This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

redirect and infection

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi ive just had an infection and hope you can help me !! it started as a redirect and a self opening page to msn support file extension page , multiple pages would open , and then i cleaned with msn sec. essentials, then sec. essentials has dissappeared from my quick start up bar and when i tried opening it from programmes it wouldnt !!!! i scanned using malware bytes and it said i had 17 infections so i cleaned those and it says it did 9 and now says im clean , but sec essentials is not opening up and is permanently closed. hope you can help phil c this is the last log from malware bytes Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6422 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 22/04/2011 22:11:13 mbam-log-2011-04-22 (22-11-13).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 289411 Time elapsed: 1 hour(s), 6 minute(s), 31 second(s) Memory Processes Infected: 1 Memory Modules Infected: 1 Registry Keys Infected: 2 Registry Values Infected: 4 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 9 Memory Processes Infected: c:\WINDOWS\Bhulya.exe (Trojan.Downloader) -> 272 -> Unloaded process successfully. Memory Modules Infected: c:\WINDOWS\dhecxvdf.dll (Trojan.Hiloti) -> Delete on reboot. Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Wmamerezuqahivaf (Trojan.Hiloti) -> Value: Wmamerezuqahivaf -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\2EOETFM3W2 (Trojan.Downloader) -> Value: 2EOETFM3W2 -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{85CFE573-5632-D799-E0B9-561C596D6994} (Trojan.ZbotR.Gen) -> Value: {85CFE573-5632-D799-E0B9-561C596D6994} -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{01EDAF18-06AD-3808-A0FC-65CE46FEDF51} (Trojan.ZbotR.Gen) -> Value: {01EDAF18-06AD-3808-A0FC-65CE46FEDF51} -> Delete on reboot. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\dhecxvdf.dll (Trojan.Hiloti) -> Delete on reboot. c:\WINDOWS\Bhulya.exe (Trojan.Downloader) -> Delete on reboot. c:\WINDOWS\Bhulyb.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\documents and settings\p compton\application data\microsoft\internet explorer\quick launch\launch whitesmoke.lnk (PUP.Whitesmoke) -> Quarantined and deleted successfully. c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully. c:\WINDOWS\Tasks\{35dc3473-a719-4d14-b7c1-fd326ca84a0c}.job (Trojan.Downloader) -> Quarantined and deleted successfully. c:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully. c:\documents and settings\p compton\application data\Uzheon\yvco.exe (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully. c:\documents and settings\p compton\application data\Adbo\qeaq.exe (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully.
Hi philcamera,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
===================================================
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

In your next post, please include the following:
  • OTL log
  • MBRcheck log
  • GMER log
Thank you noodletech,
here is the logs you require
OTL logfile created on: 23/04/2011 18:39:09 - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\P Compton\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 78.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 40.00 Gb Total Space | 8.74 Gb Free Space | 21.84% Space Free | Partition Type: NTFS
Drive D: | 146.31 Gb Total Space | 89.14 Gb Free Space | 60.92% Space Free | Partition Type: NTFS

Computer Name: EDITMACHINE | User Name: P Compton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\P Compton\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\hasplms.exe (SafeNet Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\P Compton\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SNMPTRAP) – File not found
SRV - (SNMP) – File not found
SRV - (NBService) – File not found
SRV - (HidServ) – File not found
SRV - (Fun4IM Coordinator) – File not found
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (hasplms) – C:\WINDOWS\System32\hasplms.exe (SafeNet Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (BlueSoleil Hid Service) – C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()
SRV - (AutoExNT) – C:\WINDOWS\system32\Autoexnt.exe ()


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NCHSSVAD) SoundTap Recorder (32 Bit) – C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)
DRV - (aksfridge) – C:\WINDOWS\system32\drivers\aksfridge.sys (Aladdin Knowledge Systems Ltd.)
DRV - (akshasp) – C:\WINDOWS\system32\drivers\akshasp.sys (Aladdin Knowledge Systems Ltd.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (SafeNet Inc.)
DRV - (aksusb) – C:\WINDOWS\system32\drivers\aksusb.sys (Aladdin Knowledge Systems Ltd.)
DRV - (akshhl) – C:\WINDOWS\system32\drivers\akshhl.sys (Aladdin Knowledge Systems Ltd.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (MSTAPE) – C:\WINDOWS\system32\drivers\mstape.sys (Microsoft Corporation)
DRV - (AVCSTRM) – C:\WINDOWS\system32\drivers\avcstrm.sys (Microsoft Corporation)
DRV - (cdrblock) – C:\WINDOWS\system32\drivers\cdrblock.sys (Canopus Co,. Ltd.)
DRV - (Haspnt) – C:\WINDOWS\system32\drivers\Haspnt.sys (Aladdin Knowledge Systems)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SiFilter) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc)
DRV - (SiRemFil) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc)
DRV - (SI3132) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc)
DRV - (n558) – C:\WINDOWS\system32\drivers\n558.sys ()
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (MotDev) – C:\WINDOWS\system32\drivers\motodrv.sys (Motorola Inc)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation)
DRV - (BlueletAudio) – C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\BtNetDrv.sys (IVT Corporation)
DRV - (Cam5603D) – C:\WINDOWS\system32\drivers\BisonCam.sys (Bison Electronics. Inc. )
DRV - (Ktp) – C:\WINDOWS\system32\drivers\Ktp.sys (ELANTECH Devices Corp.)
DRV - (w810obex) – C:\WINDOWS\system32\drivers\w810obex.sys (MCCI)
DRV - (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\w810mgmt.sys (MCCI)
DRV - (w810mdm) – C:\WINDOWS\system32\drivers\w810mdm.sys (MCCI)
DRV - (w810mdfl) – C:\WINDOWS\system32\drivers\w810mdfl.sys (MCCI)
DRV - (w810bus) Sony Ericsson W810 Driver driver (WDM) – C:\WINDOWS\system32\drivers\w810bus.sys (MCCI)
DRV - (BlueletSCOAudio) – C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation)
DRV - (BTHidEnum) – C:\WINDOWS\system32\drivers\vbtenum.sys ()
DRV - (BTHidMgr) – C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation)
DRV - (cdrport) – C:\WINDOWS\system32\drivers\cdrport.sys (Canopus Co,. Ltd.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation)
DRV - (PhilCam8116) Logitech QuickCam Pro 3000(PID_08B0) – C:\WINDOWS\system32\drivers\CamDrL21.sys (Philips Semiconductors)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://uk.yahoo.com"
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=ffds1&p="
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://uk.search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.16.0


[2009/04/25 13:12:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Extensions
[2009/01/19 14:07:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Extensions\[removed]
[2010/04/13 12:35:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Firefox\Profiles\jorb9q2r.default\extensions
[2010/04/13 12:35:55 | 000,000,000 | —D | M] (Vuze Remote Toolbar) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Firefox\Profiles\jorb9q2r.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
File not found (No name found) – C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX

O1 HOSTS File: ([2011/04/22 20:59:29 | 000,001,861 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.2.5 symantec.com
O1 - Hosts: 127.0.2.5 securityresponse.symantec.com
O1 - Hosts: 127.0.2.5 sarc.com
O1 - Hosts: 127.0.2.5 www.sarc.com
O1 - Hosts: 127.0.2.5 www.sophos.com
O1 - Hosts: 127.0.2.5 sophos.com
O1 - Hosts: 127.0.2.5 www.mcafee.com
O1 - Hosts: 127.0.2.5 mcafee.com
O1 - Hosts: 127.0.2.5 liveupdate.symantecliveupdate.com
O1 - Hosts: 127.0.2.5 www.viruslist.com
O1 - Hosts: 127.0.2.5 viruslist.com
O1 - Hosts: 127.0.2.5 f-secure.com
O1 - Hosts: 127.0.2.5 www.f-secure.com
O1 - Hosts: 127.0.2.5 f-prot.com
O1 - Hosts: 127.0.2.5 www.f-prot.com
O1 - Hosts: 127.0.2.5 kaspersky.com
O1 - Hosts: 127.0.2.5 kaspersky-labs.com
O1 - Hosts: 127.0.2.5 www.avp.com
O1 - Hosts: 127.0.2.5 avp.com
O1 - Hosts: 127.0.2.5 www.kaspersky.com
O1 - Hosts: 127.0.2.5 www.networkassociates.com
O1 - Hosts: 127.0.2.5 networkassociates.com
O1 - Hosts: 127.0.2.5 www.ca.com
O1 - Hosts: 127.0.2.5 ca.com
O1 - Hosts: 127.0.2.5 mast.mcafee.com
O1 - Hosts: 83 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngin0.dll (Conduit Ltd.)
O2 - BHO: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngin0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [KTPWare] C:\Program Files\Elantech\Ktp.exe (ELANTECH Devices Corp.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [D1T2EUR7FZ] File not found
O4 - Startup: C:\Documents and Settings\P Compton\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1263498871678 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} http://download.sopcast.com/download/SOPCORE.CAB (SopCore Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\P Compton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\P Compton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/20 16:39:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/05/01 22:08:11 | 000,000,000 | R–D | M] - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2009/05/01 22:08:11 | 000,000,000 | R–D | M] - D:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.CDV5 - C:\WINDOWS\System32\cdv5codc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CDVC - C:\WINDOWS\System32\cdvccodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CDVH - C:\WINDOWS\System32\cdvhcodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CLLC - C:\WINDOWS\System32\cllccodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CMIC - C:\WINDOWS\System32\cmiccodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CUVC - C:\WINDOWS\System32\cuvccodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.tscc - C:\WINDOWS\system32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55464181163360256)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/23 18:37:10 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2011/04/22 21:28:14 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\Boab
[2011/04/22 21:28:14 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\Adbo
[2011/04/22 13:45:03 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\MP3toiPodAudioBookConverter
[2011/04/22 13:44:04 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Start Menu\Programs\MP3 to iPod Audio Book Converter
[2011/04/22 13:43:52 | 000,000,000 | —D | C] – C:\Program Files\MP3ToIpodAudioBookConverter
[2011/04/21 14:36:58 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\My Documents\New Folder
[2011/04/21 11:32:06 | 000,000,000 | RH-D | C] – C:\Documents and Settings\P Compton\Recent
[2011/04/21 09:26:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/04/21 09:24:32 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/04/06 16:20:16 | 000,197,920 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\dnssdX.dll
[2011/04/06 16:20:16 | 000,107,808 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\dns-sd.exe
[2011/04/06 16:20:16 | 000,091,424 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\dnssd.dll
[2011/04/06 16:20:16 | 000,075,040 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\jdns_sd.dll

========== Files - Modified Within 30 Days ==========

[2011/04/23 18:42:00 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job
[2011/04/23 18:37:13 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2011/04/23 18:20:47 | 000,000,322 | -HS- | M] () – C:\WINDOWS\tasks\ixre.job
[2011/04/23 18:20:43 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/23 18:20:42 | 000,000,320 | -HS- | M] () – C:\WINDOWS\tasks\SPKEAPIR.job
[2011/04/23 18:20:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/22 23:45:00 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/22 20:59:29 | 000,001,861 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/22 20:21:05 | 000,106,496 | RHS- | M] () – C:\WINDOWS\System32\netfxperf0.dll
[2011/04/22 12:24:48 | 000,001,252 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/21 16:09:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/21 09:27:57 | 000,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/04/21 09:27:57 | 000,001,854 | —- | M] () – C:\Documents and Settings\P Compton\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/04/21 09:26:06 | 000,001,600 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/04/20 12:50:01 | 002,207,840 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/17 15:56:26 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/17 15:55:03 | 000,494,638 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/17 15:55:03 | 000,092,188 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/06 16:20:16 | 000,197,920 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\dnssdX.dll
[2011/04/06 16:20:16 | 000,107,808 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\dns-sd.exe
[2011/04/06 16:20:16 | 000,091,424 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\dnssd.dll
[2011/04/06 16:20:16 | 000,075,040 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\jdns_sd.dll

========== Files Created - No Company Name ==========

[2011/04/22 20:21:05 | 000,106,496 | RHS- | C] () – C:\WINDOWS\System32\netfxperf0.dll
[2011/04/22 20:21:05 | 000,000,322 | -HS- | C] () – C:\WINDOWS\tasks\ixre.job
[2011/04/22 20:21:05 | 000,000,320 | -HS- | C] () – C:\WINDOWS\tasks\SPKEAPIR.job
[2011/04/21 09:26:06 | 000,001,600 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/01 16:20:24 | 000,000,067 | —- | C] () – C:\WINDOWS\swf2avi.INI
[2010/05/29 18:59:40 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2010/05/29 18:59:40 | 000,000,039 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2010/05/19 10:08:13 | 000,000,132 | —- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\fusioncache.dat
[2010/05/19 09:55:29 | 002,515,656 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2010/05/19 09:55:29 | 000,136,650 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/04/10 18:21:31 | 000,034,064 | —- | C] () – C:\WINDOWS\System32\Instexnt.exe
[2010/04/10 18:21:31 | 000,005,904 | —- | C] () – C:\WINDOWS\System32\Autoexnt.exe
[2010/04/10 18:21:31 | 000,002,320 | —- | C] () – C:\WINDOWS\System32\Servmess.dll
[2010/04/09 02:09:00 | 000,017,182 | -HS- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\8O3lJ
[2010/04/09 02:09:00 | 000,017,182 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\8O3lJ
[2010/04/09 01:41:24 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/09 00:07:35 | 000,001,690 | -HS- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\1474v
[2010/04/09 00:07:35 | 000,001,690 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1474v
[2009/12/31 19:01:10 | 000,069,032 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/02 13:21:43 | 000,758,018 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/02 13:21:43 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/07/23 11:52:45 | 000,000,241 | —- | C] () – C:\WINDOWS\QSync.INI
[2009/07/23 11:51:06 | 000,000,544 | —- | C] () – C:\WINDOWS\_delis32.ini
[2009/07/23 11:50:51 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\MimicICM.dll
[2009/07/23 11:49:59 | 000,081,920 | R— | C] () – C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
[2009/07/23 11:38:15 | 000,005,187 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/04/25 13:12:33 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/24 23:34:25 | 001,122,304 | —- | C] () – C:\WINDOWS\System32\Boris TTK Renderer.dll
[2009/04/24 23:34:25 | 000,813,056 | —- | C] () – C:\WINDOWS\System32\Boris TTK Scene.dll
[2009/04/24 23:34:25 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\Boris TTK Utilities.dll
[2009/04/24 23:34:25 | 000,094,720 | —- | C] () – C:\WINDOWS\System32\Boris TTK Render Node.dll
[2009/04/24 23:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptTO6.0.ini
[2009/04/24 23:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptLD6.0.ini
[2009/04/24 23:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptET6.0.ini
[2009/04/24 23:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptES6.0.ini
[2009/04/24 23:34:17 | 018,619,392 | —- | C] () – C:\WINDOWS\System32\BCC6_AE_16Bit.dll
[2009/04/24 23:33:59 | 018,531,840 | —- | C] () – C:\WINDOWS\System32\BCC6_AE_8Bit.dll
[2009/04/24 23:22:18 | 000,000,000 | —- | C] () – C:\WINDOWS\BorisFX BCC6.ini
[2009/04/17 21:10:51 | 000,144,549 | —- | C] () – C:\WINDOWS\hpwins16.dat
[2009/03/29 22:07:56 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\Image2PDF.dat
[2008/09/06 00:30:42 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\WgaLogon.dll
[2008/09/06 00:29:58 | 000,012,800 | —- | C] () – C:\WINDOWS\System32\WgaTray.exe
[2008/07/21 17:14:10 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/06/21 20:01:02 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2008/05/26 22:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/16 10:11:23 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/14 13:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 13:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2008/04/14 13:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 13:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2008/04/14 13:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 13:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 13:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2008/04/14 13:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2008/04/14 13:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2008/04/14 13:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 13:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 13:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 13:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 13:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/01/23 12:53:38 | 000,237,568 | R— | C] () – C:\WINDOWS\System32\qtmlClient.dll
[2007/12/30 19:03:45 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/12/01 23:25:20 | 000,194,048 | —- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/01 18:17:13 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/30 18:39:17 | 000,000,383 | —- | C] () – C:\WINDOWS\System32\haspdos.sys
[2007/11/30 18:38:37 | 000,002,098 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/11/30 18:06:41 | 000,000,034 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/30 00:33:06 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/11/27 15:12:18 | 000,000,103 | —- | C] () – C:\WINDOWS\canopus.ini
[2007/11/21 12:42:51 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\pavedius4db.dll
[2007/11/21 12:42:51 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\pavedius.dll
[2007/11/21 12:16:29 | 000,040,960 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/11/21 12:07:21 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2007/11/21 12:05:52 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2007/11/21 12:05:52 | 000,294,912 | R— | C] () – C:\WINDOWS\Record.exe
[2007/11/21 12:05:52 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2007/11/21 11:41:36 | 000,015,190 | —- | C] () – C:\WINDOWS\M2000Twn.ini
[2007/11/20 16:42:10 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2007/11/20 16:36:54 | 000,023,392 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2007/11/20 16:28:35 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/11/20 16:27:15 | 002,207,840 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2007/10/25 04:03:45 | 000,011,216 | —- | C] () – C:\WINDOWS\hpwscr16.dat
[2007/10/25 04:00:40 | 000,001,162 | —- | C] () – C:\WINDOWS\hpwmdl16.dat
[2007/09/27 11:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/15 08:27:18 | 000,009,600 | —- | C] () – C:\WINDOWS\System32\drivers\n558.sys
[2007/07/27 13:00:00 | 000,494,638 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2007/07/27 13:00:00 | 000,092,188 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2007/07/27 13:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/04/14 10:14:12 | 000,014,312 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2005/08/12 22:57:09 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/07/30 08:21:32 | 000,011,988 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2011/01/04 13:39:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/02/03 22:59:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2007/11/30 00:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2009/08/04 20:25:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canopus
[2009/08/04 20:25:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2007/11/30 18:45:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grass Valley
[2009/10/06 09:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juicer3
[2010/11/15 15:09:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/04/08 19:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/10/06 13:05:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\proDAD
[2011/03/01 19:13:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/02/22 00:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/01/22 14:32:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/06/28 10:54:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/01/05 00:06:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/29 15:20:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/28 14:09:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/02/13 19:47:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2011/04/22 22:11:13 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Adbo
[2011/04/22 22:09:06 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Amqoi
[2011/01/04 13:39:19 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\AVG9
[2011/04/22 20:50:02 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Azureus
[2010/12/29 00:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Bandoo
[2011/04/22 21:39:14 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Boab
[2007/11/30 00:36:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Canopus
[2011/04/21 09:37:16 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Dropbox
[2011/03/01 20:12:41 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\FileZilla
[2011/03/01 16:57:06 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\GetRightToGo
[2007/12/23 16:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Grass Valley
[2009/01/21 23:38:28 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Inscriber
[2008/03/11 04:55:16 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Iqul
[2008/10/10 12:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\LimeWire
[2008/06/21 19:45:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Motorola
[2011/04/22 13:45:03 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\MP3toiPodAudioBookConverter
[2010/11/15 15:16:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\NCH Swift Sound
[2010/02/05 17:53:31 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Recordpad
[2010/03/22 20:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Red Kawa
[2010/12/30 20:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\searchqutb
[2008/06/21 19:48:00 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Teleca
[2009/01/19 14:07:24 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\TomTom
[2007/11/27 04:09:20 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Ufok
[2009/08/04 20:25:35 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Uniblue
[2011/04/22 22:11:13 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Uzheon
[2011/03/22 14:04:09 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\VSRevoGroup
[2008/11/06 12:17:45 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Windows Desktop Search
[2008/11/07 16:54:16 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Windows Search
[2011/01/04 13:50:39 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\WinPatrol
[2011/04/23 18:20:47 | 000,000,322 | -HS- | M] () – C:\WINDOWS\Tasks\ixre.job
[2011/04/23 18:20:42 | 000,000,320 | -HS- | M] () – C:\WINDOWS\Tasks\SPKEAPIR.job
[2011/04/23 18:42:00 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/05/30 09:43:08 | 000,141,258 | —- | M] () – C:\aaw7boot.log
[2010/10/12 16:41:28 | 000,115,075 | —- | M] () – C:\adorage-protocol.txt
[2007/11/20 16:39:48 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/19 16:42:48 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2007/11/20 16:39:48 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/20 16:39:48 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/07/23 11:50:02 | 000,000,183 | —- | M] () – C:\LogiSetup.log
[2009/04/17 11:08:58 | 000,000,200 | —- | M] () – C:\lxal.log
[2010/05/24 21:19:41 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2007/11/20 16:39:48 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 13:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/14 14:27:32 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/09/14 14:27:32 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2011/04/23 18:20:32 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2005/10/31 16:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/05/20 22:32:44 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/10/29 17:13:28 | 000,273,920 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp4xl.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/05/20 22:21:47 | 000,430,080 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/05/20 20:29:13 | 000,061,440 | —- | M] () – C:\WINDOWS\system32\config\security.sav
[2010/05/20 22:21:47 | 039,321,600 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/05/20 22:21:47 | 011,534,336 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/05/20 22:33:07 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/11/06 11:27:48 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\P Compton\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/11/20 16:49:13 | 000,000,079 | —- | M] () – C:\Documents and Settings\P Compton\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/01/04 12:13:20 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\P Compton\Desktop\ATF-Cleaner.exe
[2009/05/01 22:06:48 | 000,132,597 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\Flash_Disinfector.exe
[2011/04/23 18:37:13 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2005/11/23 15:53:40 | 000,070,656 | —- | M] (Canopus) – C:\Documents and Settings\P Compton\Desktop\speedcnt.exe
[2010/05/27 10:21:48 | 000,444,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\TFC.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2003/09/22 15:36:46 | 000,013,448 | —- | M] () – C:\WINDOWS\M2000Twn.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2008/11/06 11:27:48 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\P Compton\Favorites\Desktop.ini
[2011/04/22 13:32:01 | 000,000,425 | —- | M] () – C:\Documents and Settings\P Compton\Favorites\My Documents.lnk
[2011/04/22 13:32:01 | 000,000,639 | —- | M] () – C:\Documents and Settings\P Compton\Favorites\Start Menu.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/05/29 18:40:56 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\P Compton\Cookies\desktop.ini
[2011/04/23 18:42:37 | 000,081,920 | -HS- | M] () – C:\Documents and Settings\P Compton\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-21 08:17:09

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000040c

Kernel Drivers (total 150):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E5000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F79000 ACPI.sys
0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB9F68000 pci.sys
0xBA0A8000 isapnp.sys
0xBA0B8000 ohci1394.sys
0xBA0C8000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xBA4BC000 compbatt.sys
0xBA4C0000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xB9F4A000 pcmcia.sys
0xBA0D8000 MountMgr.sys
0xB9F2B000 ftdisk.sys
0xBA5AC000 dmload.sys
0xB9F05000 dmio.sys
0xBA4C4000 ACPIEC.sys
0xBA671000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
0xBA330000 PartMgr.sys
0xBA0E8000 VolSnap.sys
0xB9EED000 atapi.sys
0xB9ED6000 SI3132.sys
0xB9EBE000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xBA0F8000 disk.sys
0xBA108000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB9E9E000 fltmgr.sys
0xB9E8C000 sr.sys
0xBA4C8000 SiWinAcc.sys
0xB9E75000 KSecDD.sys
0xB9E62000 WudfPf.sys
0xB9DD5000 Ntfs.sys
0xB9DA8000 NDIS.sys
0xBA338000 SiRemFil.sys
0xBA118000 sbp2port.sys
0xB9D8E000 Mup.sys
0xBA340000 BTHidMgr.sys
0xB9286000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB9D6A000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0xB9047000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xB9033000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB900B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xB8EAE000 \SystemRoot\system32\DRIVERS\w39n51.sys
0xBA448000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB8E8A000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA450000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB8E5C000 \SystemRoot\system32\drivers\tifm21.sys
0xB8E48000 \SystemRoot\system32\DRIVERS\sdbus.sys
0xB8E2A000 \SystemRoot\system32\DRIVERS\Rtnicxp.sys
0xB9276000 \SystemRoot\system32\DRIVERS\serial.sys
0xB9D62000 \SystemRoot\system32\DRIVERS\serenum.sys
0xBA458000 \SystemRoot\system32\DRIVERS\nscirda.sys
0xB9D5E000 \SystemRoot\system32\DRIVERS\irenum.sys
0xB9266000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xBA460000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xB8DFA000 \SystemRoot\system32\DRIVERS\SynTP.sys
0xBA5E0000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xBA468000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xB9256000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA470000 \SystemRoot\system32\DRIVERS\cdrblock.sys
0xB9246000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xB9236000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB8DD7000 \SystemRoot\system32\DRIVERS\ks.sys
0xBA478000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xB9226000 \SystemRoot\System32\Drivers\VcommMgr.sys
0xB9D4A000 \SystemRoot\system32\DRIVERS\vbtenum.sys
0xBA480000 \SystemRoot\system32\DRIVERS\blueletaudio.sys
0xB8DB3000 \SystemRoot\system32\DRIVERS\portcls.sys
0xB9216000 \SystemRoot\system32\DRIVERS\drmk.sys
0xBA488000 \SystemRoot\system32\DRIVERS\BlueletSCOAudio.sys
0xB9206000 \SystemRoot\system32\drivers\nchssvad.sys
0xBA748000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA5E2000 \SystemRoot\System32\Drivers\RootMdm.sys
0xBA490000 \SystemRoot\System32\Drivers\Modem.SYS
0xBA498000 \SystemRoot\system32\DRIVERS\rasirda.sys
0xBA4A0000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xBA1E8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA554000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB8D9C000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA1F8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA208000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xB8D8B000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA218000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xBA4A8000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xBA4B0000 \SystemRoot\system32\DRIVERS\raspti.sys
0xBA350000 \SystemRoot\system32\DRIVERS\VComm.sys
0xB8D5B000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xBA228000 \SystemRoot\system32\DRIVERS\termdd.sys
0xBA5E4000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB8CD5000 \SystemRoot\system32\DRIVERS\update.sys
0xB9930000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xBA238000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xB07F9000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xB07C5000 \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
0xB06D4000 \SystemRoot\system32\DRIVERS\HSF_DPV.sys
0xB0621000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
0xBA268000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xB01C8000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0xBA652000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA7E2000 \SystemRoot\System32\Drivers\Null.SYS
0xBA654000 \SystemRoot\System32\Drivers\Beep.SYS
0xAFCCF000 \SystemRoot\System32\drivers\vga.sys
0xBA656000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xBA658000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xAFCC7000 \SystemRoot\System32\Drivers\Msfs.SYS
0xAFCBF000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB05F9000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xAF9ED000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xAF994000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xAF95A000 \SystemRoot\System32\Drivers\avgtdix.sys
0xAF934000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xBA308000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xAF8D4000 \SystemRoot\system32\DRIVERS\netbt.sys
0xAF8B2000 \SystemRoot\System32\drivers\afd.sys
0xAF887000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xAF817000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xBA318000 \SystemRoot\System32\Drivers\Fips.SYS
0xBA65A000 \SystemRoot\system32\DRIVERS\cdrport.sys
0xAFC9F000 \SystemRoot\System32\Drivers\avgmfx86.sys
0xAF7BB000 \SystemRoot\System32\Drivers\avgldx86.sys
0xBA188000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xAF7A3000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xBA5B6000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xAFA28000 \SystemRoot\System32\drivers\Dxapi.sys
0xAFA50000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA6E8000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF055000 \SystemRoot\System32\ati2cqag.dll
0xBF09D000 \SystemRoot\System32\atikvmag.dll
0xBF0E3000 \SystemRoot\System32\ati3duag.dll
0xBF331000 \SystemRoot\System32\ativvaxx.dll
0xBF43B000 \SystemRoot\System32\ATMFD.DLL
0xAD35D000 \SystemRoot\system32\DRIVERS\irda.sys
0xAD493000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xAD0F0000 \SystemRoot\system32\drivers\wdmaud.sys
0xAD39B000 \SystemRoot\system32\drivers\sysaudio.sys
0xACC63000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xACD08000 \??\C:\WINDOWS\system32\drivers\Haspnt.sys
0xACBE0000 \SystemRoot\system32\DRIVERS\aksfridge.sys
0xACB00000 \??\C:\WINDOWS\system32\drivers\hardlock.sys
0xACADC000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xACAD8000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xAC7FC000 \SystemRoot\system32\DRIVERS\srv.sys
0xAC423000 \SystemRoot\System32\Drivers\HTTP.sys
0xAC1C8000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 46):
0 System Idle Process
4 System
872 C:\WINDOWS\system32\smss.exe
944 csrss.exe
972 C:\WINDOWS\system32\winlogon.exe
1016 C:\WINDOWS\system32\services.exe
1036 C:\WINDOWS\system32\lsass.exe
1212 C:\WINDOWS\system32\ati2evxx.exe
1232 C:\WINDOWS\system32\svchost.exe
1300 svchost.exe
1464 C:\WINDOWS\system32\svchost.exe
1508 C:\WINDOWS\system32\svchost.exe
1564 svchost.exe
1720 svchost.exe
188 C:\WINDOWS\system32\ati2evxx.exe
296 C:\WINDOWS\system32\spoolsv.exe
420 C:\WINDOWS\system32\rundll32.exe
768 C:\WINDOWS\explorer.exe
112 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1172 C:\WINDOWS\RTHDCPL.EXE
1312 C:\Program Files\iTunes\iTunesHelper.exe
1356 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
1372 C:\WINDOWS\system32\ctfmon.exe
636 svchost.exe
692 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
220 C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
724 C:\Program Files\Bonjour\mDNSResponder.exe
936 svchost.exe
316 C:\WINDOWS\system32\hasplms.exe
920 C:\WINDOWS\system32\svchost.exe
1796 C:\Program Files\Java\jre6\bin\jqs.exe
2788 C:\WINDOWS\system32\svchost.exe
2808 C:\WINDOWS\system32\svchost.exe
2844 C:\WINDOWS\system32\svchost.exe
2868 C:\WINDOWS\system32\searchindexer.exe
3580 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
3624 C:\Program Files\iPod\bin\iPodService.exe
2544 alg.exe
2480 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
2112 C:\Program Files\Internet Explorer\iexplore.exe
2340 C:\Program Files\Internet Explorer\iexplore.exe
3480 C:\Documents and Settings\P Compton\Desktop\OTL.exe
3936 C:\WINDOWS\system32\searchprotocolhost.exe
1296 searchfilterhost.exe
2332 C:\Program Files\Internet Explorer\iexplore.exe
4076 C:\Documents and Settings\P Compton\Desktop\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x0000000a`0029cc00 (NTFS)

PhysicalDrive0 Model Number: ST9200420AS, Rev: 3.AAA

Size Device Name MBR Status
——————————————–
186 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Done!

GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-23 21:22:10
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9200420AS rev.3.AAA
Running: gmer.exe; Driver: C:\DOCUME~1\PCOMPT~1\LOCALS~1\Temp\awloapoc.sys


—- System - GMER 1.0.15 —-

SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwCreateKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FEC] ZwCreateKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwOpenKey [0x804D7FF1]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FF1] ZwOpenKey [0x804D7FF1]

INT 0x03 \WINDOWS\system32\ntkrnlpa.exe[unknown section] 804D7FF6
INT 0x06 \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) ACD0B16D
INT 0x0E \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) ACD0AFC2

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\aksfridge.sys section is writeable [0xACBE1000, 0x49379, 0xE0000020]
.init C:\WINDOWS\system32\DRIVERS\aksfridge.sys entry point in ".init" section [0xACC37224]
.init C:\WINDOWS\system32\DRIVERS\aksfridge.sys unknown last code section [0xACC37000, 0x4000, 0xE20000E0]
.text C:\WINDOWS\system32\drivers\hardlock.sys section is writeable [0xACB00400, 0x6EB98, 0xE8000020]
.protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xACB8AC20] C:\WINDOWS\system32\drivers\hardlock.sys entry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xACB8AC20]
.protectÿÿÿÿhardlockunknown last code section [0xACB8AA00, 0x50CA, 0xE0000020] C:\WINDOWS\system32\drivers\hardlock.sys unknown last code section [0xACB8AA00, 0x50CA, 0xE0000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ADVAPI32.dll!RegSetValueExW 77DDD767 7 Bytes JMP 10150930 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ADVAPI32.dll!RegSetValueExA 77DDEAE7 7 Bytes JMP 10150870 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ADVAPI32.dll!RegSetValueA 77DFC79E 5 Bytes JMP 101506F0 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ADVAPI32.dll!RegSetValueW 77E36116 5 Bytes JMP 101507B0 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!CreateDialogParamW 7E41EA3B 5 Bytes JMP 10150B00 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 10150E60 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 00F5C8DF
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB5C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 00F5C71B
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 00F5C392
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5117 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E5049 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 10150D70 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 00F5C63F
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 00F5C7F7
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!CreateDialogParamA 7E43C7DB 5 Bytes JMP 10150C80 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!MessageBoxA 7E4507EA 5 Bytes JMP 10150FE0 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4F1A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4F7C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E517A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1014FDE0 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4FDE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!MessageBoxW 7E466534 5 Bytes JMP 101510C0 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] USER32.dll!TrackPopupMenuEx 7E46CF62 5 Bytes JMP 1014FF40 C:\Documents and Settings\P Compton\Local Settings\Application Data\Vuze_Remote\tbVuz0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 00F5C572
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 00F5CAAC
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 00F5C4A5
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 00F5C9C7
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 00F5CE63
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] GDI32.dll!GetGlyphIndicesW 77F52604 3 Bytes JMP 00F5CF2D
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] GDI32.dll!GetGlyphIndicesW + 4 77F52608 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00F5B5B6
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00F5C304
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ws2_32.dll!send 71AB4C27 5 Bytes JMP 00F5BFED
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00F5C20E
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ws2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 00F5B4F9
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ws2_32.dll!recv 71AB676F 5 Bytes JMP 00F5C093
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00F5C13D
.text C:\Program Files\Internet Explorer\iexplore.exe[2112] ws2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 00F5B91A
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!CreateDialogParamW 7E41EA3B 5 Bytes JMP 03E20B00 C:\Documents and Settings\P Compton\Local Settings\Application Data\ConduitEngine\ConduitEngin0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 03E20E60 C:\Documents and Settings\P Compton\Local Settings\Application Data\ConduitEngine\ConduitEngin0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9B01 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD125 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 00DBC8DF
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB5C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254664 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 00DBC71B
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 00DBC392
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5117 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E5049 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 03E20D70 C:\Documents and Settings\P Compton\Local Settings\Application Data\ConduitEngine\ConduitEngin0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 00DBC63F
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 00DBC7F7
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!CreateDialogParamA 7E43C7DB 5 Bytes JMP 03E20C80 C:\Documents and Settings\P Compton\Local Settings\Application Data\ConduitEngine\ConduitEngin0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!MessageBoxA 7E4507EA 5 Bytes JMP 03E20FE0 C:\Documents and Settings\P Compton\Local Settings\Application Data\ConduitEngine\ConduitEngin0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4F1A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4F7C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E517A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 03E1FDE0 C:\Documents and Settings\P Compton\Local Settings\Application Data\ConduitEngine\ConduitEngin0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4FDE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!MessageBoxW 7E466534 5 Bytes JMP 03E210C0 C:\Documents and Settings\P Compton\Local Settings\Application Data\ConduitEngine\ConduitEngin0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] USER32.dll!TrackPopupMenuEx 7E46CF62 5 Bytes JMP 03E1FF40 C:\Documents and Settings\P Compton\Local Settings\Application Data\ConduitEngine\ConduitEngin0.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 00DBC572
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 00DBCAAC
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 00DBC4A5
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 00DBC9C7
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 00DBCE63
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] GDI32.dll!GetGlyphIndicesW 77F52604 5 Bytes JMP 00DBCF2D
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDBB8 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E547F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00DBB5B6
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DBC304
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DBBFED
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DBC20E
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 00DBB4F9
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DBC093
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DBC13D
.text C:\Program Files\Internet Explorer\iexplore.exe[2340] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 00DBB91A
.text C:\WINDOWS\system32\SearchIndexer.exe[2868] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Disk \Device\Harddisk0\DR0 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001060ea83ff
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001060ea83ff (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000

—- EOF - GMER 1.0.15 —-
Hi philcamera,

There are a few leftover baddies in there. Let's see if we can take care of them.

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image] 

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
hi noodle tech ,
here is the combofix log


ComboFix 11-04-23.01 - P Compton 23/04/2011 21:54:18.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3070.2467 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\audiograbber\audiograbber.exe
c:\documents and settings\P Compton\Application Data\Adobe\AdobeUpdate .exe
c:\documents and settings\P Compton\Application Data\Adobe\plugs
c:\documents and settings\P Compton\Application Data\Iqul
c:\documents and settings\P Compton\Application Data\Iqul\tuag.goz
c:\documents and settings\P Compton\Application Data\searchqutb
c:\documents and settings\P Compton\Application Data\searchqutb\dtx.ini
c:\documents and settings\P Compton\Application Data\searchqutb\games\00d2dfc64c07a4f32824abac1d6f735b
c:\documents and settings\P Compton\Application Data\searchqutb\games\3e4265e00cbc4a9cf22a105046a46d8a
c:\documents and settings\P Compton\Application Data\searchqutb\games\44a5d79f5451d3036ba3986425e234c8
c:\documents and settings\P Compton\Application Data\searchqutb\games\GameCategories.xml
c:\documents and settings\P Compton\Application Data\searchqutb\games\GameTypes.xml
c:\documents and settings\P Compton\Application Data\searchqutb\guid.dat
c:\documents and settings\P Compton\Application Data\searchqutb\log.txt
c:\documents and settings\P Compton\Application Data\searchqutb\preferences.dat
c:\documents and settings\P Compton\Application Data\searchqutb\stats.dat
c:\documents and settings\P Compton\Application Data\searchqutb\uninstallIE.dat
c:\documents and settings\P Compton\Application Data\searchqutb\weather\509e6a895b70b7fa0e9531c4dd5a3fa1
c:\documents and settings\P Compton\Application Data\searchqutb\weather\6fadd03b04d7f87a00fd80dcebc8b840
c:\documents and settings\P Compton\Application Data\searchqutb\weather\forecasts_cache.xml
c:\documents and settings\P Compton\Application Data\searchqutb\weather\observations_cache.xml
c:\documents and settings\P Compton\Application Data\searchqutb\weatherbutton_prefs.xml
c:\documents and settings\P Compton\Application Data\searchqutb\widgets_cache\84b70525cff6359fdeca553342c23e4c
c:\documents and settings\P Compton\Application Data\searchqutb\widgets_cache\bf5b6317ae07da699882fc948f22eda4
c:\documents and settings\P Compton\Application Data\searchqutb\widgets_cache\category_cache.xml
c:\documents and settings\P Compton\Application Data\searchqutb\widgets_cache\widget_cache.xml
c:\documents and settings\P Compton\Application Data\Ufok
c:\documents and settings\P Compton\Application Data\Ufok\ivun.exe
c:\documents and settings\P Compton\Local Settings\Application Data\{033964CD-4C22-4505-A7A9-BD9546940F05}
c:\documents and settings\P Compton\Local Settings\Application Data\{033964CD-4C22-4505-A7A9-BD9546940F05}\chrome.manifest
c:\documents and settings\P Compton\Local Settings\Application Data\{033964CD-4C22-4505-A7A9-BD9546940F05}\chrome\content\_cfg.js
c:\documents and settings\P Compton\Local Settings\Application Data\{033964CD-4C22-4505-A7A9-BD9546940F05}\chrome\content\overlay.xul
c:\documents and settings\P Compton\Local Settings\Application Data\{033964CD-4C22-4505-A7A9-BD9546940F05}\install.rdf
c:\documents and settings\P Compton\WINDOWS
c:\program files\Windows Searchqu Toolbar
c:\program files\Windows Searchqu Toolbar\Datamngr\datamngr.dll
c:\program files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\.#searchqutb.js.1.3
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\data\search\engines.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\data\search\search.xsl
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\about.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\dtxpanelwin.xul
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\dtxprefwin.xul
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\dtxwin.xul
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\emailnotifierproviders.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\external.js
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\neterror.xhtml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\wmpstreamer.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\modules\datastore.jsm
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\preferences.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\searchqutb.js
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\toolbar.htm
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\toolbar.xul
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-mdl.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-tl.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-tr.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-dragresize.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close-down.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close-over.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize-down.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize-down.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize-over.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-next-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-next.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-previous-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-previous.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\navico-home.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\panel.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\powered-mystart.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\tb_icon.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\widget.js
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\widget.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-mdl.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-tl.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-tr.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-dragresize.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close-down.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close-over.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize-down.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize-down.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize-over.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-next-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-next.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-previous-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-previous.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\navico-home.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\panel.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\powered-mystart.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\tb_icon.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\widget.js
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\widget.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-mdl.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-tl.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-tr.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-dragresize.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close-down.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close-over.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize-down.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize-down.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize-over.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-next-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-next.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-previous-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-previous.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\navico-home.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\panel.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\powered-mystart.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\tb_icon.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\widget.js
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\widget.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217.zip
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-mdl.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-tl.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-tr.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-dragresize.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close-down.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close-over.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize-down.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize-down.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize-over.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize.PNG
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-next-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-next.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-previous-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-previous.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\navico-home.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\panel.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\powered-mystart.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\tb_icon.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\widget.js
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\widget.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\bluelite.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\bluesky.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-search-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-search.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-settings-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-settings.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-widgets-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-widgets.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn_settings.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-back-ff.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-back.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-left.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-right.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-splitter.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-drop-back.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-drop-left.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-drop-right.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-drop-splitter.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-back-ff.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-back.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-left.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-right.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-splitter.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\ca.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\dictionary.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\divider.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\downloadcom.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\email.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\email_on.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\games.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\graphred0.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\graphred0_5.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\grey.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\headsup.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\ico-shield.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\images.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\add.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\aol.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\arrow-dn.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\arrow-right.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\arrow-up.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btn-end.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btn-mdl.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btn-mdl_ff.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btn-start.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btnover-end.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btnover-mdl.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btnover-mdl_ff.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btnover-start.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\blank.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnback-down-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnback-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnleft-down-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnleft-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnright-down-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnright-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\button-splitter-down-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\button-splitter-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\checkmark.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\chevron.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\collapse.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\comcast.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\dtx.css
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\edit-back-hot.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\edit-back.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\expand.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\found.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\gmail.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_blue.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_cyan.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_lime.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_magenta.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_yellow.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\hotmail.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\imap.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\lastsearch-thumb-back.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\loadingMid.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\lock.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\mailcom.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menu_bg-basic.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menu_separator_bar.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitem-splitter.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemback-down-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemback-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemleft-down-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemleft-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemright-down-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemright-vista.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\move.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\movetarget.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\css\popupAbout.css
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\css\popupGames.css
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\css\popupWidgets.css
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\footer.htm
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\gamecategory.xsl
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\gameData.js
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\gameList.xsl
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\gametype.xsl
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\arrow-sml-drop.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\arrow-sml.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\arrowr-bluew5.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\bg-aboutbox.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\bg-btnover.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\bg-pnl520x390.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-close-grey.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-close-greyover.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-drag.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-next-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-next.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-previous-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-previous.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\gamethumb-on.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\gamethumb2-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-calendar.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-download.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-joystick24.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-play.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-tags.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-Add.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-download.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-Info.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-play.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-shop.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\menul-bgon.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\menul-bgover.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\panel-botm-noscroll.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scroll-bg-206.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scroll-bg.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scroll-topwin.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollb-disable.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollb-down.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollb-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollb.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollt-disable.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollt-down.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollt-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollt.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\searchbox-pnlbtm.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\star_x_grey.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\star_x_orange.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\TRUSTe_about.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\view-detailed-on.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\view-detailed-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\view-thumb-on.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\view-thumb-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\widgets-square-16px.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\widgets-square-24px.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\popupGames.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\popupWidgets.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\pop.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\css\manager.css
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\css\slider.css
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\bg-pnl.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\btn-close-grey.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\btn-close-greyover.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\collapsed_button.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\expanded_button.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\ico-playstation-down.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\ico-playstation-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\ico-playstation.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\ico-radio.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\music-note.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause-on.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-btn-play-on.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-btn-play.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-bg.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-busy.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-on.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-warning.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-options-design-on.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-options-design.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-options-on.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-options.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-0.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-1.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-2.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-3.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-mute.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\scrollbar-handle.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\scrollbar-track.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\slider.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\slideron.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\track.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\managerpanel.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\volumeslider.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\remove.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\rename.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\resize-box.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\rss.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\rsschannelback.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\RSSLogo.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\rsstabdivider.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\scroll-left.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\scroll-right.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\search-go.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\search.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\text-ellipsis.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\throbber.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\toolbarsplitter.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\transparent_1px.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_02.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_03.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_04.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_06.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_07.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_08.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_09.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_10.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_11.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_12.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_13.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_14.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_15.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_16.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_18.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_19.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_20.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_21.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\btn-close-grey.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\btn-close-greyover.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\close-hot.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\close-normal.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\loadingMid.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\proxy.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\template.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\template.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\templateFF.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\throbber.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\cond999.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\icons.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\na-s.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\na.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\weather.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\add.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-check.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-check.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\options-weather.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-blue.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-orange.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.css
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.html
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\yahoo.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\lichen.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\logo-about.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\logo.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\maps.bmp
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\menuseparatorback.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\modify-save.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\modify.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\modifyhot.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\music.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\news.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\options\options-main.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\options\options-search.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\options\options-weather.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\options\options-widgets.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\orange.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\pixsy.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\relatedlinks.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-collapse.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-delete.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-expand.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-feed.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-folder-remove.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-folder-rename.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-folder.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-found.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-reload.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-subscribe.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rssback.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\rsstopback.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\search-over.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\search.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\searchbar\searchbar-background-left.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\searchbar\searchbar-background-middle.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\searchbar\searchbar-background-right.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\searchqutb.css
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\settings.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\shopping.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\siteinfo.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-bluelite.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-bluesky.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-grey.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-lichen.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-orange.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-yellow.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\technorati.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\throbber.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\toolbarsplitter.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\video.bmp
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\weather.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\web.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_allocine.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_bliptv.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_calcal.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_calculator.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_gservices.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_sudoku.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_todo.jpg
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_todo.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_trio.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_uconverter.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widgets-square-16px.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\widgets.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\wikipedia.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\yahoosearch.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\yellow.gif
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\youtube.png
c:\program files\Windows Searchqu Toolbar\ToolBar\chrome\skin\zoom.png
c:\program files\Windows Searchqu Toolbar\ToolBar\components\windowmediator.js
c:\program files\Windows Searchqu Toolbar\ToolBar\manifest.xml
c:\program files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll
c:\program files\Windows Searchqu Toolbar\ToolBar\SearchquTb.dll
c:\program files\Windows Searchqu Toolbar\ToolBar\uninstall.exe
c:\program files\Windows Searchqu Toolbar\uninstall.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-03-23 to 2011-04-23 )))))))))))))))))))))))))))))))
.
.
2011-04-22 20:28 . 2011-04-22 21:11 ——– d—–w- c:\documents and settings\P Compton\Application Data\Adbo
2011-04-22 20:28 . 2011-04-22 20:39 ——– d—–w- c:\documents and settings\P Compton\Application Data\Boab
2011-04-22 19:28 . 2011-04-11 07:04 7071056 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AADC512C-93D0-45CC-908B-EDFAD7852615}\mpengine.dll
2011-04-22 19:21 . 2011-04-22 19:21 106496 –sha-r- c:\windows\system32\netfxperf0.dll
2011-04-22 12:45 . 2011-04-22 12:45 ——– d—–w- c:\documents and settings\P Compton\Application Data\MP3toiPodAudioBookConverter
2011-04-22 12:43 . 2011-04-22 12:44 ——– d—–w- c:\program files\MP3ToIpodAudioBookConverter
2011-04-21 08:24 . 2011-04-21 08:26 ——– d—–w- c:\program files\iTunes
2011-04-06 15:20 . 2011-04-06 15:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-11 07:04 . 2010-06-01 12:41 7071056 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-07 05:33 . 2007-11-20 15:37 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2008-04-14 12:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2008-04-14 12:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2008-04-14 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2008-04-14 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2008-04-14 12:00 385024 —-a-w- c:\windows\system32\html.iec
2011-02-18 15:36 . 2011-01-04 23:04 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 15:36 . 2011-01-04 23:04 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 13:18 . 2008-04-14 12:00 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2008-04-14 12:00 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-04-16 22:11 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2008-04-14 12:00 290432 —-a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2008-04-14 12:00 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2008-04-14 12:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2008-04-14 12:00 978944 —-a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2008-04-14 12:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2007-11-20 15:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2007-11-20 15:35 677888 —-a-w- c:\windows\system32\mstsc.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\program files\ConduitEngine\prxConduitEngin0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 14:54 175912 —-a-w- c:\program files\Vuze_Remote\prxtbVuz0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngin0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KTPWare"="c:\program files\Elantech\ktp.exe" [2009-01-14 512000]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2007-07-27 208952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-28 786521]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 16855552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2007-07-27 44544]
.
c:\documents and settings\P Compton\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-10 16:01 12464 —-a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0sprestrt
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 17:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/04/2010 17:01 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/04/2010 17:01 242896]
R1 cdrblock;cdrblock;c:\windows\system32\drivers\cdrblock.sys [21/11/2007 12:45 20992]
R1 cdrport;cdrport;c:\windows\system32\drivers\cdrport.sys [21/11/2007 12:45 4608]
R2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run –> c:\windows\system32\hasplms.exe -run [?]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS –> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 AutoExNT;AutoExNT;c:\windows\system32\Autoexnt.exe [10/04/2010 18:21 5904]
S2 Fun4IM Coordinator;Fun4IM Coordinator;"c:\progra~1\Fun4IM\Bandoo.exe" –> c:\progra~1\Fun4IM\Bandoo.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [05/01/2011 17:35 136176]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [21/06/2008 20:05 42112]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS –> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 03:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 11:50]
.
2011-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 16:35]
.
2011-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 16:35]
.
2011-04-23 c:\windows\Tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.co.uk/
uInternet Settings,ProxyOverride = ;*.local
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://uk.search.yahoo.com
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-!SASWinLogon - c:\program files\SUPERAntiSpyware\SASWINLO.DLL
SafeBoot-Lavasoft Ad-Aware Service
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-23 21:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(980)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-04-23 22:02:02
ComboFix-quarantined-files.txt 2011-04-23 21:01
.
Pre-Run: 9,235,902,464 bytes free
Post-Run: 9,185,021,952 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 94EA01FBB02F8A4630B4A604DEDE2E14
Hi philcamera,

P2P - I see you have P2P software ( Limewire ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

===================================================

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
hi here is the eset scan log ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=6a322a6aaf3de846b42ff7234fe769ce # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-04-23 11:12:04 # local_time=2011-04-24 12:12:04 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777191 100 0 0 0 0 0 # compatibility_mode=5891 16776549 42 87 96440 15642081 0 0 # compatibility_mode=8192 67108863 100 0 9616889 9616889 0 0 # scanned=131256 # found=11 # cleaned=0 # scan_time=2704 C:\Documents and Settings\P Compton\Application Data\Sun\Java\Deployment\cache\6.0\3\56e9683-1744eb5b Win32/Spy.Zbot.YW trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\P Compton\Application Data\Ufok\ivun.exe.vir a variant of Win32/Kryptik.MXN trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll.vir Win32/Adware.Bandoo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquTb.dll.vir Win32/Adware.Bandoo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Windows Searchqu Toolbar\ToolBar\chrome\content\.#searchqutb.js.1.3.vir Win32/Adware.Bandoo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Windows Searchqu Toolbar\ToolBar\chrome\content\searchqutb.js.vir Win32/Adware.Bandoo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Windows Searchqu Toolbar\ToolBar\chrome\content\toolbar.htm.vir Win32/Adware.Bandoo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Windows Searchqu Toolbar\ToolBar\chrome\content\toolbar.xul.vir Win32/Adware.Bandoo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{9D372DA2-46BD-4BE1-9DD7-C5F05F19AF68}\RP2\A0000214.exe a variant of Win32/Kryptik.MXN trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{9D372DA2-46BD-4BE1-9DD7-C5F05F19AF68}\RP2\A0000218.dll Win32/Adware.Bandoo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{9D372DA2-46BD-4BE1-9DD7-C5F05F19AF68}\RP2\A0000219.dll Win32/Adware.Bandoo application (unable to clean) 00000000000000000000000000000000 I
How is your computer running now? Any outstanding issues? Please run OTL once more following the directions I posted earlier. Post the log in your next reply. Thanks.
all seems to be ok now and msn sec essentials is starting ok now, heres the log fromotl

OTL logfile created on: 24/04/2011 00:55:40 - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\P Compton\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 40.00 Gb Total Space | 8.49 Gb Free Space | 21.21% Space Free | Partition Type: NTFS
Drive D: | 146.31 Gb Total Space | 89.14 Gb Free Space | 60.92% Space Free | Partition Type: NTFS

Computer Name: EDITMACHINE | User Name: P Compton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\P Compton\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\hasplms.exe (SafeNet Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\P Compton\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SNMPTRAP) – File not found
SRV - (SNMP) – File not found
SRV - (NBService) – File not found
SRV - (HidServ) – File not found
SRV - (Fun4IM Coordinator) – File not found
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (hasplms) – C:\WINDOWS\System32\hasplms.exe (SafeNet Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (BlueSoleil Hid Service) – C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()
SRV - (AutoExNT) – C:\WINDOWS\system32\Autoexnt.exe ()


========== Driver Services (SafeList) ==========

DRV - (MpKsl305cfa0b) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C6342C4-A31C-40AB-8080-8B62BC89C875}\MpKsl305cfa0b.sys (Microsoft Corporation)
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NCHSSVAD) SoundTap Recorder (32 Bit) – C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)
DRV - (aksfridge) – C:\WINDOWS\system32\drivers\aksfridge.sys (Aladdin Knowledge Systems Ltd.)
DRV - (akshasp) – C:\WINDOWS\system32\drivers\akshasp.sys (Aladdin Knowledge Systems Ltd.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (SafeNet Inc.)
DRV - (aksusb) – C:\WINDOWS\system32\drivers\aksusb.sys (Aladdin Knowledge Systems Ltd.)
DRV - (akshhl) – C:\WINDOWS\system32\drivers\akshhl.sys (Aladdin Knowledge Systems Ltd.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (MSTAPE) – C:\WINDOWS\system32\drivers\mstape.sys (Microsoft Corporation)
DRV - (AVCSTRM) – C:\WINDOWS\system32\drivers\avcstrm.sys (Microsoft Corporation)
DRV - (cdrblock) – C:\WINDOWS\system32\drivers\cdrblock.sys (Canopus Co,. Ltd.)
DRV - (Haspnt) – C:\WINDOWS\system32\drivers\Haspnt.sys (Aladdin Knowledge Systems)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SiFilter) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc)
DRV - (SiRemFil) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc)
DRV - (SI3132) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc)
DRV - (n558) – C:\WINDOWS\system32\drivers\n558.sys ()
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (MotDev) – C:\WINDOWS\system32\drivers\motodrv.sys (Motorola Inc)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation)
DRV - (BlueletAudio) – C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\BtNetDrv.sys (IVT Corporation)
DRV - (Cam5603D) – C:\WINDOWS\system32\drivers\BisonCam.sys (Bison Electronics. Inc. )
DRV - (Ktp) – C:\WINDOWS\system32\drivers\Ktp.sys (ELANTECH Devices Corp.)
DRV - (w810obex) – C:\WINDOWS\system32\drivers\w810obex.sys (MCCI)
DRV - (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\w810mgmt.sys (MCCI)
DRV - (w810mdm) – C:\WINDOWS\system32\drivers\w810mdm.sys (MCCI)
DRV - (w810mdfl) – C:\WINDOWS\system32\drivers\w810mdfl.sys (MCCI)
DRV - (w810bus) Sony Ericsson W810 Driver driver (WDM) – C:\WINDOWS\system32\drivers\w810bus.sys (MCCI)
DRV - (BlueletSCOAudio) – C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation)
DRV - (BTHidEnum) – C:\WINDOWS\system32\drivers\vbtenum.sys ()
DRV - (BTHidMgr) – C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation)
DRV - (cdrport) – C:\WINDOWS\system32\drivers\cdrport.sys (Canopus Co,. Ltd.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation)
DRV - (PhilCam8116) Logitech QuickCam Pro 3000(PID_08B0) – C:\WINDOWS\system32\drivers\CamDrL21.sys (Philips Semiconductors)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://uk.yahoo.com"
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=ffds1&p="
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://uk.search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.16.0


[2009/04/25 13:12:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Extensions
[2009/01/19 14:07:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Extensions\[removed]
[2010/04/13 12:35:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Firefox\Profiles\jorb9q2r.default\extensions
[2010/04/13 12:35:55 | 000,000,000 | —D | M] (Vuze Remote Toolbar) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Firefox\Profiles\jorb9q2r.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
File not found (No name found) – C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX

O1 HOSTS File: ([2011/04/23 21:59:36 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngin0.dll (Conduit Ltd.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngin0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KTPWare] C:\Program Files\Elantech\Ktp.exe (ELANTECH Devices Corp.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\P Compton\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1263498871678 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} http://download.sopcast.com/download/SOPCORE.CAB (SopCore Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\P Compton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\P Compton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/20 16:39:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/05/01 22:08:11 | 000,000,000 | R–D | M] - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2009/05/01 22:08:11 | 000,000,000 | R–D | M] - D:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/23 23:24:10 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/04/23 22:44:56 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/04/23 21:52:56 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/04/23 21:50:21 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/04/23 21:50:21 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/04/23 21:50:21 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/04/23 21:50:21 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/04/23 21:50:01 | 000,000,000 | —D | C] – C:\Qoobox
[2011/04/23 18:37:10 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2011/04/22 21:28:14 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\Boab
[2011/04/22 21:28:14 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\Adbo
[2011/04/22 13:45:03 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\MP3toiPodAudioBookConverter
[2011/04/22 13:44:04 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Start Menu\Programs\MP3 to iPod Audio Book Converter
[2011/04/22 13:43:52 | 000,000,000 | —D | C] – C:\Program Files\MP3ToIpodAudioBookConverter
[2011/04/21 14:36:58 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\My Documents\New Folder
[2011/04/21 11:32:06 | 000,000,000 | RH-D | C] – C:\Documents and Settings\P Compton\Recent
[2011/04/21 09:26:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/04/21 09:24:32 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/04/06 16:20:16 | 000,197,920 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\dnssdX.dll
[2011/04/06 16:20:16 | 000,107,808 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\dns-sd.exe
[2011/04/06 16:20:16 | 000,091,424 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\dnssd.dll
[2011/04/06 16:20:16 | 000,075,040 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\jdns_sd.dll

========== Files - Modified Within 30 Days ==========

[2011/04/24 00:46:46 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job
[2011/04/24 00:45:00 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/23 21:59:36 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/23 21:53:04 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/04/23 21:49:44 | 004,327,899 | R— | M] () – C:\Documents and Settings\P Compton\Desktop\ComboFix.exe
[2011/04/23 21:45:46 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/23 21:45:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/23 21:22:10 | 000,034,824 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\gmer .text
[2011/04/23 18:45:59 | 000,293,019 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\gmer.zip
[2011/04/23 18:44:42 | 000,080,384 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\MBRCheck.exe
[2011/04/23 18:37:13 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2011/04/22 20:21:05 | 000,106,496 | RHS- | M] () – C:\WINDOWS\System32\netfxperf0.dll
[2011/04/22 12:24:48 | 000,001,252 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/21 16:09:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/21 09:27:57 | 000,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/04/21 09:27:57 | 000,001,854 | —- | M] () – C:\Documents and Settings\P Compton\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/04/21 09:26:06 | 000,001,600 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/04/20 12:50:01 | 002,207,840 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/17 15:56:26 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/17 15:55:03 | 000,494,638 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/17 15:55:03 | 000,092,188 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/06 16:20:16 | 000,197,920 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\dnssdX.dll
[2011/04/06 16:20:16 | 000,107,808 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\dns-sd.exe
[2011/04/06 16:20:16 | 000,091,424 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\dnssd.dll
[2011/04/06 16:20:16 | 000,075,040 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\jdns_sd.dll

========== Files Created - No Company Name ==========

[2011/04/23 21:53:04 | 000,000,282 | —- | C] () – C:\Boot.bak
[2011/04/23 21:50:21 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/04/23 21:50:21 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/04/23 21:50:21 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/04/23 21:50:21 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/04/23 21:50:21 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/04/23 21:49:37 | 004,327,899 | R— | C] () – C:\Documents and Settings\P Compton\Desktop\ComboFix.exe
[2011/04/23 21:22:10 | 000,034,824 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\gmer .text
[2011/04/23 18:45:56 | 000,293,019 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\gmer.zip
[2011/04/23 18:44:39 | 000,080,384 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\MBRCheck.exe
[2011/04/22 20:21:05 | 000,106,496 | RHS- | C] () – C:\WINDOWS\System32\netfxperf0.dll
[2011/04/21 09:26:06 | 000,001,600 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/01 16:20:24 | 000,000,067 | —- | C] () – C:\WINDOWS\swf2avi.INI
[2010/05/29 18:59:40 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2010/05/29 18:59:40 | 000,000,039 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2010/05/19 10:08:13 | 000,000,132 | —- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\fusioncache.dat
[2010/05/19 09:55:29 | 002,515,656 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2010/05/19 09:55:29 | 000,136,650 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/04/10 18:21:31 | 000,034,064 | —- | C] () – C:\WINDOWS\System32\Instexnt.exe
[2010/04/10 18:21:31 | 000,005,904 | —- | C] () – C:\WINDOWS\System32\Autoexnt.exe
[2010/04/10 18:21:31 | 000,002,320 | —- | C] () – C:\WINDOWS\System32\Servmess.dll
[2010/04/09 02:09:00 | 000,017,182 | -HS- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\8O3lJ
[2010/04/09 02:09:00 | 000,017,182 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\8O3lJ
[2010/04/09 01:41:24 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/09 00:07:35 | 000,001,690 | -HS- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\1474v
[2010/04/09 00:07:35 | 000,001,690 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1474v
[2009/12/31 19:01:10 | 000,069,032 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/02 13:21:43 | 000,758,018 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/02 13:21:43 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/07/23 11:52:45 | 000,000,241 | —- | C] () – C:\WINDOWS\QSync.INI
[2009/07/23 11:51:06 | 000,000,544 | —- | C] () – C:\WINDOWS\_delis32.ini
[2009/07/23 11:50:51 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\MimicICM.dll
[2009/07/23 11:49:59 | 000,081,920 | R— | C] () – C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
[2009/07/23 11:38:15 | 000,005,187 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/04/25 13:12:33 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/24 23:34:25 | 001,122,304 | —- | C] () – C:\WINDOWS\System32\Boris TTK Renderer.dll
[2009/04/24 23:34:25 | 000,813,056 | —- | C] () – C:\WINDOWS\System32\Boris TTK Scene.dll
[2009/04/24 23:34:25 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\Boris TTK Utilities.dll
[2009/04/24 23:34:25 | 000,094,720 | —- | C] () – C:\WINDOWS\System32\Boris TTK Render Node.dll
[2009/04/24 23:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptTO6.0.ini
[2009/04/24 23:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptLD6.0.ini
[2009/04/24 23:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptET6.0.ini
[2009/04/24 23:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptES6.0.ini
[2009/04/24 23:34:17 | 018,619,392 | —- | C] () – C:\WINDOWS\System32\BCC6_AE_16Bit.dll
[2009/04/24 23:33:59 | 018,531,840 | —- | C] () – C:\WINDOWS\System32\BCC6_AE_8Bit.dll
[2009/04/24 23:22:18 | 000,000,000 | —- | C] () – C:\WINDOWS\BorisFX BCC6.ini
[2009/04/17 21:10:51 | 000,144,549 | —- | C] () – C:\WINDOWS\hpwins16.dat
[2009/03/29 22:07:56 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\Image2PDF.dat
[2008/09/06 00:30:42 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\WgaLogon.dll
[2008/09/06 00:29:58 | 000,012,800 | —- | C] () – C:\WINDOWS\System32\WgaTray.exe
[2008/07/21 17:14:10 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/06/21 20:01:02 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2008/05/26 22:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/16 10:11:23 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/14 13:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 13:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 13:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 13:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 13:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 13:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 13:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 13:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 13:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/01/23 12:53:38 | 000,237,568 | R— | C] () – C:\WINDOWS\System32\qtmlClient.dll
[2007/12/30 19:03:45 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/12/01 23:25:20 | 000,194,048 | —- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/01 18:17:13 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/30 18:39:17 | 000,000,383 | —- | C] () – C:\WINDOWS\System32\haspdos.sys
[2007/11/30 18:38:37 | 000,002,098 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/11/30 18:06:41 | 000,000,034 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/30 00:33:06 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/11/27 15:12:18 | 000,000,103 | —- | C] () – C:\WINDOWS\canopus.ini
[2007/11/21 12:42:51 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\pavedius4db.dll
[2007/11/21 12:42:51 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\pavedius.dll
[2007/11/21 12:16:29 | 000,040,960 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/11/21 12:07:21 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2007/11/21 12:05:52 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2007/11/21 12:05:52 | 000,294,912 | R— | C] () – C:\WINDOWS\Record.exe
[2007/11/21 12:05:52 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2007/11/21 11:41:36 | 000,015,190 | —- | C] () – C:\WINDOWS\M2000Twn.ini
[2007/11/20 16:42:10 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2007/11/20 16:36:54 | 000,023,392 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2007/11/20 16:28:35 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/11/20 16:27:15 | 002,207,840 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2007/10/25 04:03:45 | 000,011,216 | —- | C] () – C:\WINDOWS\hpwscr16.dat
[2007/10/25 04:00:40 | 000,001,162 | —- | C] () – C:\WINDOWS\hpwmdl16.dat
[2007/09/27 11:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/15 08:27:18 | 000,009,600 | —- | C] () – C:\WINDOWS\System32\drivers\n558.sys
[2007/07/27 13:00:00 | 000,494,638 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2007/07/27 13:00:00 | 000,092,188 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2007/07/27 13:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/04/14 10:14:12 | 000,014,312 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2005/08/12 22:57:09 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/07/30 08:21:32 | 000,011,988 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
Awesome. We're almost done here. A few more files we need to look into.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

DirLook::
C:\Documents and Settings\P Compton\Local Settings\Application Data\8O3lJ
C:\Documents and Settings\All Users\Application Data\8O3lJ
C:\Documents and Settings\P Compton\Local Settings\Application Data\1474v
C:\Documents and Settings\All Users\Application Data\1474v
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste

===================================================

I need you to enable hidden files and folders.

To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and close My Computer.
  • Now your computer is configured to show all hidden files.
===================================================

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\WINDOWS\System32\netfxperf0.dll
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.
hi noodletech,
here is the combofix log

ComboFix 11-04-23.01 - P Compton 24/04/2011 11:19:58.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3070.2401 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\P Compton\Desktop\cfscript.txt
AV: AVG *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-24 to 2011-04-24 )))))))))))))))))))))))))))))))
.
.
2011-04-24 09:55 . 2011-04-24 09:55 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C6342C4-A31C-40AB-8080-8B62BC89C875}\MpKsl547f70b3.sys
2011-04-23 23:54 . 2011-04-11 07:04 7071056 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C6342C4-A31C-40AB-8080-8B62BC89C875}\mpengine.dll
2011-04-22 20:28 . 2011-04-22 21:11 ——– d—–w- c:\documents and settings\P Compton\Application Data\Adbo
2011-04-22 20:28 . 2011-04-22 20:39 ——– d—–w- c:\documents and settings\P Compton\Application Data\Boab
2011-04-22 19:21 . 2011-04-22 19:21 106496 –sha-r- c:\windows\system32\netfxperf0.dll
2011-04-22 12:45 . 2011-04-22 12:45 ——– d—–w- c:\documents and settings\P Compton\Application Data\MP3toiPodAudioBookConverter
2011-04-22 12:43 . 2011-04-22 12:44 ——– d—–w- c:\program files\MP3ToIpodAudioBookConverter
2011-04-21 08:24 . 2011-04-21 08:26 ——– d—–w- c:\program files\iTunes
2011-04-06 15:20 . 2011-04-06 15:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-11 07:04 . 2010-06-01 12:41 7071056 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-07 05:33 . 2007-11-20 15:37 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2008-04-14 12:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2008-04-14 12:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2008-04-14 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2008-04-14 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2008-04-14 12:00 385024 —-a-w- c:\windows\system32\html.iec
2011-02-18 15:36 . 2011-01-04 23:04 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 15:36 . 2011-01-04 23:04 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 13:18 . 2008-04-14 12:00 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2008-04-14 12:00 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-04-16 22:11 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2008-04-14 12:00 290432 —-a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2008-04-14 12:00 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2008-04-14 12:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2008-04-14 12:00 978944 —-a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2008-04-14 12:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2007-11-20 15:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2007-11-20 15:35 677888 —-a-w- c:\windows\system32\mstsc.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\All Users\Application Data\1474v —-
.
.
—- Directory of c:\documents and settings\All Users\Application Data\8O3lJ —-
.
.
—- Directory of c:\documents and settings\P Compton\Local Settings\Application Data\1474v —-
.
.
—- Directory of c:\documents and settings\P Compton\Local Settings\Application Data\8O3lJ —-
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-04-23_20.59.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-24 09:54 . 2011-04-24 09:54 16384 c:\windows\Temp\Perflib_Perfdata_9d4.dat
+ 2011-04-24 09:54 . 2011-04-24 09:54 225280 c:\windows\ERDNT\AutoBackup\24-04-2011\Users\00000002\UsrClass.dat
+ 2011-04-24 09:54 . 2005-10-20 11:02 163328 c:\windows\ERDNT\AutoBackup\24-04-2011\ERDNT.EXE
+ 2011-04-24 09:54 . 2011-04-24 09:54 8863744 c:\windows\ERDNT\AutoBackup\24-04-2011\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\program files\ConduitEngine\prxConduitEngin0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 14:54 175912 —-a-w- c:\program files\Vuze_Remote\prxtbVuz0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngin0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KTPWare"="c:\program files\Elantech\ktp.exe" [2009-01-14 512000]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2007-07-27 208952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-28 786521]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 16855552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2007-07-27 44544]
.
c:\documents and settings\P Compton\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-10 16:01 12464 —-a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0sprestrt
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 17:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/04/2010 17:01 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/04/2010 17:01 242896]
R1 cdrblock;cdrblock;c:\windows\system32\drivers\cdrblock.sys [21/11/2007 12:45 20992]
R1 cdrport;cdrport;c:\windows\system32\drivers\cdrport.sys [21/11/2007 12:45 4608]
R1 MpKsl547f70b3;MpKsl547f70b3;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C6342C4-A31C-40AB-8080-8B62BC89C875}\MpKsl547f70b3.sys [24/04/2011 10:55 28752]
R2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run –> c:\windows\system32\hasplms.exe -run [?]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS –> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 AutoExNT;AutoExNT;c:\windows\system32\Autoexnt.exe [10/04/2010 18:21 5904]
S2 Fun4IM Coordinator;Fun4IM Coordinator;"c:\progra~1\Fun4IM\Bandoo.exe" –> c:\progra~1\Fun4IM\Bandoo.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [05/01/2011 17:35 136176]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [21/06/2008 20:05 42112]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS –> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL547F70B3
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 03:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 11:50]
.
2011-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 16:35]
.
2011-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 16:35]
.
2011-04-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 12:26]
.
2011-04-24 c:\windows\Tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.co.uk/
uInternet Settings,ProxyOverride = ;*.local
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://uk.search.yahoo.com
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-24 11:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(980)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2272)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Nero\Nero 7\Nero BackItUp\NBShell.dll
c:\program files\Nero\Nero 7\Nero BackItUp\MSVCR71.dll
c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
c:\program files\WinRAR\rarext.dll
c:\progra~1\MI239C~1\shellext.dll
c:\program files\7-Zip\7-zip.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\program files\Microsoft Office\Office10\msohev.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\Audiodev.dll
c:\windows\system32\WMVCore.DLL
c:\windows\system32\WMASF.DLL
c:\program files\Logitech\ImageStudio\NameSpc.dll
c:\program files\Logitech\ImageStudio\AlbumUI.dll
c:\program files\Logitech\ImageStudio\QCUI.dll
c:\program files\Logitech\ImageStudio\LTWVC12n.dll
c:\program files\Logitech\ImageStudio\LTFIL12n.DLL
c:\program files\Logitech\ImageStudio\LTKRN12n.dll
c:\program files\Logitech\ImageStudio\LQCUI.dll
c:\program files\Logitech\ImageStudio\LAlbumUI.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
Completion time: 2011-04-24 11:27:39
ComboFix-quarantined-files.txt 2011-04-24 10:27
ComboFix2.txt 2011-04-23 21:02
.
Pre-Run: 9,111,400,448 bytes free
Post-Run: 9,084,428,288 bytes free
.
- - End Of File - - 34002E293BE5CFDAE7229AE1B287993A

i have made hidden files visable now , but when i try to open virustotal.co it comes up as no internet connection with the standard ms no connection page !!!! i def have an internet connection as my browser opens fine and im on wtt ???
ive even tried doing a search in my browser and then a go to ,still no joy?????
HERE IS THE JOYYI RESULTS netfxperf.dll Status: Scan finished. 0 out of 19 scanners reported malware. Scan taken on: Tue 8 Feb 2011 08:18:05 (CET) Permalink File size: 49488 bytes Filetype: PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit MD5: 203d5ecb5ccda683053cda42dff03573 SHA1: 986db43b3366797637858689e0ebde3ac0ff5156 HOPE THIS IS WHAT YOU NEED?
Yup that's exactly what I needed. Looks like your computer is clean! Now let's do some cleanup and get your computer up to date.

Please delete MBRCheck and GMER from your desktop.

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 24.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u24-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.


Passwords
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.


SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an add-on available for both Firefox and IE.

  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
  • Download Host.zip and Save it to your Desktop.
  • Right-click hosts.zip and select 'Extract all files' or 'Extract files…'.
  • Follow the prompts and click 'Finish'.
  • This will open the newly created hosts folder on your Desktop.
  • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
  • Once updated you should see another prompt that the task was completed.
Follow this list and keep your antivirus program and antispyware programs updated and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically. 

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so. 

**Please respond this one more time to ensure it is resolved and close this topic.
thanks for your help all seems ok now . one question if you dont mind , im running microsoft security essentials and this seems ok , i was told not to run other antivirus software ? but your recomending i run spyware blaster ?? is that ok to do this?? regards phil c

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI