This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

computer is dying, please help

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey my computer is dying, i tried to start it up in normal mode and got the blue screen of death.. i rebooted it and it runs almost normally in safe mode. but none of the antivirus i downloaded will run properly or update properly and i cant seem to figure out a solution, can you please help me fix it?

Btw im downloading files and posting from a working computer because the other one cant access internet at the moment or run any programs

heres a hijack this log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:56:26 PM, on 9/28/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Dong-Phu Thai\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071122
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z013&form=ZGAPHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071122
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1B805BB7-CEB9-4291-A6B7-CA58703FE985} - (no file)
O2 - BHO: (no name) - {63066209-A560-4B71-AB8A-F3306C7F9647} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Panda Security Toolbar - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {defeb7d7-60e8-46f2-af8d-2061e5420dd7} - (no file)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O3 - Toolbar: Panda Security Toolbar - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] "C:\WINDOWS\system32\WLTRAY.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] "C:\WINDOWS\stsystra.exe"
O4 - HKLM\..\Run: [ECenter] "C:\Dell\E-Center\EULALauncher.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PSUNMain] "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
O4 - HKLM\..\Run: [Panda Security URL Filtering] "C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-20\..\Run: [tokegabemo] Rundll32.exe "C:\WINDOWS\system32\zogadeli.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6886.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: nnnKCRlL - nnnKCRlL.dll (file missing)
O20 - Winlogon Notify: rqRKBTMF - rqRKBTMF.dll (file missing)
O20 - Winlogon Notify: urqOhFUk - urqOhFUk.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: IHA_MessageCenter - Unknown owner - C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Panda Cloud Antivirus Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Unknown owner - C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 8923 bytes
Hello Poopkabob and welcome back to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again Poopkabob

Before we start, a couple of questions:

1. The last time you asked for help you had Windows 7 64-bit and the user had a different name. Is this a friend’s or works computer?
2. Are you aware that you have two antiviruses running?

You can not run two real-time antiviruses at the same time. Although many have different methods of searching for and recognising threats, they will all be 'fighting' in memory to kick each other out, rendering them all ineffective.

Also, Antivirus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

If you choose to install more than one Anti-Virus program on your computer, then only one of them should be active in memory at a time.

Please remove one. What you choose to do after your computer problem is resolved is up to you but please follow these instructions until that time.

===================================================

OK let’s get started on sorting this mess out :)

Run HijackThis

Open HijackThis and click Do a system scan only.

Place a check mark next to:

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {1B805BB7-CEB9-4291-A6B7-CA58703FE985} - (no file)
O2 - BHO: (no name) - {63066209-A560-4B71-AB8A-F3306C7F9647} - (no file)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: (no name) - {defeb7d7-60e8-46f2-af8d-2061e5420dd7} - (no file)
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O4 - HKUS\S-1-5-20\..\Run: [tokegabemo] Rundll32.exe "C:\WINDOWS\system32\zogadeli.dll",s (User 'NETWORK SERVICE')
O20 - Winlogon Notify: nnnKCRlL - nnnKCRlL.dll (file missing)
O20 - Winlogon Notify: rqRKBTMF - rqRKBTMF.dll (file missing)
O20 - Winlogon Notify: urqOhFUk - urqOhFUk.dll (file missing)


Close all windows except for HijackThis and click Fix checked.

===================================================

Run OTL

download OTL and save it to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted
  • when the window appears, underneath Output at the top change it to Minimal Output
  • check the boxes beside LOP Check and Purity Check
  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply. You may need two posts to fit them both in.

===================================================

Run aswMBR

Download aswMBR.exe ( 511KB ) to your desktop.
  • double click the aswMBR.exe to run it
  • click the "Scan" button to start scan
  • on completion of the scan click save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfa
Oh sorry- yea, this is my friends computer so the specs are different from my past posts. With my last issue that was resolved it turned out the hard drive failed so I ended up sending it to the manufacturer to get it fixed. Anyways back to the current issue… the specs on this computer are: Windows XP home edition version 2002 service pack 3. Dell vostro 1000 AMD athlon™ 64 X2 Dual core processor TK-53 1.70 GHz. 896 MB rAM

Here are the logs you asked for. Thanks for taking the time to help.

OTL logfile created on: 9/29/2011 2:11:29 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

893.97 Mb Total Physical Memory | 704.52 Mb Available Physical Memory | 78.81% Memory free
2.12 Gb Paging File | 2.05 Gb Available in Paging File | 96.77% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.70 Gb Total Space | 75.16 Gb Free Space | 67.28% Space Free | Partition Type: NTFS
Drive E: | 1.87 Gb Total Space | 1.86 Gb Free Space | 99.87% Space Free | Partition Type: FAT

Computer Name: DONG-PHU | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - (WebrootSpySweeperService) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (IHA_MessageCenter) – C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe ()
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (hnmsvc) – C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (MRxSmb) – C:\WINDOWS\system32\drivers\mrxsmb.sys ()
DRV - (PSINAflt) – C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (PSINProt) – C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINProc) – C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (SSKBFD) – C:\WINDOWS\system32\drivers\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (MPFP) – C:\WINDOWS\system32\drivers\Mpfp.sys (McAfee, Inc.)
DRV - (atiide) – C:\WINDOWS\system32\DRIVERS\atiide.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (Packet) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=2071122
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=2071122

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=2071122
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/hws/sb/dell-usuk/en/…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk/en/…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=2071122
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/09/28 18:54:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/07 01:54:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/24 22:18:29 | 000,000,000 | —D | M]

[2011/09/28 18:51:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/03/24 00:50:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/03 15:59:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/08 22:16:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/04 19:04:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/24 04:38:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/04/05 02:11:37 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/01 20:15:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/09/07 01:54:34 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2005/12/05 22:31:00 | 000,114,688 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npmozax.dll
[2009/11/20 12:37:04 | 000,002,236 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\askcom.xml
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml.old

Hosts file not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe ()
O4 - HKLM..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Panda Security URL Filtering] C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe (Panda Security)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk = C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_23.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6886.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CDEF941E-3C08-4742-904D-4D038679A79D}: DhcpNameServer = 10.0.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\geBuTmKC) - File not found
O30 - LSA: Authentication Packages - (dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O34 - HKLM BootExecute: (SsiEfr.exe)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/29 14:08:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\backups
[2011/09/29 13:58:40 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2011/09/29 13:58:39 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/09/28 20:43:12 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2011/09/28 20:27:44 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/09/28 20:15:18 | 001,832,544 | —- | C] (McAfee, Inc.) – C:\Documents and Settings\Administrator\Desktop\MCPR.exe
[2011/09/28 18:54:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/09/28 18:54:15 | 000,320,856 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2011/09/28 18:54:15 | 000,020,568 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/09/28 18:54:13 | 000,442,200 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/09/28 18:54:13 | 000,052,568 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/09/28 18:54:13 | 000,034,392 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/09/28 18:54:12 | 000,110,552 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/09/28 18:54:12 | 000,104,536 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2011/09/28 18:54:11 | 000,030,808 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/09/28 18:54:00 | 000,041,184 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/09/28 18:53:59 | 000,199,304 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2011/09/28 18:53:46 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/09/28 18:53:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/09/28 18:52:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Recent
[2011/09/28 18:52:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2011/09/28 18:52:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/28 18:52:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/09/28 18:52:04 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/09/28 18:52:04 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/09/28 18:51:54 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\PrivacIE
[2011/09/28 18:51:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
[2011/09/28 18:51:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2011/09/28 18:50:09 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\IETldCache
[2011/09/28 18:49:28 | 000,000,000 | –SD | C] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2011/09/28 18:49:28 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Application Data
[2011/09/28 18:49:28 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Favorites
[2011/09/28 18:49:28 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\Cookies
[2011/09/28 18:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\InstallShield
[2011/09/28 18:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Identities
[2011/09/28 18:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\GTek
[2011/09/28 18:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop
[2011/09/28 18:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\ATI
[2011/09/28 18:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\ATI
[2011/09/28 18:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory
[2011/09/28 18:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe
[2011/09/28 18:49:27 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\SendTo
[2011/09/28 18:49:27 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
[2011/09/28 18:49:27 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu
[2011/09/28 18:49:27 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\My Documents\My Videos
[2011/09/28 18:49:27 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\My Documents\My Pictures
[2011/09/28 18:49:27 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\My Documents\My Music
[2011/09/28 18:49:27 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\My Documents
[2011/09/28 18:49:27 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
[2011/09/28 18:49:27 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Templates
[2011/09/28 18:49:27 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\PrintHood
[2011/09/28 18:49:27 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\NetHood
[2011/09/28 18:49:27 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Local Settings
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\SingleClick Systems
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\PowerDVD DX
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\My Google Gadgets
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Dell Accessories
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\BVRP Software
[2011/09/28 18:49:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}
[2011/09/28 18:47:14 | 009,852,544 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup-1.51.2.1300.exe
[2011/09/28 18:42:37 | 003,495,424 | —- | C] (Piriform Ltd) – C:\Documents and Settings\Administrator\Desktop\ccsetup311.exe
[2011/09/24 15:05:43 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/09/24 15:05:38 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/09/24 14:11:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering
[2011/09/24 14:09:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Panda Cloud Antivirus
[2011/09/24 10:59:29 | 000,000,000 | —D | C] – C:\fa188b1035c06f351faaaa
[2011/09/23 17:32:34 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/09/23 17:31:20 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/09/23 17:31:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/09/03 06:17:37 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[100 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/29 13:51:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/29 09:18:58 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2011/09/29 09:18:40 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/09/28 20:50:12 | 000,002,333 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk
[2011/09/28 20:43:42 | 000,000,000 | —- | M] () – C:\WINDOWS\186650240
[2011/09/28 20:42:38 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2011/09/28 20:27:44 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/09/28 20:15:20 | 001,832,544 | —- | M] (McAfee, Inc.) – C:\Documents and Settings\Administrator\Desktop\MCPR.exe
[2011/09/28 18:54:16 | 000,001,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/09/28 18:54:12 | 000,002,625 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/09/28 18:52:09 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/28 18:47:28 | 058,979,456 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\setup_av_free_cnet.exe
[2011/09/28 18:47:20 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup-1.51.2.1300.exe
[2011/09/28 18:42:46 | 003,495,424 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Administrator\Desktop\ccsetup311.exe
[2011/09/28 18:04:13 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/26 14:44:22 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/09/24 14:09:59 | 000,000,264 | —- | M] () – C:\WINDOWS\System32\PSUNCpl.dat
[2011/09/24 14:09:14 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/09/22 03:50:43 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/09/09 05:12:13 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/09/07 02:03:36 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/06 16:45:29 | 000,199,304 | —- | M] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2011/09/06 16:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/09/06 16:38:05 | 000,442,200 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/09/06 16:37:53 | 000,320,856 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2011/09/06 16:36:38 | 000,034,392 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/09/06 16:36:36 | 000,052,568 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/09/06 16:36:23 | 000,110,552 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/09/06 16:36:20 | 000,104,536 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2011/09/06 16:36:12 | 000,020,568 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/09/06 16:33:11 | 000,030,808 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[100 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/28 18:54:16 | 000,001,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/09/28 18:52:09 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/28 18:49:31 | 000,000,683 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/09/28 18:49:31 | 000,000,079 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/09/28 18:49:30 | 000,000,128 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2011/09/28 18:49:29 | 000,000,671 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Internet Explorer.lnk
[2011/09/28 18:49:28 | 000,001,503 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
[2011/09/28 18:49:28 | 000,000,642 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Outlook Express.lnk
[2011/09/28 18:46:51 | 058,979,456 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\setup_av_free_cnet.exe
[2011/09/24 14:09:59 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\PSUNCpl.dat
[2011/09/23 17:19:59 | 000,000,000 | —- | C] () – C:\WINDOWS\186650240
[2011/07/31 20:31:52 | 000,030,424 | —- | C] () – C:\WINDOWS\System32\wrLZMA.dll
[2010/06/09 05:20:35 | 000,058,292 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/06/09 17:32:30 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/03/16 12:40:21 | 000,000,164 | —- | C] () – C:\WINDOWS\install.dat
[2009/01/15 22:55:03 | 001,701,977 | -HS- | C] () – C:\WINDOWS\System32\CKmTuBeg.ini2
[2009/01/15 22:55:01 | 001,701,977 | -HS- | C] () – C:\WINDOWS\System32\CKmTuBeg.ini
[2009/01/04 17:21:38 | 000,702,875 | -HS- | C] () – C:\WINDOWS\System32\aHNnmnnn.ini2
[2008/09/05 00:03:05 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2007/12/04 00:26:50 | 000,002,024 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/12/03 22:39:38 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/11/21 19:41:39 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/11/21 19:34:27 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2007/11/21 19:26:27 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2007/11/21 19:26:25 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2007/11/21 19:26:25 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\WLTRYSVC.EXE
[2007/11/21 19:04:29 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2007/11/21 19:04:28 | 000,136,650 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2007/11/21 19:04:20 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2007/11/21 19:02:49 | 000,001,118 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 15:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 15:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 15:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 15:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 14:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 14:57:15 | 000,276,560 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 14:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 14:51:20 | 000,446,048 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 14:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 14:51:20 | 000,073,214 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 14:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 14:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 14:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 14:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 14:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 14:51:12 | 000,456,320 | —- | C] () – C:\WINDOWS\System32\drivers\mrxsmb.sys
[2004/08/10 14:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 14:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 14:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin

========== LOP Check ==========

[2009/01/27 02:46:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/12/08 08:45:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2011/09/28 18:53:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/05/11 00:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2007/12/23 15:29:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Banner Maker Pro 7
[2011/06/11 00:12:45 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/05/11 00:20:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/05/11 00:46:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2011/09/28 20:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering
[2007/11/21 19:34:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SingleClick Systems
[2011/09/28 20:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/24 04:58:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/04/12 16:09:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/12 18:45:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/21 17:21:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 784 bytes -> C:\WINDOWS\186650240:2146557940.exe
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:08948D52
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794

< End of report >

OTL Extras logfile created on: 9/29/2011 2:11:29 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

893.97 Mb Total Physical Memory | 704.52 Mb Available Physical Memory | 78.81% Memory free
2.12 Gb Paging File | 2.05 Gb Available in Paging File | 96.77% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.70 Gb Total Space | 75.16 Gb Free Space | 67.28% Space Free | Partition Type: NTFS
Drive E: | 1.87 Gb Total Space | 1.86 Gb Free Space | 99.87% Space Free | Partition Type: FAT

Computer Name: DONG-PHU | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"50000:UDP" = 50000:UDP:*:Enabled:IHA_MessageCenter

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant – (SingleClick Systems)
"C:\WINDOWS\system32\drivers\svchost.exe" = C:\WINDOWS\system32\drivers\svchost.exe:*:Disabled:svchost
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer – (Microsoft Corporation)
"C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" = C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe:*:Enabled:SpySweeperUI
"C:\Program Files\Viewpoint\Common\ViewpointService.exe" = C:\Program Files\Viewpoint\Common\ViewpointService.exe:*:Enabled:ViewpointService
"C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe" = C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe:*:Enabled:mcproxy
"C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe" = C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe:*:Enabled:WRConsumerService
"C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe" = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe:*:Enabled:CLI – (ATI Technologies Inc.)
"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" = C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe:*:Enabled:SpySweeper
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe:*:Enabled:GoogleToolbarNotifier
"C:\Program Files\Dell Network Assistant\hnm_svc.exe" = C:\Program Files\Dell Network Assistant\hnm_svc.exe:*:Enabled:hnm_svc – (SingleClick Systems)
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" = C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 23
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{BE2DDF55-4C42-44CC-A56E-C8E4A65CB2FF}" = IHA_MessageCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EF40BAC3-372B-46F4-A32D-B37CF4217CE7}" = ATI Catalyst Control Center
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{FEB2D0CA-9912-4AA1-8FBE-CFD852F9F1FC}" = Panda Cloud Antivirus
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_7" = AIM 7
"ATI Display Driver" = ATI Display Driver
"avast" = avast! Free Antivirus
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"ENTERPRISE" = Microsoft Office Enterprise 2007
"iCheck" = Internet Speed Monitor
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 6.0.2 (x86 en-US)" = Mozilla Firefox 6.0.2 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Panda Cloud Antivirus" = Panda Cloud Antivirus
"Panda Security URL Filtering" = Panda Security URL Filtering
"pandasecuritytb" = Panda Security Toolbar
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Dell Touchpad
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/28/2011 8:21:45 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 9/28/2011 8:26:29 PM | Computer Name = DONG-PHU | Source = MsiInstaller | ID = 1008
Description = The installation of C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\VSE870.MSI
is not permitted due to an error in software restriction policy processing. The
object cannot be trusted.

Error - 9/28/2011 8:26:32 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 9/28/2011 8:26:32 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 9/28/2011 8:26:32 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 9/28/2011 8:26:32 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 9/28/2011 8:26:32 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 9/28/2011 8:26:32 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 9/28/2011 8:26:32 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 9/28/2011 8:26:32 PM | Computer Name = DONG-PHU | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 9/29/2011 1:53:22 PM | Computer Name = DONG-PHU | Source = Service Control Manager | ID = 7001
Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 9/29/2011 1:53:22 PM | Computer Name = DONG-PHU | Source = Service Control Manager | ID = 7001
Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 9/29/2011 1:53:22 PM | Computer Name = DONG-PHU | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 9/29/2011 1:53:22 PM | Computer Name = DONG-PHU | Source = Service Control Manager | ID = 7000
Description = The Webroot Spy Sweeper Engine service failed to start due to the
following error: %%3

Error - 9/29/2011 1:53:22 PM | Computer Name = DONG-PHU | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 AFD APPDRV aswRdr aswSnx aswSP aswTdi Fips IPSec MPFP MRxSmb NetBIOS NetBT Processor
PSINKNC
RasAcd
Rdbss
Tcpip

Error - 9/29/2011 1:53:30 PM | Computer Name = DONG-PHU | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 9/29/2011 1:53:38 PM | Computer Name = DONG-PHU | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 9/29/2011 1:59:19 PM | Computer Name = DONG-PHU | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 9/29/2011 2:01:21 PM | Computer Name = DONG-PHU | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 9/29/2011 2:08:43 PM | Computer Name = DONG-PHU | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}


< End of report >

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-09-29 14:17:34
—————————–
14:17:34.796 OS Version: Windows 5.1.2600 Service Pack 3
14:17:34.796 Number of processors: 2 586 0x6801
14:17:34.796 ComputerName: DONG-PHU UserName:
14:17:37.781 Initialize success
14:17:41.531 AVAST engine defs: 11090801
14:17:48.140 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
14:17:48.203 Disk 0 Vendor: ST9120822AS 3.CDD Size: 114473MB BusType: 3
14:17:48.265 Disk 0 MBR read successfully
14:17:48.296 Disk 0 MBR scan
14:17:52.218 Disk 0 Windows XP default MBR code
14:17:52.296 Disk 0 scanning sectors +234420480
14:17:56.390 Disk 0 scanning C:\WINDOWS\system32\drivers
14:19:04.390 Service scanning
14:19:17.531 Modules scanning
14:19:35.406 Disk 0 trace - called modules:
14:19:35.546 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll atiide.sys
14:19:35.578 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85377ab8]
14:19:35.625 3 CLASSPNP.SYS[f75c4fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0x85301d98]
14:19:40.468 AVAST engine scan C:\WINDOWS
14:19:51.046 AVAST engine scan C:\WINDOWS\system32
14:25:34.453 AVAST engine scan C:\WINDOWS\system32\drivers
14:26:17.296 AVAST engine scan C:\Documents and Settings\Administrator
14:26:47.734 AVAST engine scan C:\Documents and Settings\All Users
14:28:21.906 Scan finished successfully
14:30:05.937 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat"
14:30:06.093 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR.txt"
I’m not a bit surprised that there is a BSOD as there are THREE antiviruses competing for attention on this computer which is causing conflict and allowing anything to slip in unnoticed while they are fighting with each other.

You must remove, (through Add or Remove programs, either Panda or Avast.

Then run McAfee Removal Tool

=======================================================

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\geBuTmKC) - File not found
    O30 - LSA: Authentication Packages - (dll) - File not found
    
    :Reg
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"=hex(7):"msv1_0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "UpdatesDisableNotify"=dword:00000000
    
    :Files
    C:\WINDOWS\system32\zogadeli.dll
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

=======================================================

Download Malwarebytes-Anti-Malware

Although Malwarebytes is on the infected machine, it would be better to download and run an updated version from an uninfected computer, then transfer and run that version

Click here
  • double-click mbam-setup.exe and follow the prompts to install the program.
  • at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
  • if an update is found, it will download and install the latest version.
  • once the program has loaded, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

=======================================================

Assuming that you now have only one antivirus, have run the OTL fix and Mbam, please try booting the infected computer in normal mode and let me know how it is running now.

Logs to include with next post:

OTL.txt
Mbam.txt


Thanks

Satchfan
Btw I attempted to use the McAfee removal tool in the past and it wont run. When I run it, it says that another file or program is using mcafee and doesnt work. I just tried it with the same results, do you have any advice on how else i can remove mcafees? i already removed panda.
So MBAM wont run the update or scan either, i get the error message after it installs that says PROGRAM_ERROR_UPDATING the requested name is valid and was found in the database but it does not have the correct associated data being resolved for. Earlier when i was trying to solve this issue it seemed to be related to McAffy not being completely uninstalled which i still cant fix. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\geBuTmKC deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:dll deleted successfully. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\\"Authentication Packages"|hex(7):"msv1_0" /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"UpdatesDisableNotify"|dword:00000000 /E : value set successfully! ========== FILES ========== File\Folder C:\WINDOWS\system32\zogadeli.dll not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 9866307 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->FireFox cache emptied: 6410843 bytes User: All Users User: Default User ->Temp folder emptied: 32768 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: Dong-Phu Thai ->Temp folder emptied: 504737181 bytes ->Temporary Internet Files folder emptied: 97966582 bytes ->Java cache emptied: 124323435 bytes ->FireFox cache emptied: 52634978 bytes ->Flash cache emptied: 41519 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 159098014 bytes ->Flash cache emptied: 5895 bytes User: NetworkService ->Temp folder emptied: 67797450 bytes ->Temporary Internet Files folder emptied: 160115199 bytes ->Java cache emptied: 39 bytes ->Flash cache emptied: 11377 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 1262609 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1259202 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 65831364 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 1595038 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1,195.00 mb OTL by OldTimer - Version 3.2.29.1 log created on 09302011_112450 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Yes i tried running both the Mcafee removal tool in both normal and safe mode. I also did this for MBAM and it wouldnt update or run due to the errors.
Do the following and transfer it to the desktop of the infected computer:

Download/run Rkill:

Please download Rkill from one of the following links and save to your Desktop:

Link One
Link Two
Link Three
Link Four

  • Double click on Rkill.
  • A command window will open then disappear upon completion, this is normal.
  • Please leave Rkill on the Desktop until otherwise advised.
Note: If you get an alert that Rkill is infected, ignore it. The alert is a fake warning given by the rogue software which attempts to terminate tools that try to remove it. If you see such a warning, leave the warning on the screen and then run Rkill again. By not closing the warning, this sometimes allows you to bypass the malware's attempt to protect itself so that Rkill can perform its routine.

You may have to make repeated attempts to use Rkill several times before it will run as some malware variants try to block it.

You'll be able to tell when rkill has done its job when your desktop (explorer.exe) cycles off and then on again.

===================================================

Run Malwarebytes using the version that is already installed on the computer.

Satchfan
So… i ran Rkill and then ran mbam on safe mode. it went through and caught 3 trojans. when i rebooted it runs up to speed in normal mode. I had internet access so i went ahead and updated mbam. after that i tried to run mbam and it went for about 5 minute and just stopped. Now the malwarebytes icon looks like the generic screen thing and it says this when I try to run it "Windows cannot access the specified device, path, or file. you may not have the appropriate permissions to access the item. This happened every other time i used mbam so im not sure why it even worked once. If i reinstall mbam i can run it again but im not sure if it will help… here is the log from when it did run Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7622 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 9/30/2011 7:03:21 PM mbam-log-2011-09-30 (19-03-21).txt Scan type: Quick scan Objects scanned: 180162 Time elapsed: 13 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\dong-phu thai\application data\gadcom (Trojan.Agent) -> Quarantined and deleted successfully. c:\program files\iCheck (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: (No malicious items detected)
MBAM updates normally now. but when i run it not in safe mode it randomly shuts down. after that i have zero access to the program and cant even delete or rename it. If MBAM got shut down before i updated then any attempt to update would show the update error mentioned earlier. I also noticed a long string of numbers under my processes that I'm pretty sure has to do with the problem… and when i try to end the process nothing happens. What i did was rebooted, uninstalled MBAM, reinstalled and updated. rebooted enter safe mode. and now it is finally running with full updates. heres the log… it came back clean… im also posting a new hijack this log just for good measure

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7839

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

10/1/2011 1:28:26 AM
mbam-log-2011-10-01 (01-28-25).txt

Scan type: Quick scan
Objects scanned: 187414
Time elapsed: 14 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:30:12 AM, on 10/1/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\xxxx.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071122
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071122
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071122
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Dell Network Assistant.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_23.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_23.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6886.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: IHA_MessageCenter - Unknown owner - C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Unknown owner - C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 5950 bytes
Mmmm we're getting somewhere but I think we need a deeper scan.

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
combofix said that rootkit.zeroaccess was detected and it has installed itself in the TCP-IP stack. ill post a log as soon as it finishes
I ran combo fix during safe mode the first time and could not install the recovery counsel. I then ran it again from normal mode to install the recovery counsel so im going to post both logs in order.

omboFix 11-09-30.05 - Dong-Phu Thai 10/01/2011 10:41:40.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.607 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\GetModule
c:\windows\$NtUninstallKB24570$
c:\windows\$NtUninstallKB24570$\2148409355\@
c:\windows\$NtUninstallKB24570$\2148409355\bckfg.tmp
c:\windows\$NtUninstallKB24570$\2148409355\cfg.ini
c:\windows\$NtUninstallKB24570$\2148409355\Desktop.ini
c:\windows\$NtUninstallKB24570$\2148409355\keywords
c:\windows\$NtUninstallKB24570$\2148409355\kwrd.dll
c:\windows\$NtUninstallKB24570$\2148409355\L\odetmngk
c:\windows\$NtUninstallKB24570$\2148409355\lsflt7.ver
c:\windows\$NtUninstallKB24570$\2148409355\U\00000001.@
c:\windows\$NtUninstallKB24570$\2148409355\U\00000002.@
c:\windows\$NtUninstallKB24570$\2148409355\U\80000000.@
c:\windows\$NtUninstallKB24570$\2148409355\U\80000032.@
c:\windows\$NtUninstallKB24570$\3984304951
c:\windows\186650240
c:\windows\system32\aHNnmnnn.ini2
c:\windows\system32\CKmTuBeg.ini
c:\windows\system32\CKmTuBeg.ini2
c:\windows\system32\d3d9caps.dat
.
Infected copy of c:\windows\system32\drivers\mrxsmb.sys was found and disinfected
Restored copy from - The cat found it :)
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_800e200b
.
.
((((((((((((((((((((((((( Files Created from 2011-09-01 to 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 14:36 . 2011-07-15 13:29 457856 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-10-01 05:08 . 2011-10-01 05:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-10-01 05:08 . 2011-08-31 21:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-01 04:57 . 2011-10-01 04:57 ——– d–h–w- c:\windows\PIF
2011-09-30 15:24 . 2011-09-30 15:24 ——– d—–w- C:\_OTL
2011-09-28 22:53 . 2011-09-30 14:07 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2011-09-28 22:53 . 2011-09-28 22:53 ——– d—–w- c:\program files\AVAST Software
2011-09-28 22:52 . 2011-09-28 22:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-09-28 22:49 . 2011-09-28 22:52 ——– d—–w- c:\documents and settings\Administrator
2011-09-24 19:05 . 2011-09-24 19:05 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2011-09-24 14:59 . 2011-09-24 14:59 ——– d—–w- C:\fa188b1035c06f351faaaa
2011-09-23 21:30 . 2011-09-23 21:30 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2011-09-03 10:17 . 2011-09-09 09:12 599040 ——w- c:\windows\system32\dllcache\crypt32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2004-08-10 18:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-07 06:03 . 2011-05-17 03:26 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-03 05:21 . 2011-08-03 05:21 260 —-a-w- c:\windows\system32\cmdVBS.vbs
2011-08-03 05:21 . 2011-08-03 05:21 256 —-a-w- c:\windows\system32\MSIevent.bat
2011-07-12 15:20 . 2011-07-12 15:20 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20 . 2011-07-12 15:20 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20 . 2011-07-12 15:20 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20 . 2011-07-12 15:20 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-07-08 14:02 . 2004-08-10 18:51 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 22:37 . 2011-07-05 22:37 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 22:37 . 2011-07-05 22:37 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-09-07 05:54 . 2011-03-24 04:50 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-11-21 7168]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2006-05-10 17:12 90112 —-a-w- c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2007-03-16 09:10 1392640 —-a-w- c:\windows\system32\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 18:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2007-05-24 13:03 17920 —-a-w- c:\dell\E-Center\EULALauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-19 05:07 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 21:00 449608 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 22:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2007-04-24 03:01 303104 —-a-w- c:\windows\stsystra.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-04-27 07:10 851968 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe"=
"c:\\WINDOWS\\system32\\BCMWLTRY.EXE"=
"c:\\Program Files\\Dell Network Assistant\\hnm_svc.exe"=
"c:\\Program Files\\QuickTime\\qttask.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.EXE"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"50000:UDP"= 50000:UDP:IHA_MessageCenter
.
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [11/21/2007 7:04 PM 3456]
R2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [7/1/2011 3:01 PM 151552]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/1/2011 1:08 AM 366152]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/1/2011 1:08 AM 22216]
S1 MpKsl06b172e8;MpKsl06b172e8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C2B640AE-1474-428D-BF90-CD4DC037225E}\MpKsl06b172e8.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C2B640AE-1474-428D-BF90-CD4DC037225E}\MpKsl06b172e8.sys [?]
S1 MpKsl2987d232;MpKsl2987d232;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6B6242A-00DB-4F60-AE3B-222DF5440CBF}\MpKsl2987d232.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6B6242A-00DB-4F60-AE3B-222DF5440CBF}\MpKsl2987d232.sys [?]
S1 MpKsl30fee6c0;MpKsl30fee6c0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D2B97D73-1D7A-40F2-B7F1-359A44797323}\MpKsl30fee6c0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D2B97D73-1D7A-40F2-B7F1-359A44797323}\MpKsl30fee6c0.sys [?]
S1 MpKsl5478b36b;MpKsl5478b36b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{60306D96-4235-49A8-A489-5FCA8EAB60E9}\MpKsl5478b36b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{60306D96-4235-49A8-A489-5FCA8EAB60E9}\MpKsl5478b36b.sys [?]
S1 MpKsl5bd7c15b;MpKsl5bd7c15b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98DDBF1F-6012-45A6-A9B7-67953F768421}\MpKsl5bd7c15b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98DDBF1F-6012-45A6-A9B7-67953F768421}\MpKsl5bd7c15b.sys [?]
S1 MpKsl7b91dc13;MpKsl7b91dc13;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{04FA064D-1730-4803-81EA-CF1CF37C99DD}\MpKsl7b91dc13.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{04FA064D-1730-4803-81EA-CF1CF37C99DD}\MpKsl7b91dc13.sys [?]
S1 MpKsl7f968dd5;MpKsl7f968dd5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EADD690F-13AA-4763-BF70-94B8D5BAF29F}\MpKsl7f968dd5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EADD690F-13AA-4763-BF70-94B8D5BAF29F}\MpKsl7f968dd5.sys [?]
S1 MpKsl84d77e37;MpKsl84d77e37;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF84F204-9621-4476-830E-BD21F991E408}\MpKsl84d77e37.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF84F204-9621-4476-830E-BD21F991E408}\MpKsl84d77e37.sys [?]
S1 MpKsl8aa7e926;MpKsl8aa7e926;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D80DAC05-75AE-467E-B871-D2B332E500FB}\MpKsl8aa7e926.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D80DAC05-75AE-467E-B871-D2B332E500FB}\MpKsl8aa7e926.sys [?]
S1 MpKsl9d705fe2;MpKsl9d705fe2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{384B2B4A-3A62-4321-8E62-BAC07556B8D0}\MpKsl9d705fe2.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{384B2B4A-3A62-4321-8E62-BAC07556B8D0}\MpKsl9d705fe2.sys [?]
S1 MpKsle3a81e8b;MpKsle3a81e8b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{43D7AB7B-B647-4F9D-8D9C-575FECC8AC40}\MpKsle3a81e8b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{43D7AB7B-B647-4F9D-8D9C-575FECC8AC40}\MpKsle3a81e8b.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MBAMPROTECTOR
*NewlyCreated* - MBAMSERVICE
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 21:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bing.com/?pc=Z013&form;=ZGAPHP
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Dong-Phu Thai\Application Data\Mozilla\Firefox\Profiles\38ca59q2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=panda&type;=PCAFSI1190&p;=
FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.homepage.dontask, true);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 10:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(784)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(4052)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\program files\Dell Network Assistant\ezi_hnm2.exe
.
**************************************************************************
.
Completion time: 2011-10-01 11:01:43 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-01 15:01
.
Pre-Run: 80,888,815,616 bytes free
Post-Run: 80,915,279,872 bytes free
.
- - End Of File - - 9E8FDF29932207970F5A17C9431B83C8

LOG 2

ComboFix 11-09-30.05 - Dong-Phu Thai 10/01/2011 11:12:15.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.349 [GMT -4:00]
Running from: E:\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Dong-Phu Thai\Application Data\Adobe\manol.exe
c:\documents and settings\Dong-Phu Thai\Application Data\GetModule
c:\documents and settings\Dong-Phu Thai\Application Data\GetModule\dicik.gz
c:\documents and settings\Dong-Phu Thai\Application Data\GetModule\kwdik.gz
c:\documents and settings\Dong-Phu Thai\Application Data\GetModule\ofadik.gz
.
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\userinit.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-09-01 to 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 14:36 . 2011-07-15 13:29 457856 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-10-01 05:08 . 2011-10-01 05:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-10-01 05:08 . 2011-08-31 21:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-01 04:57 . 2011-10-01 04:57 ——– d–h–w- c:\windows\PIF
2011-09-30 15:44 . 2011-09-30 15:44 ——– d—–w- c:\documents and settings\Dong-Phu Thai\Application Data\Malwarebytes
2011-09-30 15:24 . 2011-09-30 15:24 ——– d—–w- C:\_OTL
2011-09-28 22:53 . 2011-09-30 14:07 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2011-09-28 22:53 . 2011-09-28 22:53 ——– d—–w- c:\program files\AVAST Software
2011-09-28 22:52 . 2011-09-28 22:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-09-28 22:49 . 2011-09-28 22:52 ——– d—–w- c:\documents and settings\Administrator
2011-09-24 19:05 . 2011-09-24 19:05 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2011-09-24 18:11 . 2011-09-24 20:30 ——– d—–w- c:\documents and settings\Dong-Phu Thai\Local Settings\Application Data\panda2_0dn
2011-09-24 18:10 . 2011-09-26 18:48 ——– d—–w- c:\documents and settings\Dong-Phu Thai\Application Data\pandasecuritytb
2011-09-24 14:59 . 2011-09-24 14:59 ——– d—–w- C:\fa188b1035c06f351faaaa
2011-09-23 21:30 . 2011-09-23 21:30 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2011-09-03 10:17 . 2011-09-09 09:12 599040 ——w- c:\windows\system32\dllcache\crypt32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2004-08-10 18:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-07 06:03 . 2011-05-17 03:26 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-03 05:21 . 2011-08-03 05:21 260 —-a-w- c:\windows\system32\cmdVBS.vbs
2011-08-03 05:21 . 2011-08-03 05:21 256 —-a-w- c:\windows\system32\MSIevent.bat
2011-07-12 15:20 . 2011-07-12 15:20 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20 . 2011-07-12 15:20 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20 . 2011-07-12 15:20 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20 . 2011-07-12 15:20 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-07-08 14:02 . 2004-08-10 18:51 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 22:37 . 2011-07-05 22:37 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 22:37 . 2011-07-05 22:37 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-09-07 05:54 . 2011-03-24 04:50 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-11-21 7168]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2006-05-10 17:12 90112 —-a-w- c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2007-03-16 09:10 1392640 —-a-w- c:\windows\system32\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 18:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2007-05-24 13:03 17920 —-a-w- c:\dell\E-Center\EULALauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-19 05:07 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 21:00 449608 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 22:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2007-04-24 03:01 303104 —-a-w- c:\windows\stsystra.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-04-27 07:10 851968 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe"=
"c:\\WINDOWS\\system32\\BCMWLTRY.EXE"=
"c:\\Program Files\\Dell Network Assistant\\hnm_svc.exe"=
"c:\\Program Files\\QuickTime\\qttask.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.EXE"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"50000:UDP"= 50000:UDP:IHA_MessageCenter
.
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [11/21/2007 7:04 PM 3456]
S1 MpKsl06b172e8;MpKsl06b172e8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C2B640AE-1474-428D-BF90-CD4DC037225E}\MpKsl06b172e8.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C2B640AE-1474-428D-BF90-CD4DC037225E}\MpKsl06b172e8.sys [?]
S1 MpKsl2987d232;MpKsl2987d232;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6B6242A-00DB-4F60-AE3B-222DF5440CBF}\MpKsl2987d232.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6B6242A-00DB-4F60-AE3B-222DF5440CBF}\MpKsl2987d232.sys [?]
S1 MpKsl30fee6c0;MpKsl30fee6c0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D2B97D73-1D7A-40F2-B7F1-359A44797323}\MpKsl30fee6c0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D2B97D73-1D7A-40F2-B7F1-359A44797323}\MpKsl30fee6c0.sys [?]
S1 MpKsl5478b36b;MpKsl5478b36b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{60306D96-4235-49A8-A489-5FCA8EAB60E9}\MpKsl5478b36b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{60306D96-4235-49A8-A489-5FCA8EAB60E9}\MpKsl5478b36b.sys [?]
S1 MpKsl5bd7c15b;MpKsl5bd7c15b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98DDBF1F-6012-45A6-A9B7-67953F768421}\MpKsl5bd7c15b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98DDBF1F-6012-45A6-A9B7-67953F768421}\MpKsl5bd7c15b.sys [?]
S1 MpKsl7b91dc13;MpKsl7b91dc13;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{04FA064D-1730-4803-81EA-CF1CF37C99DD}\MpKsl7b91dc13.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{04FA064D-1730-4803-81EA-CF1CF37C99DD}\MpKsl7b91dc13.sys [?]
S1 MpKsl7f968dd5;MpKsl7f968dd5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EADD690F-13AA-4763-BF70-94B8D5BAF29F}\MpKsl7f968dd5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EADD690F-13AA-4763-BF70-94B8D5BAF29F}\MpKsl7f968dd5.sys [?]
S1 MpKsl84d77e37;MpKsl84d77e37;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF84F204-9621-4476-830E-BD21F991E408}\MpKsl84d77e37.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF84F204-9621-4476-830E-BD21F991E408}\MpKsl84d77e37.sys [?]
S1 MpKsl8aa7e926;MpKsl8aa7e926;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D80DAC05-75AE-467E-B871-D2B332E500FB}\MpKsl8aa7e926.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D80DAC05-75AE-467E-B871-D2B332E500FB}\MpKsl8aa7e926.sys [?]
S1 MpKsl9d705fe2;MpKsl9d705fe2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{384B2B4A-3A62-4321-8E62-BAC07556B8D0}\MpKsl9d705fe2.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{384B2B4A-3A62-4321-8E62-BAC07556B8D0}\MpKsl9d705fe2.sys [?]
S1 MpKsle3a81e8b;MpKsle3a81e8b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{43D7AB7B-B647-4F9D-8D9C-575FECC8AC40}\MpKsle3a81e8b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{43D7AB7B-B647-4F9D-8D9C-575FECC8AC40}\MpKsle3a81e8b.sys [?]
S2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [7/1/2011 3:01 PM 151552]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/1/2011 1:08 AM 366152]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/1/2011 1:08 AM 22216]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MDMXSDK
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 21:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=2071122
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ydhnlxsm.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 11:28
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(212)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(1276)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2011-10-01 11:37:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-01 15:37
ComboFix2.txt 2011-10-01 15:01
.
Pre-Run: 80,908,578,816 bytes free
Post-Run: 81,833,652,224 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 86AA8B3D1D0368CA0463D59BA9A2C602

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI