This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

MS Internet Explorer 8 Problems

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Often when I double-click the MS IE desktop icon, nothing happens (hourglass shows briefly). So I go to my Start menu icon, click that MS IE icon, and nothing happens. So I go to Start/Programs, and it finally launches from there. Then suddenly, three-to-five MS IE windows appear on the desktop, sometimes as many as 15. Some of them open to my home page, some of them open to Google, some of them open to Bing. After they all finishing loading, I try to close all but one; some of them refuse to close. I can then open Task Manager, and in the Processes tab, it shows between five and 20 MS IE processes running, each using 5,000 to 74,000k of memory. I manually end all but one. But more appear mysteriously in the Processes tab, and I continue to try to end those. As I type this, I have two active MS IE browsers open, one MS IE browser that is blank but won't close, and nine MS IE showing as processes in Task Manager.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:34:54 AM, on 10/9/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
C:\DOCUME~1\Philip\LOCALS~1\Temp\INSTAL~1.EXE
C:\Program Files\Starfield\offSyncService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mdmcls32.exe
C:\WINDOWS\system32\svcprs32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\VISION~1\ONETOU~2.EXE
D:\Program Files\InCD\InCD.exe
C:\WINDOWS\system32\fpplock.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\CA\CA Internet Security Suite\casc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
G:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Starfield\StarfieldUpdate.exe
C:\Program Files\Starfield\wben.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Common Files\Sonic Shared\CineTray.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
G:\Philip\digiclok1.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00583593\Light\CAGlobalLight.exe
C:\WINDOWS\system32\sndvol32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
D:\Program Files\HijackThis\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.goodsearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
O2 - BHO: D - {3B5FA6BB-44C2-3FAB-841E-34FF02CCF37D} - C:\WINDOWS\system32\tv53423.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00583593\Toolbar\CallingIDIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00583593\Toolbar\CallingIDIE.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~1\ONETOU~2.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] D:\Program Files\InCD\InCD.exe
O4 - HKLM\..\Run: [ImageDrive.exe] D:\Program Files\ahead\ImageDrive\ImageDrive.exe
O4 - HKLM\..\Run: [Warning: do not remove it!] fpplock.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\casc.exe"
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Bing Bar] "C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [PPWebCap] d:\PROGRA~1\PPWebCap.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "G:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Starfield Updater] "C:\Program Files\Starfield\StarfieldUpdate.exe"
O4 - HKCU\..\Run: [wben] "C:\Program Files\Starfield\wben.exe"
O4 - Startup: Check for OneTouch Updates.lnk = C:\Program Files\Visioneer OneTouch\WiseUpdt.exe
O4 - Startup: MS Outlook.lnk = ?
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Shortcut to digiclok1.lnk = G:\Philip\digiclok1.exe
O4 - Startup: Volume.lnk = C:\WINDOWS\system32\sndvol32.exe
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Web-Based Email Tools - http://email01.secureserver.net/Download.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://supportcenter.timewarnercable.com/s…oad/tgctlcm.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1250018558546
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1250019801421
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} (Image Uploader Control) - http://www.hebphoto.com/NET/Uploader/LPUploader57.cab
O18 - Protocol: callingid - {086D03BA-57AC-4C8E-A33D-0BAABF742411} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00583593\Toolbar\CallingIDToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: CaCCProvSP - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
O23 - Service: CA Common Scheduler Service (ccSchedulerSVC) - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
O23 - Service: Cisco Systems, Inc. Installer service (CiscoVpnInstallService) - Unknown owner - C:\DOCUME~1\Philip\LOCALS~1\Temp\INSTAL~1.EXE
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: File Backup Service (File Backup) - Starfield Technologies, Inc. - C:\Program Files\Starfield\offSyncService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: WinSock Extention Manager (WinExtManager) - Unknown owner - C:\WINDOWS\system32\mdmcls32.exe
O23 - Service: WinSock Svchost Manager (WinSvchostManager) - Unknown owner - C:\WINDOWS\system32\svcprs32.exe

–
End of file - 13648 bytes
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Scan With RootKitUnHooker

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x000040fd Kernel Drivers (total 136): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806D0000 \WINDOWS\system32\hal.dll 0xBA5A8000 \WINDOWS\system32\KDCOM.DLL 0xBA4B8000 \WINDOWS\system32\BOOTVID.dll 0xB9F79000 ACPI.sys 0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xB9F68000 pci.sys 0xBA0A8000 isapnp.sys 0xBA670000 pciide.sys 0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xBA0B8000 MountMgr.sys 0xB9F49000 ftdisk.sys 0xBA330000 PartMgr.sys 0xBA0C8000 VolSnap.sys 0xB9F31000 atapi.sys 0xB9F17000 nvata.sys 0xBA0D8000 imagedrv.sys 0xB9EFF000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS 0xBA0E8000 disk.sys 0xBA0F8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xB9EDF000 fltmgr.sys 0xB9ECD000 sr.sys 0xB9E9C000 KmxAMRT.sys 0xBA5AC000 BsStor.sys 0xBA108000 PxHelp20.sys 0xB9E85000 KSecDD.sys 0xB9E72000 WudfPf.sys 0xB9DE5000 Ntfs.sys 0xB9DB8000 NDIS.sys 0xB9D9E000 Mup.sys 0xB9D7D000 kmxstart.sys 0xBA198000 \SystemRoot\system32\DRIVERS\AmdK8.sys 0xBA438000 \SystemRoot\system32\DRIVERS\fdc.sys 0xBA1A8000 \SystemRoot\system32\DRIVERS\serial.sys 0xB96F8000 \SystemRoot\system32\DRIVERS\serenum.sys 0xB958C000 \SystemRoot\system32\DRIVERS\parport.sys 0xBA440000 \SystemRoot\system32\DRIVERS\usbohci.sys 0xB9568000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xBA448000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xB9540000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xBA1B8000 \SystemRoot\system32\DRIVERS\nvnetbus.sys 0xB9465000 \SystemRoot\system32\DRIVERS\NVNRM.SYS 0xBA1C8000 \SystemRoot\system32\DRIVERS\imapi.sys 0xBA1D8000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xBA1E8000 \SystemRoot\system32\DRIVERS\redbook.sys 0xB9442000 \SystemRoot\system32\DRIVERS\ks.sys 0xB907A000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xB9066000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xBA5DE000 \SystemRoot\system32\DRIVERS\DisplayLinkFilter.sys 0xBA450000 \SystemRoot\system32\DRIVERS\DisplayLinkmirrorport.sys 0xBA460000 \SystemRoot\system32\DRIVERS\DisplayLinkGAport.sys 0xBA6A2000 \SystemRoot\system32\DRIVERS\audstub.sys 0xBA5E0000 \SystemRoot\System32\Drivers\RootMdm.sys 0xBA470000 \SystemRoot\System32\Drivers\Modem.SYS 0xBA1F8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xB96F0000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xB904F000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xBA208000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xBA218000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xBA478000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xB903E000 \SystemRoot\system32\DRIVERS\psched.sys 0xBA228000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xB9028000 \SystemRoot\System32\DRIVERS\kmxagent.sys 0xB8FEA000 \SystemRoot\System32\DRIVERS\kmxcfg.sys 0xBA490000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xBA498000 \SystemRoot\system32\DRIVERS\raspti.sys 0xBA248000 \SystemRoot\system32\DRIVERS\termdd.sys 0xBA4A0000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xBA4A8000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xBA5E4000 \SystemRoot\system32\DRIVERS\swenum.sys 0xB8F8C000 \SystemRoot\system32\DRIVERS\update.sys 0xBA53C000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xB9600000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xBA388000 \SystemRoot\system32\DRIVERS\flpydisk.sys 0xB95D0000 \SystemRoot\system32\DRIVERS\NVENETFD.sys 0xB95C0000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xBA5F8000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xB5B69000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xB5B45000 \SystemRoot\system32\drivers\portcls.sys 0xBA288000 \SystemRoot\system32\drivers\drmk.sys 0xBA168000 \SystemRoot\System32\DRIVERS\KmxFile.sys 0xB55A9000 \SystemRoot\System32\DRIVERS\kmxfw.sys 0xBA62A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xBA6CE000 \SystemRoot\System32\Drivers\Null.SYS 0xBA62C000 \SystemRoot\System32\Drivers\Beep.SYS 0xBA3E8000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xBA3F0000 \SystemRoot\System32\drivers\vga.sys 0xBA62E000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xBA630000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xBA3F8000 \SystemRoot\System32\Drivers\Msfs.SYS 0xBA400000 \SystemRoot\System32\Drivers\Npfs.SYS 0xB9D39000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xB554E000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xB54F5000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xB54CD000 \SystemRoot\system32\DRIVERS\netbt.sys 0xB9708000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xB54AB000 \SystemRoot\System32\drivers\afd.sys 0xBA238000 \SystemRoot\system32\DRIVERS\netbios.sys 0xB5480000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xB5410000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xB65D5000 \SystemRoot\System32\Drivers\Fips.SYS 0xB53EA000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xB65C5000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xB5A22000 \SystemRoot\system32\DRIVERS\DisplayLinkUsbPort_5.2.22617.0.sys 0xB5A12000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xB5A0A000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xB5AA2000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xBA188000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xB5A9A000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xB5585000 \SystemRoot\system32\DRIVERS\usbscan.sys 0xB5581000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xA7B92000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xA7B78000 \SystemRoot\System32\Drivers\dump_nvata.sys 0xA9CA9000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xA952D000 \SystemRoot\System32\drivers\Dxapi.sys 0xA92F3000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xBA6B5000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xA2895000 \SystemRoot\System32\DRIVERS\KmxSbx.sys 0xA284D000 \SystemRoot\System32\Drivers\BsUDF.SYS 0xA9519000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xBF45C000 \SystemRoot\System32\DisplayLinkGAdisp.dll 0x9FE30000 \SystemRoot\system32\drivers\wdmaud.sys 0xA2645000 \SystemRoot\system32\drivers\sysaudio.sys 0x9FCED000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA26E5000 \??\C:\WINDOWS\system32\MLPTDR_C.SYS 0xB1913000 \SystemRoot\System32\Drivers\ParVdm.SYS 0x9F8C6000 \SystemRoot\System32\DRIVERS\KmxCF.sys 0x9F81E000 \SystemRoot\system32\DRIVERS\srv.sys 0x9FA15000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xA2821000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0x8A65E000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 80): 0 System Idle Process 4 System 600 C:\WINDOWS\system32\smss.exe 648 csrss.exe 672 C:\WINDOWS\system32\winlogon.exe 716 C:\WINDOWS\system32\services.exe 728 C:\WINDOWS\system32\lsass.exe 956 C:\WINDOWS\system32\svchost.exe 1020 svchost.exe 1144 C:\WINDOWS\system32\svchost.exe 1176 C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe 1332 C:\WINDOWS\system32\svchost.exe 1344 C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe 1500 svchost.exe 1664 svchost.exe 1748 C:\WINDOWS\system32\LEXBCES.EXE 1792 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe 1800 C:\WINDOWS\system32\LEXPPS.EXE 1908 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe 1932 C:\WINDOWS\system32\spoolsv.exe 1972 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe 284 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe 596 C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe 160 svchost.exe 224 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe 232 C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe 584 C:\DOCUME~1\Philip\LOCALS~1\Temp\INSTAL~1.EXE 1248 C:\Program Files\Starfield\offSyncService.exe 1480 C:\WINDOWS\explorer.exe 1616 C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe 1644 C:\Program Files\Java\jre6\bin\jqs.exe 2132 C:\WINDOWS\system32\nvsvc32.exe 2148 C:\WINDOWS\system32\HPZipm12.exe 2292 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2560 C:\WINDOWS\system32\svchost.exe 2668 C:\WINDOWS\system32\mdmcls32.exe 2980 C:\WINDOWS\system32\svcprs32.exe 3032 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 3264 C:\WINDOWS\system32\searchindexer.exe 3464 wmiprvse.exe 3952 C:\WINDOWS\system32\rundll32.exe 4036 C:\WINDOWS\RTHDCPL.EXE 4084 C:\PROGRA~1\VISION~1\ONETOU~2.EXE 120 D:\Program Files\InCD\InCD.exe 652 C:\WINDOWS\system32\fpplock.exe 776 D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe 1096 C:\Program Files\DivX\DivX Update\DivXUpdate.exe 1548 C:\Program Files\CA\CA Internet Security Suite\casc.exe 2324 C:\Program Files\Common Files\Java\Java Update\jusched.exe 3020 C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe 1200 C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe 2764 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 2868 alg.exe 4160 G:\Program Files\Yahoo!\Messenger\YahooMessenger.exe 4208 C:\Program Files\Starfield\starfieldupdate.exe 4556 C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe 4932 C:\Program Files\Common Files\Sonic Shared\CineTray.exe 5080 C:\Program Files\Windows Desktop Search\WindowsSearch.exe 5708 D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE 5856 G:\Philip\digiclok1.exe 5616 C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00583593\Light\CAGlobalLight.exe 4628 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE 6612 C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe 16252 C:\Program Files\Internet Explorer\iexplore.exe 6652 C:\Program Files\Internet Explorer\iexplore.exe 19276 C:\Program Files\Internet Explorer\iexplore.exe 18604 C:\Program Files\Internet Explorer\iexplore.exe 26100 C:\Program Files\Internet Explorer\iexplore.exe 21388 C:\Program Files\Internet Explorer\iexplore.exe 25752 C:\Program Files\Internet Explorer\iexplore.exe 24396 C:\Program Files\Internet Explorer\iexplore.exe 15352 C:\Program Files\Internet Explorer\iexplore.exe 17900 C:\Program Files\Internet Explorer\iexplore.exe 24700 C:\Program Files\Internet Explorer\iexplore.exe 22512 C:\Program Files\Internet Explorer\iexplore.exe 18476 D:\Program Files\Microsoft Office\Office12\WINWORD.EXE 20768 C:\WINDOWS\system32\searchprotocolhost.exe 18884 searchfilterhost.exe 13732 C:\WINDOWS\system32\searchprotocolhost.exe 25304 C:\Documents and Settings\Philip\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive2 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive2 at offset 0x00000012`8e2db000 (NTFS) \\.\F: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (FAT32) \\.\G: –> \\.\PhysicalDrive1 at offset 0x00000000`007e0000 (FAT32) PhysicalDrive2 Model Number: ST3160815SV, Rev: 3.ACF PhysicalDrive0 Model Number: WDCAC22100H, Rev: 10.07H09 PhysicalDrive1 Model Number: WDCWD300BB-00AUA1, Rev: 18.20D18 Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive2 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A 1 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A 27 GB \\.\PhysicalDrive1 Unknown MBR code SHA1: 8A0E02C7832219AB72B05103E2358F311B29AD17 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
DDS (Ver_10-10-21.02) - NTFSx86 Run by [removed] at 10:57:18.82 on Sat 10/23/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1983.501 [GMT -5:00] AV: CA Anti-Virus Plus *On-access scanning enabled* (Updated) {6B98D35F-BB76-41C0-876B-A50645ED099A} FW: CA Personal Firewall *disabled* {38102F93-1B6E-4922-90E1-A35D8DC6DAA3} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe svchost.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe C:\DOCUME~1\Philip\LOCALS~1\Temp\INSTAL~1.EXE C:\Program Files\Starfield\offSyncService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\mdmcls32.exe C:\WINDOWS\system32\svcprs32.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\VISION~1\ONETOU~2.EXE D:\Program Files\InCD\InCD.exe C:\WINDOWS\system32\fpplock.exe D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\CA\CA Internet Security Suite\casc.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe G:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\Starfield\StarfieldUpdate.exe C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe C:\Program Files\Common Files\Sonic Shared\CineTray.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE G:\Philip\digiclok1.exe C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00583593\Light\CAGlobalLight.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe D:\Program Files\Microsoft Office\Office12\WINWORD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Documents and Settings\Philip\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.goodsearch.com/ uSearch Page = hxxp://www.google.com uWindow Title = Internet Explorer, optimized for Bing and MSN uDefault_Page_URL = hxxp://www.msn.com uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: D: {3b5fa6bb-44c2-3fab-841e-34ff02ccf37d} - c:\windows\system32\tv53423.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: CA Toolbar Helper: {fbf2401b-7447-4727-be5d-c19b2075ca84} - c:\program files\ca\ca internet security suite\ca website inspector\1.2.1.24.00583593\toolbar\CallingIDIE.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: CA Toolbar: {10134636-e7af-4ac5-a1dc-c7c44bb97d81} - c:\program files\ca\ca internet security suite\ca website inspector\1.2.1.24.00583593\toolbar\CallingIDIE.dll TB: @c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [PPWebCap] d:\progra~1\PPWebCap.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Messenger (Yahoo!)] "g:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [Starfield Updater] "c:\program files\starfield\StarfieldUpdate.exe" uRun: [wben] "c:\program files\starfield\wben.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [OneTouch Monitor] c:\progra~1\vision~1\ONETOU~2.EXE mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe mRun: [InCD] d:\program files\incd\InCD.exe mRun: [ImageDrive.exe] d:\program files\ahead\imagedrive\ImageDrive.exe mRun: [Warning: do not remove it!] fpplock.exe mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [cctray] "c:\program files\ca\ca internet security suite\casc.exe" mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "d:\program files\qttask.exe" -atboottime mRun: [Bing Bar] "c:\program files\msn toolbar\platform\5.0.1449.0\mswinext.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [CarboniteSetupLite] "c:\program files\carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=1800 StartupFolder: c:\docume~1\philip\startm~1\programs\startup\checkf~1.lnk - c:\program files\visioneer onetouch\WiseUpdt.exe StartupFolder: c:\docume~1\philip\startm~1\programs\startup\msoutl~1.lnk - c:\windows\installer\{91120000-0030-0000-0000-0000000ff1ce}\outicon.exe StartupFolder: c:\docume~1\philip\startm~1\programs\startup\onenot~1.lnk - d:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\philip\startm~1\programs\startup\shortc~1.lnk - g:\philip\digiclok1.exe StartupFolder: c:\docume~1\philip\startm~1\programs\startup\volume.lnk - c:\windows\system32\sndvol32.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nikonm~1.lnk - c:\program files\common files\nikon\monitor\NkMonitor.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sonicc~1.lnk - c:\program files\common files\sonic shared\CineTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office11\REFIEBAR.DLL LSP: c:\windows\system32\winsflt.dll LSP: c:\windows\system32\VetRedir.dll DPF: Web-Based Email Tools - hxxp://email01.secureserver.net/Download.CAB DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://supportcenter.timewarnercable.com/sdccommon/download/tgctlcm.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250018558546 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1250019801421 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} - hxxp://www.hebphoto.com/NET/Uploader/LPUploader57.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: callingid - {086D03BA-57AC-4C8E-A33D-0BAABF742411} - c:\program files\ca\ca internet security suite\ca website inspector\1.2.1.24.00583593\toolbar\CallingIDToolbar.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: PFW - UmxWnp.Dll AppInit_DLLs: UmxSbxExw.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: ShellHook Class: {1869181a-9f50-4fcf-8bff-1b8588ecb85c} - c:\program files\ca\ca internet security suite\ca website inspector\1.2.1.24.00583593\linkadvisor\CIDLinkAdvisor.dll IFEO: ctfmon.exe - c:\windows\system32\ctfmonvuu.exe ============= SERVICES / DRIVERS =============== R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2009-5-9 8040] R0 KmxAMRT;KmxAMRT;c:\windows\system32\drivers\KmxAMRT.sys [2009-12-23 132088] R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2009-6-8 108024] R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2009-12-23 78840] R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2009-9-2 53240] R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2009-6-8 115704] R2 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [2009-5-9 294784] R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus plus\isafe.exe [2010-9-12 212992] R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\ca\ca internet security suite\ccschedulersvc.exe [2010-9-12 206160] R2 DisplayLinkService;DisplayLinkManager;c:\program files\displaylink core software\DisplayLinkManager.exe [2009-12-8 4719976] R2 File Backup;File Backup Service;c:\program files\starfield\offSyncService.exe [2010-7-16 1310960] R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2009-8-14 145912] R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2009-9-30 60920] R2 MLPTDR_C;MLPTDR_C;c:\windows\system32\MLPTDR_C.SYS [2002-7-2 19296] R2 UmxAgent;HIPS Event Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxAgent.exe [2009-8-4 887288] R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\ca\sharedcomponents\hipsengine\UmxCfg.exe [2009-7-13 760664] R2 UmxPol;HIPS Policy Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxPol.exe [2009-7-27 227832] R2 WinExtManager;WinSock Extention Manager;c:\windows\system32\mdmcls32.exe [2010-9-12 2347760] R2 WinSvchostManager;WinSock Svchost Manager;c:\windows\system32\svcprs32.exe [2010-9-12 1377008] R3 DisplayLinkFilter;DisplayLinkFilter;c:\windows\system32\drivers\DisplayLinkFilter.sys [2009-12-8 7040] R3 DisplayLinkGA;DisplayLinkGA;c:\windows\system32\drivers\DisplayLinkGAport.sys [2009-12-8 27776] R3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [2009-12-8 24320] R3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\drivers\DisplayLinkUsbPort_5.2.22617.0.sys [2010-3-25 21888] R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2009-9-30 239608] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-9-6 136176] S3 KmxAMVet;KmxAMVet;c:\windows\system32\drivers\KmxAMVet.sys [2009-3-27 598656] =============== Created Last 30 ================ 2010-10-19 22:20:49 ——– dc—-w- c:\program files\Carbonite 2010-10-16 02:03:33 0 -c–a-w- C:\V2T232.tmp 2010-10-16 02:01:11 0 -c–a-w- C:\V2T22E.tmp 2010-10-16 01:58:17 0 -c–a-w- C:\V2T225.tmp 2010-10-13 00:17:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll 2010-10-13 00:17:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll 2010-10-13 00:17:43 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll 2010-10-09 14:32:54 388096 -c–a-r- c:\docume~1\philip\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2010-10-09 02:48:00 605696 -c–a-w- c:\windows\system32\getuname.dll 2010-10-09 02:48:00 605696 -c–a-w- c:\windows\system32\dllcache\getuname.dll 2010-10-09 02:47:59 80384 -c–a-w- c:\windows\system32\dllcache\charmap.exe 2010-10-09 02:47:59 80384 -c–a-w- c:\windows\system32\charmap.exe 2010-10-09 02:47:58 114688 -c–a-w- c:\windows\system32\dllcache\calc.exe 2010-10-09 02:47:58 114688 -c–a-w- c:\windows\system32\calc.exe 2010-10-09 02:25:59 ——– dc-h–w- c:\windows\ie8 2010-10-09 02:25:21 ——– dc—-w- c:\program files\Microsoft 2010-10-09 02:25:18 ——– dc—-w- c:\program files\MSN Toolbar 2010-10-09 02:24:50 ——– dc—-w- c:\program files\Bing Bar Installer 2010-10-09 02:24:08 ——– dc-h–w- c:\windows\msdownld.tmp 2010-10-09 02:21:47 13312 -c—-w- c:\windows\system32\dllcache\iecompat.dll ==================== Find3M ==================== 2010-09-19 21:44:04 258048 -c–a-w- c:\windows\system32\tv53423.dll 2010-09-18 17:23:26 974848 -c–a-w- c:\windows\system32\mfc42u.dll 2010-09-18 06:53:25 974848 -c–a-w- c:\windows\system32\mfc42.dll 2010-09-18 06:53:25 954368 -c–a-w- c:\windows\system32\mfc40.dll 2010-09-18 06:53:25 953856 -c–a-w- c:\windows\system32\mfc40u.dll 2010-09-15 09:50:37 472808 -c–a-w- c:\windows\system32\deployJava1.dll 2010-09-15 07:29:49 73728 -c–a-w- c:\windows\system32\javacpl.cpl 2010-09-12 16:46:40 7 -c–a-w- c:\windows\system32\mkghj.dll 2010-09-12 16:45:36 5845744 -c–a-w- c:\windows\system32\win32cpr.dll 2010-09-12 16:45:35 1872624 -c–a-w- c:\windows\system32\winsflt.dll 2010-09-10 05:58:08 916480 -c–a-w- c:\windows\system32\wininet.dll 2010-09-10 05:58:06 43520 -c–a-w- c:\windows\system32\licmgr10.dll 2010-09-10 05:58:06 1469440 -c—-w- c:\windows\system32\inetcpl.cpl 2010-09-08 16:17:46 94208 -c–a-w- c:\windows\system32\QuickTimeVR.qtx 2010-09-08 16:17:46 69632 -c–a-w- c:\windows\system32\QuickTime.qts 2010-09-01 11:51:14 285824 -c–a-w- c:\windows\system32\atmfd.dll 2010-08-31 13:42:52 1852800 -c–a-w- c:\windows\system32\win32k.sys 2010-08-27 08:02:29 119808 -c–a-w- c:\windows\system32\t2embed.dll 2010-08-27 05:57:43 99840 -c–a-w- c:\windows\system32\srvsvc.dll 2010-08-26 12:52:45 5120 -c–a-w- c:\windows\system32\xpsp4res.dll 2010-08-23 16:12:04 617472 -c–a-w- c:\windows\system32\comctl32.dll 2010-08-17 13:17:06 58880 -c–a-w- c:\windows\system32\spoolsv.exe 2010-08-16 08:45:00 590848 -c–a-w- c:\windows\system32\rpcrt4.dll 2003-12-07 04:12:54 121856 -csha-w- c:\windows\system32\fpplock.exe ============= FINISH: 10:59:08.73 ===============

Attachments:

were you able to run the Rootkit Unhooker program as well?

Yes, I just now ran that.
Note: It did not prompt to select disks to scan.
Results:
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows XP
Version 5.1.2600 (Service Pack 3)
Number of processors #1
==============================================
>Drivers
==============================================
0xB5B69000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 5128192 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver)
0xBF012000 C:\WINDOWS\System32\nv4_disp.dll 4497408 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 91.63 )
0xB907A000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 3964928 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 91.63 )
0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2066816 bytes (Microsoft Corporation, NT Kernel & System)
0x804D7000 PnpManager 2066816 bytes
0x804D7000 RAW 2066816 bytes
0x804D7000 WMIxWDM 2066816 bytes
0xBF800000 Win32k 1855488 bytes
0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0xB9465000 C:\WINDOWS\system32\DRIVERS\NVNRM.SYS 897024 bytes (NVIDIA Corporation, NVIDIA Network Resource Manager.)
0xB9DE5000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
0xB5410000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xB8F8C000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)
0xB54F5000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
0x9F81E000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver)
0xA284D000 C:\WINDOWS\System32\Drivers\BsUDF.SYS 294912 bytes (ahead software, UDF File System Driver (WindowsNT5.x))
0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0xB8FEA000 C:\WINDOWS\System32\DRIVERS\kmxcfg.sys 253952 bytes (CA, HIPS Kernel Configuration Cache)
0xB9E9C000 KmxAMRT.sys 200704 bytes (CA, CA Antivirus File System Filter Driver for XP/2003)
0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
0x9FCED000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xB9DB8000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
0x8B31E000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
0xB5480000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0xB9540000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a)
0xB54CD000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
0x9F8C6000 C:\WINDOWS\System32\DRIVERS\KmxCF.sys 159744 bytes (CA, HIPS Content Filter Driver)
0xB53EA000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)
0xA7B92000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver)
0xB5B45000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0xB9568000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0xB9442000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
0xB54AB000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0xB9D7D000 kmxstart.sys 135168 bytes (CA, HIPS Core Driver)
0x806D0000 ACPI_HAL 131840 bytes
0x806D0000 C:\WINDOWS\system32\hal.dll 131840 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0xB9EDF000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0xB55A9000 C:\WINDOWS\System32\DRIVERS\kmxfw.sys 131072 bytes (CA, HIPS Firewall Driver)
0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
0xA7B78000 C:\WINDOWS\System32\Drivers\dump_nvata.sys 106496 bytes
0xB9D9E000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0xB9F17000 nvata.sys 106496 bytes (NVIDIA Corporation, NVIDIA® nForce™ IDE Performance Driver)
0xB9F31000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
0xB9EFF000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver)
0xB9E85000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xB904F000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0xB9028000 C:\WINDOWS\System32\DRIVERS\kmxagent.sys 90112 bytes (CA, HIPS Agent Driver)
0x9FE30000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
0xB958C000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver)
0xB9066000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
0xB554E000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
0xB9E72000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
0xA2895000 C:\WINDOWS\System32\DRIVERS\KmxSbx.sys 73728 bytes (CA, HIPS Registry, Spawning and Devices Guard driver)
0xB9ECD000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xB903E000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
0x9FA15000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xBA1D8000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xBA168000 C:\WINDOWS\System32\DRIVERS\KmxFile.sys 65536 bytes (CA, HIPS File Guard driver)
0xBA1A8000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)
0xBA288000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xB95D0000 C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 61440 bytes (NVIDIA Corporation, NVIDIA Networking Function Driver.)
0xBA1E8000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)
0xA2645000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
0xB95C0000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
0xBA198000 C:\WINDOWS\system32\DRIVERS\AmdK8.sys 57344 bytes (Advanced Micro Devices, AMD Processor Driver)
0xBA0F8000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
0xBA1F8000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xBA0C8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xBA218000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0xB65D5000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)
0xBA1C8000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)
0xBA0B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
0xBA208000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0xBA0A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)
0xB9600000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
0xBA1B8000 C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 40960 bytes (NVIDIA Corporation, NVIDIA Networking Bus Driver.)
0xBA108000 PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xBA248000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
0xBA0E8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
0xBF45C000 C:\WINDOWS\System32\DisplayLinkGAdisp.dll 36864 bytes (DisplayLink Corp., DisplayLink Graphics Adapter)
0xBA188000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)
0xBA0D8000 imagedrv.sys 36864 bytes (ahead software gmbh && its licensors, NERO IMAGEDRIVE SCSI miniport)
0xBA228000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
0xBA238000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
0x8B639000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0xB65C5000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0xBA470000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver)
0xBA400000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
0xB5A12000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0xBA448000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0xBA460000 C:\WINDOWS\system32\DRIVERS\DisplayLinkGAport.sys 28672 bytes (DisplayLink Corp., DisplayLink Graphics Adapter)
0xBA438000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver)
0xBA3E8000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0xB5A0A000 C:\WINDOWS\system32\DRIVERS\usbprint.sys 28672 bytes (Microsoft Corporation, USB Printer driver)
0xBA450000 C:\WINDOWS\system32\DRIVERS\DisplayLinkmirrorport.sys 24576 bytes (DisplayLink Corp., DisplayLink Mirror Driver)
0xB5A22000 C:\WINDOWS\system32\DRIVERS\DisplayLinkUsbPort_5.2.22617.0.sys 24576 bytes (http://libusb-win32.sourceforge.net, DisplayLinkUsb - Kernel Driver)
0xBA4A0000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
0xBA4A8000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
0xBA3F0000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0xBA388000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver)
0xBA3F8000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
0xBA490000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
0xBA498000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)
0xBA478000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
0xBA440000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver)
0xA92F3000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
0xA2821000 C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16384 bytes (Microsoft Corporation, MS Remote Access serial network driver)
0xB5A9A000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0xA26E5000 C:\WINDOWS\system32\MLPTDR_C.SYS 16384 bytes (Minolta Co., Ltd., -)
0xBA53C000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
0xA9519000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
0xB96F8000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)
0xB5585000 C:\WINDOWS\system32\DRIVERS\usbscan.sys 16384 bytes (Microsoft Corporation, USB Scanner Driver)
0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
0xA952D000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
0xB5AA2000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0xB5581000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0xB96F0000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0xB9D39000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0xB9708000 C:\WINDOWS\System32\drivers\ws2ifsl.sys 12288 bytes (Microsoft Corporation, Winsock2 IFS Layer)
0xBA62C000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
0xBA5AC000 BsStor.sys 8192 bytes (B.H.A Co.,Ltd., B.H.A Storage Helper Driver (WindowsNT5.x))
0xBA5DE000 C:\WINDOWS\system32\DRIVERS\DisplayLinkFilter.sys 8192 bytes (DisplayLink Corp., DisplayLink Filter Driver)
0xA9CA9000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes
0xBA62A000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0xBA62E000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
0xB1913000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver)
0xBA630000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
0xBA5E0000 C:\WINDOWS\System32\Drivers\RootMdm.sys 8192 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver)
0xBA5E4000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xBA5F8000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xBA6A2000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
0xBA6B5000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
0xBA6CE000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
==============================================
>Stealth
==============================================
WARNING: Virus alike driver modification [ndistapi.sys]
WARNING: Virus alike driver modification [bthpan.sys]
WARNING: Virus alike driver modification [sffp_mmc.sys]
WARNING: Virus alike driver modification [hidusb.sys]
WARNING: Virus alike driver modification [hsfdpsp2.sys]
WARNING: Virus alike driver modification [dxapi.sys]
WARNING: Virus alike driver modification [atinrvxx.sys]
WARNING: Virus alike driver modification [mup.sys]
WARNING: Virus alike driver modification [nvata.sys]
WARNING: Virus alike driver modification [KmxStart.sys]
WARNING: Virus alike driver modification [sffp_sd.sys]
WARNING: Virus alike driver modification [nvtcp.sys]
WARNING: Virus alike driver modification [irenum.sys]
WARNING: Virus alike driver modification [wadv08nt.sys]
WARNING: Virus alike driver modification [sfloppy.sys]
WARNING: Virus alike driver modification [KmxFw.sys]
WARNING: Virus alike driver modification [ati1mdxx.sys]
WARNING: Virus alike driver modification [acpiec.sys]
WARNING: Virus alike driver modification [cpqdap01.sys]
WARNING: Virus alike driver modification [wadv07nt.sys]
WARNING: Virus alike driver modification [mdmxsdk.sys]
WARNING: Virus alike driver modification [wadv09nt.sys]
WARNING: Virus alike driver modification [sffdisk.sys]
WARNING: Virus alike driver modification [wadv11nt.sys]
0x7A4D0000 Hidden Image–>System.Runtime.Serialization.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 1196032 bytes
WARNING: Virus alike driver modification [pcmcia.sys]
WARNING: Virus alike driver modification [nikedrv.sys]
WARNING: Virus alike driver modification [rio8drv.sys]
WARNING: Virus alike driver modification [riodrv.sys]
WARNING: Virus alike driver modification [ws2ifsl.sys]
WARNING: Virus alike driver modification [tdpipe.sys]
WARNING: Virus alike driver modification [ati1pdxx.sys]
WARNING: Virus alike driver modification [fsvga.sys]
WARNING: Virus alike driver modification [mouhid.sys]
WARNING: Virus alike driver modification [usbvideo.sys]
WARNING: Virus alike driver modification [tunmp.sys]
WARNING: Virus alike driver modification [nwlnkflt.sys]
WARNING: Virus alike driver modification [ftdisk.sys]
WARNING: Virus alike driver modification [dne2000.sys]
WARNING: Virus alike driver modification [mtlmnt5.sys]
WARNING: Virus alike driver modification [mutohpen.sys]
WARNING: Virus alike driver modification [usb8023.sys]
WARNING: Virus alike driver modification [usb8023x.sys]
WARNING: Virus alike driver modification [slnt7554.sys]
WARNING: Virus alike driver modification [fltmgr.sys]
WARNING: Virus alike driver modification [mtlstrm.sys]
WARNING: Virus alike driver modification [KmxAMRT.sys]
WARNING: Virus alike driver modification [slwdmsup.sys]
WARNING: Virus alike driver modification [recagent.sys]
WARNING: Virus alike driver modification [atinmdxx.sys]
WARNING: Virus alike driver modification [atinttxx.sys]
WARNING: Virus alike driver modification [afd.sys]
WARNING: Virus alike driver modification [Monfilt.sys]
WARNING: Virus alike driver modification [cbidf2k.sys]
WARNING: Virus alike driver modification [rdpwd.sys]
WARNING: Virus alike driver modification [ks.sys]
WARNING: Virus alike driver modification [diskdump.sys]
WARNING: Virus alike driver modification [wacompen.sys]
WARNING: Virus alike driver modification [asyncmac.sys]
WARNING: Virus alike driver modification [atinpdxx.sys]
0x7AA10000 Hidden Image–>System.ServiceModel.Web.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 143360 bytes
WARNING: Virus alike driver modification [fastfat.sys]
WARNING: Virus alike driver modification [usbport.sys]
WARNING: Virus alike driver modification [hdaudbus.sys]
WARNING: Virus alike driver modification [KmxCF.sys]
WARNING: Virus alike driver modification [kbdhid.sys]
WARNING: Virus alike driver modification [ndisuio.sys]
WARNING: Virus alike driver modification [smclib.sys]
WARNING: Virus alike driver modification [Hdaudio.sys]
WARNING: Virus alike driver modification [portcls.sys]
WARNING: Virus alike driver modification [tape.sys]
WARNING: Virus alike driver modification [usbscan.sys]
WARNING: Virus alike driver modification [ipnat.sys]
WARNING: Virus alike driver modification [dmio.sys]
WARNING: Virus alike driver modification [mssmbios.sys]
WARNING: Virus alike driver modification [serenum.sys]
WARNING: Virus alike driver modification [usbintel.sys]
WARNING: Virus alike driver modification [netbt.sys]
WARNING: Virus alike driver modification [HPZipr12.sys]
WARNING: Virus alike driver modification [raspti.sys]
WARNING: Virus alike driver modification [s3gnbm.sys]
WARNING: Virus alike driver modification [Ambfilt.sys]
WARNING: Virus alike driver modification [bthenum.sys]
WARNING: Virus alike driver modification [usbohci.sys]
WARNING: Virus alike driver modification [kmixer.sys]
WARNING: Virus alike driver modification [rdbss.sys]
WARNING: Virus alike driver modification [ptilink.sys]
WARNING: Virus alike driver modification [ntmtlfax.sys]
WARNING: Virus alike driver modification [mrxdav.sys]
WARNING: Virus alike driver modification [ndis.sys]
WARNING: Virus alike driver modification [cdaudio.sys]
WARNING: Virus alike driver modification [acpi.sys]
WARNING: Virus alike driver modification [bthusb.sys]
WARNING: Virus alike driver modification [msfs.sys]
WARNING: Virus alike driver modification [tdi.sys]
WARNING: Virus alike driver modification [hidir.sys]
WARNING: Virus alike driver modification [rdpdr.sys]
WARNING: Virus alike driver modification [partmgr.sys]
WARNING: Virus alike driver modification [nvnetbus.sys]
WARNING: Virus alike driver modification [rmcast.sys]
WARNING: Virus alike driver modification [flpydisk.sys]
WARNING: Virus alike driver modification [secdrv.sys]
WARNING: Virus alike driver modification [ipinip.sys]
WARNING: Virus alike driver modification [vga.sys]
WARNING: Virus alike driver modification [ati1ttxx.sys]
WARNING: Virus alike driver modification [tsbvcap.sys]
WARNING: Virus alike driver modification [HPZius12.sys]
WARNING: Virus alike driver modification [DisplayLinkUsbPort_5.2.22617.0.sys]
WARNING: Virus alike driver modification [tdtcp.sys]
WARNING: Virus alike driver modification [hsfbs2s2.sys]
WARNING: Virus alike driver modification [watv06nt.sys]
WARNING: Virus alike driver modification [tcpip6.sys]
WARNING: Virus alike driver modification [mouclass.sys]
0x79EE0000 Hidden Image–>System.Core.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 2375680 bytes
WARNING: Virus alike driver modification [KmxCfg.sys]
WARNING: Virus alike driver modification [DisplayLinkmirrorport.sys]
WARNING: Virus alike driver modification [kbdclass.sys]
WARNING: Virus alike driver modification [hidparse.sys]
WARNING: Virus alike driver modification [pciidex.sys]
WARNING: Virus alike driver modification [sonydcam.sys]
WARNING: Virus alike driver modification [watv10nt.sys]
WARNING: Virus alike driver modification [hidbth.sys]
WARNING: Virus alike driver modification [usbcamd.sys]
WARNING: Virus alike driver modification [usbcamd2.sys]
WARNING: Virus alike driver modification [usbprint.sys]
WARNING: Virus alike driver modification [nvsnpu.sys]
WARNING: Virus alike driver modification [cinemst2.sys]
WARNING: Virus alike driver modification [ati1snxx.sys]
WARNING: Virus alike driver modification [usbstor.sys]
WARNING: Virus alike driver modification [http.sys]
WARNING: Virus alike driver modification [bthport.sys]
WARNING: Virus alike driver modification [fdc.sys]
WARNING: Virus alike driver modification [DisplayLinkGAport.sys]
WARNING: Virus alike driver modification [atinsnxx.sys]
WARNING: Virus alike driver modification [ati1xbxx.sys]
WARNING: Virus alike driver modification [bsudf.sys]
WARNING: Virus alike driver modification [modem.sys]
WARNING: Virus alike driver modification [usbehci.sys]
WARNING: Virus alike driver modification [rndismp.sys]
WARNING: Virus alike driver modification [rndismpx.sys]
WARNING: Virus alike driver modification [ati1raxx.sys]
WARNING: Virus alike driver modification [npfs.sys]
WARNING: Virus alike driver modification [atmepvc.sys]
WARNING: Virus alike driver modification [atinxbxx.sys]
WARNING: Virus alike driver modification [usbccgp.sys]
WARNING: Virus alike driver modification [nwlnkfwd.sys]
WARNING: Virus alike driver modification [ati2mtaa.sys]
WARNING: Virus alike driver modification [ipfltdrv.sys]
WARNING: Virus alike driver modification [imagedrv.sys]
WARNING: Virus alike driver modification [rawwan.sys]
WARNING: Virus alike driver modification [wanarp.sys]
WARNING: Virus alike driver modification [netbios.sys]
WARNING: Virus alike driver modification [ati1xsxx.sys]
WARNING: Virus alike driver modification [msgpc.sys]
WARNING: Virus alike driver modification [atmuni.sys]
WARNING: Virus alike driver modification [srv.sys]
WARNING: Virus alike driver modification [processr.sys]
WARNING: Virus alike driver modification [tcpip.sys]
WARNING: Virus alike driver modification [disk.sys]
WARNING: Virus alike driver modification [intelppm.sys]
WARNING: Virus alike driver modification [ati1tuxx.sys]
WARNING: Virus alike driver modification [bthprint.sys]
WARNING: Virus alike driver modification [ip6fw.sys]
WARNING: Virus alike driver modification [crusoe.sys]
WARNING: Virus alike driver modification [AmdK8.sys]
WARNING: Virus alike driver modification [hidclass.sys]
WARNING: Virus alike driver modification [isapnp.sys]
WARNING: Virus alike driver modification [amdk6.sys]
WARNING: Virus alike driver modification [amdk7.sys]
WARNING: Virus alike driver modification [bthmodem.sys]
0x7B0B0000 Hidden Image–>System.Windows.Browser.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 380928 bytes
WARNING: Virus alike driver modification [update.sys]
WARNING: Virus alike driver modification [wpdusb.sys]
WARNING: Virus alike driver modification [nv4_mini.sys]
WARNING: Virus alike driver modification [nmnt.sys]
WARNING: Virus alike driver modification [slntamr.sys]
WARNING: Virus alike driver modification [ndproxy.sys]
WARNING: Virus alike driver modification [termdd.sys]
WARNING: Virus alike driver modification [sisagp.sys]
WARNING: Virus alike driver modification [raspppoe.sys]
WARNING: Virus alike driver modification [imapi.sys]
WARNING: Virus alike driver modification [beep.sys]
WARNING: Virus alike driver modification [mnmdd.sys]
WARNING: Virus alike driver modification [rdpcdd.sys]
WARNING: Virus alike driver modification [viaagp.sys]
WARNING: Virus alike driver modification [agp440.sys]
WARNING: Virus alike driver modification [mountmgr.sys]
WARNING: Virus alike driver modification [alim1541.sys]
WARNING: Virus alike driver modification [p3.sys]
WARNING: Virus alike driver modification [amdagp.sys]
WARNING: Virus alike driver modification [swenum.sys]
WARNING: Virus alike driver modification [wmilib.sys]
WARNING: Virus alike driver modification [fips.sys]
WARNING: Virus alike driver modification [uagp35.sys]
0x7B2E0000 Hidden Image–>System.Windows.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 4476928 bytes
WARNING: Virus alike driver modification [agpcpq.sys]
WARNING: Virus alike driver modification [pxhelp20.sys]
WARNING: Virus alike driver modification [mtxparhm.sys]
WARNING: Virus alike driver modification [mrxsmb.sys]
WARNING: Virus alike driver modification [gagp30kx.sys]
WARNING: Virus alike driver modification [usbd.sys]
WARNING: Virus alike driver modification [raspptp.sys]
WARNING: Virus alike driver modification [stream.sys]
WARNING: Virus alike driver modification [classpnp.sys]
WARNING: Virus alike driver modification [RtkHDAud.sys]
WARNING: Virus alike driver modification [mspqm.sys]
WARNING: Virus alike driver modification [HPZid412.sys]
WARNING: Virus alike driver modification [rasl2tp.sys]
WARNING: Virus alike driver modification [tosdvd.sys]
WARNING: Virus alike driver modification [atinraxx.sys]
WARNING: Virus alike driver modification [volsnap.sys]
WARNING: Virus alike driver modification [i8042prt.sys]
WARNING: Virus alike driver modification [CVirtA.sys]
WARNING: Virus alike driver modification [dmusic.sys]
WARNING: Virus alike driver modification [KmxFile.sys]
WARNING: Virus alike driver modification [mspclock.sys]
WARNING: Virus alike driver modification [atmlane.sys]
WARNING: Virus alike driver modification [nwlnkspx.sys]
WARNING: Virus alike driver modification [swmidi.sys]
WARNING: Virus alike driver modification [ati1btxx.sys]
WARNING: Virus alike driver modification [ntfs.sys]
WARNING: Virus alike driver modification [redbook.sys]
WARNING: Virus alike driver modification [atinbtxx.sys]
WARNING: Virus alike driver modification [vdmindvd.sys]
WARNING: Virus alike driver modification [NVENETFD.sys]
WARNING: Virus alike driver modification [dmload.sys]
WARNING: Virus alike driver modification [rootmdm.sys]
WARNING: Virus alike driver modification [smbali.sys]
WARNING: Virus alike driver modification [rfcomm.sys]
WARNING: Virus alike driver modification [usbhub.sys]
WARNING: Virus alike driver modification [KmxAMVet.sys]
WARNING: Virus alike driver modification [atmarpc.sys]
WARNING: Virus alike driver modification [usbaudio.sys]
WARNING: Virus alike driver modification [drmk.sys]
WARNING: Virus alike driver modification [arp1394.sys]
WARNING: Virus alike driver modification [sysaudio.sys]
WARNING: Virus alike driver modification [KmxSbx.sys]
WARNING: Virus alike driver modification [nic1394.sys]
0x796B0000 Hidden Image–>mscorlib.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 6197248 bytes
WARNING: Virus alike driver modification [splitter.sys]
WARNING: Virus alike driver modification [cdrom.sys]
WARNING: Virus alike driver modification [nwlnknb.sys]
WARNING: Virus alike driver modification [atinxsxx.sys]
WARNING: Virus alike driver modification [ati1rvxx.sys]
WARNING: Virus alike driver modification [cdfs.sys]
WARNING: Virus alike driver modification [mf.sys]
WARNING: Virus alike driver modification [serial.sys]
0x7A340000 Hidden Image–>System.Net.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 659456 bytes
WARNING: Virus alike driver modification [udfs.sys]
0x7A1D0000 Hidden Image–>System.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 671744 bytes
WARNING: Virus alike driver modification [parvdm.sys]
WARNING: Virus alike driver modification [pci.sys]
WARNING: Virus alike driver modification [hsfcxts2.sys]
WARNING: Virus alike driver modification [psched.sys]
WARNING: Virus alike driver modification [ati2mtag.sys]
WARNING: Virus alike driver modification [DisplayLinkFilter.sys]
WARNING: Virus alike driver modification [dxg.sys]
WARNING: Virus alike driver modification [bridge.sys]
WARNING: Virus alike driver modification [atintuxx.sys]
WARNING: Virus alike driver modification [sr.sys]
WARNING: Virus alike driver modification [ipsec.sys]
WARNING: Virus alike driver modification [mskssrv.sys]
WARNING: Virus alike driver modification [mcd.sys]
WARNING: Virus alike driver modification [WudfPf.sys]
WARNING: Virus alike driver modification [KmxAgent.sys]
WARNING: Virus alike driver modification [sdbus.sys]
WARNING: Virus alike driver modification [fs_rec.sys]
WARNING: Virus alike driver modification [dmboot.sys]
WARNING: Virus alike driver modification [parport.sys]
WARNING: Virus alike driver modification [bsstor.sys]
WARNING: Virus alike driver modification [videoprt.sys]
WARNING: Virus alike driver modification [WudfRd.sys]
WARNING: Virus alike driver modification [wdmaud.sys]
0x7AAE0000 Hidden Image–>System.Xml.ni.dll [ EPROCESS 0x888C77A8 ] PID: 3020, 847872 bytes
WARNING: Virus alike driver modification [rasacd.sys]
WARNING: Virus alike driver modification [nwlnkipx.sys]
WARNING: Virus alike driver modification [nvnrm.sys]
WARNING: Virus alike driver modification [cdr4_xp.sys]
WARNING: Virus alike driver modification [ndiswan.sys]
WARNING: Virus alike driver modification [cdralw2k.sys]
WARNING: Virus alike driver modification [ksecdd.sys]
WARNING: Virus alike driver modification [slnthal.sys]
WARNING: Virus alike driver modification [scsiport.sys]
WARNING: Virus alike driver modification [atapi.sys]
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 10-10-22.05 - Philip 10/23/2010 15:49:32.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1983.1042 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: CA Anti-Virus Plus *On-access scanning disabled* (Updated) {6B98D35F-BB76-41C0-876B-A50645ED099A}
FW: CA Personal Firewall *disabled* {38102F93-1B6E-4922-90E1-A35D8DC6DAA3}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\FunWebProducts
c:\program files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL
C:\V2T225.tmp
C:\V2T22E.tmp
C:\V2T232.tmp
c:\windows\system32\mkghj.dll
c:\windows\system32\spool\prtprocs\w32x86\Ppbiproc.dll
c:\windows\system32\tv53423.dll

.
((((((((((((((((((((((((( Files Created from 2010-09-23 to 2010-10-23 )))))))))))))))))))))))))))))))
.

2010-10-23 16:31 . 2010-10-23 16:31 ——– dc-h–w- c:\windows\PIF
2010-10-19 22:20 . 2010-10-19 22:20 ——– dc—-w- c:\program files\Carbonite
2010-10-13 00:17 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 00:17 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 00:17 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-09 14:32 . 2010-10-09 14:32 388096 -c–a-r- c:\documents and settings\Philip\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-09 02:48 . 2004-08-04 10:00 605696 -c–a-w- c:\windows\system32\getuname.dll
2010-10-09 02:48 . 2004-08-04 10:00 605696 -c–a-w- c:\windows\system32\dllcache\getuname.dll
2010-10-09 02:47 . 2004-08-04 10:00 80384 -c–a-w- c:\windows\system32\dllcache\charmap.exe
2010-10-09 02:47 . 2004-08-04 10:00 80384 -c–a-w- c:\windows\system32\charmap.exe
2010-10-09 02:47 . 2004-08-04 10:00 114688 -c–a-w- c:\windows\system32\dllcache\calc.exe
2010-10-09 02:47 . 2004-08-04 10:00 114688 -c–a-w- c:\windows\system32\calc.exe
2010-10-09 02:25 . 2010-10-09 02:26 ——– dc-h–w- c:\windows\ie8
2010-10-09 02:25 . 2010-10-09 02:25 ——– dc—-w- c:\program files\Microsoft
2010-10-09 02:25 . 2010-10-09 02:25 ——– dc—-w- c:\program files\MSN Toolbar
2010-10-09 02:24 . 2010-10-09 02:25 ——– dc—-w- c:\program files\Bing Bar Installer
2010-10-09 02:24 . 2010-10-09 02:28 ——– dc-h–w- c:\windows\msdownld.tmp
2010-10-09 02:21 . 2010-08-26 11:08 13312 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-09-23 23:34 . 2010-09-23 23:34 ——– dc—-w- c:\documents and settings\All Users\Application Data\Apple Computer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 17:23 . 2006-02-28 12:00 974848 -c–a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2006-02-28 12:00 974848 -c–a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2006-02-28 12:00 954368 -c–a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2006-02-28 12:00 953856 -c–a-w- c:\windows\system32\mfc40u.dll
2010-09-15 09:50 . 2010-06-05 02:32 472808 -c–a-w- c:\windows\system32\deployJava1.dll
2010-09-15 07:29 . 2010-04-10 01:03 73728 -c–a-w- c:\windows\system32\javacpl.cpl
2010-09-12 16:45 . 2010-09-12 16:45 5845744 -c–a-w- c:\windows\system32\win32cpr.dll
2010-09-12 16:45 . 2010-09-12 16:45 1872624 -c–a-w- c:\windows\system32\winsflt.dll
2010-09-10 05:58 . 2006-02-28 12:00 916480 -c–a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2006-02-28 12:00 43520 -c–a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2006-02-28 12:00 1469440 -c—-w- c:\windows\system32\inetcpl.cpl
2010-09-08 16:17 . 2010-09-08 16:17 94208 -c–a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17 . 2010-09-08 16:17 69632 -c–a-w- c:\windows\system32\QuickTime.qts
2010-09-01 11:51 . 2006-02-28 12:00 285824 -c–a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2006-02-28 12:00 1852800 -c–a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2006-02-28 12:00 119808 -c–a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2006-02-28 12:00 99840 -c–a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2006-02-28 12:00 357248 -c–a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-11-17 22:17 5120 -c–a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2006-02-28 12:00 617472 -c–a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2006-02-28 12:00 58880 -c–a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2006-02-28 12:00 590848 -c–a-w- c:\windows\system32\rpcrt4.dll
2003-12-07 04:12 121856 -csha-w- c:\windows\system32\fpplock.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-12 68856]
"PPWebCap"="d:\progra~1\PPWebCap.exe" [2001-08-10 40960]
"Messenger (Yahoo!)"="g:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-03-19 5248312]
"Starfield Updater"="c:\program files\Starfield\StarfieldUpdate.exe" [2010-09-12 32960]
"wben"="c:\program files\Starfield\wben.exe" [2010-07-07 1076432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"nwiz"="nwiz.exe" [2006-10-31 1622016]
"NvMediaCenter"="NvMCTray.dll" [2006-10-31 86016]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-09 18063872]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="d:\program files\InCD\InCD.exe" [2001-11-09 839680]
"ImageDrive.exe"="d:\program files\ahead\ImageDrive\ImageDrive.exe" [2009-05-09 421962]
"Warning: do not remove it!"="fpplock.exe" [2003-12-07 121856]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-08-20 1164584]
"cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" [2010-09-12 1721680]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2010-03-23 337136]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="d:\program files\qttask.exe" [2010-09-08 421888]
"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 243544]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2010-09-15 281744]

c:\documents and settings\Philip\Start Menu\Programs\Startup\
Check for OneTouch Updates.lnk - c:\program files\Visioneer OneTouch\WiseUpdt.exe [2009-4-27 166518]
MS Outlook.lnk - c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe [2010-2-14 845584]
OneNote 2007 Screen Clipper and Launcher.lnk - d:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Shortcut to digiclok1.lnk - g:\philip\digiclok1.exe [2003-7-29 16384]
Volume.lnk - c:\windows\system32\sndvol32.exe [2009-4-23 138752]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
Sonic CinePlayer Quick Launch.lnk - c:\program files\Common Files\Sonic Shared\CineTray.exe [2006-7-25 114688]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00583593\LinkAdvisor\CIDLinkAdvisor.dll" [2010-03-22 1852856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2009-03-27 20:27 79368 -c–a-w- c:\windows\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\UmxSbxExw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"d:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"g:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [5/9/2009 5:07 PM 8040]
R0 KmxAMRT;KmxAMRT;c:\windows\system32\drivers\KmxAMRT.sys [12/23/2009 11:29 AM 132088]
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/8/2009 10:02 AM 108024]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [12/23/2009 11:29 AM 78840]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [9/2/2009 5:29 PM 53240]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/8/2009 10:02 AM 115704]
R2 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [5/9/2009 5:07 PM 294784]
R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [9/12/2010 11:45 AM 206160]
R2 DisplayLinkService;DisplayLinkManager;c:\program files\DisplayLink Core Software\DisplayLinkManager.exe [12/8/2009 11:45 AM 4719976]
R2 File Backup;File Backup Service;c:\program files\Starfield\offSyncService.exe [7/16/2010 1:47 PM 1310960]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [8/14/2009 11:43 AM 145912]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [9/30/2009 4:51 PM 60920]
R2 MLPTDR_C;MLPTDR_C;c:\windows\system32\MLPTDR_C.SYS [7/2/2002 4:34 PM 19296]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [8/4/2009 10:42 AM 887288]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [7/13/2009 10:39 AM 760664]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [7/27/2009 3:40 PM 227832]
R2 WinExtManager;WinSock Extention Manager;c:\windows\system32\mdmcls32.exe [9/12/2010 11:45 AM 2347760]
R2 WinSvchostManager;WinSock Svchost Manager;c:\windows\system32\svcprs32.exe [9/12/2010 11:45 AM 1377008]
R3 DisplayLinkFilter;DisplayLinkFilter;c:\windows\system32\drivers\DisplayLinkFilter.sys [12/8/2009 11:46 AM 7040]
R3 DisplayLinkGA;DisplayLinkGA;c:\windows\system32\drivers\DisplayLinkGAport.sys [12/8/2009 11:46 AM 27776]
R3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [12/8/2009 11:46 AM 24320]
R3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\drivers\DisplayLinkUsbPort_5.2.22617.0.sys [3/25/2010 9:28 PM 21888]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [9/30/2009 4:51 PM 239608]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/6/2010 8:22 AM 136176]
S3 KmxAMVet;KmxAMVet;c:\windows\system32\drivers\KmxAMVet.sys [3/27/2009 3:27 PM 598656]

— Other Services/Drivers In Memory —

*NewlyCreated* - NORMANDY
*Deregistered* - Normandy
.
Contents of the 'Scheduled Tasks' folder

2010-10-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-06 13:21]

2010-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-06 13:21]

2010-10-22 c:\windows\Tasks\RegCure Program Check.job
- g:\program files\RegCure\RegCure.exe [2010-05-19 23:20]

2010-10-21 c:\windows\Tasks\RegCure.job
- g:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.goodsearch.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\winsflt.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: Web-Based Email Tools - hxxp://email01.secureserver.net/Download.CAB
DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} - hxxp://www.hebphoto.com/NET/Uploader/LPUploader57.cab
.
- - - - ORPHANS REMOVED - - - -

BHO-{3B5FA6BB-44C2-3FAB-841E-34FF02CCF37D} - c:\windows\system32\tv53423.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-23 15:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\UmxWnp.Dll

- - - - - - - > 'lsass.exe'(728)
c:\windows\system32\winsflt.dll
.
Completion time: 2010-10-23 16:02:41
ComboFix-quarantined-files.txt 2010-10-23 21:02

Pre-Run: 57,225,420,800 bytes free
Post-Run: 59,539,451,904 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - E33B966786ED3A5B0484AD58CFFB834E
Please run the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
2010/10/23 18:31:13.0515 TDSS rootkit removing tool 2.4.4.0 Oct 4 2010 09:06:59 2010/10/23 18:31:13.0515 ================================================================================ 2010/10/23 18:31:13.0515 SystemInfo: 2010/10/23 18:31:13.0515 2010/10/23 18:31:13.0515 OS Version: 5.1.2600 ServicePack: 3.0 2010/10/23 18:31:13.0515 Product type: Workstation 2010/10/23 18:31:13.0515 ComputerName: PHILIP-AMD 2010/10/23 18:31:13.0515 UserName: Philip 2010/10/23 18:31:13.0515 Windows directory: C:\WINDOWS 2010/10/23 18:31:13.0515 System windows directory: C:\WINDOWS 2010/10/23 18:31:13.0515 Processor architecture: Intel x86 2010/10/23 18:31:13.0515 Number of processors: 1 2010/10/23 18:31:13.0515 Page size: 0x1000 2010/10/23 18:31:13.0515 Boot type: Normal boot 2010/10/23 18:31:13.0515 ================================================================================ 2010/10/23 18:31:13.0906 Initialize success 2010/10/23 18:31:23.0078 ================================================================================ 2010/10/23 18:31:23.0078 Scan started 2010/10/23 18:31:23.0078 Mode: Manual; 2010/10/23 18:31:23.0078 ================================================================================ 2010/10/23 18:31:24.0046 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2010/10/23 18:31:24.0125 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2010/10/23 18:31:24.0187 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2010/10/23 18:31:24.0250 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2010/10/23 18:31:24.0406 AmdK8 (efbb0956baed786e137351b5ca272aef) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 2010/10/23 18:31:24.0640 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2010/10/23 18:31:24.0734 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2010/10/23 18:31:24.0828 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2010/10/23 18:31:24.0937 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2010/10/23 18:31:25.0031 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2010/10/23 18:31:25.0125 BsStor (61f8e118bc77b03f177cb531cc6fe8d4) C:\WINDOWS\system32\drivers\BsStor.sys 2010/10/23 18:31:25.0187 BsUDF (9bc16e29a4a8cdc27313a905800214de) C:\WINDOWS\system32\drivers\BsUDF.sys 2010/10/23 18:31:25.0437 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2010/10/23 18:31:25.0546 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2010/10/23 18:31:25.0609 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2010/10/23 18:31:25.0656 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2010/10/23 18:31:25.0843 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys 2010/10/23 18:31:26.0015 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2010/10/23 18:31:26.0078 DisplayLinkFilter (6ab4b3859d87dc40dc93f1427c366db8) C:\WINDOWS\system32\DRIVERS\DisplayLinkFilter.sys 2010/10/23 18:31:26.0156 DisplayLinkGA (a29e61ab672e3901b63d1df7592613b5) C:\WINDOWS\system32\DRIVERS\DisplayLinkGAport.sys 2010/10/23 18:31:26.0218 DisplayLinkmirror (f974762414e831e3469fe4d14c378f2c) C:\WINDOWS\system32\DRIVERS\DisplayLinkmirrorport.sys 2010/10/23 18:31:26.0296 DisplayLinkUsbPort (ebd5fa84bf434944d158db6302260031) C:\WINDOWS\system32\DRIVERS\DisplayLinkUsbPort_5.2.22617.0.sys 2010/10/23 18:31:26.0390 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2010/10/23 18:31:26.0500 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2010/10/23 18:31:26.0593 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2010/10/23 18:31:26.0687 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2010/10/23 18:31:26.0781 DNE (86d52c32a308f84bbc626bff7c1fb710) C:\WINDOWS\system32\DRIVERS\dne2000.sys 2010/10/23 18:31:26.0906 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2010/10/23 18:31:27.0015 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2010/10/23 18:31:27.0093 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2010/10/23 18:31:27.0171 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2010/10/23 18:31:27.0250 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2010/10/23 18:31:27.0343 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2010/10/23 18:31:27.0421 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2010/10/23 18:31:27.0515 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2010/10/23 18:31:27.0578 gdrv (c6e3105b8c68c35cc1eb26a00fd1a8c6) C:\WINDOWS\gdrv.sys 2010/10/23 18:31:28.0312 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2010/10/23 18:31:28.0406 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2010/10/23 18:31:28.0500 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2010/10/23 18:31:28.0625 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 2010/10/23 18:31:28.0687 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 2010/10/23 18:31:28.0734 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 2010/10/23 18:31:28.0812 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2010/10/23 18:31:28.0968 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2010/10/23 18:31:29.0078 Imagedrv (ee23e66bea4bb810d5e085c2588c62ec) C:\WINDOWS\system32\DRIVERS\imagedrv.sys 2010/10/23 18:31:29.0171 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2010/10/23 18:31:29.0421 IntcAzAudAddService (1508153784633e16dc3dfce3cd7a9b18) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2010/10/23 18:31:29.0781 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2010/10/23 18:31:29.0859 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2010/10/23 18:31:29.0921 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2010/10/23 18:31:30.0000 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2010/10/23 18:31:30.0078 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2010/10/23 18:31:30.0140 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2010/10/23 18:31:30.0250 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2010/10/23 18:31:30.0328 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2010/10/23 18:31:30.0406 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2010/10/23 18:31:30.0484 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2010/10/23 18:31:30.0562 KmxAgent (45ab8298ffb922fb36ba52f7dc956de4) C:\WINDOWS\system32\DRIVERS\kmxagent.sys 2010/10/23 18:31:30.0625 KmxAMRT (88c521675724bd9d9eced840112279ab) C:\WINDOWS\system32\DRIVERS\KmxAMRT.sys 2010/10/23 18:31:30.0750 KmxAMVet (041b29c8e3bed6e833ade367ecfa51f9) C:\WINDOWS\system32\Drivers\KmxAMVet.sys 2010/10/23 18:31:30.0890 KmxCF (8fb8170faf3c9aa585e976979d9c17df) C:\WINDOWS\system32\DRIVERS\KmxCF.sys 2010/10/23 18:31:30.0984 KmxCfg (0c14fc849eebb15ea4de6a62ccdd34e0) C:\WINDOWS\system32\DRIVERS\kmxcfg.sys 2010/10/23 18:31:31.0093 KmxFile (c69b4a3bc8d2c7b6398ad38aacff98c9) C:\WINDOWS\system32\DRIVERS\KmxFile.sys 2010/10/23 18:31:31.0187 KmxFw (db5fbf6efd78a1718cd040df23bd7d96) C:\WINDOWS\system32\DRIVERS\kmxfw.sys 2010/10/23 18:31:31.0281 KmxSbx (cb390a8aee3a142b1662f1115bc02394) C:\WINDOWS\system32\DRIVERS\KmxSbx.sys 2010/10/23 18:31:31.0375 KmxStart (9e0891eb24ff3e01a5802cc6e2219e98) C:\WINDOWS\system32\DRIVERS\kmxstart.sys 2010/10/23 18:31:31.0468 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2010/10/23 18:31:31.0640 MLPTDR_C (a0559040b0df7403ddcd9574cb2694de) C:\WINDOWS\system32\MLPTDR_C.SYS 2010/10/23 18:31:31.0734 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2010/10/23 18:31:31.0828 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2010/10/23 18:31:31.0921 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2010/10/23 18:31:32.0031 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2010/10/23 18:31:32.0078 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2010/10/23 18:31:32.0125 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2010/10/23 18:31:32.0187 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2010/10/23 18:31:32.0281 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2010/10/23 18:31:32.0328 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2010/10/23 18:31:32.0406 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2010/10/23 18:31:32.0484 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2010/10/23 18:31:32.0546 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2010/10/23 18:31:32.0625 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2010/10/23 18:31:32.0687 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2010/10/23 18:31:32.0750 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2010/10/23 18:31:32.0828 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2010/10/23 18:31:32.0890 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2010/10/23 18:31:32.0968 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 2010/10/23 18:31:33.0046 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2010/10/23 18:31:33.0125 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2010/10/23 18:31:33.0328 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2010/10/23 18:31:33.0375 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2010/10/23 18:31:33.0468 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2010/10/23 18:31:33.0671 nv (eb2858f920b8135b807b5ccaa3ed73dc) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2010/10/23 18:31:33.0921 nvata (ef9941593b2e9b436f64a87ddb570d1a) C:\WINDOWS\system32\DRIVERS\nvata.sys 2010/10/23 18:31:34.0000 NVENETFD (0ae6258709d58fb53638e8d28f4480d4) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 2010/10/23 18:31:34.0109 nvnetbus (1296b33c223a58485d5eaa779752216a) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 2010/10/23 18:31:34.0187 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2010/10/23 18:31:34.0250 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2010/10/23 18:31:34.0375 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2010/10/23 18:31:34.0468 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2010/10/23 18:31:34.0546 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2010/10/23 18:31:34.0656 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2010/10/23 18:31:34.0796 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2010/10/23 18:31:34.0875 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2010/10/23 18:31:35.0187 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2010/10/23 18:31:35.0250 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 2010/10/23 18:31:35.0312 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2010/10/23 18:31:35.0390 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2010/10/23 18:31:35.0453 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2010/10/23 18:31:35.0687 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2010/10/23 18:31:35.0750 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2010/10/23 18:31:35.0828 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2010/10/23 18:31:35.0890 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2010/10/23 18:31:35.0984 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2010/10/23 18:31:36.0062 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2010/10/23 18:31:36.0156 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2010/10/23 18:31:36.0234 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2010/10/23 18:31:36.0343 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 2010/10/23 18:31:36.0484 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2010/10/23 18:31:36.0578 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2010/10/23 18:31:36.0671 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2010/10/23 18:31:36.0750 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2010/10/23 18:31:36.0890 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2010/10/23 18:31:36.0968 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2010/10/23 18:31:37.0062 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 2010/10/23 18:31:37.0156 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2010/10/23 18:31:37.0218 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2010/10/23 18:31:37.0437 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2010/10/23 18:31:37.0593 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2010/10/23 18:31:37.0687 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2010/10/23 18:31:37.0765 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2010/10/23 18:31:37.0875 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2010/10/23 18:31:38.0046 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2010/10/23 18:31:38.0218 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2010/10/23 18:31:38.0328 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2010/10/23 18:31:38.0421 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2010/10/23 18:31:38.0500 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2010/10/23 18:31:38.0593 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2010/10/23 18:31:38.0671 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 2010/10/23 18:31:38.0734 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2010/10/23 18:31:38.0812 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2010/10/23 18:31:38.0875 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2010/10/23 18:31:38.0968 USB_RNDIS (bee793d4a059caea55d6ac20e19b3a8f) C:\WINDOWS\system32\DRIVERS\usb8023.sys 2010/10/23 18:31:39.0062 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2010/10/23 18:31:39.0156 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2010/10/23 18:31:39.0250 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2010/10/23 18:31:39.0343 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2010/10/23 18:31:39.0515 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2010/10/23 18:31:39.0625 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 2010/10/23 18:31:39.0750 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2010/10/23 18:31:39.0812 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2010/10/23 18:31:40.0203 ================================================================================ 2010/10/23 18:31:40.0203 Scan finished 2010/10/23 18:31:40.0203 ================================================================================ 2010/10/23 18:31:58.0203 Deinitialize success
Hi

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4938 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 10/24/2010 5:45:39 PM mbam-log-2010-10-24 (17-45-39).txt Scan type: Quick scan Objects scanned: 156507 Time elapsed: 8 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, October 25, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, October 24, 2010 15:41:26 Records in database: 4175354 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ O:\ Scan statistics: Objects scanned: 174869 Threats found: 12 Infected objects found: 15 Suspicious objects found: 0 Scan duration: 06:33:30 File name / Threat / Threats count C:\Documents and Settings\Philip\Application Data\Sun\Java\Deployment\cache\6.0\1\1c429941-4be4ee5b Infected: Trojan-Downloader.Java.OpenConnection.ay 1 C:\Documents and Settings\Philip\Application Data\Sun\Java\Deployment\cache\6.0\11\234a408b-5a282bbc Infected: Trojan-Downloader.Java.OpenConnection.ay 1 C:\Documents and Settings\Philip\Application Data\Sun\Java\Deployment\cache\6.0\38\55a58fa6-7e886061 Infected: Trojan-Downloader.Java.OpenConnection.ay 1 C:\Documents and Settings\Philip\Application Data\Sun\Java\Deployment\cache\6.0\50\64ed4a32-50aea601 Infected: Trojan-Downloader.Java.Agent.gr 1 C:\Documents and Settings\Philip\Application Data\Sun\Java\Deployment\cache\6.0\50\64ed4a32-50aea601 Infected: Trojan-Downloader.Java.Agent.gs 1 C:\Documents and Settings\Philip\Application Data\Sun\Java\Deployment\cache\6.0\50\64ed4a32-50aea601 Infected: Trojan-Downloader.Java.Agent.gt 1 C:\Documents and Settings\Philip\Application Data\Sun\Java\Deployment\cache\6.0\8\476f1e48-6cbeb1a4 Infected: Trojan-Downloader.Java.Agent.hx 1 C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL.vir Infected: not-a-virus:AdWare.Win32.FunWeb.q 1 C:\System Volume Information\_restore{49C73633-8496-4A1D-B790-93031B5A1867}\RP583\A0087426.DLL Infected: not-a-virus:AdWare.Win32.FunWeb.q 1 G:\Philip\Shooting\wfallsfree.exe Infected: not-a-virus:AdWare.Win32.SaveNow.ae 1 G:\Philip\Shooting\wfallsfree.exe Infected: not-a-virus:AdWare.Win32.SaveNow.af 1 G:\Philip\Shooting\wfallsfree.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v 1 G:\Philip\Shooting\wfallsfree.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1 G:\Download\dap53.exe Infected: not-a-virus:AdWare.Win32.Dap.g 1 O:\Documents and Settings\Lisa Zertuche\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-51fad18-377ef7e0.zip Infected: Exploit.Java.Gimsh.a 1 Selected area has been scanned. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Hi

Please do the following:


Click Start > Control Panel.
Double-click the Java icon in the control panel.
The Java Control Panel appears.
Click Settings under Temporary Internet Files.
The Temporary Files Settings dialog box appears.

There are three options on this window to clear the cache.

  • Delete Files
  • View Applications
  • View Applets



Click OK on Delete Temporary Files window.
Note: This deletes all the Downloaded Applications and Applets from the cache.
Click OK on Temporary Files Settings window.



NEXT


Kaspersky is identifying the following as Adware > delete them if you don't need them:

G:\Philip\Shooting\wfallsfree.exe Infected: not-a-virus:AdWare.Win32.SaveNow.ae 1
G:\Philip\Shooting\wfallsfree.exe Infected: not-a-virus:AdWare.Win32.SaveNow.af 1
G:\Philip\Shooting\wfallsfree.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v 1
G:\Philip\Shooting\wfallsfree.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
G:\Download\dap53.exe Infected: not-a-virus:AdWare.Win32.Dap.g 1

the rest is in quarantine or old system restore points which we will clean up shortly



NEXT



Please post a fresh DDS log and advise how the computer is running now and if there are any outstanding issues.
DDS (Ver_10-10-21.02) - NTFSx86 Run by [removed] at 15:33:05.50 on Mon 10/25/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1983.824 [GMT -5:00] AV: CA Anti-Virus Plus *On-access scanning enabled* (Updated) {6B98D35F-BB76-41C0-876B-A50645ED099A} FW: CA Personal Firewall *enabled* {38102F93-1B6E-4922-90E1-A35D8DC6DAA3} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe svchost.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe C:\Program Files\Starfield\offSyncService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\mdmcls32.exe C:\WINDOWS\system32\svcprs32.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\VISION~1\ONETOU~2.EXE D:\Program Files\InCD\InCD.exe C:\WINDOWS\system32\fpplock.exe D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\CA\CA Internet Security Suite\casc.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe G:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\Starfield\StarfieldUpdate.exe C:\Program Files\Starfield\wben.exe C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe C:\Program Files\Common Files\Sonic Shared\CineTray.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE G:\Philip\digiclok1.exe C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00583593\Light\CAGlobalLight.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Documents and Settings\Philip\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.goodsearch.com/ uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: CA Toolbar Helper: {fbf2401b-7447-4727-be5d-c19b2075ca84} - c:\program files\ca\ca internet security suite\ca website inspector\1.2.1.24.00583593\toolbar\CallingIDIE.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: CA Toolbar: {10134636-e7af-4ac5-a1dc-c7c44bb97d81} - c:\program files\ca\ca internet security suite\ca website inspector\1.2.1.24.00583593\toolbar\CallingIDIE.dll TB: @c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [PPWebCap] d:\progra~1\PPWebCap.exe uRun: [Messenger (Yahoo!)] "g:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [Starfield Updater] "c:\program files\starfield\StarfieldUpdate.exe" uRun: [wben] "c:\program files\starfield\wben.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit mRun: [RTHDCPL] RTHDCPL.EXE mRun: [OneTouch Monitor] c:\progra~1\vision~1\ONETOU~2.EXE mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe mRun: [InCD] d:\program files\incd\InCD.exe mRun: [ImageDrive.exe] d:\program files\ahead\imagedrive\ImageDrive.exe mRun: [Warning: do not remove it!] fpplock.exe mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [cctray] "c:\program files\ca\ca internet security suite\casc.exe" mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "d:\program files\qttask.exe" -atboottime mRun: [Bing Bar] "c:\program files\msn toolbar\platform\5.0.1449.0\mswinext.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [CarboniteSetupLite] "c:\program files\carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=1800 mRunOnce: [Malwarebytes' Anti-Malware] g:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\docume~1\philip\startm~1\programs\startup\checkf~1.lnk - c:\program files\visioneer onetouch\WiseUpdt.exe StartupFolder: c:\docume~1\philip\startm~1\programs\startup\msoutl~1.lnk - c:\windows\installer\{91120000-0030-0000-0000-0000000ff1ce}\outicon.exe StartupFolder: c:\docume~1\philip\startm~1\programs\startup\onenot~1.lnk - d:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\philip\startm~1\programs\startup\shortc~1.lnk - g:\philip\digiclok1.exe StartupFolder: c:\docume~1\philip\startm~1\programs\startup\volume.lnk - c:\windows\system32\sndvol32.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nikonm~1.lnk - c:\program files\common files\nikon\monitor\NkMonitor.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sonicc~1.lnk - c:\program files\common files\sonic shared\CineTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office11\REFIEBAR.DLL LSP: c:\windows\system32\winsflt.dll LSP: c:\windows\system32\VetRedir.dll DPF: Web-Based Email Tools - hxxp://email01.secureserver.net/Download.CAB DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://supportcenter.timewarnercable.com/sdccommon/download/tgctlcm.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250018558546 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1250019801421 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} - hxxp://www.hebphoto.com/NET/Uploader/LPUploader57.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: callingid - {086D03BA-57AC-4C8E-A33D-0BAABF742411} - c:\program files\ca\ca internet security suite\ca website inspector\1.2.1.24.00583593\toolbar\CallingIDToolbar.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: PFW - UmxWnp.Dll AppInit_DLLs: c:\windows\system32\UmxSbxExw.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: ShellHook Class: {1869181a-9f50-4fcf-8bff-1b8588ecb85c} - c:\program files\ca\ca internet security suite\ca website inspector\1.2.1.24.00583593\linkadvisor\CIDLinkAdvisor.dll ============= SERVICES / DRIVERS =============== R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2009-5-9 8040] R0 KmxAMRT;KmxAMRT;c:\windows\system32\drivers\KmxAMRT.sys [2009-12-23 132088] R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2009-6-8 108024] R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2009-12-23 78840] R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2009-9-2 53240] R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2009-6-8 115704] R2 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [2009-5-9 294784] R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus plus\isafe.exe [2010-9-12 212992] R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\ca\ca internet security suite\ccschedulersvc.exe [2010-9-12 206160] R2 DisplayLinkService;DisplayLinkManager;c:\program files\displaylink core software\DisplayLinkManager.exe [2009-12-8 4719976] R2 File Backup;File Backup Service;c:\program files\starfield\offSyncService.exe [2010-7-16 1310960] R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2009-8-14 145912] R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2009-9-30 60920] R2 MLPTDR_C;MLPTDR_C;c:\windows\system32\MLPTDR_C.SYS [2002-7-2 19296] R2 UmxAgent;HIPS Event Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxAgent.exe [2009-8-4 887288] R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\ca\sharedcomponents\hipsengine\UmxCfg.exe [2009-7-13 760664] R2 UmxPol;HIPS Policy Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxPol.exe [2009-7-27 227832] R2 WinExtManager;WinSock Extention Manager;c:\windows\system32\mdmcls32.exe [2010-9-12 2347760] R2 WinSvchostManager;WinSock Svchost Manager;c:\windows\system32\svcprs32.exe [2010-9-12 1377008] R3 DisplayLinkFilter;DisplayLinkFilter;c:\windows\system32\drivers\DisplayLinkFilter.sys [2009-12-8 7040] R3 DisplayLinkGA;DisplayLinkGA;c:\windows\system32\drivers\DisplayLinkGAport.sys [2009-12-8 27776] R3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [2009-12-8 24320] R3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\drivers\DisplayLinkUsbPort_5.2.22617.0.sys [2010-3-25 21888] R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2009-9-30 239608] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-9-6 136176] S3 KmxAMVet;KmxAMVet;c:\windows\system32\drivers\KmxAMVet.sys [2009-3-27 598656] S3 Normandy;Normandy SR2; [x] =============== Created Last 30 ================ 2010-10-24 22:36:06 ——– dc—-w- c:\docume~1\philip\applic~1\Malwarebytes 2010-10-24 22:35:49 38224 -c–a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-10-24 22:35:48 ——– dc—-w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-10-24 22:35:47 20952 -c–a-w- c:\windows\system32\drivers\mbam.sys 2010-10-23 20:47:44 ——– dcsha-r- C:\cmdcons 2010-10-23 20:44:40 77312 -c–a-w- c:\windows\MBR.exe 2010-10-23 20:44:39 98816 -c–a-w- c:\windows\sed.exe 2010-10-23 20:44:39 256512 -c–a-w- c:\windows\PEV.exe 2010-10-23 20:44:39 161792 -c–a-w- c:\windows\SWREG.exe 2010-10-23 20:44:11 ——– dc—-w- C:\ComboFix 2010-10-23 16:31:43 ——– dc-h–w- c:\windows\PIF 2010-10-19 22:20:49 ——– dc—-w- c:\program files\Carbonite 2010-10-13 00:17:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll 2010-10-13 00:17:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll 2010-10-13 00:17:43 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll 2010-10-09 14:32:54 388096 -c–a-r- c:\docume~1\philip\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2010-10-09 02:48:00 605696 -c–a-w- c:\windows\system32\getuname.dll 2010-10-09 02:48:00 605696 -c–a-w- c:\windows\system32\dllcache\getuname.dll 2010-10-09 02:47:59 80384 -c–a-w- c:\windows\system32\dllcache\charmap.exe 2010-10-09 02:47:59 80384 -c–a-w- c:\windows\system32\charmap.exe 2010-10-09 02:47:58 114688 -c–a-w- c:\windows\system32\dllcache\calc.exe 2010-10-09 02:47:58 114688 -c–a-w- c:\windows\system32\calc.exe 2010-10-09 02:25:59 ——– dc-h–w- c:\windows\ie8 2010-10-09 02:25:21 ——– dc—-w- c:\program files\Microsoft 2010-10-09 02:25:18 ——– dc—-w- c:\program files\MSN Toolbar 2010-10-09 02:24:50 ——– dc—-w- c:\program files\Bing Bar Installer 2010-10-09 02:24:08 ——– dc-h–w- c:\windows\msdownld.tmp 2010-10-09 02:21:47 13312 -c—-w- c:\windows\system32\dllcache\iecompat.dll ==================== Find3M ==================== 2010-09-18 17:23:26 974848 -c–a-w- c:\windows\system32\mfc42u.dll 2010-09-18 06:53:25 974848 -c–a-w- c:\windows\system32\mfc42.dll 2010-09-18 06:53:25 954368 -c–a-w- c:\windows\system32\mfc40.dll 2010-09-18 06:53:25 953856 -c–a-w- c:\windows\system32\mfc40u.dll 2010-09-15 09:50:37 472808 -c–a-w- c:\windows\system32\deployJava1.dll 2010-09-15 07:29:49 73728 -c–a-w- c:\windows\system32\javacpl.cpl 2010-09-12 16:45:36 5845744 -c–a-w- c:\windows\system32\win32cpr.dll 2010-09-12 16:45:35 1872624 -c–a-w- c:\windows\system32\winsflt.dll 2010-09-10 05:58:08 916480 -c–a-w- c:\windows\system32\wininet.dll 2010-09-10 05:58:06 43520 -c–a-w- c:\windows\system32\licmgr10.dll 2010-09-10 05:58:06 1469440 -c—-w- c:\windows\system32\inetcpl.cpl 2010-09-08 16:17:46 94208 -c–a-w- c:\windows\system32\QuickTimeVR.qtx 2010-09-08 16:17:46 69632 -c–a-w- c:\windows\system32\QuickTime.qts 2010-09-01 11:51:14 285824 -c–a-w- c:\windows\system32\atmfd.dll 2010-08-31 13:42:52 1852800 -c–a-w- c:\windows\system32\win32k.sys 2010-08-27 08:02:29 119808 -c–a-w- c:\windows\system32\t2embed.dll 2010-08-27 05:57:43 99840 -c–a-w- c:\windows\system32\srvsvc.dll 2010-08-26 12:52:45 5120 -c–a-w- c:\windows\system32\xpsp4res.dll 2010-08-23 16:12:04 617472 -c–a-w- c:\windows\system32\comctl32.dll 2010-08-17 13:17:06 58880 -c–a-w- c:\windows\system32\spoolsv.exe 2010-08-16 08:45:00 590848 -c–a-w- c:\windows\system32\rpcrt4.dll 2003-12-07 04:12:54 121856 -csha-w- c:\windows\system32\fpplock.exe ============= FINISH: 15:34:13.17 ===============
Hi

Please do the following:


submit a file to virustotal for analysis
  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file G:\Philip\digiclok1.exe
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results
  • If you get a message saying File has already been analyzed: click Reanalyze file now
  • Once scanned, copy and paste the link to the results page in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI