This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.Vundo.H

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been trying to get rid of this all morning please help I work online and afraid to right now because of this, is this trojan real bad? here are my log files

MBAM LOG


Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5343

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

12/17/2010 11:20:29 AM
mbam-log-2010-12-17 (11-20-29).txt

Scan type: Quick scan
Objects scanned: 131771
Time elapsed: 3 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on reboot.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on reboot.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

HIJACK LOG

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:04:05 PM, on 12/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/home/home.do
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~1\ArcSoft\MEDIAC~1\INTERN~1\ARCURL~1.DLL
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Watch for Browser Events - {42A7CE31-CEE7-4CCE-A060-A44A7E52E062} - C:\PROGRA~1\KEYBOA~1\kie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 7114 bytes
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Run a new MBAM scan and post the results
here is the MBAM log from this morning Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5343 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 12/18/2010 7:47:19 AM mbam-log-2010-12-18 (07-47-05).txt Scan type: Quick scan Objects scanned: 131927 Time elapsed: 2 minute(s), 37 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
So it appears the bad guys aren't really staying dead.



DO NOT use any TOOLS such as Combofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


Next:

Close all browsers before running ATF: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
I have looked the how to disable my AVG anti-virus and I can not disable it. It is the AVG 2011 version, how do I disable it? will be writing down all that is listed above and wont do anything until I hear back from you, and thanks in advance for all your help.
Due to recent changes in AVG and how it interacts with CF, AVG must be uninstalled to run ComboFix.

AVG > AVG Removal Tool (x86) - AVG Removal Tool (x64)
AVG Identity Protection > AVGIDPUninstaller


If AVG will not uninstall, it is first recommended to uninstall it with AppRemover by Opswat. The AVG uninstaller can be downloaded from here > http://www.appremove.../AppRemover.exe Go to their homepage and you will see they have support for removal of other AV's as well http://www.appremover.com/
COMBOFIX.TXT LOG IS AS FOLLOWS


ComboFix 10-12-18.01 - user 12/18/2010 12:46:08.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.319.111 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\user\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\Internet Explorer\msimg32.dll
c:\windows\system32\mftxaivv.ini
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2010-11-18 to 2010-12-18 )))))))))))))))))))))))))))))))
.

2010-12-17 19:03 . 2010-12-17 19:03 388096 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-17 19:03 . 2010-12-17 19:03 ——– d—–w- c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-30 00:42 . 2008-12-08 02:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-30 00:42 . 2008-12-08 02:22 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LegacyDrive"= 2a3efff3e35dff2016d79b643ccad1d8de2e0462134fa0d24481fc2a330f843c3c74177bdaceae0b
6c8f3f1a3a76e073b3bd3050f894f3709fcffc6ab0dc5041f4f7883870a177e82c4e0d8fc9385e7ba
bf14e98c881308496a5588b3eb3594cf6db2f1ad3adbea2dfdb7bce6c416aeaa822480571b5099b6a
e085704e436ebf84788594f4990d771a03804a585a827491cd1340f39c087f14ead7bc75416803f31
2535fc0423d773dbe2bc449fc8d8e638e7b170ef73e157abd126660bf2a002ec9f5276466a0e23ef6
dcaf9300e176fdc9b3bc3a25a419d28d1aecfa72924db9d1e5434908b6ca37c0e79da9ef0b5f228b6
7fd6a8a24d5fad0ab76b40b00a7d2dc51ab1d37cec45f0cbcf61a27c50d7a5493e189c89dd9a2bc40
ae285b117277de72d01bf66395406a9b6f6a01d7f567a273a6e881ba37b9f7de734bafb14ef925095
bdba74d6d45c421ad910246e91fcfbb2f99ba299b7ce37d6dd4b0d75e46c2a33454280595ddd27b19
e348bea2919be8f07d9cdc702a4de355d19593eaaa6138f527c405e6826451be07eea530ab55b471d
e1a909d5fcc1d5654cac5ae9a506d475ab2a8b8dde22b33a1388165ac73009e20fbfc3210683a1f92
48a8f0151d4be1f5a678434d6047220cbc4b45264cf169b7dfa54a642a098e8636d2a62004d0b80a2
128dd4f7be48dd373af573933d9d60342a2e0fb55b400d269f127080e6f9e0b06c13fa30e79e58dfc
ea21660a332fcb727828bf3bc773784d522c936edc04e42ccbf80608af24379acf860a7779055b579
6b28878814dde3d1a0b521b159672b598569b4606ef6b40150b7932275944efd7d56aedd24b1bebe8
16ccd7622e30ee97c3626425bae169c8f6ffd861bd36d1db5d6b35e7d473159fe5d66a696bd3061fe
ea4ca6d74021a7a99ec8ecae2a5ea624ffc512e2fcfb5a138d2929bd78ddc8fc5a435e5db5b649d27
5903363fb6ac77ced50e258a8c67e3380a92ad334f649a8745eb0e5698f3307bc7cf9f6c7c5660651
82b1bc3934188ad839f24fa7a61284f9500bb8852d3675aa2d5ca3640a88e7040da9aa0eb678a48ca
c8805db8018b6e2fde6ba643b201ef83e0f3ec5a33ace73675a40bea3de1d35108bdc2358beb556f4
8b5354f6087b23ea8b16da1fe695401de0fd46930b5491064dfba38c187c356fa65d27303bd6d96d2
2298b5d349e7be17a3a55ee56dedd6cd076dac8b4b69a12d1d03e47843b98589772f2cb8bb2f0bc1e
dee11269b9161cf18ef02f4d099d83cd817d327c97566a9cffe3b17fd482547e4df7155f363a7d25f
c0ee233cf81d4ecb542a07463da8217b518e48bab63af2f1afb693166d3910c527f1772b6dffed22b
9c3e79d475b9e472666bc678f0e5c0776453155604e054974806688d4c3479c892e6bddf68d95c455
760f00e730cb49d063a79979e4ef9833d023581dd8fb4247dba95117ba5e7dec680f7b024079a3959
c63314aa323b1ca6263b5b01e25c9a5e905a9c974beb15524d8f0947f6821519e4901638f42f23857
53c7e50a51cc18eb80074ed463be46d9d339b5284fc93b33930996126c641522cad850f317f91761c
738a800316525be9d7345c39e7c499ca2043299c7a0823173f01c5f3218b3ae4ee71f1f1583bc364c
a925ab19fc3f63209d7a9eedfb537292ed1d7891fe02c5fc07451cda04c961cd20d751f2121c7109a
cf144d6b1dfc1c6e86304d66eee44b150db30051859968f8729129e16871a5b9df8f38b1b912f0759
09746cca128013b6ea6a44972d2ba6c3ed5cfa4c04410925a907db86424a2a9179da163592bf1a53f
c7b3f1f268e90c99340cd5d31d89a64e8e7b69cdd6d3814b7601d6cdf96b442cfaee96078ecc933e1
44437f12b52c5230d98636e9b902ab12e5c3d58fc56571742a3e0d6928e4795328ef79313900bc43a
7011272cfafd9ec31c956b80fc7dc90889501b0bc82e5496666cb2182641c8b6a7aaf96405647858b
6c5e7f25452188541abbb037a1d68a64275fe0cfdf8aa5ed7a172b1af7d39638bd61919ae73a3f20d
ff375a32e99be269392341fde5152f414cec13ac95a5af63b4ce9563554319f340c3167c7d0a6043c
d0d14478637a5e279e35291626e48cdc427d36c0350e8fd7cafeee6d30950ca608beb865bd0ccd6d1
4f2fc62c6047a4063c7a6990131d7f65241e0725bf593261b6384e46d060f282f569d4ba49b22fa17
02eae7c2f196beed98615b5ac8a93ae109aa2f58e78c57b58ca04e7794e6a2421cd488c91c9652cef
0f709113251dd304121b800ed078a4247df8ed20696ce202a3ce9e4de5b140ea3885ffcab3739f083
d337c1f50f11d12d76ed3e1a4ae15d178bb364cb56e3664e70eb858d23c562ef4995aed939a62aeca
e7b48fc7b57273f5331b96e57b4c7be38da35129fbc886fcda8a5b07e75db7b14132473f166a8af25
55836b491ec8feaaecc60caaab8afd641ba4ae8f232e66a5680b0b441fd56d96d41f9ac46a3bef0ee
cce25dc7697d3f6fdc8343b33592b95aaa2842c3b297ddaa9b985df82b443d746a9dae8cb296c40e0
d7dcbf31bfd9f06ae9183ea02de065ec48cc265930cc3f00a5c56e9a71095cc5557125a252fc40602
f634da939d29f1de5f7f800b658932f61e968592fdeab6ba4be964c5eb968cb3f3baed5cfc1c1ecdb
eb90d462d39f90b29e508ccf50611c14e5b7251d9dc85a1ae397c02b29a14eb9184f1c0c264af9483
cebaf9d170987bfee0f109656511d3663a00d11111b4f6be249240fc865a74144f90bf3d0ae253b7b
632a05d37cb905077d1cf04dd7cbec82019f314510cbb36115f0eff6c2ea417a000a8cdc5ac737711
7567531a67cca2340a1ca16c8252492f6f7e00eb463e563c82bbe81b4da9e61da55a13ae4b354f863
4e78eab61a03bb2e3668a36fc1ab18de1aef495ea95cf6bd99a02775cf2372533532c229a45357c30
6d60e1dbcade3d33d7db4d900f5476c9c5f8f492e752b1cfc75303b58782894c6ff5ae461cf4c2a7a
ff875c834f9a582bbbf5621dcb50883b013f4a889a307f15b6d8d56126ce5ecc199a4b4ef80ff6688
edb265b6c5d8f998cb699793423632e1d8a06fad5521e9f6278871628e064840ce9666ada434a1ce4
05a474ecfaf7dcc7453c76183405968c9cc1c31edb68eb94ef0aa7b2ddabc1ad5352f3e28c5df2c87
417ab240d8dcd7c119d87cdd84f93807d68739b3c3dfb351fc60f2cdaf3ae1af3432f842692cb5507
32b95c8be93e6431ff2b518dc1a0009a91887fb89f6517a30ae78aa247bd9900c7abc9c0d4dd678db
c7bcaf0327dd8c6f1c1cbf0a25a354c002b42e43ab53e66992e57d462d3a37dfe7e652c587bc38c9f
87987c3bad7b11fd1f39e1b4c623c26ec4e38c305bc920ea0b5faaa9fb43220f9a3619008670b29fa
d36ef79b2af2eff92f4f33a8766e7ba2d4421d0e37ca5fc74c22aa9f6e02118f34db5f29bc7008903
4986115bae53ffd7a9565307d7cf1a505b65389dc573645239a47481cdbfdb6132c470fc97377027c
abcc7b7a1e48bf29847ca44bbd38533c763fc958c932c0195d397830bbbc44394d79e05490762ffca
738f6806a0a58ba5e4b3133ecb2585cbbade0e5ad2877f0417269623d2f27fc033659a4b3b947f8fd
9bc3fe4541deda7e80b5ee7b4422c61d37a01afca3b12bc22f3d1e97b554568d9efa50befed226d7d
69820e947994539254c2ce53b6e6c0a6865edcfeb6634e6a6b96fcc85fdc0c35836ca6c7e826fb7fd
f2786795f9a9166a8d1fc3c26943a2c98b99cd571f4cbd2b77ff1aeeacaa02c10bfd0b0888e008ee4
d072cf9e6d803206bd33727fed12c7eba538af64e7aaee2d3ae7d4e809c0be094669df8a52d141e02
12f062f99ddf4ba3c6a319d07ea4abe9a91d97a0198812abb51dfb4699f2c6ca30dd3e14b3ffe600a
8eaebafdf20b47ab25f82b3b05ebd8e33afcd4a41a3bbd35c9478a3ca51d13c4e12dd4ec6fb3eedc2
4446efe17a7d26a4ae7c9a18ca6fe3b7f9db4896b94e016d17e0f06d2488b463ade9dccb2955d2036
c6c91bcabc15ee69d142673fd3f27017ad7bd817433a57ab9d29ccbf48b4c831f9c95086742fdfdca
c18ab1f2cf92980b599c6d32329682918a713f68df855d4422a10f23c7a9c15be775fdd75659e4af3
e0927e5ec1bfc56a4681d2846ce84b50a0c58956970598f87b3e86a84788da58748e6231d5e43287b
f9ce90d6e14963645a4119b3b93127173fdde2d209a60e196bab405022b8278595d8bc28ec4819c08
7e1cb253366aa71648665a4526cd6897fa2df13b8d3fa0c66776e57037d88581760d550648b642c8a
3ffcf957fb27875427c20ae42c1c3b0b82487db1c8fc1fa98d40d0dbc909d4b7355d167360808137f
87b6c2818fb7b316dde42bf994e30135df4360ddd7c8c9fea70357d2ee2647366417b75ec1c3a8aec
8dbb55d6e0ee7a540e0d8d8d1e5dec451e1beeebb2d7a1b4f5c6a15431d8eabb66323fae5c474eba1
1ff3fd00828845544b29b2598dab96b2b5d862976dc1b1c8c05589c57f33dd40e4bddf56d3766e52e
f2c6d2d14d562c048b78828c27703c9e63875927607cc8206775d6bb08837f60aceb1e755cf46a2f7
aca3ee2b04fdfaf815a89d5f24e6e2d91ffcc401828c368d771e67824100e843a8da503d3cdb574ce
69d1833ea9e2906a226c2ea2c2a141c6070dc3505f437ac448ab89c5cc6b8c79819eddb7e3c3ef54a
d2d6649b4978af6b0112d944b094e3b1050293f38bc874f6d04f9f1e83c7cdb7b76c61bab4a65ff79
671e8dba93cbff2d99057aa6af3315ae90c648362087d55d33b8a75e10b72fdca0a88c49b625fe0a2
76df6a27c698815713579281c4f7d685897a1c883e58bcc8ed12171c81e81cb6f6fdc15a93cca8f22
92f4ed349c6e342b49c59371308ba60e9d2c069c5979f7bbc6f260316cc06b448a571cf22d5e8a24a
be4e4ee93140cea492a935ce379037dc123595eb19905dcf9ac0ea0d75b8aefd2e3481ea728191190
89afa07049097f33e2f179c02de534c09c7de15a838de5b48491b9216c05649fb31dc68cf695ab6ca
0df39e3b7f90327c017870251d20a2c4804444cf3db5366767a076df978c848868f6f2772a3bbd89d
bb7dda5522f1b41be6c23284f29da7a3330f2f4c4bfbb7100303cb139d9825a0d32383c993578d9ea
0be125b4e4ea8a472675ec2fbecba77a7a04f8d3cf2386acfcb7afbe61f9de95ec67a54ed5ae0da08
bcd2a19ed78f2aabeba4e6653df72878f916ab21141f67bacc8982c184febc2e76c3639ba8d410ab4
9a68f12fd6edaaf3ae0692a013d668961378e246e68e2dfb434ac4178bd43fa044ec6bfccad0a0f94
1604f10ce80dbeb07beaa24a8347b5087b0fa3cca13917657f782108c9533a030e5c88baa06f78471
e118e94fc4097ccb9be6002fdd13e294d304d3b4ddec4df164de26980f3266683a2a554ea4d5d9736
734ff782e9cd800a25b8670259e96f2c39290c065cacd9f48e189a9ae603950d4e21fa023761bc2c4
aa44c4cccc74b7ad364b2f8a1497d732854edce94c72456bc837872e266854e8d507b5513a33582aa
64f2b7e85612928d7b87495e5d2a5cb2c7c60aa9e3b2b720aeb8086d8a62070f9e8abce241ef06e89
28697c35e0490078e9fad19df2b7476c30394df30c94b887195bd705480b4c5d5fa71a52a79ffe7be
5f6038e8ca451dd313a46213fc4c877ecf3d9a86c7c6bad64bb7673a19c4995db0abb1d05d3caf0ce
f4339197dafff7485cf7d695f00974801fedb920360786a03f90488a2ff1cd46616f56dd430ded034
faef9553e7b0fdf78840be1ceaa60d36bbcaca608e08f4d6035bee07ce4b653b0af61676fbc99e3d1
57ca933fd14b7d7b788870e0c660dfebd9ccf0fb23c2d15563594b6bd42d995ea4057ac1a7b385a04
d3cbdc1d2396529b47d15e26af80efc53dbcbd2edfdd8bc8e477ee7f0b9aa214ad220bad09233c80e
d99055ba2021b3ac67320f2b6ed3496a287d03526df8f982ef7b90956f15b1a3314dd70aad05676e8
7a540fec17594f92f49f6712c64b44f8c97669898d1a9c7efa2fbc45a786cd3499b7b86d44dab6044
452ce7d55fb7faba91ba656221b5b3fa15e44333eb1e9e458bfd08337a3f5551506cff046cb975cae
62db57ac5021ccc734e7d1b6de2719b6a3f73efa6b0f71d2a3a526588bd32ca8773387d682758ab6e
a2829a9c6782f4c1a02562b2579d5dd7e92641e9b8eaa4f92122e5b5ae7f08e78cc8c13e3fc4ce519
45a8ae1d7f7c05e4730bdf6adc7a9a929d63517e8c13eda3f17671a885e71a822045b8fba98ceebc9
3ab7ff5e5136811e7bb73889ca5ec97e2da9ce022c51293dd97198c503e98920ac052f83bd5ad5e0f
9f1732030a87fc4adb5d40534112bfaa9f9e2cd8b7e124069846076a575dd4d78362bed365be1a1d4
9731e6a776c8c26e4ef65893720fb8aeaa11fc4be08790ed1cadd152b2d4daf9ba089ae2c1f12a95b
ef75ed56548a99bf60660e8fd661f474792be45fd9f48d02608a1496d5c6cda25332b0a8a66a88e4a
809462446f6f198f7fa771be8a042b6268431ad1ad01792694dc818936d43bb100f794a6633daf95c
ccdb17f1dd9d194b6c23835951e7ab0a1c950eeea1ff54a336ecfa3adaa52b006632194a2f577b328
ffc6c341169e269cbacf773688d263d8b265bae1ad76c5452942dbd646be2fc30536ec9a5efc34842
24fa344f4db342ca9b401ffc9d2709692075b7940346eb08cbdd0d7733a05713870137eac7fe350ad
5ceb9aed820acaf4e5b39969284ee08d0fdbad0837d996e805664de7dca775acec936ab4d5260a0a7
4ab9361d7882765cde4a195a55b779a39f6e5d82b5a48446f3fc7750a2439fd194143f914bec1e754
2268b8d30ea926342bd84803618d643d4a4b0413e65f4ceb900b8adda830e40f2bb3793d19b835e2d
f8c87c4f4593f7d5e9a3b8a78d2449ef27e333c19485884597d1c4d00c1e4754402397588aa2639db
19e22ec252af9c37f40236f16ce4efe66a98100f917e88ce6b73378346bc0a3ebbad871978cd6aedc
1dbc1a1b70652f8db6037adce91cbc25ac8ca15b6f7b3340640717222aa3b3b9819b9a4f47d68463f
493f4dc52793cc1bea385361c4e9c4c5b9e962e84853eb2bc5982f682f39ef821a0cf9177dbc9d4db
6bfc967ce897396ff003711732f42674f3e6e14f0a2ae537491ad347db9b2ee3131c77685b01a51bc
fda3a62aa607973ef5bdd1c0206f62ed56c0a3cb4d849a57962778ab0f9fa69d0498754af62004629
ba463c7251bf857c781220576871d2fed89262bf3c0df23e0b9f4245e05ff716d32a91da9fb12d9d0
bc730a7f28021f3c3e1721fcb9798c8b5748695deabdc16cbc89d7fcd42885907859df01f0d113ce8
d3093b3ea34777d722d1c1c22b112fa9090358b2d0a1925c740ac1352e916e4e746e4090d5866a038
50558a8f47b9c3fcf22f0af33c0a9640c55922672bd8d40b5368514caa4d229cb1995cceb8e88070e
94ea05b898ec3887b8d8b26060615e9d77e21a44a7b731ae5f1781125fd2da97ed53dec9dff69a6f0
c22d77a768dba1267e709d38744a20c2dd3ef37b5fec8915b8ac2aceffc650422ce15283dbbf3f6b4
d270d31b022f33ba0691333ed1f5c5d9fbcaf283749400238d34071e61ab9604e89b9b6866bb22ee6
365b216257fc6e283beb1322cef201911b7f3f6a1254d5ac887fe8f07f8d2642a8fb642f26ed861f9
522a0e54b285a95ddcc9996e5d55cf803f2e30722f01720fd3026c3e1596eeab44a9c99fb365215b7
87a4941ce90515ebc8c8f322f7fc4d6f3de4ad4510a7ec30a049506618daf89e20ee7a25a64cca2ed
eeb5e69871a8fd870fe43de3c41c999620904727727ccf3b09191d8a3134168ec4d416c0659b0a603
9f662eb6ec8ecccf017000e8dea1585d4077225e68c043421eb4671ef6275b97d203b6f4a8f6bf778
5688beed2b06685d68774de7dbd9864582a95dce4e8743c0fbf25c1aff8e1683cf7d8eeacddbcbc12
7da9d1816b700875038d4065ad5ab99c6081c14465b791c45ea8724c862d23ad3ac57f6fb9435b1d2
8c4aee4d8e4f45ccc32d4a676e000b7c2bf5cf3556b63fe9517c3c7cfef9d5806cdb7277feef0eb27
5bb8a40eb4c57ebe2b07f7cbd3df44ac1b8cf1c995e5c9d5fd4ef55e76e567a316fc7aa5a5ccd281a
2678afc87ef8e604e06458734857435bd715faad6f82a307804e69d93d35ec6a72ec75caefa0408c1
b91a0b2e53e421cc1708ac8bfd290e4f2e5f57ffc6e420d8d80fb608b2877c7863b08ae97b6a9a421
2fb25280c49c9d09a4dee1104c4a9bef7a728e03239deb02c55b10bdd337fa640b63212aaadf228a2
5299abf2176829fea3f8225517736c869503d635038b0c6e0c96bb38688cf56e5e2cd6ca87366843d
468c499d2ac7a2e2d903317ec73f695731b0d67fbc680f6dbc4edb7c0da982d3343610d25f4f3a1cb
243f6aac0c2809f7ec805f1b4e34f4928ec395fd9af54176f7c9472205afa80583f7c21b558a30a48
5d8ecbf8911b63ad4c498baa94eb46db5f889b8b78b48588551a2848cd782d120f0fb540ffd7f067c
6c536ceb7f3f77984f8aa80d102579f39627f9291879b61335d3df3534e7aa0090dbf4ebb4fd27c60
3b3614b951bb0d3f75b6e6617a2d8a5265a46d756b6af6b6d371a9ad2755647e81ceb2a9a35502d37
a75f1681fd056700693e829d0941116b6af7a5c84bb29da5a31c4a22e46d505e82e2508daf6ac44ba
c69a22a2fb70364a4305a5ff4bc79f3a69f2d0a0ab3700512f4df5b63426e83ac635a1537485f2cbd
912b0e7f52130f921806b27b27bf12fb063e802c3e786ecd5e4e8bdb42bc30619553fb90cf95e9b91
2168f8a9ccac33fc3bfe7071029f24b566266d6432f81393645b86e500c61bbcea2b0d99623e4560f
28c238368d43e3ef788a3d9896180fe4a843aee73fe4dc6dc351e990ba8b1d8ad347b85ac7f1d3fe3
ea6a2070200e87a14c6dc057cb6dbe398825a00b3181e5ed926afb7eade0a64eef6967da8f459426e
a86cb937faac99f6e5b36727c406dfa7cd9095c8db50dca5704ee7b3fbfad32e9955d9134292c1c63
0f744661346ac699a42443d89700d2f0b1bb28d4a9abe073ed50d5bc2068032edbdf5449f2777c35a
8fb1f75425a925caffabb6965d82950431eed9e2df53a4d6f041af4bf4eeceb790bcc10b51838c868
7241fabbfca88a0947066d5c8a4a1e5938a58c13a231b0be4cf5bc0a9111e1aed93f7b5ec6a36f095
9a5c969cddd2becba0daef984fc588fdd2665f84b457c8a9a1531c1a45c3f54cb0b8b86587124df42
68c1b1d37f934f684cccc3009def0fa4e6c7422f45f2e7e8dd1618ab0cc7c524d5505933fa9d01d20
c6747b612dffd69ae7e9171ec6474cd3bbed414d4192c69fe8037e98d7e701c47ac74688b4cd5e052
dcb623fee7eaa7f2b143ff55fed93a29e9f7075273c2fb539d72a9e2944734fb020c7e48911bddf3c
4f43cc34644b24182fc27358e22fc2b606fe0807e81ca87ccbeeff4c1a07ea33afa53518e87f57edf
ebe5cd8924922908945c8091adc6453253ef4bfc7e697452b1ffe22a3c61dc5f75126ecfc10b70b69
b352ede70d0f9d67dc178d87b8382edb59c484328cc20674abf208f9bf0eeaee4f518ffb763610223
882b2eb168416bee09cb090cbfa7ac1c3a8ea4503cb2103e226657af0dfd1aa41864b320953b7b669
af6a8389dff6e276e77cb419efcec510cb3abdb47c91b9fd2a2b40a5b82c798a9c069b54ee3fa459b
e744ebdab9f3fdeb19580ef43d230e29a797a8c4c97c40420a8294c215c2a33f19ba07960c6f5353d
b94094746c2d9e233979df2fec1c00ea9e9dfeb14bd5dacb27f6939536cb51dc1742e38b20276b86b
03258d5c1449505bdee00cb93331eeb098f0d585437ba9de6a3537b874a00d4a7accec7f3c196eb1d
26a219e422fd5d593f6df70ce392973e526bce8ec81dc3d4c5f0274ea99b6bfa80c130421fbbffde7
0983af70a62528805a33b0a0c281d50b3054db00bd97b6374542c2eb3f66b4245e219bc61f2315243
a45382387af4760e19f3263542da8421aa61f7f006340b4d65f76794c286ff37da818b603b0837d89
ec39c277626effdc9f378d03f0046c7783a22d7a3eac12b4d373dca76fdecc674ea7c95ccce4322bc
7a0f971686df847728ebd471bde400e9a57c82bd54298daaa626fb6e73bb872964bf3c09055b2d261
b1067ab37fc24378b594183fd46f3447acab5538d16850b30a70a4ff2e1fbaa9cf9b4c2cd3aba95de
a7d4636298cb5f080d6fabc343da832985f9b819454761a16bdccd1feda7bca6a0f8cea34d413bc00
81dc508bd91eb4c0c9260c657c8bbfd199270e879d54aff561eca6b8d462fee3212dceb6924c2243c
6cdf2d413f052077aadd9372052bc7b8cb54226aa81de027d4b5052da0f696c14ee808d12687f9d9c
6c61e03bad37d924d9ddc809e937966f6b3affb9d58b4a9a35ab4dac034d4ace91753f9e4c0c987ad
4cad7f194e1a21b91fd3b5017584c5a9374b89549076a370428e0c5d3e954fd1718df57be03940e6f
7281ca11eee529d8eb5ffd6639df54435f27f40b55cc03bc5634424ee7d793eb627b616c47c7bb845
06fa228dd4d7f902cd2d7b3643d1b553cbdaf6bc4d6183f157858cb3b7b25f694823dcc30ca6299d7
ba0a6261b50244151a858512b7779775f2e9e67b7f61cafd3fc3814be32e93ccfa5e0aace0bc6ef58
9cc51f85244983c755088d16613f114ac83fb1c86f299960f3f66d763cba8060552947107b5a0df37
4cbe81821eaa5eb9557429d27ebedaa180ce9d966d6b43e21238cb115a5337ea932f05e075ed6a77d
4f48bf23cdbdd6bf9900

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"MySpaceIM"=c:\program files\MySpace\IM\MySpaceIM.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
""=
"Performance Center"=c:\program files\Ascentive\Performance Center\APCMain.exe -m
"GetModule31"="c:\program files\GetModule\GetModule31.exe"
"Google Update"="c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
"SoundMan"=SOUNDMAN.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=

R1 SiSEsc;SISLIB_ESC;c:\windows\system32\sisesc.sys [7/23/2008 4:43 PM 28416]
R2 VProt2k;BroadJump PPPoE Helper Protocol;c:\windows\system32\drivers\VPROT2K.sys [1/21/2009 11:58 AM 16690]
R3 VWan2k;BroadJump PPPoE Adapter;c:\windows\system32\drivers\VWAN2K.sys [1/21/2009 11:58 AM 29228]
S1 74756e32;74756e32;c:\windows\system32\drivers\74756e32.sys [1/25/2009 12:04 PM 0]
.
Contents of the 'Scheduled Tasks' folder

2010-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1563985344-682003330-1004Core.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-11 00:29]

2010-12-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1563985344-682003330-1004UA.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-11 00:29]

2010-07-04 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-09-01 22:31]

2010-07-04 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-09-01 22:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.pogo.com/home/home.do
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\zpw6ll8z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2260173&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - swagbucks.com
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2260173&SearchSource;=2&q;=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Clippings: {91aa5abe-9de4-4347-b7b5-322c38dd9271} - %profile%\extensions\{91aa5abe-9de4-4347-b7b5-322c38dd9271}
FF - Ext: ChaCha Guide App Toolbar: [removed] - %profile%\extensions\[removed]
FF - Ext: ChaCha StatsClicker: statsclicker@codewolf - %profile%\extensions\statsclicker@codewolf
FF - Ext: Fasterfox: {c36177c0-224a-11da-8cd6-0800200c9a99} - %profile%\extensions\{c36177c0-224a-11da-8cd6-0800200c9a99}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - %profile%\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Internet Video Downloader: {B728AB94-9BC7-49b7-B76A-422BB31B2FD0} - c:\program files\ArcSoft\Media Converter for Philips\Internet Video Downloader\Plugin_FireFox
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-18 12:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-12-18 12:53:20
ComboFix-quarantined-files.txt 2010-12-18 19:53

Pre-Run: 154,453,368,832 bytes free
Post-Run: 154,426,167,296 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 767035E71F5967B96B862478DE2530C3
You have a file we need to collect and analyze


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/index.php?showtopic=116090

Collect:: 
c:\windows\system32\drivers\74756e32.sys

Driver::
74756e32

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
COMBOFIX.TXT log 2 and my computer is starting up faster now don't take a few minutes to start up



ComboFix 10-12-18.01 - user 12/18/2010 13:24:22.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.319.117 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2010-11-18 to 2010-12-18 )))))))))))))))))))))))))))))))
.

2010-12-17 19:03 . 2010-12-17 19:03 388096 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-17 19:03 . 2010-12-17 19:03 ——– d—–w- c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-30 00:42 . 2008-12-08 02:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-30 00:42 . 2008-12-08 02:22 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-12-18_19.50.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-18 20:18 . 2010-12-18 20:18 16384 c:\windows\Temp\Perflib_Perfdata_694.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LegacyDrive"= 2a3efff3e35dff2016d79b643ccad1d8de2e0462134fa0d24481fc2a330f843c3c74177bdaceae0b
6c8f3f1a3a76e073b3bd3050f894f3709fcffc6ab0dc5041f4f7883870a177e82c4e0d8fc9385e7ba
bf14e98c881308496a5588b3eb3594cf6db2f1ad3adbea2dfdb7bce6c416aeaa822480571b5099b6a
e085704e436ebf84788594f4990d771a03804a585a827491cd1340f39c087f14ead7bc75416803f31
2535fc0423d773dbe2bc449fc8d8e638e7b170ef73e157abd126660bf2a002ec9f5276466a0e23ef6
dcaf9300e176fdc9b3bc3a25a419d28d1aecfa72924db9d1e5434908b6ca37c0e79da9ef0b5f228b6
7fd6a8a24d5fad0ab76b40b00a7d2dc51ab1d37cec45f0cbcf61a27c50d7a5493e189c89dd9a2bc40
ae285b117277de72d01bf66395406a9b6f6a01d7f567a273a6e881ba37b9f7de734bafb14ef925095
bdba74d6d45c421ad910246e91fcfbb2f99ba299b7ce37d6dd4b0d75e46c2a33454280595ddd27b19
e348bea2919be8f07d9cdc702a4de355d19593eaaa6138f527c405e6826451be07eea530ab55b471d
e1a909d5fcc1d5654cac5ae9a506d475ab2a8b8dde22b33a1388165ac73009e20fbfc3210683a1f92
48a8f0151d4be1f5a678434d6047220cbc4b45264cf169b7dfa54a642a098e8636d2a62004d0b80a2
128dd4f7be48dd373af573933d9d60342a2e0fb55b400d269f127080e6f9e0b06c13fa30e79e58dfc
ea21660a332fcb727828bf3bc773784d522c936edc04e42ccbf80608af24379acf860a7779055b579
6b28878814dde3d1a0b521b159672b598569b4606ef6b40150b7932275944efd7d56aedd24b1bebe8
16ccd7622e30ee97c3626425bae169c8f6ffd861bd36d1db5d6b35e7d473159fe5d66a696bd3061fe
ea4ca6d74021a7a99ec8ecae2a5ea624ffc512e2fcfb5a138d2929bd78ddc8fc5a435e5db5b649d27
5903363fb6ac77ced50e258a8c67e3380a92ad334f649a8745eb0e5698f3307bc7cf9f6c7c5660651
82b1bc3934188ad839f24fa7a61284f9500bb8852d3675aa2d5ca3640a88e7040da9aa0eb678a48ca
c8805db8018b6e2fde6ba643b201ef83e0f3ec5a33ace73675a40bea3de1d35108bdc2358beb556f4
8b5354f6087b23ea8b16da1fe695401de0fd46930b5491064dfba38c187c356fa65d27303bd6d96d2
2298b5d349e7be17a3a55ee56dedd6cd076dac8b4b69a12d1d03e47843b98589772f2cb8bb2f0bc1e
dee11269b9161cf18ef02f4d099d83cd817d327c97566a9cffe3b17fd482547e4df7155f363a7d25f
c0ee233cf81d4ecb542a07463da8217b518e48bab63af2f1afb693166d3910c527f1772b6dffed22b
9c3e79d475b9e472666bc678f0e5c0776453155604e054974806688d4c3479c892e6bddf68d95c455
760f00e730cb49d063a79979e4ef9833d023581dd8fb4247dba95117ba5e7dec680f7b024079a3959
c63314aa323b1ca6263b5b01e25c9a5e905a9c974beb15524d8f0947f6821519e4901638f42f23857
53c7e50a51cc18eb80074ed463be46d9d339b5284fc93b33930996126c641522cad850f317f91761c
738a800316525be9d7345c39e7c499ca2043299c7a0823173f01c5f3218b3ae4ee71f1f1583bc364c
a925ab19fc3f63209d7a9eedfb537292ed1d7891fe02c5fc07451cda04c961cd20d751f2121c7109a
cf144d6b1dfc1c6e86304d66eee44b150db30051859968f8729129e16871a5b9df8f38b1b912f0759
09746cca128013b6ea6a44972d2ba6c3ed5cfa4c04410925a907db86424a2a9179da163592bf1a53f
c7b3f1f268e90c99340cd5d31d89a64e8e7b69cdd6d3814b7601d6cdf96b442cfaee96078ecc933e1
44437f12b52c5230d98636e9b902ab12e5c3d58fc56571742a3e0d6928e4795328ef79313900bc43a
7011272cfafd9ec31c956b80fc7dc90889501b0bc82e5496666cb2182641c8b6a7aaf96405647858b
6c5e7f25452188541abbb037a1d68a64275fe0cfdf8aa5ed7a172b1af7d39638bd61919ae73a3f20d
ff375a32e99be269392341fde5152f414cec13ac95a5af63b4ce9563554319f340c3167c7d0a6043c
d0d14478637a5e279e35291626e48cdc427d36c0350e8fd7cafeee6d30950ca608beb865bd0ccd6d1
4f2fc62c6047a4063c7a6990131d7f65241e0725bf593261b6384e46d060f282f569d4ba49b22fa17
02eae7c2f196beed98615b5ac8a93ae109aa2f58e78c57b58ca04e7794e6a2421cd488c91c9652cef
0f709113251dd304121b800ed078a4247df8ed20696ce202a3ce9e4de5b140ea3885ffcab3739f083
d337c1f50f11d12d76ed3e1a4ae15d178bb364cb56e3664e70eb858d23c562ef4995aed939a62aeca
e7b48fc7b57273f5331b96e57b4c7be38da35129fbc886fcda8a5b07e75db7b14132473f166a8af25
55836b491ec8feaaecc60caaab8afd641ba4ae8f232e66a5680b0b441fd56d96d41f9ac46a3bef0ee
cce25dc7697d3f6fdc8343b33592b95aaa2842c3b297ddaa9b985df82b443d746a9dae8cb296c40e0
d7dcbf31bfd9f06ae9183ea02de065ec48cc265930cc3f00a5c56e9a71095cc5557125a252fc40602
f634da939d29f1de5f7f800b658932f61e968592fdeab6ba4be964c5eb968cb3f3baed5cfc1c1ecdb
eb90d462d39f90b29e508ccf50611c14e5b7251d9dc85a1ae397c02b29a14eb9184f1c0c264af9483
cebaf9d170987bfee0f109656511d3663a00d11111b4f6be249240fc865a74144f90bf3d0ae253b7b
632a05d37cb905077d1cf04dd7cbec82019f314510cbb36115f0eff6c2ea417a000a8cdc5ac737711
7567531a67cca2340a1ca16c8252492f6f7e00eb463e563c82bbe81b4da9e61da55a13ae4b354f863
4e78eab61a03bb2e3668a36fc1ab18de1aef495ea95cf6bd99a02775cf2372533532c229a45357c30
6d60e1dbcade3d33d7db4d900f5476c9c5f8f492e752b1cfc75303b58782894c6ff5ae461cf4c2a7a
ff875c834f9a582bbbf5621dcb50883b013f4a889a307f15b6d8d56126ce5ecc199a4b4ef80ff6688
edb265b6c5d8f998cb699793423632e1d8a06fad5521e9f6278871628e064840ce9666ada434a1ce4
05a474ecfaf7dcc7453c76183405968c9cc1c31edb68eb94ef0aa7b2ddabc1ad5352f3e28c5df2c87
417ab240d8dcd7c119d87cdd84f93807d68739b3c3dfb351fc60f2cdaf3ae1af3432f842692cb5507
32b95c8be93e6431ff2b518dc1a0009a91887fb89f6517a30ae78aa247bd9900c7abc9c0d4dd678db
c7bcaf0327dd8c6f1c1cbf0a25a354c002b42e43ab53e66992e57d462d3a37dfe7e652c587bc38c9f
87987c3bad7b11fd1f39e1b4c623c26ec4e38c305bc920ea0b5faaa9fb43220f9a3619008670b29fa
d36ef79b2af2eff92f4f33a8766e7ba2d4421d0e37ca5fc74c22aa9f6e02118f34db5f29bc7008903
4986115bae53ffd7a9565307d7cf1a505b65389dc573645239a47481cdbfdb6132c470fc97377027c
abcc7b7a1e48bf29847ca44bbd38533c763fc958c932c0195d397830bbbc44394d79e05490762ffca
738f6806a0a58ba5e4b3133ecb2585cbbade0e5ad2877f0417269623d2f27fc033659a4b3b947f8fd
9bc3fe4541deda7e80b5ee7b4422c61d37a01afca3b12bc22f3d1e97b554568d9efa50befed226d7d
69820e947994539254c2ce53b6e6c0a6865edcfeb6634e6a6b96fcc85fdc0c35836ca6c7e826fb7fd
f2786795f9a9166a8d1fc3c26943a2c98b99cd571f4cbd2b77ff1aeeacaa02c10bfd0b0888e008ee4
d072cf9e6d803206bd33727fed12c7eba538af64e7aaee2d3ae7d4e809c0be094669df8a52d141e02
12f062f99ddf4ba3c6a319d07ea4abe9a91d97a0198812abb51dfb4699f2c6ca30dd3e14b3ffe600a
8eaebafdf20b47ab25f82b3b05ebd8e33afcd4a41a3bbd35c9478a3ca51d13c4e12dd4ec6fb3eedc2
4446efe17a7d26a4ae7c9a18ca6fe3b7f9db4896b94e016d17e0f06d2488b463ade9dccb2955d2036
c6c91bcabc15ee69d142673fd3f27017ad7bd817433a57ab9d29ccbf48b4c831f9c95086742fdfdca
c18ab1f2cf92980b599c6d32329682918a713f68df855d4422a10f23c7a9c15be775fdd75659e4af3
e0927e5ec1bfc56a4681d2846ce84b50a0c58956970598f87b3e86a84788da58748e6231d5e43287b
f9ce90d6e14963645a4119b3b93127173fdde2d209a60e196bab405022b8278595d8bc28ec4819c08
7e1cb253366aa71648665a4526cd6897fa2df13b8d3fa0c66776e57037d88581760d550648b642c8a
3ffcf957fb27875427c20ae42c1c3b0b82487db1c8fc1fa98d40d0dbc909d4b7355d167360808137f
87b6c2818fb7b316dde42bf994e30135df4360ddd7c8c9fea70357d2ee2647366417b75ec1c3a8aec
8dbb55d6e0ee7a540e0d8d8d1e5dec451e1beeebb2d7a1b4f5c6a15431d8eabb66323fae5c474eba1
1ff3fd00828845544b29b2598dab96b2b5d862976dc1b1c8c05589c57f33dd40e4bddf56d3766e52e
f2c6d2d14d562c048b78828c27703c9e63875927607cc8206775d6bb08837f60aceb1e755cf46a2f7
aca3ee2b04fdfaf815a89d5f24e6e2d91ffcc401828c368d771e67824100e843a8da503d3cdb574ce
69d1833ea9e2906a226c2ea2c2a141c6070dc3505f437ac448ab89c5cc6b8c79819eddb7e3c3ef54a
d2d6649b4978af6b0112d944b094e3b1050293f38bc874f6d04f9f1e83c7cdb7b76c61bab4a65ff79
671e8dba93cbff2d99057aa6af3315ae90c648362087d55d33b8a75e10b72fdca0a88c49b625fe0a2
76df6a27c698815713579281c4f7d685897a1c883e58bcc8ed12171c81e81cb6f6fdc15a93cca8f22
92f4ed349c6e342b49c59371308ba60e9d2c069c5979f7bbc6f260316cc06b448a571cf22d5e8a24a
be4e4ee93140cea492a935ce379037dc123595eb19905dcf9ac0ea0d75b8aefd2e3481ea728191190
89afa07049097f33e2f179c02de534c09c7de15a838de5b48491b9216c05649fb31dc68cf695ab6ca
0df39e3b7f90327c017870251d20a2c4804444cf3db5366767a076df978c848868f6f2772a3bbd89d
bb7dda5522f1b41be6c23284f29da7a3330f2f4c4bfbb7100303cb139d9825a0d32383c993578d9ea
0be125b4e4ea8a472675ec2fbecba77a7a04f8d3cf2386acfcb7afbe61f9de95ec67a54ed5ae0da08
bcd2a19ed78f2aabeba4e6653df72878f916ab21141f67bacc8982c184febc2e76c3639ba8d410ab4
9a68f12fd6edaaf3ae0692a013d668961378e246e68e2dfb434ac4178bd43fa044ec6bfccad0a0f94
1604f10ce80dbeb07beaa24a8347b5087b0fa3cca13917657f782108c9533a030e5c88baa06f78471
e118e94fc4097ccb9be6002fdd13e294d304d3b4ddec4df164de26980f3266683a2a554ea4d5d9736
734ff782e9cd800a25b8670259e96f2c39290c065cacd9f48e189a9ae603950d4e21fa023761bc2c4
aa44c4cccc74b7ad364b2f8a1497d732854edce94c72456bc837872e266854e8d507b5513a33582aa
64f2b7e85612928d7b87495e5d2a5cb2c7c60aa9e3b2b720aeb8086d8a62070f9e8abce241ef06e89
28697c35e0490078e9fad19df2b7476c30394df30c94b887195bd705480b4c5d5fa71a52a79ffe7be
5f6038e8ca451dd313a46213fc4c877ecf3d9a86c7c6bad64bb7673a19c4995db0abb1d05d3caf0ce
f4339197dafff7485cf7d695f00974801fedb920360786a03f90488a2ff1cd46616f56dd430ded034
faef9553e7b0fdf78840be1ceaa60d36bbcaca608e08f4d6035bee07ce4b653b0af61676fbc99e3d1
57ca933fd14b7d7b788870e0c660dfebd9ccf0fb23c2d15563594b6bd42d995ea4057ac1a7b385a04
d3cbdc1d2396529b47d15e26af80efc53dbcbd2edfdd8bc8e477ee7f0b9aa214ad220bad09233c80e
d99055ba2021b3ac67320f2b6ed3496a287d03526df8f982ef7b90956f15b1a3314dd70aad05676e8
7a540fec17594f92f49f6712c64b44f8c97669898d1a9c7efa2fbc45a786cd3499b7b86d44dab6044
452ce7d55fb7faba91ba656221b5b3fa15e44333eb1e9e458bfd08337a3f5551506cff046cb975cae
62db57ac5021ccc734e7d1b6de2719b6a3f73efa6b0f71d2a3a526588bd32ca8773387d682758ab6e
a2829a9c6782f4c1a02562b2579d5dd7e92641e9b8eaa4f92122e5b5ae7f08e78cc8c13e3fc4ce519
45a8ae1d7f7c05e4730bdf6adc7a9a929d63517e8c13eda3f17671a885e71a822045b8fba98ceebc9
3ab7ff5e5136811e7bb73889ca5ec97e2da9ce022c51293dd97198c503e98920ac052f83bd5ad5e0f
9f1732030a87fc4adb5d40534112bfaa9f9e2cd8b7e124069846076a575dd4d78362bed365be1a1d4
9731e6a776c8c26e4ef65893720fb8aeaa11fc4be08790ed1cadd152b2d4daf9ba089ae2c1f12a95b
ef75ed56548a99bf60660e8fd661f474792be45fd9f48d02608a1496d5c6cda25332b0a8a66a88e4a
809462446f6f198f7fa771be8a042b6268431ad1ad01792694dc818936d43bb100f794a6633daf95c
ccdb17f1dd9d194b6c23835951e7ab0a1c950eeea1ff54a336ecfa3adaa52b006632194a2f577b328
ffc6c341169e269cbacf773688d263d8b265bae1ad76c5452942dbd646be2fc30536ec9a5efc34842
24fa344f4db342ca9b401ffc9d2709692075b7940346eb08cbdd0d7733a05713870137eac7fe350ad
5ceb9aed820acaf4e5b39969284ee08d0fdbad0837d996e805664de7dca775acec936ab4d5260a0a7
4ab9361d7882765cde4a195a55b779a39f6e5d82b5a48446f3fc7750a2439fd194143f914bec1e754
2268b8d30ea926342bd84803618d643d4a4b0413e65f4ceb900b8adda830e40f2bb3793d19b835e2d
f8c87c4f4593f7d5e9a3b8a78d2449ef27e333c19485884597d1c4d00c1e4754402397588aa2639db
19e22ec252af9c37f40236f16ce4efe66a98100f917e88ce6b73378346bc0a3ebbad871978cd6aedc
1dbc1a1b70652f8db6037adce91cbc25ac8ca15b6f7b3340640717222aa3b3b9819b9a4f47d68463f
493f4dc52793cc1bea385361c4e9c4c5b9e962e84853eb2bc5982f682f39ef821a0cf9177dbc9d4db
6bfc967ce897396ff003711732f42674f3e6e14f0a2ae537491ad347db9b2ee3131c77685b01a51bc
fda3a62aa607973ef5bdd1c0206f62ed56c0a3cb4d849a57962778ab0f9fa69d0498754af62004629
ba463c7251bf857c781220576871d2fed89262bf3c0df23e0b9f4245e05ff716d32a91da9fb12d9d0
bc730a7f28021f3c3e1721fcb9798c8b5748695deabdc16cbc89d7fcd42885907859df01f0d113ce8
d3093b3ea34777d722d1c1c22b112fa9090358b2d0a1925c740ac1352e916e4e746e4090d5866a038
50558a8f47b9c3fcf22f0af33c0a9640c55922672bd8d40b5368514caa4d229cb1995cceb8e88070e
94ea05b898ec3887b8d8b26060615e9d77e21a44a7b731ae5f1781125fd2da97ed53dec9dff69a6f0
c22d77a768dba1267e709d38744a20c2dd3ef37b5fec8915b8ac2aceffc650422ce15283dbbf3f6b4
d270d31b022f33ba0691333ed1f5c5d9fbcaf283749400238d34071e61ab9604e89b9b6866bb22ee6
365b216257fc6e283beb1322cef201911b7f3f6a1254d5ac887fe8f07f8d2642a8fb642f26ed861f9
522a0e54b285a95ddcc9996e5d55cf803f2e30722f01720fd3026c3e1596eeab44a9c99fb365215b7
87a4941ce90515ebc8c8f322f7fc4d6f3de4ad4510a7ec30a049506618daf89e20ee7a25a64cca2ed
eeb5e69871a8fd870fe43de3c41c999620904727727ccf3b09191d8a3134168ec4d416c0659b0a603
9f662eb6ec8ecccf017000e8dea1585d4077225e68c043421eb4671ef6275b97d203b6f4a8f6bf778
5688beed2b06685d68774de7dbd9864582a95dce4e8743c0fbf25c1aff8e1683cf7d8eeacddbcbc12
7da9d1816b700875038d4065ad5ab99c6081c14465b791c45ea8724c862d23ad3ac57f6fb9435b1d2
8c4aee4d8e4f45ccc32d4a676e000b7c2bf5cf3556b63fe9517c3c7cfef9d5806cdb7277feef0eb27
5bb8a40eb4c57ebe2b07f7cbd3df44ac1b8cf1c995e5c9d5fd4ef55e76e567a316fc7aa5a5ccd281a
2678afc87ef8e604e06458734857435bd715faad6f82a307804e69d93d35ec6a72ec75caefa0408c1
b91a0b2e53e421cc1708ac8bfd290e4f2e5f57ffc6e420d8d80fb608b2877c7863b08ae97b6a9a421
2fb25280c49c9d09a4dee1104c4a9bef7a728e03239deb02c55b10bdd337fa640b63212aaadf228a2
5299abf2176829fea3f8225517736c869503d635038b0c6e0c96bb38688cf56e5e2cd6ca87366843d
468c499d2ac7a2e2d903317ec73f695731b0d67fbc680f6dbc4edb7c0da982d3343610d25f4f3a1cb
243f6aac0c2809f7ec805f1b4e34f4928ec395fd9af54176f7c9472205afa80583f7c21b558a30a48
5d8ecbf8911b63ad4c498baa94eb46db5f889b8b78b48588551a2848cd782d120f0fb540ffd7f067c
6c536ceb7f3f77984f8aa80d102579f39627f9291879b61335d3df3534e7aa0090dbf4ebb4fd27c60
3b3614b951bb0d3f75b6e6617a2d8a5265a46d756b6af6b6d371a9ad2755647e81ceb2a9a35502d37
a75f1681fd056700693e829d0941116b6af7a5c84bb29da5a31c4a22e46d505e82e2508daf6ac44ba
c69a22a2fb70364a4305a5ff4bc79f3a69f2d0a0ab3700512f4df5b63426e83ac635a1537485f2cbd
912b0e7f52130f921806b27b27bf12fb063e802c3e786ecd5e4e8bdb42bc30619553fb90cf95e9b91
2168f8a9ccac33fc3bfe7071029f24b566266d6432f81393645b86e500c61bbcea2b0d99623e4560f
28c238368d43e3ef788a3d9896180fe4a843aee73fe4dc6dc351e990ba8b1d8ad347b85ac7f1d3fe3
ea6a2070200e87a14c6dc057cb6dbe398825a00b3181e5ed926afb7eade0a64eef6967da8f459426e
a86cb937faac99f6e5b36727c406dfa7cd9095c8db50dca5704ee7b3fbfad32e9955d9134292c1c63
0f744661346ac699a42443d89700d2f0b1bb28d4a9abe073ed50d5bc2068032edbdf5449f2777c35a
8fb1f75425a925caffabb6965d82950431eed9e2df53a4d6f041af4bf4eeceb790bcc10b51838c868
7241fabbfca88a0947066d5c8a4a1e5938a58c13a231b0be4cf5bc0a9111e1aed93f7b5ec6a36f095
9a5c969cddd2becba0daef984fc588fdd2665f84b457c8a9a1531c1a45c3f54cb0b8b86587124df42
68c1b1d37f934f684cccc3009def0fa4e6c7422f45f2e7e8dd1618ab0cc7c524d5505933fa9d01d20
c6747b612dffd69ae7e9171ec6474cd3bbed414d4192c69fe8037e98d7e701c47ac74688b4cd5e052
dcb623fee7eaa7f2b143ff55fed93a29e9f7075273c2fb539d72a9e2944734fb020c7e48911bddf3c
4f43cc34644b24182fc27358e22fc2b606fe0807e81ca87ccbeeff4c1a07ea33afa53518e87f57edf
ebe5cd8924922908945c8091adc6453253ef4bfc7e697452b1ffe22a3c61dc5f75126ecfc10b70b69
b352ede70d0f9d67dc178d87b8382edb59c484328cc20674abf208f9bf0eeaee4f518ffb763610223
882b2eb168416bee09cb090cbfa7ac1c3a8ea4503cb2103e226657af0dfd1aa41864b320953b7b669
af6a8389dff6e276e77cb419efcec510cb3abdb47c91b9fd2a2b40a5b82c798a9c069b54ee3fa459b
e744ebdab9f3fdeb19580ef43d230e29a797a8c4c97c40420a8294c215c2a33f19ba07960c6f5353d
b94094746c2d9e233979df2fec1c00ea9e9dfeb14bd5dacb27f6939536cb51dc1742e38b20276b86b
03258d5c1449505bdee00cb93331eeb098f0d585437ba9de6a3537b874a00d4a7accec7f3c196eb1d
26a219e422fd5d593f6df70ce392973e526bce8ec81dc3d4c5f0274ea99b6bfa80c130421fbbffde7
0983af70a62528805a33b0a0c281d50b3054db00bd97b6374542c2eb3f66b4245e219bc61f2315243
a45382387af4760e19f3263542da8421aa61f7f006340b4d65f76794c286ff37da818b603b0837d89
ec39c277626effdc9f378d03f0046c7783a22d7a3eac12b4d373dca76fdecc674ea7c95ccce4322bc
7a0f971686df847728ebd471bde400e9a57c82bd54298daaa626fb6e73bb872964bf3c09055b2d261
b1067ab37fc24378b594183fd46f3447acab5538d16850b30a70a4ff2e1fbaa9cf9b4c2cd3aba95de
a7d4636298cb5f080d6fabc343da832985f9b819454761a16bdccd1feda7bca6a0f8cea34d413bc00
81dc508bd91eb4c0c9260c657c8bbfd199270e879d54aff561eca6b8d462fee3212dceb6924c2243c
6cdf2d413f052077aadd9372052bc7b8cb54226aa81de027d4b5052da0f696c14ee808d12687f9d9c
6c61e03bad37d924d9ddc809e937966f6b3affb9d58b4a9a35ab4dac034d4ace91753f9e4c0c987ad
4cad7f194e1a21b91fd3b5017584c5a9374b89549076a370428e0c5d3e954fd1718df57be03940e6f
7281ca11eee529d8eb5ffd6639df54435f27f40b55cc03bc5634424ee7d793eb627b616c47c7bb845
06fa228dd4d7f902cd2d7b3643d1b553cbdaf6bc4d6183f157858cb3b7b25f694823dcc30ca6299d7
ba0a6261b50244151a858512b7779775f2e9e67b7f61cafd3fc3814be32e93ccfa5e0aace0bc6ef58
9cc51f85244983c755088d16613f114ac83fb1c86f299960f3f66d763cba8060552947107b5a0df37
4cbe81821eaa5eb9557429d27ebedaa180ce9d966d6b43e21238cb115a5337ea932f05e075ed6a77d
4f48bf23cdbdd6bf9900

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"MySpaceIM"=c:\program files\MySpace\IM\MySpaceIM.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
""=
"Performance Center"=c:\program files\Ascentive\Performance Center\APCMain.exe -m
"GetModule31"="c:\program files\GetModule\GetModule31.exe"
"Google Update"="c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
"SoundMan"=SOUNDMAN.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=

R1 SiSEsc;SISLIB_ESC;c:\windows\system32\sisesc.sys [7/23/2008 4:43 PM 28416]
R2 VProt2k;BroadJump PPPoE Helper Protocol;c:\windows\system32\drivers\VPROT2K.sys [1/21/2009 11:58 AM 16690]
R3 VWan2k;BroadJump PPPoE Adapter;c:\windows\system32\drivers\VWAN2K.sys [1/21/2009 11:58 AM 29228]
.
Contents of the 'Scheduled Tasks' folder

2010-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1563985344-682003330-1004Core.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-11 00:29]

2010-12-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1563985344-682003330-1004UA.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-11 00:29]

2010-07-04 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-09-01 22:31]

2010-07-04 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-09-01 22:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.pogo.com/home/home.do
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\zpw6ll8z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2260173&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - swagbucks.com
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2260173&SearchSource;=2&q;=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Clippings: {91aa5abe-9de4-4347-b7b5-322c38dd9271} - %profile%\extensions\{91aa5abe-9de4-4347-b7b5-322c38dd9271}
FF - Ext: ChaCha Guide App Toolbar: [removed] - %profile%\extensions\[removed]
FF - Ext: ChaCha StatsClicker: statsclicker@codewolf - %profile%\extensions\statsclicker@codewolf
FF - Ext: Fasterfox: {c36177c0-224a-11da-8cd6-0800200c9a99} - %profile%\extensions\{c36177c0-224a-11da-8cd6-0800200c9a99}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - %profile%\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Internet Video Downloader: {B728AB94-9BC7-49b7-B76A-422BB31B2FD0} - c:\program files\ArcSoft\Media Converter for Philips\Internet Video Downloader\Plugin_FireFox
FF - user.js: yahoo.homepage.dontask - true
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-18 13:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2116)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-12-18 13:30:34
ComboFix-quarantined-files.txt 2010-12-18 20:30
ComboFix2.txt 2010-12-18 20:20
ComboFix3.txt 2010-12-18 19:53

Pre-Run: 154,343,997,440 bytes free
Post-Run: 154,334,986,240 bytes free

- - End Of File - - 74BE8E87F7215D116FE18808233742A5
http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Check Remove found threats and Scan potentially unwanted applications.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
ESET log is as follows ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6415 # api_version=3.0.2 # EOSSerial=93d0bfed065a8845b1c36a4abfca940c # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-12-18 09:02:20 # local_time=2010-12-18 02:02:20 (-0700, Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 9586 9586 0 0 # compatibility_mode=1024 16777215 100 0 3209850 3209850 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=49667 # found=4 # cleaned=4 # scan_time=1141 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetSpeedMonitor.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\system32\mftxaivv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{7FA9D1EA-A39D-481A-B781-94AFF8DC1C72}\RP5\A0000309.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

For XP:
  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

For Vista / Windows 7
  • Click START Search
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.


Here's my usual all clean post

To be on the safe side, I would also change all my passwords.

This infection appears to have been cleaned, but as the malware could be configured to run any program a remote attacker requires, it's impossible to be 100% sure that any machine is clean.


Log looks good :D


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.


  • WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    Green to go
    Yellow for caution
    Red to stop
    WOT has an addon available for both Firefox and IE.



  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

Only run one Anti-Virus and Firewall program.


I would suggest you read:
PC Safety and Security–What Do I Need?.
How to Prevent Malware:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI