This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus on computer

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I had some help from here before with my laptop and I thank you for that. Now my parents computer has a virus, and I need help removing it. Last night is when it started, and a program called MS Removal Tool keeps popping up claiming to have found infenctions, I can't run Task Manager, and it won't let me run any antivirus software. I put it in safe mode and ran MBAM, but the problem still seems to be there. I had to run it again in safe mode to get Hijack This to work, here is the log:

EDIT: With the help of google, I think I was able to find the MS Removal Tool thing and delete it. The computer is faster but I'm not sure if it's fully gone, because I haven't messed with the registry files.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:27:28 AM, on 3/31/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/home.php?ref=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBitT.dll
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBitT.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
O3 - Toolbar: MAGIX Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBitT.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SGPUpdater] C:\Program Files\Search Guard PlusU\sgpUpdaters.exe
O4 - HKLM\..\Run: [FBSearch] C:\Program Files\Search Guard Plus\SearchGuardPlus.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DriverCure] C:\Program Files\ParetoLogic\DriverCure\DriverCure.exe -scan
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\RunOnce: [pBh24512dLlKn24512] C:\Documents and Settings\All Users\Application Data\pBh24512dLlKn24512\pBh24512dLlKn24512.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} (Photo Upload Plugin Class) - http://www.walmartphotocentre.ca/upload/ac…veX_Control.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: intu-tt2010 - {97A0575E-2309-4E75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe

–
End of file - 10652 bytes
Hello lamaroo and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

I think I was able to find the MS Removal Tool thing and delete it

Are you able to boot into Normal Mode and connect to the net using the infected machine now?

If you are still having problems connecting, you will need to download the required tools using an uninfected machine and then transfer them to the infected system. If you use a flash drive for the transfer, please run the following tool first to reduce the chances of cross infection:


  • Please download Flash Disinfector


    • Click here to download Flash Disinfector and save the file (called Flash_Disinfector.exe) to your desktop.
    • Double click on the Flash_Disinfector.exe icon to run the program and follow any prompts that may appear.
    • The program may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so if prompted.
    • Wait until Flash disinfector has finished scanning and then exit the program.
    • Reboot your computer.

    Please try the following from Normal Mode. If you are unable to scan with DDS and GMER after running rkill from normal mode, please scan the machine from safe mode.

  • rkill


    • Please download rkill (Courtesy of Bleepingcomputer.com).
    • There are 5 different versions of this tool. If one of them will not run, please try the next one in the list.
    • Note: Vista and Windows 7 Users must right click and select "Run as Administrator" to run the tool.
    • Note: You only need to get one of the tools to run, not all of them.


    1. rkill.exe
    2. rkill.com
    3. rkill.scr
    4. WiNlOgOn.exe
    5. uSeRiNiT.exe

    Note: You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message.

    Run rkill repeatedly until it's able to do it's job. This may take a few tries.

    You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.
  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you encounter any problems with the scans come back and let me know.
The first DDS log is in the post, the attach.txt and Gmer.txt are attached, hope that's alright.


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 9:11:12.35 on Fri 04/01/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.55 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
svchost.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\AM_Delta.exe
C:\WINDOWS\system32\MpSigStub.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.facebook.com/home.php?ref=hp
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: SearchSettings Class: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\search settings\SearchSettings.dll
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: MAGIX Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SearchSettings Class: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\search settings\SearchSettings.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: MAGIX Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DriverCure] c:\program files\paretologic\drivercure\DriverCure.exe -scan
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nForce Tray Options] sstray.exe /r
mRun: []
mRun: [CHotkey] zHotkey.exe
mRun: [ShowWnd] ShowWnd.exe
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SGPUpdater] c:\program files\search guard plusu\sgpUpdaters.exe
mRun: [FBSearch] c:\program files\search guard plus\SearchGuardPlus.exe
mRun: [SearchSettings] c:\program files\search settings\SearchSettings.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: &Search
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.walmartphotocentre.ca/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: intu-tt2010 - {97A0575E-2309-4e75-8509-B1F9390C4DE7} - c:\program files\turbotax 2010\ic2010pp.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\u4qtwskk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2790392&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=
FF - plugin: c:\documents and settings\owner\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: theSUPERprofile: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: [removed] - %profile%\extensions\[removed]
FF - Ext: Easy Youtube Video Downloader: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} - %profile%\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-04-01 13:10:09 6792528 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{5a8b8911-3eb5-41f7-8a1a-06653d67aae7}\mpengine.dll
2011-03-31 19:56:53 ——– d—–w- c:\docume~1\owner\applic~1\PriceGong
2011-03-31 02:10:00 ——– d—–w- c:\docume~1\alluse~1\applic~1\pBh24512dLlKn24512
2011-03-16 02:54:47 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\Conduit
2011-03-16 02:54:46 ——– d—–w- c:\program files\Conduit
2011-03-16 02:54:44 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\BitTorrentBar
2011-03-16 02:54:34 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\ConduitEngine
2011-03-16 02:54:31 ——– d—–w- c:\program files\ConduitEngine
2011-03-16 02:54:19 ——– d—–w- c:\program files\BitTorrentBar
2011-03-16 02:54:19 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\Temp
2011-03-16 02:53:14 ——– d—–w- c:\program files\BitTorrent
2011-03-16 02:52:16 ——– d—–w- c:\docume~1\owner\applic~1\BitTorrent
2011-03-06 22:32:46 1409 —-a-w- c:\windows\QTFont.for
2011-03-06 15:58:50 ——– d—–w- c:\docume~1\owner\applic~1\Intuit Canada
2011-03-06 15:58:12 ——– d—–w- c:\program files\common files\Intuit
2011-03-06 15:57:48 ——– d—–w- c:\program files\TurboTax 2010
2011-03-06 15:57:08 ——– d—–w- c:\docume~1\alluse~1\applic~1\Intuit Canada
.
==================== Find3M ====================
.
2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll
2011-01-05 16:47:18 1712201 —-a-w- c:\windows\system32\InetClnt.dll
.
============= FINISH: 9:15:29.00 ===============
Hello lamaroo

Thank you for the logs.

hope that's alright

Its no problem at all :)

Please work your way through the following steps:

  • P2P Programs:


    • P2P programs are a major source of Malware infections.
    • From your log I see you have LimeWire 5.0.11 and BitTorrent We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • A list of currently installed programs will be displayed.
    • Find each program, click on it once and then click on the "Remove" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.

      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Toolbars


    • I can see that you have ask toolbar and BitTorrentBar Toolbar installed.
    • We recommend that you uninstall these toolbars from your machine.
    • To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • A list of currently installed programs will be displayed.
    • Find the "ask toolbar" program, click on it once and then click on the "Remove" button.
    • Repeat this procedure for "BitTorrentBar Toolbar"
    • If you are prompted to re-boot your computer to complete the uninstall please do so.

  • Combofix


    • Download ComboFix from one of the following locations:

      Link 1
      Link 2

    • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

    • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]

    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
    • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
    • Should there be issues with internet afterward:

      In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

      In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

    Please post the ComboFix log in your next reply.
ComboFix 11-04-02.03 - Owner 04/02/2011 23:34:03.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.209 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\pBh24512dLlKn24512
c:\documents and settings\All Users\Application Data\pBh24512dLlKn24512\pBh24512dLlKn24512
c:\documents and settings\All Users\Application Data\pBh24512dLlKn24512\pBh24512dLlKn24512.exe
c:\documents and settings\Owner\Application Data\.#
c:\documents and settings\Owner\Application Data\.#\MBX@114@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@114@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@114@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@11A8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@11A8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@11E4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@11E4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@11FC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@11FC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@11FC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@1244@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@1244@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@1244@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@1310@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@1310@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@1310@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@13EC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@13EC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@13EC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@140C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@140C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@140C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@1528@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@1528@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@1528@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@15C0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@15C0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@15C0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@15F0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@15F0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@15F0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@16C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@16C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@16C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@1788@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@1788@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@1788@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@1A0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@1A0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@1A0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@1C0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@1C0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@1C0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@1CC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@1CC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@1CC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@250@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@250@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@250@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@360@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@360@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@360@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@424@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@424@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@424@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@438@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@438@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@438@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@4548@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@4548@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@4548@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@4564@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@4564@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@4564@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@468@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@468@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@468@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@488@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@488@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@488@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@4A4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@4A4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@4BC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@4BC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@4BC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@4F0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@4F0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@4F0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@52C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@52C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@52C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@54C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@54C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@54C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@5EC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@5EC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@5EC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@640@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@640@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@640@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@660@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@660@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@660@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@664@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@664@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@664@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@6B0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@6B0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@6B0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@6D0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@6D0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@6D0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@708@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@708@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@708@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@71C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@71C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@71C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@738@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@738@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@738@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@74C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@74C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@74C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@7A4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@7A4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@7F0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@7F0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@7F0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@808@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@808@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@808@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@814@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@814@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@814@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@818@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@818@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@818@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@820@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@820@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@820@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@824@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@824@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@824@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@834@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@834@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@834@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@850@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@850@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@850@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@85C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@85C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@85C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@8B0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@8B0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@8B0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@8BC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@8BC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@8BC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@8C8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@8C8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@8C8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@8D0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@8D0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@8DC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@8DC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@8DC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@8E4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@8E4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@8E4@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@8EC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@8EC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@8EC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@934@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@934@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@934@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@944@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@944@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@944@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@98C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@98C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@98C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@990@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@990@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@990@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@9AC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@9AC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@9AC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@9C4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@9C4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@9C4@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@9C8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@9C8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@9C8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@9F8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@9F8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@9F8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@9FC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@9FC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@A40@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@A40@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@A40@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@A48@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@A48@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@A48@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@A50@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@A50@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@A50@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@A6C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@A6C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@A6C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@B18@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@B18@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@B18@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@B44@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@B44@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@B44@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@B74@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@B74@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@B74@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@B9C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@B9C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@B9C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@BC0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@BC0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@BC0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@BD8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@BD8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@BD8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@C14@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@C14@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@C14@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@C1C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@C1C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@C1C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@C24@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@C24@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@C24@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@C38@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@C38@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@C38@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@C48@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@C48@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@C48@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@C58@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@C58@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@C58@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@C9C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@C9C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@C9C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@CA4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@CA4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@CA4@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@CA8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@CA8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@CA8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@CC8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@CC8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@CC8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@CD0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@CD0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@CD0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@CDC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@CDC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@CDC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@CF0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@CF0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@CF0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@CF8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@CF8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@CF8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@D04@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@D04@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@D04@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@D2C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@D2C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@D2C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@D3C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@D3C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@D3C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@D6C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@D6C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@D6C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@D74@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@D74@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@D74@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@D7C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@D7C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@D7C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@D80@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@D80@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@D80@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@D94@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@D94@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@D94@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@DA0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@DA0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@DA0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@DA4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@DA4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@DA4@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@DAC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@DAC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@DAC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@DB0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@DB0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@DB0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@DC0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@DC0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@DC0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@DD0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@DD0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@DD0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@DE4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@DE4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@DE4@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@DF8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@DF8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@DF8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E10@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E10@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E10@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E18@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E18@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E18@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E1C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E1C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E1C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E20@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E20@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E20@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E28@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E28@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E28@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E34@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E34@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E34@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E44@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E44@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E44@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E48@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E48@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E48@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E4C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E4C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E4C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E50@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E50@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E50@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E54@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E54@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E54@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E6C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E6C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E6C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@E8C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@E8C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@E8C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@EA0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@EA0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@EA0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@EA4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@EA4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@EA4@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@EB8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@EB8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@EC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@EC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@EC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@EE8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@EE8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@EE8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@EF8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@EF8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@EF8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F04@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F04@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F04@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F14@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F14@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F14@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F20@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F20@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F20@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F2C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F2C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F2C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F30@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F30@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F30@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F38@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F38@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F38@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F3C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F3C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F3C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F68@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F68@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F68@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F78@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F78@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F78@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F84@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F84@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F84@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F8C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F8C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F8C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F90@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F90@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F90@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F98@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F98@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F98@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@F9C@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@F9C@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@F9C@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@FA4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@FA4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@FA4@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@FB4@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@FB4@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@FB4@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@FB8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@FB8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@FB8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@FBC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@FBC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@FBC@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@FC0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@FC0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@FC0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@FE0@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@FE0@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@FE0@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@FE8@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@FE8@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@FE8@384248.###
c:\documents and settings\Owner\Application Data\.#\MBX@FEC@3841E8.###
c:\documents and settings\Owner\Application Data\.#\MBX@FEC@384218.###
c:\documents and settings\Owner\Application Data\.#\MBX@FEC@384248.###
c:\documents and settings\Owner\Application Data\PriceGong
c:\documents and settings\Owner\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Owner\System
c:\documents and settings\Owner\System\win_qs8.jqx
c:\program files\Search Settings
c:\program files\Search Settings\FF\chrome.manifest
c:\program files\Search Settings\FF\chrome\content\plugin.js
c:\program files\Search Settings\FF\chrome\content\plugin.xul
c:\program files\Search Settings\FF\chrome\content\protection.js
c:\program files\Search Settings\FF\chrome\content\utils.js
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.dtd
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.properties
c:\program files\Search Settings\FF\components\IFBHOSearch.xpt
c:\program files\Search Settings\FF\components\IFBHOSearchHelperEngine.xpt
c:\program files\Search Settings\FF\components\IFHelperPreferences.xpt
c:\program files\Search Settings\FF\components\SearchSettingsFF.dll
c:\program files\Search Settings\FF\install.rdf
c:\program files\Search Settings\SeARchsettings.dll
c:\program files\Search Settings\SearchSettings.exe
c:\program files\Search Settings\SearchSettingsRes409.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\hack
c:\windows\system32\hack\OEMLINK\OEM1.reg
c:\windows\system32\hack\OEMLINK\OEM2.reg
c:\windows\system32\hack\OEMLINK\OEM3.reg
.
.
((((((((((((((((((((((((( Files Created from 2011-03-03 to 2011-04-03 )))))))))))))))))))))))))))))))
.
.
2011-04-03 03:05 . 2011-04-03 03:05 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EBB0C9A-2A9C-4D0F-AAC8-94938ED58E20}\MpKsl0ac15fd0.sys
2011-04-02 13:40 . 2011-04-02 13:40 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EBB0C9A-2A9C-4D0F-AAC8-94938ED58E20}\MpKslabf5d65c.sys
2011-04-02 13:36 . 2011-03-15 04:05 6792528 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EBB0C9A-2A9C-4D0F-AAC8-94938ED58E20}\mpengine.dll
2011-03-16 02:54 . 2011-04-03 02:21 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Conduit
2011-03-16 02:54 . 2011-03-16 02:54 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2011-03-06 22:32 . 2011-03-06 22:32 1409 —-a-w- c:\windows\QTFont.for
2011-03-06 15:58 . 2011-03-06 15:58 ——– d—–w- c:\documents and settings\Owner\Application Data\Intuit Canada
2011-03-06 15:58 . 2011-03-06 15:58 ——– d—–w- c:\program files\Common Files\Intuit
2011-03-06 15:57 . 2011-03-08 21:21 ——– d—–w- c:\program files\TurboTax 2010
2011-03-06 15:57 . 2011-03-06 15:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Intuit Canada
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-15 04:05 . 2010-08-20 03:47 6792528 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-09 13:53 . 2003-01-03 11:41 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2003-01-03 11:41 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2003-01-03 12:53 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2003-01-03 12:53 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2003-01-03 11:41 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-13 09:41 . 2011-01-27 21:54 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-01-07 14:09 . 2003-01-03 11:41 290048 —-a-w- c:\windows\system32\atmfd.dll
2011-01-05 16:47 . 2011-01-05 16:47 1712201 —-a-w- c:\windows\system32\InetClnt.dll
2011-03-18 17:53 . 2011-04-03 02:54 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-04-23 801904]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-12 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-03-03 46080]
"nForce Tray Options"="sstray.exe" [2003-09-03 73728]
"CHotkey"="zHotkey.exe" [2004-05-18 543232]
"ShowWnd"="ShowWnd.exe" [2003-09-19 36864]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-03-11 135168]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 50688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-01-03 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Zac Browser English\\zacbrowser.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\GoLive2\\Golive2 Sphere\\StixTM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22483:TCP"= 22483:TCP:PORT_22483
"41852:TCP"= 41852:TCP:PORT_41852
"55664:TCP"= 55664:TCP:PORT_55664
"22071:TCP"= 22071:TCP:PORT_22071
"55000:TCP"= 55000:TCP:PORT_55000
"16470:TCP"= 16470:TCP:PORT_16470
"25610:TCP"= 25610:TCP:PORT_25610
"24131:TCP"= 24131:TCP:PORT_24131
"8531:TCP"= 8531:TCP:PORT_8531
"45461:TCP"= 45461:TCP:PORT_45461
"20820:TCP"= 20820:TCP:PORT_20820
"38102:TCP"= 38102:TCP:PORT_38102
"46949:TCP"= 46949:TCP:PORT_46949
"62164:TCP"= 62164:TCP:PORT_62164
"45445:TCP"= 45445:TCP:PORT_45445
"12914:TCP"= 12914:TCP:PORT_12914
"46195:TCP"= 46195:TCP:PORT_46195
"36680:TCP"= 36680:TCP:PORT_36680
"19476:TCP"= 19476:TCP:PORT_19476
"7793:TCP"= 7793:TCP:PORT_7793
"11571:TCP"= 11571:TCP:PORT_11571
"14617:TCP"= 14617:TCP:PORT_14617
"49368:TCP"= 49368:TCP:PORT_49368
"23430:TCP"= 23430:TCP:PORT_23430
"34000:TCP"= 34000:TCP:PORT_34000
"53360:TCP"= 53360:TCP:PORT_53360
"27785:TCP"= 27785:TCP:PORT_27785
"22201:TCP"= 22201:TCP:PORT_22201
"44629:TCP"= 44629:TCP:PORT_44629
"55872:TCP"= 55872:TCP:PORT_55872
"20406:TCP"= 20406:TCP:PORT_20406
"27738:TCP"= 27738:TCP:PORT_27738
"10707:TCP"= 10707:TCP:PORT_10707
"9521:TCP"= 9521:TCP:PORT_9521
"25025:TCP"= 25025:TCP:PORT_25025
"32231:TCP"= 32231:TCP:PORT_32231
"64906:TCP"= 64906:TCP:PORT_64906
"49726:TCP"= 49726:TCP:PORT_49726
"12887:TCP"= 12887:TCP:PORT_12887
"50990:TCP"= 50990:TCP:PORT_50990
"8438:TCP"= 8438:TCP:PORT_8438
"38434:TCP"= 38434:TCP:PORT_38434
"41438:TCP"= 41438:TCP:PORT_41438
"50473:TCP"= 50473:TCP:PORT_50473
"6915:TCP"= 6915:TCP:PORT_6915
"42695:TCP"= 42695:TCP:PORT_42695
"36766:TCP"= 36766:TCP:PORT_36766
"49520:TCP"= 49520:TCP:PORT_49520
"44201:TCP"= 44201:TCP:PORT_44201
"7955:TCP"= 7955:TCP:PORT_7955
"10723:TCP"= 10723:TCP:PORT_10723
"8864:TCP"= 8864:TCP:PORT_8864
"36653:TCP"= 36653:TCP:PORT_36653
"59211:TCP"= 59211:TCP:PORT_59211
"63935:TCP"= 63935:TCP:PORT_63935
"56551:TCP"= 56551:TCP:PORT_56551
"43528:TCP"= 43528:TCP:PORT_43528
"5552:TCP"= 5552:TCP:PORT_5552
"23122:TCP"= 23122:TCP:PORT_23122
"48895:TCP"= 48895:TCP:PORT_48895
"30226:TCP"= 30226:TCP:PORT_30226
"17598:TCP"= 17598:TCP:PORT_17598
"62423:TCP"= 62423:TCP:PORT_62423
"18060:TCP"= 18060:TCP:PORT_18060
"12963:TCP"= 12963:TCP:PORT_12963
"20278:TCP"= 20278:TCP:PORT_20278
"40495:TCP"= 40495:TCP:PORT_40495
"62781:TCP"= 62781:TCP:PORT_62781
"53411:TCP"= 53411:TCP:PORT_53411
"57540:TCP"= 57540:TCP:PORT_57540
"7540:TCP"= 7540:TCP:PORT_7540
"38958:TCP"= 38958:TCP:PORT_38958
"35594:TCP"= 35594:TCP:PORT_35594
"14438:TCP"= 14438:TCP:PORT_14438
"23469:TCP"= 23469:TCP:PORT_23469
"27665:TCP"= 27665:TCP:PORT_27665
"38204:TCP"= 38204:TCP:PORT_38204
"31493:TCP"= 31493:TCP:PORT_31493
"34805:TCP"= 34805:TCP:PORT_34805
"34518:TCP"= 34518:TCP:PORT_34518
"5676:TCP"= 5676:TCP:PORT_5676
"56988:TCP"= 56988:TCP:PORT_56988
"42658:TCP"= 42658:TCP:PORT_42658
"14986:TCP"= 14986:TCP:PORT_14986
"48153:TCP"= 48153:TCP:PORT_48153
"19876:TCP"= 19876:TCP:PORT_19876
"32205:TCP"= 32205:TCP:PORT_32205
"23353:TCP"= 23353:TCP:PORT_23353
"20551:TCP"= 20551:TCP:PORT_20551
"23067:TCP"= 23067:TCP:PORT_23067
"56906:TCP"= 56906:TCP:PORT_56906
"27999:TCP"= 27999:TCP:PORT_27999
"48560:TCP"= 48560:TCP:PORT_48560
"23020:TCP"= 23020:TCP:PORT_23020
"30985:TCP"= 30985:TCP:PORT_30985
"23705:TCP"= 23705:TCP:PORT_23705
"17518:TCP"= 17518:TCP:PORT_17518
"14910:TCP"= 14910:TCP:PORT_14910
"57680:TCP"= 57680:TCP:PORT_57680
"9950:TCP"= 9950:TCP:PORT_9950
"26871:TCP"= 26871:TCP:PORT_26871
"18269:TCP"= 18269:TCP:PORT_18269
"25148:TCP"= 25148:TCP:PORT_25148
"60391:TCP"= 60391:TCP:PORT_60391
"52916:TCP"= 52916:TCP:PORT_52916
"61248:TCP"= 61248:TCP:PORT_61248
"26708:TCP"= 26708:TCP:PORT_26708
"51696:TCP"= 51696:TCP:PORT_51696
"44434:TCP"= 44434:TCP:PORT_44434
"28332:TCP"= 28332:TCP:PORT_28332
"18425:TCP"= 18425:TCP:PORT_18425
"29477:TCP"= 29477:TCP:PORT_29477
"38933:TCP"= 38933:TCP:PORT_38933
"35270:TCP"= 35270:TCP:PORT_35270
"26060:TCP"= 26060:TCP:PORT_26060
"44633:TCP"= 44633:TCP:PORT_44633
"35363:TCP"= 35363:TCP:PORT_35363
"64520:TCP"= 64520:TCP:PORT_64520
"51748:TCP"= 51748:TCP:PORT_51748
"38137:TCP"= 38137:TCP:PORT_38137
"5087:TCP"= 5087:TCP:PORT_5087
"35231:TCP"= 35231:TCP:PORT_35231
"55633:TCP"= 55633:TCP:PORT_55633
"50793:TCP"= 50793:TCP:PORT_50793
"58060:TCP"= 58060:TCP:PORT_58060
"50270:TCP"= 50270:TCP:PORT_50270
"62400:TCP"= 62400:TCP:PORT_62400
"17203:TCP"= 17203:TCP:PORT_17203
"41775:TCP"= 41775:TCP:PORT_41775
"14563:TCP"= 14563:TCP:PORT_14563
"38873:TCP"= 38873:TCP:PORT_38873
"27196:TCP"= 27196:TCP:PORT_27196
"40110:TCP"= 40110:TCP:PORT_40110
"57481:TCP"= 57481:TCP:PORT_57481
"21703:TCP"= 21703:TCP:PORT_21703
"40000:TCP"= 40000:TCP:PORT_40000
"17223:TCP"= 17223:TCP:PORT_17223
"48536:TCP"= 48536:TCP:PORT_48536
"15571:TCP"= 15571:TCP:PORT_15571
"57476:TCP"= 57476:TCP:PORT_57476
"22981:TCP"= 22981:TCP:PORT_22981
"52853:TCP"= 52853:TCP:PORT_52853
"36703:TCP"= 36703:TCP:PORT_36703
"61801:TCP"= 61801:TCP:PORT_61801
"20613:TCP"= 20613:TCP:PORT_20613
"65395:TCP"= 65395:TCP:PORT_65395
"11910:TCP"= 11910:TCP:PORT_11910
"49650:TCP"= 49650:TCP:PORT_49650
"45454:TCP"= 45454:TCP:PORT_45454
"23537:TCP"= 23537:TCP:PORT_23537
"22164:TCP"= 22164:TCP:PORT_22164
"39985:TCP"= 39985:TCP:PORT_39985
"48789:TCP"= 48789:TCP:PORT_48789
"31892:TCP"= 31892:TCP:PORT_31892
"16981:TCP"= 16981:TCP:PORT_16981
"59868:TCP"= 59868:TCP:PORT_59868
"40993:TCP"= 40993:TCP:PORT_40993
"46954:TCP"= 46954:TCP:PORT_46954
"16293:TCP"= 16293:TCP:PORT_16293
"38094:TCP"= 38094:TCP:PORT_38094
"11500:TCP"= 11500:TCP:PORT_11500
"43536:TCP"= 43536:TCP:PORT_43536
"39923:TCP"= 39923:TCP:PORT_39923
"36528:TCP"= 36528:TCP:PORT_36528
"7190:TCP"= 7190:TCP:PORT_7190
"61008:TCP"= 61008:TCP:PORT_61008
"15621:TCP"= 15621:TCP:PORT_15621
"37306:TCP"= 37306:TCP:PORT_37306
"47043:TCP"= 47043:TCP:PORT_47043
"12931:TCP"= 12931:TCP:PORT_12931
"33876:TCP"= 33876:TCP:PORT_33876
"61243:TCP"= 61243:TCP:PORT_61243
"62548:TCP"= 62548:TCP:PORT_62548
"22856:TCP"= 22856:TCP:PORT_22856
"52290:TCP"= 52290:TCP:PORT_52290
"61459:TCP"= 61459:TCP:PORT_61459
"25481:TCP"= 25481:TCP:PORT_25481
"44313:TCP"= 44313:TCP:PORT_44313
"19965:TCP"= 19965:TCP:PORT_19965
"27358:TCP"= 27358:TCP:PORT_27358
"40691:TCP"= 40691:TCP:PORT_40691
"44363:TCP"= 44363:TCP:PORT_44363
"30496:TCP"= 30496:TCP:PORT_30496
"39116:TCP"= 39116:TCP:PORT_39116
"54571:TCP"= 54571:TCP:PORT_54571
"39560:TCP"= 39560:TCP:PORT_39560
"6700:TCP"= 6700:TCP:PORT_6700
"61446:TCP"= 61446:TCP:PORT_61446
"11583:TCP"= 11583:TCP:PORT_11583
"12469:TCP"= 12469:TCP:PORT_12469
"23584:TCP"= 23584:TCP:PORT_23584
"5311:TCP"= 5311:TCP:PORT_5311
"52563:TCP"= 52563:TCP:PORT_52563
"5816:TCP"= 5816:TCP:PORT_5816
"22094:TCP"= 22094:TCP:PORT_22094
"27411:TCP"= 27411:TCP:PORT_27411
"56840:TCP"= 56840:TCP:PORT_56840
"27969:TCP"= 27969:TCP:PORT_27969
"53758:TCP"= 53758:TCP:PORT_53758
"60586:TCP"= 60586:TCP:PORT_60586
"29983:TCP"= 29983:TCP:PORT_29983
"64840:TCP"= 64840:TCP:PORT_64840
"46297:TCP"= 46297:TCP:PORT_46297
"17788:TCP"= 17788:TCP:PORT_17788
"37012:TCP"= 37012:TCP:PORT_37012
"48731:TCP"= 48731:TCP:PORT_48731
"18927:TCP"= 18927:TCP:PORT_18927
"51457:TCP"= 51457:TCP:PORT_51457
"43344:TCP"= 43344:TCP:PORT_43344
"46828:TCP"= 46828:TCP:PORT_46828
"21049:TCP"= 21049:TCP:PORT_21049
"20740:TCP"= 20740:TCP:PORT_20740
"39301:TCP"= 39301:TCP:PORT_39301
"43543:TCP"= 43543:TCP:PORT_43543
"8006:TCP"= 8006:TCP:PORT_8006
"40395:TCP"= 40395:TCP:PORT_40395
"31325:TCP"= 31325:TCP:PORT_31325
"43595:TCP"= 43595:TCP:PORT_43595
"28707:TCP"= 28707:TCP:PORT_28707
"54981:TCP"= 54981:TCP:PORT_54981
"55145:TCP"= 55145:TCP:PORT_55145
"35903:TCP"= 35903:TCP:PORT_35903
"57551:TCP"= 57551:TCP:PORT_57551
"8165:TCP"= 8165:TCP:PORT_8165
"55028:TCP"= 55028:TCP:PORT_55028
"49508:TCP"= 49508:TCP:PORT_49508
"5618:TCP"= 5618:TCP:PORT_5618
"49547:TCP"= 49547:TCP:PORT_49547
"62188:TCP"= 62188:TCP:PORT_62188
"28625:TCP"= 28625:TCP:PORT_28625
"61582:TCP"= 61582:TCP:PORT_61582
"39153:TCP"= 39153:TCP:PORT_39153
"59599:TCP"= 59599:TCP:PORT_59599
"38034:TCP"= 38034:TCP:PORT_38034
"27762:TCP"= 27762:TCP:PORT_27762
"18879:TCP"= 18879:TCP:PORT_18879
"58711:TCP"= 58711:TCP:PORT_58711
"26662:TCP"= 26662:TCP:PORT_26662
"41555:TCP"= 41555:TCP:PORT_41555
"44215:TCP"= 44215:TCP:PORT_44215
"7051:TCP"= 7051:TCP:PORT_7051
"34885:TCP"= 34885:TCP:PORT_34885
"52876:TCP"= 52876:TCP:PORT_52876
"57856:TCP"= 57856:TCP:PORT_57856
"57422:TCP"= 57422:TCP:PORT_57422
"27189:TCP"= 27189:TCP:PORT_27189
"44661:TCP"= 44661:TCP:PORT_44661
"49254:TCP"= 49254:TCP:PORT_49254
"10157:TCP"= 10157:TCP:PORT_10157
"56157:TCP"= 56157:TCP:PORT_56157
"36207:TCP"= 36207:TCP:PORT_36207
"16475:TCP"= 16475:TCP:PORT_16475
"50415:TCP"= 50415:TCP:PORT_50415
"44488:TCP"= 44488:TCP:PORT_44488
"14000:TCP"= 14000:TCP:PORT_14000
"25094:TCP"= 25094:TCP:PORT_25094
"54535:TCP"= 54535:TCP:PORT_54535
"11317:TCP"= 11317:TCP:PORT_11317
"50448:TCP"= 50448:TCP:PORT_50448
"11829:TCP"= 11829:TCP:PORT_11829
"25698:TCP"= 25698:TCP:PORT_25698
"55887:TCP"= 55887:TCP:PORT_55887
"27298:TCP"= 27298:TCP:PORT_27298
"63445:TCP"= 63445:TCP:PORT_63445
"11526:TCP"= 11526:TCP:PORT_11526
"52076:TCP"= 52076:TCP:PORT_52076
"27996:TCP"= 27996:TCP:PORT_27996
"24450:TCP"= 24450:TCP:PORT_24450
"39438:TCP"= 39438:TCP:PORT_39438
"41385:TCP"= 41385:TCP:PORT_41385
"24777:TCP"= 24777:TCP:PORT_24777
"19953:TCP"= 19953:TCP:PORT_19953
"51107:TCP"= 51107:TCP:PORT_51107
"54790:TCP"= 54790:TCP:PORT_54790
"18649:TCP"= 18649:TCP:PORT_18649
"31365:TCP"= 31365:TCP:PORT_31365
"5235:TCP"= 5235:TCP:PORT_5235
"58578:TCP"= 58578:TCP:PORT_58578
"56953:TCP"= 56953:TCP:PORT_56953
"9340:TCP"= 9340:TCP:PORT_9340
"7501:TCP"= 7501:TCP:PORT_7501
"24281:TCP"= 24281:TCP:PORT_24281
"60680:TCP"= 60680:TCP:PORT_60680
"54504:TCP"= 54504:TCP:PORT_54504
"39138:TCP"= 39138:TCP:PORT_39138
"65348:TCP"= 65348:TCP:PORT_65348
"51113:TCP"= 51113:TCP:PORT_51113
"24750:TCP"= 24750:TCP:PORT_24750
"62250:TCP"= 62250:TCP:PORT_62250
"17278:TCP"= 17278:TCP:PORT_17278
"40008:TCP"= 40008:TCP:PORT_40008
"40973:TCP"= 40973:TCP:PORT_40973
"18200:TCP"= 18200:TCP:PORT_18200
"6780:TCP"= 6780:TCP:PORT_6780
"12087:TCP"= 12087:TCP:PORT_12087
"57668:TCP"= 57668:TCP:PORT_57668
"23911:TCP"= 23911:TCP:PORT_23911
"56021:TCP"= 56021:TCP:PORT_56021
"53508:TCP"= 53508:TCP:PORT_53508
"26419:TCP"= 26419:TCP:PORT_26419
"8657:TCP"= 8657:TCP:PORT_8657
"51130:TCP"= 51130:TCP:PORT_51130
"39543:TCP"= 39543:TCP:PORT_39543
"58258:TCP"= 58258:TCP:PORT_58258
"33821:TCP"= 33821:TCP:PORT_33821
"13016:TCP"= 13016:TCP:PORT_13016
"15220:TCP"= 15220:TCP:PORT_15220
"61029:TCP"= 61029:TCP:PORT_61029
"56777:TCP"= 56777:TCP:PORT_56777
"12547:TCP"= 12547:TCP:PORT_12547
"10551:TCP"= 10551:TCP:PORT_10551
"50410:TCP"= 50410:TCP:PORT_50410
"24183:TCP"= 24183:TCP:PORT_24183
"23059:TCP"= 23059:TCP:PORT_23059
"6231:TCP"= 6231:TCP:PORT_6231
"37913:TCP"= 37913:TCP:PORT_37913
"27103:TCP"= 27103:TCP:PORT_27103
"15705:TCP"= 15705:TCP:PORT_15705
"48488:TCP"= 48488:TCP:PORT_48488
"64020:TCP"= 64020:TCP:PORT_64020
"17525:TCP"= 17525:TCP:PORT_17525
"18160:TCP"= 18160:TCP:PORT_18160
"30348:TCP"= 30348:TCP:PORT_30348
"7681:TCP"= 7681:TCP:PORT_7681
"17715:TCP"= 17715:TCP:PORT_17715
"12450:TCP"= 12450:TCP:PORT_12450
"51665:TCP"= 51665:TCP:PORT_51665
"29860:TCP"= 29860:TCP:PORT_29860
"62379:TCP"= 62379:TCP:PORT_62379
"46423:TCP"= 46423:TCP:PORT_46423
"59270:TCP"= 59270:TCP:PORT_59270
"18011:TCP"= 18011:TCP:PORT_18011
"38036:TCP"= 38036:TCP:PORT_38036
"29465:TCP"= 29465:TCP:PORT_29465
"56668:TCP"= 56668:TCP:PORT_56668
"48637:TCP"= 48637:TCP:PORT_48637
"26774:TCP"= 26774:TCP:PORT_26774
"65313:TCP"= 65313:TCP:PORT_65313
"47676:TCP"= 47676:TCP:PORT_47676
"60869:TCP"= 60869:TCP:PORT_60869
"27541:TCP"= 27541:TCP:PORT_27541
"43246:TCP"= 43246:TCP:PORT_43246
"49602:TCP"= 49602:TCP:PORT_49602
"11111:TCP"= 11111:TCP:PORT_11111
"13332:TCP"= 13332:TCP:PORT_13332
"30969:TCP"= 30969:TCP:PORT_30969
"40688:TCP"= 40688:TCP:PORT_40688
"19782:TCP"= 19782:TCP:PORT_19782
"14746:TCP"= 14746:TCP:PORT_14746
"51340:TCP"= 51340:TCP:PORT_51340
"38040:TCP"= 38040:TCP:PORT_38040
"35993:TCP"= 35993:TCP:PORT_35993
"53022:TCP"= 53022:TCP:PORT_53022
"44746:TCP"= 44746:TCP:PORT_44746
"17615:TCP"= 17615:TCP:PORT_17615
"40047:TCP"= 40047:TCP:PORT_40047
"18892:TCP"= 18892:TCP:PORT_18892
"57531:TCP"= 57531:TCP:PORT_57531
"16348:TCP"= 16348:TCP:PORT_16348
"40118:TCP"= 40118:TCP:PORT_40118
"59926:TCP"= 59926:TCP:PORT_59926
"51016:TCP"= 51016:TCP:PORT_51016
"53323:TCP"= 53323:TCP:PORT_53323
"45871:TCP"= 45871:TCP:PORT_45871
"62238:TCP"= 62238:TCP:PORT_62238
"50475:TCP"= 50475:TCP:PORT_50475
"20118:TCP"= 20118:TCP:PORT_20118
"49762:TCP"= 49762:TCP:PORT_49762
"31181:TCP"= 31181:TCP:PORT_31181
"51126:TCP"= 51126:TCP:PORT_51126
"11460:TCP"= 11460:TCP:PORT_11460
"46540:TCP"= 46540:TCP:PORT_46540
"23543:TCP"= 23543:TCP:PORT_23543
"23348:TCP"= 23348:TCP:PORT_23348
"34325:TCP"= 34325:TCP:PORT_34325
"55715:TCP"= 55715:TCP:PORT_55715
"23050:TCP"= 23050:TCP:PORT_23050
"33216:TCP"= 33216:TCP:PORT_33216
"12966:TCP"= 12966:TCP:PORT_12966
"7746:TCP"= 7746:TCP:PORT_7746
"25828:TCP"= 25828:TCP:PORT_25828
"34305:TCP"= 34305:TCP:PORT_34305
"56471:TCP"= 56471:TCP:PORT_56471
"41301:TCP"= 41301:TCP:PORT_41301
"6774:TCP"= 6774:TCP:PORT_6774
"44770:TCP"= 44770:TCP:PORT_44770
"53931:TCP"= 53931:TCP:PORT_53931
"51418:TCP"= 51418:TCP:PORT_51418
"6934:TCP"= 6934:TCP:PORT_6934
"59185:TCP"= 59185:TCP:PORT_59185
"40840:TCP"= 40840:TCP:PORT_40840
"16051:TCP"= 16051:TCP:PORT_16051
"12246:TCP"= 12246:TCP:PORT_12246
"9090:TCP"= 9090:TCP:PORT_9090
"48684:TCP"= 48684:TCP:PORT_48684
"39637:TCP"= 39637:TCP:PORT_39637
"22420:TCP"= 22420:TCP:PORT_22420
"31535:TCP"= 31535:TCP:PORT_31535
"48216:TCP"= 48216:TCP:PORT_48216
"11650:TCP"= 11650:TCP:PORT_11650
"53900:TCP"= 53900:TCP:PORT_53900
"31793:TCP"= 31793:TCP:PORT_31793
"51306:TCP"= 51306:TCP:PORT_51306
"9922:TCP"= 9922:TCP:PORT_9922
"36668:TCP"= 36668:TCP:PORT_36668
"10782:TCP"= 10782:TCP:PORT_10782
"42966:TCP"= 42966:TCP:PORT_42966
"52387:TCP"= 52387:TCP:PORT_52387
"24209:TCP"= 24209:TCP:PORT_24209
"32965:TCP"= 32965:TCP:PORT_32965
"30934:TCP"= 30934:TCP:PORT_30934
"60036:TCP"= 60036:TCP:PORT_60036
"62256:TCP"= 62256:TCP:PORT_62256
"50885:TCP"= 50885:TCP:PORT_50885
"44559:TCP"= 44559:TCP:PORT_44559
"32250:TCP"= 32250:TCP:PORT_32250
"22208:TCP"= 22208:TCP:PORT_22208
"51517:TCP"= 51517:TCP:PORT_51517
"17110:TCP"= 17110:TCP:PORT_17110
"59605:TCP"= 59605:TCP:PORT_59605
"49890:TCP"= 49890:TCP:PORT_49890
"26364:TCP"= 26364:TCP:PORT_26364
"48752:TCP"= 48752:TCP:PORT_48752
"19798:TCP"= 19798:TCP:PORT_19798
"51938:TCP"= 51938:TCP:PORT_51938
"46180:TCP"= 46180:TCP:PORT_46180
"39184:TCP"= 39184:TCP:PORT_39184
"53793:TCP"= 53793:TCP:PORT_53793
"16625:TCP"= 16625:TCP:PORT_16625
"26212:TCP"= 26212:TCP:PORT_26212
"52489:TCP"= 52489:TCP:PORT_52489
"58204:TCP"= 58204:TCP:PORT_58204
"42801:TCP"= 42801:TCP:PORT_42801
"36816:TCP"= 36816:TCP:PORT_36816
"42093:TCP"= 42093:TCP:PORT_42093
"52198:TCP"= 52198:TCP:PORT_52198
"51983:TCP"= 51983:TCP:PORT_51983
"15496:TCP"= 15496:TCP:PORT_15496
"50485:TCP"= 50485:TCP:PORT_50485
"39328:TCP"= 39328:TCP:PORT_39328
"39922:TCP"= 39922:TCP:PORT_39922
"51750:TCP"= 51750:TCP:PORT_51750
"44071:TCP"= 44071:TCP:PORT_44071
"41614:TCP"= 41614:TCP:PORT_41614
"40793:TCP"= 40793:TCP:PORT_40793
"63223:TCP"= 63223:TCP:PORT_63223
"45401:TCP"= 45401:TCP:PORT_45401
"17555:TCP"= 17555:TCP:PORT_17555
"9771:TCP"= 9771:TCP:PORT_9771
"11353:TCP"= 11353:TCP:PORT_11353
"18566:TCP"= 18566:TCP:PORT_18566
"21363:TCP"= 21363:TCP:PORT_21363
"6200:TCP"= 6200:TCP:PORT_6200
"15368:TCP"= 15368:TCP:PORT_15368
"49951:TCP"= 49951:TCP:PORT_49951
"22547:TCP"= 22547:TCP:PORT_22547
"62142:TCP"= 62142:TCP:PORT_62142
"61156:TCP"= 61156:TCP:PORT_61156
"31098:TCP"= 31098:TCP:PORT_31098
"16770:TCP"= 16770:TCP:PORT_16770
"23916:TCP"= 23916:TCP:PORT_23916
"13865:TCP"= 13865:TCP:PORT_13865
"14766:TCP"= 14766:TCP:PORT_14766
"14205:TCP"= 14205:TCP:PORT_14205
"24768:TCP"= 24768:TCP:PORT_24768
"34719:TCP"= 34719:TCP:PORT_34719
"16063:TCP"= 16063:TCP:PORT_16063
"56223:TCP"= 56223:TCP:PORT_56223
"33516:TCP"= 33516:TCP:PORT_33516
"63997:TCP"= 63997:TCP:PORT_63997
"33582:TCP"= 33582:TCP:PORT_33582
"55208:TCP"= 55208:TCP:PORT_55208
"11798:TCP"= 11798:TCP:PORT_11798
"34012:TCP"= 34012:TCP:PORT_34012
"9223:TCP"= 9223:TCP:PORT_9223
"28620:TCP"= 28620:TCP:PORT_28620
"24754:TCP"= 24754:TCP:PORT_24754
"15113:TCP"= 15113:TCP:PORT_15113
"43004:TCP"= 43004:TCP:PORT_43004
"48500:TCP"= 48500:TCP:PORT_48500
"54681:TCP"= 54681:TCP:PORT_54681
"31103:TCP"= 31103:TCP:PORT_31103
"43141:TCP"= 43141:TCP:PORT_43141
"7410:TCP"= 7410:TCP:PORT_7410
"27661:TCP"= 27661:TCP:PORT_27661
"56395:TCP"= 56395:TCP:PORT_56395
"65024:TCP"= 65024:TCP:PORT_65024
"51721:TCP"= 51721:TCP:PORT_51721
"33402:TCP"= 33402:TCP:PORT_33402
"44021:TCP"= 44021:TCP:PORT_44021
"32922:TCP"= 32922:TCP:PORT_32922
"30473:TCP"= 30473:TCP:PORT_30473
"15072:TCP"= 15072:TCP:PORT_15072
"26200:TCP"= 26200:TCP:PORT_26200
"50985:TCP"= 50985:TCP:PORT_50985
"38653:TCP"= 38653:TCP:PORT_38653
"45469:TCP"= 45469:TCP:PORT_45469
"31380:TCP"= 31380:TCP:PORT_31380
"33790:TCP"= 33790:TCP:PORT_33790
"30328:TCP"= 30328:TCP:PORT_30328
"38906:TCP"= 38906:TCP:PORT_38906
"64113:TCP"= 64113:TCP:PORT_64113
"7450:TCP"= 7450:TCP:PORT_7450
"34379:TCP"= 34379:TCP:PORT_34379
"5121:TCP"= 5121:TCP:PORT_5121
"10915:TCP"= 10915:TCP:PORT_10915
"17750:TCP"= 17750:TCP:PORT_17750
"36053:TCP"= 36053:TCP:PORT_36053
"29184:TCP"= 29184:TCP:PORT_29184
"31468:TCP"= 31468:TCP:PORT_31468
"40094:TCP"= 40094:TCP:PORT_40094
"19415:TCP"= 19415:TCP:PORT_19415
"5149:TCP"= 5149:TCP:PORT_5149
"41418:TCP"= 41418:TCP:PORT_41418
"46110:TCP"= 46110:TCP:PORT_46110
"14157:TCP"= 14157:TCP:PORT_14157
"49205:TCP"= 49205:TCP:PORT_49205
"37121:TCP"= 37121:TCP:PORT_37121
"31665:TCP"= 31665:TCP:PORT_31665
"12172:TCP"= 12172:TCP:PORT_12172
"16317:TCP"= 16317:TCP:PORT_16317
"58322:TCP"= 58322:TCP:PORT_58322
"47576:TCP"= 47576:TCP:PORT_47576
"30063:TCP"= 30063:TCP:PORT_30063
"22231:TCP"= 22231:TCP:PORT_22231
"24735:TCP"= 24735:TCP:PORT_24735
"26071:TCP"= 26071:TCP:PORT_26071
"32715:TCP"= 32715:TCP:PORT_32715
"11926:TCP"= 11926:TCP:PORT_11926
"10762:TCP"= 10762:TCP:PORT_10762
"36231:TCP"= 36231:TCP:PORT_36231
"34493:TCP"= 34493:TCP:PORT_34493
"40498:TCP"= 40498:TCP:PORT_40498
"31473:TCP"= 31473:TCP:PORT_31473
"51880:TCP"= 51880:TCP:PORT_51880
"55204:TCP"= 55204:TCP:PORT_55204
"31805:TCP"= 31805:TCP:PORT_31805
"38481:TCP"= 38481:TCP:PORT_38481
"55563:TCP"= 55563:TCP:PORT_55563
"51031:TCP"= 51031:TCP:PORT_51031
"59086:TCP"= 59086:TCP:PORT_59086
"19278:TCP"= 19278:TCP:PORT_19278
"45066:TCP"= 45066:TCP:PORT_45066
"7076:TCP"= 7076:TCP:PORT_7076
"23110:TCP"= 23110:TCP:PORT_23110
"59153:TCP"= 59153:TCP:PORT_59153
"39391:TCP"= 39391:TCP:PORT_39391
"10731:TCP"= 10731:TCP:PORT_10731
"24110:TCP"= 24110:TCP:PORT_24110
"48395:TCP"= 48395:TCP:PORT_48395
"46516:TCP"= 46516:TCP:PORT_46516
"37969:TCP"= 37969:TCP:PORT_37969
"45387:TCP"= 45387:TCP:PORT_45387
"19418:TCP"= 19418:TCP:PORT_19418
"32575:TCP"= 32575:TCP:PORT_32575
"58499:TCP"= 58499:TCP:PORT_58499
"53735:TCP"= 53735:TCP:PORT_53735
"28034:TCP"= 28034:TCP:PORT_28034
"10560:TCP"= 10560:TCP:PORT_10560
"28200:TCP"= 28200:TCP:PORT_28200
"42688:TCP"= 42688:TCP:PORT_42688
"49356:TCP"= 49356:TCP:PORT_49356
"26250:TCP"= 26250:TCP:PORT_26250
"37848:TCP"= 37848:TCP:PORT_37848
"62750:TCP"= 62750:TCP:PORT_62750
"55583:TCP"= 55583:TCP:PORT_55583
"39563:TCP"= 39563:TCP:PORT_39563
"48910:TCP"= 48910:TCP:PORT_48910
"18161:TCP"= 18161:TCP:PORT_18161
"54606:TCP"= 54606:TCP:PORT_54606
"52634:TCP"= 52634:TCP:PORT_52634
"42047:TCP"= 42047:TCP:PORT_42047
"24373:TCP"= 24373:TCP:PORT_24373
"49504:TCP"= 49504:TCP:PORT_49504
"47758:TCP"= 47758:TCP:PORT_47758
"7083:TCP"= 7083:TCP:PORT_7083
"53215:TCP"= 53215:TCP:PORT_53215
"30770:TCP"= 30770:TCP:PORT_30770
"29703:TCP"= 29703:TCP:PORT_29703
"33297:TCP"= 33297:TCP:PORT_33297
"35946:TCP"= 35946:TCP:PORT_35946
"5488:TCP"= 5488:TCP:PORT_5488
"41316:TCP"= 41316:TCP:PORT_41316
"20111:TCP"= 20111:TCP:PORT_20111
"43457:TCP"= 43457:TCP:PORT_43457
"16316:TCP"= 16316:TCP:PORT_16316
"58410:TCP"= 58410:TCP:PORT_58410
"13398:TCP"= 13398:TCP:PORT_13398
"40559:TCP"= 40559:TCP:PORT_40559
"23391:TCP"= 23391:TCP:PORT_23391
"47852:TCP"= 47852:TCP:PORT_47852
"29895:TCP"= 29895:TCP:PORT_29895
"32176:TCP"= 32176:TCP:PORT_32176
"21606:TCP"= 21606:TCP:PORT_21606
"9301:TCP"= 9301:TCP:PORT_9301
"6485:TCP"= 6485:TCP:PORT_6485
"29172:TCP"= 29172:TCP:PORT_29172
"49676:TCP"= 49676:TCP:PORT_49676
"26188:TCP"= 26188:TCP:PORT_26188
"15809:TCP"= 15809:TCP:PORT_15809
"54313:TCP"= 54313:TCP:PORT_54313
"29331:TCP"= 29331:TCP:PORT_29331
"39094:TCP"= 39094:TCP:PORT_39094
"58066:TCP"= 58066:TCP:PORT_58066
"36453:TCP"= 36453:TCP:PORT_36453
"53703:TCP"= 53703:TCP:PORT_53703
"61630:TCP"= 61630:TCP:PORT_61630
"5594:TCP"= 5594:TCP:PORT_5594
"49462:TCP"= 49462:TCP:PORT_49462
"26106:TCP"= 26106:TCP:PORT_26106
"45328:TCP"= 45328:TCP:PORT_45328
"65438:TCP"= 65438:TCP:PORT_65438
"22860:TCP"= 22860:TCP:PORT_22860
"22297:TCP"= 22297:TCP:PORT_22297
"55559:TCP"= 55559:TCP:PORT_55559
"28731:TCP"= 28731:TCP:PORT_28731
"62457:TCP"= 62457:TCP:PORT_62457
"11302:TCP"= 11302:TCP:PORT_11302
"24200:TCP"= 24200:TCP:PORT_24200
"38035:TCP"= 38035:TCP:PORT_38035
"44220:TCP"= 44220:TCP:PORT_44220
"6368:TCP"= 6368:TCP:PORT_6368
"60309:TCP"= 60309:TCP:PORT_60309
"14250:TCP"= 14250:TCP:PORT_14250
"31102:TCP"= 31102:TCP:PORT_31102
"41586:TCP"= 41586:TCP:PORT_41586
"61772:TCP"= 61772:TCP:PORT_61772
"12953:TCP"= 12953:TCP:PORT_12953
"64996:TCP"= 64996:TCP:PORT_64996
"41625:TCP"= 41625:TCP:PORT_41625
"9946:TCP"= 9946:TCP:PORT_9946
"36941:TCP"= 36941:TCP:PORT_36941
"29188:TCP"= 29188:TCP:PORT_29188
"42741:TCP"= 42741:TCP:PORT_42741
"30078:TCP"= 30078:TCP:PORT_30078
"45875:TCP"= 45875:TCP:PORT_45875
"21743:TCP"= 21743:TCP:PORT_21743
"50325:TCP"= 50325:TCP:PORT_50325
"13423:TCP"= 13423:TCP:PORT_13423
"8114:TCP"= 8114:TCP:PORT_8114
"20591:TCP"= 20591:TCP:PORT_20591
"52348:TCP"= 52348:TCP:PORT_52348
"55090:TCP"= 55090:TCP:PORT_55090
"25211:TCP"= 25211:TCP:PORT_25211
"32793:TCP"= 32793:TCP:PORT_32793
"19098:TCP"= 19098:TCP:PORT_19098
"17323:TCP"= 17323:TCP:PORT_17323
"35576:TCP"= 35576:TCP:PORT_35576
"59532:TCP"= 59532:TCP:PORT_59532
"32406:TCP"= 32406:TCP:PORT_32406
"5391:TCP"= 5391:TCP:PORT_5391
"18214:TCP"= 18214:TCP:PORT_18214
"58332:TCP"= 58332:TCP:PORT_58332
"48314:TCP"= 48314:TCP:PORT_48314
"18996:TCP"= 18996:TCP:PORT_18996
"19281:TCP"= 19281:TCP:PORT_19281
"15673:TCP"= 15673:TCP:PORT_15673
"64009:TCP"= 64009:TCP:PORT_64009
"30994:TCP"= 30994:TCP:PORT_30994
"31235:TCP"= 31235:TCP:PORT_31235
"44896:TCP"= 44896:TCP:PORT_44896
"20354:TCP"= 20354:TCP:PORT_20354
.
R1 MpKsl0ac15fd0;MpKsl0ac15fd0;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EBB0C9A-2A9C-4D0F-AAC8-94938ED58E20}\MpKsl0ac15fd0.sys [4/2/2011 11:05 PM 28752]
R1 MpKslabf5d65c;MpKslabf5d65c;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EBB0C9A-2A9C-4D0F-AAC8-94938ED58E20}\MpKslabf5d65c.sys [4/2/2011 9:40 AM 28752]
R3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link PCI Express Ethernet Controller;c:\windows\system32\drivers\m4cxw2k3.sys [2/15/2007 8:04 AM 250752]
R3 StixKB;Stix Virtual Keybord Driver;c:\windows\system32\drivers\StixKB.sys [6/3/2008 12:00 PM 6656]
S1 MpKsl0f011679;MpKsl0f011679;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042F6761-E609-4A27-9ADF-7C2403AC7BF2}\MpKsl0f011679.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042F6761-E609-4A27-9ADF-7C2403AC7BF2}\MpKsl0f011679.sys [?]
S1 MpKsl11680c02;MpKsl11680c02;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl11680c02.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl11680c02.sys [?]
S1 MpKsl13f0b068;MpKsl13f0b068;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6C8D5826-B445-4F66-A091-C349F89F676E}\MpKsl13f0b068.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6C8D5826-B445-4F66-A091-C349F89F676E}\MpKsl13f0b068.sys [?]
S1 MpKsl14574ba7;MpKsl14574ba7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl14574ba7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl14574ba7.sys [?]
S1 MpKsl14d8e27c;MpKsl14d8e27c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsl14d8e27c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsl14d8e27c.sys [?]
S1 MpKsl204cb44c;MpKsl204cb44c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl204cb44c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl204cb44c.sys [?]
S1 MpKsl218cac29;MpKsl218cac29;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2E9234F2-65BD-44F5-8219-389D4366BEBB}\MpKsl218cac29.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2E9234F2-65BD-44F5-8219-389D4366BEBB}\MpKsl218cac29.sys [?]
S1 MpKsl22c94aa4;MpKsl22c94aa4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7220C1CE-8E02-487D-8702-06161D9A5BFF}\MpKsl22c94aa4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7220C1CE-8E02-487D-8702-06161D9A5BFF}\MpKsl22c94aa4.sys [?]
S1 MpKsl306fd987;MpKsl306fd987;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl306fd987.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl306fd987.sys [?]
S1 MpKsl39f08552;MpKsl39f08552;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl39f08552.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl39f08552.sys [?]
S1 MpKsl3dafc59f;MpKsl3dafc59f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl3dafc59f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl3dafc59f.sys [?]
S1 MpKsl3eefa506;MpKsl3eefa506;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D109E1F7-1787-4DDE-9D93-35A7F1F34F47}\MpKsl3eefa506.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D109E1F7-1787-4DDE-9D93-35A7F1F34F47}\MpKsl3eefa506.sys [?]
S1 MpKsl58bc9ea6;MpKsl58bc9ea6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsl58bc9ea6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsl58bc9ea6.sys [?]
S1 MpKsl5fa55f68;MpKsl5fa55f68;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1CACE630-FDE2-4D02-BA71-7BDD8D65A8C2}\MpKsl5fa55f68.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1CACE630-FDE2-4D02-BA71-7BDD8D65A8C2}\MpKsl5fa55f68.sys [?]
S1 MpKsl64138ae0;MpKsl64138ae0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0013CCDD-0AA0-4D8C-B9DE-C3576051964C}\MpKsl64138ae0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0013CCDD-0AA0-4D8C-B9DE-C3576051964C}\MpKsl64138ae0.sys [?]
S1 MpKsl6866e241;MpKsl6866e241;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{79685C0F-ACDE-4402-8FFC-05C48AF1C23B}\MpKsl6866e241.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{79685C0F-ACDE-4402-8FFC-05C48AF1C23B}\MpKsl6866e241.sys [?]
S1 MpKsl6b25b0b4;MpKsl6b25b0b4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{58571905-B5CC-41CC-AA60-E74AA2C137E0}\MpKsl6b25b0b4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{58571905-B5CC-41CC-AA60-E74AA2C137E0}\MpKsl6b25b0b4.sys [?]
S1 MpKsl715c1e8c;MpKsl715c1e8c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl715c1e8c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl715c1e8c.sys [?]
S1 MpKsl74562173;MpKsl74562173;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC1E9BFF-4B05-4EFB-B1F1-44344CCD8CC8}\MpKsl74562173.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC1E9BFF-4B05-4EFB-B1F1-44344CCD8CC8}\MpKsl74562173.sys [?]
S1 MpKsl75ec66f4;MpKsl75ec66f4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl75ec66f4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl75ec66f4.sys [?]
S1 MpKsl7c45c504;MpKsl7c45c504;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl7c45c504.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl7c45c504.sys [?]
S1 MpKsl8b7f16c1;MpKsl8b7f16c1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl8b7f16c1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl8b7f16c1.sys [?]
S1 MpKsl8e1ace65;MpKsl8e1ace65;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKsl8e1ace65.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKsl8e1ace65.sys [?]
S1 MpKsl9a287dce;MpKsl9a287dce;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl9a287dce.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl9a287dce.sys [?]
S1 MpKslb8b10199;MpKslb8b10199;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKslb8b10199.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKslb8b10199.sys [?]
S1 MpKslbdf64b93;MpKslbdf64b93;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E6CDD660-6947-4801-84EF-DFC5ED217D5D}\MpKslbdf64b93.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E6CDD660-6947-4801-84EF-DFC5ED217D5D}\MpKslbdf64b93.sys [?]
S1 MpKslc7c26fd6;MpKslc7c26fd6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKslc7c26fd6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKslc7c26fd6.sys [?]
S1 MpKsld35d3203;MpKsld35d3203;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsld35d3203.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsld35d3203.sys [?]
S1 MpKsld57954f1;MpKsld57954f1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsld57954f1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsld57954f1.sys [?]
S1 MpKsld7effc74;MpKsld7effc74;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{79606413-0CE5-4713-A22B-45C9A82D88BC}\MpKsld7effc74.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{79606413-0CE5-4713-A22B-45C9A82D88BC}\MpKsld7effc74.sys [?]
S1 MpKsld869e660;MpKsld869e660;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2142D778-1398-47A6-B424-BA576EEA2DB5}\MpKsld869e660.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2142D778-1398-47A6-B424-BA576EEA2DB5}\MpKsld869e660.sys [?]
S1 MpKsle59653d0;MpKsle59653d0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC1E9BFF-4B05-4EFB-B1F1-44344CCD8CC8}\MpKsle59653d0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC1E9BFF-4B05-4EFB-B1F1-44344CCD8CC8}\MpKsle59653d0.sys [?]
S1 MpKsle7038b28;MpKsle7038b28;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsle7038b28.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsle7038b28.sys [?]
S1 MpKsle9c5ff7b;MpKsle9c5ff7b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsle9c5ff7b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsle9c5ff7b.sys [?]
S1 MpKslf24dcb46;MpKslf24dcb46;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKslf24dcb46.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKslf24dcb46.sys [?]
S1 MpKslf59b2af0;MpKslf59b2af0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKslf59b2af0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKslf59b2af0.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL0AC15FD0
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2008-07-09 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-03 00:12]
.
2008-07-09 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-03 00:12]
.
2008-07-09 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-03 00:12]
.
2011-04-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 17:26]
.
2008-07-16 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-01-03 01:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.facebook.com/home.php?ref=hp
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = iexplore
IE: &AOL; Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.walmartphotocentre.ca/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\u4qtwskk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=867034&p;=
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe
HKCU-Run-RegistryMechanic - c:\program files\Registry Mechanic\RegMech.exe
HKLM-Run-SGPUpdater - c:\program files\Search Guard PlusU\sgpUpdaters.exe
HKLM-Run-FBSearch - c:\program files\Search Guard Plus\SearchGuardPlus.exe
HKLM-Run-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
AddRemove-Registry Mechanic_is1 - c:\program files\Registry Mechanic\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-02 23:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-04-03 00:01:31
ComboFix-quarantined-files.txt 2011-04-03 04:01
.
Pre-Run: 91,687,981,056 bytes free
Post-Run: 95,178,203,136 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 10DDAEBFDA4837014C185424F10FFE48
Hello lamaroo

Thank you for the log.

  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      Firefox::
      FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\u4qtwskk.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}

      Registry::
      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "22483:TCP"=-
      "41852:TCP"=-
      "55664:TCP"=-
      "22071:TCP"=-
      "55000:TCP"=-
      "16470:TCP"=-
      "25610:TCP"=-
      "24131:TCP"=-
      "8531:TCP"=-
      "45461:TCP"=-
      "20820:TCP"=-
      "38102:TCP"=-
      "46949:TCP"=-
      "62164:TCP"=-
      "45445:TCP"=-
      "12914:TCP"=-
      "46195:TCP"=-
      "36680:TCP"=-
      "19476:TCP"=-
      "7793:TCP"=-
      "11571:TCP"=-
      "14617:TCP"=-
      "49368:TCP"=-
      "23430:TCP"=-
      "34000:TCP"=-
      "53360:TCP"=-
      "27785:TCP"=-
      "22201:TCP"=-
      "44629:TCP"=-
      "55872:TCP"=-
      "20406:TCP"=-
      "27738:TCP"=-
      "10707:TCP"=-
      "9521:TCP"=-
      "25025:TCP"=-
      "32231:TCP"=-
      "64906:TCP"=-
      "49726:TCP"=-
      "12887:TCP"=-
      "50990:TCP"=-
      "8438:TCP"=-
      "38434:TCP"=-
      "41438:TCP"=-
      "50473:TCP"=-
      "6915:TCP"=-
      "42695:TCP"=-
      "36766:TCP"=-
      "49520:TCP"=-
      "44201:TCP"=-
      "7955:TCP"=-
      "10723:TCP"=-
      "8864:TCP"=-
      "36653:TCP"=-
      "59211:TCP"=-
      "63935:TCP"=-
      "56551:TCP"=-
      "43528:TCP"=-
      "5552:TCP"=-
      "23122:TCP"=-
      "48895:TCP"=-
      "30226:TCP"=-
      "17598:TCP"=-
      "62423:TCP"=-
      "18060:TCP"=-
      "12963:TCP"=-
      "20278:TCP"=-
      "40495:TCP"=-
      "62781:TCP"=-
      "53411:TCP"=-
      "57540:TCP"=-
      "7540:TCP"=-
      "38958:TCP"=-
      "35594:TCP"=-
      "14438:TCP"=-
      "23469:TCP"=-
      "27665:TCP"=-
      "38204:TCP"=-
      "31493:TCP"=-
      "34805:TCP"=-
      "34518:TCP"=-
      "5676:TCP"=-
      "56988:TCP"=-
      "42658:TCP"=-
      "14986:TCP"=-
      "48153:TCP"=-
      "19876:TCP"=-
      "32205:TCP"=-
      "23353:TCP"=-
      "20551:TCP"=-
      "23067:TCP"=-
      "56906:TCP"=-
      "27999:TCP"=-
      "48560:TCP"=-
      "23020:TCP"=-
      "30985:TCP"=-
      "23705:TCP"=-
      "17518:TCP"=-
      "14910:TCP"=-
      "57680:TCP"=-
      "9950:TCP"=-
      "26871:TCP"=-
      "18269:TCP"=-
      "25148:TCP"=-
      "60391:TCP"=-
      "52916:TCP"=-
      "61248:TCP"=-
      "26708:TCP"=-
      "51696:TCP"=-
      "44434:TCP"=-
      "28332:TCP"=-
      "18425:TCP"=-
      "29477:TCP"=-
      "38933:TCP"=-
      "35270:TCP"=-
      "26060:TCP"=-
      "44633:TCP"=-
      "35363:TCP"=-
      "64520:TCP"=-
      "51748:TCP"=-
      "38137:TCP"=-
      "5087:TCP"=-
      "35231:TCP"=-
      "55633:TCP"=-
      "50793:TCP"=-
      "58060:TCP"=-
      "50270:TCP"=-
      "62400:TCP"=-
      "17203:TCP"=-
      "41775:TCP"=-
      "14563:TCP"=-
      "38873:TCP"=-
      "27196:TCP"=-
      "40110:TCP"=-
      "57481:TCP"=-
      "21703:TCP"=-
      "40000:TCP"=-
      "17223:TCP"=-
      "48536:TCP"=-
      "15571:TCP"=-
      "57476:TCP"=-
      "22981:TCP"=-
      "52853:TCP"=-
      "36703:TCP"=-
      "61801:TCP"=-
      "20613:TCP"=-
      "65395:TCP"=-
      "11910:TCP"=-
      "49650:TCP"=-
      "45454:TCP"=-
      "23537:TCP"=-
      "22164:TCP"=-
      "39985:TCP"=-
      "48789:TCP"=-
      "31892:TCP"=-
      "16981:TCP"=-
      "59868:TCP"=-
      "40993:TCP"=-
      "46954:TCP"=-
      "16293:TCP"=-
      "38094:TCP"=-
      "11500:TCP"=-
      "43536:TCP"=-
      "39923:TCP"=-
      "36528:TCP"=-
      "7190:TCP"=-
      "61008:TCP"=-
      "15621:TCP"=-
      "37306:TCP"=-
      "47043:TCP"=-
      "12931:TCP"=-
      "33876:TCP"=-
      "61243:TCP"=-
      "62548:TCP"=-
      "22856:TCP"=-
      "52290:TCP"=-
      "61459:TCP"=-
      "25481:TCP"=-
      "44313:TCP"=-
      "19965:TCP"=-
      "27358:TCP"=-
      "40691:TCP"=-
      "44363:TCP"=-
      "30496:TCP"=-
      "39116:TCP"=-
      "54571:TCP"=-
      "39560:TCP"=-
      "6700:TCP"=-
      "61446:TCP"=-
      "11583:TCP"=-
      "12469:TCP"=-
      "23584:TCP"=-
      "5311:TCP"=-
      "52563:TCP"=-
      "5816:TCP"=-
      "22094:TCP"=-
      "27411:TCP"=-
      "56840:TCP"=-
      "27969:TCP"=-
      "53758:TCP"=-
      "60586:TCP"=-
      "29983:TCP"=-
      "64840:TCP"=-
      "46297:TCP"=-
      "17788:TCP"=-
      "37012:TCP"=-
      "48731:TCP"=-
      "18927:TCP"=-
      "51457:TCP"=-
      "43344:TCP"=-
      "46828:TCP"=-
      "21049:TCP"=-
      "20740:TCP"=-
      "39301:TCP"=-
      "43543:TCP"=-
      "8006:TCP"=-
      "40395:TCP"=-
      "31325:TCP"=-
      "43595:TCP"=-
      "28707:TCP"=-
      "54981:TCP"=-
      "55145:TCP"=-
      "35903:TCP"=-
      "57551:TCP"=-
      "8165:TCP"=-
      "55028:TCP"=-
      "49508:TCP"=-
      "5618:TCP"=-
      "49547:TCP"=-
      "62188:TCP"=-
      "28625:TCP"=-
      "61582:TCP"=-
      "39153:TCP"=-
      "59599:TCP"=-
      "38034:TCP"=-
      "27762:TCP"=-
      "18879:TCP"=-
      "58711:TCP"=-
      "26662:TCP"=-
      "41555:TCP"=-
      "44215:TCP"=-
      "7051:TCP"=-
      "34885:TCP"=-
      "52876:TCP"=-
      "57856:TCP"=-
      "57422:TCP"=-
      "27189:TCP"=-
      "44661:TCP"=-
      "49254:TCP"=-
      "10157:TCP"=-
      "56157:TCP"=-
      "36207:TCP"=-
      "16475:TCP"=-
      "50415:TCP"=-
      "44488:TCP"=-
      "14000:TCP"=-
      "25094:TCP"=-
      "54535:TCP"=-
      "11317:TCP"=-
      "50448:TCP"=-
      "11829:TCP"=-
      "25698:TCP"=-
      "55887:TCP"=-
      "27298:TCP"=-
      "63445:TCP"=-
      "11526:TCP"=-
      "52076:TCP"=-
      "27996:TCP"=-
      "24450:TCP"=-
      "39438:TCP"=-
      "41385:TCP"=-
      "24777:TCP"=-
      "19953:TCP"=-
      "51107:TCP"=-
      "54790:TCP"=-
      "18649:TCP"=-
      "31365:TCP"=-
      "5235:TCP"=-
      "58578:TCP"=-
      "56953:TCP"=-
      "9340:TCP"=-
      "7501:TCP"=-
      "24281:TCP"=-
      "60680:TCP"=-
      "54504:TCP"=-
      "39138:TCP"=-
      "65348:TCP"=-
      "51113:TCP"=-
      "24750:TCP"=-
      "62250:TCP"=-
      "17278:TCP"=-
      "40008:TCP"=-
      "40973:TCP"=-
      "18200:TCP"=-
      "6780:TCP"=-
      "12087:TCP"=-
      "57668:TCP"=-
      "23911:TCP"=-
      "56021:TCP"=-
      "53508:TCP"=-
      "26419:TCP"=-
      "8657:TCP"=-
      "51130:TCP"=-
      "39543:TCP"=-
      "58258:TCP"=-
      "33821:TCP"=-
      "13016:TCP"=-
      "15220:TCP"=-
      "61029:TCP"=-
      "56777:TCP"=-
      "12547:TCP"=-
      "10551:TCP"=-
      "50410:TCP"=-
      "24183:TCP"=-
      "23059:TCP"=-
      "6231:TCP"=-
      "37913:TCP"=-
      "27103:TCP"=-
      "15705:TCP"=-
      "48488:TCP"=-
      "64020:TCP"=-
      "17525:TCP"=-
      "18160:TCP"=-
      "30348:TCP"=-
      "7681:TCP"=-
      "17715:TCP"=-
      "12450:TCP"=-
      "51665:TCP"=-
      "29860:TCP"=-
      "62379:TCP"=-
      "46423:TCP"=-
      "59270:TCP"=-
      "18011:TCP"=-
      "38036:TCP"=-
      "29465:TCP"=-
      "56668:TCP"=-
      "48637:TCP"=-
      "26774:TCP"=-
      "65313:TCP"=-
      "47676:TCP"=-
      "60869:TCP"=-
      "27541:TCP"=-
      "43246:TCP"=-
      "49602:TCP"=-
      "11111:TCP"=-
      "13332:TCP"=-
      "30969:TCP"=-
      "40688:TCP"=-
      "19782:TCP"=-
      "14746:TCP"=-
      "51340:TCP"=-
      "38040:TCP"=-
      "35993:TCP"=-
      "53022:TCP"=-
      "44746:TCP"=-
      "17615:TCP"=-
      "40047:TCP"=-
      "18892:TCP"=-
      "57531:TCP"=-
      "16348:TCP"=-
      "40118:TCP"=-
      "59926:TCP"=-
      "51016:TCP"=-
      "53323:TCP"=-
      "45871:TCP"=-
      "62238:TCP"=-
      "50475:TCP"=-
      "20118:TCP"=-
      "49762:TCP"=-
      "31181:TCP"=-
      "51126:TCP"=-
      "11460:TCP"=-
      "46540:TCP"=-
      "23543:TCP"=-
      "23348:TCP"=-
      "34325:TCP"=-
      "55715:TCP"=-
      "23050:TCP"=-
      "33216:TCP"=-
      "12966:TCP"=-
      "7746:TCP"=-
      "25828:TCP"=-
      "34305:TCP"=-
      "56471:TCP"=-
      "41301:TCP"=-
      "6774:TCP"=-
      "44770:TCP"=-
      "53931:TCP"=-
      "51418:TCP"=-
      "6934:TCP"=-
      "59185:TCP"=-
      "40840:TCP"=-
      "16051:TCP"=-
      "12246:TCP"=-
      "9090:TCP"=-
      "48684:TCP"=-
      "39637:TCP"=-
      "22420:TCP"=-
      "31535:TCP"=-
      "48216:TCP"=-
      "11650:TCP"=-
      "53900:TCP"=-
      "31793:TCP"=-
      "51306:TCP"=-
      "9922:TCP"=-
      "36668:TCP"=-
      "10782:TCP"=-
      "42966:TCP"=-
      "52387:TCP"=-
      "24209:TCP"=-
      "32965:TCP"=-
      "30934:TCP"=-
      "60036:TCP"=-
      "62256:TCP"=-
      "50885:TCP"=-
      "44559:TCP"=-
      "32250:TCP"=-
      "22208:TCP"=-
      "51517:TCP"=-
      "17110:TCP"=-
      "59605:TCP"=-
      "49890:TCP"=-
      "26364:TCP"=-
      "48752:TCP"=-
      "19798:TCP"=-
      "51938:TCP"=-
      "46180:TCP"=-
      "39184:TCP"=-
      "53793:TCP"=-
      "16625:TCP"=-
      "26212:TCP"=-
      "52489:TCP"=-
      "58204:TCP"=-
      "42801:TCP"=-
      "36816:TCP"=-
      "42093:TCP"=-
      "52198:TCP"=-
      "51983:TCP"=-
      "15496:TCP"=-
      "50485:TCP"=-
      "39328:TCP"=-
      "39922:TCP"=-
      "51750:TCP"=-
      "44071:TCP"=-
      "41614:TCP"=-
      "40793:TCP"=-
      "63223:TCP"=-
      "45401:TCP"=-
      "17555:TCP"=-
      "9771:TCP"=-
      "11353:TCP"=-
      "18566:TCP"=-
      "21363:TCP"=-
      "6200:TCP"=-
      "15368:TCP"=-
      "49951:TCP"=-
      "22547:TCP"=-
      "61156:TCP"=-
      "31098:TCP"=-
      "16770:TCP"=-
      "23916:TCP"=-
      "13865:TCP"=-
      "14766:TCP"=-
      "14205:TCP"=-
      "24768:TCP"=-
      "34719:TCP"=-
      "16063:TCP"=-
      "56223:TCP"=-
      "33516:TCP"=-
      "63997:TCP"=-
      "33582:TCP"=-
      "55208:TCP"=-
      "11798:TCP"=-
      "34012:TCP"=-
      "9223:TCP"=-
      "28620:TCP"=-
      "24754:TCP"=-
      "15113:TCP"=-
      "43004:TCP"=-
      "48500:TCP"=-
      "54681:TCP"=-
      "31103:TCP"=-
      "43141:TCP"=-
      "7410:TCP"=-
      "27661:TCP"=-
      "56395:TCP"=-
      "65024:TCP"=-
      "51721:TCP"=-
      "33402:TCP"=-
      "44021:TCP"=-
      "32922:TCP"=-
      "30473:TCP"=-
      "15072:TCP"=-
      "26200:TCP"=-
      "50985:TCP"=-
      "38653:TCP"=-
      "45469:TCP"=-
      "31380:TCP"=-
      "33790:TCP"=-
      "30328:TCP"=-
      "38906:TCP"=-
      "64113:TCP"=-
      "7450:TCP"=-
      "34379:TCP"=-
      "5121:TCP"=-
      "10915:TCP"=-
      "17750:TCP"=-
      "36053:TCP"=-
      "29184:TCP"=-
      "31468:TCP"=-
      "40094:TCP"=-
      "19415:TCP"=-
      "5149:TCP"=-
      "41418:TCP"=-
      "46110:TCP"=-
      "14157:TCP"=-
      "49205:TCP"=-
      "37121:TCP"=-
      "31665:TCP"=-
      "12172:TCP"=-
      "16317:TCP"=-
      "58322:TCP"=-
      "47576:TCP"=-
      "30063:TCP"=-
      "22231:TCP"=-
      "24735:TCP"=-
      "26071:TCP"=-
      "32715:TCP"=-
      "11926:TCP"=-
      "10762:TCP"=-
      "36231:TCP"=-
      "34493:TCP"=-
      "40498:TCP"=-
      "31473:TCP"=-
      "51880:TCP"=-
      "55204:TCP"=-
      "31805:TCP"=-
      "38481:TCP"=-
      "55563:TCP"=-
      "51031:TCP"=-
      "59086:TCP"=-
      "19278:TCP"=-
      "45066:TCP"=-
      "7076:TCP"=-
      "23110:TCP"=-
      "59153:TCP"=-
      "39391:TCP"=-
      "10731:TCP"=-
      "24110:TCP"=-
      "48395:TCP"=-
      "46516:TCP"=-
      "37969:TCP"=-
      "45387:TCP"=-
      "19418:TCP"=-
      "32575:TCP"=-
      "58499:TCP"=-
      "53735:TCP"=-
      "28034:TCP"=-
      "10560:TCP"=-
      "28200:TCP"=-
      "42688:TCP"=-
      "49356:TCP"=-
      "26250:TCP"=-
      "37848:TCP"=-
      "62750:TCP"=-
      "55583:TCP"=-
      "39563:TCP"=-
      "48910:TCP"=-
      "18161:TCP"=-
      "54606:TCP"=-
      "52634:TCP"=-
      "42047:TCP"=-
      "24373:TCP"=-
      "49504:TCP"=-
      "47758:TCP"=-
      "7083:TCP"=-
      "53215:TCP"=-
      "30770:TCP"=-
      "29703:TCP"=-
      "33297:TCP"=-
      "35946:TCP"=-
      "5488:TCP"=-
      "41316:TCP"=-
      "20111:TCP"=-
      "43457:TCP"=-
      "16316:TCP"=-
      "58410:TCP"=-
      "13398:TCP"=-
      "40559:TCP"=-
      "23391:TCP"=-
      "47852:TCP"=-
      "29895:TCP"=-
      "32176:TCP"=-
      "21606:TCP"=-
      "9301:TCP"=-
      "6485:TCP"=-
      "29172:TCP"=-
      "49676:TCP"=-
      "26188:TCP"=-
      "15809:TCP"=-
      "54313:TCP"=-
      "29331:TCP"=-
      "39094:TCP"=-
      "58066:TCP"=-
      "36453:TCP"=-
      "53703:TCP"=-
      "61630:TCP"=-
      "5594:TCP"=-
      "49462:TCP"=-
      "26106:TCP"=-
      "45328:TCP"=-
      "65438:TCP"=-
      "22860:TCP"=-
      "22297:TCP"=-
      "55559:TCP"=-
      "28731:TCP"=-
      "62457:TCP"=-
      "11302:TCP"=-
      "24200:TCP"=-
      "38035:TCP"=-
      "44220:TCP"=-
      "6368:TCP"=-
      "60309:TCP"=-
      "14250:TCP"=-
      "31102:TCP"=-
      "41586:TCP"=-
      "61772:TCP"=-
      "12953:TCP"=-
      "64996:TCP"=-
      "41625:TCP"=-
      "9946:TCP"=-
      "36941:TCP"=-
      "29188:TCP"=-
      "42741:TCP"=-
      "30078:TCP"=-
      "45875:TCP"=-
      "21743:TCP"=-
      "50325:TCP"=-
      "13423:TCP"=-
      "8114:TCP"=-
      "20591:TCP"=-
      "52348:TCP"=-
      "55090:TCP"=-
      "25211:TCP"=-
      "32793:TCP"=-
      "19098:TCP"=-
      "17323:TCP"=-
      "35576:TCP"=-
      "59532:TCP"=-
      "32406:TCP"=-
      "5391:TCP"=-
      "18214:TCP"=-
      "58332:TCP"=-
      "48314:TCP"=-
      "18996:TCP"=-
      "19281:TCP"=-
      "15673:TCP"=-
      "64009:TCP"=-
      "30994:TCP"=-
      "31235:TCP"=-
      "44896:TCP"=-
      "20354:TCP"=-

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.

  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

    Please post the ComboFix log and the MBAM log in your next reply.
Combofix updated while scanning this time but finished. If the formatting in this post is messed up i can upload the Combofix.txt if you'd like.

ComboFix 11-04-02.05 - Owner 04/03/2011 11:39:40.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.200 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_WMPNetworkSvc
.
.
((((((((((((((((((((((((( Files Created from 2011-03-03 to 2011-04-03 )))))))))))))))))))))))))))))))
.
.
2011-04-03 04:02 . 2011-03-15 04:05 6792528 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{50844ECA-A8C9-4F60-8579-D897C4894A5D}\mpengine.dll
2011-03-16 02:54 . 2011-04-03 02:21 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Conduit
2011-03-16 02:54 . 2011-03-16 02:54 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2011-03-06 22:32 . 2011-03-06 22:32 1409 —-a-w- c:\windows\QTFont.for
2011-03-06 15:58 . 2011-03-06 15:58 ——– d—–w- c:\documents and settings\Owner\Application Data\Intuit Canada
2011-03-06 15:58 . 2011-03-06 15:58 ——– d—–w- c:\program files\Common Files\Intuit
2011-03-06 15:57 . 2011-03-08 21:21 ——– d—–w- c:\program files\TurboTax 2010
2011-03-06 15:57 . 2011-03-06 15:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Intuit Canada
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-15 04:05 . 2010-08-20 03:47 6792528 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-09 13:53 . 2003-01-03 11:41 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2003-01-03 11:41 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2003-01-03 12:53 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2003-01-03 12:53 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2003-01-03 11:41 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-13 09:41 . 2011-01-27 21:54 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-01-07 14:09 . 2003-01-03 11:41 290048 —-a-w- c:\windows\system32\atmfd.dll
2011-01-05 16:47 . 2011-01-05 16:47 1712201 —-a-w- c:\windows\system32\InetClnt.dll
2011-03-18 17:53 . 2011-04-03 02:54 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-04-23 801904]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-12 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-03-03 46080]
"nForce Tray Options"="sstray.exe" [2003-09-03 73728]
"CHotkey"="zHotkey.exe" [2004-05-18 543232]
"ShowWnd"="ShowWnd.exe" [2003-09-19 36864]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-03-11 135168]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 50688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-01-03 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Zac Browser English\\zacbrowser.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\GoLive2\\Golive2 Sphere\\StixTM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"62142:TCP"= 62142:TCP:PORT_62142
.
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [1/8/2010 1:51 AM 380928]
R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [8/27/2009 6:09 PM 1253376]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [7/8/2010 7:39 PM 632792]
R3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link PCI Express Ethernet Controller;c:\windows\system32\drivers\m4cxw2k3.sys [2/15/2007 8:04 AM 250752]
R3 StixKB;Stix Virtual Keybord Driver;c:\windows\system32\drivers\StixKB.sys [6/3/2008 12:00 PM 6656]
S1 MpKsl0f011679;MpKsl0f011679;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042F6761-E609-4A27-9ADF-7C2403AC7BF2}\MpKsl0f011679.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042F6761-E609-4A27-9ADF-7C2403AC7BF2}\MpKsl0f011679.sys [?]
S1 MpKsl11680c02;MpKsl11680c02;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl11680c02.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl11680c02.sys [?]
S1 MpKsl13f0b068;MpKsl13f0b068;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6C8D5826-B445-4F66-A091-C349F89F676E}\MpKsl13f0b068.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6C8D5826-B445-4F66-A091-C349F89F676E}\MpKsl13f0b068.sys [?]
S1 MpKsl14574ba7;MpKsl14574ba7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl14574ba7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl14574ba7.sys [?]
S1 MpKsl14d8e27c;MpKsl14d8e27c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsl14d8e27c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsl14d8e27c.sys [?]
S1 MpKsl204cb44c;MpKsl204cb44c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl204cb44c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl204cb44c.sys [?]
S1 MpKsl218cac29;MpKsl218cac29;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2E9234F2-65BD-44F5-8219-389D4366BEBB}\MpKsl218cac29.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2E9234F2-65BD-44F5-8219-389D4366BEBB}\MpKsl218cac29.sys [?]
S1 MpKsl22c94aa4;MpKsl22c94aa4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7220C1CE-8E02-487D-8702-06161D9A5BFF}\MpKsl22c94aa4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7220C1CE-8E02-487D-8702-06161D9A5BFF}\MpKsl22c94aa4.sys [?]
S1 MpKsl306fd987;MpKsl306fd987;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl306fd987.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl306fd987.sys [?]
S1 MpKsl39f08552;MpKsl39f08552;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl39f08552.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl39f08552.sys [?]
S1 MpKsl3dafc59f;MpKsl3dafc59f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl3dafc59f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsl3dafc59f.sys [?]
S1 MpKsl3eefa506;MpKsl3eefa506;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D109E1F7-1787-4DDE-9D93-35A7F1F34F47}\MpKsl3eefa506.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D109E1F7-1787-4DDE-9D93-35A7F1F34F47}\MpKsl3eefa506.sys [?]
S1 MpKsl58bc9ea6;MpKsl58bc9ea6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsl58bc9ea6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsl58bc9ea6.sys [?]
S1 MpKsl5fa55f68;MpKsl5fa55f68;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1CACE630-FDE2-4D02-BA71-7BDD8D65A8C2}\MpKsl5fa55f68.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1CACE630-FDE2-4D02-BA71-7BDD8D65A8C2}\MpKsl5fa55f68.sys [?]
S1 MpKsl64138ae0;MpKsl64138ae0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0013CCDD-0AA0-4D8C-B9DE-C3576051964C}\MpKsl64138ae0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0013CCDD-0AA0-4D8C-B9DE-C3576051964C}\MpKsl64138ae0.sys [?]
S1 MpKsl6866e241;MpKsl6866e241;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{79685C0F-ACDE-4402-8FFC-05C48AF1C23B}\MpKsl6866e241.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{79685C0F-ACDE-4402-8FFC-05C48AF1C23B}\MpKsl6866e241.sys [?]
S1 MpKsl6b25b0b4;MpKsl6b25b0b4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{58571905-B5CC-41CC-AA60-E74AA2C137E0}\MpKsl6b25b0b4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{58571905-B5CC-41CC-AA60-E74AA2C137E0}\MpKsl6b25b0b4.sys [?]
S1 MpKsl715c1e8c;MpKsl715c1e8c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl715c1e8c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl715c1e8c.sys [?]
S1 MpKsl74562173;MpKsl74562173;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC1E9BFF-4B05-4EFB-B1F1-44344CCD8CC8}\MpKsl74562173.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC1E9BFF-4B05-4EFB-B1F1-44344CCD8CC8}\MpKsl74562173.sys [?]
S1 MpKsl75ec66f4;MpKsl75ec66f4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl75ec66f4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl75ec66f4.sys [?]
S1 MpKsl7c45c504;MpKsl7c45c504;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl7c45c504.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsl7c45c504.sys [?]
S1 MpKsl8b7f16c1;MpKsl8b7f16c1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl8b7f16c1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl8b7f16c1.sys [?]
S1 MpKsl8e1ace65;MpKsl8e1ace65;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKsl8e1ace65.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKsl8e1ace65.sys [?]
S1 MpKsl9a287dce;MpKsl9a287dce;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl9a287dce.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsl9a287dce.sys [?]
S1 MpKsl9a3d125f;MpKsl9a3d125f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{50844ECA-A8C9-4F60-8579-D897C4894A5D}\MpKsl9a3d125f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{50844ECA-A8C9-4F60-8579-D897C4894A5D}\MpKsl9a3d125f.sys [?]
S1 MpKslb8b10199;MpKslb8b10199;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKslb8b10199.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKslb8b10199.sys [?]
S1 MpKslbdf64b93;MpKslbdf64b93;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E6CDD660-6947-4801-84EF-DFC5ED217D5D}\MpKslbdf64b93.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E6CDD660-6947-4801-84EF-DFC5ED217D5D}\MpKslbdf64b93.sys [?]
S1 MpKslc7c26fd6;MpKslc7c26fd6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKslc7c26fd6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKslc7c26fd6.sys [?]
S1 MpKsld35d3203;MpKsld35d3203;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsld35d3203.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E00E63FA-5D65-474D-86A3-B7A9C651D1D0}\MpKsld35d3203.sys [?]
S1 MpKsld57954f1;MpKsld57954f1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsld57954f1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKsld57954f1.sys [?]
S1 MpKsld7effc74;MpKsld7effc74;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{79606413-0CE5-4713-A22B-45C9A82D88BC}\MpKsld7effc74.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{79606413-0CE5-4713-A22B-45C9A82D88BC}\MpKsld7effc74.sys [?]
S1 MpKsld869e660;MpKsld869e660;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2142D778-1398-47A6-B424-BA576EEA2DB5}\MpKsld869e660.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2142D778-1398-47A6-B424-BA576EEA2DB5}\MpKsld869e660.sys [?]
S1 MpKsle59653d0;MpKsle59653d0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC1E9BFF-4B05-4EFB-B1F1-44344CCD8CC8}\MpKsle59653d0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC1E9BFF-4B05-4EFB-B1F1-44344CCD8CC8}\MpKsle59653d0.sys [?]
S1 MpKsle7038b28;MpKsle7038b28;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsle7038b28.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0A7D7B17-5DF4-40C8-A165-3E8E090B8BAA}\MpKsle7038b28.sys [?]
S1 MpKsle9c5ff7b;MpKsle9c5ff7b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsle9c5ff7b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E28AFF32-F435-4758-A35C-59605338B3A8}\MpKsle9c5ff7b.sys [?]
S1 MpKslf24dcb46;MpKslf24dcb46;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKslf24dcb46.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3741F107-5BA4-4204-97C5-9A1346F9B5A2}\MpKslf24dcb46.sys [?]
S1 MpKslf59b2af0;MpKslf59b2af0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKslf59b2af0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDD5BD99-5033-4D5A-A112-86E2E226538F}\MpKslf59b2af0.sys [?]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [8/7/2008 12:10 PM 3276800]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2008-07-09 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-03 00:12]
.
2008-07-09 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-03 00:12]
.
2008-07-09 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-03 00:12]
.
2011-04-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 17:26]
.
2008-07-16 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-01-03 01:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.facebook.com/home.php?ref=hp
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = iexplore
IE: &AOL; Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.walmartphotocentre.ca/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\u4qtwskk.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=867034&p;=
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-03 12:03
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3608)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\sstray.exe
c:\windows\zHotkey.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-04-03 12:17:15 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-03 16:17
ComboFix2.txt 2011-04-03 04:01
.
Pre-Run: 95,217,532,928 bytes free
Post-Run: 95,125,504,000 bytes free
.
- - End Of File - - 89E0625351E7B58F69CACA2849A16A87


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6258

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

4/3/2011 3:34:23 PM
mbam-log-2011-04-03 (15-34-23).txt

Scan type: Quick scan
Objects scanned: 145947
Time elapsed: 14 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\GamevanceText.DLL (Adware.GameVance) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\Owner\Desktop\hangman.exe (Adware.Iwon) -> Quarantined and deleted successfully.
Hello lamaroo

If the formatting in this post is messed up i can upload the Combofix.txt if you'd like

The formatting is fine :)

  • Please un-install Java 2 Runtime Environment, SE v1.4.2


    • Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • Click on "remove a program". A list of currently installed programs will be displayed.
    • Find the "Java 2 Runtime Environment, SE v1.4.2" program, click on it once and then click on the "uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Foistware


    • I can see from your log that you have Viewpoint Media Player installed.
    • Viewpoint Media Player is considered as foistware rather than malware since it is installed without user's approval but doesn't spy or do anything "bad".
    • It is recommended that you remove Viewpoint products. However, this choice is up to you.
    • To remove these programs, click "Start" and then on "Control Panel" and then on "Add or Remove Programs".
    • Select Viewpoint Media Player and click on "Remove".

  • Please run the following scan


    • Note: You will need to use Internet Explorer for this scan.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the ESET log in your next reply and let me know how the machine is running now.
I've deleted Java 2 Runtime Environment, but I'm not seeing an update tab in the Java Control Panel. I haven't run the scan yet.
Hello lamaroo

I'm not seeing an update tab in the Java Control Panel

Not a problem, we can update it manually:


  • Please update your Java


  • Click on "Start", then on "Control Panel".
  • Go to "Add or Remove Programs" and uninstall any previous versions of Java that you find.
  • Reboot your computer.
  • Next, download the latest version of Java by clicking here
  • Scroll down the page until you reach "Java Platform Standard Edition".
  • Beneath this and to the right, you will see a button marked "Download JRE".
  • Click the "Download JRE" button.
  • Select the platform (Windows, in your case), multi language.
  • Accept the license agreement and click on "Continue".
  • You do not have to register if you do not want to (the registration step is optional).
  • Scroll down and click on the file called jre-6u24-windows-i586.exe located under "Windows Offline Installation".
  • Save the file to your desktop.
  • Do not select Run.
  • Double click on the saved file (jre-6u24-windows-i586.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot your system if not prompted to do so.

Once Java is updated run the Online scan :)
C:\Documents and Settings\Owner\Desktop\PlatoVideoCreator.exe multiple threats C:\Program Files\Application Updater\ApplicationUpdater.exe probably a variant of Win32/Adware.Toolbar.Dealio application C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\pBh24512dLlKn24512\pBh24512dLlKn24512.exe.vir a variant of Win32/Kryptik.MDN trojan C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettings.dll.vir Win32/Adware.Toolbar.Dealio application C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettings.exe.vir Win32/Adware.Toolbar.Dealio application C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettingsRes409.dll.vir Win32/Adware.Toolbar.Dealio application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1072\A1255500.exe Win32/Adware.Toolbar.Dealio application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1072\A1255501.dll Win32/Adware.Toolbar.Dealio application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1072\A1255502.dll Win32/Adware.Toolbar.Dealio application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1072\A1255503.dll Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1078\A1258364.exe Win32/Adware.Toolbar.Dealio application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1078\A1258368.exe a variant of Win32/RegistryBooster application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1078\A1258423.exe a variant of Win32/Kryptik.MDN trojan C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1078\A1258427.dll Win32/Adware.Toolbar.Dealio application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1078\A1258428.exe Win32/Adware.Toolbar.Dealio application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1078\A1258429.dll Win32/Adware.Toolbar.Dealio application C:\System Volume Information\_restore{AB52BD40-7182-4E6D-A2D3-98415849E1A9}\RP1079\A1258681.exe Win32/Toolbar.MyWebSearch application Operating memory probably a variant of Win32/Adware.Toolbar.Dealio application
Hello lamaroo

Thank you for the log.

ESET has detected some infected restore points and some items already quarantined by ComboFix which we will deal with shortly. It also detected some infected files that we will deal with now:


  • Please download OTM


    • Please download OTM by OldTimer by clicking here.
    • Save the file (called OTM.exe) to your desktop.
    • Double click on the OTM.exe icon to run the program. (Note: If you are running on Vista/Windows 7, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :Processes 
    explorer.exe
    
    :Files
    C:\Documents and Settings\Owner\Desktop\PlatoVideoCreator.exe
    C:\Program Files\Application Updater\ApplicationUpdater.exe
    
    :Commands
    [Purity]
    [EmptyTemp]
    [Emptyflash]
    [Start Explorer]
    [Reboot]




    • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    • Click the Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTM.
    • Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File -> Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

  • Please flush your DNS Cache


    • To do this:
    • Click on "Start" and then on "Run"
    • Type cmd then press OK or hit Enter.
    • A command prompt will appear.
    • At the command prompt, type or copy/paste the following: ipconfig /flushdns (note the space between the “..g" and the "/f…” it needs to be there).
    • Hit Enter.
    • You will get a confirmation that the flush was successful.
    • Close the command box.

    Please post the OTM log in your next reply along with a new DDS scan and let me know how the machine is running now.
As far as how the machine is running now, it's hard to tell. The computer is getting old now, and sometimes it's running really well, and others it's slow, especially on start up. If I was going to guess I'd say it was probably running "back to normal" before the last virus hit.

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
C:\Documents and Settings\Owner\Desktop\PlatoVideoCreator.exe moved successfully.
C:\Program Files\Application Updater\ApplicationUpdater.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 10580 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 405 bytes

User: Owner
->Temp folder emptied: 214434 bytes
->Temporary Internet Files folder emptied: 6909516 bytes
->Java cache emptied: 124302463 bytes
->FireFox cache emptied: 86898092 bytes
->Flash cache emptied: 4382822 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 219321 bytes
%systemroot%\System32 .tmp files removed: 3590161 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1104189 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33701 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 217.00 mb


OTM by OldTimer - Version 3.1.17.2 log created on 04042011_083242

Files moved on Reboot…

Registry entries deleted on Reboot…


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 8:54:34.53 on Mon 04/04/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.116 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.facebook.com/home.php?ref=hp
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = iexplore
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Google; Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nForce Tray Options] sstray.exe /r
mRun: [CHotkey] zHotkey.exe
mRun: [ShowWnd] ShowWnd.exe
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: &AOL; Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.walmartphotocentre.ca/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: intu-tt2010 - {97A0575E-2309-4e75-8509-B1F9390C4DE7} - c:\program files\turbotax 2010\ic2010pp.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\u4qtwskk.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=867034&p;=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\owner\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 165264]
R1 MpKsl7c6c14dc;MpKsl7c6c14dc;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b6f704f6-0c10-4859-b878-2c78ede777ea}\MpKsl7c6c14dc.sys [2011-4-4 28752]
R1 MpKsle8b7c0f6;MpKsle8b7c0f6;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b6f704f6-0c10-4859-b878-2c78ede777ea}\MpKsle8b7c0f6.sys [2011-4-4 28752]
R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\common files\magix services\database\bin\FABS.exe [2009-8-27 1253376]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-7-27 54752]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2010-7-8 632792]
R3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link PCI Express Ethernet Controller;c:\windows\system32\drivers\m4cxw2k3.sys [2007-2-15 250752]
R3 StixKB;Stix Virtual Keybord Driver;c:\windows\system32\drivers\StixKB.sys [2008-6-3 6656]
S1 MpKsl0f011679;MpKsl0f011679;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{042f6761-e609-4a27-9adf-7c2403ac7bf2}\mpksl0f011679.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{042f6761-e609-4a27-9adf-7c2403ac7bf2}\MpKsl0f011679.sys [?]
S1 MpKsl11680c02;MpKsl11680c02;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e00e63fa-5d65-474d-86a3-b7a9c651d1d0}\mpksl11680c02.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e00e63fa-5d65-474d-86a3-b7a9c651d1d0}\MpKsl11680c02.sys [?]
S1 MpKsl13f0b068;MpKsl13f0b068;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6c8d5826-b445-4f66-a091-c349f89f676e}\mpksl13f0b068.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6c8d5826-b445-4f66-a091-c349f89f676e}\MpKsl13f0b068.sys [?]
S1 MpKsl14574ba7;MpKsl14574ba7;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\mpksl14574ba7.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\MpKsl14574ba7.sys [?]
S1 MpKsl14d8e27c;MpKsl14d8e27c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0a7d7b17-5df4-40c8-a165-3e8e090b8baa}\mpksl14d8e27c.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0a7d7b17-5df4-40c8-a165-3e8e090b8baa}\MpKsl14d8e27c.sys [?]
S1 MpKsl204cb44c;MpKsl204cb44c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\mpksl204cb44c.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\MpKsl204cb44c.sys [?]
S1 MpKsl218cac29;MpKsl218cac29;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2e9234f2-65bd-44f5-8219-389d4366bebb}\mpksl218cac29.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2e9234f2-65bd-44f5-8219-389d4366bebb}\MpKsl218cac29.sys [?]
S1 MpKsl22c94aa4;MpKsl22c94aa4;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7220c1ce-8e02-487d-8702-06161d9a5bff}\mpksl22c94aa4.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7220c1ce-8e02-487d-8702-06161d9a5bff}\MpKsl22c94aa4.sys [?]
S1 MpKsl306fd987;MpKsl306fd987;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e00e63fa-5d65-474d-86a3-b7a9c651d1d0}\mpksl306fd987.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e00e63fa-5d65-474d-86a3-b7a9c651d1d0}\MpKsl306fd987.sys [?]
S1 MpKsl39f08552;MpKsl39f08552;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\mpksl39f08552.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\MpKsl39f08552.sys [?]
S1 MpKsl3dafc59f;MpKsl3dafc59f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e00e63fa-5d65-474d-86a3-b7a9c651d1d0}\mpksl3dafc59f.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e00e63fa-5d65-474d-86a3-b7a9c651d1d0}\MpKsl3dafc59f.sys [?]
S1 MpKsl3eefa506;MpKsl3eefa506;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d109e1f7-1787-4dde-9d93-35a7f1f34f47}\mpksl3eefa506.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d109e1f7-1787-4dde-9d93-35a7f1f34f47}\MpKsl3eefa506.sys [?]
S1 MpKsl58bc9ea6;MpKsl58bc9ea6;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0a7d7b17-5df4-40c8-a165-3e8e090b8baa}\mpksl58bc9ea6.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0a7d7b17-5df4-40c8-a165-3e8e090b8baa}\MpKsl58bc9ea6.sys [?]
S1 MpKsl5fa55f68;MpKsl5fa55f68;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1cace630-fde2-4d02-ba71-7bdd8d65a8c2}\mpksl5fa55f68.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1cace630-fde2-4d02-ba71-7bdd8d65a8c2}\MpKsl5fa55f68.sys [?]
S1 MpKsl64138ae0;MpKsl64138ae0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0013ccdd-0aa0-4d8c-b9de-c3576051964c}\mpksl64138ae0.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0013ccdd-0aa0-4d8c-b9de-c3576051964c}\MpKsl64138ae0.sys [?]
S1 MpKsl6866e241;MpKsl6866e241;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{79685c0f-acde-4402-8ffc-05c48af1c23b}\mpksl6866e241.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{79685c0f-acde-4402-8ffc-05c48af1c23b}\MpKsl6866e241.sys [?]
S1 MpKsl6b25b0b4;MpKsl6b25b0b4;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{58571905-b5cc-41cc-aa60-e74aa2c137e0}\mpksl6b25b0b4.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{58571905-b5cc-41cc-aa60-e74aa2c137e0}\MpKsl6b25b0b4.sys [?]
S1 MpKsl715c1e8c;MpKsl715c1e8c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\mpksl715c1e8c.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\MpKsl715c1e8c.sys [?]
S1 MpKsl74562173;MpKsl74562173;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dc1e9bff-4b05-4efb-b1f1-44344ccd8cc8}\mpksl74562173.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dc1e9bff-4b05-4efb-b1f1-44344ccd8cc8}\MpKsl74562173.sys [?]
S1 MpKsl75ec66f4;MpKsl75ec66f4;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\mpksl75ec66f4.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\MpKsl75ec66f4.sys [?]
S1 MpKsl7c45c504;MpKsl7c45c504;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\mpksl7c45c504.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\MpKsl7c45c504.sys [?]
S1 MpKsl8b7f16c1;MpKsl8b7f16c1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\mpksl8b7f16c1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\MpKsl8b7f16c1.sys [?]
S1 MpKsl8e1ace65;MpKsl8e1ace65;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdd5bd99-5033-4d5a-a112-86e2e226538f}\mpksl8e1ace65.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdd5bd99-5033-4d5a-a112-86e2e226538f}\MpKsl8e1ace65.sys [?]
S1 MpKsl9a287dce;MpKsl9a287dce;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\mpksl9a287dce.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\MpKsl9a287dce.sys [?]
S1 MpKsl9a3d125f;MpKsl9a3d125f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{50844eca-a8c9-4f60-8579-d897c4894a5d}\mpksl9a3d125f.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{50844eca-a8c9-4f60-8579-d897c4894a5d}\MpKsl9a3d125f.sys [?]
S1 MpKslb8b10199;MpKslb8b10199;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdd5bd99-5033-4d5a-a112-86e2e226538f}\mpkslb8b10199.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdd5bd99-5033-4d5a-a112-86e2e226538f}\MpKslb8b10199.sys [?]
S1 MpKslbdf64b93;MpKslbdf64b93;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e6cdd660-6947-4801-84ef-dfc5ed217d5d}\mpkslbdf64b93.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e6cdd660-6947-4801-84ef-dfc5ed217d5d}\MpKslbdf64b93.sys [?]
S1 MpKslc7c26fd6;MpKslc7c26fd6;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\mpkslc7c26fd6.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\MpKslc7c26fd6.sys [?]
S1 MpKsld35d3203;MpKsld35d3203;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e00e63fa-5d65-474d-86a3-b7a9c651d1d0}\mpksld35d3203.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e00e63fa-5d65-474d-86a3-b7a9c651d1d0}\MpKsld35d3203.sys [?]
S1 MpKsld57954f1;MpKsld57954f1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\mpksld57954f1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\MpKsld57954f1.sys [?]
S1 MpKsld7effc74;MpKsld7effc74;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{79606413-0ce5-4713-a22b-45c9a82d88bc}\mpksld7effc74.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{79606413-0ce5-4713-a22b-45c9a82d88bc}\MpKsld7effc74.sys [?]
S1 MpKsld869e660;MpKsld869e660;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2142d778-1398-47a6-b424-ba576eea2db5}\mpksld869e660.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2142d778-1398-47a6-b424-ba576eea2db5}\MpKsld869e660.sys [?]
S1 MpKsle59653d0;MpKsle59653d0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dc1e9bff-4b05-4efb-b1f1-44344ccd8cc8}\mpksle59653d0.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dc1e9bff-4b05-4efb-b1f1-44344ccd8cc8}\MpKsle59653d0.sys [?]
S1 MpKsle7038b28;MpKsle7038b28;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0a7d7b17-5df4-40c8-a165-3e8e090b8baa}\mpksle7038b28.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0a7d7b17-5df4-40c8-a165-3e8e090b8baa}\MpKsle7038b28.sys [?]
S1 MpKsle9c5ff7b;MpKsle9c5ff7b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\mpksle9c5ff7b.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e28aff32-f435-4758-a35c-59605338b3a8}\MpKsle9c5ff7b.sys [?]
S1 MpKslf24dcb46;MpKslf24dcb46;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\mpkslf24dcb46.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3741f107-5ba4-4204-97c5-9a1346f9b5a2}\MpKslf24dcb46.sys [?]
S1 MpKslf59b2af0;MpKslf59b2af0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdd5bd99-5033-4d5a-a112-86e2e226538f}\mpkslf59b2af0.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdd5bd99-5033-4d5a-a112-86e2e226538f}\MpKslf59b2af0.sys [?]
S2 Application Updater;Application Updater;"c:\program files\application updater\applicationupdater.exe" –> c:\program files\application updater\ApplicationUpdater.exe [?]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\common files\magix services\database\bin\fbserver.exe [2008-8-7 3276800]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
.
=============== Created Last 30 ================
.
2011-04-04 12:45:10 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{b6f704f6-0c10-4859-b878-2c78ede777ea}\MpKsle8b7c0f6.sys
2011-04-04 12:32:42 ——– d—–w- C:\_OTM
2011-04-04 12:18:40 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{b6f704f6-0c10-4859-b878-2c78ede777ea}\MpKsl7c6c14dc.sys
2011-04-04 12:16:14 6792528 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{b6f704f6-0c10-4859-b878-2c78ede777ea}\mpengine.dll
2011-04-04 00:45:11 ——– d—–w- c:\program files\ESET
2011-04-04 00:27:06 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-04-03 03:30:13 ——– d-sha-r- C:\cmdcons
2011-04-03 03:24:44 98816 —-a-w- c:\windows\sed.exe
2011-04-03 03:24:44 89088 —-a-w- c:\windows\MBR.exe
2011-04-03 03:24:44 256512 —-a-w- c:\windows\PEV.exe
2011-04-03 03:24:44 161792 —-a-w- c:\windows\SWREG.exe
2011-03-16 02:54:47 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\Conduit
2011-03-16 02:54:19 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\Temp
2011-03-06 22:32:46 1409 —-a-w- c:\windows\QTFont.for
2011-03-06 15:58:50 ——– d—–w- c:\docume~1\owner\applic~1\Intuit Canada
2011-03-06 15:58:12 ——– d—–w- c:\program files\common files\Intuit
2011-03-06 15:57:48 ——– d—–w- c:\program files\TurboTax 2010
2011-03-06 15:57:08 ——– d—–w- c:\docume~1\alluse~1\applic~1\Intuit Canada
.
==================== Find3M ====================
.
2011-04-04 00:25:17 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll
2011-01-05 16:47:18 1712201 —-a-w- c:\windows\system32\InetClnt.dll
.
============= FINISH: 8:56:33.64 ===============

Attachments:

Hello lamaroo

If I was going to guess I'd say it was probably running "back to normal" before the last virus hit

You logs appear to be clean.

Just out of curiosity, are you having any problems updating your Microsoft Security Essentials?

  • Please Uninstall Combofix


    • Click on "Start" and then on "Run".
    • Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.

  • Please perform the following cleanup procedure


    • Double click on the OTM.exe icon on your desktop to run the program.
    • Once OTM has opened, click on the "CleanUp!" button.
    • Follow any prompts that you receive.

  • Removal of Tools


    • You no longer need rkill. Please delete it from your machine.

  • Your Adobe Reader is out of date


    • You can obtain the latest version of Adobe Reader from here, and the latest version of Flash Player from here.
    • For more information and links to Adobe updates and downloads click here.

    it's slow, especially on start up

    The following may help:
  • Defragment your hard drive



  • StartupLight


    • You may wish to try StartupLite. Simply download this tool to your desktop and run it.
    • It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup.
    • This will result in fewer programs running when you boot your system, and should improve performance.
    • You can find it here: http://www.malwarebytes.org/startuplite.php

    If that does not work, you can try the steps mentioned in the link below:

    http://www.bleepingcomputer.com/forums/ind…st&p=487112

    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • Firefox is generally considered to have greater browsing security in comparison to other popular programs. You can download Firefox 4.0 from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.
    • Please Note: IE9 is not configured to run on XP machines.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.

Just out of curiosity, are you having any problems updating your Microsoft Security Essentials?


I haven't really noticed, it usually updates on it's own. I don't think there's been a problem.

I noticed in task manager that MsMpEng.exe is always running. I looked it up on google and found out it's Windows Defender, I also read that Microsoft Security Essentials disables WD, but it still appears. I'm not sure it would make a large difference to have it completely disabled, but if you think I should I will.

I want to thank you for all your help, even suggesting solutions to the general speed problem of the PC and slow start-up times. I was actually going to ask that after it was completely clean, but I wasn't sure if there was another sub-forum where I should be asking about that instead of the malware removal one.

Thank you JonTom!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI