This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.BHO

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I use CA Internet Security Suite for my secureity antivirus software. On 10/28, during a full scan picked up the following:

Win32/FakeAV.ZAAD!suspicious
Win32/Orsam.ZAAH!suspicious
Heur/Exploit.ZAAB!suspicious
Heur/TrojanHorse.ZAJE!suspicious
Win32/Dynamer.ZAAQ!suspicious
Win32/Karagany.C!packed
Win32/FakeSysdef.ZAAC!suspicious

I ran Malwarebytes antimalware software and it cleaned up most but it picked up Trojan.BHO

Here's MBAM's output file:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7622

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

10/31/2011 2:18:03 PM
mbam-log-2011-10-31 (14-17-52).txt

Scan type: Quick scan
Objects scanned: 184484
Time elapsed: 6 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


HJT output file: Also Attached

Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 2:09:30 PM, on 10/31/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe
C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe
C:\Windows\MHotKey.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\CNYHKey.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\MHotkey.exe C:\Windows\ModLedKey.exe
C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\ChiFuncExt.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…00-01e&c=BB
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsearcher.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {0E7AF71C-0D74-441D-A6FD-E939B66D905d} - C:\Users\Admin\AppData\Local\NetworkWMP.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: CA Anti-Phishing Toolbar Helper - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: WinZip Courier BHO - {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\PROGRA~2\WINZIP~2\wzwmcie.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Vuze Remote - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: CA Anti-Phishing Toolbar - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O3 - Toolbar: (no name) - {DAB35D68-1CDC-4375-8333-D7BBCEE3C0A0} - (no file)
O4 - HKLM\..\Run: [LchDrvKey] LchDrvKey.exe
O4 - HKLM\..\Run: [LedKey] CNYHKey.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [-1560979195] rundll32.exe "C:\Users\Admin\AppData\Local\Temp\nsc746A.tmp\quota.dll",DllRegisterServer
O4 - HKCU\..\Run: [IntegralPro Update] rundll32 "C:\Users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.dll",DllRegisterServer
O4 - HKCU\..\Run: [DirectxOnlineTray] rundll32.exe "C:\ProgramData\DirectxOnlineTray.dll",DllRegisterServer
O4 - HKCU\..\Run: [Monkey's Update] rundll32 "C:\Users\Admin\AppData\Local\{5199B627-11F3-4F3E-A210-262BD2DED8DB}\{5199B627-11F3-4F3E-A210-262BD2
DED8DB}Update\{5199B627-11F3-4F3E-A210-262BD2DED8DB}up.dll",DllRegisterServer
O4 - HKCU\..\Run: [ChiconyKye Update] rundll32 "C:\Users\Admin\AppData\Local\ATI\ATIUpdate\ATIup.dll",DllRegisterServer
O4 - HKCU\..\Run: [Hpfwyvmytd Update] rundll32 C:\Users\Admin\AppData\Local\ElevatedDiagnostics\ElevatedDiagnosticsUpdate\ElevatedDiagnosticsup.dll",DllRegisterServer
O4 - HKCU\..\Run: [ORL Update] rundll32 "C:\Users\Admin\AppData\Local\FileServeManager\FileServeUpdate\FileServeup.dll",DllRegisterServer
O4 - HKCU\..\Run: [YahooPartnerToolbar Update] rundll32 "C:\Users\Admin\AppData\Local\OpenCandy\OpenCandyUpdate\OpenCandyup.dll",DllRegisterServer
O4 - HKCU\..\Run: [Data Update] rundll32 "C:\Users\Admin\AppData\Local\Mozilla\MozillaUpdate\Mozillaup.dll",DllRegisterServer
O4 - HKCU\..\Run: [CDDB Update] rundll32 "C:\Users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftup.dll",DllRegisterServer
O4 - HKCU\..\Run: [Mozilla Update] rundll32 "C:\Users\Admin\AppData\Local\Citrix\CitrixUpdate\Citrixup.dll",DllRegisterServer
O4 - HKCU\..\Run: [DelTel Update] rundll32 "C:\Users\Admin\AppData\Local\WinZipCourier\WinZipUpdate\WinZipup.dll",DllRegisterServer
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebarexe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebarexe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [StartMSu] "C:\Program Files (x86)\Creative\MediaSource5\Startmsu.exe" /s (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [StartMSu] "C:\Program Files (x86)\Creative\MediaSource5\Startmsu.exe" /s (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004- { 219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\WindowsLive\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.7.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: NameServer = 192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: NameServer = 192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: NameServer = 192.168.0.1
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CAAMSvc - CA - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe
O23 - Service: CaCCProvSP - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
O23 - Service: CA Common Scheduler Service (ccSchedulerSVC) - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Norton Disk Doctor Service (DiskDoctorService) - Symantec Corporation - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\615\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Norton SpeedDisk Service (SpeedDiskService) - Symantec Corporation - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files (x86)\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: TM Engine (UmxEngine) - CA - C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: WinSock Extention Manager (WinExtManager) - Unknown owner - C:\Windows\SysWOW64\mdmcls32.exe
O23 - Service: WinSock Svchost Manager (WinSvchostManager) - Unknown owner - C:\Windows\SysWOW64\svcprs32.exe
O23 - Service: WinSvchostManagerSrv - Unknown owner - C:\Windows\SysWOW64\cfgmig32.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 16083 bytes

Please assist as the performance of this PC has severely diminished in the last thirty days.


James

Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs created by DDS and aswMBR.exe. :)


Hi Jeff
Thanks for the quick response. Here is the DDS output file: DDS.TXT
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 23:23:44 on 2011-10-31
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6134.3612 [GMT -4:00]
.
AV: CA Anti-Virus Plus *Disabled/Updated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA}
SP: CA Anti-Virus Plus *Disabled/Updated* {ECD425A9-8C8F-D447-4EAB-6F599E267857}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: CA Personal Firewall *Enabled* {6F8E4568-E0DA-DA91-5F44-FD1E1B727591}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agr64svc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\SysWOW64\mdmcls32.exe
C:\Windows\SysWOW64\svcprs32.exe
C:\Windows\SysWOW64\cfgmig32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\ccevtmgr.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\MHotKey.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RAVCpl64.exe
C:\Program Files\CA\CA Internet Security Suite\casc.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\CNYHKey.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\ModLedKey.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Windows\ChiFuncExt.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\mobsync.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Windows\splwow64.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovep.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = Preserve
mStart Page = hxxp://www.startsearcher.com
mDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&s;=1&o;=vp64&d;=0909&m;=fx6800-01e&c;=BB
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
mWinlogon: Userinit=userinit.exe,
BHO: {0e7af71c-0d74-441d-a6fd-e939b66d905d} - C:\Users\Admin\AppData\Local\SecurityWOW64.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
BHO: CA Anti-Phishing Toolbar Helper: {45011cf5-e4a9-4f13-9093-f30a784eb9b2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: WinZip Courier BHO: {a8fb70fa-0fdf-4601-9dc4-bfa1b357204f} - C:\PROGRA~2\WINZIP~2\wzwmcie.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: CA Anti-Phishing Toolbar: {0123b506-0ad9-43aa-b0cf-916c122ad4c5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll
TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: {DAB35D68-1CDC-4375-8333-D7BBCEE3C0A0} - No File
TB: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [Google Update] "C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [-1560979195] rundll32.exe "C:\Users\Admin\AppData\Local\Temp\nsc746A.tmp\quota.dll",DllRegisterServer
uRun: [IntegralPro Update] rundll32 "C:\Users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.dll",DllRegisterServer
uRun: [DirectxOnlineTray] rundll32.exe "C:\ProgramData\DirectxOnlineTray.dll",DllRegisterServer
uRun: [Monkey's Update] rundll32 "C:\Users\Admin\AppData\Local\{5199B627-11F3-4F3E-A210-262BD2DED8DB}\{5199B627-11F3-4F3E-A210-262BD2DED8DB}Update\{5199B627-11F3-4F3E-A210-262BD2DED8DB}up.dll",DllRegisterServer
uRun: [ChiconyKye Update] rundll32 "C:\Users\Admin\AppData\Local\ATI\ATIUpdate\ATIup.dll",DllRegisterServer
uRun: [Hpfwyvmytd Update] rundll32 "C:\Users\Admin\AppData\Local\ElevatedDiagnostics\ElevatedDiagnosticsUpdate\ElevatedDiagnosticsup.dll",DllRegisterServer
uRun: [ORL Update] rundll32 "C:\Users\Admin\AppData\Local\FileServe Manager\FileServeUpdate\FileServeup.dll",DllRegisterServer
uRun: [YahooPartnerToolbar Update] rundll32 "C:\Users\Admin\AppData\Local\OpenCandy\OpenCandyUpdate\OpenCandyup.dll",DllRegisterServer
uRun: [Data Update] rundll32 "C:\Users\Admin\AppData\Local\Mozilla\MozillaUpdate\Mozillaup.dll",DllRegisterServer
uRun: [CDDB Update] rundll32 "C:\Users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftup.dll",DllRegisterServer
uRun: [Mozilla Update] rundll32 "C:\Users\Admin\AppData\Local\Citrix\CitrixUpdate\Citrixup.dll",DllRegisterServer
uRun: [DelTel Update] rundll32 "C:\Users\Admin\AppData\Local\WinZip Courier\WinZipUpdate\WinZipup.dll",DllRegisterServer
mRun: [LchDrvKey] LchDrvKey.exe
mRun: [LedKey] CNYHKey.exe
mRun: [eRecoveryService]
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
dRunOnce: [StartMSu] "C:\Program Files (x86)\Creative\MediaSource5\Startmsu.exe" /s
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver; - C:\Windows\system32\GPhotos.scr/200
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
LSP: winsflt.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E} : NameServer = 192.168.0.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: PFW - UmxWnp.Dll
AppInit_DLLs: UmxSbxExw.dll
C:\Users\Admin\AppData\Local\SecurityWOW64.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
BHO-X64: Conduit Engine - No File
BHO-X64: CA Anti-Phishing Toolbar Helper: {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: WinZip Courier BHO: {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\PROGRA~2\WINZIP~2\wzwmcie.dll
BHO-X64: WinZip Courier BHO - No File
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
BHO-X64: Vuze Remote - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: SmartSelect - No File
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB-X64: CA Anti-Phishing Toolbar: {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll
TB-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
TB-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
TB-X64: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB-X64: {DAB35D68-1CDC-4375-8333-D7BBCEE3C0A0} - No File
TB-X64: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [LchDrvKey] LchDrvKey.exe
mRun-x64: [LedKey] CNYHKey.exe
mRun-x64: [eRecoveryService]
mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
AppInit_DLLs-X64: UmxSbxExw.dll
.
============= SERVICES / DRIVERS ===============
.
R0 KmxAMRT;KmxAMRT;C:\Windows\system32\DRIVERS\KmxAMRT.sys –> C:\Windows\system32\DRIVERS\KmxAMRT.sys [?]
R0 KmxFw;KmxFw;C:\Windows\system32\DRIVERS\kmxfw.sys –> C:\Windows\system32\DRIVERS\kmxfw.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 KmxAgent;KmxAgent;C:\Windows\system32\DRIVERS\kmxagent.sys –> C:\Windows\system32\DRIVERS\kmxagent.sys [?]
R1 KmxCfg;KmxCfg;C:\Windows\system32\DRIVERS\kmxcfg.sys –> C:\Windows\system32\DRIVERS\kmxcfg.sys [?]
R1 KmxFile;KmxFile;C:\Windows\system32\DRIVERS\KmxFile.sys –> C:\Windows\system32\DRIVERS\KmxFile.sys [?]
R1 KmxFilter;HIPS Core Filter Driver;C:\Windows\system32\DRIVERS\KmxFilter.sys –> C:\Windows\system32\DRIVERS\KmxFilter.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?]
R2 CAAMSvc;CAAMSvc;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe [2010-10-28 291656]
R2 CAISafe;CAISafe;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe [2010-1-21 312656]
R2 ccSchedulerSVC;CA Common Scheduler Service;C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe [2010-1-21 286032]
R2 DiskDoctorService;Norton Disk Doctor Service;C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [2010-12-27 1029480]
R2 ETService;Empowering Technology Service;C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [2009-11-17 24576]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 KmxCF;KmxCF;C:\Windows\system32\DRIVERS\KmxCF.sys –> C:\Windows\system32\DRIVERS\KmxCF.sys [?]
R2 KmxSbx;KmxSbx;C:\Windows\system32\DRIVERS\KmxSbx.sys –> C:\Windows\system32\DRIVERS\KmxSbx.sys [?]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-9-23 641832]
R2 SpeedDiskService;Norton SpeedDisk Service;C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [2010-12-27 1037672]
R2 UmxEngine;TM Engine;C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe [2011-4-4 920656]
R2 WinExtManager;WinSock Extention Manager;C:\Windows\SysWOW64\mdmcls32.exe [2010-12-25 3207184]
R2 WinSvchostManager;WinSock Svchost Manager;C:\Windows\SysWOW64\svcprs32.exe [2010-12-25 2760720]
R2 WinSvchostManagerSrv;WinSvchostManagerSrv;C:\Windows\SysWOW64\cfgmig32.exe [2010-12-25 263504]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;C:\Windows\system32\DRIVERS\e1y60x64.sys –> C:\Windows\system32\DRIVERS\e1y60x64.sys [?]
R3 gwfilt64;gwfilt64;C:\Windows\system32\drivers\gwfilt64.sys –> C:\Windows\system32\drivers\gwfilt64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-23 136176]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-1-9 79360]
S3 fssfltr;FssFltr;C:\Windows\system32\DRIVERS\fssfltr.sys –> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-23 136176]
S3 HPEWSFXBULK;HPEWSFXBULK;C:\Windows\system32\drivers\hpfx64bulk.sys –> C:\Windows\system32\drivers\hpfx64bulk.sys [?]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 Symantec Core LC;Symantec Core LC;C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [2008-1-9 1245064]
S3 SymDSMon;SymDSMon;\??\C:\Windows\system32\drivers\SymDSMon.sys –> C:\Windows\system32\drivers\SymDSMon.sys [?]
S3 SYMSpeedDisk;SYMSpeedDisk;C:\Windows\System32\drivers\SymSpeedDisk.sys [2010-12-27 108800]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 Auliaflisa;Auliaflisa; [x]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-11-19 89920]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-11-01 03:08:27 294912 —-a-w- C:\Users\Admin\AppData\Local\SecurityWOW64.dll
2011-10-31 11:39:32 294912 —-a-w- C:\Users\Admin\AppData\Local\NetworkWMP.dll
2011-10-30 16:58:13 294912 —-a-w- C:\Users\Admin\AppData\Local\TrayWin32.dll
2011-10-30 13:20:06 294912 —-a-w- C:\Users\Admin\AppData\Local\NetworkWin32.dll
2011-10-30 04:56:13 294912 —-a-w- C:\Users\Admin\AppData\Local\Securityx86_x64.dll
2011-10-30 04:20:55 ——– d—–w- C:\Users\Admin\AppData\Roaming\Malwarebytes
2011-10-30 04:20:39 ——– d—–w- C:\ProgramData\Malwarebytes
2011-10-30 04:20:34 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-10-30 04:20:34 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-10-30 03:57:04 294912 —-a-w- C:\Users\Admin\AppData\Local\SecuritySys32.dll
2011-10-29 18:34:34 388096 —-a-r- C:\Users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-29 18:34:32 ——– d—–w- C:\Program Files (x86)\Trend Micro
2011-10-29 12:57:18 294912 —-a-w- C:\Users\Admin\AppData\Local\Explorerx86_x64.dll
2011-10-28 20:46:26 294912 —-a-w- C:\Users\Admin\AppData\Local\Servicex86_x64.dll
2011-10-28 19:10:38 294912 —-a-w- C:\Users\Admin\AppData\Local\SecurityWin32.dll
2011-10-28 17:34:51 294912 —-a-w- C:\Users\Admin\AppData\Local\ServiceSys32.dll
2011-10-28 13:40:03 294912 —-a-w- C:\Users\Admin\AppData\Local\TCPIPWMP.dll
2011-10-28 13:39:49 129024 —-a-w- C:\ProgramData\DirectxOnlineTray.dll
2011-10-14 23:54:59 9049936 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A8D30E98-67CE-4263-A46B-1E88087603AA}\mpengine.dll
2011-10-13 00:10:00 2764288 —-a-w- C:\Windows\System32\win32k.sys
2011-10-13 00:09:31 847360 —-a-w- C:\Windows\System32\oleaut32.dll
2011-10-13 00:09:31 735744 —-a-w- C:\Windows\System32\UIAutomationCore.dll
2011-10-13 00:09:31 563712 —-a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-13 00:09:31 555520 —-a-w- C:\Windows\SysWow64\UIAutomationCore.dll
2011-10-13 00:09:31 4096 —-a-w- C:\Windows\SysWow64\oleaccrc.dll
2011-10-13 00:09:31 4096 —-a-w- C:\Windows\System32\oleaccrc.dll
2011-10-13 00:09:31 332288 —-a-w- C:\Windows\System32\oleacc.dll
2011-10-13 00:09:31 238080 —-a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-13 00:08:59 73216 —-a-w- C:\Windows\System32\MSDvbNP.ax
2011-10-13 00:08:59 69632 —-a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2011-10-13 00:08:59 57856 —-a-w- C:\Windows\SysWow64\MSDvbNP.ax
2011-10-13 00:08:59 375808 —-a-w- C:\Windows\System32\psisdecd.dll
2011-10-13 00:08:59 293376 —-a-w- C:\Windows\SysWow64\psisdecd.dll
2011-10-13 00:08:59 289792 —-a-w- C:\Windows\System32\psisrndr.ax
2011-10-13 00:08:59 217088 —-a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-13 00:08:59 100352 —-a-w- C:\Windows\System32\Mpeg2Data.ax
2011-10-12 00:03:05 ——– d—–w- C:\Program Files\iPod
2011-10-12 00:02:31 ——– d—–w- C:\Program Files\iTunes
2011-10-12 00:02:31 ——– d—–w- C:\Program Files (x86)\iTunes
2011-10-11 23:54:35 ——– d—–w- C:\Program Files\Bonjour
2011-10-11 23:54:35 ——– d—–w- C:\Program Files (x86)\Bonjour
.
==================== Find3M ====================
.
2011-10-16 09:41:04 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-12 01:06:22 72080 —-a-w- C:\Users\Admin\g2mdlhlpx.exe
2011-09-16 08:23:07 2524176 —-a-w- C:\Windows\System32\winsflt.dll
2011-09-16 08:23:07 1744912 —-a-w- C:\Windows\SysWow64\winsflt.dll
2011-09-16 08:19:45 1422672 —-a-w- C:\Windows\SysWow64\cfgmig32.dll
2011-09-16 08:19:45 1422672 —-a-w- C:\Windows\System32\cfgmig32.dll
2011-09-16 08:19:44 263504 —-a-w- C:\Windows\SysWow64\cfgmig32.exe
2011-09-16 08:19:36 95568 —-a-w- C:\Windows\System32\vetredir.dll
2011-09-16 08:19:36 141136 —-a-w- C:\Windows\System32\isafeif64.dll
2011-09-16 08:19:36 128336 —-a-w- C:\Windows\System32\isafeif.dll
2011-09-16 08:19:36 103760 —-a-w- C:\Windows\System32\vetredir64.dll
2011-09-14 15:47:42 60416 —-a-w- C:\Windows\System32\OVDecode64.dll
2011-09-14 15:47:40 53760 —-a-w- C:\Windows\SysWow64\OVDecode.dll
2011-09-14 15:47:10 16652288 —-a-w- C:\Windows\System32\amdocl64.dll
2011-09-14 15:38:30 44032 —-a-w- C:\Windows\System32\amdoclcl64.dll
2011-09-14 15:38:28 37376 —-a-w- C:\Windows\SysWow64\amdoclcl.dll
2011-09-08 18:27:22 10203648 —-a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-09-08 17:59:44 24229376 —-a-w- C:\Windows\System32\atio6axx.dll
2011-09-08 17:39:44 18534912 —-a-w- C:\Windows\SysWow64\atioglxx.dll
2011-09-08 17:34:20 151552 —-a-w- C:\Windows\System32\atiapfxx.exe
2011-09-08 17:34:10 732672 —-a-w- C:\Windows\SysWow64\aticfx32.dll
2011-09-08 17:32:58 862720 —-a-w- C:\Windows\System32\aticfx64.dll
2011-09-08 17:30:38 466944 —-a-w- C:\Windows\System32\ATIDEMGX.dll
2011-09-08 17:30:26 486912 —-a-w- C:\Windows\System32\atieclxx.exe
2011-09-08 17:29:56 204288 —-a-w- C:\Windows\System32\atiesrxx.exe
2011-09-08 17:28:54 120320 —-a-w- C:\Windows\System32\atitmm64.dll
2011-09-08 17:28:38 423424 —-a-w- C:\Windows\System32\atipdl64.dll
2011-09-08 17:28:32 356352 —-a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-09-08 17:28:22 278528 —-a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-09-08 17:28:18 21504 —-a-w- C:\Windows\System32\atimuixx.dll
2011-09-08 17:28:14 59392 —-a-w- C:\Windows\System32\atiedu64.dll
2011-09-08 17:28:10 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-09-08 17:24:38 4204032 —-a-w- C:\Windows\SysWow64\atidxx32.dll
2011-09-08 17:18:56 1113088 —-a-w- C:\Windows\System32\atiumd6v.dll
2011-09-08 17:18:22 1828864 —-a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-09-08 17:18:08 3888640 —-a-w- C:\Windows\System32\atiumd6a.dll
2011-09-08 17:16:00 4944896 —-a-w- C:\Windows\System32\atidxx64.dll
2011-09-08 17:09:42 51200 —-a-w- C:\Windows\System32\aticalrt64.dll
2011-09-08 17:09:40 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll
2011-09-08 17:09:30 44544 —-a-w- C:\Windows\System32\aticalcl64.dll
2011-09-08 17:09:28 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll
2011-09-08 17:09:18 8723456 —-a-w- C:\Windows\System32\aticaldd64.dll
2011-09-08 17:08:24 4064768 —-a-w- C:\Windows\SysWow64\atiumdva.dll
2011-09-08 17:05:52 7331840 —-a-w- C:\Windows\SysWow64\aticaldd.dll
2011-09-08 17:05:44 4289024 —-a-w- C:\Windows\SysWow64\atiumdag.dll
2011-09-08 17:00:02 5428736 —-a-w- C:\Windows\System32\atiumd64.dll
2011-09-08 16:59:48 58880 —-a-w- C:\Windows\System32\coinst.dll
2011-09-08 16:53:20 381952 —-a-w- C:\Windows\System32\atiadlxx.dll
2011-09-08 16:53:12 270336 —-a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-09-08 16:52:58 15360 —-a-w- C:\Windows\System32\atig6pxx.dll
2011-09-08 16:52:56 13312 —-a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-09-08 16:52:56 13312 —-a-w- C:\Windows\System32\atiglpxx.dll
2011-09-08 16:52:54 39936 —-a-w- C:\Windows\System32\atig6txx.dll
2011-09-08 16:52:46 32768 —-a-w- C:\Windows\SysWow64\atigktxx.dll
2011-09-08 16:52:40 310784 —-a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-09-08 16:52:00 40960 —-a-w- C:\Windows\System32\atiuxp64.dll
2011-09-08 16:51:54 31744 —-a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-09-08 16:51:50 38912 —-a-w- C:\Windows\System32\atiu9p64.dll
2011-09-08 16:51:44 29184 —-a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-09-08 16:51:28 45056 —-a-w- C:\Windows\System32\atitmp64.dll
2011-09-08 16:51:12 53248 —-a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-09-08 16:51:02 54784 —-a-w- C:\Windows\System32\atimpc64.dll
2011-09-08 16:51:02 54784 —-a-w- C:\Windows\System32\amdpcom64.dll
2011-09-08 16:50:54 53760 —-a-w- C:\Windows\SysWow64\atimpc32.dll
2011-09-08 16:50:54 53760 —-a-w- C:\Windows\SysWow64\amdpcom32.dll
2011-09-01 05:24:07 2309120 —-a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 —-a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-31 03:05:32 96104 —-a-w- C:\Windows\System32\dns-sd.exe
2011-08-31 03:05:32 85864 —-a-w- C:\Windows\System32\dnssd.dll
2011-08-31 03:05:04 83816 —-a-w- C:\Windows\SysWow64\dns-sd.exe
2011-08-31 03:05:04 73064 —-a-w- C:\Windows\SysWow64\dnssd.dll
2011-08-25 00:19:10 56320 —-a-w- C:\Windows\SysWow64\OpenVideo.dll
2011-08-25 00:18:30 13601280 —-a-w- C:\Windows\SysWow64\amdocl.dll
2011-08-25 00:17:52 43520 —-a-w- C:\Windows\SysWow64\OpenCL.dll
.
============= FINISH: 23:25:25.69 ===============

Here is the outfle for the ATTACH.TXT

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 9/10/2009 5:36:39 PM
System Uptime: 10/31/2011 11:05:03 PM (0 hours ago)
.
Motherboard: Gateway | | TBGM01
Processor: Intel® Core™ i7 CPU 920 @ 2.67GHz | CPU 1 | 2667/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 689 GiB total, 42.603 GiB free.
D: is CDROM (UDF)
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft 6to4 Adapter
Device ID: ROOT\*6TO4MP\0001
Manufacturer: Microsoft
Name: Microsoft 6to4 Adapter #2
PNP Device ID: ROOT\*6TO4MP\0001
Service: tunnel
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft 6to4 Adapter
Device ID: ROOT\*6TO4MP\0002
Manufacturer: Microsoft
Name: Microsoft 6to4 Adapter #3
PNP Device ID: ROOT\*6TO4MP\0002
Service: tunnel
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&6730480&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&6730480&0
Service: i8042prt
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
.
Update for Microsoft Office 2007 (KB2508958)
2008 National Repair and Remodeling Estimator Download
2011 National Repair and Remodeling Estimator
2011 National Repair and Remodeling Estimator License
Adobe Acrobat 9 Pro - English, Français, Deutsch
Adobe Acrobat 9.1.2 - CPSID_49166
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Creative Suite
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Illustrator CS
Adobe Photoshop CS
Adobe Shockwave Player 11.5
Adobe SVG Viewer 6.0
Advertising Center
Amazon MP3 Downloader 1.0.10
Apple Application Support
Apple Software Update
Application Profiles
AVerMedia M791 PCIe Combo NTSC/ATSC 6.104.64.5
CA Anti-Spam
CA Backup and Migration
CA Parental Controls
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
CCC Help English
Compatibility Pack for the 2007 Office system
Conduit Engine
CyberLink LabelPrint
D3DX10
DNAMigrator
DolbyFiles
EPSON Scan
Forté Agent
Gateway Recovery Management
GearDrvs
Google Earth Plug-in
Google Talk Plugin
Google Update Helper
GoToAssist Corporate
GoToMeeting 4.8.0.723
High-Definition Video Playback
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
ImagXpress
Intuit SiteBuilder
Java Auto Updater
Java™ 6 Update 22
Java™ 6 Update 5
Junk Mail filter update
KB0817 Keyboard Driver
Lane Guide Online Launcher version 1.0
Malwarebytes' Anti-Malware version 1.51.2.1300
Menu Templates - Starter Kit
Mesh Runtime
Messenger Companion
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual J# 2.0 Redistributable Package
Monkey's Audio
Movie Templates - Starter Kit
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 10 Creative CollectionPack 1
Nero 10 Menu TemplatePack Basic
Nero 10 Movie ThemePack 3
Nero 10 Movie ThemePack 4
Nero 10 Movie ThemePack Basic
Nero 10 PiP EffectPack 1
Nero 10 Video TransitionPack 1
Nero 9
Nero BackItUp 10
Nero BackItUp 10 Help (CHM)
Nero Burning ROM 10
Nero BurningROM 10 Help (CHM)
Nero BurnRights
Nero BurnRights 10
Nero BurnRights 10 Help (CHM)
Nero Control Center 10
Nero ControlCenter
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero CoverDesigner
Nero CoverDesigner 10
Nero CoverDesigner 10 Help (CHM)
Nero Disc Copy Gadget
Nero DiscSpeed
Nero DiscSpeed 10
Nero DiscSpeed 10 Help (CHM)
Nero Dolby Files 10
Nero DriveSpeed
Nero Express 10
Nero Express 10 Help (CHM)
Nero InfoTool
Nero InfoTool 10
Nero InfoTool 10 Help (CHM)
Nero Installer
Nero Live
Nero MediaHub 10
Nero MediaHub 10 Help (CHM)
Nero Move it
Nero Move it Help
Nero Move it Trial
Nero Multimedia Suite 10
Nero PhotoSnap
Nero Recode
Nero Recode 10
Nero Recode 10 Help (CHM)
Nero Rescue Agent
Nero RescueAgent 10
Nero RescueAgent 10 Help (CHM)
Nero ShowTime
Nero SoundTrax 10
Nero SoundTrax 10 Help (CHM)
Nero StartSmart
Nero StartSmart 10
Nero StartSmart 10 Help (CHM)
Nero Update
Nero Vision
Nero Vision 10
Nero Vision 10 Help (CHM)
Nero WaveEditor
Nero WaveEditor 10
Nero WaveEditor 10 Help (CHM)
NeroBurningROM
NeroExpress
NeroLiveGadget
neroxml
Norton Utilities 15
Picasa 3
QuickTime
RapidShare Manager 2
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Segoe UI
Sound Blaster X-Fi MB
SoundTrax
Symantec Technical Support Web Controls
The National Estimator
TWC Customer Controls
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2596560)
VLC media player 1.1.11
VuePrint
VueScan
Vuze Remote Toolbar
WebEx Record and Playback
Winamp
Winamp Detector Plug-in
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player Firefox Plugin
WinZip 15.5
WinZip Courier
WinZip Self-Extractor
.
==== Event Viewer Messages From Past Week ========
.
10/31/2011 8:44:05 AM, Error: Service Control Manager [7034] - The WinSock Extention Manager service terminated unexpectedly. It has done this 2 time(s).
10/31/2011 8:22:15 AM, Error: Service Control Manager [7034] - The WinSock Extention Manager service terminated unexpectedly. It has done this 1 time(s).
10/31/2011 12:24:53 PM, Error: Service Control Manager [7034] - The Creative Audio Service service terminated unexpectedly. It has done this 1 time(s).
10/31/2011 11:08:39 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {5F36DC27-B076-4D0C-BD8C-7AEE14022193} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
10/31/2011 11:05:29 PM, Error: EventLog [6008] - The previous system shutdown at 8:17:43 PM on 10/31/2011 was unexpected.
10/30/2011 4:16:10 PM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
10/29/2011 8:31:59 AM, Error: EventLog [6008] - The previous system shutdown at 8:07:35 AM on 10/29/2011 was unexpected.
10/29/2011 2:25:07 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Volume Shadow Copy service to connect.
10/29/2011 2:25:07 PM, Error: Service Control Manager [7000] - The Volume Shadow Copy service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/29/2011 2:24:36 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service VSS with arguments "" in order to run the server: {E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
10/28/2011 2:46:39 PM, Error: EventLog [6008] - The previous system shutdown at 2:44:05 PM on 10/28/2011 was unexpected.
10/28/2011 2:30:46 PM, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/28/2011 2:30:44 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
10/28/2011 2:30:41 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}
10/28/2011 2:15:05 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the stisvc service.
10/28/2011 10:56:20 AM, Error: Service Control Manager [7034] - The WinSock Extention Manager service terminated unexpectedly. It has done this 4 time(s).
10/28/2011 10:25:07 AM, Error: Service Control Manager [7034] - The WinSock Extention Manager service terminated unexpectedly. It has done this 3 time(s).
10/27/2011 7:24:25 AM, Error: EventLog [6008] - The previous system shutdown at 7:21:59 AM on 10/27/2011 was unexpected.
10/27/2011 12:16:18 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
10/27/2011 12:16:18 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/27/2011 12:16:17 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
10/26/2011 7:31:42 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Font Cache Service service to connect.
10/26/2011 7:31:42 AM, Error: Service Control Manager [7000] - The Windows Font Cache Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/25/2011 5:55:43 PM, Error: Service Control Manager [7031] - The Norton Disk Doctor Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
.
==== End Of File ===========================


Scan Results for ASWMBR.TXT

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-31 23:28:50
—————————–
23:28:50.940 OS Version: Windows x64 6.0.6002 Service Pack 2
23:28:50.940 Number of processors: 8 586 0x1A04
23:28:50.944 ComputerName: ADMIN-PC UserName: Admin
23:28:52.970 Initialize success
23:30:40.047 AVAST engine defs: 11110100
23:31:03.346 The log file has been saved successfully to "I:\aswMBR.txt"


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-31 23:28:50
—————————–
23:28:50.940 OS Version: Windows x64 6.0.6002 Service Pack 2
23:28:50.940 Number of processors: 8 586 0x1A04
23:28:50.944 ComputerName: ADMIN-PC UserName: Admin
23:28:52.970 Initialize success
23:30:40.047 AVAST engine defs: 11110100
23:31:03.346 The log file has been saved successfully to "I:\aswMBR.txt"
23:31:17.497 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
23:31:17.498 Disk 0 Vendor: ST375063 SD46 Size: 715404MB BusType: 3
23:31:17.509 Disk 0 MBR read successfully
23:31:17.511 Disk 0 MBR scan
23:31:17.514 Disk 0 unknown MBR code
23:31:17.516 Service scanning
23:31:22.273 Modules scanning
23:31:22.275 Disk 0 trace - called modules:
23:31:22.314 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
23:31:22.316 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008997240]
23:31:22.318 3 CLASSPNP.SYS[fffffa60011aec33] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80065eb050]
23:31:24.712 AVAST engine scan C:\Windows
23:31:44.437 AVAST engine scan C:\Windows\system32
23:36:57.872 AVAST engine scan C:\Windows\system32\drivers
23:37:45.189 AVAST engine scan C:\Users\Admin
23:38:01.557 File: C:\Users\Admin\AppData\Local\ATI\ATIUpdate\ATIup.dll **INFECTED** Win32:Trojan-gen
23:38:01.839 File: C:\Users\Admin\AppData\Local\Citrix\CitrixUpdate\Citrixup.dll **INFECTED** Win32:Trojan-gen
23:38:03.759 File: C:\Users\Admin\AppData\Local\ElevatedDiagnostics\ElevatedDiagnosticsUpdate\ElevatedDiagnosticsup.dll **INFECTED** Win32:Trojan-gen
23:38:04.326 File: C:\Users\Admin\AppData\Local\FileServe Manager\FileServeUpdate\FileServeup.dll **INFECTED** Win32:Trojan-gen
23:47:20.514 File: C:\Users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftup.dll **INFECTED** Win32:Trojan-gen
23:47:20.762 File: C:\Users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.dll **INFECTED** Win32:Kryptik-FFX [Trj]
23:49:39.766 File: C:\Users\Admin\AppData\Local\Mozilla\MozillaUpdate\Mozillaup.dll **INFECTED** Win32:Trojan-gen
23:50:03.898 File: C:\Users\Admin\AppData\Local\OpenCandy\OpenCandyUpdate\OpenCandyup.dll **INFECTED** Win32:Trojan-gen
23:50:12.085 File: C:\Users\Admin\AppData\Local\Temp\nsc746A.tmp\jio18d.da_ **INFECTED** Win32:Trojan-gen
23:50:12.312 File: C:\Users\Admin\AppData\Local\Temp\nsc746A.tmp\mh78e2.da_ **INFECTED** Win32:Malware-gen
23:50:24.115 File: C:\Users\Admin\AppData\Local\WinZip Courier\WinZipUpdate\WinZipup.dll **INFECTED** Win32:Trojan-gen
23:50:24.302 File: C:\Users\Admin\AppData\Local\{5199B627-11F3-4F3E-A210-262BD2DED8DB}\{5199B627-11F3-4F3E-A210-262BD2DED8DB}Update\{5199B627-11F3-4F3E-A210-262BD2DED8DB}up.dll **INFECTED** Win32:Trojan-gen
03:01:07.338 AVAST engine scan C:\ProgramData
03:01:57.275 File: C:\ProgramData\DirectxOnlineTray.dll **INFECTED** Win32:Malware-gen
03:05:53.297 Scan finished successfully
05:56:00.633 Disk 0 MBR has been saved successfully to "I:\MBR.dat"
05:56:00.643 The log file has been saved successfully to "I:\aswMBR.txt"


Jeff, Thanks for your help. Seems like I have some infections on my computer… :(

Hi James (I hope it's ok to call you that?),

Thanks for the scan results. Actually I prefer them to be pasted just like you have done. :)
———-

I have a quick question…What brand of computer is this…Dell, Gateway, HP?
———-

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.


I have a Gateway Desktop PC FX6800-01e with 6GB mem, 750GB HD, Intel i7 CPU, 2.67 Ghz

Call me James or Greyhome

Here is the COMBOFIX.TXT output file:

ComboFix 11-11-01.04 - Admin 11/01/2011 19:46:38.1.8 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6134.2760 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: CA Anti-Virus Plus *Disabled/Updated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA}
FW: CA Personal Firewall *Disabled* {6F8E4568-E0DA-DA91-5F44-FD1E1B727591}
SP: CA Anti-Virus Plus *Disabled/Updated* {ECD425A9-8C8F-D447-4EAB-6F599E267857}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\desktop.ini
c:\program files (x86)\Object
c:\program files (x86)\Object\config.ini
c:\programdata\IntelUpdateProfile.dll
c:\users\Admin\AppData\Local\{5199B627-11F3-4F3E-A210-262BD2DED8DB}\{5199B627-11F3-4F3E-A210-262BD2DED8DB}Update\{5199B627-11F3-4F3E-A210-262BD2DED8DB}up.dll
c:\users\Admin\AppData\Local\ATI\ATIUpdate\ATIup.dll
c:\users\Admin\AppData\Local\Citrix\CitrixUpdate\Citrixup.dll
c:\users\Admin\AppData\Local\ElevatedDiagnostics\ElevatedDiagnosticsUpdate\ElevatedDiagnosticsup.dll
c:\users\Admin\AppData\Local\Explorerx86_x64.dll
c:\users\Admin\AppData\Local\FileServe Manager\FileServeUpdate\FileServeup.dll
c:\users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftup.dll
c:\users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.dll
c:\users\Admin\AppData\Local\Mozilla\MozillaUpdate\Mozillaup.dll
c:\users\Admin\AppData\Local\NetworkWin32.dll
c:\users\Admin\AppData\Local\NetworkWMP.dll
c:\users\Admin\AppData\Local\OpenCandy\OpenCandyUpdate\OpenCandyup.dll
c:\users\Admin\AppData\Local\SecuritySys32.dll
c:\users\Admin\AppData\Local\SecurityWin32.dll
c:\users\Admin\AppData\Local\SecurityWOW64.dll
c:\users\Admin\AppData\Local\Securityx86_x64.dll
c:\users\Admin\AppData\Local\ServiceCodec.dll
c:\users\Admin\AppData\Local\ServiceSys32.dll
c:\users\Admin\AppData\Local\Servicex86_x64.dll
c:\users\Admin\AppData\Local\TCPIPWMP.dll
c:\users\Admin\AppData\Local\Temp\nsc746A.tmp\quota.dll
c:\users\Admin\AppData\Local\TrayWin32.dll
c:\users\Admin\AppData\Local\WinZip Courier\WinZipUpdate\WinZipup.dll
c:\users\Admin\g2mdlhlpx.exe
c:\users\Admin\GoToAssistDownloadHelper.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-10-02 to 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-02 01:44 . 2011-11-02 01:44 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-11-02 01:44 . 2011-11-02 01:44 ——– d—–w- c:\users\Admin\AppData\Local\temp
2011-10-30 04:20 . 2011-10-30 04:20 ——– d—–w- c:\users\Admin\AppData\Roaming\Malwarebytes
2011-10-30 04:20 . 2011-10-30 04:20 ——– d—–w- c:\programdata\Malwarebytes
2011-10-30 04:20 . 2011-10-31 18:18 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-10-30 04:20 . 2011-08-31 21:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-29 18:34 . 2011-10-29 18:34 388096 —-a-r- c:\users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-29 18:34 . 2011-10-29 18:34 ——– d—–w- c:\program files (x86)\Trend Micro
2011-10-14 23:54 . 2011-09-13 00:26 9049936 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8D30E98-67CE-4263-A46B-1E88087603AA}\mpengine.dll
2011-10-13 00:10 . 2011-09-06 13:56 2764288 —-a-w- c:\windows\system32\win32k.sys
2011-10-13 00:09 . 2011-08-25 16:20 735744 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-13 00:09 . 2011-08-25 16:19 847360 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 00:09 . 2011-08-25 16:19 332288 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 00:09 . 2011-08-25 16:15 555520 —-a-w- c:\windows\SysWow64\UIAutomationCore.dll
2011-10-13 00:09 . 2011-08-25 16:14 563712 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-13 00:09 . 2011-08-25 16:14 238080 —-a-w- c:\windows\SysWow64\oleacc.dll
2011-10-13 00:09 . 2011-08-25 13:54 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-10-13 00:09 . 2011-08-25 13:31 4096 —-a-w- c:\windows\SysWow64\oleaccrc.dll
2011-10-13 00:08 . 2011-07-29 16:08 375808 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 00:08 . 2011-07-29 16:08 289792 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 00:08 . 2011-07-29 16:06 73216 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-10-13 00:08 . 2011-07-29 16:06 100352 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-13 00:08 . 2011-07-29 16:01 293376 —-a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-13 00:08 . 2011-07-29 16:01 217088 —-a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-13 00:08 . 2011-07-29 16:00 57856 —-a-w- c:\windows\SysWow64\MSDvbNP.ax
2011-10-13 00:08 . 2011-07-29 16:00 69632 —-a-w- c:\windows\SysWow64\Mpeg2Data.ax
2011-10-12 00:03 . 2011-10-12 00:03 ——– d—–w- c:\program files\iPod
2011-10-12 00:02 . 2011-10-12 00:03 ——– d—–w- c:\program files\iTunes
2011-10-12 00:02 . 2011-10-12 00:03 ——– d—–w- c:\program files (x86)\iTunes
2011-10-11 23:54 . 2011-10-11 23:54 ——– d—–w- c:\program files\Bonjour
2011-10-11 23:54 . 2011-10-11 23:54 ——– d—–w- c:\program files (x86)\Bonjour
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-16 09:41 . 2011-06-07 10:25 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-16 08:23 . 2010-12-26 00:43 2524176 —-a-w- c:\windows\system32\winsflt.dll
2011-09-16 08:23 . 2010-12-26 00:43 1744912 —-a-w- c:\windows\SysWow64\winsflt.dll
2011-09-16 08:19 . 2010-12-26 00:43 1422672 —-a-w- c:\windows\SysWow64\cfgmig32.dll
2011-09-16 08:19 . 2010-12-26 00:43 1422672 —-a-w- c:\windows\system32\cfgmig32.dll
2011-09-16 08:19 . 2010-12-26 00:43 263504 —-a-w- c:\windows\SysWow64\cfgmig32.exe
2011-09-16 08:19 . 2011-09-16 08:20 95568 —-a-w- c:\windows\system32\vetredir.dll
2011-09-16 08:19 . 2011-09-16 08:20 128336 —-a-w- c:\windows\system32\isafeif.dll
2011-09-16 08:19 . 2010-01-21 13:34 141136 —-a-w- c:\windows\system32\isafeif64.dll
2011-09-16 08:19 . 2010-01-21 13:34 103760 —-a-w- c:\windows\system32\vetredir64.dll
2011-09-14 15:47 . 2011-09-14 15:47 60416 —-a-w- c:\windows\system32\OVDecode64.dll
2011-09-14 15:47 . 2011-09-14 15:47 53760 —-a-w- c:\windows\SysWow64\OVDecode.dll
2011-09-14 15:47 . 2011-09-14 15:47 16652288 —-a-w- c:\windows\system32\amdocl64.dll
2011-09-14 15:38 . 2011-09-14 15:38 44032 —-a-w- c:\windows\system32\amdoclcl64.dll
2011-09-14 15:38 . 2011-09-14 15:38 37376 —-a-w- c:\windows\SysWow64\amdoclcl.dll
2011-09-08 18:27 . 2011-09-08 18:27 10203648 —-a-w- c:\windows\system32\drivers\atikmdag.sys
2011-09-08 17:59 . 2011-09-08 17:59 24229376 —-a-w- c:\windows\system32\atio6axx.dll
2011-09-08 17:39 . 2011-09-08 17:39 18534912 —-a-w- c:\windows\SysWow64\atioglxx.dll
2011-09-08 17:34 . 2011-09-08 17:34 151552 —-a-w- c:\windows\system32\atiapfxx.exe
2011-09-08 17:34 . 2011-09-08 17:34 732672 —-a-w- c:\windows\SysWow64\aticfx32.dll
2011-09-08 17:32 . 2011-07-28 21:39 862720 —-a-w- c:\windows\system32\aticfx64.dll
2011-09-08 17:30 . 2011-09-08 17:30 466944 —-a-w- c:\windows\system32\ATIDEMGX.dll
2011-09-08 17:30 . 2011-09-08 17:30 486912 —-a-w- c:\windows\system32\atieclxx.exe
2011-09-08 17:29 . 2011-09-08 17:29 204288 —-a-w- c:\windows\system32\atiesrxx.exe
2011-09-08 17:28 . 2011-09-08 17:28 120320 —-a-w- c:\windows\system32\atitmm64.dll
2011-09-08 17:28 . 2011-09-08 17:28 423424 —-a-w- c:\windows\system32\atipdl64.dll
2011-09-08 17:28 . 2011-09-08 17:28 356352 —-a-w- c:\windows\SysWow64\atipdlxx.dll
2011-09-08 17:28 . 2011-09-08 17:28 278528 —-a-w- c:\windows\SysWow64\Oemdspif.dll
2011-09-08 17:28 . 2011-09-08 17:28 21504 —-a-w- c:\windows\system32\atimuixx.dll
2011-09-08 17:28 . 2011-09-08 17:28 59392 —-a-w- c:\windows\system32\atiedu64.dll
2011-09-08 17:28 . 2011-09-08 17:28 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll
2011-09-08 17:24 . 2011-09-08 17:24 4204032 —-a-w- c:\windows\SysWow64\atidxx32.dll
2011-09-08 17:18 . 2011-09-08 17:18 1113088 —-a-w- c:\windows\system32\atiumd6v.dll
2011-09-08 17:18 . 2011-09-08 17:18 1828864 —-a-w- c:\windows\SysWow64\atiumdmv.dll
2011-09-08 17:18 . 2011-07-28 21:11 3888640 —-a-w- c:\windows\system32\atiumd6a.dll
2011-09-08 17:16 . 2011-09-08 17:16 4944896 —-a-w- c:\windows\system32\atidxx64.dll
2011-09-08 17:09 . 2011-09-08 17:09 51200 —-a-w- c:\windows\system32\aticalrt64.dll
2011-09-08 17:09 . 2011-09-08 17:09 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll
2011-09-08 17:09 . 2011-09-08 17:09 44544 —-a-w- c:\windows\system32\aticalcl64.dll
2011-09-08 17:09 . 2011-09-08 17:09 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll
2011-09-08 17:09 . 2011-09-08 17:09 8723456 —-a-w- c:\windows\system32\aticaldd64.dll
2011-09-08 17:08 . 2011-09-08 17:08 4064768 —-a-w- c:\windows\SysWow64\atiumdva.dll
2011-09-08 17:05 . 2011-09-08 17:05 7331840 —-a-w- c:\windows\SysWow64\aticaldd.dll
2011-09-08 17:05 . 2011-09-08 17:05 4289024 —-a-w- c:\windows\SysWow64\atiumdag.dll
2011-09-08 17:00 . 2011-07-28 21:02 5428736 —-a-w- c:\windows\system32\atiumd64.dll
2011-09-08 16:59 . 2011-07-28 21:01 58880 —-a-w- c:\windows\system32\coinst.dll
2011-09-08 16:53 . 2011-09-08 16:53 381952 —-a-w- c:\windows\system32\atiadlxx.dll
2011-09-08 16:53 . 2011-09-08 16:53 270336 —-a-w- c:\windows\SysWow64\atiadlxy.dll
2011-09-08 16:52 . 2011-09-08 16:52 15360 —-a-w- c:\windows\system32\atig6pxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 13312 —-a-w- c:\windows\SysWow64\atiglpxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 13312 —-a-w- c:\windows\system32\atiglpxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 39936 —-a-w- c:\windows\system32\atig6txx.dll
2011-09-08 16:52 . 2011-09-08 16:52 32768 —-a-w- c:\windows\SysWow64\atigktxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 310784 —-a-w- c:\windows\system32\drivers\atikmpag.sys
2011-09-08 16:52 . 2011-09-08 16:52 40960 —-a-w- c:\windows\system32\atiuxp64.dll
2011-09-08 16:51 . 2011-09-08 16:51 31744 —-a-w- c:\windows\SysWow64\atiuxpag.dll
2011-09-08 16:51 . 2011-07-28 20:53 38912 —-a-w- c:\windows\system32\atiu9p64.dll
2011-09-08 16:51 . 2011-09-08 16:51 29184 —-a-w- c:\windows\SysWow64\atiu9pag.dll
2011-09-08 16:51 . 2011-07-28 20:52 45056 —-a-w- c:\windows\system32\atitmp64.dll
2011-09-08 16:51 . 2011-09-08 16:51 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll
2011-09-08 16:51 . 2011-09-08 16:51 54784 —-a-w- c:\windows\system32\atimpc64.dll
2011-09-08 16:51 . 2011-09-08 16:51 54784 —-a-w- c:\windows\system32\amdpcom64.dll
2011-09-08 16:50 . 2011-09-08 16:50 53760 —-a-w- c:\windows\SysWow64\atimpc32.dll
2011-09-08 16:50 . 2011-09-08 16:50 53760 —-a-w- c:\windows\SysWow64\amdpcom32.dll
2011-08-31 03:05 . 2011-08-31 03:05 96104 —-a-w- c:\windows\system32\dns-sd.exe
2011-08-31 03:05 . 2011-08-31 03:05 85864 —-a-w- c:\windows\system32\dnssd.dll
2011-08-31 03:05 . 2011-08-31 03:05 83816 —-a-w- c:\windows\SysWow64\dns-sd.exe
2011-08-31 03:05 . 2011-08-31 03:05 73064 —-a-w- c:\windows\SysWow64\dnssd.dll
2011-08-25 00:19 . 2011-08-25 00:19 56320 —-a-w- c:\windows\SysWow64\OpenVideo.dll
2011-08-25 00:18 . 2011-08-25 00:18 13601280 —-a-w- c:\windows\SysWow64\amdocl.dll
2011-08-25 00:17 . 2011-08-25 00:17 43520 —-a-w- c:\windows\SysWow64\OpenCL.dll
2011-08-06 14:54 . 2011-08-06 14:54 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll
2011-08-06 14:54 . 2011-08-06 14:54 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-08-06 14:54 . 2011-08-06 14:54 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-08-06 14:54 . 2011-08-06 14:54 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll
2011-08-06 14:54 . 2011-08-06 14:54 161792 —-a-w- c:\windows\SysWow64\msls31.dll
2011-08-06 14:54 . 2011-08-06 14:54 63488 —-a-w- c:\windows\SysWow64\tdc.ocx
2011-08-06 14:54 . 2011-08-06 14:54 367104 —-a-w- c:\windows\SysWow64\html.iec
2011-08-06 14:54 . 2011-08-06 14:54 74752 —-a-w- c:\windows\SysWow64\iesetup.dll
2011-08-06 14:54 . 2011-08-06 14:54 420864 —-a-w- c:\windows\SysWow64\vbscript.dll
2011-08-06 14:54 . 2011-08-06 14:54 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll
2011-08-06 14:54 . 2011-08-06 14:54 152064 —-a-w- c:\windows\SysWow64\wextract.exe
2011-08-06 14:54 . 2011-08-06 14:54 150528 —-a-w- c:\windows\SysWow64\iexpress.exe
2011-08-06 14:54 . 2011-08-06 14:54 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2011-08-06 14:54 . 2011-08-06 14:54 35840 —-a-w- c:\windows\SysWow64\imgutil.dll
2011-08-06 14:54 . 2011-08-06 14:54 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2011-08-06 14:54 . 2011-08-06 14:54 11776 —-a-w- c:\windows\SysWow64\mshta.exe
2011-08-06 14:54 . 2011-08-06 14:54 101888 —-a-w- c:\windows\SysWow64\admparse.dll
2011-08-06 14:54 . 2011-08-06 14:54 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-08-06 14:54 . 2011-08-06 14:54 222208 —-a-w- c:\windows\system32\msls31.dll
2011-08-06 14:54 . 2011-08-06 14:54 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-08-06 14:54 . 2011-08-06 14:54 49664 —-a-w- c:\windows\system32\imgutil.dll
2011-08-06 14:54 . 2011-08-06 14:54 12288 —-a-w- c:\windows\system32\mshta.exe
2011-08-06 14:54 . 2011-08-06 14:54 114176 —-a-w- c:\windows\system32\admparse.dll
2011-08-06 14:54 . 2011-08-06 14:54 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-08-06 14:54 . 2011-08-06 14:54 76800 —-a-w- c:\windows\system32\tdc.ocx
2011-08-06 14:54 . 2011-08-06 14:54 48640 —-a-w- c:\windows\system32\mshtmler.dll
2011-08-06 14:54 . 2011-08-06 14:54 448512 —-a-w- c:\windows\system32\html.iec
2011-08-06 14:54 . 2011-08-06 14:54 135168 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-08-06 14:54 . 2011-08-06 14:54 111616 —-a-w- c:\windows\system32\iesysprep.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 20:54 175912 —-a-w- c:\program files (x86)\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 20:54 175912 —-a-w- c:\program files (x86)\Vuze_Remote\prxtbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LchDrvKey"="LchDrvKey.exe" [2007-03-28 36864]
"LedKey"="CNYHKey.exe" [2008-04-23 339968]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-08 343168]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"StartMSu"="c:\program files (x86)\Creative\MediaSource5\Startmsu.exe" [2006-10-02 81920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2011-02-24 18:33 79368 —-a-w- c:\windows\System32\UmxWNP.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 136176]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-01-10 79360]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 136176]
R3 HPEWSFXBULK;HPEWSFXBULK;c:\windows\system32\drivers\hpfx64bulk.sys [x]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTS5121.sys [x]
R3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 SymDSMon;SymDSMon;c:\windows\system32\drivers\SymDSMon.sys [x]
R3 SYMSpeedDisk;SYMSpeedDisk;c:\windows\system32\drivers\SymSpeedDisk.sys [2010-11-30 163384]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
R4 Auliaflisa;Auliaflisa; [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 KmxAMRT;KmxAMRT;c:\windows\system32\DRIVERS\KmxAMRT.sys [x]
S0 KmxFw;KmxFw;c:\windows\System32\DRIVERS\kmxfw.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 KmxAgent;KmxAgent;c:\windows\system32\DRIVERS\kmxagent.sys [x]
S1 KmxCfg;KmxCfg;c:\windows\system32\DRIVERS\kmxcfg.sys [x]
S1 KmxFile;KmxFile;c:\windows\system32\DRIVERS\KmxFile.sys [x]
S1 KmxFilter;HIPS Core Filter Driver;c:\windows\system32\DRIVERS\KmxFilter.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 CAAMSvc;CAAMSvc;c:\program files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe [2011-10-17 291656]
S2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [2011-09-16 286032]
S2 DiskDoctorService;Norton Disk Doctor Service;c:\program files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [2010-11-30 1029480]
S2 ETService;Empowering Technology Service;c:\program files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [2008-06-11 24576]
S2 KmxCF;KmxCF;c:\windows\system32\DRIVERS\KmxCF.sys [x]
S2 KmxSbx;KmxSbx;c:\windows\system32\DRIVERS\KmxSbx.sys [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]
S2 SpeedDiskService;Norton SpeedDisk Service;c:\program files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [2010-11-30 1037672]
S2 UmxEngine;TM Engine;c:\program files\CA\SharedComponents\TMEngine\UmxEngine.exe [2011-04-04 920656]
S2 WinExtManager;WinSock Extention Manager;c:\windows\SysWOW64\mdmcls32.exe [2011-06-29 3207184]
S2 WinSvchostManager;WinSock Svchost Manager;c:\windows\SysWOW64\svcprs32.exe [2011-06-29 2760720]
S2 WinSvchostManagerSrv;WinSvchostManagerSrv;c:\windows\SysWOW64\cfgmig32.exe [2011-09-16 263504]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [x]
S3 gwfilt64;gwfilt64;c:\windows\system32\drivers\gwfilt64.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 19:57]
.
2011-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 19:57]
.
2011-11-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000Core.job
- c:\users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 18:14]
.
2011-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000UA.job
- c:\users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 18:14]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2006-11-02 46592]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"RtHDVCpl"="RAVCpl64.exe" [2008-09-19 6495264]
"cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" [2011-09-16 2658128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\UmxSbxExA64.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.startsearcher.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
LSP: winsflt.dll
TCP: Interfaces\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: NameServer = 192.168.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{DAB35D68-1CDC-4375-8333-D7BBCEE3C0A0} - (no file)
Wow6432Node-HKCU-Run-IntegralPro Update - c:\users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.dll
Wow6432Node-HKCU-Run-Monkey's Update - c:\users\Admin\AppData\Local\{5199B627-11F3-4F3E-A210-262BD2DED8DB}\{5199B627-11F3-4F3E-A210-262BD2DED8DB}Update\{5199B627-11F3-4F3E-A210-262BD2DED8DB}up.dll
Wow6432Node-HKCU-Run-ChiconyKye Update - c:\users\Admin\AppData\Local\ATI\ATIUpdate\ATIup.dll
Wow6432Node-HKCU-Run-Hpfwyvmytd Update - c:\users\Admin\AppData\Local\ElevatedDiagnostics\ElevatedDiagnosticsUpdate\ElevatedDiagnosticsup.dll
Wow6432Node-HKCU-Run-ORL Update - c:\users\Admin\AppData\Local\FileServe Manager\FileServeUpdate\FileServeup.dll
Wow6432Node-HKCU-Run-YahooPartnerToolbar Update - c:\users\Admin\AppData\Local\OpenCandy\OpenCandyUpdate\OpenCandyup.dll
Wow6432Node-HKCU-Run-Data Update - c:\users\Admin\AppData\Local\Mozilla\MozillaUpdate\Mozillaup.dll
Wow6432Node-HKCU-Run-CDDB Update - c:\users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftup.dll
Wow6432Node-HKCU-Run-Mozilla Update - c:\users\Admin\AppData\Local\Citrix\CitrixUpdate\Citrixup.dll
Wow6432Node-HKCU-Run-DelTel Update - c:\users\Admin\AppData\Local\WinZip Courier\WinZipUpdate\WinZipup.dll
Wow6432Node-HKCU-Run-IntelUpdateProfile - c:\programdata\IntelUpdateProfile.dll
Wow6432Node-HKLM-Run-eRecoveryService - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)
WebBrowser-{DAB35D68-1CDC-4375-8333-D7BBCEE3C0A0} - (no file)
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\09\05\17\16#1?"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2011-11-01 22:01:19
ComboFix-quarantined-files.txt 2011-11-02 02:01
.
Pre-Run: 43,407,937,536 bytes free
Post-Run: 44,478,558,208 bytes free
.
- - End Of File - - BC5E93A7DE6992D7543346CEEB052674


I able to get on the internet, the overall speed has improved.

What next???

~James
Hi James,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    DDS::
    mStart Page = hxxp://www.startsearcher.com
    uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    BHO: {0e7af71c-0d74-441d-a6fd-e939b66d905d} - C:\Users\Admin\AppData\Local\SecurityWOW64.dll
    BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
    BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
    BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
    TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
    TB: {DAB35D68-1CDC-4375-8333-D7BBCEE3C0A0} - No File
    TB: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File
    TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    uRun: [IntegralPro Update] rundll32 "C:\Users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.dll",DllRegisterServer
    uRun: [DirectxOnlineTray] rundll32.exe "C:\ProgramData\DirectxOnlineTray.dll",DllRegisterServer
    uRun: [Monkey's Update] rundll32 "C:\Users\Admin\AppData\Local\{5199B627-11F3-4F3E-A210-262BD2DED8DB}\{5199B627-11F3-4F3E-A210-262BD2DED8DB}Update\{5199B627-11F3-4F3E-A210-262BD2DED8DB}up.dll",DllRegisterServer
    uRun: [ChiconyKye Update] rundll32 "C:\Users\Admin\AppData\Local\ATI\ATIUpdate\ATIup.dll",DllRegisterServer
    uRun: [Hpfwyvmytd Update] rundll32 "C:\Users\Admin\AppData\Local\ElevatedDiagnostics\ElevatedDiagnosticsUpdate\ElevatedDiagnosticsup.dll",DllRegisterServer
    uRun: [ORL Update] rundll32 "C:\Users\Admin\AppData\Local\FileServe Manager\FileServeUpdate\FileServeup.dll",DllRegisterServer
    uRun: [YahooPartnerToolbar Update] rundll32 "C:\Users\Admin\AppData\Local\OpenCandy\OpenCandyUpdate\OpenCandyup.dll",DllRegisterServer
    uRun: [Data Update] rundll32 "C:\Users\Admin\AppData\Local\Mozilla\MozillaUpdate\Mozillaup.dll",DllRegisterServer
    uRun: [CDDB Update] rundll32 "C:\Users\Admin\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftup.dll",DllRegisterServer
    uRun: [Mozilla Update] rundll32 "C:\Users\Admin\AppData\Local\Citrix\CitrixUpdate\Citrixup.dll",DllRegisterServer
    uRun: [DelTel Update] rundll32 "C:\Users\Admin\AppData\Local\WinZip Courier\WinZipUpdate\WinZipup.dll",DllRegisterServer
    C:\Users\Admin\AppData\Local\SecurityWOW64.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
    BHO-X64: Conduit Engine - No File
    BHO-X64: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
    BHO-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    BHO-X64: Vuze Remote - No File
    TB-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    TB-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
    TB-X64: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
    TB-X64: {DAB35D68-1CDC-4375-8333-D7BBCEE3C0A0} - No File
    TB-X64: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File
    TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    
    RegNull::
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\DbgagD\1*]
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{ba14329e-9550-4989-b3f2-9732e92d17cc}"=-
    "{30F9B915-B755-4826-820B-08FBA6BD249D}=-
    
    Driver::
    Auliaflisa
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-


Hi Jeff:

Attached is the output file by Combofix as per your request, COMBO-FIX.TXT

ComboFix 11-11-02.03 - Admin 11/02/2011 22:19:42.3.8 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6134.4142 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Admin\Desktop\CFScript.txt
AV: CA Anti-Virus Plus *Disabled/Updated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA}
FW: CA Personal Firewall *Enabled* {6F8E4568-E0DA-DA91-5F44-FD1E1B727591}
SP: CA Anti-Virus Plus *Disabled/Updated* {ECD425A9-8C8F-D447-4EAB-6F599E267857}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\program files (x86)\ConduitEngine\prxConduitEngine.dll
c:\program files (x86)\Vuze_Remote\prxtbVuze.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_Auliaflisa
.
.
((((((((((((((((((((((((( Files Created from 2011-10-03 to 2011-11-03 )))))))))))))))))))))))))))))))
.
.
2011-11-03 02:42 . 2011-11-03 02:42 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-11-03 02:42 . 2011-11-03 02:42 ——– d—–w- c:\users\Admin\AppData\Local\temp
2011-10-30 04:20 . 2011-10-30 04:20 ——– d—–w- c:\users\Admin\AppData\Roaming\Malwarebytes
2011-10-30 04:20 . 2011-10-30 04:20 ——– d—–w- c:\programdata\Malwarebytes
2011-10-30 04:20 . 2011-10-31 18:18 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-10-30 04:20 . 2011-08-31 21:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-29 18:34 . 2011-10-29 18:34 388096 —-a-r- c:\users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-29 18:34 . 2011-10-29 18:34 ——– d—–w- c:\program files (x86)\Trend Micro
2011-10-14 23:54 . 2011-09-13 00:26 9049936 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8D30E98-67CE-4263-A46B-1E88087603AA}\mpengine.dll
2011-10-13 00:10 . 2011-09-06 13:56 2764288 —-a-w- c:\windows\system32\win32k.sys
2011-10-13 00:09 . 2011-08-25 16:20 735744 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-13 00:09 . 2011-08-25 16:19 847360 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 00:09 . 2011-08-25 16:19 332288 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 00:09 . 2011-08-25 16:15 555520 —-a-w- c:\windows\SysWow64\UIAutomationCore.dll
2011-10-13 00:09 . 2011-08-25 16:14 563712 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-13 00:09 . 2011-08-25 16:14 238080 —-a-w- c:\windows\SysWow64\oleacc.dll
2011-10-13 00:09 . 2011-08-25 13:54 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-10-13 00:09 . 2011-08-25 13:31 4096 —-a-w- c:\windows\SysWow64\oleaccrc.dll
2011-10-13 00:08 . 2011-07-29 16:08 375808 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 00:08 . 2011-07-29 16:08 289792 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 00:08 . 2011-07-29 16:06 73216 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-10-13 00:08 . 2011-07-29 16:06 100352 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-13 00:08 . 2011-07-29 16:01 293376 —-a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-13 00:08 . 2011-07-29 16:01 217088 —-a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-13 00:08 . 2011-07-29 16:00 57856 —-a-w- c:\windows\SysWow64\MSDvbNP.ax
2011-10-13 00:08 . 2011-07-29 16:00 69632 —-a-w- c:\windows\SysWow64\Mpeg2Data.ax
2011-10-12 00:03 . 2011-10-12 00:03 ——– d—–w- c:\program files\iPod
2011-10-12 00:02 . 2011-10-12 00:03 ——– d—–w- c:\program files\iTunes
2011-10-12 00:02 . 2011-10-12 00:03 ——– d—–w- c:\program files (x86)\iTunes
2011-10-11 23:54 . 2011-10-11 23:54 ——– d—–w- c:\program files\Bonjour
2011-10-11 23:54 . 2011-10-11 23:54 ——– d—–w- c:\program files (x86)\Bonjour
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-16 09:41 . 2011-06-07 10:25 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-16 08:23 . 2010-12-26 00:43 2524176 —-a-w- c:\windows\system32\winsflt.dll
2011-09-16 08:23 . 2010-12-26 00:43 1744912 —-a-w- c:\windows\SysWow64\winsflt.dll
2011-09-16 08:19 . 2010-12-26 00:43 1422672 —-a-w- c:\windows\SysWow64\cfgmig32.dll
2011-09-16 08:19 . 2010-12-26 00:43 1422672 —-a-w- c:\windows\system32\cfgmig32.dll
2011-09-16 08:19 . 2010-12-26 00:43 263504 —-a-w- c:\windows\SysWow64\cfgmig32.exe
2011-09-16 08:19 . 2011-09-16 08:20 95568 —-a-w- c:\windows\system32\vetredir.dll
2011-09-16 08:19 . 2011-09-16 08:20 128336 —-a-w- c:\windows\system32\isafeif.dll
2011-09-16 08:19 . 2010-01-21 13:34 141136 —-a-w- c:\windows\system32\isafeif64.dll
2011-09-16 08:19 . 2010-01-21 13:34 103760 —-a-w- c:\windows\system32\vetredir64.dll
2011-09-14 15:47 . 2011-09-14 15:47 60416 —-a-w- c:\windows\system32\OVDecode64.dll
2011-09-14 15:47 . 2011-09-14 15:47 53760 —-a-w- c:\windows\SysWow64\OVDecode.dll
2011-09-14 15:47 . 2011-09-14 15:47 16652288 —-a-w- c:\windows\system32\amdocl64.dll
2011-09-14 15:38 . 2011-09-14 15:38 44032 —-a-w- c:\windows\system32\amdoclcl64.dll
2011-09-14 15:38 . 2011-09-14 15:38 37376 —-a-w- c:\windows\SysWow64\amdoclcl.dll
2011-09-08 18:27 . 2011-09-08 18:27 10203648 —-a-w- c:\windows\system32\drivers\atikmdag.sys
2011-09-08 17:59 . 2011-09-08 17:59 24229376 —-a-w- c:\windows\system32\atio6axx.dll
2011-09-08 17:39 . 2011-09-08 17:39 18534912 —-a-w- c:\windows\SysWow64\atioglxx.dll
2011-09-08 17:34 . 2011-09-08 17:34 151552 —-a-w- c:\windows\system32\atiapfxx.exe
2011-09-08 17:34 . 2011-09-08 17:34 732672 —-a-w- c:\windows\SysWow64\aticfx32.dll
2011-09-08 17:32 . 2011-07-28 21:39 862720 —-a-w- c:\windows\system32\aticfx64.dll
2011-09-08 17:30 . 2011-09-08 17:30 466944 —-a-w- c:\windows\system32\ATIDEMGX.dll
2011-09-08 17:30 . 2011-09-08 17:30 486912 —-a-w- c:\windows\system32\atieclxx.exe
2011-09-08 17:29 . 2011-09-08 17:29 204288 —-a-w- c:\windows\system32\atiesrxx.exe
2011-09-08 17:28 . 2011-09-08 17:28 120320 —-a-w- c:\windows\system32\atitmm64.dll
2011-09-08 17:28 . 2011-09-08 17:28 423424 —-a-w- c:\windows\system32\atipdl64.dll
2011-09-08 17:28 . 2011-09-08 17:28 356352 —-a-w- c:\windows\SysWow64\atipdlxx.dll
2011-09-08 17:28 . 2011-09-08 17:28 278528 —-a-w- c:\windows\SysWow64\Oemdspif.dll
2011-09-08 17:28 . 2011-09-08 17:28 21504 —-a-w- c:\windows\system32\atimuixx.dll
2011-09-08 17:28 . 2011-09-08 17:28 59392 —-a-w- c:\windows\system32\atiedu64.dll
2011-09-08 17:28 . 2011-09-08 17:28 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll
2011-09-08 17:24 . 2011-09-08 17:24 4204032 —-a-w- c:\windows\SysWow64\atidxx32.dll
2011-09-08 17:18 . 2011-09-08 17:18 1113088 —-a-w- c:\windows\system32\atiumd6v.dll
2011-09-08 17:18 . 2011-09-08 17:18 1828864 —-a-w- c:\windows\SysWow64\atiumdmv.dll
2011-09-08 17:18 . 2011-07-28 21:11 3888640 —-a-w- c:\windows\system32\atiumd6a.dll
2011-09-08 17:16 . 2011-09-08 17:16 4944896 —-a-w- c:\windows\system32\atidxx64.dll
2011-09-08 17:09 . 2011-09-08 17:09 51200 —-a-w- c:\windows\system32\aticalrt64.dll
2011-09-08 17:09 . 2011-09-08 17:09 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll
2011-09-08 17:09 . 2011-09-08 17:09 44544 —-a-w- c:\windows\system32\aticalcl64.dll
2011-09-08 17:09 . 2011-09-08 17:09 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll
2011-09-08 17:09 . 2011-09-08 17:09 8723456 —-a-w- c:\windows\system32\aticaldd64.dll
2011-09-08 17:08 . 2011-09-08 17:08 4064768 —-a-w- c:\windows\SysWow64\atiumdva.dll
2011-09-08 17:05 . 2011-09-08 17:05 7331840 —-a-w- c:\windows\SysWow64\aticaldd.dll
2011-09-08 17:05 . 2011-09-08 17:05 4289024 —-a-w- c:\windows\SysWow64\atiumdag.dll
2011-09-08 17:00 . 2011-07-28 21:02 5428736 —-a-w- c:\windows\system32\atiumd64.dll
2011-09-08 16:59 . 2011-07-28 21:01 58880 —-a-w- c:\windows\system32\coinst.dll
2011-09-08 16:53 . 2011-09-08 16:53 381952 —-a-w- c:\windows\system32\atiadlxx.dll
2011-09-08 16:53 . 2011-09-08 16:53 270336 —-a-w- c:\windows\SysWow64\atiadlxy.dll
2011-09-08 16:52 . 2011-09-08 16:52 15360 —-a-w- c:\windows\system32\atig6pxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 13312 —-a-w- c:\windows\SysWow64\atiglpxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 13312 —-a-w- c:\windows\system32\atiglpxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 39936 —-a-w- c:\windows\system32\atig6txx.dll
2011-09-08 16:52 . 2011-09-08 16:52 32768 —-a-w- c:\windows\SysWow64\atigktxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 310784 —-a-w- c:\windows\system32\drivers\atikmpag.sys
2011-09-08 16:52 . 2011-09-08 16:52 40960 —-a-w- c:\windows\system32\atiuxp64.dll
2011-09-08 16:51 . 2011-09-08 16:51 31744 —-a-w- c:\windows\SysWow64\atiuxpag.dll
2011-09-08 16:51 . 2011-07-28 20:53 38912 —-a-w- c:\windows\system32\atiu9p64.dll
2011-09-08 16:51 . 2011-09-08 16:51 29184 —-a-w- c:\windows\SysWow64\atiu9pag.dll
2011-09-08 16:51 . 2011-07-28 20:52 45056 —-a-w- c:\windows\system32\atitmp64.dll
2011-09-08 16:51 . 2011-09-08 16:51 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll
2011-09-08 16:51 . 2011-09-08 16:51 54784 —-a-w- c:\windows\system32\atimpc64.dll
2011-09-08 16:51 . 2011-09-08 16:51 54784 —-a-w- c:\windows\system32\amdpcom64.dll
2011-09-08 16:50 . 2011-09-08 16:50 53760 —-a-w- c:\windows\SysWow64\atimpc32.dll
2011-09-08 16:50 . 2011-09-08 16:50 53760 —-a-w- c:\windows\SysWow64\amdpcom32.dll
2011-08-31 03:05 . 2011-08-31 03:05 96104 —-a-w- c:\windows\system32\dns-sd.exe
2011-08-31 03:05 . 2011-08-31 03:05 85864 —-a-w- c:\windows\system32\dnssd.dll
2011-08-31 03:05 . 2011-08-31 03:05 83816 —-a-w- c:\windows\SysWow64\dns-sd.exe
2011-08-31 03:05 . 2011-08-31 03:05 73064 —-a-w- c:\windows\SysWow64\dnssd.dll
2011-08-25 00:19 . 2011-08-25 00:19 56320 —-a-w- c:\windows\SysWow64\OpenVideo.dll
2011-08-25 00:18 . 2011-08-25 00:18 13601280 —-a-w- c:\windows\SysWow64\amdocl.dll
2011-08-25 00:17 . 2011-08-25 00:17 43520 —-a-w- c:\windows\SysWow64\OpenCL.dll
2011-08-06 14:54 . 2011-08-06 14:54 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll
2011-08-06 14:54 . 2011-08-06 14:54 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-08-06 14:54 . 2011-08-06 14:54 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-08-06 14:54 . 2011-08-06 14:54 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll
2011-08-06 14:54 . 2011-08-06 14:54 161792 —-a-w- c:\windows\SysWow64\msls31.dll
2011-08-06 14:54 . 2011-08-06 14:54 63488 —-a-w- c:\windows\SysWow64\tdc.ocx
2011-08-06 14:54 . 2011-08-06 14:54 367104 —-a-w- c:\windows\SysWow64\html.iec
2011-08-06 14:54 . 2011-08-06 14:54 74752 —-a-w- c:\windows\SysWow64\iesetup.dll
2011-08-06 14:54 . 2011-08-06 14:54 420864 —-a-w- c:\windows\SysWow64\vbscript.dll
2011-08-06 14:54 . 2011-08-06 14:54 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll
2011-08-06 14:54 . 2011-08-06 14:54 152064 —-a-w- c:\windows\SysWow64\wextract.exe
2011-08-06 14:54 . 2011-08-06 14:54 150528 —-a-w- c:\windows\SysWow64\iexpress.exe
2011-08-06 14:54 . 2011-08-06 14:54 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2011-08-06 14:54 . 2011-08-06 14:54 35840 —-a-w- c:\windows\SysWow64\imgutil.dll
2011-08-06 14:54 . 2011-08-06 14:54 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2011-08-06 14:54 . 2011-08-06 14:54 11776 —-a-w- c:\windows\SysWow64\mshta.exe
2011-08-06 14:54 . 2011-08-06 14:54 101888 —-a-w- c:\windows\SysWow64\admparse.dll
2011-08-06 14:54 . 2011-08-06 14:54 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-08-06 14:54 . 2011-08-06 14:54 222208 —-a-w- c:\windows\system32\msls31.dll
2011-08-06 14:54 . 2011-08-06 14:54 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-08-06 14:54 . 2011-08-06 14:54 49664 —-a-w- c:\windows\system32\imgutil.dll
2011-08-06 14:54 . 2011-08-06 14:54 12288 —-a-w- c:\windows\system32\mshta.exe
2011-08-06 14:54 . 2011-08-06 14:54 114176 —-a-w- c:\windows\system32\admparse.dll
2011-08-06 14:54 . 2011-08-06 14:54 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-08-06 14:54 . 2011-08-06 14:54 76800 —-a-w- c:\windows\system32\tdc.ocx
2011-08-06 14:54 . 2011-08-06 14:54 48640 —-a-w- c:\windows\system32\mshtmler.dll
2011-08-06 14:54 . 2011-08-06 14:54 448512 —-a-w- c:\windows\system32\html.iec
2011-08-06 14:54 . 2011-08-06 14:54 135168 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-08-06 14:54 . 2011-08-06 14:54 111616 —-a-w- c:\windows\system32\iesysprep.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-02_01.45.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-11-02 15:45 . 2011-11-03 02:03 88146 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-11-17 18:07 . 2011-11-03 02:03 28426 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4027082081-1360438707-2940866900-1000_UserData.bin
- 2009-11-17 17:36 . 2011-11-01 15:58 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-11-17 17:36 . 2011-11-02 22:30 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-01 03:12 . 2011-11-01 03:12 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-11-01 03:12 . 2011-11-02 06:36 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-17 17:36 . 2011-11-02 06:36 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-11-17 17:36 . 2011-11-01 03:12 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-10-31 19:16 . 2011-11-01 15:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-02 23:52 . 2011-11-03 02:01 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-02 23:52 . 2011-11-03 02:01 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-10-31 19:16 . 2011-11-01 15:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-01-21 02:23 . 2011-11-02 22:46 104010 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2011-03-11 06:51 . 2011-10-31 19:05 377624 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-03-11 06:51 . 2011-11-02 23:49 377624 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-12-26 06:40 . 2011-10-31 19:05 1749352 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-12-26 06:40 . 2011-11-02 23:49 1749352 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-09-16 16:13 . 2011-11-02 07:04 1048576 c:\windows\rnapxs\CSDK\urlcache\domainNames.dat
+ 2011-05-29 05:41 . 2011-11-02 23:49 24198588 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4027082081-1360438707-2940866900-1000-8192.dat
+ 2011-08-07 00:14 . 2011-11-02 15:58 18680112 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4027082081-1360438707-2940866900-1000-4096.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LchDrvKey"="LchDrvKey.exe" [2007-03-28 36864]
"LedKey"="CNYHKey.exe" [2008-04-23 339968]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-08 343168]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"StartMSu"="c:\program files (x86)\Creative\MediaSource5\Startmsu.exe" [2006-10-02 81920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2011-02-24 18:33 79368 —-a-w- c:\windows\System32\UmxWNP.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 136176]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-01-10 79360]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 136176]
R3 HPEWSFXBULK;HPEWSFXBULK;c:\windows\system32\drivers\hpfx64bulk.sys [x]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTS5121.sys [x]
R3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 SymDSMon;SymDSMon;c:\windows\system32\drivers\SymDSMon.sys [x]
R3 SYMSpeedDisk;SYMSpeedDisk;c:\windows\system32\drivers\SymSpeedDisk.sys [2010-11-30 163384]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 KmxAMRT;KmxAMRT;c:\windows\system32\DRIVERS\KmxAMRT.sys [x]
S0 KmxFw;KmxFw;c:\windows\System32\DRIVERS\kmxfw.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 KmxAgent;KmxAgent;c:\windows\system32\DRIVERS\kmxagent.sys [x]
S1 KmxCfg;KmxCfg;c:\windows\system32\DRIVERS\kmxcfg.sys [x]
S1 KmxFile;KmxFile;c:\windows\system32\DRIVERS\KmxFile.sys [x]
S1 KmxFilter;HIPS Core Filter Driver;c:\windows\system32\DRIVERS\KmxFilter.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 CAAMSvc;CAAMSvc;c:\program files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe [2011-10-17 291656]
S2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [2011-09-16 286032]
S2 DiskDoctorService;Norton Disk Doctor Service;c:\program files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [2010-11-30 1029480]
S2 ETService;Empowering Technology Service;c:\program files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [2008-06-11 24576]
S2 KmxCF;KmxCF;c:\windows\system32\DRIVERS\KmxCF.sys [x]
S2 KmxSbx;KmxSbx;c:\windows\system32\DRIVERS\KmxSbx.sys [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]
S2 SpeedDiskService;Norton SpeedDisk Service;c:\program files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [2010-11-30 1037672]
S2 UmxEngine;TM Engine;c:\program files\CA\SharedComponents\TMEngine\UmxEngine.exe [2011-04-04 920656]
S2 WinExtManager;WinSock Extention Manager;c:\windows\SysWOW64\mdmcls32.exe [2011-06-29 3207184]
S2 WinSvchostManager;WinSock Svchost Manager;c:\windows\SysWOW64\svcprs32.exe [2011-06-29 2760720]
S2 WinSvchostManagerSrv;WinSvchostManagerSrv;c:\windows\SysWOW64\cfgmig32.exe [2011-09-16 263504]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [x]
S3 gwfilt64;gwfilt64;c:\windows\system32\drivers\gwfilt64.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 19:57]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 19:57]
.
2011-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000Core.job
- c:\users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 18:14]
.
2011-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000UA.job
- c:\users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 18:14]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2006-11-02 46592]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"RtHDVCpl"="RAVCpl64.exe" [2008-09-19 6495264]
"cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" [2011-09-16 2658128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\UmxSbxExA64.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
LSP: winsflt.dll
TCP: Interfaces\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: NameServer = 192.168.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-combofix - c:\combofix\CF10572.3XE
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2011-11-02 22:48:22
ComboFix-quarantined-files.txt 2011-11-03 02:48
ComboFix2.txt 2011-11-02 02:01
.
Pre-Run: 42,609,631,232 bytes free
Post-Run: 42,572,288,000 bytes free
.
- - End Of File - - DCA6DDBCB5E6F4F6AC5147BBB85B2E9B


Thanks for your help in advance

~James




Hi,

I see that you have Malwarebytes on your computer. Please start Malwarebytes, update it and then run a Quick Scan. There will be a log produced when it finishes that I will need in your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


  • Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs made by Malwarebytes and ESET online scanner.
Hi Jeff:

My Internet access is not working on the affected computer (I'm using laptop now to get files on a flash drive to scan the Gateway desktop)

Is there a standalone version of EST Online Scanner or a comparable scanner?

Is there any way to get a copy of malwarebytes software that is already updated. I get this message when I try to update Mawlwarebytes scan software:

"Error reported trying to update Malwarebytes Anti-Malware. Please report to the support team the following message:

PROGRAM_ERROR_UPDATING (2, 0, Net Exception)"

. . . because I haven't got a connection on the Gateway

~James
Hi Jeff:

Here is the output file of Malwarebytes antimalware scan:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7622

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

11/3/2011 1:01:00 PM
mbam-log-2011-11-03 (13-01-00).txt

Scan type: Quick scan
Objects scanned: 185760
Time elapsed: 3 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

I believe this software is current.


~James

Hi,

Lets see if we can get that internet repaired.

Open Network Diagnostics by right-clicking the network icon (it looks like this [external image: Posted Image]) in the notification area, and then clicking Diagnose and repair.

If that does not work completely unplug your router for 30 seconds, plug the power back in and then attempt to reconnect with the internet.

After you try those let me know if you get the internet back. If you do get your internet back go ahead and run ESET online scan. :)
I followed your instructions and it will go to the page but will not do anything when I click on the button (or any link on that page for that matter). I also tried to link up to the site through google and it will not go to the next screen on ESET Online Scanner (???!!!) I hope this message gets through to the webpage to post. ~James
Hi James, Is this happening across all browsers? What I mean is are you unable to connect to the internet in Internet Explorer as well as FireFox or other browsers or are you unable to connect at all?
Hi Jeff I removed Firefox and am only using IE 9. I am able to connect to the initial page (link) but nothing happens when I click on any link in the webpage. This was happening before I used one of the tools you recommended I think it was COMBOFIX. I think there may be, IMHO, a reinfection. I don't really know what is happening. ~James

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI