This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Vista SP2

Symantec is Auto-protecting multiple Trojan.Gen about 220 today so far and it is still finding more.
I was infected with MS Remove virus and have removed it, I thought. I have scanned using Symantec, Malwarebytes, and Spybot.

OTL did not create the Extras.txt file. Here is the OTL.txt

OTL logfile created on: 5/1/2011 6:32:29 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Catanachs\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 42.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 122.94 Gb Free Space | 56.34% Space Free | Partition Type: NTFS
Drive E: | 14.65 Gb Total Space | 8.45 Gb Free Space | 57.68% Space Free | Partition Type: NTFS
Drive G: | 7.43 Gb Total Space | 2.88 Gb Free Space | 38.74% Space Free | Partition Type: FAT32

Computer Name: HALA-PC | User Name: Catanachs | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Catanachs\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe (Mentor Graphics Corporation)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\DWHWizrd.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\RacAgent.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\activePDF\Composer\APCLIENT.exe (activePDF, Inc.)
PRC - C:\Windows\System32\PDFCreatorMessages.exe (Global Graphics Software Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Catanachs\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_a35e6b9.dll ()
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (CoordinatorServiceHost) – C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe (Dassault Systèmes SolidWorks Corp.)
SRV - (Remote Solver for Flow Simulation 2010) – C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe (Mentor Graphics Corporation)
SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (dsNcService) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\stacsv.exe (IDT, Inc.)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (msvsmon80) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (PDFCreatorMessages) – C:\Windows\System32\PDFCreatorMessages.exe (Global Graphics Software Ltd)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110501.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110501.002\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) – C:\Windows\System32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (dsNcAdpt) – C:\Windows\System32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (SysPlant) – C:\Windows\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\Windows\System32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (Teefer2) – C:\Windows\System32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (COH_Mon) – C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (CVPNDRVA) – C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (PalmUSBD) – C:\Windows\System32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (tosrfbd) – C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (OA009Vid) – C:\Windows\System32\drivers\OA009Vid.sys (Creative Technology Ltd.)
DRV - (OA009Ufd) – C:\Windows\System32\drivers\OA009Ufd.sys (Creative Technology Ltd.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (DNE) – C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (tosrfusb) – C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (CVirtA) – C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=ZUGO&form=ZGAADF&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/17 21:10:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 06:52:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/27 14:47:55 | 000,000,000 | —D | M]

[2009/12/17 12:27:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Catanachs\AppData\Roaming\Mozilla\Extensions
[2011/05/01 08:20:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions
[2010/05/01 06:36:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/30 15:26:40 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/02/08 19:38:33 | 000,001,919 | —- | M] () – C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\searchplugins\bing-zugo.xml
[2010/08/16 12:20:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/08/10 19:34:18 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/16 12:20:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/11/04 18:31:36 | 000,274,432 | —- | M] (Dassault Systèmes SolidWorks Corp.) – C:\Program Files\Mozilla Firefox\plugins\npEModelPlugin.dll

O1 HOSTS File: ([2011/04/27 07:57:43 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APCOMPOSERClient] C:\Program Files\activePDF\Composer\APCLIENT.exe (activePDF, Inc.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [RegistryBooster] File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Catanachs\Pictures\Lucas\20110303.jpg
O24 - Desktop BackupWallPaper: C:\Users\Catanachs\Pictures\Lucas\20110303.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2011/04/20 21:51:56 | 000,000,000 | —D | M] - G:\Autocad – [ FAT32 ]
O33 - MountPoints2\{3dfcc0f1-bd3f-11df-ad92-0023ae289855}\Shell - "" = AutoRun
O33 - MountPoints2\{3dfcc0f1-bd3f-11df-ad92-0023ae289855}\Shell\AutoRun\command - "" = H:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/05/01 18:31:43 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Catanachs\Desktop\OTL.exe
[2011/05/01 14:25:14 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/01 14:25:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/01 14:25:09 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/05/01 14:25:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/01 10:39:32 | 000,000,000 | —D | C] – C:\Users\Catanachs\Desktop\malware
[2011/05/01 09:06:54 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/04/29 07:48:56 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/04/27 06:30:45 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2011/04/27 06:30:41 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/04/27 06:30:31 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/04/24 06:29:56 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{6CD15DF3-15BB-43FA-9B31-A3291F216138}
[2011/04/23 06:18:55 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{C9A120F2-C595-4187-B250-B67D63050628}
[2011/04/22 17:57:44 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{A69EE6BB-E887-45F9-920A-9F674E89744D}
[2011/04/22 05:56:50 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{A735A9E5-345C-4FE0-875D-CE95710E190B}
[2011/04/22 03:04:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/04/21 17:35:57 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{800DCEEF-A34A-4B15-B1EB-2A44FD742290}
[2011/04/20 19:20:36 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{255BBB5C-9B0F-4BE9-A778-BA972B0158F1}
[2011/04/20 19:13:25 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{BE7B20C5-CF16-41DB-9C64-0F52CE6231CF}
[2011/04/20 06:59:28 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Roaming\Malwarebytes
[2011/04/20 06:59:19 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/04/20 06:44:07 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{DD2EF450-93FD-427F-BE44-4D892A7195B7}
[2011/04/19 18:43:06 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{80EAA354-98BF-405E-90D4-84F89502FB59}
[2011/04/19 17:51:14 | 000,000,000 | —D | C] – C:\Users\Catanachs\Documents\My Scans
[2011/04/19 06:42:53 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{70F7482E-40D9-4155-A9A0-CEEB32DABD2D}
[2011/04/18 18:42:04 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{2D252F26-86C8-46FB-9E94-EBD737A7FD7D}
[2011/04/18 06:41:32 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{61D3F18B-8C17-4499-8190-07C6DCFBC327}
[2011/04/17 18:40:34 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{2356CF4E-D8DA-46D2-8A5A-F07A30452607}
[2011/04/16 18:06:33 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{8BA25DB1-8C31-4E24-B5EC-2AA6A0ADE678}
[2011/04/16 12:52:27 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/04/16 06:05:31 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{17341695-176C-46A7-A1DB-5E259540CBA4}
[2011/04/15 03:50:29 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{4410F27B-EA7D-4BE2-BE7D-11007E0C005F}
[2011/04/14 06:42:26 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/04/14 06:42:25 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/04/14 06:42:23 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/04/14 06:42:22 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/04/14 06:42:03 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/04/14 06:42:03 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/04/14 06:42:03 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/04/14 06:42:02 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/04/14 06:42:02 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/04/14 06:42:02 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/04/14 06:42:01 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/04/14 06:42:01 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/04/14 06:42:01 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/04/14 06:42:00 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/04/14 06:42:00 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/04/14 06:42:00 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/04/14 06:42:00 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/04/14 06:42:00 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/04/14 06:42:00 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/04/14 06:42:00 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/04/14 06:41:59 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/04/14 06:41:53 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/04/14 06:41:51 | 002,041,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/04/14 06:41:47 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/04/14 06:41:46 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/04/11 03:01:37 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2011/04/09 20:08:20 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{E7E54728-1146-432A-8DEC-2FB08EB83839}
[2011/04/09 20:00:18 | 000,000,000 | —D | C] – C:\Windows\en
[2011/04/09 10:12:08 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{043EE6BF-D5AB-4691-9641-210EBF807F0D}
[2011/04/08 22:10:59 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{BC927F59-B78B-467F-93AD-208852085A0D}
[2011/04/08 06:10:06 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{D75B5FB4-CF95-48FA-9BAD-758EF3FE02A4}
[2011/04/07 17:49:32 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{3BEB90AE-0859-437E-BE65-EDD65C94B02D}
[2011/04/06 19:15:03 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{701923F1-3014-4B4C-AACF-CCC8C2667411}
[2011/04/06 06:04:45 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{EC978D9D-3A13-45C2-8765-DC42ED0EBA0B}
[2011/04/05 17:59:06 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{31FD46E7-DCF0-4371-A322-33634A85A6A0}
[2011/04/04 20:03:25 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{C6B4A93A-F74F-4FD6-AC67-D63E8CA9B5D3}
[2011/04/04 07:21:40 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{CFC43579-7E1E-4B6A-BD6C-54112DA7F978}
[2011/04/03 19:21:17 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{E5C6530F-E91E-4F65-A3C4-C9123BAA3E65}
[2011/04/03 07:20:54 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{B64E2AC5-AC55-4E70-A5E7-955B92683897}
[2011/04/02 19:20:31 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{809958F9-4BFF-4B6C-B64B-5D1E47E9DF5A}
[2011/04/02 07:19:23 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{3EFF54E9-B49C-4C2F-B896-61BD47D1B5D7}

========== Files - Modified Within 30 Days ==========

[2011/05/01 18:31:47 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Catanachs\Desktop\OTL.exe
[2011/05/01 18:27:07 | 000,000,836 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/01 18:25:04 | 000,000,924 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3374457839-533223774-2140850072-1001UA.job
[2011/05/01 17:24:13 | 000,604,816 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/01 17:24:13 | 000,104,670 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/01 17:17:23 | 000,000,832 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/01 17:17:13 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/01 17:17:12 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/01 17:17:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/01 17:16:44 | 3177,582,592 | -HS- | M] () – C:\hiberfil.sys
[2011/05/01 15:25:02 | 000,000,872 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3374457839-533223774-2140850072-1001Core.job
[2011/05/01 14:25:14 | 000,000,868 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/01 13:40:07 | 000,000,036 | —- | M] () – C:\Users\Catanachs\AppData\Local\housecall.guid.cache
[2011/04/27 08:06:25 | 000,002,505 | —- | M] () – C:\Users\Catanachs\Desktop\VPN Client.lnk
[2011/04/27 07:59:34 | 000,596,552 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/27 07:57:43 | 000,000,761 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/04/09 19:10:30 | 000,006,080 | —- | M] () – C:\Users\Catanachs\AppData\Local\d3d9caps.dat

========== Files Created - No Company Name ==========

[2011/05/01 14:25:14 | 000,000,868 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/01 13:40:07 | 000,000,036 | —- | C] () – C:\Users\Catanachs\AppData\Local\housecall.guid.cache
[2011/04/27 07:59:26 | 3177,582,592 | -HS- | C] () – C:\hiberfil.sys
[2011/02/04 09:17:02 | 000,000,223 | —- | C] () – C:\Windows\resfen5.ini
[2010/11/23 09:57:12 | 000,290,816 | —- | C] () – C:\Windows\System32\niknakXML.dll
[2010/11/23 09:57:12 | 000,135,168 | —- | C] () – C:\Windows\System32\expat.dll
[2010/11/23 09:57:12 | 000,032,768 | —- | C] () – C:\Windows\System32\EventConsumer.dll
[2010/11/23 09:57:12 | 000,024,576 | —- | C] () – C:\Windows\System32\APCOMPOSERMacroUtils.dll
[2010/09/22 07:57:20 | 000,000,105 | —- | C] () – C:\Windows\MTB12.INI
[2010/09/18 17:34:18 | 000,006,656 | —- | C] () – C:\Windows\System32\bcmwlrc.dll
[2010/09/18 17:34:13 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2010/09/18 16:38:46 | 000,982,196 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2010/09/18 16:38:45 | 000,417,344 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2010/09/18 16:38:45 | 000,139,824 | —- | C] () – C:\Windows\System32\igfcg500.bin
[2010/09/18 16:38:45 | 000,097,448 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2010/09/09 12:13:54 | 000,000,000 | —- | C] () – C:\Windows\eDrawingOfficeAutomator.INI
[2010/07/17 21:09:23 | 000,023,115 | —- | C] () – C:\Windows\hpqins15.dat
[2010/06/06 09:04:39 | 000,201,686 | —- | C] () – C:\Windows\hpoins43.dat
[2010/05/07 22:25:42 | 000,000,000 | —- | C] () – C:\Windows\MTSTACK.INI
[2010/01/07 20:24:54 | 000,000,197 | —- | C] () – C:\Windows\QUICKEN.INI
[2009/09/07 08:03:42 | 000,000,154 | —- | C] () – C:\Windows\ODBC.INI
[2009/08/30 20:53:39 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2009/08/23 21:41:22 | 000,197,424 | —- | C] () – C:\Windows\System32\vpnapi.dll
[2009/08/04 20:27:22 | 000,006,080 | —- | C] () – C:\Users\Catanachs\AppData\Local\d3d9caps.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/27 21:16:10 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/07/21 19:51:33 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/07/21 19:51:32 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/07/19 13:29:03 | 000,028,672 | —- | C] () – C:\Users\Catanachs\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/17 19:03:25 | 000,000,462 | —- | C] () – C:\Users\Catanachs\AppData\Roaming\wklnhst.dat
[2009/05/22 05:25:35 | 000,000,675 | —- | C] () – C:\Windows\hpomdl43.dat
[2009/04/01 04:29:49 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1576.dll
[2009/04/01 04:29:49 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2009/04/01 04:25:28 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/04/01 02:02:50 | 000,000,076 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/04/01 01:52:37 | 000,026,112 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2008/02/03 19:11:25 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,596,552 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,604,816 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,104,670 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/02/06 03:18:21 | 000,061,502 | —- | C] () – C:\Windows\System32\ODBCMON.DLL

========== LOP Check ==========

[2009/09/21 11:35:30 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\acccore
[2011/03/28 11:49:09 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Autodesk
[2009/09/23 16:27:03 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Aveyond 3
[2009/09/23 16:13:31 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Camel101
[2009/07/13 18:11:29 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/12/11 20:56:26 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\DassaultSystemes
[2010/10/31 09:07:03 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\EDrawings
[2009/09/28 10:39:46 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Enchanted Katya
[2010/01/31 19:18:32 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Facebook
[2009/09/23 13:39:19 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Flood Light Games
[2011/02/08 19:36:59 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\GetRightToGo
[2009/09/23 16:16:50 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Gold Casual Games
[2009/07/14 12:45:57 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\HotSync
[2009/12/17 21:18:50 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\InfraRecorder
[2009/09/24 18:29:06 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\IronCode
[2011/01/28 07:22:03 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Juniper Networks
[2009/07/14 12:57:18 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Leadertech
[2009/09/19 09:32:55 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Merscom
[2009/07/26 08:45:13 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\OpenOffice.org
[2009/09/23 19:24:50 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\PlayFirst
[2009/12/31 19:16:59 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Research In Motion
[2009/07/17 17:18:48 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\RIM Palm&PPC Upgrade Wizard
[2009/09/22 14:49:00 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Shape games
[2009/07/24 22:21:54 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Template
[2010/09/18 17:21:12 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\TMP
[2010/09/18 11:44:18 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Uniblue
[2010/04/14 03:20:14 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\uTorrent
[2010/11/22 16:44:01 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\WinBatch
[2009/10/14 12:16:22 | 000,000,000 | —D | M] – C:\Users\Catanachs\AppData\Roaming\Windows Live Writer
[2011/05/01 17:15:37 | 000,032,582 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/04/01 04:30:00 | 000,003,392 | RH– | M] () – C:\dell.sdr
[2011/05/01 17:16:44 | 3177,582,592 | -HS- | M] () – C:\hiberfil.sys
[2010/01/07 20:23:35 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/09/21 11:35:19 | 000,000,367 | -H– | M] () – C:\IPH.PH
[2010/01/07 20:23:35 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/05/01 17:16:39 | 3493,470,208 | -HS- | M] () – C:\pagefile.sys
[2011/04/24 17:23:46 | 000,000,542 | —- | M] () – C:\rkill.log

< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/21 20:12:05 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/16 14:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpfpp70v.dll
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/01/20 22:43:21 | 000,000,442 | -HS- | M] () – C:\ProgramData\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/03 22:24:53 | 000,000,574 | -HS- | M] () – C:\Users\Catanachs\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2009/10/01 20:32:03 | 000,561,152 | —- | M] (Joshua F. Madison) – C:\Users\Catanachs\Desktop\Convert.exe
[2011/05/01 18:31:47 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Catanachs\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-28 07:09:19

< End of report >

Hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:54:48 PM, on 5/1/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\activePDF\Composer\APCLIENT.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\DWHWizrd.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SavUI.exe
C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
C:\Users\Catanachs\Desktop\HiJackThis.exe
C:\Program Files\SolidWorks Corp\SolidWorks\sldShellExtServer.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [APCOMPOSERClient] C:\Program Files\activePDF\Composer\APClient.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systèmes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ???? Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd - C:\Windows\System32\PDFCreatorMessages.exe
O23 - Service: Remote Solver for Flow Simulation 2010 - Mentor Graphics Corporation - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)

–
End of file - 12673 bytes

DDS.txt
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 19:05:42.63 on Sun 05/01/2011
Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_21
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3032.1027 [GMT -4:00]
.
AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\STacSV.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\aestsrv.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\PDFCreatorMessages.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\RUNDLL32.EXE
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\activePDF\Composer\APCLIENT.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\DWHWizrd.exe
C:\Users\Catanachs\Desktop\OTL.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SavUI.exe
C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
C:\Users\Catanachs\Desktop\dds.exe
C:\Windows\system32\conime.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SescLU.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
c:\windows\system32\rundll32.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uWindow Title = Internet Explorer provided by Dell
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [Aim6]
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [RegistryBooster] "c:\program files\uniblue\registrybooster\launcher.exe" delay 20000
mRun: []
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [QuickSet] c:\program files\dell\quickset\QuickSet.exe
mRun: [APCOMPOSERClient] c:\program files\activepdf\composer\APClient.exe
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
Trusted Zone: intuit.com\ttlc
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\catana~1\appdata\roaming\mozilla\firefox\profiles\zsdg4jwt.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=ZUGO&form=ZGAADF&q=
FF - component: c:\users\catanachs\appdata\roaming\mozilla\firefox\profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\users\catanachs\appdata\roaming\mozilla\firefox\profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\catanachs\appdata\local\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\users\catanachs\appdata\roaming\facebook\npfbplugin_1_0_1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
.
============= SERVICES / DRIVERS ===============
.
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_0145da1d\AEstSrv.exe [2009-3-31 81920]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-23 155648]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\solidworks corp\solidworks flow simulation\bincfw\StandAloneSlv.exe [2010-10-6 71432]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2010-4-23 1831024]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-9-21 24652]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc –> RUNDLL32.EXE ykx32coinst,serviceStartProc [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-9-7 102448]
R3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-11-9 39272]
R3 OA009Ufd;Creative Camera OA009 Upper Filter Driver;c:\windows\system32\drivers\OA009Ufd.sys [2009-3-6 133632]
R3 OA009Vid;Creative Camera OA009 Function Driver;c:\windows\system32\drivers\OA009Vid.sys [2009-3-19 271552]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-4 135664]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2009-12-2 23888]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\solidworks corp\solidworks\swscheduler\DTSCoordinatorService.exe [2010-12-2 87336]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2005-9-23 2799808]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== File Associations ===============
.
.scr=AutoCADScriptFile
.
=============== Created Last 30 ================
.
2011-05-01 18:25:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-01 18:25:09 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-01 18:25:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-05-01 13:06:54 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-04-29 11:48:56 ——– d—–w- c:\progra~2\Spybot - Search & Destroy
2011-04-27 10:30:45 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-04-27 10:30:41 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 10:30:31 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-04-24 10:29:56 ——– d—–w- c:\users\catana~1\appdata\local\{6CD15DF3-15BB-43FA-9B31-A3291F216138}
2011-04-23 10:18:55 ——– d—–w- c:\users\catana~1\appdata\local\{C9A120F2-C595-4187-B250-B67D63050628}
2011-04-22 21:57:44 ——– d—–w- c:\users\catana~1\appdata\local\{A69EE6BB-E887-45F9-920A-9F674E89744D}
2011-04-22 09:56:50 ——– d—–w- c:\users\catana~1\appdata\local\{A735A9E5-345C-4FE0-875D-CE95710E190B}
2011-04-21 21:35:57 ——– d—–w- c:\users\catana~1\appdata\local\{800DCEEF-A34A-4B15-B1EB-2A44FD742290}
2011-04-20 23:20:36 ——– d—–w- c:\users\catana~1\appdata\local\{255BBB5C-9B0F-4BE9-A778-BA972B0158F1}
2011-04-20 23:13:25 ——– d—–w- c:\users\catana~1\appdata\local\{BE7B20C5-CF16-41DB-9C64-0F52CE6231CF}
2011-04-20 10:59:28 ——– d—–w- c:\users\catana~1\appdata\roaming\Malwarebytes
2011-04-20 10:59:19 ——– d—–w- c:\progra~2\Malwarebytes
2011-04-20 10:44:07 ——– d—–w- c:\users\catana~1\appdata\local\{DD2EF450-93FD-427F-BE44-4D892A7195B7}
2011-04-19 22:43:06 ——– d—–w- c:\users\catana~1\appdata\local\{80EAA354-98BF-405E-90D4-84F89502FB59}
2011-04-19 10:42:53 ——– d—–w- c:\users\catana~1\appdata\local\{70F7482E-40D9-4155-A9A0-CEEB32DABD2D}
2011-04-18 22:42:04 ——– d—–w- c:\users\catana~1\appdata\local\{2D252F26-86C8-46FB-9E94-EBD737A7FD7D}
2011-04-18 10:41:32 ——– d—–w- c:\users\catana~1\appdata\local\{61D3F18B-8C17-4499-8190-07C6DCFBC327}
2011-04-17 22:40:34 ——– d—–w- c:\users\catana~1\appdata\local\{2356CF4E-D8DA-46D2-8A5A-F07A30452607}
2011-04-16 22:06:33 ——– d—–w- c:\users\catana~1\appdata\local\{8BA25DB1-8C31-4E24-B5EC-2AA6A0ADE678}
2011-04-16 16:52:27 ——– d—–w- c:\progra~2\MFAData
2011-04-16 10:05:31 ——– d—–w- c:\users\catana~1\appdata\local\{17341695-176C-46A7-A1DB-5E259540CBA4}
2011-04-15 07:50:29 ——– d—–w- c:\users\catana~1\appdata\local\{4410F27B-EA7D-4BE2-BE7D-11007E0C005F}
2011-04-14 10:41:59 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-04-14 10:41:57 305152 —-a-w- c:\windows\system32\drivers\srv.sys
2011-04-14 10:41:56 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-04-14 10:41:56 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-14 10:41:54 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-04-14 10:41:53 25088 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-04-14 10:41:51 2041856 —-a-w- c:\windows\system32\win32k.sys
2011-04-14 10:41:48 739328 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-14 10:41:46 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-04-14 10:41:42 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-04-11 07:01:37 ——– d—–w- c:\program files\Microsoft
2011-04-10 00:08:20 ——– d—–w- c:\users\catana~1\appdata\local\{E7E54728-1146-432A-8DEC-2FB08EB83839}
2011-04-10 00:00:18 ——– d—–w- c:\windows\en
2011-04-09 23:55:09 469256 —-a-w- c:\program files\common files\windows live\.cache\8b6815301cbf71104\InstallManager_WLE_WLE.exe
2011-04-09 23:54:23 15712 —-a-w- c:\program files\common files\windows live\.cache\733133201cbf71103\MeshBetaRemover.exe
2011-04-09 14:12:08 ——– d—–w- c:\users\catana~1\appdata\local\{043EE6BF-D5AB-4691-9641-210EBF807F0D}
2011-04-09 02:10:59 ——– d—–w- c:\users\catana~1\appdata\local\{BC927F59-B78B-467F-93AD-208852085A0D}
2011-04-08 10:10:06 ——– d—–w- c:\users\catana~1\appdata\local\{D75B5FB4-CF95-48FA-9BAD-758EF3FE02A4}
2011-04-07 21:49:32 ——– d—–w- c:\users\catana~1\appdata\local\{3BEB90AE-0859-437E-BE65-EDD65C94B02D}
2011-04-06 23:15:03 ——– d—–w- c:\users\catana~1\appdata\local\{701923F1-3014-4B4C-AACF-CCC8C2667411}
2011-04-06 10:04:45 ——– d—–w- c:\users\catana~1\appdata\local\{EC978D9D-3A13-45C2-8765-DC42ED0EBA0B}
2011-04-05 21:59:06 ——– d—–w- c:\users\catana~1\appdata\local\{31FD46E7-DCF0-4371-A322-33634A85A6A0}
2011-04-05 00:03:25 ——– d—–w- c:\users\catana~1\appdata\local\{C6B4A93A-F74F-4FD6-AC67-D63E8CA9B5D3}
2011-04-04 11:21:40 ——– d—–w- c:\users\catana~1\appdata\local\{CFC43579-7E1E-4B6A-BD6C-54112DA7F978}
2011-04-03 23:21:17 ——– d—–w- c:\users\catana~1\appdata\local\{E5C6530F-E91E-4F65-A3C4-C9123BAA3E65}
2011-04-03 11:20:54 ——– d—–w- c:\users\catana~1\appdata\local\{B64E2AC5-AC55-4E70-A5E7-955B92683897}
2011-04-02 23:20:31 ——– d—–w- c:\users\catana~1\appdata\local\{809958F9-4BFF-4B6C-B64B-5D1E47E9DF5A}
2011-04-02 11:19:23 ——– d—–w- c:\users\catana~1\appdata\local\{3EFF54E9-B49C-4C2F-B896-61BD47D1B5D7}
.
==================== Find3M ====================
.
2011-03-10 17:03:51 1162240 —-a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03:51 1136640 —-a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:40:07 173056 —-a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40:05 542720 —-a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40:05 458752 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40:04 2159616 —-a-w- c:\windows\apppatch\AcGenral.dll
2011-02-22 14:13:01 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33:12 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33:09 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-02-22 06:21:28 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 06:17:08 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 06:16:53 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 06:16:40 71680 —-a-w- c:\windows\system32\iesetup.dll
2011-02-22 06:16:40 109056 —-a-w- c:\windows\system32\iesysprep.dll
2011-02-22 05:20:39 385024 —-a-w- c:\windows\system32\html.iec
2011-02-22 04:43:54 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2011-02-16 16:16:37 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-02-16 14:02:23 292864 —-a-w- c:\windows\system32\atmfd.dll
.
============= FINISH: 19:06:59.28 ===============

Thank you,

Attachments:

Hello wcatanach and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

P2P - I see you have P2P software, (uTorrent, ), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Registry cleaners

I notice that you have Registry Booster on your system. It's not recommended to use of registry cleaners/boosters.

The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in "unpredictable results". Unless you have a particular problem that requires a registry edit to correct it, I would suggest you leave the registry alone.

One of the malware experts, miekiemoes, has an excellent writeup here
Another excellent article by Bill Castner is located here

===================================================

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    [2010/07/30 15:26:40 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found
    O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [Aim6] File not found
    O4 - HKCU..\Run: [RegistryBooster] File not found
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
===================================================

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL fix log
New OTL.txt
Gmer.txt


Could you also send the result of the Malwarebytes scan

Thanks

Satchfan
OTL log: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\searchplugin folder moved successfully. C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\META-INF folder moved successfully. C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\lib folder moved successfully. C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\defaults folder moved successfully. C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components folder moved successfully. C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\chrome folder moved successfully. C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822} folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D425283-D487-4337-BAB6-AB8354A81457}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{9D425283-D487-4337-BAB6-AB8354A81457} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9D425283-D487-4337-BAB6-AB8354A81457} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Aim6 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\RegistryBooster deleted successfully. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} C:\Windows\Downloaded Program Files\popcaploader.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}\ not found. ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Catanachs ->Temp folder emptied: 259599742 bytes ->Temporary Internet Files folder emptied: 9146664 bytes ->Java cache emptied: 41277400 bytes ->FireFox cache emptied: 117810519 bytes ->Google Chrome cache emptied: 409610796 bytes ->Flash cache emptied: 321963 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes
OTL log:

gmer crashed before I ran this log.

OTL logfile created on: 5/3/2011 10:13:08 AM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Catanachs\Desktop\malware
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 119.09 Gb Free Space | 54.58% Space Free | Partition Type: NTFS
Drive E: | 14.65 Gb Total Space | 8.45 Gb Free Space | 57.68% Space Free | Partition Type: NTFS
Drive G: | 7.43 Gb Total Space | 2.79 Gb Free Space | 37.57% Space Free | Partition Type: FAT32

Computer Name: HALA-PC | User Name: Catanachs | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\Catanachs\Desktop\malware\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe (Mentor Graphics Corporation)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\activePDF\Composer\APCLIENT.exe (activePDF, Inc.)
PRC - C:\Windows\System32\PDFCreatorMessages.exe (Global Graphics Software Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Catanachs\Desktop\malware\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_a35e6b9.dll ()
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (CoordinatorServiceHost) – C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe (Dassault Systèmes SolidWorks Corp.)
SRV - (Remote Solver for Flow Simulation 2010) – C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe (Mentor Graphics Corporation)
SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (dsNcService) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\stacsv.exe (IDT, Inc.)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (msvsmon80) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (PDFCreatorMessages) – C:\Windows\System32\PDFCreatorMessages.exe (Global Graphics Software Ltd)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110502.018\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110502.018\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) – C:\Windows\System32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (dsNcAdpt) – C:\Windows\System32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (SysPlant) – C:\Windows\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\Windows\System32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (Teefer2) – C:\Windows\System32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (COH_Mon) – C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (CVPNDRVA) – C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (PalmUSBD) – C:\Windows\System32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (tosrfbd) – C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (OA009Vid) – C:\Windows\System32\drivers\OA009Vid.sys (Creative Technology Ltd.)
DRV - (OA009Ufd) – C:\Windows\System32\drivers\OA009Ufd.sys (Creative Technology Ltd.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (DNE) – C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (tosrfusb) – C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (CVirtA) – C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=ZUGO&form=ZGAADF&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/17 21:10:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/02 18:43:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/02 18:43:27 | 000,000,000 | —D | M]

[2009/12/17 12:27:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Catanachs\AppData\Roaming\Mozilla\Extensions
[2011/05/03 10:13:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions
[2010/05/01 06:36:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/02/08 19:38:33 | 000,001,919 | —- | M] () – C:\Users\Catanachs\AppData\Roaming\Mozilla\Firefox\Profiles\zsdg4jwt.default\searchplugins\bing-zugo.xml
[2010/08/16 12:20:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/08/10 19:34:18 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/16 12:20:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/11/04 18:31:36 | 000,274,432 | —- | M] (Dassault Systèmes SolidWorks Corp.) – C:\Program Files\Mozilla Firefox\plugins\npEModelPlugin.dll

O1 HOSTS File: ([2011/04/27 07:57:43 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [APCOMPOSERClient] C:\Program Files\activePDF\Composer\APCLIENT.exe (activePDF, Inc.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] File not found
O4 - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Catanachs\Pictures\Lucas\20110303.jpg
O24 - Desktop BackupWallPaper: C:\Users\Catanachs\Pictures\Lucas\20110303.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2011/04/20 21:51:56 | 000,000,000 | —D | M] - G:\Autocad – [ FAT32 ]
O33 - MountPoints2\{3dfcc0f1-bd3f-11df-ad92-0023ae289855}\Shell - "" = AutoRun
O33 - MountPoints2\{3dfcc0f1-bd3f-11df-ad92-0023ae289855}\Shell\AutoRun\command - "" = H:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/03 09:50:38 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/02 10:17:49 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Roaming\HPAppData
[2011/05/01 14:25:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/01 10:39:32 | 000,000,000 | —D | C] – C:\Users\Catanachs\Desktop\malware
[2011/05/01 09:06:54 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/04/29 07:48:56 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/04/27 06:30:45 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2011/04/27 06:30:41 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/04/27 06:30:31 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/04/24 06:29:56 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{6CD15DF3-15BB-43FA-9B31-A3291F216138}
[2011/04/23 06:18:55 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{C9A120F2-C595-4187-B250-B67D63050628}
[2011/04/22 17:57:44 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{A69EE6BB-E887-45F9-920A-9F674E89744D}
[2011/04/22 05:56:50 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{A735A9E5-345C-4FE0-875D-CE95710E190B}
[2011/04/22 03:04:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/04/21 17:35:57 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{800DCEEF-A34A-4B15-B1EB-2A44FD742290}
[2011/04/20 19:20:36 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{255BBB5C-9B0F-4BE9-A778-BA972B0158F1}
[2011/04/20 19:13:25 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{BE7B20C5-CF16-41DB-9C64-0F52CE6231CF}
[2011/04/20 06:59:28 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Roaming\Malwarebytes
[2011/04/20 06:59:19 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/04/20 06:44:07 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{DD2EF450-93FD-427F-BE44-4D892A7195B7}
[2011/04/19 18:43:06 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{80EAA354-98BF-405E-90D4-84F89502FB59}
[2011/04/19 17:51:14 | 000,000,000 | —D | C] – C:\Users\Catanachs\Documents\My Scans
[2011/04/19 06:42:53 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{70F7482E-40D9-4155-A9A0-CEEB32DABD2D}
[2011/04/18 18:42:04 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{2D252F26-86C8-46FB-9E94-EBD737A7FD7D}
[2011/04/18 06:41:32 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{61D3F18B-8C17-4499-8190-07C6DCFBC327}
[2011/04/17 18:40:34 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{2356CF4E-D8DA-46D2-8A5A-F07A30452607}
[2011/04/16 18:06:33 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{8BA25DB1-8C31-4E24-B5EC-2AA6A0ADE678}
[2011/04/16 12:52:27 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/04/16 06:05:31 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{17341695-176C-46A7-A1DB-5E259540CBA4}
[2011/04/15 03:50:29 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{4410F27B-EA7D-4BE2-BE7D-11007E0C005F}
[2011/04/14 06:42:26 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/04/14 06:42:25 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/04/14 06:42:23 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/04/14 06:42:22 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/04/14 06:42:03 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/04/14 06:42:03 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/04/14 06:42:03 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/04/14 06:42:02 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/04/14 06:42:02 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/04/14 06:42:02 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/04/14 06:42:01 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/04/14 06:42:01 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/04/14 06:42:01 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/04/14 06:42:00 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/04/14 06:42:00 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/04/14 06:42:00 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/04/14 06:42:00 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/04/14 06:42:00 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/04/14 06:42:00 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/04/14 06:42:00 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/04/14 06:41:59 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/04/14 06:41:53 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/04/14 06:41:51 | 002,041,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/04/14 06:41:47 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/04/14 06:41:46 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/04/11 03:01:37 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2011/04/09 20:08:20 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{E7E54728-1146-432A-8DEC-2FB08EB83839}
[2011/04/09 20:00:18 | 000,000,000 | —D | C] – C:\Windows\en
[2011/04/09 10:12:08 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{043EE6BF-D5AB-4691-9641-210EBF807F0D}
[2011/04/08 22:10:59 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{BC927F59-B78B-467F-93AD-208852085A0D}
[2011/04/08 06:10:06 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{D75B5FB4-CF95-48FA-9BAD-758EF3FE02A4}
[2011/04/07 17:49:32 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{3BEB90AE-0859-437E-BE65-EDD65C94B02D}
[2011/04/06 19:15:03 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{701923F1-3014-4B4C-AACF-CCC8C2667411}
[2011/04/06 06:04:45 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{EC978D9D-3A13-45C2-8765-DC42ED0EBA0B}
[2011/04/05 17:59:06 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{31FD46E7-DCF0-4371-A322-33634A85A6A0}
[2011/04/04 20:03:25 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{C6B4A93A-F74F-4FD6-AC67-D63E8CA9B5D3}
[2011/04/04 07:21:40 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{CFC43579-7E1E-4B6A-BD6C-54112DA7F978}
[2011/04/03 19:21:17 | 000,000,000 | —D | C] – C:\Users\Catanachs\AppData\Local\{E5C6530F-E91E-4F65-A3C4-C9123BAA3E65}

========== Files - Modified Within 30 Days ==========

[2011/05/03 10:07:24 | 000,301,568 | —- | M] () – C:\Users\Catanachs\Desktop\gmer.exe
[2011/05/03 10:06:49 | 000,293,176 | —- | M] () – C:\Users\Catanachs\Desktop\gmer.zip
[2011/05/03 10:05:20 | 000,604,816 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/03 10:05:20 | 000,104,670 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/03 09:57:22 | 000,000,832 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/03 09:57:16 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/03 09:57:15 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/03 09:57:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/03 09:56:38 | 3177,615,360 | -HS- | M] () – C:\hiberfil.sys
[2011/05/03 09:35:34 | 000,002,505 | —- | M] () – C:\Users\Catanachs\Desktop\VPN Client.lnk
[2011/05/03 09:27:00 | 000,000,836 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/03 09:25:00 | 000,000,924 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3374457839-533223774-2140850072-1001UA.job
[2011/05/02 15:25:00 | 000,000,872 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3374457839-533223774-2140850072-1001Core.job
[2011/05/01 13:40:07 | 000,000,036 | —- | M] () – C:\Users\Catanachs\AppData\Local\housecall.guid.cache
[2011/04/27 07:59:34 | 000,596,552 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/27 07:57:43 | 000,000,761 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/04/09 19:10:30 | 000,006,080 | —- | M] () – C:\Users\Catanachs\AppData\Local\d3d9caps.dat

========== Files Created - No Company Name ==========

[2011/05/03 10:06:48 | 000,293,176 | —- | C] () – C:\Users\Catanachs\Desktop\gmer.zip
[2011/05/01 13:40:07 | 000,000,036 | —- | C] () – C:\Users\Catanachs\AppData\Local\housecall.guid.cache
[2011/04/29 12:45:36 | 000,301,568 | —- | C] () – C:\Users\Catanachs\Desktop\gmer.exe
[2011/04/27 07:59:26 | 3177,615,360 | -HS- | C] () – C:\hiberfil.sys
[2011/02/04 09:17:02 | 000,000,223 | —- | C] () – C:\Windows\resfen5.ini
[2010/11/23 09:57:12 | 000,290,816 | —- | C] () – C:\Windows\System32\niknakXML.dll
[2010/11/23 09:57:12 | 000,135,168 | —- | C] () – C:\Windows\System32\expat.dll
[2010/11/23 09:57:12 | 000,032,768 | —- | C] () – C:\Windows\System32\EventConsumer.dll
[2010/11/23 09:57:12 | 000,024,576 | —- | C] () – C:\Windows\System32\APCOMPOSERMacroUtils.dll
[2010/09/22 07:57:20 | 000,000,105 | —- | C] () – C:\Windows\MTB12.INI
[2010/09/18 17:34:18 | 000,006,656 | —- | C] () – C:\Windows\System32\bcmwlrc.dll
[2010/09/18 17:34:13 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2010/09/18 16:38:46 | 000,982,196 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2010/09/18 16:38:45 | 000,417,344 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2010/09/18 16:38:45 | 000,139,824 | —- | C] () – C:\Windows\System32\igfcg500.bin
[2010/09/18 16:38:45 | 000,097,448 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2010/09/09 12:13:54 | 000,000,000 | —- | C] () – C:\Windows\eDrawingOfficeAutomator.INI
[2010/07/17 21:09:23 | 000,023,115 | —- | C] () – C:\Windows\hpqins15.dat
[2010/06/06 09:04:39 | 000,201,686 | —- | C] () – C:\Windows\hpoins43.dat
[2010/05/07 22:25:42 | 000,000,000 | —- | C] () – C:\Windows\MTSTACK.INI
[2010/01/07 20:24:54 | 000,000,197 | —- | C] () – C:\Windows\QUICKEN.INI
[2009/09/07 08:03:42 | 000,000,154 | —- | C] () – C:\Windows\ODBC.INI
[2009/08/30 20:53:39 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2009/08/23 21:41:22 | 000,197,424 | —- | C] () – C:\Windows\System32\vpnapi.dll
[2009/08/04 20:27:22 | 000,006,080 | —- | C] () – C:\Users\Catanachs\AppData\Local\d3d9caps.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/27 21:16:10 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/07/21 19:51:33 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/07/21 19:51:32 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/07/19 13:29:03 | 000,028,672 | —- | C] () – C:\Users\Catanachs\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/17 19:03:25 | 000,000,462 | —- | C] () – C:\Users\Catanachs\AppData\Roaming\wklnhst.dat
[2009/05/22 05:25:35 | 000,000,675 | —- | C] () – C:\Windows\hpomdl43.dat
[2009/04/01 04:29:49 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1576.dll
[2009/04/01 04:29:49 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2009/04/01 04:25:28 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/04/01 02:02:50 | 000,000,076 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/04/01 01:52:37 | 000,026,112 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2008/02/03 19:11:25 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,596,552 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,604,816 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,104,670 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/02/06 03:18:21 | 000,061,502 | —- | C] () – C:\Windows\System32\ODBCMON.DLL

< End of report >
Here is the Hijack this log file after running Malware bytes. I do not have any logs created by Malware bytes.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:50:46 PM, on 5/1/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\activePDF\Composer\APCLIENT.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Catanachs\Desktop\malware\HijackThis.exe
C:\Program Files\palmOne\Palm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [APCOMPOSERClient] C:\Program Files\activePDF\Composer\APClient.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systèmes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ???? Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd - C:\Windows\System32\PDFCreatorMessages.exe
O23 - Service: Remote Solver for Flow Simulation 2010 - Mentor Graphics Corporation - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)

–
End of file - 12478 bytes
Hi wcatanach

Thanks for the logs. There is no need to send more HijackThis logs unless requested.

Please run GMER again, but this time uncheck everything EXCEPT "Sections" and "C:\" .

If it still doesn’t work, try it in safe mode.

Boot to Safe mode with Networking and see if you can then run it

To Enter Safemode• Go to Start> Shut off your Computer> Restart
• As the computer starts to boot-up, Tap the F8 KEY - this will bring up a menu.
• Use the Up and Down Arrow Keys to scroll up to Safemode
• Then press Enter on your keyboard
===================================================

You should finf your Malwarebytes log in the following location:

C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-yyyy-mm-dd

Satchfan
Sections and C:\ checked:

GMER 1.0.15.15572 - http://www.gmer.net
Rootkit scan 2011-05-03 16:28:45
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\CATANA~1\AppData\Local\Temp\pxldipow.sys


—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4268] USER32.dll!TrackPopupMenu 76CD14F3 5 Bytes JMP 61ECC334 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[5564] ntdll.dll!LdrLoadDll 76E893A8 5 Bytes JMP 011413F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[6088] USER32.dll!TrackPopupMenu 76CD14F3 5 Bytes JMP 61ECC334 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

—- EOF - GMER 1.0.15 —-


My dell can't take the heat. I had to put it in the freezer for a while to help it stay cool….

Here is as far as it has gotten when running all the checks except IAT/EAT
GMER 1.0.15.15572 - http://www.gmer.net
Rootkit scan 2011-05-03 16:38:36
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\CATANA~1\AppData\Local\Temp\pxldipow.sys


—- System - GMER 1.0.15 —-

SSDT 87F22118 ZwAlertResumeThread
SSDT 87F221F8 ZwAlertThread
SSDT 87EAF7D8 ZwAllocateVirtualMemory
SSDT 87E2AED0 ZwConnectPort
SSDT 87F4BE20 ZwCreateMutant
SSDT 87F17E48 ZwCreateThread
SSDT 87F4A778 ZwFreeVirtualMemory
SSDT 87F4BF10 ZwImpersonateAnonymousToken
SSDT 87F4BFD0 ZwImpersonateThread
SSDT 87F218D8 ZwMapViewOfSection
SSDT 87F4BD40 ZwOpenEvent
SSDT 8879CF60 ZwOpenProcessToken
SSDT 87F22AC8 ZwOpenThreadToken
SSDT \??\C:\Windows\system32\drivers\wpsdrvnt.sys ZwProtectVirtualMemory [0x92F358B0]
SSDT 87D59758 ZwResumeThread
SSDT 87F22008 ZwSetContextThread
SSDT 87F22BB8 ZwSetInformationProcess
SSDT 87F22500 ZwSetInformationThread
SSDT 87F4BC60 ZwSuspendProcess
SSDT 87F22340 ZwSuspendThread
SSDT 879290E0 ZwTerminateProcess
SSDT 87F22420 ZwTerminateThread
SSDT 87F217F8 ZwUnmapViewOfSection
SSDT 87F4A868 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 11D 820EE8A0 8 Bytes [18, 21, F2, 87, F8, 21, F2, …]
.text ntkrnlpa.exe!KeSetEvent + 131 820EE8B4 4 Bytes [D8, F7, EA, 87]
.text ntkrnlpa.exe!KeSetEvent + 1C1 820EE944 4 Bytes [D0, AE, E2, 87]
.text ntkrnlpa.exe!KeSetEvent + 1F5 820EE978 4 Bytes [20, BE, F4, 87]
.text ntkrnlpa.exe!KeSetEvent + 221 820EE9A4 4 Bytes [48, 7E, F1, 87]
.text …

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4268] USER32.dll!TrackPopupMenu 76CD14F3 5 Bytes JMP 61ECC334 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[5564] ntdll.dll!LdrLoadDll 76E893A8 5 Bytes JMP 011413F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[6088] USER32.dll!TrackPopupMenu 76CD14F3 5 Bytes JMP 61ECC334 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

It is still running but it is taking forever!
Got a blue screen of death. Is there something specific I should run so it can have time to cool down? I can run each check.
Hi wcatanach

I was just about to advise you to stop Gmer and try this:

Scan With RootKitUnHooker
  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.
Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


===================================================

Please send your Malwarebytes log which you’ll find in the following location:

C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-yyyy-mm-dd

===================================================

Can you also clarify what you mean by “Symantec is Auto-protecting”. Do you mean Symantec won’t disinfect them or that it won’t allow Malwarebytes to disinfect them

Satchfan
Here are the results of the Rootkit Unhooker: RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6002 (Service Pack 2) Number of processors #2 ============================================== >Drivers ============================================== 0x8E808000 C:\Windows\system32\DRIVERS\igdkmd32.sys 9428992 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver) 0x82005000 C:\Windows\system32\ntkrnlpa.exe 3907584 bytes (Microsoft Corporation, NT Kernel & System) 0x82005000 PnpManager 3907584 bytes 0x82005000 RAW 3907584 bytes 0x82005000 WMIxWDM 3907584 bytes 0xA0420000 Win32k 2113536 bytes 0xA0420000 C:\Windows\System32\win32k.sys 2113536 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0x8FE01000 C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110503.021\NAVEX15.SYS 1388544 bytes (Symantec Corporation, AV Engine) 0x8F49B000 C:\Windows\system32\DRIVERS\bcmwl6.sys 1343488 bytes (Broadcom Corporation, Broadcom 802.11 Network Adapter wireless driver) 0x8A603000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver) 0x83007000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0x83208000 C:\Windows\System32\drivers\tcpip.sys 970752 bytes (Microsoft Corporation, TCP/IP Driver) 0x804D6000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module) 0xBFC08000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0x83310000 C:\Windows\System32\Drivers\dump_iaStor.sys 851968 bytes 0x8260B000 C:\Windows\system32\drivers\iastor.sys 851968 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32) 0xB780E000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor) 0x8F106000 C:\Windows\System32\drivers\dxgkrnl.sys 655360 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0xBB09E000 C:\Windows\system32\Drivers\CVPNDRVA.sys 589824 bytes (Cisco Systems, Inc., Cisco Systems VPN Client IPSec Driver) 0x8F40E000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0x82726000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0x80601000 C:\Windows\system32\drivers\Wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime) 0x8040C000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library) 0xB7979000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack) 0x8F6F3000 C:\Windows\system32\DRIVERS\stwrt.sys 442368 bytes (IDT, Inc., IDT PC Audio) 0x9B202000 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 434176 bytes (Symantec Corporation, SPBBC Driver) 0x9B2B2000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0xBB037000 C:\Windows\System32\DRIVERS\srv.sys 323584 bytes (Microsoft Corporation, Server driver) 0xA0670000 C:\Windows\System32\ATMFD.DLL 315392 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0x83178000 C:\Windows\system32\DRIVERS\yk60x86.sys 315392 bytes (Marvell, Miniport Driver for Marvell Yukon Ethernet Controller.) 0x8F7B1000 C:\Windows\System32\Drivers\SRTSP.SYS 307200 bytes (Symantec Corporation, Symantec AutoProtect) 0x80729000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x93567000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x80680000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT) 0x93402000 C:\Windows\system32\DRIVERS\OA009Vid.sys 274432 bytes (Creative Technology Ltd., Video Capture Device Driver) 0x82797000 C:\Windows\system32\DRIVERS\Apfiltr.sys 270336 bytes (Alps Electric Co., Ltd., Alps Touch Pad Driver) 0x80495000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver) 0x807B2000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0x8F1BD000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x9B26C000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x8313D000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem) 0x9B3C5000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x8A713000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0x8F6AD000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x823BF000 ACPI_HAL 208896 bytes 0x823BF000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0x826DB000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0x935AF000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x80783000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0x8F75F000 C:\Windows\system32\DRIVERS\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x93518000 C:\Windows\System32\Drivers\SYMTDI.SYS 184320 bytes (Symantec Corporation, Network Dispatch Driver) 0x83112000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0x8F66C000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0xB7932000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0xBFCE6000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xBB00F000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x8A763000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache) 0x806D7000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0x8F78C000 C:\Windows\system32\DRIVERS\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0x8FF54000 C:\Windows\system32\Drivers\SYMEVENT.SYS 151552 bytes (Symantec Corporation, Symantec Event Library) 0x805CD000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x8F648000 C:\Windows\system32\DRIVERS\teefer2.sys 139264 bytes (Symantec Corporation, Symantec CMC Firewall Teefer2) 0x8A79B000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0x9B385000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0x93445000 C:\Windows\system32\DRIVERS\OA009Ufd.sys 135168 bytes (Creative Technology Ltd., Video Class Upper Filter Driver) 0x934AF000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0x831DD000 C:\Windows\system32\DRIVERS\dne2000.sys 126976 bytes (Deterministic Networks, Inc., Deterministic Network Enhancer) 0x9B3A6000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0x9B310000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 118784 bytes (Symantec Corporation, Symantec Eraser Utility Driver) 0xB78BE000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver) 0x832F5000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0x9B36A000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0xB78DB000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x833E0000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xB79E6000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x9B32D000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0x805B6000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0x8FFB7000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xBFD2C000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0x935E1000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler) 0x93502000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver) 0xB78F4000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x8F61C000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0x8FF79000 C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110503.021\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine) 0x8F608000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0x93553000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0x8F5E3000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver) 0xB7966000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x93466000 C:\Windows\system32\drivers\RTSTOR.SYS 77824 bytes (Realtek Semiconductor Corp., Realtek USB Mass Storage Driver for Vista) 0x8FFDC000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x8A78A000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x8F6E2000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0x8047C000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0x8270D000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0x8FF96000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library) 0xB7922000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x80773000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0x8F638000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver) 0x831CE000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver) 0x9B35B000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0x8A754000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0x806FE000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0x805F0000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x8A7F1000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x8071A000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0xA0660000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0x8FFCE000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x934EB000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x80672000 C:\Windows\system32\drivers\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader) 0x93545000 C:\Windows\system32\drivers\wpsdrvnt.sys 57344 bytes (Symantec Corporation, Symantec CMC Firewall WPS) 0x9B344000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x827EF000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver) 0x8F6A0000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0xBFD18000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0x934A3000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0x8F1A6000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver) 0x827D9000 C:\Windows\system32\DRIVERS\dsNcAdpt.sys 45056 bytes (Juniper Networks, dsNcAdapter) 0xB7917000 C:\Windows\system32\DRIVERS\fssfltr.sys 45056 bytes (Microsoft Corporation, Family Safety Filter Driver (WFP Callout)) 0x8A7D2000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver) 0x8F400000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver) 0x934E0000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x82600000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x827E4000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0x8A7DD000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x8F1B2000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0x80710000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver) 0x9B351000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x8F5F6000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 40960 bytes (GEAR Software Inc., CD DVD Filter) 0x8F696000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0xB795C000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0x9B2A8000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0xBFD0E000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0x93479000 C:\Windows\System32\Drivers\SRTSPX.SYS 40960 bytes (Symantec Corporation, Symantec AutoProtect) 0xBFD47000 C:\Windows\system32\DRIVERS\asyncmac.sys 36864 bytes (Microsoft Corporation, MS Remote Access serial network driver) 0x8A7BC000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0x93483000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0x8FF8D000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xBFD50000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0x8271D000 C:\Windows\System32\Drivers\PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0x934F9000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xA0640000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x8A7E8000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x831C5000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0x806C6000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBFD24000 C:\Windows\system32\drivers\BCM42RLY.sys 32768 bytes (Broadcom Corporation, Broadcom iLine10™ PCI Network Adapter Proxy Protocol Driver) 0x8048D000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x8FFAF000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0x806CF000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x934D0000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x934D8000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x8E800000 C:\Windows\System32\Drivers\RootMdm.sys 32768 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver) 0x8A74C000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0x93493000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0x8FFA6000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0x80405000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0x9348C000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x8F631000 C:\Windows\system32\DRIVERS\RimSerial.sys 28672 bytes (Research in Motion Ltd, RIM Virtual Serial Driver) 0xBFD42000 C:\Windows\System32\Drivers\SYMREDRV.SYS 20480 bytes (Symantec Corporation, Redirector Filter Driver) 0x8F1FB000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0x8070D000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0x8F66A000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0x8FFAD000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) ============================================== >Stealth ============================================== 0x65650000 Hidden Image–>System.Runtime.Serialization.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 1196032 bytes 0x66EA0000 Hidden Image–>System.ServiceModel.Web.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 143360 bytes 0x63550000 Hidden Image–>System.Core.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 2375680 bytes 0x01C50000 Hidden Image–>msvcm90.dll [ EPROCESS 0x88CBC330 ] PID: 1852, 270336 bytes 0x02340000 Hidden Image–>msvcm90.dll [ EPROCESS 0x851A0550 ] PID: 2916, 270336 bytes 0x032D0000 Hidden Image–>log4net.dll [ EPROCESS 0x857828B8 ] PID: 6036, 282624 bytes 0x01C30000 Hidden Image–>SupportSoft.Agent.Sprocket.dll [ EPROCESS 0x850E05D0 ] PID: 3304, 28672 bytes 0x6B790000 Hidden Image–>System.Windows.Browser.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 380928 bytes 0x05AD0000 Hidden Image–>WLTRAY.EXE [ EPROCESS 0x88CBC330 ] PID: 1852, 4231168 bytes 0x61E70000 Hidden Image–>System.Windows.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 4493312 bytes 0x01B90000 Hidden Image–>SupportSoft.Agent.Sprocket.SupportMessage.dll [ EPROCESS 0x850E05D0 ] PID: 3304, 45056 bytes 0x622C0000 Hidden Image–>mscorlib.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 6197248 bytes 0x66D90000 Hidden Image–>System.Net.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 659456 bytes 0x6B6E0000 Hidden Image–>System.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 671744 bytes 0x01CA0000 Hidden Image–>bcmwlrmt.dll [ EPROCESS 0x88CBC330 ] PID: 1852, 77824 bytes 0x015D0000 Hidden Image–>sprtmessage.dll [ EPROCESS 0x850E05D0 ] PID: 3304, 77824 bytes 0x024B0000 Hidden Image–>bcmwlrmt.dll [ EPROCESS 0x851A0550 ] PID: 2916, 77824 bytes 0x65780000 Hidden Image–>System.Xml.ni.dll [ EPROCESS 0x864A8020 ] PID: 5348, 847872 bytes 0x047F0000 Hidden Image–>System.Data.SQLite.DLL [ EPROCESS 0x857828B8 ] PID: 6036, 872448 bytes !!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)
Hi Satchfan, Where did you get that name? Symantic is identifying risks: Trojan.Gen and quarantining the DWH####.tmp files found in C:\Users\Catanachs\AppData\Local\Temp\ There isn't a folder: C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-yyyy-mm-dd. Not sure if it got deleted when I uninstalled it or if I deleted the folders. Sorry, I know this may have shed some light on the infections. I do remember MTCmakeMeSearchcom that Spybot found. I ran Spybot after Malwarebytes. Here is the first Spybot log: — Report generated: 2011-04-29 08:45 — MTC.MakeMeSearch.com: [SBI $EF0EE69A] Uninstall settings (Registry key, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Toolbar MTC.MakeMeSearch.com: [SBI $EF0EE69A] Uninstall settings (Registry key, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Toolbar DoubleClick: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) MediaPlex: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) MediaPlex: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) MediaPlex: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) MediaPlex: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) CasaleMedia: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) CasaleMedia: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) CasaleMedia: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) CasaleMedia: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) CasaleMedia: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) FastClick: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) FastClick: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) FastClick: Tracking cookie (Firefox: Catanachs (default)) (Cookie, nothing done) DoubleClick: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) Zedo: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) Zedo: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) Zedo: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) Clickbank: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) Statcounter: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) MediaPlex: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) MediaPlex: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) MediaPlex: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) Right Media: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) Zedo: Tracking cookie (Chrome: Chrome) (Cookie, nothing done) — Spybot - Search & Destroy version: 1.6.2 (build: 20090126) — 2009-01-26 blindman.exe (1.0.0.8) 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SDWinSec.exe (1.0.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-01-26 TeaTimer.exe ([removed]) 2011-04-29 unins000.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll ([removed]) 2007-04-02 aports.dll (2.1.0.0) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2011-03-18 Includes\Adware.sbi (*) 2011-03-22 Includes\AdwareC.sbi (*) 2010-08-13 Includes\Cookies.sbi (*) 2010-12-14 Includes\Dialer.sbi (*) 2011-03-08 Includes\DialerC.sbi (*) 2011-02-24 Includes\HeavyDuty.sbi (*) 2011-03-29 Includes\Hijackers.sbi (*) 2011-03-29 Includes\HijackersC.sbi (*) 2010-09-15 Includes\iPhone.sbi (*) 2010-12-14 Includes\Keyloggers.sbi (*) 2011-03-08 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2011-04-05 Includes\Malware.sbi (*) 2011-04-26 Includes\MalwareC.sbi (*) 2011-02-24 Includes\PUPS.sbi (*) 2011-03-15 Includes\PUPSC.sbi (*) 2010-01-25 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2011-03-08 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2011-02-24 Includes\Spyware.sbi (*) 2011-03-15 Includes\SpywareC.sbi (*) 2010-03-08 Includes\Tracks.uti 2010-12-28 Includes\Trojans.sbi (*) 2011-04-26 Includes\TrojansC-02.sbi (*) 2011-04-26 Includes\TrojansC-03.sbi (*) 2011-04-18 Includes\TrojansC-04.sbi (*) 2011-04-26 Includes\TrojansC-05.sbi (*) 2011-03-08 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll Thank you for helping!
Hi Satchfan, I didn't even know how/when the registry boosters were installed. How do I uninstall the registry boosters? Thank you.
Hi wcatanach

Where did you get that name?

Guitarist, Joe Satriani’s nickname.

===================================================

I didn't even know how/when the registry cleaners were installed. How do I uninstall the registry cleaners?

C:\Program Files\Uniblue\RegistryBooster

To remove it:click Start, Control Panel, Programs, and then Programs and Features.
click on Uniblue and then Uninstall.
===================================================

Download and run ComboFix

Download Combofix from either of the links below. You must rename it to 123 before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
  • Double click on the renamed ComboFix.exe & follow the prompts.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt in your next reply.

Satchfan
I've already looked in the program folders and control panel programs for Uniblue and Registry booster. None found. Is it gone from my system?
I doubt it has just disappeared. Don't worry bout that now, if it shows up we can deal with it later. Please follow the ComboFix instructions SF

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI