\Downloaded Program Files\sysreqlabdetect.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{40F576AD-8680-4F9E-9490-99D069CD665F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40F576AD-8680-4F9E-9490-99D069CD665F}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{40F576AD-8680-4F9E-9490-99D069CD665F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{40F576AD-8680-4F9E-9490-99D069CD665F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40F576AD-8680-4F9E-9490-99D069CD665F}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Starting removal of ActiveX control {FD0EBBED-0C42-4D0F-82DA-44399B5C420A}
C:\Windows\Downloaded Program Files\tb_download.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0EBBED-0C42-4D0F-82DA-44399B5C420A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD0EBBED-0C42-4D0F-82DA-44399B5C420A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{FD0EBBED-0C42-4D0F-82DA-44399B5C420A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD0EBBED-0C42-4D0F-82DA-44399B5C420A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{588c7944-22e5-11df-a21e-001f16b25d8b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{588c7944-22e5-11df-a21e-001f16b25d8b}\ not found.
File F:\InstallTomTomHOME.exe not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Dave\Desktop\cmd.bat deleted successfully.
C:\Users\Dave\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Dave
->Temp folder emptied: 1311666 bytes
->Temporary Internet Files folder emptied: 16234470 bytes
->Java cache emptied: 9196808 bytes
->FireFox cache emptied: 60820011 bytes
->Flash cache emptied: 24143 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41695 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 75 bytes

User: Mcx1
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 102295 bytes
->Flash cache emptied: 41695 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 90 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 84.00 mb


OTL by OldTimer - Version 3.2.11.0 log created on 09102010_064558

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


As I was now nearing the point of giving up and just formatting the system and reinstalling windows from scratch I also ran MBAM and here is what it found

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wtbstawq (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wmsdk64_32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Dave\AppData\Local\pocmflcnd\bxkllemshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
C:\Users\Dave\Desktop\uSeRiNiT.exe (Heuristics.Reserved.Word.Exploit) -> Not selected for removal.
C:\Users\Dave\Desktop\WiNlOgOn.exe (Heuristics.Reserved.Word.Exploit) -> Not selected for removal.


I am sorry for pre-empting you on that one but I was near the end of my tether
We now seem to be getting somewhere, the laptop is currently showing no symptoms of malware
Hi Davecl

Two of the files that MBAM found were two that were dealt with by OTL but have now been “restored”.

I think we’ll have to take a different approach.

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done
  • Right click on ComboFix.exe and select Run As Administrator then follow the prompts.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
hi, here is combofix' report

ComboFix 10-09-09.04 - Dave 11/09/2010 7:04.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2941.1908 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe
c:\users\Dave\AppData\Local\{A935FC84-352F-4017-9AE5-7D93536683DD}
c:\users\Dave\AppData\Local\{A935FC84-352F-4017-9AE5-7D93536683DD}\chrome.manifest
c:\users\Dave\AppData\Local\{A935FC84-352F-4017-9AE5-7D93536683DD}\chrome\content\_cfg.js
c:\users\Dave\AppData\Local\{A935FC84-352F-4017-9AE5-7D93536683DD}\chrome\content\overlay.xul
c:\users\Dave\AppData\Local\{A935FC84-352F-4017-9AE5-7D93536683DD}\install.rdf
c:\users\Dave\AppData\Roaming\inst.exe
c:\windows\system32\adcefcdbf_r.dll

.
((((((((((((((((((((((((( Files Created from 2010-08-11 to 2010-09-11 )))))))))))))))))))))))))))))))
.

2010-09-11 06:19 . 2010-09-11 06:19 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2010-09-11 06:19 . 2010-09-11 06:19 ——– d—–w- c:\users\Guest\AppData\Local\temp
2010-09-11 06:19 . 2010-09-11 06:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-09-10 13:42 . 2010-09-10 13:41 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-09-10 05:45 . 2010-09-10 05:45 ——– d—–w- C:\_OTL
2010-09-10 05:25 . 2010-09-10 05:25 ——– d—–w- c:\windows\Sun
2010-09-10 05:25 . 2010-09-10 05:25 ——– d—–w- c:\program files\Common Files\Java
2010-09-09 14:25 . 2010-09-10 15:05 ——– d—–w- c:\program files\SpywareBlaster
2010-09-05 21:31 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-05 21:31 . 2010-09-05 21:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-05 21:31 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-05 15:37 . 2010-09-05 15:37 2843 —-a-w- c:\users\Dave\AppData\Local\Vmusigamewob.dat
2010-09-05 06:01 . 2010-09-05 06:01 0 —-a-w- c:\users\Dave\AppData\Local\Lnejipug.bin
2010-09-05 05:58 . 2010-09-09 13:54 ——– d—–w- c:\users\Dave\AppData\Local\pocmflcnd
2010-09-04 16:58 . 2010-09-10 16:04 ——– d—–w- c:\programdata\xml_param
2010-09-04 16:55 . 2010-09-04 16:55 ——– d—–w- c:\program files\iSkysoft
2010-09-04 14:39 . 2010-09-04 14:50 ——– d—–w- c:\users\Dave\AppData\Roaming\avidemux
2010-09-04 14:34 . 2010-09-04 14:34 ——– d—–w- c:\users\Dave\AppData\Roaming\Dr. DivX 2.0 OSS
2010-09-03 16:45 . 2010-09-10 16:11 ——– d—–w- c:\users\Dave\AppData\Roaming\vlc
2010-09-03 16:43 . 2010-09-03 16:43 ——– d—–w- c:\program files\VideoLAN
2010-09-03 06:46 . 2010-09-03 06:46 ——– d—–w- c:\windows\system32\DefaultDirName
2010-09-02 18:49 . 2010-09-02 18:48 185640 —-a-w- c:\programdata\DivX\Setup\finishPlugin.dll
2010-09-02 18:49 . 2010-09-02 18:49 56765 —-a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-09-02 18:49 . 2010-09-02 18:49 56997 —-a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-09-02 18:49 . 2010-09-02 18:49 53600 —-a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-09-02 18:49 . 2010-09-02 18:49 57691 —-a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-09-02 18:49 . 2010-09-02 18:49 84063 —-a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe
2010-09-02 18:49 . 2010-09-02 18:49 54153 —-a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-09-02 18:48 . 2010-09-04 16:41 144696 —-a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-09-02 18:44 . 2010-09-02 18:48 1062184 —-a-w- c:\programdata\DivX\Setup\Resource.dll
2010-09-02 18:44 . 2010-09-01 17:37 850200 —-a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-09-02 18:43 . 2010-09-02 18:43 57054 —-a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe
2010-09-02 18:43 . 2010-09-02 18:43 54166 —-a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe
2010-09-02 18:43 . 2010-09-02 18:43 57532 —-a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe
2010-09-02 18:43 . 2010-09-02 18:43 56458 —-a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-09-02 18:43 . 2010-09-02 18:43 54174 —-a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe
2010-09-02 18:43 . 2010-09-02 18:43 54128 —-a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-09-02 18:42 . 2010-09-02 18:42 54644 —-a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-09-02 18:42 . 2010-09-02 18:42 54101 —-a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-09-02 18:42 . 2010-09-02 18:42 57409 —-a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-09-02 18:42 . 2010-09-02 18:42 52963 —-a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-09-02 18:42 . 2010-09-02 18:42 54073 —-a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-09-02 18:42 . 2010-09-02 18:42 56969 —-a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-08-24 13:13 . 2010-08-24 13:13 ——– d—–w- c:\programdata\HipSoft
2010-08-24 12:16 . 2010-08-24 12:16 ——– d—–w- c:\windows\Build a lot 3 Passport to Europe
2010-08-23 11:10 . 2010-08-23 11:14 ——– d—–w- c:\program files\PeerGuardian2
2010-08-16 11:40 . 2010-02-04 09:01 74072 —-a-w- c:\windows\system32\XAPOFX1_4.dll
2010-08-16 11:40 . 2010-02-04 09:01 528216 —-a-w- c:\windows\system32\XAudio2_6.dll
2010-08-16 11:40 . 2010-02-04 09:01 238936 —-a-w- c:\windows\system32\xactengine3_6.dll
2010-08-16 11:40 . 2010-02-04 09:01 22360 —-a-w- c:\windows\system32\X3DAudio1_7.dll
2010-08-16 11:40 . 2009-09-04 16:44 515416 —-a-w- c:\windows\system32\XAudio2_5.dll
2010-08-16 11:40 . 2009-09-04 16:44 238936 —-a-w- c:\windows\system32\xactengine3_5.dll
2010-08-16 11:40 . 2009-09-04 16:29 453456 —-a-w- c:\windows\system32\d3dx10_42.dll
2010-08-16 11:40 . 2009-09-04 16:29 235344 —-a-w- c:\windows\system32\d3dx11_42.dll
2010-08-16 11:40 . 2009-09-04 16:29 5501792 —-a-w- c:\windows\system32\d3dcsx_42.dll
2010-08-16 11:40 . 2009-09-04 16:29 1974616 —-a-w- c:\windows\system32\D3DCompiler_42.dll
2010-08-16 11:39 . 2009-09-04 16:29 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll
2010-08-16 11:39 . 2009-09-04 16:44 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2010-08-16 11:39 . 2008-07-31 09:41 238088 —-a-w- c:\windows\system32\xactengine3_2.dll
2010-08-16 11:39 . 2008-07-31 09:41 68616 —-a-w- c:\windows\system32\XAPOFX1_1.dll
2010-08-16 11:39 . 2008-07-31 09:40 509448 —-a-w- c:\windows\system32\XAudio2_2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-10 16:11 . 2010-06-27 17:58 ——– d—–w- c:\users\Dave\AppData\Roaming\Facebook
2010-09-10 16:11 . 2009-10-15 06:35 ——– d—–w- c:\users\Dave\AppData\Roaming\BitTorrent
2010-09-10 16:11 . 2009-10-11 16:36 ——– d—–w- c:\programdata\R-Wipe&Clean
2010-09-10 16:11 . 2009-10-05 19:48 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-09-10 15:06 . 2010-02-28 03:06 ——– d—–w- c:\users\Dave\AppData\Roaming\wsInspector
2010-09-10 13:14 . 2009-10-11 16:20 ——– d—–w- c:\users\Dave\AppData\Roaming\R-Wipe&Clean
2010-09-10 05:25 . 2009-10-12 14:39 ——– d—–w- c:\program files\Java
2010-09-08 19:38 . 2009-10-10 06:06 ——– d—–w- c:\program files\Microsoft Silverlight
2010-09-05 14:54 . 2009-12-15 00:19 1356 —-a-w- c:\users\Dave\AppData\Local\d3d9caps.dat
2010-09-04 14:37 . 2009-10-08 23:51 ——– d—–w- c:\program files\DivX
2010-09-03 18:14 . 2009-11-02 13:40 ——– d—–w- c:\users\Dave\AppData\Roaming\Any Video Converter Professional
2010-09-03 15:47 . 2009-10-08 18:19 ——– d—–w- c:\users\Dave\AppData\Roaming\Vso
2010-09-03 06:47 . 2009-10-08 18:19 ——– d—–w- c:\program files\VSO
2010-09-03 06:47 . 2009-10-08 18:19 47360 —-a-w- c:\users\Dave\AppData\Roaming\pcouffin.sys
2010-09-03 06:47 . 2009-10-08 18:19 47360 —-a-w- c:\users\Dave\AppData\Roaming\pcouffin.sys
2010-09-02 18:49 . 2010-08-08 16:16 57344 —-a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-09-02 18:49 . 2010-08-08 16:08 ——– d—–w- c:\programdata\DivX
2010-09-02 18:44 . 2009-10-08 23:51 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-09-02 05:25 . 2009-10-06 14:40 ——– d—–w- c:\users\Dave\AppData\Roaming\MailWasherPro
2010-08-23 16:44 . 2009-10-15 15:05 ——– d—–w- c:\programdata\Rosetta Stone
2010-08-17 01:07 . 2009-02-21 00:35 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-11 09:49 . 2009-02-23 17:45 ——– d—–w- c:\programdata\Microsoft Help
2010-08-11 09:47 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-08-08 17:09 . 2010-08-08 17:09 ——– d—–w- c:\programdata\Ipswitch
2010-08-08 16:54 . 2009-10-08 23:51 ——– d—–w- c:\users\Dave\AppData\Roaming\DivX
2010-08-07 21:26 . 2010-08-07 21:23 ——– d—–w- c:\program files\jv16 PowerTools 2007
2010-08-07 21:12 . 2010-03-14 04:50 ——– d—–w- c:\users\Dave\AppData\Roaming\Newsbin
2010-08-07 06:14 . 2009-10-05 15:06 ——– d—–w- c:\program files\Google
2010-07-25 06:11 . 2010-03-13 16:38 ——– d—–w- c:\program files\Cheat Engine
2010-07-24 18:23 . 2010-07-24 18:23 ——– d—–w- c:\program files\Lame for Audacity
2010-07-15 06:36 . 2010-07-15 06:36 ——– d—–w- c:\program files\Virgin Media Ltd
2010-06-29 15:47 . 2010-08-11 09:10 834048 —-a-w- c:\windows\system32\wininet.dll
2010-06-28 16:13 . 2010-08-11 09:10 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-06-27 17:58 . 2010-06-27 17:58 50354 —-a-w- c:\users\Dave\AppData\Roaming\Facebook\uninstall.exe
2010-06-23 05:25 . 2010-06-23 05:25 501936 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb7C71.tmp.exe
2010-06-21 13:37 . 2010-08-11 09:08 2037760 —-a-w- c:\windows\system32\win32k.sys
2010-06-18 17:31 . 2010-08-11 09:08 36864 —-a-w- c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-08-11 09:07 302080 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-11 09:07 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-11 09:07 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-03-18 61440]
"PLFSetI"="c:\windows\PLFSetI.exe" [2009-07-17 200704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-05 1410344]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-02-19 866824]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-04-03 698912]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-11 6957600]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-11 1833504]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2010-05-28 126976]

c:\users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0RwcLkRen c:\windows\system32\RwcLkCfg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Dave^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserChoice]
2010-02-12 10:32 293376 —-a-w- c:\windows\System32\browserchoice.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 06:39 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
2010-05-28 07:27 126976 —-a-w- c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyStartUp10.0]
2001-07-25 09:00 245810 —-a-w- c:\program files\Microsoft Money\System\Activation.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
2009-11-06 16:00 2090272 —-a-w- c:\program files\Nokia\Ovi Player\NokiaOviPlayer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2009-12-10 15:05 401728 —-a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-03-28 23:37 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 10:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 135664]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-02-16 3305708]
R3 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-04-11 61184]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
R3 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192]
R3 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-09-15 53328]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-04-03 723488]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2008-09-04 223232]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2008-05-28 22072]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HsfXAudioService REG_MULTI_SZ HsfXAudioService
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 19:29]

2010-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 19:29]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vp32&d=0709&m=aspire_5536
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:6092
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: {2FD395CB-BD93-4BA9-AA4B-D725754E20D1} - hxxp://player.portalarium.com/installers/win32/PortalariumPlayer.cab
DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} - hxxp://downloads.virginmedia.com/CST/ver1/vistainstaller.cab
FF - ProfilePath - c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\yktciq6t.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Web Platform Installer\NPWPIDetector.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Dave\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-BackRex Outlook Backup Demo - c:\progra~1\BACKRE~1\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-11 07:19
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-339857901-1859257069-4024874132-1000\Software\G*e*n*i*e*"!\FM Genie Scout 10]
"GameDir"="c:\\Users\\Dave\\Documents\\Sports Interactive\\Football Manager 2010\\games"
"ShortlistDir"="c:\\Users\\Dave\\Documents\\Sports Interactive\\Football Manager 2010\\shortlists"
"ScreenshotsDir"="c:\\Users\\Dave\\Documents\\Sports Interactive\\Football Manager 2010"
"SaveDir"="c:\\Users\\Dave\\Documents\\Sports Interactive\\Football Manager 2010\\"
"LangDB"=""
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000000
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="Steklo Black"
"LastUpdateCheck"=dword:00000000
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:0000006f
"UniqueID"="04-F345-2A33"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""

[HKEY_USERS\S-1-5-21-339857901-1859257069-4024874132-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30po\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 3.v30po"

[HKEY_USERS\S-1-5-21-339857901-1859257069-4024874132-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30pp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 3.v30pp"

[HKEY_USERS\S-1-5-21-339857901-1859257069-4024874132-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30ppf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 3.v30ppf"

[HKEY_USERS\S-1-5-21-339857901-1859257069-4024874132-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 3.xmp"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-09-11 07:25:33
ComboFix-quarantined-files.txt 2010-09-11 06:25

Pre-Run: 133,893,541,888 bytes free
Post-Run: 133,857,710,080 bytes free

- - End Of File - - 0C30C50ECE1EE8565F682BE41911DF9F

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI