This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware Trace Registry infection

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

SECOND COMPUTER (belongs to parents)



I think I have remnants of a malware trace infection that will re-appear after I do a SuperAntiSpyware scan and remove the following registry key:

HLM\Software\Microsoft\WindowsNT\CurrentVersion\WinLogon#Shell

I will scan my laptop and remove this infected registry and upon re-boot it will come up again during a subsequent scan with this same registry infection.
I believe this is something that I was not able to remove in an earlier infection that I had. I would like to note that my Bitdefender AV will run for around 3 or 4 days and then my real time protection will be disabled and I cannot get it to start. Bitdefenders virus signatures will indicate “0” and my engine version will be blank. I have also noticed that when I remove this registry infection and then go into a MS word document that it loads much faster when I open, save, and close MS Word documents.

I did run an rkill report on this laptop a few days ago on my machine (without any previous virus scans) and it produced the following:

Rkill was run on 01/06/2011 at 21:26:13.
Operating System: Microsoft Windows XP
Processes terminated by Rkill or while it was running:
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
Rkill completed on 01/06/2011 at 21:44:45

Below is my DDS report.


THANK YOU!



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 23:25:06.10 on Tue 01/11/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1302 [GMT -6:00]

AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiService.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe
c:\program files\verizon wireless\venturi\Client\ventc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe
C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch32.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
c:\program files\verizon wireless\venturi\Configurator\ventcfg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\BitDefender\BitDefender 2011\downloader.exe
C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Utilities\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
mStart Page = about:blank
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - Adobe PDF Reader Link Helper
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2011\IEToolbar.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
TB: {C70E30C7-140A-4166-A2E8-43557E62B41A} - No File
TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [Controlled StartUp] c:\program files\startup organizer\Ctrl.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [LXBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBUtime.dll,_RunDLLEntry@16
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2011\ieshow.exe"
uPolicies-explorer: MaxRecentDocs = 4 (0x4)
mPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {2643ABF9-63C0-479C-B0A1-DBCEAEB940B7} = 69.78.96.14 66.174.92.14
Notify: IfxWlxEN - IfxWlxEN.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [2002-3-11 9216]
R1 BdRawPr;BdRawPr;c:\windows\system32\drivers\bdrawpr.sys [2011-1-11 12960]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [2010-8-25 76768]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2005-11-29 36768]
R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [2010-6-6 6144]
R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\microsoft sql server\mssql10.mssqlserver\mssql\binn\fdlauncher.exe [2008-7-10 31256]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2011\TuneUpUtilitiesService32.exe [2010-11-23 1483072]
R2 Updatesrv;BitDefender Desktop Update Service;c:\program files\bitdefender\bitdefender 2011\updatesrv.exe [2010-6-29 43424]
R3 BDFM;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-4-22 152528]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf.sys [2010-6-18 111696]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [2010-10-21 44368]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-8-29 36352]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [2007-7-19 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [2007-7-19 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [2007-7-19 39808]
R3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [2007-7-19 5888]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2010-5-21 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2010-5-26 808448]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-7 10064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 cpuz132;cpuz132;\??\c:\docume~1\user~2.mar\locals~1\temp\cpuz132\cpuz132_x32.sys –> c:\docume~1\user~2.mar\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-7-18 23456]
S3 icsak;icsak;\??\c:\program files\checkpoint\zaforcefield\ak\icsak.sys –> c:\program files\checkpoint\zaforcefield\ak\icsak.sys [?]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-12-22 20952]
S3 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-12-22 363344]
S3 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\microsoft sql server\100\dts\binn\MsDtsSrvr.exe [2008-7-10 218136]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\drivers\pwi_bus.sys –> c:\windows\system32\drivers\pwi_bus.sys [?]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\drivers\pwi_mdfl.sys –> c:\windows\system32\drivers\pwi_mdfl.sys [?]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\drivers\pwi_mdm.sys –> c:\windows\system32\drivers\pwi_mdm.sys [?]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\drivers\pwi_oflt.sys –> c:\windows\system32\drivers\pwi_oflt.sys [?]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\drivers\pwi_serd.sys –> c:\windows\system32\drivers\pwi_serd.sys [?]
S3 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\microsoft sql server\msrs10.mssqlserver\reporting services\reportserver\bin\ReportingServicesService.exe [2009-3-30 1113448]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-8-19 27064]
S3 Update Server;BitDefender Update Server v2;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2010-6-29 307544]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2010-5-25 11520]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2003-3-31 14336]
S3 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2010-6-28 633424]
S4 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2010-6-28 970320]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128]

=============== Created Last 30 ================

2011-01-11 23:19 0 a–sh— C:\DkHyperbootSync
2011-01-11 21:29 385 a——- c:\windows\system32\user_gensett.xml
2011-01-11 21:26 –d—– c:\docume~1\user~2.mar\applic~1\BitDefender
2011-01-11 21:25 –d—– c:\program files\BitDefender
2011-01-11 21:18 –d—– c:\program files\common files\BitDefender
2011-01-11 21:18 –d—– c:\docume~1\alluse~1.win\applic~1\BitDefender
2011-01-11 21:17 306,104 a——- c:\windows\system32\drivers\trufos.sys
2011-01-11 21:17 327,368 a——- c:\windows\system32\drivers\bdfsfltr.sys
2011-01-11 21:17 12,960 a——- c:\windows\system32\drivers\bdrawpr.sys
2011-01-04 10:25 –d—– c:\docume~1\alluse~1.win\applic~1\bdch
2011-01-03 19:15 –d—– c:\docume~1\user~2.mar\applic~1\QuickScan
2011-01-02 20:29 –d—– c:\docume~1\user~2.mar\applic~1\IsolatedStorage
2011-01-02 17:14 –d—– c:\windows\system32\wbem\Repository
2011-01-02 17:12 –d—– c:\program files\Doublekiller Pro
2011-01-01 21:17 92 a——- C:\ResumeOmgApDeliveryMgrCntrl_SonicStage_EmdDownloadObj.dmf
2011-01-01 16:39 –d—– c:\docume~1\user~2.mar\applic~1\Vistanita
2011-01-01 16:39 –d—– c:\program files\Vistanita
2011-01-01 12:04 –d—– c:\docume~1\user~2.mar\applic~1\Malwarebytes
2011-01-01 12:04 –d—– c:\docume~1\user~2.mar\applic~1\FileMaker Pro Advanced
2011-01-01 12:04 –d—– c:\docume~1\user~2.mar\applic~1\DMCache
2011-01-01 12:04 –d-h— c:\windows\PIF
2011-01-01 12:04 –d—– c:\windows\EHome
2011-01-01 12:04 –d—– c:\windows\Downloaded Installations
2010-12-31 15:54 20 a——- c:\windows\system32\SYSTEM
2010-12-30 19:46 –d—– c:\program files\SigmaTel
2010-12-29 11:41 16 a——- c:\windows\system32\asdict.dat
2010-12-29 11:41 4 a——- c:\windows\system32\aspdict-en.dat
2010-12-29 00:14 –d—– c:\program files\MagicISO
2010-12-25 15:22 57 a——- c:\windows\system32\mapisvc.inf
2010-12-25 15:22 132,608 a——- c:\windows\system32\dllcache\fxsclntr.dll
2010-12-25 15:22 31,744 a——- c:\windows\system32\dllcache\fxsroute.dll
2010-12-25 15:22 11,264 a——- c:\windows\system32\dllcache\fxssend.exe
2010-12-25 15:22 –d—– c:\windows\addins
2010-12-25 15:22 111,104 a——- c:\windows\system32\dllcache\fxscfgwz.dll
2010-12-23 15:46 52 a——- c:\windows\system32\ashttpstats.csv
2010-12-23 01:25 113,933 a——- c:\windows\system32\drivers\klin.dat
2010-12-23 01:25 97,549 a——- c:\windows\system32\drivers\klick.dat
2010-12-22 22:33 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-22 22:33 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-12-22 22:33 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-12-22 19:08 0 a——- c:\windows\system32\wsbl.dat
2010-12-22 19:08 0 a——- c:\windows\system32\ph_white.dat
2010-12-22 19:08 0 a——- c:\windows\system32\ph_summ.dat
2010-12-22 19:08 0 a——- c:\windows\system32\ph_spoof.sig
2010-12-22 19:08 0 a——- c:\windows\system32\ph_sign.slf
2010-12-22 19:08 0 a——- c:\windows\system32\ph_fuzzy.sig
2010-12-22 19:08 0 a——- c:\windows\system32\ph_black.dat
2010-12-22 19:08 0 a——- c:\windows\system32\pcwords2.dat
2010-12-22 19:08 0 a——- c:\windows\system32\pcwords.dat
2010-12-22 19:08 0 a——- c:\windows\system32\pc_sign.slf
2010-12-22 19:08 0 a——- c:\windows\system32\ab_sbl.sig
2010-12-22 19:08 0 a——- c:\windows\system32\ab_bl.sig
2010-12-22 18:36 132 a——- c:\windows\system32\rezumatenoi.dat
2010-12-22 15:21 520,994 a——- c:\docume~1\alluse~1.win\applic~1\bdinstall.bin
2010-12-21 21:56 a-dsh— C:\cmdcons
2010-12-21 21:40 146,432 a——- c:\windows\system32\dllcache\regedit.exe
2010-12-21 21:40 146,432 ——– c:\windows\regedit.exe
2010-12-20 17:40 3,696 a——- c:\windows\system32\RW_{72D15443-6504-11DF-8918-806D6172696F}.dat
2010-12-14 16:53 –d—– c:\program files\Windows Script Control
2010-12-14 16:53 –d—– c:\program files\common files\e.World
2010-12-13 18:00 –d—– c:\docume~1\user~2.mar\applic~1\MetaProducts
2010-12-13 18:00 73,728 a——- c:\windows\system32\SUO.cpl
2010-12-13 17:59 –d—– c:\program files\StartUp Organizer

==================== Find3M ====================

2011-01-11 23:02 111,696 a——- c:\windows\system32\drivers\bdfndisf.sys
2011-01-11 21:50 152,528 a——- c:\windows\system32\drivers\bdfm.sys
2011-01-06 15:43 62,016 a——- c:\windows\system32\RW_FileType.dat
2011-01-06 15:43 15,956 a——- c:\windows\system32\RW_AppData.dat
2010-11-23 17:16 31,552 a——- c:\windows\system32\TURegOpt.exe
2010-11-23 17:11 29,504 a——- c:\windows\system32\uxtuneup.dll
2010-11-18 12:12 81,920 a——- c:\windows\system32\isign32.dll
2010-11-18 12:12 81,920 a——- c:\windows\system32\dllcache\isign32.dll
2010-11-09 08:52 536,576 a——- c:\windows\system32\dllcache\msado15.dll
2010-11-09 08:52 249,856 a——- c:\windows\system32\odbc32.dll
2010-11-09 08:52 249,856 a——- c:\windows\system32\dllcache\odbc32.dll
2010-11-09 08:52 200,704 a——- c:\windows\system32\dllcache\msadox.dll
2010-11-09 08:52 180,224 a——- c:\windows\system32\dllcache\msadomd.dll
2010-11-09 08:52 143,360 a——- c:\windows\system32\dllcache\msadco.dll
2010-11-09 08:52 102,400 a——- c:\windows\system32\dllcache\msjro.dll
2010-11-03 06:26 173,568 a——- c:\windows\system32\dllcache\ie4uinit.exe
2010-11-02 09:17 40,960 a——- c:\windows\system32\dllcache\ndproxy.sys
2010-10-28 07:13 290,048 a——- c:\windows\system32\dllcache\atmfd.dll
2010-10-28 07:13 290,048 a——- c:\windows\system32\atmfd.dll
2010-10-26 07:25 1,853,312 a——- c:\windows\system32\win32k.sys
2010-10-26 07:25 1,853,312 a——- c:\windows\system32\dllcache\win32k.sys
2010-10-20 16:56 4,212 a—h— c:\windows\system32\zllictbl.dat
2010-03-29 18:40 100,256 a——- c:\program files\common files\LinkInstaller.exe
2010-07-10 22:21 2 a–shrot c:\windows\winstart.bat

============= FINISH: 23:27:20.39 ===============
Hello ToddB and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.

I am looking through your log now and will reply as soon as possible.

Satchfan
Hello again ToddB

We’ll need to run a couple of other scans to see what is happening on your machine as there isn’t enough information in that log.

OTL Custom Scan

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic.

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

I’d also like to see the last SUPERAntiSpyware scan log. Please find the most currently-dated log and press View log. A text file will open in your default text editor. Please copy and paste that into your next reply.

===================================================

Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt
SUPERAntiSpyware log


Thanks

Satchfan
Thank you for offering to look at this for me. I really appreciate it! I think this problem may be bigger (or evolving) as when I was online running the above scans you requested after I was finished I noticed that again my Bitdefender AV was shut down. I my real time protection is disabled (and I cannot enable), the virus signatures for the AV is “0” and the engine version is “blank”. Also it has disabled my MBAM application since when I try to access it gives me a runtime error of “0” and then another runtime error of “440”. I would also like to add that when I was online and was getting ready to download OTL my laptop “bluescreened” shut down and rebooted.

Some behaviors of my laptop which are suspicious: I notice a lot of disk activity on my laptop when it is idle. When I close out an internet window the hour glass will appear like it is saving something? When I am using MS Word I have noticed that when word will save I believe it says it is saving to an area of systemrecovery? It just seems that MS word is doing multiple reads and saves when I open, save and close a document. The cursor will “get a mind of its own” and overall my laptop has become sluggish and non-responsive. Finally, when I Iogoff (and shutdown) the machine I notice that the window that says windows is shutting down something that is still running will flash during this time. It appears so quickly that I cannot determine what it is.

With the SuperAntiSpyware scan log I decided to do a fresh scan since I am concerned that the version on my laptop may be compromised (I am able to run my laptop installed version so should I be concerned about using this one?). I have a portable free version that I used to do a complete scan on my laptop. This scan picked up a Trojan that really concerns me. I did quarantine these but I know the malware trace registry infection will re-appear. It is interesting to note that when I quarantined these infections my Bitdefender AV virus signatures and engine version came back to their correct versions and real time scanning is enabled. However MBAM is still giving me the above errors.

Please find the reguested logs below and thank you again! You folks at WTT are GREAT!


OTL logfile created on: 1/12/2011 9:17:24 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 3067 3067 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.78 Gb Total Space | 70.65 Gb Free Space | 66.78% Space Free | Partition Type: NTFS

Computer Name: MARCIA-6X7H850P | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Removal\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch32.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe (BitDefender S.R.L.)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Sony\SmartWi Connection Utility\SmartWiService.exe (Sony Electronics, Inc)
PRC - C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software Inc.)
PRC - c:\Program Files\Verizon Wireless\venturi\Configurator\ventcfg.exe (Venturi Wireless)
PRC - c:\Program Files\Verizon Wireless\venturi\Client\VentC.exe (Venturi Wireless)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Removal\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BitDefender\BitDefender 2011\Active Virus Control\Midas_00074_002\plugin_net.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2011\Active Virus Control\Midas_00074_002\plugin_extra.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2011\Active Virus Control\Midas_00074_002\plugin_nt.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2011\Active Virus Control\Midas_00074_002\plugin_base.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2011\Active Virus Control\Midas_00074_002\plugin_fragments.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2011\Active Virus Control\Midas_00074_002\plugin_registry.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2011\Active Virus Control\Midas_00074_002\midas32.dll (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2011\pchook32.dll (BitDefender S.R.L.)
MOD - C:\Program Files\Internet Download Manager\IDMShellExt.dll (Tonec Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Internet Download Manager\idmmkb.dll (Tonec Inc.)
MOD - C:\Program Files\Windows Script Control\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (TuneUp.Defrag) – C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Update Server) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender)
SRV - (VSSERV) – C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe (BitDefender S.R.L.)
SRV - (Updatesrv) – C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe (BitDefender S.R.L.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (msvsmon90) – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (SmartWiService) – C:\Program Files\Sony\SmartWi Connection Utility\SmartWiService.exe (Sony Electronics, Inc)
SRV - (PersonalSecureDriveService) – C:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE (Infineon Technologies AG)
SRV - (Venturi2) – c:\Program Files\Verizon Wireless\venturi\Client\VentC.exe (Venturi Wireless)
SRV - (lxbu_device) – C:\WINDOWS\System32\lxbucoms.exe (Lexmark International, Inc.)


========== Driver Services (SafeList) ==========

DRV - (sfng32) – C:\WINDOWS\System32\drivers\sfng32.sys File not found
DRV - (pwi_serd) Curitel PC Card Diagnostic Serial Port (WDM) – C:\WINDOWS\System32\DRIVERS\pwi_serd.sys File not found
DRV - (pwi_oflt) – C:\WINDOWS\System32\DRIVERS\pwi_oflt.sys File not found
DRV - (pwi_mdm) – C:\WINDOWS\System32\DRIVERS\pwi_mdm.sys File not found
DRV - (pwi_mdfl) – C:\WINDOWS\System32\DRIVERS\pwi_mdfl.sys File not found
DRV - (pwi_bus) Curitel PC Card Composite Device driver (WDM) – C:\WINDOWS\System32\DRIVERS\pwi_bus.sys File not found
DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\USER~2.MAR\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (bdselfpr) – C:\Program Files\BitDefender\BitDefender 2011\bdselfpr.sys (BitDefender LLC)
DRV - (Trufos) – C:\WINDOWS\system32\drivers\trufos.sys (BitDefender S.R.L.)
DRV - (BDFM) – C:\WINDOWS\system32\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (bdfsfltr) – C:\WINDOWS\system32\DRIVERS\bdfsfltr.sys (BitDefender)
DRV - (Bdfndisf) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfndisf.sys (BitDefender)
DRV - (Bdftdif) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys (BitDefender LLC)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Mvc25U870_VID_1262&PID_25FD) – C:\WINDOWS\system32\drivers\Mvc25U870.sys (Micro Vision Co.,Ltd)
DRV - (DKRtWrt) – C:\WINDOWS\system32\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (IDMTDI) – C:\WINDOWS\system32\drivers\idmtdi.sys (Tonec Inc.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (DrvAgent32) – C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (avckf) – C:\WINDOWS\system32\drivers\avckf.sys (BitDefender)
DRV - (avc3) – C:\WINDOWS\system32\drivers\avc3.sys (BitDefender)
DRV - (BdRawPr) – C:\WINDOWS\system32\drivers\bdrawpr.sys (BITDEFENDER LLC)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Revoflt) – C:\WINDOWS\system32\drivers\revoflt.sys (VS Revo Group)
DRV - (SRS_SSCFilter) SRS Labs Audio Sandbox (WDM) – C:\WINDOWS\system32\drivers\SRS_SSCFilter_i386.sys ()
DRV - (RsFx0103) – C:\WINDOWS\system32\drivers\RsFx0103.sys (Microsoft Corporation)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (PWCTLDRV) – C:\WINDOWS\System32\drivers\PWCTLDRV.sys (DEVGURU Co,LTD.)
DRV - (PTDWVsp) Curitel PC Card Diagnostic Serial Port (UDP) – C:\WINDOWS\system32\drivers\PTDWVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDWMdm) Curitel PC Card Drivers (UDP) – C:\WINDOWS\system32\drivers\PTDWMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDWBus) Curitel PC Card Composite Device driver (UDP) – C:\WINDOWS\system32\drivers\PTDWBus.sys (DEVGURU Co,LTD.)
DRV - (ti21sony) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (TosRfSnd) Bluetooth Audio Device (WDM) – C:\WINDOWS\system32\drivers\tosrfsnd.sys (TOSHIBA Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (TcUsb) – C:\WINDOWS\system32\drivers\tcusb.sys (UPEK Inc.)
DRV - (PersonalSecureDrive) – C:\WINDOWS\System32\drivers\psd.sys (Infineon Technologies AG)
DRV - (shpf) – C:\WINDOWS\system32\DRIVERS\shpf.sys (Sony Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (toshidpt) – C:\WINDOWS\system32\drivers\toshidpt.sys (TOSHIBA Corporation.)
DRV - (SMNDIS5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (SPI) – C:\WINDOWS\system32\drivers\SonyPI.sys (Sony Corporation)
DRV - (UsbFltr) – C:\WINDOWS\System32\drivers\UsbFltr.sys (Waytech Development, Inc.)
DRV - (moufiltr) – C:\WINDOWS\System32\drivers\MOUFILTR.SYS (Windows ® 2000 DDK provider)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7C E9 B7 80 D2 1C CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdaphffext\ [2011/01/11 23:08:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdtbext\ [2011/01/11 21:26:20 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/12/29 11:22:53 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [LXBUCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.DLL ()
O4 - HKCU..\Run: [Controlled StartUp] C:\Program Files\StartUp Organizer\ctrl.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 4
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll (Apple Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (C:\WINDOWS\Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\IfxWlxEN: DllName - IfxWlxEN.dll - C:\WINDOWS\System32\IfxWlxEN.dll (Infineon Technologies AG)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/22 12:47:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()

MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: vsmon - Service
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Security Update for Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.UnInstall.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - rundll32.exe C:\WINDOWS\System32\Setup\FxsOcm.dll,XP_UninstallProvider
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {E9743A4B-95AC-7CD1-E504-44679604A0BE} - Browser Customizations
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /HideWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

========== Files/Folders - Created Within 30 Days ==========

[2011/01/12 21:09:50 | 000,000,000 | RH-D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Recent
[2011/01/12 20:24:42 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Removal
[2011/01/11 21:26:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\BitDefender 2011
[2011/01/11 21:26:12 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\BitDefender
[2011/01/11 21:25:29 | 000,000,000 | —D | C] – C:\Program Files\BitDefender
[2011/01/11 21:18:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\BitDefender
[2011/01/11 21:18:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\BitDefender
[2011/01/11 21:17:56 | 000,306,104 | —- | C] (BitDefender S.R.L.) – C:\WINDOWS\System32\drivers\trufos.sys
[2011/01/11 21:17:55 | 000,327,368 | —- | C] (BitDefender) – C:\WINDOWS\System32\drivers\bdfsfltr.sys
[2011/01/11 21:17:55 | 000,012,960 | —- | C] (BITDEFENDER LLC) – C:\WINDOWS\System32\drivers\bdrawpr.sys
[2011/01/04 20:20:48 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\My Documents\Misc Documents
[2011/01/04 10:25:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\bdch
[2011/01/03 19:15:45 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\QuickScan
[2011/01/02 20:29:52 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\IsolatedStorage
[2011/01/02 17:12:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Doublekiller Pro
[2011/01/02 17:12:47 | 000,000,000 | —D | C] – C:\Program Files\Doublekiller Pro
[2011/01/02 16:26:56 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\My Documents\Visual Studio 2005
[2011/01/01 16:39:44 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Vistanita
[2011/01/01 16:39:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Vistanita Duplicate Finder
[2011/01/01 16:39:41 | 000,000,000 | —D | C] – C:\Program Files\Vistanita
[2011/01/01 12:04:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Templates
[2011/01/01 12:04:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Favorites
[2011/01/01 12:04:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Malwarebytes
[2011/01/01 12:04:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\FileMaker Pro Advanced
[2011/01/01 12:04:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\DMCache
[2011/01/01 12:04:27 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Local Settings\Application Data\Apple
[2011/01/01 12:04:26 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Local Settings\Application Data\Microsoft Help
[2011/01/01 12:04:23 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2011/01/01 12:04:23 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2011/01/01 12:04:23 | 000,000,000 | —D | C] – C:\Qoobox
[2011/01/01 12:04:23 | 000,000,000 | —D | C] – C:\WINDOWS\EHome
[2011/01/01 12:04:23 | 000,000,000 | —D | C] – C:\WINDOWS\Downloaded Installations
[2011/01/01 11:57:27 | 000,000,000 | -H-D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\NetHood
[2010/12/30 19:46:54 | 000,000,000 | —D | C] – C:\Program Files\SigmaTel
[2010/12/29 13:02:31 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/12/29 00:14:21 | 000,000,000 | —D | C] – C:\Documents and Settings\User.MARCIA-6X7H850P\Start Menu\Programs\MagicISO
[2010/12/29 00:14:19 | 000,000,000 | —D | C] – C:\Program Files\MagicISO
[2010/12/25 15:22:46 | 000,000,000 | —D | C] – C:\WINDOWS\addins
[2010/12/22 22:33:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Malwarebytes' Anti-Malware
[2010/12/22 22:33:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/22 22:33:31 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/22 22:33:31 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/21 21:56:06 | 000,000,000 | -HSD | C] – C:\cmdcons
[2010/12/14 16:53:32 | 000,000,000 | —D | C] – C:\Program Files\Windows Script Control
[2010/12/14 16:53:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\e.World

========== Files - Modified Within 30 Days ==========

[2011/01/12 21:13:34 | 000,000,000 | -HS- | M] () – C:\DkHyperbootSync
[2011/01/12 21:12:54 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/12 21:12:25 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/12 20:37:26 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{06B1BC02-2B9F-4237-AF0C-834FD0BDA026}.job
[2011/01/12 20:31:10 | 000,026,396 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Instructions.docx.docx
[2011/01/12 18:41:45 | 000,012,979 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\reply.docx.docx
[2011/01/12 11:34:00 | 000,016,152 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Bdsteps.docx.docx
[2011/01/11 23:35:07 | 000,128,443 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\infection.docx.docx
[2011/01/11 23:07:21 | 000,000,052 | —- | M] () – C:\WINDOWS\System32\ashttpstats.csv
[2011/01/11 23:02:34 | 000,111,696 | —- | M] (BitDefender) – C:\WINDOWS\System32\drivers\bdfndisf.sys
[2011/01/11 22:14:44 | 000,306,104 | —- | M] (BitDefender S.R.L.) – C:\WINDOWS\System32\drivers\trufos.sys
[2011/01/11 21:50:42 | 000,152,528 | —- | M] (BitDefender S.R.L. Bucharest, ROMANIA) – C:\WINDOWS\System32\drivers\bdfm.sys
[2011/01/11 21:34:35 | 000,327,368 | —- | M] (BitDefender) – C:\WINDOWS\System32\drivers\bdfsfltr.sys
[2011/01/11 21:29:03 | 000,000,385 | —- | M] () – C:\WINDOWS\System32\user_gensett.xml
[2011/01/11 21:26:44 | 000,001,869 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\BitDefender Internet Security 2011.lnk
[2011/01/09 21:30:09 | 000,606,792 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/01/09 21:30:09 | 000,134,572 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/01/09 21:29:30 | 000,000,057 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2011/01/07 18:35:36 | 000,015,872 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/07 16:22:13 | 000,018,925 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\RKillInstructions.docx.docx
[2011/01/06 15:43:32 | 000,062,016 | —- | M] () – C:\WINDOWS\System32\RW_FileType.dat
[2011/01/06 15:43:32 | 000,015,956 | —- | M] () – C:\WINDOWS\System32\RW_AppData.dat
[2011/01/06 15:43:32 | 000,000,492 | —- | M] () – C:\WINDOWS\System32\RW_FileFlag.dat
[2011/01/04 17:36:11 | 000,000,376 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Dataprivacy.xml
[2011/01/01 21:17:21 | 000,000,092 | —- | M] () – C:\ResumeOmgApDeliveryMgrCntrl_SonicStage_EmdDownloadObj.dmf
[2010/12/31 15:54:54 | 000,000,020 | —- | M] () – C:\WINDOWS\System32\SYSTEM
[2010/12/29 11:41:10 | 000,000,016 | —- | M] () – C:\WINDOWS\System32\asdict.dat
[2010/12/29 11:41:10 | 000,000,004 | —- | M] () – C:\WINDOWS\System32\aspdict-en.dat
[2010/12/29 11:22:53 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/28 17:02:48 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2010/12/26 22:14:39 | 000,024,097 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Sony laptop support.docx
[2010/12/26 14:41:06 | 000,001,308 | —- | M] () – C:\config.xml
[2010/12/26 14:39:25 | 000,003,696 | —- | M] () – C:\WINDOWS\System32\RW_{72D15443-6504-11DF-8918-806D6172696F}.dat
[2010/12/23 01:25:51 | 000,113,933 | —- | M] () – C:\WINDOWS\System32\drivers\klin.dat
[2010/12/23 01:25:51 | 000,097,549 | —- | M] () – C:\WINDOWS\System32\drivers\klick.dat
[2010/12/22 22:33:41 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/22 22:28:47 | 000,000,025 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\bdfvconp.ini
[2010/12/22 22:07:27 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\phar_unmip.dat
[2010/12/22 22:07:27 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\phar_histprot.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_video.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_socialnetworks.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_searchengines.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_regionaltlds.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_pornography.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_onlineshop.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_onlinepay.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_onlinedating.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_news.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_im.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_webproxy.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_tabloids.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_illegal.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_hate.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_games.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_gambling.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_drugs.dat
[2010/12/22 21:35:37 | 000,000,850 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application DataProductTweaks.xml
[2010/12/22 21:35:37 | 000,000,385 | —- | M] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Datauser_gensett.xml
[2010/12/22 21:32:54 | 000,000,132 | —- | M] () – C:\WINDOWS\System32\rezumatenoi.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\wsbl.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ph_white.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ph_summ.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ph_spoof.sig
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ph_sign.slf
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ph_fuzzy.sig
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ph_black.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pcwords2.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pcwords.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\pc_sign.slf
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ab_sbl.sig
[2010/12/22 19:08:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ab_bl.sig
[2010/12/22 16:42:17 | 000,520,994 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\bdinstall.bin
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/15 21:10:48 | 000,298,048 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/14 11:58:36 | 000,000,211 | —- | M] () – C:\Boot.bak

========== Files Created - No Company Name ==========

[2011/01/12 21:13:34 | 000,000,000 | -HS- | C] () – C:\DkHyperbootSync
[2011/01/12 20:25:27 | 000,026,396 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Instructions.docx.docx
[2011/01/12 17:52:36 | 000,012,979 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\reply.docx.docx
[2011/01/12 11:23:05 | 000,016,152 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Bdsteps.docx.docx
[2011/01/11 21:29:03 | 000,000,385 | —- | C] () – C:\WINDOWS\System32\user_gensett.xml
[2011/01/11 21:26:44 | 000,001,869 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\BitDefender Internet Security 2011.lnk
[2011/01/08 17:02:24 | 000,128,443 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\infection.docx.docx
[2011/01/06 09:43:01 | 000,018,925 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\RKillInstructions.docx.docx
[2011/01/01 21:17:21 | 000,000,092 | —- | C] () – C:\ResumeOmgApDeliveryMgrCntrl_SonicStage_EmdDownloadObj.dmf
[2010/12/31 15:54:53 | 000,000,020 | —- | C] () – C:\WINDOWS\System32\SYSTEM
[2010/12/29 11:41:10 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\asdict.dat
[2010/12/29 11:41:10 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\aspdict-en.dat
[2010/12/25 15:22:48 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\mapisvc.inf
[2010/12/23 15:46:19 | 000,000,052 | —- | C] () – C:\WINDOWS\System32\ashttpstats.csv
[2010/12/23 01:25:51 | 000,113,933 | —- | C] () – C:\WINDOWS\System32\drivers\klin.dat
[2010/12/23 01:25:51 | 000,097,549 | —- | C] () – C:\WINDOWS\System32\drivers\klick.dat
[2010/12/22 22:33:41 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/22 22:28:47 | 000,000,025 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\bdfvconp.ini
[2010/12/22 22:07:27 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\phar_unmip.dat
[2010/12/22 22:07:27 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\phar_histprot.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_video.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_socialnetworks.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_searchengines.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_regionaltlds.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_pornography.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlineshop.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlinepay.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlinedating.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_news.dat
[2010/12/22 22:07:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_im.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_webproxy.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_tabloids.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_illegal.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_hate.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_games.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_gambling.dat
[2010/12/22 22:07:25 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_drugs.dat
[2010/12/22 21:35:37 | 000,000,850 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application DataProductTweaks.xml
[2010/12/22 21:35:37 | 000,000,385 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Datauser_gensett.xml
[2010/12/22 21:35:29 | 000,000,376 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Dataprivacy.xml
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\wsbl.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_white.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_summ.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_spoof.sig
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_sign.slf
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_fuzzy.sig
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_black.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pcwords2.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pcwords.dat
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_sign.slf
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ab_sbl.sig
[2010/12/22 19:08:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ab_bl.sig
[2010/12/22 18:36:34 | 000,000,132 | —- | C] () – C:\WINDOWS\System32\rezumatenoi.dat
[2010/12/22 15:21:34 | 000,520,994 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\bdinstall.bin
[2010/12/21 21:56:10 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/12/20 17:40:46 | 000,003,696 | —- | C] () – C:\WINDOWS\System32\RW_{72D15443-6504-11DF-8918-806D6172696F}.dat
[2010/09/21 20:47:52 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2010/09/07 21:23:49 | 000,268,912 | R— | C] () – C:\WINDOWS\System32\drivers\SRS_SSCFilter_i386.sys
[2010/07/21 16:39:32 | 000,000,036 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Local Settings\Application Data\housecall.guid.cache
[2010/07/11 00:02:41 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfmonnt.dll
[2010/07/09 12:19:46 | 000,015,872 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/30 21:41:54 | 000,000,029 | —- | C] () – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\default.rss
[2010/05/26 13:03:36 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2010/05/26 08:53:11 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2010/04/01 22:08:30 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/04/01 22:08:30 | 000,000,520 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/04/01 22:08:30 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/03/29 18:40:20 | 000,100,256 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2007/04/04 20:28:53 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxbuvs.dll
[2007/03/16 18:15:19 | 000,000,137 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2007/01/31 14:50:32 | 000,913,408 | —- | C] () – C:\WINDOWS\System32\xreglib.dll
[2005/10/25 11:33:06 | 000,036,736 | —- | C] () – C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys

========== LOP Check ==========

[2011/01/04 10:25:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\bdch
[2011/01/11 21:27:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\BitDefender
[2010/11/13 19:10:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2010/10/21 13:08:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Diskeeper Corporation
[2010/10/08 17:49:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Infineon
[2010/06/17 23:14:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MySQL
[2010/11/11 10:27:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PreEmptive Solutions
[2010/09/07 21:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\SRS Labs
[2010/09/20 20:06:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\SuperHideIP
[2010/11/13 17:47:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
[2010/09/28 21:21:22 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2010/07/17 19:08:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
[2010/09/23 19:28:06 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2011/01/11 21:26:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\BitDefender
[2010/06/28 18:43:17 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Business Logic
[2010/12/07 23:20:13 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Business Objects
[2010/08/29 14:43:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\DeepBurner
[2011/01/12 12:13:35 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\DMCache
[2010/07/19 09:04:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\ElevatedDiagnostics
[2010/08/24 21:37:02 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\FileMaker
[2011/01/01 12:04:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\FileMaker Pro Advanced
[2011/01/01 10:58:19 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\IDM
[2011/01/01 18:28:17 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Individual Software
[2010/05/25 18:43:07 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Infineon
[2010/10/08 17:50:47 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\IObit
[2011/01/02 20:29:52 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\IsolatedStorage
[2010/06/20 08:45:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Leadertech
[2010/12/13 18:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\MetaProducts
[2010/10/14 20:19:09 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Notepad++
[2011/01/03 19:15:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\QuickScan
[2010/06/06 10:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Smith Micro
[2010/10/19 10:41:44 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Spam Monitor
[2010/09/20 20:06:32 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\SuperHideIP
[2010/08/31 19:23:23 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Thinstall
[2011/01/01 10:58:31 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\TuneUp Software
[2011/01/01 16:39:44 | 000,000,000 | —D | M] – C:\Documents and Settings\User.MARCIA-6X7H850P\Application Data\Vistanita
[2010/12/05 12:45:10 | 000,000,312 | —- | M] () – C:\WINDOWS\Tasks\Security Platform Backup Schedule.job
[2011/01/12 20:37:26 | 000,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{06B1BC02-2B9F-4237-AF0C-834FD0BDA026}.job

========== Purity Check ==========



< End of report >


OTL Extras logfile created on: 1/12/2011 9:17:24 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 3067 3067 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.78 Gb Total Space | 70.65 Gb Free Space | 66.78% Space Free | Partition Type: NTFS

Computer Name: MARCIA-6X7H850P | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Internet Download Manager\IDMan.exe" = C:\Program Files\Internet Download Manager\IDMan.exe:*:Enabled:Internet Download Manager (IDM) – (Tonec Inc.)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01C5A10F-AD9B-405B-853A-6659841A1242}" = Microsoft SQL Server 2008 Policies
"{05EC21B8-4593-3037-A781-A6B5AFFCB19D}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools - enu
"{068857D8-FDD1-4F29-8F74-E9DE91E8A587}" = Crystal Reports 2008 SP3
"{06A7EA72-0F00-4D53-A81C-A5D925711141}" = Microsoft SQL Server 2008 Full text search
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}" = Visual C++ 2008 x64 Runtime - (v9.0.30729)
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}.vc_x64runtime_30729_01" = Visual C++ 2008 x64 Runtime - v9.0.30729.01
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1EB9429A-A874-4BF0-961D-BDAAFB1641A6}" = Microsoft SQL Server 2005 Backward compatibility
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F1D2DFF-AC4D-4F45-94A4-DDE01ED5ACA2}" = SQL Server 2000 DTS Designer Components
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{2020045B-8DCF-4449-8D5C-EB5BA37440F1}" = Microsoft SQL Server 2008 Management Studio
"{22E23C71-C27A-3F30-8849-BB6129E50679}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729)
"{22E23C71-C27A-3F30-8849-BB6129E50679}.vc_i64runtime_30729_01" = Visual C++ 2008 IA64 Runtime - v9.0.30729.01
"{23BE4DF2-293D-4077-82F4-1FD8C269277C}" = TuneUp Utilities Language Pack (en-US)
"{23F70562-02F4-4805-ACF5-6E52BAD167C2}" = Microsoft SQL Server 2008 Reporting Services
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{275ABBA2-4817-4443-9AB8-ED43CA9AAA17}" = Microsoft SQL Server 2008 BI Development Studio
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2A8CF485-5A4D-4C7D-8ACF-4AB98914D529}" = Infineon TPM Professional Package
"{33AE9E89-47C9-4A0D-9E9D-BDD6966A3804}" = Microsoft SQL Server 2008 RsFx Driver
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{3431A7A3-6287-46B0-8AF1-BE2452A1FE62}" = Microsoft SQL Server 2008 Books Online (English)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3A762A82-618D-3CAA-B847-D074ABFA0B2E}" = MSDN Library for Visual Studio 2008 - ENU
"{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}" = Visual C++ 2008 x64 Runtime - (v9.0.30729.4148)
"{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}.vc_x64runtime_30729_4148" = Visual C++ 2008 x64 Runtime - v9.0.30729.4148
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{40F34A1C-65A2-4163-98CE-A0D0646CABEF}" = Microsoft SQL Server 2008 Integration Services
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{49E98741-B7A4-4A44-A536-6AFCA23106FE}" = Microsoft SQL Server 2008 Reporting Services
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4D28EFCF-5999-44D2-8D4E-AC643E76C33F}" = Microsoft SQL Server 2008 Client Tools
"{4F44B5AE-82A6-4A8A-A3E3-E24D489728E3}" = Microsoft SQL Server 2008 Native Client
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{59996900-0E6C-45B7-8C39-C64CB98462E4}" = Microsoft Web Platform Installer 2.0
"{60D46DEE-5221-47AA-B978-BA25C5D9F560}" = Microsoft SQL Server 2008 Client Tools
"{6249567F-65C3-4EE7-B023-E4FA035B0520}" = Microsoft SQL Server 2008 Analysis Services
"{64c5b887-b5ee-42b8-8596-78905a6b5f1f}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{64CDE8F2-3791-46F5-BAD2-72FFF5252FAB}" = Microsoft SQL Server Compact 3.5 SP1 Query Tools English
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B45B327-4A6F-44BD-AFEF-20822311CFED}" = BitDefender Internet Security 2011
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77E6239B-BF3B-496B-9634-2AC9589B61BB}" = Labtec Mouse Software 2.0
"{7B33F480-496D-334A-BAC2-205DEC0CBC2D}" = Visual C++ 2008 x86 Runtime - (v9.0.30729.4148)
"{7B33F480-496D-334A-BAC2-205DEC0CBC2D}.vc_x86runtime_30729_4148" = Visual C++ 2008 x86 Runtime - v9.0.30729.4148
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-0021-0409-0000-0000000FF1CE}_VisualWebDeveloper_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{97CE8B73-AA5A-4987-A1BE-50DD1A187478}" = Microsoft Sync Framework SDK v1.0 SP1
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.3
"{9B5F85CA-90D4-4AFC-BB37-32477FD0D2B9}" = SmartWi Connection Utility
"{9C59FA2E-EEDA-41FA-90AC-F8FCBD032E85}" = Venturi Client 3.1.4
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E158BB9-37B9-464B-837E-CC1D5766291B}" = VAIO Update 3
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AC54DC1F-EDA7-448C-BA4C-218A92F5E985}" = Microsoft SQL Server 2008 BI Development Studio
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AEB03FAF-90EB-4B4F-BA32-9C4DDE2C9804}" = Microsoft SQL Server 2008 Integration Services
"{AEE75F46-7014-48E6-8AB2-5A12E37475CD}_is1" = Vistanita Duplicate Finder 3.9.6
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B268E9A1-04A9-40D0-9866-846BE2B74BA7}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Win32 Tools
"{B32E7732-B2FB-3FD0-81AC-6025B1104C66}" = Microsoft Device Emulator version 3.0 - ENU
"{B502B428-3386-40A9-98DB-079AAB72E64F}" = mEoU
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{BA4DA261-CB60-4690-B202-44998DFC6986}" = Microsoft SQL Server 2008 Setup Support Files
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C53BECC0-C579-44F8-A995-E97FACB04DFC}" = FileMaker Pro 11 Advanced
"{C53BECC0-C579-44F8-A995-E97FACB04DFC}_FileMaker" = FileMaker Pro 11 Advanced
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C6DD625F-4B61-4561-8286-87CA0275CEA1}" = Microsoft Sync Framework Runtime v1.0 SP1 (x86)
"{C89B00A2-B72A-4935-96FC-38796E9554EC}" = Microsoft Sync Services for ADO.NET v2.0 (x86)
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Tools
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D1087411-3382-4298-8B1B-215A7F02E086}" = MySQL Server 5.1
"{D7DAD1E4-45F4-3B2B-899A-EA728167EC4F}" = Microsoft Visual Studio 2008 Professional Edition - ENU
"{DAA8590D-D93E-4697-9CBE-D96A7590A8E3}" = Microsoft SQL Server 2008 Analysis Services
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F240855E-57B8-4807-9A00-7047211D9793}" = Curitel PC Card Software
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F990B526-8F7C-46E0-B1F1-6C893A8B478F}" = Microsoft Sync Framework Services v1.0 SP1 (x86)
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"{FA9C3624-C693-4423-8A8B-2BC2B9F607AB}" = Microsoft SQL Server 2008 Management Studio
"{FC122DB2-338C-49CF-BBB6-9AB78B23234D}" = Diskeeper 2010 Pro Premier
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FE3997D3-6B56-4AC4-A99C-9DDFC45359BF}" = TuneUp Utilities Language Pack (en-US)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"474492506B458A0013C8197612FA45B887DF7B06" = Windows Driver Package - Sony Corporation (SPI) HIDCLASS (08/20/2002 7.0.3.820)
"5244-9769-3058-9401" = Moneydance 2010
"6228B4FE0926AA3D873E8209B97FB99D06CC1DD8" = Windows Driver Package - Sony Corporation (SNC) HIDClass (06/04/2002 6.0.0.2)
"75CFB2C43D1C9AE2A7A0E5B0453B7550102420DB" = Windows Driver Package - NVIDIA (nv) Display (06/20/2006 8.4.9.1)
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Antechinus C# Editor_is1" = Antechinus C# Editor v6.1
"Applian FLV Player2.0.24" = Applian FLV Player
"BitDefender" = BitDefender Internet Security 2011
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_20030003" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"Convert DOC to PDF For Word_is1" = Convert DOC to PDF For Word 3.50
"Curitel PC Card" = Curitel PC Card Software
"D832C197AD0F836A2AB5DE2033E5948D317F2928" = Windows Driver Package - UPEK (TcUsb) Biometric (11/15/2005 1.8.1.0055)
"Doublekiller Pro_is1" = Doublekiller Pro v2.1.0.104
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ie8" = Windows Internet Explorer 8
"Internet Cell Boost3.0.0" = Internet Cell Boost
"Internet Download Manager" = Internet Download Manager
"Lexmark 6200 Series" = Lexmark 6200 Series
"Magic ISO Maker v5.5 (build 0276)" = Magic ISO Maker v5.5 (build 0276)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaMonkey_is1" = MediaMonkey 3.2
"MetaProducts StartUp Organizer" = MetaProducts StartUp Organizer
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Report Viewer Redistributable 2008 (KB971119)" = Microsoft Report Viewer Redistributable 2008 SP1
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio 2008 Professional Edition - ENU" = Microsoft Visual Studio 2008 Professional Edition - ENU
"MouseSuite98" = Sony USB Mouse
"MSDN Library for Visual Studio 2008 - ENU" = MSDN Library for Visual Studio 2008 - ENU
"Notepad++" = Notepad++
"OpenMG HotFix4.7-07-13-22-01" = OpenMG Limited Patch 4.7-07-14-05-01
"ProInst" = Intel® PROSet/Wireless Software
"Remove Empty Directories" = Remove Empty Directories 2.1
"Revo Uninstaller Pro Retail zoo_is1" = Revo Uninstaller Pro 2.4.1
"SuperHideIP" = Super Hide IP
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"Tweak UI 2.10" = Tweak UI
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Wise Registry Cleaner_is1" = Wise Registry Cleaner Professional V5.12
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wondershare Video to DVD Burner_is1" = Wondershare Video to DVD Burner(Build 2.5.7.3)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/30/2010 11:46:31 PM | Computer Name = MARCIA-6X7H850P | Source = IFXWlxEN | ID = 2687344
Description = Failed to create instance of IWlxEvent interface.

Error - 12/30/2010 11:54:48 PM | Computer Name = MARCIA-6X7H850P | Source = IFXWlxEN | ID = 2687344
Description = Failed to create instance of IWlxEvent interface.

Error - 12/31/2010 12:07:48 AM | Computer Name = MARCIA-6X7H850P | Source = IFXWlxEN | ID = 2687344
Description = Failed to create instance of IWlxEvent interface.

Error - 12/31/2010 12:23:34 AM | Computer Name = MARCIA-6X7H850P | Source = IFXWlxEN | ID = 2687344
Description = Failed to create instance of IWlxEvent interface.

Error - 12/31/2010 12:26:57 AM | Computer Name = MARCIA-6X7H850P | Source = IFXWlxEN | ID = 2687344
Description = Failed to create instance of IWlxEvent interface.

Error - 12/31/2010 12:36:47 AM | Computer Name = MARCIA-6X7H850P | Source = IFXWlxEN | ID = 2687344
Description = Failed to create instance of IWlxEvent interface.

[ System Events ]
Error - 1/12/2011 1:47:57 AM | Computer Name = MARCIA-6X7H850P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IFXSpMgtSrv
with arguments "-Service" in order to run the server: {FBCD9C6A-72CB-47BB-99DD-2317551491DE}

Error - 1/12/2011 9:20:57 AM | Computer Name = MARCIA-6X7H850P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IFXSpMgtSrv
with arguments "-Service" in order to run the server: {FBCD9C66-72CB-47BB-99DD-2317551491DE}

Error - 1/12/2011 12:28:35 PM | Computer Name = MARCIA-6X7H850P | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 1/12/2011 5:43:47 PM | Computer Name = MARCIA-6X7H850P | Source = Service Control Manager | ID = 7034
Description = The Venturi Client service terminated unexpectedly. It has done this
1 time(s).

Error - 1/12/2011 5:43:56 PM | Computer Name = MARCIA-6X7H850P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IFXSpMgtSrv
with arguments "-Service" in order to run the server: {FBCD9C6A-72CB-47BB-99DD-2317551491DE}

Error - 1/12/2011 7:06:41 PM | Computer Name = MARCIA-6X7H850P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IFXSpMgtSrv
with arguments "-Service" in order to run the server: {FBCD9C66-72CB-47BB-99DD-2317551491DE}

Error - 1/12/2011 10:34:03 PM | Computer Name = MARCIA-6X7H850P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IFXSpMgtSrv
with arguments "-Service" in order to run the server: {FBCD9C66-72CB-47BB-99DD-2317551491DE}

Error - 1/12/2011 11:09:45 PM | Computer Name = MARCIA-6X7H850P | Source = Service Control Manager | ID = 7034
Description = The Venturi Client service terminated unexpectedly. It has done this
1 time(s).

Error - 1/12/2011 11:09:51 PM | Computer Name = MARCIA-6X7H850P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IFXSpMgtSrv
with arguments "-Service" in order to run the server: {FBCD9C6A-72CB-47BB-99DD-2317551491DE}

Error - 1/12/2011 11:12:41 PM | Computer Name = MARCIA-6X7H850P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IFXSpMgtSrv
with arguments "-Service" in order to run the server: {FBCD9C66-72CB-47BB-99DD-2317551491DE}


< End of report >

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/13/2011 at 11:11 AM

Application Version : 4.46.1000

Core Rules Database Version : 6191
Trace Rules Database Version: 4003

Scan type : Complete Scan
Total Scan Time : 01:10:50

Memory items scanned : 486
Memory threats detected : 0
Registry items scanned : 9752
Registry threats detected : 1
File items scanned : 29244
File threats detected : 5

Malware.Trace
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL

Adware.Tracking Cookie
C:\Documents and Settings\User.MARCIA-6X7H850P\Cookies\user@collective-media[2].txt
C:\Documents and Settings\User.MARCIA-6X7H850P\Cookies\[removed][2].txt
C:\Documents and Settings\User.MARCIA-6X7H850P\Cookies\[removed][2].txt

Trojan.Agent/Gen-FraudPack
C:\PROGRAM FILES\NOTEPAD++\UNINSTALL.EXE
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\START MENU\PROGRAMS\NOTEPAD++\UNINSTALL.LNK

Attachments:

Satchfan- Just thought of and forgot to mention in my last reply to you that when I did the OTL custom scan I noticed that it only went back 30 days. I did as instructed but I think this infection may be older than that. Just wanted to advise you of this. Also when I mention above that my AV virus signatures and engine came back I spoke too soon as it is again disabled. Finally I forgot to attach a screen shot of this suspect registry and I think I accessed the correct one when I go into my registry editor. I know just enough about virus removal to be dangerous and thank goodness for folks like you but thought I would attach as it requires "permissions". Which raised my suspicion. Thought it may help. Thank you again for your time and work on this and I look forward to your reply!

Attachments:

Hi ToddB

A couple of things to bring to your attention

ComboFix

This is not a tool that should be used by anyone other than an expert. In the hands of someone without COMPLETE knowledge of how it works, it could render your machine a useless piece of metal.

Registry cleaners

These are definitely not recommended. Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance. Please read this.

===================================================

There are indeed some strange outputs in SAS but although the BitDefender problem is one that is quite common, we’ll look a bit deeper and see if we can find out what is happening here.

Let's run a quick scan and have a look at some folders.

Run OTL
  • Double click on the icon to run it
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following

/md5start
netsvcs
drivers32 
msconfig
safebootminimal
safebootnetwork
activex
explorer.*
winlogon.*
/md5stop
C:\WINDOWS\System32\SYSTEM\*.* /s

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt Please post this log.

===================================================

Please navigate to C:\Qoobox and post back with the content of the last ComboFix log: they are numbered ComboFix1, ComboFix2etc. The latest is the one with the highest number.

Please copy and paste that in your next reply together with OTL.txt

Thanks

Satchfan
Thank you for the advice on ComboFix and my registry cleaner. I was not aware of the damage each of these could cause. I was using Combofix under direction to try to remove an outdated/disabled AVG AV application that I thought was corrupt. (You will see it in the log and I was finallly able to delete it) the log I copied/pasted below was the last time I ran it.

For some reason, my BD AV currently is working correctly as my real time protection is enabled, it is successfully updating, and it has the correct virus signatures and engine version.

However, the malware trace registry infection at HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL persist and that is what really concerns me.

Thanks again for your assistance and I do look forward to your reply!

OTL logfile created on: 1/14/2011 6:44:20 PM - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 3067 3067 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.78 Gb Total Space | 70.53 Gb Free Space | 66.68% Space Free | Partition Type: NTFS

Computer Name: MARCIA-6X7H850P | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()

MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: vsmon - Service
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Security Update for Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.UnInstall.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - rundll32.exe C:\WINDOWS\System32\Setup\FxsOcm.dll,XP_UninstallProvider
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {E9743A4B-95AC-7CD1-E504-44679604A0BE} - Browser Customizations
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /HideWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

========== Custom Scans ==========



< MD5 for: EXPLORER.BMP >
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\1028\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\1031\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\1033\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\1036\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\1040\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\1041\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\1042\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\1049\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\2052\explorer.bmp
[2007/08/30 17:14:22 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\templates\3082\explorer.bmp

< MD5 for: EXPLORER.DESIGNER.VB >
[2009/12/21 10:28:26 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\VSTAHost\SSIS_ScriptTask\9.0\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer.zip\explorer.designer.vb
[2007/11/08 08:02:06 | 000,036,523 | —- | M] () MD5=D0619C994564E5DD196C3E8650D91174 – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplatesCache(2)\VisualBasic(2)\Windows Forms(2)\1033(2)\Explorer(2).zip\explorer.designer.vb
[2007/11/08 08:02:06 | 000,036,523 | —- | M] () MD5=D0619C994564E5DD196C3E8650D91174 – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer.zip\explorer.designer.vb

< MD5 for: EXPLORER.EX_ >
[2003/03/31 06:00:00 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2011/01/14 18:01:02 | 000,103,766 | —- | M] () MD5=C445BF6907759A2A4095D5BBCD542B9F – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.GIF >
[2008/01/09 13:04:30 | 000,003,342 | —- | M] () MD5=2C9E121C2DECEF61FED6EA977A30D90F – C:\Program Files\Microsoft Visual Studio 9.0\VC\VCWizards\AppWiz\MFC\Application\images\Explorer.gif

< MD5 for: EXPLORER.RESX >
[2009/12/21 10:28:26 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\VSTAHost\SSIS_ScriptTask\9.0\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer.zip\explorer.resx
[2007/11/08 08:02:06 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplatesCache(2)\VisualBasic(2)\Windows Forms(2)\1033(2)\Explorer(2).zip\explorer.resx
[2007/11/08 08:02:06 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer.zip\explorer.resx

< MD5 for: EXPLORER.SC_ >
[2003/03/31 06:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2003/03/31 06:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: EXPLORER.VB >
[2009/12/21 10:28:26 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\VSTAHost\SSIS_ScriptTask\9.0\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer.zip\explorer.vb
[2007/11/08 08:02:06 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplatesCache(2)\VisualBasic(2)\Windows Forms(2)\1033(2)\Explorer(2).zip\explorer.vb
[2007/11/08 08:02:06 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer.zip\explorer.vb

< MD5 for: EXPLORER.VSTEMPLATE >
[2009/12/21 10:28:26 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\VSTAHost\SSIS_ScriptTask\9.0\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer.zip\explorer.vstemplate
[2007/11/08 08:02:06 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplatesCache(2)\VisualBasic(2)\Windows Forms(2)\1033(2)\Explorer(2).zip\explorer.vstemplate
[2007/11/08 08:02:06 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer.zip\explorer.vstemplate

< MD5 for: EXPLORER.ZIP >
[2007/11/08 07:02:08 | 000,024,306 | —- | M] () MD5=3CAA9AA502C183C02137F62D0D538984 – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer.zip

< MD5 for: WINLOGON.EX_ >
[2003/03/31 06:00:00 | 000,271,067 | —- | M] () MD5=C73F996304F177262B0C2B70A7DCB66C – C:\I386\WINLOGON.EX_

< MD5 for: WINLOGON.EXE >
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< C:\WINDOWS\System32\SYSTEM\*.* /s >

< End of report >



ComboFix 10-12-28.01 - User 12/28/2010 20:28:27.8.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1481 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Virus Stuff\ComboFix.exe
AV: AVG Anti-Virus 2011 *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *Enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-29 )))))))))))))))))))))))))))))))
.

2010-12-26 21:12 . 2010-12-26 21:12 ——– d—–w- c:\documents and settings\Administrator.MARCIA-6X7H850P\Application Data\BitDefender
2010-12-26 21:00 . 2010-12-26 21:00 ——– d—–w- c:\documents and settings\Guest\Application Data\TuneUp Software
2010-12-26 20:57 . 2010-12-26 20:57 ——– d—–w- c:\documents and settings\Guest\Application Data\BitDefender
2010-12-26 20:50 . 2010-12-26 20:50 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\VS Revo Group
2010-12-25 21:24 . 2010-12-25 21:24 ——– d—–w- c:\windows\system32\FxsTmp
2010-12-25 21:22 . 2010-12-25 21:22 ——– d—–w- c:\windows\addins
2010-12-25 21:22 . 2003-03-31 12:00 31744 -c–a-w- c:\windows\system32\dllcache\fxsroute.dll
2010-12-25 21:22 . 2003-03-31 12:00 31744 —-a-w- c:\windows\system32\fxsroute.dll
2010-12-25 21:22 . 2003-03-31 12:00 132608 -c–a-w- c:\windows\system32\dllcache\fxsclntr.dll
2010-12-25 21:22 . 2003-03-31 12:00 132608 —-a-w- c:\windows\system32\fxsclntR.dll
2010-12-25 21:22 . 2003-03-31 12:00 11264 -c–a-w- c:\windows\system32\dllcache\fxssend.exe
2010-12-25 21:22 . 2003-03-31 12:00 11264 —-a-w- c:\windows\system32\fxssend.exe
2010-12-25 21:22 . 2003-03-31 12:00 111104 -c–a-w- c:\windows\system32\dllcache\fxscfgwz.dll
2010-12-25 21:22 . 2003-03-31 12:00 111104 —-a-w- c:\windows\system32\fxscfgwz.dll
2010-12-23 16:06 . 2010-12-23 16:06 ——– d—–w- c:\windows\system32\wbem\Repository
2010-12-23 07:25 . 2010-12-23 07:25 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-12-23 07:25 . 2010-12-23 07:25 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-12-23 07:20 . 2010-12-23 21:57 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2010-12-23 07:16 . 2010-12-23 07:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2010-12-23 04:33 . 2010-12-21 00:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 04:33 . 2010-12-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-12-23 04:33 . 2010-12-21 00:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 00:12 . 2010-12-23 00:19 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2010-12-23 00:12 . 2010-12-23 00:14 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\BitDefender
2010-12-23 00:12 . 2010-12-23 00:12 ——– d—–w- c:\program files\BitDefender
2010-12-23 00:00 . 2010-12-23 00:13 ——– d—–w- c:\program files\Common Files\BitDefender
2010-12-22 23:56 . 2010-12-22 23:59 37099 —-a-w- C:\BdUninstallTool2010.12.22-05.56.18.reg
2010-12-22 21:23 . 2010-12-22 21:23 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\QuickScan
2010-12-22 21:21 . 2010-12-22 22:42 520994 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\bdinstall.bin
2010-12-22 03:40 . 2008-04-14 10:42 146432 -c–a-w- c:\windows\system32\dllcache\regedit.exe
2010-12-22 03:40 . 2008-04-14 10:42 146432 ——w- c:\windows\regedit.exe
2010-12-19 03:00 . 2010-12-19 03:00 ——– d—–w- c:\program files\Free ISO Creator
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Windows Script Control
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Common Files\e.World
2010-12-14 00:00 . 2010-12-14 00:00 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\MetaProducts
2010-12-14 00:00 . 2009-03-02 19:55 73728 —-a-w- c:\windows\system32\SUO.cpl
2010-12-13 23:59 . 2010-12-14 00:00 ——– d—–w- c:\program files\StartUp Organizer
2010-12-13 22:34 . 2010-12-13 22:35 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\GetRightToGo
2010-12-08 05:11 . 2010-12-25 21:25 ——– d—–w- c:\program files\Business Objects
2010-12-05 02:41 . 2010-11-23 23:16 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2010-12-05 02:41 . 2010-11-23 23:11 29504 —-a-w- c:\windows\system32\uxtuneup.dll
2010-12-05 02:40 . 2010-12-05 02:41 ——– d—–w- c:\program files\TuneUp Utilities 2011
2010-12-05 01:09 . 2003-06-25 22:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2010-11-29 03:59 . 2010-12-18 23:53 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\Smart PC Solutions

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-23 03:04 . 2009-11-10 23:03 106464 —-a-w- c:\windows\system32\drivers\bdhv.sys
2010-12-23 03:04 . 2009-11-10 23:04 153448 —-a-w- c:\windows\system32\drivers\bdfm.sys
2010-12-23 03:04 . 2009-07-24 17:26 291352 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2010-12-23 02:59 . 2009-10-19 22:04 111312 —-a-w- c:\windows\system32\drivers\bdfndisf.sys
2010-12-08 05:19 . 2010-06-16 02:19 1748416 -c–a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-11-18 18:12 . 2010-05-21 23:35 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-12 02:14 . 2010-06-06 22:07 18368 -c–a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-11-06 00:26 . 2003-03-31 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2003-03-31 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2003-03-31 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2010-05-25 16:35 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2003-03-31 12:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2003-03-31 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2003-03-31 12:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-10-11 02:32 . 2010-10-11 02:32 73728 -c–a-w- c:\windows\system32\javacpl.cpl
2010-10-11 02:32 . 2010-10-11 02:32 423656 -c–a-w- c:\windows\system32\deployJava1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-08-25 14:36 70264 —-a-w- c:\program files\Internet Download Manager\IDMShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Controlled StartUp"="c:\program files\StartUp Organizer\Ctrl.exe" [2009-03-02 193576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]

c:\documents and settings\user\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 4 (0x4)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-10 20:20 434176 —-a-w- c:\windows\system32\IfxWlxEN.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [3/11/2002 1:55 AM 9216]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [8/25/2010 8:40 AM 76768]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [11/29/2005 5:50 PM 36768]
R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 2:09 AM 239336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [6/6/2010 7:57 PM 6144]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [9/22/2009 8:22 AM 85128]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/22/2010 10:33 PM 363344]
R2 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [7/10/2008 12:22 AM 218136]
R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [7/10/2008 12:15 AM 31256]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [11/23/2010 5:13 PM 1483072]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [11/10/2009 5:04 PM 153448]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [10/19/2009 4:04 PM 111312]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [10/21/2010 1:08 PM 44368]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [8/29/2006 7:31 PM 36352]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/22/2010 10:33 PM 20952]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [7/19/2007 10:38 AM 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [7/19/2007 10:38 AM 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [7/19/2007 10:38 AM 39808]
R3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [7/19/2007 10:38 AM 5888]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [5/21/2010 12:29 PM 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [5/26/2010 11:26 AM 808448]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10/7/2010 12:34 PM 10064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [10/19/2009 4:06 PM 183880]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [7/18/2010 9:58 PM 23456]
S3 icsak;icsak;\??\c:\program files\CheckPoint\ZAForceField\AK\icsak.sys –> c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [?]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys –> c:\windows\system32\DRIVERS\pwi_bus.sys [?]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys –> c:\windows\system32\DRIVERS\pwi_mdfl.sys [?]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys –> c:\windows\system32\DRIVERS\pwi_mdm.sys [?]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys –> c:\windows\system32\DRIVERS\pwi_oflt.sys [?]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys –> c:\windows\system32\DRIVERS\pwi_serd.sys [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [8/19/2010 9:08 PM 27064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/25/2010 7:33 PM 11520]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [3/31/2003 6:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 1:49 AM 47128]
S4 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/30/2009 1:16 AM 1113448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
bdx REG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-12-05 c:\windows\Tasks\Security Platform Backup Schedule.job
- c:\program files\Infineon\Security Platform Software\SpBackupWz.exe [2006-03-10 20:33]

2010-12-29 c:\windows\Tasks\User_Feed_Synchronization-{06B1BC02-2B9F-4237-AF0C-834FD0BDA026}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = about:blank
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {2643ABF9-63C0-479C-B0A1-DBCEAEB940B7} = 69.78.96.14 66.174.92.14
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-28 20:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6175B6E8-3D5E-8729-2540-D055604E5C59}*]
"kaggmdejllmffnhbnbhiod"=hex:61,61,00,00
"faggmdejamki"=hex:66,61,6a,68,68,67,6e,63,68,6a,65,6d,00,00

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9C6CF11F-216C-07F5-E86A-095ECC1154CA}*]
"oakejaihmocgedmecojhjmchapjlnm"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54
"naielbhcbbjkfininppakggoecap"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e0,a1,23,af,68,fc,2d,6a,cb,34,5f,bf,47,3b,62,7f,b7,d2,33,0e,96,
27,2e,b5,dc,b8,92,b1,c9,d5,77,69,f1,05,b4,49,db,0c,65,0e,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8f,d2,4d,a1,8f,eb,94,ad,30,43,d0,63,83,f2,01,57,f0,c1,28,fd,a3,
b1,76,9e,ce,65,77,04,5b,b1,78,29,37,3d,3d,76,92,d0,05,90,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1888)
c:\windows\system32\IfxWlxEN.dll

- - - - - - - > 'explorer.exe'(2672)
c:\windows\system32\WININET.dll
c:\program files\Internet Download Manager\IDMShellExt.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-12-28 20:40:53
ComboFix-quarantined-files.txt 2010-12-29 02:40
ComboFix2.txt 2010-12-28 03:33
ComboFix3.txt 2010-12-27 22:13
ComboFix4.txt 2010-12-27 17:49
ComboFix5.txt 2010-12-29 02:26

Pre-Run: 71,970,467,840 bytes free
Post-Run: 71,968,591,872 bytes free

- - End Of File - - C6593847A7275B5CB626C3FCA477027F
Satchfan- I just wanted to pass along to you something that happened to me after I carried out your instructions above. I decided to check my email and I use Yahoo Email so I signed into my account. I noticed an email that indicated it was sent by me to a handful of my contacts but which I did not send and it included me since I keep myself in my contacts for such an occasion. It was just a link to something I imagine is harmful or obscene so I decided to open a new email and advise those it was sent to that the email may be harmful. Just as I was finishing composing this message a popup appeared saying “do you want to navigate away from this page” – I believe I hit yes and it discarded my email and sent me back to my inbox. I have also noticed that on the Yahoo email signon screen that I do not get the “are you protected – create a signon seal” (I do not have one) but instead just has a create a new account above my logon id and password. Does someone have control of my email account and can they “see” what I am currently doing on it? Is that possible? Maybe I am getting paranoid here but this is REALLY getting strange!
Hi ToddB

What you're seeing is called ”spoofing" or more correctly "From-spoofing" - sending email that appears as if it's coming "From:" someone that it is not.

The “From:” address is meaningless in spam - it tells you absolutely nothing, but it is just spam and not coming from you.

It is possible that your email/IM login credentials have been compromised. You could try changing your password which will prevent the remote server from accessing your account.


[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of
    Java Runtime Environment (JRE) 23
    and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 23 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u20 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys File not found
    IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No CLSID value found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - Reg Error: Value error. File not found
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Value error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
    O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [resethosts]
    [emptyflash]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)


Run Malwarebytes’ Anti-Malware
  • Please open your MalwareBytes AntiMalware Program (If you no longer have it, you can download it from here)
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


Run ESET Online Scan

Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Please let me know how your computer is running.

Thanks

Satchfan
Satchfan-
I carried out your instructions above but unfortunately when I do a SAS scan I am still getting the malware trace registry infection HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL. SAS is the only scan which will pick this up for some reason as my MBAM and ESET scans come up clean.

Thank you for the JAVA instructions. I looked for “jre-6u20-windows-i586-p.exe” but could not find. Thinking it may be “jre-6u23-windows-i586-p.exe” so I follow your instructions above and loaded that. Is that correct?

A couple of things in regards the OTL fix I carried out above. You will notice that I copied/pasted 2 logs as I did 2 runs of this as my first fix gave me a “cannot create file c:\windows\system32\drivers\etc\hosts” and then it hung. I waited for the longest time and then decided to shut it down and rerun it. The 2nd run seemed to run normally and the results are below as well.

Also, I was not sure if you wanted me to post the OTL scan fix results or do another quick OTL scan after I ran the fix so I decided to post the fixes and await further direction.

A couple of items I would like to pass on to you at this point: When I remove this malware trace registry with SAS it will not reappear in a scan until I log onto the internet, logoff, reboot and then do another SAS scan. Also, when I shutdown widows I have noticed that apntex.exe will not shutdown normally as it flashes that windows is shutting it down.

Could this possibly be a winlogon vundo virus? I noticed there is a tool called VundoFix but will not do ANYTHING until I receive further direction from you.

Thank you again for your assistance, I look forward to your reply, and please find my logs below.

1st OTL run fix:

Files\Folders moved on Reboot…
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.

Registry entries deleted on Reboot…


2nd OTL run fix:


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Error: No service named icsak was found to stop!
Service\Driver key icsak not found.
File C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys File not found not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{472734EA-242A-422b-ADF8-83D1E48CC825} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422b-ADF8-83D1E48CC825}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found.
Starting removal of ActiveX control {7530BFB8-7293-4D34-9923-61A11451AFC5}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A9007C0-4076-11D3-8789-0000F8105754}\ not found.
File {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Removal\cmd.bat deleted successfully.
C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Removal\cmd.txt deleted successfully.
========== COMMANDS ==========
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator

User: Administrator.MARCIA-6X7H850P

User: All Users

User: All Users.WINDOWS

User: Default User

User: Default User.WINDOWS

User: Guest

User: Laptop

User: LocalService

User: LocalService.NT AUTHORITY

User: LocalService.NT AUTHORITY.000

User: LocalService.NT AUTHORITY.001
->Flash cache emptied: 0 bytes

User: NetworkService

User: NetworkService.NT AUTHORITY

User: NetworkService.NT AUTHORITY.000

User: NetworkService.NT AUTHORITY.001
->Flash cache emptied: 0 bytes

User: user

User: User.MARCIA-6X7H850P
->Flash cache emptied: 653 bytes

User: User.Todd-TF2IQZZQ

User: USER~2~MAR

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Administrator.MARCIA-6X7H850P
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: All Users.WINDOWS

User: Default User
->Temporary Internet Files folder emptied: 0 bytes

User: Default User.WINDOWS
->Temporary Internet Files folder emptied: 0 bytes

User: Guest
->Temporary Internet Files folder emptied: 0 bytes

User: Laptop
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.NT AUTHORITY.001
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.NT AUTHORITY.001
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 50686 bytes
->Flash cache emptied: 0 bytes

User: user
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: User.MARCIA-6X7H850P
->Temp folder emptied: 37677 bytes
->Temporary Internet Files folder emptied: 5937490 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: User.Todd-TF2IQZZQ
->Temporary Internet Files folder emptied: 0 bytes

User: USER~2~MAR

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 82403 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 6.00 mb


OTL by OldTimer - Version 3.2.20.1 log created on 01162011_182839

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5534

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/16/2011 6:45:58 PM
mbam-log-2011-01-16 (18-45-58).txt

Scan type: Quick scan
Objects scanned: 272371
Time elapsed: 7 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/17/2011 at 02:43 PM

Application Version : 4.45.1000

Core Rules Database Version : 6216
Trace Rules Database Version: 4028

Scan type : Quick Scan
Total Scan Time : 00:14:32

Memory items scanned : 467
Memory threats detected : 0
Registry items scanned : 1922
Registry threats detected : 1
File items scanned : 6735
File threats detected : 0

Malware.Trace
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL
ToddB

I looked for “jre-6u20-windows-i586-p.exe” but could not find. Thinking it may be “jre-6u23-windows-i586-p.exe” so I follow your instructions above and loaded that. Is that correct?

Yes. Apologies, my mistake

Download and run ComboFix

I realise that you have done this before but I don't know which forum it was and what the previous instructions were so I'd like a fresh look.

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.


When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
Satchfan-
Thank you for the reply and offer to look at my ComboFix Log. I have copied/pasted my ComboFix Log below. I would like to advise of something I did just prior to receiving your thread reply and hopefully will give some insight into this situation.

I decided to do a Rkill with my Bitdefender IDS activated and I blocked the following process (actually there were two similar but hoping the screen shot wil be of help) from running prior to running rkill.exe (please see attached). I then did a quick SAS scan and it picked up a bunch of Trojans! I copied/pasted those results below as well. I also did a follow up scan and no Trojans appeared but the malware trace registry persist.

I also had something really strange and scary occur on my laptop just after I deleted these and was going online to download ComboFix. I was online when I noticed a small box in the right hand corner of my machine appear that said something like “drop hyperlinks here” and it had the symbol of a shopping cart just below it! I quickly went into task manager and killed the process which was running. I guess I was so shocked that I forgot to get the exe name.

Thank you for your help on this as this infection really has me worried. I look forward to your reply.

ComboFix 11-01-18.02 - User 01/18/2011 20:31:40.10.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1436 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Virus Removal\ComboFix.exe
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *Enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users.WINDOWS\Application Data\1doc2pdf.dll
c:\windows\system32\html
c:\windows\system32\html\calendar.html
c:\windows\system32\html\calendarbottom.html
c:\windows\system32\html\calendartop.html
c:\windows\system32\html\crystalexportdialog.htm
c:\windows\system32\html\crystalprinthost.html

.
((((((((((((((((((((((((( Files Created from 2010-12-19 to 2011-01-19 )))))))))))))))))))))))))))))))
.

2011-01-17 00:18 . 2011-01-17 00:18 ——– d—–w- C:\_OTL
2011-01-16 23:59 . 2011-01-16 23:59 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-01-14 00:28 . 2011-01-14 00:28 ——– d—–w- c:\windows\system32\psconv
2011-01-14 00:28 . 2011-01-14 00:28 ——– d—–w- c:\program files\psconvert
2011-01-12 03:26 . 2011-01-12 03:26 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\BitDefender
2011-01-12 03:25 . 2011-01-12 03:25 ——– d—–w- c:\program files\BitDefender
2011-01-12 03:18 . 2011-01-12 03:25 ——– d—–w- c:\program files\Common Files\BitDefender
2011-01-12 03:18 . 2011-01-12 03:27 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2011-01-12 03:17 . 2011-01-13 17:57 308152 —-a-w- c:\windows\system32\drivers\trufos.sys
2011-01-12 03:17 . 2011-01-12 03:34 327368 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2011-01-12 03:17 . 2010-05-13 23:02 12960 —-a-w- c:\windows\system32\drivers\bdrawpr.sys
2011-01-04 16:25 . 2011-01-04 16:25 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\bdch
2011-01-04 03:15 . 2011-01-04 03:15 ——– d—–w- c:\documents and settings\NetworkService.NT AUTHORITY.001\Application Data\QuickScan
2011-01-04 01:15 . 2011-01-04 01:15 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\QuickScan
2011-01-03 02:29 . 2011-01-03 02:29 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\IsolatedStorage
2011-01-02 23:14 . 2011-01-02 23:14 ——– d—–w- c:\windows\system32\wbem\Repository
2011-01-02 23:12 . 2011-01-02 23:12 ——– d—–w- c:\program files\Doublekiller Pro
2011-01-01 22:39 . 2011-01-01 22:39 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\Vistanita
2011-01-01 22:39 . 2011-01-01 22:39 ——– d—–w- c:\program files\Vistanita
2010-12-31 01:46 . 2010-12-31 01:46 ——– d—–w- c:\program files\SigmaTel
2010-12-29 06:14 . 2010-12-29 06:14 ——– d—–w- c:\program files\MagicISO
2010-12-26 20:50 . 2010-12-26 20:50 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\VS Revo Group
2010-12-25 21:22 . 2011-01-10 03:30 ——– d—–w- c:\windows\addins
2010-12-25 21:22 . 2003-03-31 12:00 31744 —-a-w- c:\windows\system32\dllcache\fxsroute.dll
2010-12-25 21:22 . 2003-03-31 12:00 132608 —-a-w- c:\windows\system32\dllcache\fxsclntr.dll
2010-12-25 21:22 . 2003-03-31 12:00 11264 —-a-w- c:\windows\system32\dllcache\fxssend.exe
2010-12-25 21:22 . 2003-03-31 12:00 111104 —-a-w- c:\windows\system32\dllcache\fxscfgwz.dll
2010-12-23 07:25 . 2010-12-23 07:25 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-12-23 07:25 . 2010-12-23 07:25 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-12-23 04:33 . 2010-12-21 00:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 04:33 . 2010-12-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-12-23 04:33 . 2010-12-21 00:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-22 21:21 . 2010-12-22 22:42 520994 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\bdinstall.bin
2010-12-22 03:40 . 2008-04-14 10:42 146432 —-a-w- c:\windows\system32\dllcache\regedit.exe
2010-12-22 03:40 . 2008-04-14 10:42 146432 ——w- c:\windows\regedit.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-16 23:59 . 2010-10-11 02:32 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-01-12 05:02 . 2010-06-18 22:11 111696 —-a-w- c:\windows\system32\drivers\bdfndisf.sys
2011-01-12 03:50 . 2010-04-22 19:19 152528 —-a-w- c:\windows\system32\drivers\bdfm.sys
2010-12-08 05:19 . 2010-06-16 02:19 1748416 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-11-23 23:16 . 2010-12-05 02:41 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2010-11-23 23:11 . 2010-12-05 02:41 29504 —-a-w- c:\windows\system32\uxtuneup.dll
2010-11-18 18:12 . 2010-05-21 23:35 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-12 02:14 . 2010-06-06 22:07 18368 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-11-09 14:52 . 2003-03-31 12:00 249856 —-a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2003-03-31 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2003-03-31 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2003-03-31 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2010-05-25 16:35 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2003-03-31 12:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2003-03-31 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2003-03-31 12:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-03-30 00:40 . 2010-03-30 00:40 100256 —-a-w- c:\program files\Common Files\LinkInstaller.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-08-25 14:36 70264 —-a-w- c:\program files\Internet Download Manager\IDMShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Controlled StartUp"="c:\program files\StartUp Organizer\Ctrl.exe" [2009-03-02 193576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-09-10 69632]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\ieshow.exe" [2011-01-12 71216]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\user\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 4 (0x4)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-10 20:20 434176 —-a-w- c:\windows\system32\IfxWlxEN.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [3/11/2002 1:55 AM 9216]
R1 BdRawPr;BdRawPr;c:\windows\system32\drivers\bdrawpr.sys [1/11/2011 9:17 PM 12960]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [8/25/2010 8:40 AM 76768]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [11/29/2005 5:50 PM 36768]
R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 2:09 AM 239336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [6/6/2010 7:57 PM 6144]
R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [7/10/2008 12:15 AM 31256]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [11/23/2010 5:13 PM 1483072]
R2 Updatesrv;BitDefender Desktop Update Service;c:\program files\BitDefender\BitDefender 2011\updatesrv.exe [6/29/2010 9:33 PM 43424]
R3 BDFM;BDFM;c:\windows\system32\drivers\bdfm.sys [4/22/2010 1:19 PM 152528]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfndisf.sys [6/18/2010 4:11 PM 111696]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [10/21/2010 1:08 PM 44368]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [8/29/2006 7:31 PM 36352]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [7/19/2007 10:38 AM 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [7/19/2007 10:38 AM 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [7/19/2007 10:38 AM 39808]
R3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [7/19/2007 10:38 AM 5888]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [5/21/2010 12:29 PM 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [5/26/2010 11:26 AM 808448]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10/7/2010 12:34 PM 10064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [7/18/2010 9:58 PM 23456]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/22/2010 10:33 PM 20952]
S3 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/22/2010 10:33 PM 363344]
S3 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [7/10/2008 12:22 AM 218136]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys –> c:\windows\system32\DRIVERS\pwi_bus.sys [?]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys –> c:\windows\system32\DRIVERS\pwi_mdfl.sys [?]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys –> c:\windows\system32\DRIVERS\pwi_mdm.sys [?]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys –> c:\windows\system32\DRIVERS\pwi_oflt.sys [?]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys –> c:\windows\system32\DRIVERS\pwi_serd.sys [?]
S3 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/30/2009 1:16 AM 1113448]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [8/19/2010 9:08 PM 27064]
S3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [6/29/2010 8:22 PM 307544]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/25/2010 7:33 PM 11520]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [3/31/2003 6:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 avc3;avc3;c:\windows\system32\drivers\avc3.sys [6/28/2010 12:55 PM 633424]
S4 avckf;avckf;c:\windows\system32\drivers\avckf.sys [6/28/2010 12:55 PM 970320]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 1:49 AM 47128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
bdx REG_MULTI_SZ scan sysagent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-12-05 c:\windows\Tasks\Security Platform Backup Schedule.job
- c:\program files\Infineon\Security Platform Software\SpBackupWz.exe [2006-03-10 20:33]

2011-01-18 c:\windows\Tasks\User_Feed_Synchronization-{06B1BC02-2B9F-4237-AF0C-834FD0BDA026}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = about:blank
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-18 20:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6175B6E8-3D5E-8729-2540-D055604E5C59}*]
"kaggmdejllmffnhbnbhiod"=hex:61,61,00,00
"faggmdejamki"=hex:66,61,6a,68,68,67,6e,63,68,6a,65,6d,00,00

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9C6CF11F-216C-07F5-E86A-095ECC1154CA}*]
"oakejaihmocgedmecojhjmchapjlnm"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54
"naielbhcbbjkfininppakggoecap"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e0,a1,23,af,68,fc,2d,6a,cb,34,5f,bf,47,3b,62,7f,b7,d2,33,0e,96,
27,2e,b5,dc,b8,92,b1,c9,d5,77,69,f1,05,b4,49,db,0c,65,0e,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8f,d2,4d,a1,8f,eb,94,ad,30,43,d0,63,83,f2,01,57,f0,c1,28,fd,a3,
b1,76,9e,ce,65,77,04,5b,b1,78,29,37,3d,3d,76,92,d0,05,90,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1168)
c:\windows\system32\IfxWlxEN.dll
.
Completion time: 2011-01-18 20:59:18
ComboFix-quarantined-files.txt 2011-01-19 02:59

Pre-Run: 76,167,450,624 bytes free
Post-Run: 76,141,580,288 bytes free

- - End Of File - - 8D6DA8315BF1AB6DD9492C0A00C549DB


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/18/2011 at 06:34 PM

Application Version : 4.45.1000

Core Rules Database Version : 6228
Trace Rules Database Version: 4040

Scan type : Quick Scan
Total Scan Time : 00:15:03

Memory items scanned : 456
Memory threats detected : 0
Registry items scanned : 1922
Registry threats detected : 1
File items scanned : 6770
File threats detected : 9

Malware.Trace
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL

Trojan.Agent/Gen-IEFake
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX0\H\IEXPLORE.EXE
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX0\PROCS\IEXPLORE.EXE
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX1\H\IEXPLORE.EXE
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX1\PROCS\IEXPLORE.EXE
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX2\H\IEXPLORE.EXE
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX2\PROCS\IEXPLORE.EXE

Trojan.Agent/Gen-IExplorer[Fake]
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX0\NIRD\IEXPLORE.EXE
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX1\NIRD\IEXPLORE.EXE
C:\DOCUMENTS AND SETTINGS\USER.MARCIA-6X7H850P\LOCAL SETTINGS\TEMP\RARSFX2\NIRD\IEXPLORE.EXE


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/18/2011 at 07:56 PM

Application Version : 4.45.1000

Core Rules Database Version : 6228
Trace Rules Database Version: 4040

Scan type : Quick Scan
Total Scan Time : 00:15:30

Memory items scanned : 467
Memory threats detected : 0
Registry items scanned : 1922
Registry threats detected : 1
File items scanned : 6764
File threats detected : 0

Malware.Trace
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL

Attachments:

Satchfan- In thinking about this last night after I sent you my last reply and logs I thought that in order to further help you with this I would send some more screen shots that I have taken. Each screen shot has an explanation of the situation . Just thought it may assist in your endeavor and if they are more of a nuisance than assistance please just let me know and I will stop sending these with my replies. 📎screenshot1.pdf 📎screenshot2.pdf Also in thinking about the “Trojans” my first SAS scan picked up last night after running Rkill I am thinking these were actually Rkill “Trojans” that SAS quarantined? :blush: If so, thank goodness for folks like you and WTT! Thanks again for your help on this and I look forward to your reply and direction!
Satchfan- I forgot to included one more attachment that I did for "explorer.exe" on my machine. There is a prefetch one that I am suspicious of. Again if these screen shots are a hassle or hindrance in your evaluation please advise. 📎screenshot4.pdf

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI