This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Antivirus Studio 2010 infection

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys, So, I got the Antivirus Studio 2010 infection. I attempted to remove it with my Symantec AV software and Spybot S&D, but no luck. I didn't catch the pinned post here about it, and in the course of my attempts it killed my internet access. I don't have it with me, so I can't do the scans and such that you're supposed to do for opening a new thread. I'm not sure if I'll be able to do those in the future: I'm hesitant to connect stuff to that computer and then to another one, in case the infection jumps to the new media. I've seen it mentioned around the internets that the Malwarebytes software can remove it. Is that true? If it can't do it, I won't bother trying. Also, will removing the infection also restore internet access? If it won't, I may just back up the important stuff and wipe the system. Thanks!
:welcome:

Please don't attach the scans / logs, use "copy/paste".


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


Internet Explorer (Windows)
1. Click "Tools", then click "Internet Options". This will bring up the Internet Options window.

2. Click the "Connections" tab, then click the "LAN Settings" button.

3. Uncheck the box labeled "Use a proxy server for your LAN". Click "OK", and click "OK" in the previous window. This will remove the proxy server settings in Internet Explorer.



Firefox (Windows)
1. Click "Tools", then click "Options" to bring up the Options window.

2. Click the "Advanced" button, then click the "Network" tab.

3. Click the "Settings" button, located next to "Configure how Firefox connects to the Internet".

4. Click the radio button labeled "No proxy". Click "OK" twice. This will remove the proxy server settings in Firefox.



Next:

Disable Internet Explorer Proxy Settings and Reset TCP/IP and Winsock

Disable Internet Explorer Proxy Settings and Reset TCP/IP

It is very important that these steps be carried out exactly as shown otherwise the fix will not work.
If you have any questions please ask before moving on.
  • Please start Notepad and using your mouse make sure you select and copy all the information below in the Code box into your new document.
  • Then save the file as "fixme.bat" to your Desktop
  • In the drop down box for Save as type: make sure you select All Files (*.*) and keep the quotes on the name as well. Then close the new file.
    @ECHO OFF
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer /f
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyOverride /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyEnable  /t REG_DWORD /d 0 /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v GlobalUserOffline /t REG_DWORD /d 0 /f
    netsh int ip reset resetlog.txt
    netsh winsock reset catalog
  • On Windows XP you can double-click the file to run it.
  • On Vista/Win7 you need to Right click the file and choose Run as administrator to run it. With User Account Control on it should ask permission to run it. Click Yes
  • This will flash a black DOS box very quickly and go away, this is normal.
  • Restart your computer now.
  • Launch Internet Explorer and see if you can connect to the Internet.
  • Launch MBAM and check for Updates
Thanks! I haven't yet managed to try this (I'm not able to print for the moment), but hopefully I will get a chance tonight. I'm assuming MBAM is the Malwarebytes software. I don't yet have it- you're saying get it and update it, but don't run it yet?

Thanks! I haven't yet managed to try this (I'm not able to print for the moment), but hopefully I will get a chance tonight. I'm assuming MBAM is the Malwarebytes software. I don't yet have it- you're saying get it and update it, but don't run it yet?

Yes and yes.
Quick clarification/question: I cannot access the internet because Windows can't find my wireless card. I haven't tried a wired connection, but Device Manager and nothing shows up in Network Connections, so I think that won't work either. I've presumed it was due to the virus, but I suppose it's possible it's from a restart or something like that. Does that sound like it is a consequence of the virus, or not? Thanks!
I ran the first part of the fix, up to but not including the install of MBAM and didn't regain access. The wireless adapter is still not detected. It also can't detect the fingerprint reader, though the CD drive works just fine. I already have OTL and will run the scan as soon as I'm able. I'm currently writing my most important files to DVD and the computer is pretty occupied with that.
OTL Log follows. The "extras.txt" file I was expecting didn't appear. I don't know why. I also have MBAM on the machine now, though obviously I couldn't update it. I sent them an email to see if they could send me an update file I could download and run on the machine.





OTL logfile created on: 11/11/2010 8:05:49 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\berrid\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 21.55 Gb Free Space | 14.46% Space Free | Partition Type: NTFS
Drive D: | 4.38 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: BERRIDT61 | User Name: berrid | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\berrid\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Documents and Settings\berrid\Application Data\Dropbox\bin\Dropbox.exe ()
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE (Lenovo Group Limited)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\system32\mebeam.exe ()
PRC - C:\WINDOWS\system32\TpShocks.exe (Lenovo.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
PRC - C:\Program Files\Common Files\Logishrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - C:\Program Files\Iconoid\iconoid.exe (SillySot Software)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\berrid\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\nview.dll ()
MOD - C:\WINDOWS\system32\nvwddi.dll (NVIDIA Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (CoordinatorServiceHost) – C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe (Dassault Systèmes SolidWorks Corp.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Power Manager DBC Service) – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (SUService) – c:\Program Files\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (IBMPMSVC) – C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (AcPrfMgrSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (AcSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (TPHDEXLGSVC) – C:\WINDOWS\system32\TPHDEXLG.exe (Lenovo.)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (TVT Scheduler) – C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\Logishrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (ThinkVantage Registry Monitor Service) – C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (msvsmon80) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (TpKmpSVC) – C:\WINDOWS\system32\TpKmpSvc.exe ()
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – C:\WINDOWS\System32\DRIVERS\UIUSYS.SYS File not found
DRV - (PcdrNdisuio) – C:\WINDOWS\System32\DRIVERS\pcdrndisuio.sys File not found
DRV - (InCDRm) – C:\WINDOWS\System32\drivers\InCDRm.sys File not found
DRV - (InCDPass) – C:\WINDOWS\System32\drivers\InCDPass.sys File not found
DRV - (InCDFs) – C:\WINDOWS\System32\drivers\InCDFs.sys File not found
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101107.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101107.003\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (TSMAPIP) – C:\WINDOWS\system32\drivers\TSMAPIP.SYS ()
DRV - (TPPWRIF) – C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (IBMPMDRV) – C:\WINDOWS\system32\drivers\ibmpmdrv.sys (Lenovo.)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (tbhsd) – C:\WINDOWS\system32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (smihlp2) SMI Helper Driver (smihlp2) – C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys (UPEK Inc.)
DRV - (ANC) – C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (IBMTPCHK) – C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (TcUsb) – C:\WINDOWS\system32\drivers\tcusb.sys (UPEK Inc.)
DRV - (CVPNDRVA) – C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (Shockprf) – C:\WINDOWS\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\WINDOWS\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (TPHKDRV) – C:\WINDOWS\system32\drivers\TPHKDRV.sys (Lenovo Group Limited)
DRV - (ADIHdAudAddService) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (NiViPxiK) – C:\WINDOWS\system32\drivers\NiViPxiKl.sys (National Instruments Corporation)
DRV - (NiViPciK) – C:\WINDOWS\system32\drivers\NiViPciKl.sys (National Instruments Corporation)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (LVcKap) – C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam Pro 9000(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (lvpopflt) – C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (LVMVDrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (NiViFWK) – C:\WINDOWS\system32\drivers\NiViFWKl.sys (National Instruments Corporation)
DRV - (VClone) – C:\WINDOWS\system32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (psadd) – C:\WINDOWS\system32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (ElbyDelay) – C:\WINDOWS\system32\drivers\ElbyDelay.sys (Elaborate Bytes AG)
DRV - (CVirtA) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (CyUsb) – C:\WINDOWS\system32\drivers\IOBrdUSB.sys (Cypress Semiconductor)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (imagesrv) – C:\WINDOWS\system32\DRIVERS\imagesrv.sys (Ahead Software AG)
DRV - (imagedrv) – C:\WINDOWS\System32\Drivers\imagedrv.sys (Ahead Software AG)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs LLC)
DRV - (Ser2pl) – C:\WINDOWS\system32\drivers\ser2pl.sys (Prolific Technology Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: {936cdc4a-ba3f-4b6c-9abc-90a06a722341}:2.7.2.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.50
FF - prefs.js..extensions.enabledItems: {B66CFA13-CAE4-44C6-89A7-695D65DF50EE}:1.9.1
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}: C:\Documents and Settings\berrid\Local Settings\Application Data\Copy of BackUp{B66CFA13-CAE4-44C6-89A7-695D65DF50EE} [2010/11/08 17:48:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/29 08:37:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/29 08:37:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.7\extensions\\Components: C:\Program Files\Mozilla Sunbird\components [2010/10/15 18:02:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.6\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/11/03 08:48:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.6\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/10/15 18:02:40 | 000,000,000 | —D | M]

[2010/09/04 00:01:07 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Mozilla\Extensions
[2010/09/04 00:01:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\berrid\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/11/10 19:56:50 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions
[2010/04/28 08:51:59 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/19 00:39:49 | 000,000,000 | —D | M] (EngrTechLibrary Toolbar) – C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{936cdc4a-ba3f-4b6c-9abc-90a06a722341}
[2010/11/04 08:58:47 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/11/07 22:43:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/11/04 08:58:48 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\[removed]
[2009/04/11 12:02:50 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\[removed]
[2008/01/17 23:36:54 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Mozilla\Sunbird\Profiles\n5zjzwb7.default\extensions
[2008/06/22 18:18:26 | 000,001,108 | —- | M] () – C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\searchplugins\wikipedia-en.xml
[2010/11/07 22:34:20 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/02/07 20:46:12 | 000,087,360 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/02/07 20:46:20 | 000,091,448 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/02/07 20:46:16 | 000,021,824 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2007/03/16 16:27:00 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2007/03/16 16:27:00 | 000,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2007/03/16 16:27:00 | 000,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2008/09/03 19:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2009/04/10 14:43:03 | 000,072,960 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2008/02/07 20:48:26 | 000,419,136 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2010/03/28 11:18:09 | 000,151,552 | —- | M] (PopCap Games) – C:\Program Files\Mozilla Firefox\plugins\nppopcaploader.dll
[2008/05/19 13:57:00 | 002,641,920 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npRACtrl.dll
[2007/03/09 18:16:44 | 000,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
[2008/02/28 13:30:00 | 000,008,784 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ractrlkeyhook.dll
[2008/02/07 20:46:12 | 000,024,384 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2008/02/28 13:33:00 | 000,245,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\unicows.dll

O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\Utilities\BATLOGEX.DLL ()
O4 - HKLM..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe (brother)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
O4 - HKLM..\Run: [googleTalk MeBeam plugin] C:\WINDOWS\system32\mebeam.exe ()
O4 - HKLM..\Run: [IgfxTray.exe] C:\Program Files\Rosetta Stone\Rosetta Stone V3\Patch.exe File not found
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LENOVO.TPFNF6R] C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [LPMailChecker] C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [LPManager] C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NWEReboot] File not found
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [QuickFinder Scheduler] C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (Lenovo)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [AntiVirus 2010] C:\Documents and Settings\berrid\Application Data\AntiVirus 2010\AntiVirus_Studio_2010.exe (It Systems)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Bwixox] C:\WINDOWS\imsapr.DLL (Progressive Networks)
O4 - HKCU..\Run: [c4ubvnuvuff5] C:\DOCUME~1\berrid\LOCALS~1\Temp\vqvexyxa.exe File not found
O4 - HKCU..\Run: [Iconoid] C:\Program Files\Iconoid\iconoid.exe (SillySot Software)
O4 - HKCU..\Run: [SecurityCenter] C:\Documents and Settings\berrid\Application Data\AntiVirus 2010\securitycenter.exe (It Systems)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Purdue University VPN Client.lnk = C:\WINDOWS\Installer\{A7091E1D-36A4-47F1-A739-173CC341414F}\connected.ico ()
O4 - Startup: C:\Documents and Settings\berrid\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\berrid\Application Data\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Documents and Settings\berrid\Start Menu\Programs\Startup\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - ACNotify.dll - c:\program files\thinkpad\connectutilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\psfus: DllName - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (UPEK Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll ()
O24 - Desktop BackupWallPaper: C:\Documents and Settings\berrid\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/14 12:01:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{bd65758b-7aae-11de-a66d-0013e883238f}\Shell\Autoplay\command - "" = H:\usb_installer.exe – File not found
O33 - MountPoints2\{bd65758b-7aae-11de-a66d-0013e883238f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{bd65758b-7aae-11de-a66d-0013e883238f}\Shell\explore\Command - "" = H:\usb_installer.exe – File not found
O33 - MountPoints2\{bd65758b-7aae-11de-a66d-0013e883238f}\Shell\Open\Command - "" = H:\usb_installer.exe – File not found
O33 - MountPoints2\{eb0c141f-2856-11dd-a5c1-0013e883238f}\Shell - "" = AutoRun
O33 - MountPoints2\{eb0c141f-2856-11dd-a5c1-0013e883238f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{eb0c141f-2856-11dd-a5c1-0013e883238f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/11/11 19:44:05 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\berrid\Desktop\OTL.exe
[2010/11/11 19:44:01 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\berrid\Desktop\mbam-setup-1.46.exe
[2010/11/08 17:48:01 | 000,000,000 | —D | C] – C:\Documents and Settings\berrid\Local Settings\Application Data\Copy of BackUp{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}
[2010/11/07 22:58:41 | 000,000,000 | —D | C] – C:\Documents and Settings\berrid\Local Settings\Application Data\{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}
[2010/11/07 22:51:42 | 000,000,000 | —D | C] – C:\Documents and Settings\berrid\Desktop\GooredFix Backups
[2010/11/07 12:29:33 | 000,000,000 | —D | C] – C:\Documents and Settings\berrid\Application Data\AntiVirus 2010
[2010/11/05 23:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\berrid\Application Data\Amazon
[2010/11/05 23:37:30 | 000,000,000 | —D | C] – C:\Program Files\Amazon
[2010/10/17 19:00:13 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/17 19:00:13 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/17 19:00:04 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/15 18:05:48 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/10/15 10:02:57 | 000,000,000 | —D | C] – C:\Program Files\HJT
[2010/10/15 09:46:49 | 000,000,000 | —D | C] – C:\Documents and Settings\berrid\Application Data\QuickScan
[2010/10/14 23:00:40 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/11 19:06:19 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\berrid\Desktop\mbam-setup-1.46.exe
[2010/11/11 19:03:01 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\berrid\Desktop\OTL.exe
[2010/11/10 20:22:17 | 000,002,437 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Purdue University VPN Client.lnk
[2010/11/10 20:21:27 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\PMTask.job
[2010/11/10 20:20:54 | 000,293,710 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2010/11/10 20:20:36 | 000,182,918 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/11/10 20:20:20 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/10 20:18:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/10 20:18:18 | 2112,139,264 | -HS- | M] () – C:\hiberfil.sys
[2010/11/10 20:12:55 | 000,000,555 | —- | M] () – C:\Documents and Settings\berrid\Desktop\fixme.bat
[2010/11/10 20:11:10 | 000,001,857 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MSN Installer.lnk
[2010/11/09 00:40:21 | 000,000,245 | -HS- | M] () – C:\boot.ini
[2010/11/08 18:35:37 | 000,000,086 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/11/08 17:59:15 | 000,000,000 | —- | M] () – C:\WINDOWS\Bjegahukoziy.bin
[2010/11/07 22:57:09 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-527237240-725345543-1003UA.job
[2010/11/07 21:29:16 | 000,644,572 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/11/07 21:29:15 | 000,168,736 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/11/07 21:28:31 | 000,000,120 | —- | M] () – C:\WINDOWS\Mjeduwupomuk.dat
[2010/11/07 12:28:22 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/11/05 23:40:13 | 000,099,960 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/11/05 15:12:23 | 000,293,710 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2010/11/04 13:57:50 | 000,002,293 | —- | M] () – C:\Documents and Settings\berrid\Desktop\Google Chrome.lnk
[2010/11/03 22:18:33 | 000,011,391 | —- | M] () – C:\Documents and Settings\berrid\gsview32.ini
[2010/11/02 15:57:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-527237240-725345543-1003Core.job
[2010/11/02 13:58:55 | 000,002,429 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SolidWorks 2010.lnk
[2010/10/29 12:30:59 | 000,215,040 | —- | M] () – C:\Documents and Settings\berrid\Desktop\WashDCTrips.est
[2010/10/28 14:39:08 | 000,002,740 | —- | M] () – C:\Documents and Settings\berrid\Maple9.5.ini
[2010/10/28 14:39:08 | 000,001,250 | —- | M] () – C:\Documents and Settings\berrid\Untitled0_MAS.bak
[2010/10/18 09:08:45 | 000,199,182 | —- | M] () – C:\Documents and Settings\berrid\Desktop\BerridgeTR.pdf
[2010/10/17 19:55:25 | 000,000,900 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2010/10/17 19:43:56 | 000,452,472 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/17 19:15:43 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/10/15 18:30:50 | 000,001,620 | —- | M] () – C:\Documents and Settings\berrid\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/15 18:30:50 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/10/15 09:49:10 | 192,553,016 | —- | M] () – C:\hdata\PreViralRemoveOct2010.reg
[2010/10/15 09:21:33 | 000,000,933 | —- | M] () – C:\Documents and Settings\berrid\Desktop\Spybot - Search & Destroy.lnk
[2010/10/15 09:20:09 | 000,011,316 | —- | M] () – C:\Documents and Settings\berrid\_viminfo
[2010/10/15 08:57:43 | 000,000,999 | —- | M] () – C:\Documents and Settings\berrid\Start Menu\Programs\Startup\Dropbox.lnk
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/10 20:12:55 | 000,000,555 | —- | C] () – C:\Documents and Settings\berrid\Desktop\fixme.bat
[2010/11/10 20:11:09 | 000,001,857 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN Installer.lnk
[2010/11/08 18:35:37 | 000,000,086 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/11/08 17:49:34 | 2112,139,264 | -HS- | C] () – C:\hiberfil.sys
[2010/11/07 12:30:42 | 000,000,120 | —- | C] () – C:\WINDOWS\Mjeduwupomuk.dat
[2010/11/07 12:30:42 | 000,000,000 | —- | C] () – C:\WINDOWS\Bjegahukoziy.bin
[2010/10/29 12:29:52 | 000,215,040 | —- | C] () – C:\Documents and Settings\berrid\Desktop\WashDCTrips.est
[2010/10/15 18:30:50 | 000,001,620 | —- | C] () – C:\Documents and Settings\berrid\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/15 18:30:50 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/10/15 17:18:18 | 000,002,437 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Purdue University VPN Client.lnk
[2010/10/15 17:18:18 | 000,001,808 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/10/15 17:18:18 | 000,001,687 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
[2010/10/15 17:18:18 | 000,000,999 | —- | C] () – C:\Documents and Settings\berrid\Start Menu\Programs\Startup\Dropbox.lnk
[2010/10/15 17:18:18 | 000,000,986 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2010/10/15 17:18:18 | 000,000,947 | —- | C] () – C:\Documents and Settings\berrid\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010/10/15 17:18:18 | 000,000,734 | —- | C] () – C:\Documents and Settings\berrid\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
[2010/10/15 09:47:17 | 192,553,016 | —- | C] () – C:\hdata\PreViralRemoveOct2010.reg
[2010/10/15 09:21:33 | 000,000,933 | —- | C] () – C:\Documents and Settings\berrid\Desktop\Spybot - Search & Destroy.lnk
[2010/10/14 21:48:04 | 001,354,936 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/09/29 10:34:17 | 000,000,158 | —- | C] () – C:\WINDOWS\ricdb.ini
[2009/10/21 16:09:21 | 000,000,600 | —- | C] () – C:\Documents and Settings\berrid\Local Settings\Application Data\PUTTY.RND
[2009/10/14 20:14:59 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2009/10/14 20:14:59 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/10/14 20:14:14 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2009/10/14 20:14:13 | 000,009,853 | —- | C] () – C:\WINDOWS\HL-2140.INI
[2009/10/14 20:13:29 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/10/14 20:12:37 | 000,000,234 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/09/25 19:03:17 | 000,205,824 | —- | C] () – C:\WINDOWS\patchw32.dll
[2009/09/25 18:57:58 | 000,205,824 | —- | C] () – C:\WINDOWS\pw32a.dll
[2009/09/25 18:57:57 | 000,205,824 | —- | C] () – C:\WINDOWS\System32\pw32a.dll
[2009/09/11 16:20:00 | 000,000,180 | —- | C] () – C:\Documents and Settings\berrid\Application Data\setup.log
[2009/09/11 16:19:52 | 000,000,760 | —- | C] () – C:\Documents and Settings\berrid\Application Data\setup_ldm.iss
[2009/05/08 15:37:06 | 000,000,604 | —- | C] () – C:\Documents and Settings\berrid\Application Data\PrimoPDFSet.xml
[2009/05/08 15:33:20 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/05/08 15:31:07 | 000,000,336 | —- | C] () – C:\Program Files\temp995.bat
[2009/04/13 21:06:21 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2009/04/13 21:05:10 | 000,000,141 | —- | C] () – C:\WINDOWS\wpd99.drv
[2009/04/13 21:05:09 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2009/02/15 02:25:40 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/02/05 17:15:56 | 000,000,190 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/02/05 17:15:13 | 000,000,795 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/02/05 17:14:25 | 000,000,797 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/09/05 09:29:33 | 000,000,157 | —- | C] () – C:\WINDOWS\matlab.ini
[2008/07/12 17:01:53 | 000,001,161 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/06/19 18:08:52 | 000,197,408 | —- | C] () – C:\WINDOWS\System32\vpnapi.dll
[2008/06/19 17:08:44 | 000,193,312 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2008/06/18 13:59:56 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/05/29 14:03:38 | 000,059,500 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/05/24 16:36:06 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2008/04/18 13:49:10 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\WMIMPLEX.dll
[2008/04/18 13:49:10 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\maplec.dll
[2008/04/18 12:57:18 | 000,000,049 | —- | C] () – C:\WINDOWS\wwwbatch.ini
[2008/04/08 11:24:17 | 000,002,446 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/12/29 22:10:58 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/12/26 18:18:44 | 000,000,011 | —- | C] () – C:\WINDOWS\OSA.INI
[2007/12/25 21:51:17 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/12/04 01:10:45 | 000,007,168 | —- | C] () – C:\Documents and Settings\berrid\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/16 16:15:04 | 000,004,224 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2007/11/16 15:56:28 | 000,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2007/11/15 22:27:55 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/11/15 17:38:06 | 000,000,900 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/11/14 12:22:58 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2007/11/14 06:50:40 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/10/11 17:59:24 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/05/18 00:53:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/05/18 00:53:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/05/18 00:53:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/05/18 00:53:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/03/16 17:00:00 | 000,003,403 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2004/08/04 07:00:00 | 000,000,393 | R-S- | C] () – C:\Documents and Settings\berrid\Application Data\usernt.dat
[2002/03/21 14:39:02 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\UNACEV2.DLL
[2002/03/20 21:01:06 | 000,006,688 | —- | C] () – C:\WINDOWS\System32\Digita.sys
[2002/03/20 21:00:20 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\TransportUSB.dll
[2002/03/20 21:00:20 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\TransportSerial.dll
[2002/03/20 21:00:18 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\TransportIrDA.dll
[2002/03/20 21:00:18 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\TransportIrCOMM.dll

========== LOP Check ==========

[2009/09/15 19:41:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\24109
[2007/11/15 14:09:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2010/10/15 18:06:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/03/02 13:43:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk, Inc
[2007/11/15 17:37:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Borland
[2010/01/27 14:34:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Credant
[2008/07/12 16:53:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeRIP
[2008/05/24 16:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lenovo
[2010/03/13 18:49:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\National Instruments
[2008/05/24 16:52:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC-Doctor
[2009/05/08 15:24:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2010/03/28 11:18:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/04/18 13:08:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2009/05/29 09:12:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RapidSolution
[2008/12/30 19:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rosetta Stone
[2008/12/29 17:38:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdBackup
[2010/03/16 19:07:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2010/08/17 19:40:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/22 20:53:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Thomson.ResearchSoft.Installers
[2009/01/25 12:51:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UIB
[2010/05/19 13:34:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/09 23:48:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/14 21:00:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/09/02 14:30:24 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\.purple
[2007/11/15 22:05:00 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\ACD Systems
[2010/11/05 23:37:50 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Amazon
[2009/03/02 14:48:25 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Ansys
[2010/11/07 12:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\AntiVirus 2010
[2009/04/11 16:23:02 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Autodesk
[2010/07/03 16:56:49 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\BitTorrent
[2009/01/22 11:48:35 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Bullzip
[2010/11/11 20:04:18 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\DNA
[2010/11/10 20:22:56 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Dropbox
[2007/11/24 15:56:34 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\DWGEditor
[2010/01/18 16:55:01 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\EndNote
[2009/04/03 13:10:15 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Foxit
[2010/01/30 23:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\GARMIN
[2009/02/04 09:43:18 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\goombah
[2010/03/23 20:20:21 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\gtk-2.0
[2008/01/14 18:28:58 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Hummingbird
[2008/09/26 14:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\ICAClient
[2008/05/24 17:00:05 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Lenovo
[2010/05/13 09:46:54 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\lyx16
[2008/05/03 17:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Management-Ware
[2008/05/03 17:41:38 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Management-Ware Solutions Inc
[2010/02/18 14:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\MuPAD
[2009/04/13 21:06:22 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\pdf995
[2010/11/07 22:44:17 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\QuickScan
[2008/01/14 18:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Rensselaer Polytechnic Institute
[2009/02/03 22:45:15 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Ruckus Network
[2009/09/26 10:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\SystemRequirementsLab
[2010/03/16 19:11:11 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\TaxCut
[2010/09/04 00:01:02 | 000,000,000 | —D | M] – C:\Documents and Settings\berrid\Application Data\Thunderbird
[2010/11/10 20:21:27 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/11/14 12:01:34 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/11/09 00:40:21 | 000,000,245 | -HS- | M] () – C:\boot.ini
[2007/11/14 12:01:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/21 14:08:01 | 000,000,000 | —- | M] () – C:\gambit.fnl
[2010/11/10 20:18:18 | 2112,139,264 | -HS- | M] () – C:\hiberfil.sys
[2007/11/14 12:01:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/09/26 15:35:30 | 000,134,839 | —- | M] () – C:\Log.txt
[2007/11/14 12:01:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/16 10:41:11 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/10 20:18:15 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2008/01/01 23:09:17 | 000,000,027 | —- | M] () – C:\Report.txt
[2010/10/15 10:36:23 | 000,051,240 | —- | M] () – C:\TDSSKiller.2.4.4.0_15.10.2010_11.35.37_log.txt
[2009/01/12 16:01:17 | 000,344,725 | —- | M] () – C:\temp.wpd
[2009/09/21 19:55:07 | 000,003,048 | —- | M] () – C:\test_Tk.py
[2008/05/24 14:35:17 | 000,001,824 | —- | M] () – C:\TPHKLOCK.TXT
[1996/09/09 15:18:38 | 000,088,064 | —- | M] () – C:\uninstal.exe

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2007/11/14 12:01:11 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/01/16 18:45:58 | 000,241,664 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5k4.DLL
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/05/08 15:31:14 | 000,000,336 | —- | M] () – C:\Program Files\temp995.bat

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2007/11/14 06:44:16 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/11/14 06:44:16 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/11/14 06:44:16 | 000,917,504 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak ./s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/16 10:48:00 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/11/14 12:09:10 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\berrid\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/11/11 19:06:19 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\berrid\Desktop\mbam-setup-1.46.exe
[2010/11/11 19:03:01 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\berrid\Desktop\OTL.exe
[2009/10/21 14:30:58 | 000,454,656 | —- | M] (Simon Tatham) – C:\Documents and Settings\berrid\Desktop\putty.exe
[2009/08/12 12:05:47 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\berrid\Desktop\setup-spybotsd162.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-18 00:16:00

========== Alternate Data Streams ==========

@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD

< End of report >
O4 - HKCU..\Run: [AntiVirus 2010] C:\Documents and Settings\berrid\Application Data\AntiVirus 2010\AntiVirus_Studio_2010.exe (It Systems)
O4 - HKCU..\Run: [Bwixox] C:\WINDOWS\imsapr.DLL (Progressive Networks)
O4 - HKCU..\Run: [c4ubvnuvuff5] C:\DOCUME~1\berrid\LOCALS~1\Temp\vqvexyxa.exe File not found
O4 - HKCU..\Run: [SecurityCenter] C:\Documents and Settings\berrid\Application Data\AntiVirus 2010\securitycenter.exe (It Systems)

Bad guys are still there.


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Latest steps completed, the log is attached. Combofix installed the Recovery Console, so that's now available. Also, I installed MBAM and updated it with the latest definition files that they include in a file you can download without the program.

Formerly, my computer would boot fairly normally. The AV2010 stuff would pop up, but I could shut it down by terminating the two programs it ran in Task Manager. After that, it acted normally. However, it wasn't able to detect the wired or wireless adapters, nor could it find the fingerprint reader or the sound driver, and the theme I had installed was lost. Graphics and CD drive are apparently fine. Device Manager couldn't find anything at all when I opened it.

After running Combofix, I don't get the virus pop-ups, but the wireless and wired adapters are still not found, nor does it find the sound driver or the fingerprint reader.

I found two logs after I ran combofix, the one it opened itself, and a "resetlog.txt". I'm including both of them here in case you need them. Thanks so much for your help!

Combofix log follows:

ComboFix 10-11-11.02 - berrid 11/12/2010 19:31:06.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2014.1234 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\berrid\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\berrid\Application Data\AntiVirus 2010
c:\documents and settings\berrid\Application Data\AntiVirus 2010\AntiVirus_Studio_2010.exe
c:\documents and settings\berrid\Application Data\AntiVirus 2010\securitycenter.exe
c:\documents and settings\berrid\Application Data\AntiVirus 2010\securityhelper.exe
c:\documents and settings\berrid\Application Data\AntiVirus 2010\taskmgr.dll
c:\documents and settings\berrid\Application Data\usernt.dat
c:\documents and settings\berrid\Local Settings\Application Data\{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}
c:\documents and settings\berrid\Local Settings\Application Data\{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}\chrome.manifest
c:\documents and settings\berrid\Local Settings\Application Data\{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}\chrome\content\_cfg.js
c:\documents and settings\berrid\Local Settings\Application Data\{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}\chrome\content\overlay.xul
c:\documents and settings\berrid\Local Settings\Application Data\{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}\install.rdf
c:\documents and settings\berrid\Local Settings\Application Data\Copy of BackUp{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}
c:\documents and settings\berrid\Local Settings\Application Data\Copy of BackUp{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}\chrome.manifest
c:\documents and settings\berrid\Local Settings\Application Data\Copy of BackUp{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}\chrome\content\_cfg.js
c:\documents and settings\berrid\Local Settings\Application Data\Copy of BackUp{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}\chrome\content\overlay.xul
c:\documents and settings\berrid\Local Settings\Application Data\Copy of BackUp{B66CFA13-CAE4-44C6-89A7-695D65DF50EE}\install.rdf
c:\documents and settings\berrid\Start Menu\Programs\AntiVirus 2010
c:\documents and settings\berrid\Start Menu\Programs\AntiVirus 2010.lnk
c:\documents and settings\berrid\Start Menu\Programs\AntiVirus 2010\Activate AntiVirus 2010.lnk
c:\documents and settings\berrid\Start Menu\Programs\AntiVirus 2010\AntiVirus 2010.lnk
c:\documents and settings\berrid\Start Menu\Programs\AntiVirus 2010\Help AntiVirus 2010.lnk
c:\documents and settings\berrid\Start Menu\Programs\AntiVirus 2010\How to Activate AntiVirus 2010.lnk
c:\hdata\PreViralRemoveOct2010.reg
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\ex23567.dat
c:\windows\imsapr.dll
c:\windows\prxid93ps.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_dDNsFilter


((((((((((((((((((((((((( Files Created from 2010-10-13 to 2010-11-13 )))))))))))))))))))))))))))))))
.

2010-11-07 17:30 . 2010-11-08 22:59 0 —-a-w- c:\windows\Bjegahukoziy.bin
2010-11-06 04:37 . 2010-11-06 04:37 ——– d—–w- c:\documents and settings\berrid\Application Data\Amazon
2010-11-06 04:37 . 2010-11-06 04:37 ——– d—–w- c:\program files\Amazon
2010-10-18 00:00 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-18 00:00 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-18 00:00 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-15 19:09 . 2010-09-22 22:10 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-10-15 15:02 . 2010-10-15 15:02 ——– d—–w- c:\program files\HJT
2010-10-15 14:46 . 2010-11-08 03:44 ——– d—–w- c:\documents and settings\berrid\Application Data\QuickScan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-15 15:37 . 2004-08-04 12:00 61696 —-a-w- c:\windows\system32\drivers\ohci1394.sys
2010-09-18 16:23 . 2004-08-04 12:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-04 12:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-08-04 12:00 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-08-04 12:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2004-08-04 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2004-08-04 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-08-04 12:00 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2004-08-04 12:00 1852800 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2004-08-04 12:00 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2004-08-04 12:00 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-15 21:15 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2004-08-04 12:00 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-08-04 12:00 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2004-08-04 12:00 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2009-05-08 20:31 . 2009-05-08 20:31 336 —-a-w- c:\program files\temp995.bat
2008-02-08 01:46 . 2008-02-08 01:46 13624 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-02-08 01:46 . 2008-02-08 01:46 87360 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-02-08 01:46 . 2008-02-08 01:46 91448 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-02-08 01:46 . 2008-02-08 01:46 21824 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-02-08 01:46 . 2008-02-08 01:46 206136 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-02-08 01:46 . 2008-02-08 01:46 31544 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-02-08 01:46 . 2008-02-08 01:46 40248 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2007-03-16 21:27 . 2007-03-16 21:27 479232 —-a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2007-03-16 21:27 . 2007-03-16 21:27 548864 —-a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2007-03-16 21:27 . 2007-03-16 21:27 626688 —-a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-02-28 18:30 . 2008-07-09 15:58 8784 —-a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-07-20 16:47 . 2007-07-20 16:47 981170 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-02-08 01:46 . 2008-02-08 01:46 24384 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2008-02-28 18:33 . 2008-07-09 15:58 245408 —-a-w- c:\program files\mozilla firefox\plugins\unicows.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\berrid\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\berrid\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\berrid\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2010-08-24 1242448]
"Iconoid"="c:\program files\Iconoid\iconoid.exe" [2007-02-03 274432]
"Google Update"="c:\documents and settings\berrid\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-02 133104]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-10-15 323392]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-14 13549568]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 94208]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"TpShocks"="TpShocks.exe" [2008-06-06 181536]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"TPFNF7"="c:\progra~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-08-03 62240]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-10-06 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-10-06 1323008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-04-24 1036288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2006-07-05 77892]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2009-07-15 417792]
"nwiz"="nwiz.exe" [2009-01-14 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-14 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-09-01 165208]
"LPMailChecker"="c:\progra~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2008-09-01 124248]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-04-14 15136]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"googleTalk MeBeam plugin"="c:\windows\system32\mebeam.exe" [2008-06-12 310272]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-10-08 256576]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-09-18 880640]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2009-07-15 208896]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2010-09-23 38840]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-10-27 143360]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-10-27 425984]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]

c:\documents and settings\berrid\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\berrid\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-1-1 113664]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-5-24 805392]
Purdue University VPN Client.lnk - c:\windows\Installer\{A7091E1D-36A4-47F1-A739-173CC341414F}\connected.ico [2010-2-20 77414]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2008-11-21 05:35 95496 —-a-w- c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 20:37 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FTP Commander\\ftpcomm.exe"=
"c:\\Program Files\\Pidgin\\pidgin.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Live for Speed S2\\LFS.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Maple 9.5\\jre\\bin\\java.exe"=
"c:\\Program Files\\Maple 9.5\\bin.win\\mserver.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\MATLAB\\R2008b\\bin\\win32\\MATLAB.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [5/14/2008 3:21 PM 19496]
R2 smihlp2;SMI Helper Driver (smihlp2);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [11/21/2008 12:11 AM 12560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/4/2010 7:03 PM 102448]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\Lenovo\HOTKEY\micmute.exe [5/21/2009 7:48 PM 45424]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [1/10/2008 3:18 PM 11360]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [6/15/2010 8:14 AM 87336]
S3 CyUsb;Rensselaer IOBoard USB Driver;c:\windows\system32\drivers\IOBrdUSB.sys [11/2/2006 4:52 PM 34304]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [7/19/2007 10:48 AM 11384]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [1/10/2008 3:18 PM 11360]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [12/2/2006 5:17 AM 2805000]
S4 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [8/25/2008 2:27 PM 53248]
S4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 8:33 PM 116464]
S4 TPHKSVC;On Screen Display;c:\program files\Lenovo\HOTKEY\TPHKSVC.exe [3/2/2007 2:07 PM 62320]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
ddnsfilter REG_MULTI_SZ ddnsfilter

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}]
2008-06-18 19:04 8192 —-a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder

2010-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-527237240-725345543-1003Core.job
- c:\documents and settings\berrid\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-02 20:26]

2010-11-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-527237240-725345543-1003UA.job
- c:\documents and settings\berrid\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-02 20:26]

2010-11-13 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2007-11-16 05:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
FF - ProfilePath - c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{936cdc4a-ba3f-4b6c-9abc-90a06a722341}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{936cdc4a-ba3f-4b6c-9abc-90a06a722341}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - plugin: c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: c:\documents and settings\berrid\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Bwixox - c:\windows\imsapr.dll
HKCU-Run-AntiVirus 2010 - c:\documents and settings\berrid\Application Data\AntiVirus 2010\AntiVirus_Studio_2010.exe
HKLM-Run-NWEReboot - (no file)
HKLM-Run-IgfxTray.exe - c:\program files\Rosetta Stone\Rosetta Stone V3\Patch.exe
Notify-ACNotify - ACNotify.dll
SafeBoot-klmdb.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-12 20:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1123561945-527237240-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:94,ee,7e,85,0e,ec,79,ba,a8,a9,0a,29,4f,f2,c4,8b,90,bf,6f,f9,34,
89,6e,a8,88,23,f9,6f,6b,62,a4,a9,4f,09,3a,d6,5e,9a,73,db,fc,f2,4a,54,f5,0c,\
"rkeysecu"=hex:e9,cb,c8,5a,b6,59,7b,64,6a,03,6a,16,1e,cf,8c,54

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ ¬ ·*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1512)
c:\program files\thinkpad\connectutilities\ACNotify.dll
c:\program files\thinkpad\connectutilities\AcSvcStub.dll
c:\program files\thinkpad\connectutilities\AcLocSettings.dll
c:\windows\system32\MSVCR71.dll
c:\program files\thinkpad\connectutilities\ACHelper.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\gdiplus.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\qlbase.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll

- - - - - - - > 'lsass.exe'(1576)
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll

- - - - - - - > 'explorer.exe'(1668)
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\documents and settings\berrid\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\program files\Iconoid\tr3dll.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\TpShocks.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\Zoom\TpScrex.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2010-11-12 20:42:34 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-13 01:42

Pre-Run: 24,579,588,096 bytes free
Post-Run: 24,447,086,592 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30

- - End Of File - - 94B43EA675383BA4F02CBAE5601A2A56






And now resetlog.txt:



reset SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\15\RegLocation
old REG_MULTI_SZ =
SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\?\DhcpDomain
SYSTEM\CurrentControlSet\Services\TcpIp\Parameters\DhcpDomain

reset SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\NameServerList
old REG_MULTI_SZ =


reset SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\NameServerList
old REG_MULTI_SZ =


reset SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{DE38EF58-B157-49CC-832A-BE9F6C227B69}\NameServerList
old REG_MULTI_SZ =


added SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}\NetbiosOptions
added SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}\NetbiosOptions
deleted SYSTEM\CurrentControlSet\Services\Netbt\Parameters\EnableDns
deleted SYSTEM\CurrentControlSet\Services\Netbt\Parameters\EnableLmhosts
deleted SYSTEM\CurrentControlSet\Services\Netbt\Parameters\ScopeId
added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}\AddressType
added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}\DisableDynamicUpdate
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}\Mtu
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}\RawIpAllowedProtocols
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}\TcpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}\UdpAllowedPorts
old REG_MULTI_SZ =
0

added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38838E3F-F13F-439B-8D7A-082236AE18D7}\AddressType
added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38838E3F-F13F-439B-8D7A-082236AE18D7}\DisableDynamicUpdate
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38838E3F-F13F-439B-8D7A-082236AE18D7}\Mtu
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38838E3F-F13F-439B-8D7A-082236AE18D7}\RawIpAllowedProtocols
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38838E3F-F13F-439B-8D7A-082236AE18D7}\TcpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38838E3F-F13F-439B-8D7A-082236AE18D7}\UdpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\DefaultGateway
old REG_MULTI_SZ =


reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\DefaultGatewayMetric
old REG_MULTI_SZ =


added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\DisableDynamicUpdate
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\EnableDhcp
old REG_DWORD = 0

deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\IpAutoconfigurationAddress
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\IpAutoconfigurationMask
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\IpAutoconfigurationSeed
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\Mtu
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\RawIpAllowedProtocols
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\TcpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}\UdpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\DefaultGateway
old REG_MULTI_SZ =


added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\DisableDynamicUpdate
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\IpAutoconfigurationAddress
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\IpAutoconfigurationMask
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\IpAutoconfigurationSeed
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\Mtu
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\NameServer
old REG_SZ = 

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\RawIpAllowedProtocols
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\TcpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}\UdpAllowedPorts
old REG_MULTI_SZ =
0

added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}\AddressType
added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}\DisableDynamicUpdate
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}\Mtu
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}\RawIpAllowedProtocols
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}\TcpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}\UdpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\DefaultGateway
old REG_MULTI_SZ =


added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\DisableDynamicUpdate
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\IpAutoconfigurationAddress
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\IpAutoconfigurationMask
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\IpAutoconfigurationSeed
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\Mtu
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\NameServer
old REG_SZ = 

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\RawIpAllowedProtocols
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\TcpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DE38EF58-B157-49CC-832A-BE9F6C227B69}\UdpAllowedPorts
old REG_MULTI_SZ =
0

deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DisableTaskOffload
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DisableUserTosSetting
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DontAddDefaultGatewayDefault
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableIcmpRedirect
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableSecurityFilters
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer
old REG_SZ = 208.67.220.220,208.67.222.222

deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\TcpWindowSize
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution
reset Linkage\Bind for ms_server. bad value was:
REG_MULTI_SZ =
\Device\NetbiosSmb
\Device\NetBT_Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\NetBT_Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\NetBT_Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\NetBT_Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\NetBT_Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\NetBT_Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

reset Linkage\Route for ms_server. bad value was:
REG_MULTI_SZ =
"NetbiosSmb"
"NetBT" "Tcpip" "{61FFC18B-055D-4844-B04F-C7FC6B9D197A}"
"NetBT" "Tcpip" "{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}"
"NetBT" "Tcpip" "{379226E0-D14A-4D4A-9115-C9AADCC4DC94}"
"NetBT" "Tcpip" "{38838E3F-F13F-439B-8D7A-082236AE18D7}"
"NetBT" "Tcpip" "NdisWanIp"

reset Linkage\Export for ms_server. bad value was:
REG_MULTI_SZ =
\Device\LanmanServer_NetbiosSmb
\Device\LanmanServer_NetBT_Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\LanmanServer_NetBT_Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\LanmanServer_NetBT_Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\LanmanServer_NetBT_Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\LanmanServer_NetBT_Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\LanmanServer_NetBT_Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

reset Linkage\Bind for ms_netbios. bad value was:
REG_MULTI_SZ =
\Device\NetBT_Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\NetBT_Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\NetBT_Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\NetBT_Tcpip_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\NetBT_Tcpip_{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\NetBT_Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\NetBT_Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\NetBT_Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

reset Linkage\Route for ms_netbios. bad value was:
REG_MULTI_SZ =
"NetBT" "Tcpip" "{61FFC18B-055D-4844-B04F-C7FC6B9D197A}"
"NetBT" "Tcpip" "{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}"
"NetBT" "Tcpip" "{379226E0-D14A-4D4A-9115-C9AADCC4DC94}"
"NetBT" "Tcpip" "{6D9C39AA-3D62-44B8-9EC5-809695A277AC}"
"NetBT" "Tcpip" "{DE38EF58-B157-49CC-832A-BE9F6C227B69}"
"NetBT" "Tcpip" "{38838E3F-F13F-439B-8D7A-082236AE18D7}"
"NetBT" "Tcpip" "NdisWanIp"

reset Linkage\Export for ms_netbios. bad value was:
REG_MULTI_SZ =
\Device\NetBIOS_NetBT_Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\NetBIOS_NetBT_Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\NetBIOS_NetBT_Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\NetBIOS_NetBT_Tcpip_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\NetBIOS_NetBT_Tcpip_{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\NetBIOS_NetBT_Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\NetBIOS_NetBT_Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\NetBIOS_NetBT_Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

reset Linkage\Bind for ms_msclient. bad value was:
REG_MULTI_SZ =
\Device\NetbiosSmb
\Device\NetBT_Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\NetBT_Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\NetBT_Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\NetBT_Tcpip_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\NetBT_Tcpip_{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\NetBT_Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\NetBT_Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\NetBT_Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

reset Linkage\Route for ms_msclient. bad value was:
REG_MULTI_SZ =
"NetbiosSmb"
"NetBT" "Tcpip" "{61FFC18B-055D-4844-B04F-C7FC6B9D197A}"
"NetBT" "Tcpip" "{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}"
"NetBT" "Tcpip" "{379226E0-D14A-4D4A-9115-C9AADCC4DC94}"
"NetBT" "Tcpip" "{6D9C39AA-3D62-44B8-9EC5-809695A277AC}"
"NetBT" "Tcpip" "{DE38EF58-B157-49CC-832A-BE9F6C227B69}"
"NetBT" "Tcpip" "{38838E3F-F13F-439B-8D7A-082236AE18D7}"
"NetBT" "Tcpip" "NdisWanIp"

reset Linkage\Export for ms_msclient. bad value was:
REG_MULTI_SZ =
\Device\LanmanWorkstation_NetbiosSmb
\Device\LanmanWorkstation_NetBT_Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\LanmanWorkstation_NetBT_Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\LanmanWorkstation_NetBT_Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\LanmanWorkstation_NetBT_Tcpip_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\LanmanWorkstation_NetBT_Tcpip_{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\LanmanWorkstation_NetBT_Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\LanmanWorkstation_NetBT_Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\LanmanWorkstation_NetBT_Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

reset Linkage\Bind for s24trans. bad value was:
REG_MULTI_SZ =
\Device\{DE38EF58-B157-49CC-832A-BE9F6C227B69}

reset Linkage\Route for s24trans. bad value was:
REG_MULTI_SZ =
"{DE38EF58-B157-49CC-832A-BE9F6C227B69}"

reset Linkage\Export for s24trans. bad value was:
REG_MULTI_SZ =
\Device\s24trans_{DE38EF58-B157-49CC-832A-BE9F6C227B69}

reset Linkage\Bind for pcdr_pcdrndisuio. bad value was:
REG_MULTI_SZ =
\Device\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}

reset Linkage\Route for pcdr_pcdrndisuio. bad value was:
REG_MULTI_SZ =
"{61FFC18B-055D-4844-B04F-C7FC6B9D197A}"
"{DE38EF58-B157-49CC-832A-BE9F6C227B69}"
"{6D9C39AA-3D62-44B8-9EC5-809695A277AC}"
"{379226E0-D14A-4D4A-9115-C9AADCC4DC94}"
"{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}"

reset Linkage\Export for pcdr_pcdrndisuio. bad value was:
REG_MULTI_SZ =
\Device\PcdrNdisuio_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\PcdrNdisuio_{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\PcdrNdisuio_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\PcdrNdisuio_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\PcdrNdisuio_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}

reset Linkage\Bind for ms_ndisuio. bad value was:
REG_MULTI_SZ =
\Device\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\{DE38EF58-B157-49CC-832A-BE9F6C227B69}

reset Linkage\Route for ms_ndisuio. bad value was:
REG_MULTI_SZ =
"{61FFC18B-055D-4844-B04F-C7FC6B9D197A}"
"{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}"
"{379226E0-D14A-4D4A-9115-C9AADCC4DC94}"
"{6D9C39AA-3D62-44B8-9EC5-809695A277AC}"
"{DE38EF58-B157-49CC-832A-BE9F6C227B69}"

reset Linkage\Export for ms_ndisuio. bad value was:
REG_MULTI_SZ =
\Device\Ndisuio_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\Ndisuio_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\Ndisuio_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\Ndisuio_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\Ndisuio_{DE38EF58-B157-49CC-832A-BE9F6C227B69}

reset Linkage\Bind for ms_pppoe. bad value was:
REG_MULTI_SZ =
\Device\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\{DE38EF58-B157-49CC-832A-BE9F6C227B69}

reset Linkage\Route for ms_pppoe. bad value was:
REG_MULTI_SZ =
"{61FFC18B-055D-4844-B04F-C7FC6B9D197A}"
"{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}"
"{379226E0-D14A-4D4A-9115-C9AADCC4DC94}"
"{6D9C39AA-3D62-44B8-9EC5-809695A277AC}"
"{DE38EF58-B157-49CC-832A-BE9F6C227B69}"

reset Linkage\Export for ms_pppoe. bad value was:
REG_MULTI_SZ =
\Device\RasPppoe_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\RasPppoe_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\RasPppoe_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\RasPppoe_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\RasPppoe_{DE38EF58-B157-49CC-832A-BE9F6C227B69}

reset Linkage\Bind for ms_ndiswan. bad value was:
REG_MULTI_SZ =
\Device\{F743DC8B-F053-409D-813A-294E08095405}
\Device\{D135B1FA-8598-4BA9-944E-5270B6154CEB}
\Device\{75A6425E-573A-47A4-8463-A68BA8C52906}
\Device\{41E9E6D8-6443-4783-8CA0-F26C0B8D1045}
\Device\{A1482725-8494-4F8C-825A-985B72550FD8}

reset Linkage\Route for ms_ndiswan. bad value was:
REG_MULTI_SZ =
"{F743DC8B-F053-409D-813A-294E08095405}"
"{D135B1FA-8598-4BA9-944E-5270B6154CEB}"
"{75A6425E-573A-47A4-8463-A68BA8C52906}"
"{41E9E6D8-6443-4783-8CA0-F26C0B8D1045}"
"{A1482725-8494-4F8C-825A-985B72550FD8}"

reset Linkage\Export for ms_ndiswan. bad value was:
REG_MULTI_SZ =
\Device\NdisWan_{F743DC8B-F053-409D-813A-294E08095405}
\Device\NdisWan_{D135B1FA-8598-4BA9-944E-5270B6154CEB}
\Device\NdisWan_{75A6425E-573A-47A4-8463-A68BA8C52906}
\Device\NdisWan_{41E9E6D8-6443-4783-8CA0-F26C0B8D1045}
\Device\NdisWan_{A1482725-8494-4F8C-825A-985B72550FD8}

reset Linkage\Bind for ms_netbt. bad value was:
REG_MULTI_SZ =
\Device\Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\Tcpip_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\Tcpip_{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

reset Linkage\Route for ms_netbt. bad value was:
REG_MULTI_SZ =
"Tcpip" "{61FFC18B-055D-4844-B04F-C7FC6B9D197A}"
"Tcpip" "{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}"
"Tcpip" "{379226E0-D14A-4D4A-9115-C9AADCC4DC94}"
"Tcpip" "{6D9C39AA-3D62-44B8-9EC5-809695A277AC}"
"Tcpip" "{DE38EF58-B157-49CC-832A-BE9F6C227B69}"
"Tcpip" "{38838E3F-F13F-439B-8D7A-082236AE18D7}"
"Tcpip" "NdisWanIp"

reset Linkage\Export for ms_netbt. bad value was:
REG_MULTI_SZ =
\Device\NetBT_Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\NetBT_Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\NetBT_Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\NetBT_Tcpip_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\NetBT_Tcpip_{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\NetBT_Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\NetBT_Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\NetBT_Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

reset Linkage\Bind for ms_tcpip. bad value was:
REG_MULTI_SZ =
\Device\{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\NdisWanIp

reset Linkage\Route for ms_tcpip. bad value was:
REG_MULTI_SZ =
"{61FFC18B-055D-4844-B04F-C7FC6B9D197A}"
"{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}"
"{379226E0-D14A-4D4A-9115-C9AADCC4DC94}"
"{6D9C39AA-3D62-44B8-9EC5-809695A277AC}"
"{DE38EF58-B157-49CC-832A-BE9F6C227B69}"
"{38838E3F-F13F-439B-8D7A-082236AE18D7}"
"NdisWanIp"

reset Linkage\Export for ms_tcpip. bad value was:
REG_MULTI_SZ =
\Device\Tcpip_{61FFC18B-055D-4844-B04F-C7FC6B9D197A}
\Device\Tcpip_{C6024FD8-A9FC-454F-821B-5DC6CBC19D28}
\Device\Tcpip_{379226E0-D14A-4D4A-9115-C9AADCC4DC94}
\Device\Tcpip_{6D9C39AA-3D62-44B8-9EC5-809695A277AC}
\Device\Tcpip_{DE38EF58-B157-49CC-832A-BE9F6C227B69}
\Device\Tcpip_{38838E3F-F13F-439B-8D7A-082236AE18D7}
\Device\Tcpip_{EA063616-91A6-420B-B39D-01F52B53BD21}
\Device\Tcpip_{F71E8928-087E-4D07-A3D0-8C99DF411757}

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

File::
c:\windows\Bjegahukoziy.bin

Reglock::
[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ ¬ ·*]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
I've now run the most recent steps. I don't notice any change in the operation of the computer: it still acts fine except that the sound driver, fingerprint reader, and ethernet adapters are not found. Let me know if you need more detail in the description, I'm not sure what else to include.

Here's the log:


ComboFix 10-11-11.02 - berrid 11/13/2010 12:27:11.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2014.1290 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\berrid\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

FILE ::
"c:\windows\Bjegahukoziy.bin"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Bjegahukoziy.bin

.
((((((((((((((((((((((((( Files Created from 2010-10-13 to 2010-11-13 )))))))))))))))))))))))))))))))
.

2010-11-13 03:42 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-13 03:42 . 2010-11-13 03:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-11-13 03:42 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-11-13 03:42 . 2010-11-13 03:42 ——– d—–w- c:\program files\MBAM
2010-11-06 04:37 . 2010-11-06 04:37 ——– d—–w- c:\documents and settings\berrid\Application Data\Amazon
2010-11-06 04:37 . 2010-11-06 04:37 ——– d—–w- c:\program files\Amazon
2010-10-18 00:00 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-18 00:00 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-18 00:00 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-15 19:09 . 2010-09-22 22:10 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-10-15 15:02 . 2010-10-15 15:02 ——– d—–w- c:\program files\HJT
2010-10-15 14:46 . 2010-11-08 03:44 ——– d—–w- c:\documents and settings\berrid\Application Data\QuickScan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-15 15:37 . 2004-08-04 12:00 61696 —-a-w- c:\windows\system32\drivers\ohci1394.sys
2010-09-18 16:23 . 2004-08-04 12:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-04 12:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-08-04 12:00 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-08-04 12:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2004-08-04 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2004-08-04 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-08-04 12:00 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2004-08-04 12:00 1852800 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2004-08-04 12:00 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2004-08-04 12:00 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-15 21:15 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2004-08-04 12:00 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-08-04 12:00 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2004-08-04 12:00 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2009-05-08 20:31 . 2009-05-08 20:31 336 —-a-w- c:\program files\temp995.bat
2008-02-08 01:46 . 2008-02-08 01:46 13624 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-02-08 01:46 . 2008-02-08 01:46 87360 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-02-08 01:46 . 2008-02-08 01:46 91448 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-02-08 01:46 . 2008-02-08 01:46 21824 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-02-08 01:46 . 2008-02-08 01:46 206136 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-02-08 01:46 . 2008-02-08 01:46 31544 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-02-08 01:46 . 2008-02-08 01:46 40248 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2007-03-16 21:27 . 2007-03-16 21:27 479232 —-a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2007-03-16 21:27 . 2007-03-16 21:27 548864 —-a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2007-03-16 21:27 . 2007-03-16 21:27 626688 —-a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-02-28 18:30 . 2008-07-09 15:58 8784 —-a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-07-20 16:47 . 2007-07-20 16:47 981170 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-02-08 01:46 . 2008-02-08 01:46 24384 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2008-02-28 18:33 . 2008-07-09 15:58 245408 —-a-w- c:\program files\mozilla firefox\plugins\unicows.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\berrid\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\berrid\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\berrid\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2010-08-24 1242448]
"Iconoid"="c:\program files\Iconoid\iconoid.exe" [2007-02-03 274432]
"Google Update"="c:\documents and settings\berrid\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-02 133104]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-10-15 323392]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-14 13549568]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 94208]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"TpShocks"="TpShocks.exe" [2008-06-06 181536]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"TPFNF7"="c:\progra~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-08-03 62240]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-10-06 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-10-06 1323008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-04-24 1036288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2006-07-05 77892]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2009-07-15 417792]
"nwiz"="nwiz.exe" [2009-01-14 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-14 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-09-01 165208]
"LPMailChecker"="c:\progra~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2008-09-01 124248]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-04-14 15136]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"googleTalk MeBeam plugin"="c:\windows\system32\mebeam.exe" [2008-06-12 310272]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-10-08 256576]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-09-18 880640]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2009-07-15 208896]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2010-09-23 38840]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-10-27 143360]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-10-27 425984]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]

c:\documents and settings\berrid\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\berrid\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-1-1 113664]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-5-24 805392]
Purdue University VPN Client.lnk - c:\windows\Installer\{A7091E1D-36A4-47F1-A739-173CC341414F}\connected.ico [2010-2-20 77414]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2008-11-21 05:35 95496 —-a-w- c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 20:37 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FTP Commander\\ftpcomm.exe"=
"c:\\Program Files\\Pidgin\\pidgin.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Live for Speed S2\\LFS.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Maple 9.5\\jre\\bin\\java.exe"=
"c:\\Program Files\\Maple 9.5\\bin.win\\mserver.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\MATLAB\\R2008b\\bin\\win32\\MATLAB.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [5/14/2008 3:21 PM 19496]
R2 smihlp2;SMI Helper Driver (smihlp2);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [11/21/2008 12:11 AM 12560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/4/2010 7:03 PM 102448]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\Lenovo\HOTKEY\micmute.exe [5/21/2009 7:48 PM 45424]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [1/10/2008 3:18 PM 11360]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [6/15/2010 8:14 AM 87336]
S3 CyUsb;Rensselaer IOBoard USB Driver;c:\windows\system32\drivers\IOBrdUSB.sys [11/2/2006 4:52 PM 34304]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [7/19/2007 10:48 AM 11384]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [1/10/2008 3:18 PM 11360]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [12/2/2006 5:17 AM 2805000]
S4 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [8/25/2008 2:27 PM 53248]
S4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 8:33 PM 116464]
S4 TPHKSVC;On Screen Display;c:\program files\Lenovo\HOTKEY\TPHKSVC.exe [3/2/2007 2:07 PM 62320]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
ddnsfilter REG_MULTI_SZ ddnsfilter

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}]
2008-06-18 19:04 8192 —-a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder

2010-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-527237240-725345543-1003Core.job
- c:\documents and settings\berrid\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-02 20:26]

2010-11-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-527237240-725345543-1003UA.job
- c:\documents and settings\berrid\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-02 20:26]

2010-11-13 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2007-11-16 05:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
FF - ProfilePath - c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{936cdc4a-ba3f-4b6c-9abc-90a06a722341}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{936cdc4a-ba3f-4b6c-9abc-90a06a722341}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\berrid\Application Data\Mozilla\Firefox\Profiles\0hhhq7fa.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-13 12:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1123561945-527237240-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:94,ee,7e,85,0e,ec,79,ba,a8,a9,0a,29,4f,f2,c4,8b,90,bf,6f,f9,34,
89,6e,a8,88,23,f9,6f,6b,62,a4,a9,4f,09,3a,d6,5e,9a,73,db,fc,f2,4a,54,f5,0c,\
"rkeysecu"=hex:e9,cb,c8,5a,b6,59,7b,64,6a,03,6a,16,1e,cf,8c,54

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ ¬ ·*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1512)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\qlbase.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\windows\system32\WlNotify.dll

- - - - - - - > 'lsass.exe'(1576)
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll

- - - - - - - > 'explorer.exe'(2092)
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\documents and settings\berrid\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\nvwddi.dll
c:\program files\Iconoid\tr3dll.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\TpShocks.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\Zoom\TpScrex.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2010-11-13 13:06:16 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-13 18:06
ComboFix2.txt 2010-11-13 01:42

Pre-Run: 24,441,016,320 bytes free
Post-Run: 24,426,586,112 bytes free

- - End Of File - - 5488E8DBD5F66DD820FF4DF46696013D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI