This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

virusm or something

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! yesterday when I turn on my laptop was the the black bacground and windows try to check my system about harddisk, ram… then I restore my system to an earlier date, but thisthing was not good. All my documents and all files on my usb disk was became hidden. Then I install the ESET NOD 32 Antivirus and it displaying me all the time in red field in right corner FILE C:WINDOWS\System32\Drivers\volsnap.sys Win32/Olmasco.E trojan information cleaning not done How to clean this stuff from my laptop? and how to make these files (which were hidden) make it unhidden? oh and on my internet explorer all favorite pages are gone, is any chance to get them back?
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Having said that….Let's get going!! :thumbup:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
I have windows XP service pack 3 Oh and voice/sound on web pages are gone on Internet Explorer on Firefox browser is everythink ok!
Hi Avtovleka,

Lets get going. :)

Please read carefully and follow these steps.
———-

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

In your next reply please post the logs created by both TDSSKiller and both logs from DDS. :)
I have done all this… TDDS killer report: 2011/06/07 20:06:12.0609 1392 TDSS rootkit removing tool 2.5.4.0 Jun 7 2011 17:31:48 2011/06/07 20:06:12.0781 1392 ================================================================================ 2011/06/07 20:06:12.0781 1392 SystemInfo: 2011/06/07 20:06:12.0781 1392 2011/06/07 20:06:12.0781 1392 OS Version: 5.1.2600 ServicePack: 3.0 2011/06/07 20:06:12.0781 1392 Product type: Workstation 2011/06/07 20:06:12.0781 1392 ComputerName: LUKEZ 2011/06/07 20:06:12.0781 1392 UserName: xp 2011/06/07 20:06:12.0781 1392 Windows directory: C:\WINDOWS 2011/06/07 20:06:12.0781 1392 System windows directory: C:\WINDOWS 2011/06/07 20:06:12.0781 1392 Processor architecture: Intel x86 2011/06/07 20:06:12.0781 1392 Number of processors: 2 2011/06/07 20:06:12.0781 1392 Page size: 0x1000 2011/06/07 20:06:12.0781 1392 Boot type: Normal boot 2011/06/07 20:06:12.0781 1392 ================================================================================ 2011/06/07 20:06:14.0171 1392 Initialize success 2011/06/07 20:06:28.0250 4040 ================================================================================ 2011/06/07 20:06:28.0250 4040 Scan started 2011/06/07 20:06:28.0250 4040 Mode: Manual; 2011/06/07 20:06:28.0250 4040 ================================================================================ 2011/06/07 20:06:29.0875 4040 Accelerometer (a0baabb7d3549460e3f8c5ad6f778683) C:\WINDOWS\system32\DRIVERS\Accelerometer.sys 2011/06/07 20:06:29.0921 4040 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/06/07 20:06:29.0984 4040 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 2011/06/07 20:06:30.0046 4040 adatadrv (5ee8aaa16951e46d197392ba6f2402ea) C:\WINDOWS\system32\DRIVERS\adatadrv.sys 2011/06/07 20:06:30.0125 4040 ADIHdAudAddService (7214d020d546351cac03e051b284d9e9) C:\WINDOWS\system32\drivers\ADIHdAud.sys 2011/06/07 20:06:30.0187 4040 AEAudio (fff87a9b1ab36ee4b7bec98a4cb01b79) C:\WINDOWS\system32\drivers\AEAudio.sys 2011/06/07 20:06:30.0218 4040 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/06/07 20:06:30.0265 4040 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys 2011/06/07 20:06:30.0359 4040 AgereSoftModem (35c391e40471a0b479328fc7b1b5f40f) C:\WINDOWS\system32\DRIVERS\AGRSM.sys 2011/06/07 20:06:30.0562 4040 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/06/07 20:06:30.0578 4040 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/06/07 20:06:30.0750 4040 ati2mtag (81c3e6674d0609aa84c07681bca252de) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/06/07 20:06:30.0812 4040 AtiHdmiService (1e82f05cff41316bcaa513909d99a004) C:\WINDOWS\system32\drivers\AtiHdmi.sys 2011/06/07 20:06:30.0843 4040 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/06/07 20:06:30.0906 4040 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/06/07 20:06:31.0000 4040 BCM43XX (911439d49dc396a2bf0f595a703759d6) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 2011/06/07 20:06:31.0140 4040 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/06/07 20:06:31.0187 4040 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 2011/06/07 20:06:31.0203 4040 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 2011/06/07 20:06:31.0281 4040 btaudio (4b43dfe1c1fbb305a1dc5504ef9bb34e) C:\WINDOWS\system32\drivers\btaudio.sys 2011/06/07 20:06:31.0296 4040 BTDriver (2f9f111d31aa3fbbe5781d829a4524e6) C:\WINDOWS\system32\DRIVERS\btport.sys 2011/06/07 20:06:31.0390 4040 BTKRNL (ed0bd05be3c494a8fec0674880d5bc4d) C:\WINDOWS\system32\DRIVERS\btkrnl.sys 2011/06/07 20:06:31.0421 4040 BTWDNDIS (485020a1e1fc5c51a800ca69c618d881) C:\WINDOWS\system32\DRIVERS\btwdndis.sys 2011/06/07 20:06:31.0453 4040 btwhid (949eca9c56f657c06d3166d51f3226c7) C:\WINDOWS\system32\DRIVERS\btwhid.sys 2011/06/07 20:06:31.0546 4040 btwmodem (5922bae0cd84924b9cd7e6bb515ee070) C:\WINDOWS\system32\DRIVERS\btwmodem.sys 2011/06/07 20:06:31.0562 4040 BTWUSB (6b622612fe21b59faee2ca4385959778) C:\WINDOWS\system32\Drivers\btwusb.sys 2011/06/07 20:06:31.0625 4040 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/06/07 20:06:31.0656 4040 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/06/07 20:06:31.0718 4040 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/06/07 20:06:31.0734 4040 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/06/07 20:06:31.0796 4040 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/06/07 20:06:31.0843 4040 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 2011/06/07 20:06:31.0875 4040 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 2011/06/07 20:06:32.0546 4040 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/06/07 20:06:32.0593 4040 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/06/07 20:06:32.0625 4040 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/06/07 20:06:32.0656 4040 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/06/07 20:06:32.0687 4040 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/06/07 20:06:32.0734 4040 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/06/07 20:06:32.0765 4040 eamon (d42dd9021acd47683b33adf21bca49aa) C:\WINDOWS\system32\DRIVERS\eamon.sys 2011/06/07 20:06:32.0828 4040 ehdrv (fe7824239d132ad9ebd8645fe1199b30) C:\WINDOWS\system32\DRIVERS\ehdrv.sys 2011/06/07 20:06:32.0875 4040 epfwtdir (aa0667eb9a92414abb784c101a6c7fec) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys 2011/06/07 20:06:32.0906 4040 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/06/07 20:06:32.0937 4040 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 2011/06/07 20:06:32.0968 4040 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/06/07 20:06:32.0984 4040 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 2011/06/07 20:06:33.0015 4040 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/06/07 20:06:33.0078 4040 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/06/07 20:06:33.0125 4040 FTDIBUS (7d1a4851c3daa76b0b82af5f73479e8c) C:\WINDOWS\system32\drivers\ftdibus.sys 2011/06/07 20:06:33.0140 4040 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/06/07 20:06:33.0187 4040 FTSER2K (90570ec16c55548e3565ac8599939063) C:\WINDOWS\system32\drivers\ftser2k.sys 2011/06/07 20:06:33.0218 4040 ggflt (007aea2e06e7cef7372e40c277163959) C:\WINDOWS\system32\DRIVERS\ggflt.sys 2011/06/07 20:06:33.0250 4040 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\WINDOWS\system32\DRIVERS\ggsemc.sys 2011/06/07 20:06:33.0296 4040 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/06/07 20:06:33.0359 4040 Hardlock (d95554949082fd29a04d351b58396718) C:\WINDOWS\system32\drivers\hardlock.sys 2011/06/07 20:06:33.0421 4040 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/06/07 20:06:33.0437 4040 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/06/07 20:06:33.0515 4040 hpdskflt (9f620e11b80b74f4dab50a81a5df357f) C:\WINDOWS\system32\DRIVERS\hpdskflt.sys 2011/06/07 20:06:33.0593 4040 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys 2011/06/07 20:06:33.0656 4040 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 2011/06/07 20:06:33.0671 4040 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 2011/06/07 20:06:33.0703 4040 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 2011/06/07 20:06:33.0750 4040 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/06/07 20:06:33.0796 4040 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/06/07 20:06:33.0828 4040 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/06/07 20:06:33.0921 4040 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/06/07 20:06:33.0937 4040 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/06/07 20:06:33.0953 4040 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/06/07 20:06:34.0000 4040 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/06/07 20:06:34.0015 4040 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/06/07 20:06:34.0046 4040 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/06/07 20:06:34.0062 4040 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/06/07 20:06:34.0078 4040 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/06/07 20:06:34.0140 4040 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/06/07 20:06:34.0171 4040 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/06/07 20:06:34.0218 4040 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/06/07 20:06:34.0312 4040 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\WINDOWS\system32\DRIVERS\mcdbus.sys 2011/06/07 20:06:34.0375 4040 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/06/07 20:06:34.0390 4040 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/06/07 20:06:34.0437 4040 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/06/07 20:06:34.0453 4040 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/06/07 20:06:34.0500 4040 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/06/07 20:06:34.0515 4040 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/06/07 20:06:34.0593 4040 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/06/07 20:06:34.0640 4040 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/06/07 20:06:34.0656 4040 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/06/07 20:06:34.0671 4040 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/06/07 20:06:34.0687 4040 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/06/07 20:06:34.0781 4040 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/06/07 20:06:34.0796 4040 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/06/07 20:06:34.0812 4040 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/06/07 20:06:34.0843 4040 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/06/07 20:06:34.0859 4040 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/06/07 20:06:34.0875 4040 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/06/07 20:06:34.0906 4040 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/06/07 20:06:34.0921 4040 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/06/07 20:06:34.0953 4040 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/06/07 20:06:35.0015 4040 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/06/07 20:06:35.0046 4040 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/06/07 20:06:35.0062 4040 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/06/07 20:06:35.0125 4040 NetworkX (598d2f0176b169118f025f3ed6444d16) C:\WINDOWS\system32\ckldrv.sys 2011/06/07 20:06:35.0187 4040 nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\WINDOWS\system32\drivers\ccdcmb.sys 2011/06/07 20:06:35.0218 4040 nmwcdc (3859c69a77793180548802dac9f34a38) C:\WINDOWS\system32\drivers\ccdcmbo.sys 2011/06/07 20:06:35.0265 4040 nmwcdnsu (338f83ee9cb9e15eeacf0cbb90218cbf) C:\WINDOWS\system32\drivers\nmwcdnsu.sys 2011/06/07 20:06:35.0281 4040 nmwcdnsuc (d15bac979144fb69ed28f97b2dd84d48) C:\WINDOWS\system32\drivers\nmwcdnsuc.sys 2011/06/07 20:06:35.0296 4040 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/06/07 20:06:35.0343 4040 NSHE (f8e396f5e703d7a8f37d90f59c776268) C:\WINDOWS\system32\Drivers\NSHE.SYS 2011/06/07 20:06:35.0390 4040 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/06/07 20:06:35.0453 4040 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/06/07 20:06:35.0515 4040 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/06/07 20:06:35.0531 4040 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/06/07 20:06:35.0562 4040 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 2011/06/07 20:06:35.0593 4040 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/06/07 20:06:35.0609 4040 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/06/07 20:06:35.0640 4040 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys 2011/06/07 20:06:35.0656 4040 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/06/07 20:06:35.0703 4040 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/06/07 20:06:35.0718 4040 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/06/07 20:06:35.0843 4040 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/06/07 20:06:35.0875 4040 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/06/07 20:06:35.0921 4040 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/06/07 20:06:36.0046 4040 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/06/07 20:06:36.0062 4040 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/06/07 20:06:36.0093 4040 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/06/07 20:06:36.0125 4040 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/06/07 20:06:36.0156 4040 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/06/07 20:06:36.0187 4040 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/06/07 20:06:36.0218 4040 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/06/07 20:06:36.0281 4040 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/06/07 20:06:36.0343 4040 s0016bus (59509ad6cbc28f2c73056268985b3e48) C:\WINDOWS\system32\DRIVERS\s0016bus.sys 2011/06/07 20:06:36.0359 4040 s0016mdfl (b98c3a6f91f4fba285af9606a240c6b4) C:\WINDOWS\system32\DRIVERS\s0016mdfl.sys 2011/06/07 20:06:36.0375 4040 s0016mdm (8a83426f4fb7b5212825d9de76368b1a) C:\WINDOWS\system32\DRIVERS\s0016mdm.sys 2011/06/07 20:06:36.0390 4040 s0016mgmt (7a78bba97feb5e6d24c49e93a3bf7287) C:\WINDOWS\system32\DRIVERS\s0016mgmt.sys 2011/06/07 20:06:36.0406 4040 s0016nd5 (34ef7b5f611957b73e7219dd5a222ad1) C:\WINDOWS\system32\DRIVERS\s0016nd5.sys 2011/06/07 20:06:36.0421 4040 s0016obex (36792935847143e4a3cda0dc87248487) C:\WINDOWS\system32\DRIVERS\s0016obex.sys 2011/06/07 20:06:36.0453 4040 s0016unic (927208754fb27fc3e7a659e77500c5d1) C:\WINDOWS\system32\DRIVERS\s0016unic.sys 2011/06/07 20:06:36.0484 4040 s1039bus (20eb79fd0a13a18b70b6731a1285ca94) C:\WINDOWS\system32\DRIVERS\s1039bus.sys 2011/06/07 20:06:36.0515 4040 s1039mdfl (58780c6c3ad51da84b57d6ae42dc49ca) C:\WINDOWS\system32\DRIVERS\s1039mdfl.sys 2011/06/07 20:06:36.0531 4040 s1039mdm (1ff8b42d1346133a945b52876376ed40) C:\WINDOWS\system32\DRIVERS\s1039mdm.sys 2011/06/07 20:06:36.0593 4040 s1039mgmt (f64c13c549cb4732fe99c771fa35d038) C:\WINDOWS\system32\DRIVERS\s1039mgmt.sys 2011/06/07 20:06:36.0640 4040 s1039nd5 (ec22d9baa464a892c0637982b67292e6) C:\WINDOWS\system32\DRIVERS\s1039nd5.sys 2011/06/07 20:06:36.0656 4040 s1039obex (69e9ce002e7249e61ff2ea1336c71d89) C:\WINDOWS\system32\DRIVERS\s1039obex.sys 2011/06/07 20:06:36.0671 4040 s1039unic (482dfb3721a0de11cc22b439d17c348c) C:\WINDOWS\system32\DRIVERS\s1039unic.sys 2011/06/07 20:06:36.0718 4040 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/06/07 20:06:36.0781 4040 seehcri (e5b56569a9f79b70314fede6c953641e) C:\WINDOWS\system32\DRIVERS\seehcri.sys 2011/06/07 20:06:36.0843 4040 Sentinel (a2cc81c30bef6ac9f27055490eef6de3) C:\WINDOWS\System32\Drivers\SENTINEL.SYS 2011/06/07 20:06:36.0859 4040 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/06/07 20:06:36.0890 4040 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 2011/06/07 20:06:36.0953 4040 SFAUDIO (b6401608579b6431994425ba7653f774) C:\WINDOWS\system32\drivers\sfaudio.sys 2011/06/07 20:06:36.0968 4040 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/06/07 20:06:37.0000 4040 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/06/07 20:06:37.0093 4040 SNP2UVC (6ce01f8c131f6754cf3ef3f97ac31ec6) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys 2011/06/07 20:06:37.0156 4040 SNTNLUSB (9de6e60ce7fd82b4985de5d9c22265ad) C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS 2011/06/07 20:06:37.0218 4040 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 2011/06/07 20:06:37.0281 4040 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/06/07 20:06:37.0359 4040 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys 2011/06/07 20:06:37.0359 4040 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 2011/06/07 20:06:37.0375 4040 sptd - detected LockedFile.Multi.Generic (1) 2011/06/07 20:06:37.0421 4040 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/06/07 20:06:37.0453 4040 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/06/07 20:06:37.0484 4040 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/06/07 20:06:37.0500 4040 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/06/07 20:06:37.0531 4040 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/06/07 20:06:37.0656 4040 SynTP (5c3e900f41426a372de60675afc8aa07) C:\WINDOWS\system32\DRIVERS\SynTP.sys 2011/06/07 20:06:37.0671 4040 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/06/07 20:06:37.0750 4040 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/06/07 20:06:37.0765 4040 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/06/07 20:06:37.0781 4040 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/06/07 20:06:37.0796 4040 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/06/07 20:06:37.0890 4040 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/06/07 20:06:37.0968 4040 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/06/07 20:06:38.0031 4040 upperdev (0ccadc7391021376edbb8aa649d04e68) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys 2011/06/07 20:06:38.0062 4040 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/06/07 20:06:38.0109 4040 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/06/07 20:06:38.0156 4040 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/06/07 20:06:38.0171 4040 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/06/07 20:06:38.0218 4040 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/06/07 20:06:38.0281 4040 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys 2011/06/07 20:06:38.0328 4040 UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys 2011/06/07 20:06:38.0375 4040 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/06/07 20:06:38.0390 4040 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/06/07 20:06:38.0453 4040 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 2011/06/07 20:06:38.0484 4040 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/06/07 20:06:38.0531 4040 VolSnap (7c38f81f40d61d1607ddb62fe5817bb9) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/06/07 20:06:38.0531 4040 Suspicious file (NoAccess): C:\WINDOWS\system32\drivers\VolSnap.sys. md5: 7c38f81f40d61d1607ddb62fe5817bb9 2011/06/07 20:06:38.0531 4040 VolSnap - detected Rootkit.Win32.TDSS.tdl3 (0) 2011/06/07 20:06:38.0625 4040 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/06/07 20:06:38.0687 4040 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys 2011/06/07 20:06:38.0734 4040 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/06/07 20:06:38.0781 4040 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 2011/06/07 20:06:38.0828 4040 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2011/06/07 20:06:38.0843 4040 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/06/07 20:06:38.0906 4040 WudfPf (6ff66513d372d479ef1810223c8d20ce) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/06/07 20:06:38.0921 4040 WudfRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/06/07 20:06:38.0984 4040 yukonwxp (d57a909f1a9114d5d18a2eacb1afecd5) C:\WINDOWS\system32\DRIVERS\yk51x86.sys 2011/06/07 20:06:39.0046 4040 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 2011/06/07 20:06:39.0250 4040 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR2 2011/06/07 20:06:39.0265 4040 ================================================================================ 2011/06/07 20:06:39.0265 4040 Scan finished 2011/06/07 20:06:39.0265 4040 ================================================================================ 2011/06/07 20:06:39.0281 2392 Detected object count: 2 2011/06/07 20:06:39.0281 2392 Actual detected object count: 2 2011/06/07 20:07:25.0218 2392 LockedFile.Multi.Generic(sptd) - User select action: Skip 2011/06/07 20:07:25.0375 2392 VolSnap (7c38f81f40d61d1607ddb62fe5817bb9) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/06/07 20:07:25.0375 2392 Suspicious file (NoAccess): C:\WINDOWS\system32\drivers\VolSnap.sys. md5: 7c38f81f40d61d1607ddb62fe5817bb9 2011/06/07 20:07:28.0312 2392 Backup copy not found, trying to cure infected file.. 2011/06/07 20:07:28.0312 2392 Cure success, using it.. 2011/06/07 20:07:28.0515 2392 C:\WINDOWS\system32\drivers\VolSnap.sys - will be cured after reboot 2011/06/07 20:07:28.0515 2392 Rootkit.Win32.TDSS.tdl3(VolSnap) - User select action: Cure 2011/06/07 20:07:46.0140 2356 Deinitialize success dds report: . DDS (Ver_2011-06-03.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22 Run by [removed] at 20:32:06 on 2011-06-07 Microsoft Windows XP Home Edition 5.1.2600.3.1250.386.1033.18.3036.2380 [GMT 2:00] . AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe C:\WINDOWS\System32\svchost.exe -k eapsvcs svchost.exe C:\WINDOWS\System32\svchost.exe -k dot3svc C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe svchost.exe C:\WINDOWS\system32\YHF\QJTN.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\LSI SoftModem\agrsmsvc.exe C:\WINDOWS\system32\crypserv.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\WINDOWS\system32\svchost.exe -k HPService C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.siol.net/ uInternet Connection Wizard,ShellNext = iexplore mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Windows Live - Pomoc pri vpisu: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: {00000000-0000-0000-0000-000000000000} - No File uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [RGSC] c:\program files\rockstar games\rockstar games social club\RGSCLauncher.exe /silent uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray uRun: [xydzu] c:\windows\system32\mhyytkkf.exe uRun: [gbwxc81] c:\windows\system32\q1h703o1.exe uRun: [injee] c:\windows\system32\bxnnjzzvll.exe uRun: [hcdyuu] c:\windows\system32\k9g1cyytkk.exe uRun: [hyytk] c:\windows\system32\bxnnjzzvll.exe uRun: [pplbbx] c:\windows\system32\ojaavmmhyy.exe uRun: [efawwr] c:\windows\system32\3ggbssn.exe uRun: [jkplgg6] c:\windows\system32\sneezqqlcc.exe uRun: [jeeaqq] c:\windows\system32\i6uu6gg6.exe uRun: [pkk6w] c:\windows\system32\oojaavmmhy.exe uRun: [lgg6s] c:\windows\system32\0ccxooj.exe uRun: [bchdyy6] c:\windows\system32\6cc6oo6.exe uRun: [lgccxo] c:\windows\system32\70hdd2j.exe uRun: [rmnie] c:\windows\system32\1miiduu.exe uRun: [tkkfw] c:\windows\system32\0aavmm9.exe uRun: [lgccxoo] c:\windows\system32\zzvllhxxtjj.exe uRun: [oojaa] c:\windows\system32\dzpplbbx.exe uRun: [kvwrh] c:\windows\system32\ozavlmhxyt.exe uRun: [ares] "c:\program files\ares\Ares.exe" -h mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QJTN Agent] c:\windows\system32\yhf\QJTN.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray mRunServices: [DRam prosessor] msconfig.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRun: [Nokia.PCSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog StartupFolder: c:\docume~1\xp\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: Free YouTube Download - c:\documents and settings\xp\application data\dvdvideosoftiehelpers\freeyoutubedownload.htm IE: Free YouTube to Mp3 Converter - c:\documents and settings\xp\application data\dvdvideosoftiehelpers\youtubetomp3.htm IE: Google Sidewiki … - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: I&zvozi v Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.mascus.si/imageUploader/ImageUploader6.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} - hxxps://asp.photoprintit.de/microsite/defaults/activex/ips/IPSUploader4.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{C4F9C734-204E-4918-9F36-4CCECBAE4472} : DhcpNameServer = 192.168.0.1 Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - BrotherSoft Extreme Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2776682&SearchSource=13 FF - component: c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}\components\FFExternalAlert.dll FF - component: c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}\components\RadioWMPCore.dll FF - component: c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll FF - component: c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: BrotherSoft Extreme Community Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - %profile%\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13} FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff . ============= SERVICES / DRIVERS =============== . R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [2010-1-25 24064] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-12-21 115008] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-12-21 94872] R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2011-1-12 810144] R2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [2010-1-31 97792] R3 adatadrv;Autodata Protection Service;c:\windows\system32\drivers\adatadrv.sys [2011-2-27 762112] R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2010-8-17 222512] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-5-8 27632] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2010-5-8 13224] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-11-5 137344] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-11-5 8320] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2010-11-8 89256] S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2010-11-8 15016] S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2010-11-8 120744] S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2010-11-8 114216] S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2010-11-8 25512] S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2010-11-8 110632] S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2010-11-8 115752] S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [2010-11-2 98672] S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [2010-11-2 14960] S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [2010-11-2 124016] S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [2010-11-2 117872] S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [2010-11-2 25456] S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [2010-11-2 113904] S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [2010-11-2 123504] . =============== Created Last 30 ================ . 2011-06-05 07:35:56 ——– d—–w- c:\documents and settings\xp\application data\ActiveState 2011-06-05 07:23:21 ——– d—–w- c:\program files\ActiveState Perl Dev Kit 9.0.1 2011-06-04 17:57:50 ——– d—–w- c:\documents and settings\xp\local settings\application data\BVRP Software 2011-06-04 17:51:34 ——– d—–w- c:\windows\system32\wbem\repository\FS 2011-06-04 17:51:34 ——– d—–w- c:\windows\system32\wbem\Repository 2011-06-04 17:28:51 ——– d—–w- c:\program files\ESET . ==================== Find3M ==================== . 2011-06-07 18:11:09 52352 —-a-w- c:\windows\system32\drivers\volsnap.sys 2011-04-06 19:28:02 91376 —-a-w- c:\windows\system32\bcmwlcoi.dll 2011-04-06 19:28:02 1735296 —-a-w- c:\windows\system32\drivers\BCMWL5.SYS 2011-03-29 05:50:16 14 —-a-w- c:\windows\system32\systeminfo.dll . ============= FINISH: 20:33:11,20 =============== I have 2 problems more, 1. my laptop doesn't want to shut down or hibernate, everytime stopped somwhere in the middle of process and then i have to pres turn off swich. every time when I turn on this laptop I get the message that ATI Catalyst Control Center have to be closed. I try to install it or repair it but the problem is still the same. Thanks!

Attachments:

Hi Avtovleka,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

In your next reply please post the log created by ComboFix. :)
Hi Avtovleka,

In your next reply please just copy/paste the logs instead of attaching them as it makes it easier to read for me. Thank you. :)

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :file
    C:\msconfig.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
———-

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DDS:
mRunServices: [DRam prosessor] msconfig.exe

Firefox::
FF - ProfilePath - c:\documents and settings\xp\Application Data\Mozilla\Firefox\Profiles\w5g1xhcw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2776682&SearchSource=13


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


In your next reply please post the logs created by SystemLook and Combofix. :)
Hi!
SystemLook report

SystemLook 04.09.10 by jpshortstuff
Log created at 20:50 on 09/06/2011 by xp
Administrator - Elevation successful

========== file ==========

C:\msconfig.exe - Unable to find/read file.

-= EOF =-


combofix


ComboFix 11-06-09.03 - xp 09.06.2011 21:02:23.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.386.1033.18.3036.2416 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\xp\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-05-09 to 2011-06-09 )))))))))))))))))))))))))))))))
.
.
2011-06-08 05:51 . 2011-06-08 05:51 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-06-08 05:51 . 2011-06-08 05:51 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-06-08 05:51 . 2011-06-08 05:51 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-06-08 05:51 . 2011-06-08 05:51 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-06-08 05:51 . 2011-06-08 05:51 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-06-08 05:50 . 2011-06-08 05:50 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-06-08 05:50 . 2011-06-08 05:50 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-06-08 05:50 . 2011-06-08 05:50 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-06-05 07:35 . 2011-06-05 07:36 ——– d—–w- c:\documents and settings\xp\Application Data\ActiveState
2011-06-05 07:23 . 2011-06-05 07:23 ——– d—–w- c:\program files\ActiveState Perl Dev Kit 9.0.1
2011-06-04 17:57 . 2011-06-04 17:57 ——– d—–w- c:\documents and settings\xp\Local Settings\Application Data\BVRP Software
2011-06-04 17:51 . 2011-06-04 17:51 ——– d—–w- c:\windows\system32\wbem\Repository
2011-06-04 17:28 . 2011-06-04 17:28 ——– d—–w- c:\program files\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-06 19:28 . 2011-04-06 19:27 91376 —-a-w- c:\windows\system32\bcmwlcoi.dll
2011-04-06 19:28 . 2010-01-25 14:23 1735296 —-a-w- c:\windows\system32\drivers\BCMWL5.SYS
2011-06-08 05:50 . 2011-06-08 05:50 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"RGSC"="c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2010-02-08 306088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-03-10 506936]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-02-18 177720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-01-16 1044480]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\xp\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-1-27 576000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\SIERRA\\Empire Earth\\Empire Earth.exe"=
"c:\\Documents and Settings\\xp\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed™ Hot Pursuit\\Launcher.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed™ Hot Pursuit\\NFS11.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=
"c:\\Program Files\\EA Sports\\FIFA 11\\Game\\fifa.exe"=
"c:\\Program Files\\Electronic Arts\\SHIFT 2 UNLEASHED\\shift2u.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"427:UDP"= 427:UDP:SLP_Port(427)
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [25.1.2010 16:02 24064]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31.1.2010 15:35 691696]
R2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [31.1.2010 15:54 97792]
R3 adatadrv;Autodata Protection Service;c:\windows\system32\drivers\adatadrv.sys [27.2.2011 16:41 762112]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [17.8.2010 21:46 222512]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [8.5.2010 16:30 27632]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [8.5.2010 16:30 13224]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [5.11.2010 0:23 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [5.11.2010 0:23 8320]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [8.11.2010 21:00 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [8.11.2010 21:00 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [8.11.2010 21:00 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [8.11.2010 21:00 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [8.11.2010 21:00 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [8.11.2010 21:00 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [8.11.2010 21:00 115752]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [2.11.2010 20:59 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [2.11.2010 20:59 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [2.11.2010 20:59 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [2.11.2010 20:59 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [2.11.2010 20:59 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [2.11.2010 20:59 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [2.11.2010 20:59 123504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-01-09 14:28 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.siol.net/
uInternet Connection Wizard,ShellNext = iexplore
IE: Free YouTube Download - c:\documents and settings\xp\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\xp\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki … - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: I&zvozi v Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.mascus.si/imageUploader/ImageUploader6.cab
FF - ProfilePath - c:\documents and settings\xp\Application Data\Mozilla\Firefox\Profiles\w5g1xhcw.default\
FF - prefs.js: browser.search.selectedEngine - BrotherSoft Extreme Customized Web Search
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-09 21:12
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2216)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-06-09 21:13:53
ComboFix-quarantined-files.txt 2011-06-09 19:13
ComboFix2.txt 2011-06-08 18:48
.
Pre-Run: 35.493.576.704 bytes free
Post-Run: 35.494.461.440 prosto bajtov
.
- - End Of File - - 1EB0C4CC4D081920293026B1715DAC66
Hi Avtovleka,

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    msconfig.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
———-

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/

In your next reply please post the logs created by SystemLook, Malwarebytes and ESET Online scan as well as let me know how your system is running now. :)
system look report SystemLook 04.09.10 by jpshortstuff Log created at 21:51 on 11/06/2011 by xp Administrator - Elevation successful ========== filefind ========== Searching for "msconfig.exe" C:\WINDOWS\$NtServicePackUninstall$\msconfig.exe —–c- 158208 bytes [21:37 26/01/2010] [12:00 28/02/2006] 4FD22142F54692463A7B98B7DE175573 C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe –a–c- 169984 bytes [13:43 25/01/2010] [00:12 14/04/2008] A81135541C9D4EBCE43EFA8AD31395B4 C:\WINDOWS\ServicePackFiles\i386\msconfig.exe —–c- 169984 bytes [00:12 14/04/2008] [00:12 14/04/2008] A81135541C9D4EBCE43EFA8AD31395B4 C:\WINDOWS\system32\dllcache\msconfig.exe –a–c- 169984 bytes [13:43 25/01/2010] [00:12 14/04/2008] A81135541C9D4EBCE43EFA8AD31395B4 -= EOF =- malware bytes report Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Različica baze: 6837 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 11.6.2011 22:16:53 mbam-log-2011-06-11 (22-16-53).txt Tip pregleda: Hitri pregled Preverjenih objektov: 150767 Pretečen čas: 3 minut, 24 sekund Okuženih spominskih procesov: 0 Okuženih spominskih modulov: 0 Okuženih ključev registra: 1 Okuženih vrednosti registra: 0 Okuženih vnosov v register: 0 Okuženih map: 0 Okuženih datotek: 0 Okuženih spominskih procesov: (Ni bilo najdenih zlonamernih objektov) Okuženih spominskih modulov: (Ni bilo najdenih zlonamernih objektov) Okuženih ključev registra: HKEY_CURRENT_USER\Software\Noobs (Trojan.Agent) -> Quarantined and deleted successfully. Okuženih vrednosti registra: (Ni bilo najdenih zlonamernih objektov) Okuženih vnosov v register: (Ni bilo najdenih zlonamernih objektov) Okuženih map: (Ni bilo najdenih zlonamernih objektov) Okuženih datotek: (Ni bilo najdenih zlonamernih objektov) eset report C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\ScanMasterELM_1[1].1.0_with_Patch.zip a variant of MSIL/Agent.AT trojan C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\lauflicht.zip a variant of MSIL/Agent.AT trojan C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\ScanMasterELM_DEMO_2[1].0.zip a variant of MSIL/Agent.AT trojan C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\ScanMasterFree0[1].4.0.0.zip a variant of MSIL/Agent.AT trojan C:\Documents and Settings\xp\My Documents\Downloads\DC++.rar a variant of MSIL/Agent.AT trojan C:\Documents and Settings\xp\My Documents\Downloads\dsgfsg.rar a variant of MSIL/Agent.AT trojan C:\Documents and Settings\xp\My Documents\Downloads\AutoData 3.24\AutoData324.iso Win32/Delf.PNF trojan C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\REVO\Vag com Lemmiwinks.exe Win32/VB.ODU trojan C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\REVO\VAG-REVOFlash_IIa_ECU_TUNING_VW_AUDI_SEAT_SKODA.exe Win32/VB.ODU trojan C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v413.exe Win32/VB.ODU trojan C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v414.exe Win32/VB.ODU trojan C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v413.exe Win32/VB.ODU trojan C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v414.exe Win32/VB.ODU trojan C:\Documents and Settings\xp\My Documents\Downloads\Mercedes EPC+WIS.net\Mercedes EWA - WIS.net_1of3.iso probably unknown NewHeur_PE virus C:\Documents and Settings\xp\My Documents\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe Win32/Packed.Autoit.E.Gen application C:\Documents and Settings\xp\My Documents\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe a variant of Win32/Keygen.AI application C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfig.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfigInternal.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfo.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Class.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\CodeFile.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\EmptyDatabase.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\MDIParent.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Resource.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Settings.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\SettingsInternal.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\UserControl.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Visualizer.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\XmlFile.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AssemblyInfoInternal.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dataset.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\EmptyDatabase.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Form.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\LoginForm.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\MDIParent.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SplashScreen.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\UserControl.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Windows Media Player\npdrmv2.zip a variant of MSIL/Agent.AT trojan C:\Program Files\Windows Media Player\npds.zip a variant of MSIL/Agent.AT trojan C:\System Volume Information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP407\A0140836.exe a variant of Win32/Kryptik.OOY trojan C:\System Volume Information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP409\A0142037.dll a variant of Win32/Packed.VMProtect.AAA trojan H:\dc++ downloadi\Autodata 3 18 new crack time unlimited.rar multiple threats H:\dc++ downloadi\Crack to Autodata - Versjon 3.16 (6.200) - Engelsk.rar multiple threats H:\Downloads\DC++.rar a variant of MSIL/Agent.AT trojan H:\Downloads\dsgfsg.rar a variant of MSIL/Agent.AT trojan H:\Downloads\Assassins.Creed.II-SKIDROW\sr-acii\sr-acii.iso a variant of Win32/Packed.VMProtect.AAA trojan H:\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe Win32/Packed.Autoit.E.Gen application H:\Downloads\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso probably a variant of Win32/Agent.KUNSSGB trojan H:\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe a variant of Win32/Keygen.AI application H:\DUSKO\svjetlana.exe a variant of Win32/Bflient.L worm H:\hipnoza\sladjica.exe Win32/Bflient.AG worm H:\IKONA\zauzeta.exe a variant of Win32/Kryptik.HJM trojan H:\insomnia\jkdrolja.exe a variant of Win32/Kryptik.JBW trojan H:\KAZAN\marijana.exe a variant of Win32/Bflient.N worm H:\KOLONIJA\letsrok.exe a variant of Win32/Kryptik.HSQ trojan H:\KOMPLEKSE\lechi.exe a variant of Win32/Kryptik.IBH trojan H:\miriskamiona\gostiona.exe a variant of Win32/Kryptik.IZB trojan H:\nfs\hot pursiut\rld-nshp.iso a variant of Win32/Packed.VMProtect.AAD trojan H:\nfs\hot pursiut\Crack\NFSHP_Activator.exe a variant of Win32/Packed.VMProtect.AAD trojan H:\NIKOLIC\baswala.exe Win32/Bflient.K worm H:\pridjimi\necedaboli.exe a variant of Win32/Bflient.V worm H:\sejo\kalac.exe a variant of Win32/Kryptik.FRV trojan H:\sojcice\obucicarapice.exe a variant of Win32/Bflient.AE worm H:\vatraopasna\slobodnaiskusna.exe a variant of Win32/Kryptik.KRJ trojan H:\VSI DOWNLOADI\Downloads\DC++.rar a variant of MSIL/Agent.AT trojan H:\VSI DOWNLOADI\Downloads\dsgfsg.rar a variant of MSIL/Agent.AT trojan H:\VSI DOWNLOADI\ETKA 7.0\ETKA.7.0.Marken.Freischaltung.-11.2006.By.ANTI_AKTE_FORUM\Marken Freischaltung\AKTE7Mfs.rar a variant of MSIL/Agent.AT trojan H:\VSI DOWNLOADI\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso probably a variant of Win32/Agent.KUNSSGB trojan H:\zamorepromena\zaletipad.exe a variant of Win32/Bflient.Z worm H:\zivac\primitivac.exe a variant of Win32/Bflient.AD worm The laptop still does't want to shut down, it take action that will shut down, but when it get on that moment where it have to shut down, stopps and then I have to press swich (turn off) for a few seconds… it's the same when i press hibernate… the sound on web pages is back :) the favorite pages on IE still not shown and when I turn on computer and when it get in windows show me a window and : ATI CATALYST CONTROL CENTER has to stop ( something like that) i press ''don't send'' and then show me once again that window, i press once again '''don't send'' and then don't show me this window again… Thanks for your helpful answers :)
Hi Avtovleka,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

If you would like to continue with the cleaning please let me know and I will be more than happy to help. :)
———-

Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/index.php?sh…mp;#entry734410

Collect::
C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\ScanMasterELM_1[1].1.0_with_Patch.zip
C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\lauflicht.zip
C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\ScanMasterELM_DEMO_2[1].0.zip
C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\ScanMasterFree0[1].4.0.0.zip
C:\Documents and Settings\xp\My Documents\Downloads\DC++.rar
C:\Documents and Settings\xp\My Documents\Downloads\dsgfsg.rar
C:\Documents and Settings\xp\My Documents\Downloads\AutoData 3.24\AutoData324.iso
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\REVO\Vag com Lemmiwinks.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\REVO\VAG-REVOFlash_IIa_ECU_TUNING_VW_AUDI_SEAT_SKODA.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v413.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v414.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v413.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v414.exe
C:\Documents and Settings\xp\My Documents\Downloads\Mercedes EPC+WIS.net\Mercedes EWA - WIS.net_1of3.iso
C:\Documents and Settings\xp\My Documents\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
C:\Documents and Settings\xp\My Documents\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfig.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfigInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfo.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Class.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\CodeFile.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\EmptyDatabase.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\MDIParent.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Resource.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Settings.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\SettingsInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\UserControl.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Visualizer.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\XmlFile.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AssemblyInfoInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dataset.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\EmptyDatabase.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Form.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\LoginForm.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\MDIParent.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SplashScreen.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\UserControl.zip
C:\Program Files\Windows Media Player\npdrmv2.zip
C:\Program Files\Windows Media Player\npds.zip
C:\System Volume Information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP407\A0140836.exe
C:\System Volume Information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP409\A0142037.dll
H:\dc++ downloadi\Autodata 3 18 new crack time unlimited.rar
H:\dc++ downloadi\Crack to Autodata - Versjon 3.16 (6.200) - Engelsk.rar
H:\Downloads\DC++.rar
H:\Downloads\dsgfsg.rar
H:\Downloads\Assassins.Creed.II-SKIDROW\sr-acii\sr-acii.iso
H:\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
H:\Downloads\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso
H:\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
H:\DUSKO\svjetlana.exe
H:\hipnoza\sladjica.exe
H:\IKONA\zauzeta.exe
H:\insomnia\jkdrolja.exe
H:\KAZAN\marijana.exe
H:\KOLONIJA\letsrok.exe
H:\KOMPLEKSE\lechi.exe
H:\miriskamiona\gostiona.exe
H:\nfs\hot pursiut\rld-nshp.iso
H:\nfs\hot pursiut\Crack\NFSHP_Activator.exe
H:\NIKOLIC\baswala.exe
H:\pridjimi\necedaboli.exe
H:\sejo\kalac.exe
H:\sojcice\obucicarapice.exe
H:\vatraopasna\slobodnaiskusna.exe
H:\VSI DOWNLOADI\Downloads\DC++.rar
H:\VSI DOWNLOADI\Downloads\dsgfsg.rar
H:\VSI DOWNLOADI\ETKA 7.0\ETKA.7.0.Marken.Freischaltung.-11.2006.By.ANTI_AKTE_FORUM\Marken Freischaltung\AKTE7Mfs.rar
H:\VSI DOWNLOADI\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso
H:\zamorepromena\zaletipad.exe
H:\zivac\primitivac.exe


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

In your next reply please post the log created by ComboFix.
HI! I'm a little busy now, and don't have time or even the patient to reinstall this notebook. So I want to continue with cleaning this….

ComboFix 11-06-09.03 - xp 14.06.2011 22:17:19.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.386.1033.18.3036.2401 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\xp\Desktop\CFScript.txt
.
- REDUCED FUNCTIONALITY MODE -
.
file zipped: c:\documents and settings\xp\My Documents\Downloads\DC++.rar
file zipped: c:\documents and settings\xp\My Documents\Downloads\dsgfsg.rar
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\REVO\VAG-REVOFlash_IIa_ECU_TUNING_VW_AUDI_SEAT_SKODA.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\REVO\Vag com Lemmiwinks.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v413.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v414.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v413.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v414.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfig.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfigInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfo.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Class.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\CodeFile.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\EmptyDatabase.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\MDIParent.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Resource.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Settings.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\SettingsInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\UserControl.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Visualizer.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\XmlFile.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AssemblyInfoInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dataset.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\EmptyDatabase.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Form.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\LoginForm.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\MDIParent.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SplashScreen.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\UserControl.zip
file zipped: c:\program files\Windows Media Player\npdrmv2.zip
file zipped: c:\program files\Windows Media Player\npds.zip
file zipped: c:\system volume information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP407\A0140836.exe
file zipped: c:\system volume information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP409\A0142037.dll
file zipped: h:\dc++ downloadi\Autodata 3 18 new crack time unlimited.rar
file zipped: h:\dc++ downloadi\Crack to Autodata - Versjon 3.16 (6.200) - Engelsk.rar
file zipped: h:\downloads\DC++.rar
file zipped: h:\downloads\dsgfsg.rar
file zipped: h:\downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
file zipped: h:\downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
file zipped: h:\dusko\svjetlana.exe
file zipped: h:\hipnoza\sladjica.exe
file zipped: h:\ikona\zauzeta.exe
file zipped: h:\insomnia\jkdrolja.exe
file zipped: h:\kazan\marijana.exe
file zipped: h:\kolonija\letsrok.exe
file zipped: h:\komplekse\lechi.exe
file zipped: h:\miriskamiona\gostiona.exe
file zipped: h:\nfs\hot pursiut\Crack\NFSHP_Activator.exe
file zipped: h:\nikolic\baswala.exe
file zipped: h:\pridjimi\necedaboli.exe
file zipped: h:\sejo\kalac.exe
file zipped: h:\sojcice\obucicarapice.exe
file zipped: h:\vatraopasna\slobodnaiskusna.exe
file zipped: h:\vsi downloadi\Downloads\DC++.rar
file zipped: h:\vsi downloadi\Downloads\dsgfsg.rar
file zipped: h:\vsi downloadi\ETKA 7.0\ETKA.7.0.Marken.Freischaltung.-11.2006.By.ANTI_AKTE_FORUM\Marken Freischaltung\AKTE7Mfs.rar
file zipped: h:\zamorepromena\zaletipad.exe
file zipped: h:\zivac\primitivac.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\xp\My Documents\Downloads\AutoData 3.24\AutoData324.iso
c:\documents and settings\xp\My Documents\Downloads\DC++.rar
c:\documents and settings\xp\My Documents\Downloads\dsgfsg.rar
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\REVO\VAG-REVOFlash_IIa_ECU_TUNING_VW_AUDI_SEAT_SKODA.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\REVO\Vag com Lemmiwinks.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v413.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v414.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v413.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v414.exe
c:\documents and settings\xp\My Documents\Downloads\Mercedes EPC+WIS.net\Mercedes EWA - WIS.net_1of3.iso
c:\documents and settings\xp\My Documents\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
c:\documents and settings\xp\My Documents\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfig.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfigInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfo.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Class.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\CodeFile.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\EmptyDatabase.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\MDIParent.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Resource.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Settings.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\SettingsInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\UserControl.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Visualizer.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\XmlFile.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AssemblyInfoInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dataset.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\EmptyDatabase.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Form.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\LoginForm.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\MDIParent.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SplashScreen.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\UserControl.zip
c:\program files\Windows Media Player\npdrmv2.zip
c:\program files\Windows Media Player\npds.zip
c:\system volume information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP407\A0140836.exe
c:\system volume information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP409\A0142037.dll
h:\dc++ downloadi\Autodata 3 18 new crack time unlimited.rar
h:\dc++ downloadi\Crack to Autodata - Versjon 3.16 (6.200) - Engelsk.rar
h:\downloads\Assassins.Creed.II-SKIDROW\sr-acii\sr-acii.iso
h:\downloads\DC++.rar
h:\downloads\dsgfsg.rar
h:\downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
h:\downloads\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso
h:\downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
h:\dusko\svjetlana.exe
h:\hipnoza\sladjica.exe
h:\ikona\zauzeta.exe
h:\insomnia\jkdrolja.exe
h:\kazan\marijana.exe
h:\kolonija\letsrok.exe
h:\komplekse\lechi.exe
h:\miriskamiona\gostiona.exe
h:\nfs\hot pursiut\Crack\NFSHP_Activator.exe
h:\nfs\hot pursiut\rld-nshp.iso
h:\nikolic\baswala.exe
h:\pridjimi\necedaboli.exe
h:\sejo\kalac.exe
h:\sojcice\obucicarapice.exe
h:\vatraopasna\slobodnaiskusna.exe
h:\vsi downloadi\Downloads\DC++.rar
h:\vsi downloadi\Downloads\dsgfsg.rar
h:\vsi downloadi\ETKA 7.0\ETKA.7.0.Marken.Freischaltung.-11.2006.By.ANTI_AKTE_FORUM\Marken Freischaltung\AKTE7Mfs.rar
h:\vsi downloadi\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso
h:\zamorepromena\zaletipad.exe
h:\zivac\primitivac.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-14 to 2011-06-14 )))))))))))))))))))))))))))))))
.
.
2011-06-12 21:38 . 2011-06-12 22:44 ——– d—–w- c:\documents and settings\xp\Local Settings\Application Data\WMTools Downloaded Files
2011-06-11 20:05 . 2011-06-11 20:05 ——– d—–w- c:\documents and settings\xp\Application Data\Malwarebytes
2011-06-11 20:04 . 2011-06-11 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-11 20:04 . 2011-05-29 07:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-11 20:04 . 2011-06-11 20:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-11 20:04 . 2011-05-29 07:11 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-08 05:51 . 2011-06-08 05:51 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-06-08 05:51 . 2011-06-08 05:51 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-06-08 05:51 . 2011-06-08 05:51 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-06-08 05:51 . 2011-06-08 05:51 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-06-08 05:51 . 2011-06-08 05:51 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-06-08 05:50 . 2011-06-08 05:50 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-06-08 05:50 . 2011-06-08 05:50 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-06-08 05:50 . 2011-06-08 05:50 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-06-05 07:35 . 2011-06-05 07:36 ——– d—–w- c:\documents and settings\xp\Application Data\ActiveState
2011-06-05 07:23 . 2011-06-05 07:23 ——– d—–w- c:\program files\ActiveState Perl Dev Kit 9.0.1
2011-06-04 17:57 . 2011-06-04 17:57 ——– d—–w- c:\documents and settings\xp\Local Settings\Application Data\BVRP Software
2011-06-04 17:51 . 2011-06-04 17:51 ——– d—–w- c:\windows\system32\wbem\Repository
2011-06-04 17:28 . 2011-06-11 20:22 ——– d—–w- c:\program files\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-06 19:28 . 2011-04-06 19:27 91376 —-a-w- c:\windows\system32\bcmwlcoi.dll
2011-04-06 19:28 . 2010-01-25 14:23 1735296 —-a-w- c:\windows\system32\drivers\BCMWL5.SYS
2011-06-08 05:50 . 2011-06-08 05:50 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-09_19.12.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-06-14 20:22 . 2011-06-14 20:22 16384 c:\windows\Temp\Perflib_Perfdata_748.dat
+ 2011-06-12 21:13 . 2011-06-12 21:13 105984 c:\windows\assembly\GAC_MSIL\Microsoft.WindowsAPICodePack\1.1.0.0__31bf3856ad364e35\Microsoft.WindowsAPICodePack.dll
+ 2011-06-12 21:13 . 2011-06-12 21:13 542720 c:\windows\assembly\GAC_MSIL\Microsoft.WindowsAPICodePack.Shell\1.1.0.0__31bf3856ad364e35\Microsoft.WindowsAPICodePack.Shell.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"RGSC"="c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2010-02-08 306088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-03-10 506936]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-02-18 177720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-01-16 1044480]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\xp\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-1-27 576000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\SIERRA\\Empire Earth\\Empire Earth.exe"=
"c:\\Documents and Settings\\xp\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed™ Hot Pursuit\\Launcher.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed™ Hot Pursuit\\NFS11.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=
"c:\\Program Files\\EA Sports\\FIFA 11\\Game\\fifa.exe"=
"c:\\Program Files\\Electronic Arts\\SHIFT 2 UNLEASHED\\shift2u.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"427:UDP"= 427:UDP:SLP_Port(427)
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [25.1.2010 16:02 24064]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31.1.2010 15:35 691696]
R2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [31.1.2010 15:54 97792]
R3 adatadrv;Autodata Protection Service;c:\windows\system32\drivers\adatadrv.sys [27.2.2011 16:41 762112]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [17.8.2010 21:46 222512]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [8.5.2010 16:30 27632]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\xp\LOCALS~1\Temp\CFcatchme.sys –> c:\docume~1\xp\LOCALS~1\Temp\CFcatchme.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [8.5.2010 16:30 13224]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [11.6.2011 22:04 39984]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [5.11.2010 0:23 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [5.11.2010 0:23 8320]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [8.11.2010 21:00 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [8.11.2010 21:00 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [8.11.2010 21:00 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [8.11.2010 21:00 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [8.11.2010 21:00 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [8.11.2010 21:00 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [8.11.2010 21:00 115752]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [2.11.2010 20:59 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [2.11.2010 20:59 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [2.11.2010 20:59 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [2.11.2010 20:59 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [2.11.2010 20:59 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [2.11.2010 20:59 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [2.11.2010 20:59 123504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-01-09 14:28 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.siol.net/
uInternet Connection Wizard,ShellNext = iexplore
IE: Free YouTube Download - c:\documents and settings\xp\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\xp\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki … - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: I&zvozi v Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.mascus.si/imageUploader/ImageUploader6.cab
FF - ProfilePath - c:\documents and settings\xp\Application Data\Mozilla\Firefox\Profiles\w5g1xhcw.default\
FF - prefs.js: browser.search.selectedEngine - BrotherSoft Extreme Customized Web Search
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-14 22:23
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(724)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\MSVCR80.dll
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slv.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\windows\system32\crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\PnkBstrA.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-06-14 23:06:12 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-14 21:06
ComboFix2.txt 2011-06-09 19:13
ComboFix3.txt 2011-06-08 18:48
.
Pre-Run: 35.080.028.160 bytes free
Post-Run: 11.176.620.032 prosto bajtov
.
- - End Of File - - 515C3E02266C76ECBEFEEC47F4745F88
Hi Avtovleka,

Great job running ComboFix!! Things are looking better, but we have a couple more things to do before we are done…stick with me. :)

P2P - I see you have P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs.
———-

You have an older version of Adobe Reader. You can download the current version HERE
———-

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

Now please run DDS once more and post both the logs created into your next reply.

In your next reply please post the logs created by DDS and let me know how your system is running now. :)
java not installed it show me an error , (Internal error 2753.regutils.dll) system continue with the same problems reports attach . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-03.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 25.1.2010 14:49:03 System Uptime: 17.6.2011 17:42:41 (5 hours ago) . Motherboard: Hewlett-Packard | | 3074 Processor: Intel® Core™2 Duo CPU T5870 @ 2.00GHz | Intel® Genuine processor | 1995/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 233 GiB total, 9,588 GiB free. D: is CDROM () E: is CDROM (CDFS) F: is CDROM () H: is FIXED (NTFS) - 373 GiB total, 83,79 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318} Description: Photosmart C4500 series Device ID: ROOT\MULTIFUNCTION\0000 Manufacturer: HP Name: Photosmart C4500 series PNP Device ID: ROOT\MULTIFUNCTION\0000 Service: . ==== System Restore Points =================== . RP380: 28.4.2011 10:53:59 - Točka preverjanja sistema RP381: 29.4.2011 12:02:07 - Točka preverjanja sistema RP382: 29.4.2011 17:00:08 - Installed ProductName from default.wxl RP383: 30.4.2011 9:24:32 - Installed ProductName from default.wxl RP384: 1.5.2011 12:52:42 - Točka preverjanja sistema RP385: 1.5.2011 15:48:26 - Installed Sony Ericsson Drivers RP386: 1.5.2011 16:14:53 - Sony Ericsson PC Companion RP387: 2.5.2011 18:53:59 - Točka preverjanja sistema RP388: 3.5.2011 22:21:18 - Točka preverjanja sistema RP389: 5.5.2011 20:55:28 - Točka preverjanja sistema RP390: 6.5.2011 5:51:27 - Software Distribution Service 3.0 RP391: 8.5.2011 19:08:36 - Točka preverjanja sistema RP392: 9.5.2011 22:12:12 - Točka preverjanja sistema RP393: 12.5.2011 5:45:32 - Software Distribution Service 3.0 RP394: 14.5.2011 21:41:13 - Točka preverjanja sistema RP395: 17.5.2011 20:37:10 - Točka preverjanja sistema RP396: 18.5.2011 20:39:39 - Točka preverjanja sistema RP397: 19.5.2011 21:42:11 - Točka preverjanja sistema RP398: 21.5.2011 21:06:35 - Točka preverjanja sistema RP399: 22.5.2011 21:07:17 - Točka preverjanja sistema RP400: 24.5.2011 20:37:15 - Točka preverjanja sistema RP401: 25.5.2011 21:13:57 - Točka preverjanja sistema RP402: 30.5.2011 21:04:05 - Točka preverjanja sistema RP403: 3.6.2011 20:51:40 - Točka preverjanja sistema RP404: 4.6.2011 18:50:35 - Operacija obnovitve RP405: 4.6.2011 19:28:46 - Nameščeno ESET NOD32 Antivirus RP406: 4.6.2011 19:35:23 - Operacija obnovitve RP407: 4.6.2011 19:46:17 - Operacija obnovitve RP408: 4.6.2011 19:57:02 - Nameščeno ESET NOD32 Antivirus RP409: 5.6.2011 9:23:18 - Installed ActiveState Perl Dev Kit 9.0.1 Build 293382 RP410: 5.6.2011 19:22:48 - Configured SoundMAX RP411: 5.6.2011 19:23:07 - Installed SoundMAX RP412: 5.6.2011 19:24:04 - Installed ATI Catalyst Control Center RP413: 5.6.2011 19:27:45 - Installed ATI Catalyst Control Center RP414: 8.6.2011 20:15:44 - ComboFix created restore point RP415: 9.6.2011 20:34:18 - Točka preverjanja sistema RP416: 10.6.2011 21:39:06 - Točka preverjanja sistema RP417: 12.6.2011 0:04:54 - Točka preverjanja sistema RP418: 13.6.2011 12:59:59 - Točka preverjanja sistema RP419: 14.6.2011 20:50:41 - Točka preverjanja sistema RP420: 15.6.2011 21:36:52 - Točka preverjanja sistema RP421: 16.6.2011 22:05:05 - Točka preverjanja sistema RP422: 16.6.2011 23:16:03 - Software Distribution Service 3.0 RP423: 17.6.2011 22:07:46 - Removed Adobe Reader 9.4.4. RP424: 17.6.2011 22:19:33 - Removed Java™ 6 Update 22 RP425: 17.6.2011 22:23:04 - Removed Java™ 6 Update 22 . ==== Installed Programs ====================== . 2007 Microsoft Office Suite Service Pack 2 (SP2) 32 Bit HP CIO Components Installer 3D Home Architect Design Suite Deluxe 8 4x4 Hummer Acrobat.com ActiveState Perl Dev Kit 9.0.1 Build 293382 Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader X (10.1.0) Adobe Shockwave Player 11.5 Apple Application Support Apple Software Update Assassin's Creed II ATI Catalyst Control Center ATI Display Driver µTorrent Avanquest update Broadcom 802.11 BS.Player PRO BufferChm Bullzip PDF Printer 7.1.0.1218 C4580 C4580_Help Cards_Calendar_OrderGift_DoMorePlugout Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Localization All ccc-core-preinstall ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CustomerResearchQFolder DC++ 0.674 Destination Component DeviceDiscovery DeviceManagementQFolder Diashapes (samo odstrani) DocProc DocProcQFolder Empire Earth ESET Online Scanner v3 eSupportQFolder ETKA 7.2 Final FIFA 11 Free 3GP Video Converter version 3.7.18 Free YouTube Download version 3.0.1.610 Free YouTube to MP3 Converter version 3.9 Freeware Edition (Version 0.4.0.0) FTDI USB Serial Converter Drivers Garmin USB Drivers Garmin WebUpdater German Truck Simulator 1.00 GPBaseService GPL Ghostscript Lite 8.70 Grand Theft Auto IV Graph 4.3 GRID Hardlock Device Drivers Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB942288-v3) Hotfix for Windows XP (KB949764) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Common Access Service Library HP Customer Participation Program 11.0 HP Imaging Device Functions 11.0 HP Integrated Module with Bluetooth wireless technology HP Photosmart C4500 All-In-One Driver Software 11.0 Rel .4 HP Photosmart Essential 2.5 HP Photosmart Essential 3.0 HP Quick Launch Buttons HP Smart Web Printing HP Solution Center 11.0 HP Update HP Webcam HP Wireless Assistant HPPhotoSmartPhotobookWebPack1 HPProductAssistant HPSSupply ImagXpress Java™ 6 Update 22 LightScribe System Software Magic ISO Maker v5.5 (build 0274) MagicDisc 2.7.106 Malwarebytes' Anti-Malware različica 1.51.0.1200 MarketResearch Marvell Miniport Driver Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft Office Access MUI (Slovenian) 2007 Microsoft Office Excel MUI (Slovenian) 2007 Microsoft Office InfoPath MUI (Slovenian) 2007 Microsoft Office Outlook MUI (Slovenian) 2007 Microsoft Office PowerPoint MUI (Slovenian) 2007 Microsoft Office Professional Plus 2007 Microsoft Office Proof (Croatian) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (German) 2007 Microsoft Office Proof (Italian) 2007 Microsoft Office Proof (Slovenian) 2007 Microsoft Office Proofing (Slovenian) 2007 Microsoft Office Publisher MUI (Slovenian) 2007 Microsoft Office Shared MUI (Slovenian) 2007 Microsoft Office Word MUI (Slovenian) 2007 Microsoft Software Update for Web Folders (Slovenian) 12 Microsoft User-Mode Driver Framework Feature Pack 1.7 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Motordiag Komfort Manager Lite 1.20 Mozilla Firefox 4.0.1 (x86 sl) MSN MSVC80_x86_v2 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) Need For Speed Shift Need for Speed™ Hot Pursuit Need for Speed™ Carbon Need for Speed™ ProStreet Need for Speed™ SHIFT Need for Speed™ Undercover neroxml Network Nokia Connectivity Cable Driver Nokia PC Suite Nokia Software Updater NVIDIA PhysX OBDII Drive Traces OCR Software by I.R.I.S. 11.0 Octoshape add-in for Adobe Flash Player OpenAL Orodje za prenos storitve Windows Live Overspeed: High Performance Street Racing PanoStandAlone PC Connectivity Solution Posodobitev za Microsoft Office Excel 2007 Help (KB963678) Posodobitev za Microsoft Office Powerpoint 2007 Help (KB963669) Posodobitev za Microsoft Office Word 2007 Help (KB963665) ProcessModeler PS_AIO_04_C4580_ProductContext PS_AIO_04_C4580_Software PS_AIO_04_C4580_Software_Min PSSWCORE QuickTime Race Driver 3 RCT3 Soaked Return to Castle Wolfenstein Rockstar Games Social Club RollerCoaster Tycoon® 3 Scan ScanMaster-ELM 1.1.0.0 ScanMaster-ELM 2.0.101.650 DEMO SecureW2 EAP Suite 1.1.4 for Windows Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft Office 2007 System (KB2541012) Security Update for Microsoft Office Access 2007 (KB979440) Security Update for Microsoft Office Excel 2007 (KB2541007) Security Update for Microsoft Office InfoPath 2007 (KB2510061) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office Publisher 2007 (KB2284697) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Segoe UI Sentinel Protection Installer 7.5.0 SHIFT 2 UNLEASHED™ Shop for HP Supplies SIDx Sierra On-Line Games (Remove only) Skins SmartWebPrinting SolutionCenter Sony Ericsson Update Service SoundMAX Status Synaptics Pointing Device Driver Toolbox TrayApp Ubisoft Game Launcher Uninstall 1.0.0.1 UnloadSupport Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Outlook 2007 (KB2509470) Update for Outlook 2007 Junk Email Filter (KB2536413) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB978506) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB960763) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB978207) VCDS PCI 908 VideoToolkit01 Vivid WorkshopData ATI VLC media player 0.9.8a WebFldrs XP WebReg Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) Windows Driver Package - Nokia Modem (02/15/2007 3.1) Windows Driver Package - Nokia Modem (05/24/2007 6.84.0.1) Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4) Windows Driver Package - Nokia Modem (10/05/2009 4.2) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Driver Package - Ross-Tech USB Driver Package (05/21/2009 2.04.18) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Live - Pomocnik za vpis Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Media Format 11 runtime Windows XP Service Pack 3 WinRAR archiver Zoo Tycoon 2 - Extinct Animals . ==== End Of File =========================== dds report . DDS (Ver_2011-06-03.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22 Run by [removed] at 22:23:35 on 2011-06-17 Microsoft Windows XP Home Edition 5.1.2600.3.1250.386.1033.18.3036.2274 [GMT 2:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe C:\WINDOWS\System32\svchost.exe -k eapsvcs svchost.exe C:\WINDOWS\System32\svchost.exe -k dot3svc C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE svchost.exe C:\Program Files\LSI SoftModem\agrsmsvc.exe C:\WINDOWS\system32\crypserv.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\WINDOWS\system32\svchost.exe -k HPService C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\msiexec.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.siol.net/ uInternet Connection Wizard,ShellNext = iexplore BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Windows Live - Pomoc pri vpisu: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: {00000000-0000-0000-0000-000000000000} - No File uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [RGSC] c:\program files\rockstar games\rockstar games social club\RGSCLauncher.exe /silent uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\xp\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: Free YouTube Download - c:\documents and settings\xp\application data\dvdvideosoftiehelpers\freeyoutubedownload.htm IE: Free YouTube to Mp3 Converter - c:\documents and settings\xp\application data\dvdvideosoftiehelpers\youtubetomp3.htm IE: Google Sidewiki … - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: I&zvozi v Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.mascus.si/imageUploader/ImageUploader6.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} - hxxps://asp.photoprintit.de/microsite/defaults/activex/ips/IPSUploader4.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{9909413C-9D45-4C92-9A69-E02DE5A05841} : DhcpNameServer = 192.168.1.1 192.168.2.1 TCP: Interfaces\{C4F9C734-204E-4918-9F36-4CCECBAE4472} : DhcpNameServer = 192.168.0.1 Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\ FF - prefs.js: browser.search.selectedEngine - BrotherSoft Extreme Customized Web Search FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&q= FF - component: c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}\components\FFExternalAlert.dll FF - component: c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}\components\RadioWMPCore.dll FF - component: c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll FF - component: c:\documents and settings\xp\application data\mozilla\firefox\profiles\w5g1xhcw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [2010-1-25 24064] R2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [2010-1-31 97792] R3 adatadrv;Autodata Protection Service;c:\windows\system32\drivers\adatadrv.sys [2011-2-27 762112] R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2010-8-17 222512] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-5-8 27632] S3 CFcatchme;CFcatchme;\??\c:\docume~1\xp\locals~1\temp\cfcatchme.sys –> c:\docume~1\xp\locals~1\temp\CFcatchme.sys [?] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2010-5-8 13224] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-6-11 39984] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-11-5 137344] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-11-5 8320] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2010-11-8 89256] S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2010-11-8 15016] S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2010-11-8 120744] S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2010-11-8 114216] S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2010-11-8 25512] S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2010-11-8 110632] S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2010-11-8 115752] S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [2010-11-2 98672] S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [2010-11-2 14960] S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [2010-11-2 124016] S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [2010-11-2 117872] S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [2010-11-2 25456] S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [2010-11-2 113904] S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [2010-11-2 123504] . =============== Created Last 30 ================ . 2011-06-16 21:20:58 ——– d—–w- c:\windows\SxsCaPendDel 2011-06-16 19:10:18 105472 -c—-w- c:\windows\system32\dllcache\mup.sys 2011-06-12 21:38:55 ——– d—–w- c:\documents and settings\xp\local settings\application data\WMTools Downloaded Files 2011-06-11 20:05:01 ——– d—–w- c:\documents and settings\xp\application data\Malwarebytes 2011-06-11 20:04:48 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-06-11 20:04:48 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-06-11 20:04:45 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-06-11 20:04:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-06-08 18:20:09 ——– d-sha-r- C:\cmdcons 2011-06-08 18:14:12 98816 —-a-w- c:\windows\sed.exe 2011-06-08 18:14:12 518144 —-a-w- c:\windows\SWREG.exe 2011-06-08 18:14:12 256512 —-a-w- c:\windows\PEV.exe 2011-06-08 18:14:12 208896 —-a-w- c:\windows\MBR.exe 2011-06-08 05:51:00 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2011-06-08 05:51:00 781272 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-06-08 05:51:00 465880 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-06-08 05:51:00 1874904 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2011-06-08 05:51:00 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll 2011-06-08 05:50:59 1892184 —-a-w- c:\program files\mozilla firefox\d3dx9_42.dll 2011-06-08 05:50:59 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-06-08 05:50:58 1974616 —-a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll 2011-06-06 10:55:30 183696 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2011-06-06 10:55:30 183696 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2011-06-05 07:35:56 ——– d—–w- c:\documents and settings\xp\application data\ActiveState 2011-06-05 07:23:21 ——– d—–w- c:\program files\ActiveState Perl Dev Kit 9.0.1 2011-06-04 17:57:50 ——– d—–w- c:\documents and settings\xp\local settings\application data\BVRP Software 2011-06-04 17:51:34 ——– d—–w- c:\windows\system32\wbem\repository\FS 2011-06-04 17:51:34 ——– d—–w- c:\windows\system32\wbem\Repository 2011-06-04 17:28:51 ——– d—–w- c:\program files\ESET . ==================== Find3M ==================== . 2011-05-02 15:31:52 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-04-29 16:19:43 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-25 16:11:12 916480 —-a-w- c:\windows\system32\wininet.dll 2011-04-25 16:11:11 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-04-25 16:11:11 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-04-25 12:01:22 385024 —-a-w- c:\windows\system32\html.iec 2011-04-21 13:37:43 105472 —-a-w- c:\windows\system32\drivers\mup.sys 2011-04-06 19:28:02 91376 —-a-w- c:\windows\system32\bcmwlcoi.dll 2011-04-06 19:28:02 1735296 —-a-w- c:\windows\system32\drivers\BCMWL5.SYS . ============= FINISH: 22:23:45,03 ===============

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI