This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe Google redirect [Solved]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All,
I've been hit by the same ping.exe & google redirect virus that has been flooding the forums here. Ran all types of scans to no avail, but I see that you guys seem to have this nut cracked. Thanks for any assistance provided. Here are the logs:


OTL logfile created on: 12/20/2011 10:07:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Patricia\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.54 Gb Available Physical Memory | 78.27% Memory free
5.09 Gb Paging File | 4.50 Gb Available in Paging File | 88.35% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 11.72 Gb Total Space | 0.89 Gb Free Space | 7.62% Space Free | Partition Type: NTFS
Drive E: | 74.55 Gb Total Space | 9.44 Gb Free Space | 12.66% Space Free | Partition Type: NTFS
Drive F: | 116.27 Gb Total Space | 7.38 Gb Free Space | 6.35% Space Free | Partition Type: NTFS
Drive I: | 170.10 Gb Total Space | 128.45 Gb Free Space | 75.51% Space Free | Partition Type: NTFS

Computer Name: THE-BEAST | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Patricia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Webroot\WRSA.exe (Webroot)
PRC - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - E:\Programs\Sage\Peachtree\SmartPostingService2011.exe (Sage Software, Inc.)
PRC - C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Pervasive Software Inc.)
PRC - C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
PRC - E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - E:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\Program Files\GIGABYTE\GEST\gest.exe ()
PRC - C:\Program Files\GIGABYTE\GEST\GSvr.exe ()


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - E:\Programs\Sage\Peachtree\pchqb32.dll ()
MOD - F:\Programs\Office\Office14\1033\GrooveIntlResource.dll ()
MOD - F:\Programs\WINRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\GIGABYTE\GEST\gest.exe ()
MOD - C:\Program Files\GIGABYTE\GEST\GSvr.exe ()
MOD - C:\Program Files\GIGABYTE\GEST\ycc.dll ()
MOD - C:\Program Files\GIGABYTE\GEST\etiv.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()


========== Win32 Services (SafeList) ==========

SRV - (NeroRegInCDSrv) – File not found
SRV - (WRSVC) – C:\Program Files\Webroot\WRSA.exe (Webroot)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (MBAMService) – F:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – F:\Programs\Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (Peachtree SmartPosting 2011) – E:\Programs\Sage\Peachtree\SmartPostingService2011.exe (Sage Software, Inc.)
SRV - (psqlWGE) – C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Pervasive Software Inc.)
SRV - (InCDsrv) – E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (GEST Service) – C:\Program Files\GIGABYTE\GEST\GSvr.exe ()


========== Driver Services (SafeList) ==========

DRV - (pIclxoGw) – C:\WINDOWS\System32\drivers\pIclxoGw.sys (Webroot)
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (MpKsl4eb7697b) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7EBDA840-A36E-474A-A355-8831D9343538}\MpKsl4eb7697b.sys (Microsoft Corporation)
DRV - (WRkrn) – C:\WINDOWS\System32\drivers\WRkrn.sys (Webroot)
DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (urvpndrv) – C:\WINDOWS\system32\drivers\covpndrv.sys (F5 Networks, Inc.)
DRV - (f5ipfw) – C:\WINDOWS\system32\drivers\urfltw2k.sys (F5 Networks, Inc.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (incdrm) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (ET5Drv) – C:\WINDOWS\system32\drivers\ET5Drv.sys (Windows ® 2000 DDK provider)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: I:\programs\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: F:\Programs\Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: F:\Programs\Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: F:\Programs\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: F:\Programs\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\MyWebSearch\bar\2.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2011/11/27 17:40:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2011/12/10 10:09:20 | 000,000,000 | —D | M]

[2011/05/01 08:06:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Patricia\Application Data\Mozilla\Extensions
[2010/04/28 20:50:00 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/06 03:08:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION

O1 HOSTS File: ([2011/12/04 09:11:17 | 000,001,401 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 216.240.133.193 www.google-analytics.com.
O1 - Hosts: 216.240.133.193 ad-emea.doubleclick.net.
O1 - Hosts: 216.240.133.193 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Programs\Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - F:\Programs\Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [GEST] C:\Program Files\GIGABYTE\GEST\run.exe ()
O4 - HKLM..\Run: [InCD] E:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PeachtreePrefetcher.exe] E:\Programs\Sage\Peachtree\PeachtreePrefetcher.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [SecurDisc] E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WRSVC] C:\Program Files\Webroot\WRSA.exe (Webroot)
O4 - HKCU..\Run: [Core Temp] C:\Program Files\Core Temp\Core Temp.exe ()
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil11c_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT AntiViruses Class)
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} https://vpn.na.sage.com/vdesk/terminal/urxv…0,2011,104,2321 (F5 Networks VPN Manager)
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT FireWalls Class)
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} https://vpn.na.sage.com/vdesk/terminal/f5tu…0,2011,104,2309 (F5 Networks Dynamic Application Tunnel Control)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://vpn.na.sage.com/vdesk/terminal/Inst…,2010,1020,1507 (F5 Networks Auto Update)
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT ProcessesScanner Class)
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} https://vpn.na.sage.com/vdesk/terminal/f5In…,2010,1020,1407 (F5 Networks Policy Agent Host Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} https://vpn.na.sage.com/vdesk/terminal/urxs…,2010,1020,1428 (F5 Networks SuperHost Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} https://vpn.na.sage.com/vdesk/terminal/urxh…00,2011,124,911 (F5 Networks Host Control)
O16 - DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} https://vpn.na.sage.com/policy/download_bin…,2010,1020,1432 (F5 Networks OS Policy Agent)
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (F5 Networks OPSWAT Helper Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0A4CBC1-2119-4C19-8FD1-BF4952EFE657}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\Programs\Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/26 01:55:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/10/12 10:59:30 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1999/08/11 12:09:06 | 000,000,233 | —- | M] () - I:\AUTOEXEC – [ NTFS ]
O32 - AutoRun File - [2000/08/28 13:56:10 | 000,000,023 | —- | M] () - I:\AUTOEXEC.112 – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/20 09:40:43 | 000,107,336 | —- | C] (Webroot) – C:\WINDOWS\System32\drivers\pIclxoGw.sys
[2011/12/20 09:40:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:23 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe
[2011/12/20 08:58:44 | 000,028,992 | —- | C] (TuneUp Software) – C:\WINDOWS\System32\uxtuneup.dll
[2011/12/20 08:37:56 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/12/20 08:34:51 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\BineenXt.sys
[2011/12/19 20:31:05 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\srvlnASy.sys
[2011/12/18 23:27:36 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\xocVqFMR.sys
[2011/12/18 23:27:22 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\odcgeLCR.sys
[2011/12/18 19:33:24 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\VGlxxmhq.sys
[2011/12/18 16:17:39 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\tftUsCuh.sys
[2011/12/18 16:12:40 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\UtNACVPB.sys
[2011/12/18 15:56:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Webroot SecureAnywhere
[2011/12/18 15:56:34 | 000,141,272 | —- | C] (Webroot) – C:\WINDOWS\System32\WRusr.dll
[2011/12/18 15:56:34 | 000,107,336 | —- | C] (Webroot) – C:\WINDOWS\System32\drivers\WRkrn.sys
[2011/12/18 15:56:32 | 000,000,000 | —D | C] – C:\Program Files\Webroot
[2011/12/18 15:56:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WRData
[2011/12/15 19:23:27 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2011/12/11 10:35:25 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2011/12/10 10:09:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\DivX
[2011/12/10 10:09:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2011/12/05 05:18:18 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/12/04 10:31:30 | 000,031,552 | —- | C] (TuneUp Software) – C:\WINDOWS\System32\TURegOpt.exe
[2011/12/04 10:31:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TuneUp Utilities 2012
[2011/12/04 10:30:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\Application Data\TuneUp Software
[2011/12/04 10:30:34 | 000,000,000 | —D | C] – C:\Program Files\TuneUp Utilities 2012
[2011/12/04 10:29:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/12/04 10:28:39 | 000,000,000 | -HSD | C] – C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2011/12/04 09:50:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\My Documents\Downloads
[2011/12/04 09:11:18 | 000,041,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\ubxxitam.sys
[2011/12/04 09:09:55 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/04 09:09:55 | 000,100,880 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/04 09:09:55 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/03 15:30:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/03 14:49:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\Application Data\Malwarebytes
[2011/12/03 12:48:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/03 12:48:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/23 08:10:19 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/20 10:12:20 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/20 09:41:39 | 000,625,664 | —- | M] () – C:\Documents and Settings\Patricia\Desktop\dds.scr
[2011/12/20 09:40:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:43 | 000,107,336 | —- | M] (Webroot) – C:\WINDOWS\System32\drivers\pIclxoGw.sys
[2011/12/20 09:40:30 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe
[2011/12/20 08:41:01 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/20 08:36:10 | 000,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2011/12/20 08:36:09 | 000,272,484 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2011/12/20 08:35:58 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/20 08:35:53 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/18 15:56:34 | 000,141,272 | —- | M] (Webroot) – C:\WINDOWS\System32\WRusr.dll
[2011/12/18 15:56:34 | 000,107,336 | —- | M] (Webroot) – C:\WINDOWS\System32\drivers\WRkrn.sys
[2011/12/16 03:20:50 | 000,282,928 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/15 20:27:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/12/14 06:47:06 | 000,031,552 | —- | M] (TuneUp Software) – C:\WINDOWS\System32\TURegOpt.exe
[2011/12/14 06:46:50 | 000,028,992 | —- | M] (TuneUp Software) – C:\WINDOWS\System32\uxtuneup.dll
[2011/12/09 09:28:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/08 08:49:11 | 000,118,582 | —- | M] () – C:\logfile
[2011/12/04 10:31:27 | 000,001,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp 1-Click Maintenance.lnk
[2011/12/04 10:31:27 | 000,001,741 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp Utilities 2012.lnk
[2011/12/04 09:33:10 | 000,437,014 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/04 09:33:10 | 000,069,358 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/04 09:11:19 | 000,041,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\ubxxitam.sys
[2011/12/04 09:11:17 | 000,001,401 | RHS- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/04 09:09:55 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/04 09:09:55 | 000,100,880 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/04 09:09:55 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/03 14:29:04 | 000,015,476 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\627013l4q800u827c180j1gsa0e0
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/20 09:41:16 | 000,625,664 | —- | C] () – C:\Documents and Settings\Patricia\Desktop\dds.scr
[2011/12/18 15:58:51 | 000,162,816 | —- | C] () – C:\WINDOWS\System32\drivers\tkGBMHJb.sys
[2011/12/06 15:25:36 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/04 10:31:27 | 000,001,747 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\TuneUp Utilities 2012.lnk
[2011/12/04 10:31:27 | 000,001,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp 1-Click Maintenance.lnk
[2011/12/04 10:31:27 | 000,001,741 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp Utilities 2012.lnk
[2011/12/03 12:35:57 | 000,015,476 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\627013l4q800u827c180j1gsa0e0
[2011/09/21 21:09:59 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2011/09/19 21:59:17 | 000,017,905 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2011/09/19 19:52:15 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/02/20 10:32:50 | 000,103,535 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/02/20 10:32:50 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2010/12/12 09:28:54 | 000,000,000 | —- | C] () – C:\WINDOWS\f5unistall.INI
[2010/10/19 07:42:47 | 000,013,132 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/09/12 11:28:05 | 000,103,535 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2010/09/12 11:28:05 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2010/06/20 21:45:29 | 000,003,402 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate
[2010/05/14 20:25:38 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/04/26 23:48:17 | 002,183,470 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/04/26 23:14:28 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/26 22:57:01 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/04/26 01:56:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/04/26 01:52:52 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/04/25 18:44:47 | 000,004,633 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/04/25 18:43:55 | 000,282,928 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/06/25 02:57:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/03/21 07:28:50 | 000,000,106 | —- | C] () – C:\WINDOWS\System32\mmc.exe.config
[2004/08/04 01:07:22 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 00:56:44 | 000,193,024 | —- | C] () – C:\WINDOWS\System32\msrating.dll
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,437,014 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,069,358 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011/03/05 10:40:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aatrix Software
[2010/12/19 10:54:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/12/12 09:28:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F5 Networks
[2010/05/14 20:23:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/03/05 10:35:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pervasive Software
[2011/12/04 10:31:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/07/31 10:35:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/12/20 09:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WRData
[2011/12/04 10:28:39 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2010/05/01 16:11:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/04 10:30:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Patricia\Application Data\TuneUp Software
[2011/12/20 08:41:01 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/04/26 01:55:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/09/19 22:09:45 | 000,000,000 | —- | M] () – C:\BnetLog.txt
[2011/12/15 20:27:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2006/11/02 04:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2010/04/26 01:55:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/26 23:29:09 | 000,000,206 | —- | M] () – C:\csb.log
[2010/03/10 20:20:52 | 000,799,352 | —- | M] () – C:\D2XP_IX86_112a_113c.mpq
[2010/04/26 01:55:00 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/12/08 08:49:11 | 000,118,582 | —- | M] () – C:\logfile
[2010/04/26 01:55:00 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 22:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/07 19:59:38 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/04/26 23:29:09 | 000,000,480 | —- | M] () – C:\RHDSetup.log
[2011/03/05 10:41:25 | 000,899,274 | —- | M] () – C:\SageMessageCenter_Install.log
[2011/12/20 08:36:39 | 000,000,122 | —- | M] () – C:\service.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/04/26 01:54:43 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/04/25 18:42:52 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/04/25 18:42:52 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/04/25 18:42:52 | 000,925,696 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/07 20:03:06 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/05/02 14:55:11 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Patricia\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/05/02 14:55:11 | 000,000,079 | —- | M] () – C:\Documents and Settings\Patricia\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/12/20 09:40:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:30 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdate]

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-16 08:04:55

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB10581$] -> -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 514 bytes -> C:\WINDOWS\System32\drivers\ubxxitam.sys:changelist

< End of report >

OTL Extras logfile created on: 12/20/2011 10:07:18 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Patricia\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.54 Gb Available Physical Memory | 78.27% Memory free
5.09 Gb Paging File | 4.50 Gb Available in Paging File | 88.35% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 11.72 Gb Total Space | 0.89 Gb Free Space | 7.62% Space Free | Partition Type: NTFS
Drive E: | 74.55 Gb Total Space | 9.44 Gb Free Space | 12.66% Space Free | Partition Type: NTFS
Drive F: | 116.27 Gb Total Space | 7.38 Gb Free Space | 6.35% Space Free | Partition Type: NTFS
Drive I: | 170.10 Gb Total Space | 128.45 Gb Free Space | 75.51% Space Free | Partition Type: NTFS

Computer Name: THE-BEAST | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = internetshortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – E:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "F:\Programs\Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "F:\Programs\Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"1583:TCP" = 1583:TCP:*:Enabled:Pervasive DBEngine
"3351:TCP" = 3351:TCP:*:Enabled:Pervasive DBEngine

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\Programs\BitTorrent\bittorrent.exe" = F:\Programs\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"H:\CDS\Nero\Installation\SetupX.exe" = H:\CDS\Nero\Installation\SetupX.exe:*:Enabled:Nero ProductSetup
"E:\Program Files\StarCraft II Beta\StarCraft II.exe" = E:\Program Files\StarCraft II Beta\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\Adobe\Acrobat_com\Acrobat_com.exe" = C:\Program Files\Adobe\Acrobat_com\Acrobat_com.exe:*:Enabled:Acrobat_com – ()
"E:\Program Files\StarCraft II\StarCraft II.exe" = E:\Program Files\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"E:\Program Files\StarCraft II\Versions\Base15405\SC2.exe" = E:\Program Files\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II – (Blizzard Entertainment, Inc.)
"C:\Documents and Settings\DeViouS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\DeViouS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"E:\Program Files\PFPortChecker\PFPortChecker.exe" = E:\Program Files\PFPortChecker\PFPortChecker.exe:*:Enabled:PFPortchecker by portforward.com helps check if your ports are properly forwarded. – (portforward.com)
"F:\Programs\Office\Office14\GROOVE.EXE" = F:\Programs\Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"F:\Programs\Office\Office14\ONENOTE.EXE" = F:\Programs\Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"F:\Programs\Office\Office14\OUTLOOK.EXE" = F:\Programs\Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe" = C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe:*:Enabled:Database Service Manager – (Pervasive Software Inc.)
"C:\Program Files\GIGABYTE\GEST\run.exe" = C:\Program Files\GIGABYTE\GEST\run.exe:*:Disabled:update – ()
"E:\Program Files\StarCraft II\Versions\Base18092\SC2.exe" = E:\Program Files\StarCraft II\Versions\Base18092\SC2.exe:*:Enabled:StarCraft II – (Blizzard Entertainment, Inc.)
"F:\Programs\XBMC\XBMC.exe" = F:\Programs\XBMC\XBMC.exe:*:Enabled:XBMC – (Team XBMC)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC2
"{0A3238D7-AB32-1010-B717-F3E3F18B4A8C}" = Pervasive PSQL v10 SP2 Workgroup (32-bit)
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE1008C-11A1-4F4F-8DB7-27573924DE78}" = DMIView B06.1227.01
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5869CE1E-BC0B-4648-B1AE-6EF4A985590C}" = Dynamic Energy Saver 1.0 B8.0128.1
"{6798DD4E-BD16-4735-87EB-D712637CCB8C}" = Sage Message Center
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{714ACFF3-B8A3-4AD6-937B-13C833D71033}" = Nero 7 Essentials
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7ED169D4-5053-4166-93DF-53B12AE6C539}" = Energy Saver Advance B8.0711.1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BCB844B-0814-4354-A413-1063DB4618E9}" = PeachTree Signature Ready Forms
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E67BFA7-2A1C-4439-95CE-D6ACD3E85073}" = Peachtree Accounting 2011
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A95A76C9-6F65-477E-83A0-9F884B6DC21B}" = TuneUp Utilities Language Pack (en-US)
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C484CC8D-03CF-4022-89C4-DB4F02E8A15B}" = Crystal Reports 2008 Runtime SP1
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF8C077A-B467-4C43-8DB5-3A9B94FF9681}" = LightScribe System Software [removed]
"{D237A127-1229-41EF-8F89-F5B2363868E7}" = Diablo II Character Manager
"{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
"{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATT-PRT22" = ATT-PRT22
"BitTorrent" = BitTorrent
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Diablo II" = Diablo II
"DriverCD" = DriverCD
"DVDFab 8 Qt_is1" = DVDFab 8.1.0.5 (04/07/2011) Qt
"F5 Networks Client Components" = BIG-IP Edge Client Components (All Users)
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{9E67BFA7-2A1C-4439-95CE-D6ACD3E85073}" = Peachtree Accounting 2011
"Integration Services" = Sage Integration Services
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 8.0.1 (x86 en-US)" = Mozilla Firefox 8.0.1 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"PFPortChecker" = PFPortChecker 1.0.36
"Portforward Static IP Address" = Portforward Static IP Address 1.0.44
"RealAlt_is1" = Real Alternative 2.0.2
"TuneUp Utilities 2012" = TuneUp Utilities 2012
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WRUNINST" = Webroot SecureAnywhere

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:18:38 AM, on 12/20/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17095)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
E:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\GIGABYTE\GEST\gest.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
C:\WINDOWS\system32\svchost.exe
E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
C:\Program Files\GIGABYTE\GEST\GSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\Documents and Settings\Patricia\Desktop\OTL.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Core Temp\Core Temp.exe
E:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O1 - Hosts: ::1 localhost
O1 - Hosts: 216.240.133.193 www.google-analytics.com.
O1 - Hosts: 216.240.133.193 ad-emea.doubleclick.net.
O1 - Hosts: 216.240.133.193 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Programs\Office\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - F:\Programs\Office\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SecurDisc] E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PeachtreePrefetcher.exe] E:\Programs\Sage\Peachtree\PeachtreePrefetcher.exe /configfile:peachtreeprefetcher.winstart.config
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [InCD] E:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [GEST] C:\Program Files\GIGABYTE\GEST\RUN.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WRSVC] "C:\Program Files\Webroot\WRSA.exe" -ul
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.872
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Core Temp] "C:\Program Files\Core Temp\Core Temp.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil11c_Plugin.exe -update plugin
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} (OPSWAT AntiViruses Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} (F5 Networks VPN Manager) - https://vpn.na.sage.com/vdesk/terminal/urxv…0,2011,104,2321
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} (OPSWAT FireWalls Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} (F5 Networks Dynamic Application Tunnel Control) - https://vpn.na.sage.com/vdesk/terminal/f5tu…0,2011,104,2309
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://vpn.na.sage.com/vdesk/terminal/Inst…,2010,1020,1507
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} (OPSWAT ProcessesScanner Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} (F5 Networks Policy Agent Host Class) - https://vpn.na.sage.com/vdesk/terminal/f5In…,2010,1020,1407
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://vpn.na.sage.com/vdesk/terminal/urxs…,2010,1020,1428
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://vpn.na.sage.com/vdesk/terminal/urxh…00,2011,124,911
O16 - DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} (F5 Networks OS Policy Agent) - https://vpn.na.sage.com/policy/download_bin…,2010,1020,1432
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} (F5 Networks OPSWAT Helper Control) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - E:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Peachtree SmartPosting 2011 - Sage Software, Inc. - E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
O23 - Service: Pervasive PSQL Workgroup Engine (psqlWGE) - Pervasive Software Inc. - C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
O23 - Service: WRSVC - Webroot - C:\Program Files\Webroot\WRSA.exe

–
End of file - 11703 bytes

DDS
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:21:52.10 on Tue 12/20/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2476 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
.
============== Running Processes ===============
.
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
E:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\GIGABYTE\GEST\gest.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
C:\Program Files\GIGABYTE\GEST\GSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Core Temp\Core Temp.exe
E:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\ping.exe
C:\Documents and Settings\Patricia\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - f:\programs\office\office14\GROOVEEX.DLL
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - f:\programs\office\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Core Temp] "c:\program files\core temp\Core Temp.exe"
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil11c_Plugin.exe -update plugin
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [SecurDisc] e:\program files\nero\nero 7\incd\NBHGui.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [PeachtreePrefetcher.exe] e:\programs\sage\peachtree\PeachtreePrefetcher.exe /configfile:peachtreeprefetcher.winstart.config
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [InCD] e:\program files\nero\nero 7\incd\InCD.exe
mRun: [GEST] c:\program files\gigabyte\gest\RUN.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WRSVC] "c:\program files\webroot\WRSA.exe" -ul
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.872
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
uPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
uPolicies-explorer: NoWindowsUpdate = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
mPolicies-explorer: NoViewOnDrive = 0 (0x0)
mPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
mPolicies-explorer: NoWindowsUpdate = 0 (0x0)
mPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
dPolicies-explorer: NoViewOnDrive = 0 (0x0)
dPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
dPolicies-explorer: NoWindowsUpdate = 0 (0x0)
dPolicies-system: NoDispAppearancePage = 0 (0x0)
dPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\programs\office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - f:\programs\office\office14\ONBttnIELinkedNotes.dll
LSP: mswsock.dll
DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} - hxxps://vpn.na.sage.com/vdesk/terminal/urxvpn.cab#version=7000,2011,104,2321
DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://vpn.na.sage.com/vdesk/terminal/f5tunsrv.cab#version=7000,2011,104,2309
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - hxxps://vpn.na.sage.com/vdesk/terminal/InstallerControl.cab#version=7000,2010,1020,1507
DPF: {49EC7987-E331-44E3-B170-748B58A268B9} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} - hxxps://vpn.na.sage.com/vdesk/terminal/f5InspectionHost.cab#version=7000,2010,1020,1407
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} - hxxps://vpn.na.sage.com/vdesk/terminal/urxshost.cab#version=7000,2010,1020,1428
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://vpn.na.sage.com/vdesk/terminal/urxhost.cab#version=7000,2011,124,911
DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} - hxxps://vpn.na.sage.com/policy/download_binary.php/win32/f5syschk.cab#Version=7000,2010,1020,1432
DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - f:\programs\office\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 216.240.133.193 www.google-analytics.com.
Hosts: 216.240.133.193 ad-emea.doubleclick.net.
Hosts: 216.240.133.193 www.statcounter.com.
Hosts: 69.72.252.254 www.google-analytics.com.
Hosts: 69.72.252.254 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\patricia\applic~1\mozilla\firefox\profiles\wkqja21d.default\
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: e:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: f:\programs\office\office14\NPAUTHZ.DLL
FF - plugin: f:\programs\office\office14\NPSPWRAP.DLL
FF - plugin: f:\programs\real alternative\browser\plugins\nppl3260.dll
FF - plugin: f:\programs\real alternative\browser\plugins\nprpjplug.dll
FF - plugin: i:\programs\divx\divx web player\npdivx32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [2011-12-18 107336]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
R1 MpKsl4eb7697b;MpKsl4eb7697b;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\MpKsl4eb7697b.sys [2011-12-20 29904]
R2 Peachtree SmartPosting 2011;Peachtree SmartPosting 2011;e:\programs\sage\peachtree\SmartPostingService2011.exe [2010-9-13 43848]
R2 psqlWGE;Pervasive PSQL Workgroup Engine;c:\program files\pervasive software\psql\bin\w3dbsmgr.exe [2008-6-6 435496]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2012\TuneUpUtilitiesService32.exe [2011-12-14 1514304]
R2 WRSVC;WRSVC;c:\program files\webroot\WRSA.exe [2011-12-18 637208]
R3 ALSysIO;ALSysIO;\??\c:\docume~1\patricia\locals~1\temp\alsysio.sys –> c:\docume~1\patricia\locals~1\temp\ALSysIO.sys [?]
R3 GEST Service;GEST Service for program management.;c:\program files\gigabyte\gest\GSvr.exe [2010-4-26 47624]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2012\TuneUpUtilitiesDriver32.sys [2011-11-8 10064]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [2010-6-11 35448]
S0 pIclxoGw;pIclxoGw;c:\windows\system32\drivers\pIclxoGw.sys [2011-12-20 107336]
S1 MpKsl05309e57;MpKsl05309e57;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c584baa6-e20e-44be-9141-61d6417b9b42}\mpksl05309e57.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c584baa6-e20e-44be-9141-61d6417b9b42}\MpKsl05309e57.sys [?]
S1 MpKsl2714a0e1;MpKsl2714a0e1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdbb7fc4-3c2a-4e0b-80ad-4e490922cee0}\mpksl2714a0e1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdbb7fc4-3c2a-4e0b-80ad-4e490922cee0}\MpKsl2714a0e1.sys [?]
S1 MpKsl2f23e610;MpKsl2f23e610;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\mpksl2f23e610.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\MpKsl2f23e610.sys [?]
S1 MpKsl354afefd;MpKsl354afefd;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{01751214-b360-4f2b-a0f5-14a514a2d6ed}\mpksl354afefd.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{01751214-b360-4f2b-a0f5-14a514a2d6ed}\MpKsl354afefd.sys [?]
S1 MpKsl6d86a591;MpKsl6d86a591;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32aa8df5-fbc5-4db8-a871-71feadde419f}\mpksl6d86a591.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32aa8df5-fbc5-4db8-a871-71feadde419f}\MpKsl6d86a591.sys [?]
S1 MpKsl7990e691;MpKsl7990e691;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{803f0683-2921-4ba4-b339-847eb250ceb5}\mpksl7990e691.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{803f0683-2921-4ba4-b339-847eb250ceb5}\MpKsl7990e691.sys [?]
S1 MpKsl836b7f90;MpKsl836b7f90;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{29d607b1-73f8-4c69-b41d-cc62685ab812}\mpksl836b7f90.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{29d607b1-73f8-4c69-b41d-cc62685ab812}\MpKsl836b7f90.sys [?]
S1 MpKsl88e6af3b;MpKsl88e6af3b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e8c76270-ac80-4a45-9ace-65c7af84bc87}\mpksl88e6af3b.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e8c76270-ac80-4a45-9ace-65c7af84bc87}\MpKsl88e6af3b.sys [?]
S1 MpKsl944debed;MpKsl944debed;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4dbb258c-2bde-43d7-9caa-61ba55584da1}\mpksl944debed.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4dbb258c-2bde-43d7-9caa-61ba55584da1}\MpKsl944debed.sys [?]
S1 MpKsl99c0f781;MpKsl99c0f781;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f8af1b56-0c99-4ac0-b79f-fb5d0c0c8140}\mpksl99c0f781.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f8af1b56-0c99-4ac0-b79f-fb5d0c0c8140}\MpKsl99c0f781.sys [?]
S1 MpKslaae793a0;MpKslaae793a0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\mpkslaae793a0.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\MpKslaae793a0.sys [?]
S1 MpKslcbd862da;MpKslcbd862da;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{042caf0a-ea2f-4642-bd5c-d436c09b9add}\mpkslcbd862da.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{042caf0a-ea2f-4642-bd5c-d436c09b9add}\MpKslcbd862da.sys [?]
S1 MpKslce097d11;MpKslce097d11;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a1b535f4-7bf2-4167-8573-7720aa6f42d6}\mpkslce097d11.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a1b535f4-7bf2-4167-8573-7720aa6f42d6}\MpKslce097d11.sys [?]
S1 MpKsld45cf3e6;MpKsld45cf3e6;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ab8b7ebc-2b9e-4937-8142-4be51f0ebf69}\mpksld45cf3e6.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ab8b7ebc-2b9e-4937-8142-4be51f0ebf69}\MpKsld45cf3e6.sys [?]
S1 MpKsldaa75e46;MpKsldaa75e46;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f17962e0-8376-4980-9ad4-622c9950922f}\mpksldaa75e46.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f17962e0-8376-4980-9ad4-622c9950922f}\MpKsldaa75e46.sys [?]
S1 MpKsle7be0667;MpKsle7be0667;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17c6adc8-1ee4-4a18-bce9-821f136857ed}\mpksle7be0667.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17c6adc8-1ee4-4a18-bce9-821f136857ed}\MpKsle7be0667.sys [?]
S1 MpKslecb2ba95;MpKslecb2ba95;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb483246-1cd6-4db2-896f-12372ff095cf}\mpkslecb2ba95.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb483246-1cd6-4db2-896f-12372ff095cf}\MpKslecb2ba95.sys [?]
S2 NeroRegInCDSrv;Nero Registry InCD Service;e:\program files\nero\nero 7\incd\nbhregincdsrv.exe –> e:\program files\nero\nero 7\incd\NBHRegInCDSrv.exe [?]
S3 esgiguard;esgiguard;\??\c:\program files\enigma software group\spyhunter\esgiguard.sys –> c:\program files\enigma software group\spyhunter\esgiguard.sys [?]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [2010-12-12 10744]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-4-17 22216]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;f:\programs\office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-12-4 50704]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S4 MBAMService;MBAMService;f:\programs\malwarebytes' anti-malware\mbamservice.exe [2011-4-17 366152]
.
=============== File Associations ===============
.
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
.
=============== Created Last 30 ================
.
2011-12-20 14:40:43 107336 —-a-w- c:\windows\system32\drivers\pIclxoGw.sys
2011-12-20 13:58:44 28992 —-a-w- c:\windows\system32\uxtuneup.dll
2011-12-20 13:36:01 29904 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\MpKsl4eb7697b.sys
2011-12-20 13:35:59 56200 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\offreg.dll
2011-12-20 13:34:51 162816 —-a-w- c:\windows\system32\drivers\BineenXt.sys
2011-12-20 01:31:05 162816 —-a-w- c:\windows\system32\drivers\srvlnASy.sys
2011-12-19 21:16:33 6823496 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\mpengine.dll
2011-12-19 04:27:36 162816 —-a-w- c:\windows\system32\drivers\xocVqFMR.sys
2011-12-19 04:27:22 162816 —-a-w- c:\windows\system32\drivers\odcgeLCR.sys
2011-12-19 00:33:24 162816 —-a-w- c:\windows\system32\drivers\VGlxxmhq.sys
2011-12-18 21:17:39 162816 —-a-w- c:\windows\system32\drivers\tftUsCuh.sys
2011-12-18 21:12:40 162816 —-a-w- c:\windows\system32\drivers\UtNACVPB.sys
2011-12-18 20:58:51 162816 —-a-w- c:\windows\system32\drivers\tkGBMHJb.sys
2011-12-18 20:56:34 141272 —-a-w- c:\windows\system32\WRusr.dll
2011-12-18 20:56:34 107336 —-a-w- c:\windows\system32\drivers\WRkrn.sys
2011-12-18 20:56:32 ——– d—–w- c:\program files\Webroot
2011-12-18 20:56:30 ——– d—–w- c:\docume~1\alluse~1\applic~1\WRData
2011-12-10 15:09:11 ——– d—–w- c:\program files\common files\DivX Shared
2011-12-04 15:31:30 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2011-12-04 15:30:56 ——– d—–w- c:\docume~1\patricia\applic~1\TuneUp Software
2011-12-04 15:30:34 ——– d—–w- c:\program files\TuneUp Utilities 2012
2011-12-04 15:29:11 ——– d—–w- c:\docume~1\alluse~1\applic~1\TuneUp Software
2011-12-04 15:28:39 ——– d-sh–w- c:\docume~1\alluse~1\applic~1\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-12-04 14:11:18 41680 —-a-w- c:\windows\system32\drivers\ubxxitam.sys
2011-12-04 14:09:55 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-12-04 14:09:55 281104 —-a-w- c:\windows\system32\wpcap.dll
2011-12-04 14:09:55 100880 —-a-w- c:\windows\system32\Packet.dll
2011-12-03 22:05:01 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-12-03 22:05:01 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-03 19:49:17 ——– d—–w- c:\docume~1\patricia\applic~1\Malwarebytes
.
==================== Find3M ====================
.
2011-12-20 13:36:10 16608 —-a-w- c:\windows\gdrv.sys
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 19:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-23 17:08:43 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 -c–a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 -c–a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 -c–a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 10:22:06.64 ===============



——————————————————————————–
Hi DeViouS,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-23 09:54:49 —————————– 09:54:49.732 OS Version: Windows 5.1.2600 Service Pack 3 09:54:49.732 Number of processors: 2 586 0x170A 09:54:49.732 ComputerName: THE-BEAST UserName: Patricia 09:54:50.123 Initialize success 09:55:35.654 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 09:55:35.654 Disk 0 Vendor: SAMSUNG_SP0802N TK100-23 Size: 76350MB BusType: 3 09:55:35.654 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T1L0-19 09:55:35.654 Disk 1 Vendor: WDC_WD3200AAKS-00B3A0 01.03A01 Size: 305244MB BusType: 3 09:55:37.654 Disk 1 MBR read successfully 09:55:37.654 Disk 1 MBR scan 09:55:37.654 Disk 1 Windows XP default MBR code 09:55:37.654 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 12001 MB offset 63 09:55:37.654 Disk 0 Partition - 00 0F Extended LBA 119059 MB offset 24579450 09:55:37.685 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 174181 MB offset 268414020 09:55:37.701 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 119059 MB offset 24579513 09:55:37.701 Disk 1 scanning sectors +625137345 09:55:37.763 Disk 1 scanning C:\WINDOWS\system32\drivers 09:55:45.357 File: C:\WINDOWS\system32\drivers\netbt.sys **SUSPICIOUS** 09:55:48.966 Service scanning 09:55:49.451 Service MpKsl432b342d C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{06C695D0-FB47-4A3A-B93B-226642FBF3E5}\MpKsl432b342d.sys **LOCKED** 32 09:55:49.576 Service WRkrn C:\WINDOWS\System32\drivers\WRkrn.sys **LOCKED** 32 09:55:50.076 Modules scanning 09:55:52.669 Module: C:\WINDOWS\system32\DRIVERS\netbt.sys **SUSPICIOUS** 09:55:53.779 Disk 1 trace - called modules: 09:55:53.794 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a4c5f10]<< 09:55:53.794 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8b218ab8] 09:55:53.794 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> [0x8a778e10] 09:55:53.794 \Driver\00000772[0x8b0ae5a0] -> IRP_MJ_CREATE -> 0x8a4c5f10 09:55:53.794 Scan finished successfully 09:56:08.748 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\Patricia\Desktop\MBR.dat" 09:56:08.763 The log file has been saved successfully to "C:\Documents and Settings\Patricia\Desktop\aswMBR.txt" 09:57:01.0435 0788 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 09:57:02.0919 0788 ============================================================ 09:57:02.0919 0788 Current date / time: 2011/12/23 09:57:02.0919 09:57:02.0919 0788 SystemInfo: 09:57:02.0919 0788 09:57:02.0919 0788 OS Version: 5.1.2600 ServicePack: 3.0 09:57:02.0919 0788 Product type: Workstation 09:57:02.0919 0788 ComputerName: THE-BEAST 09:57:02.0919 0788 UserName: Patricia 09:57:02.0919 0788 Windows directory: C:\WINDOWS 09:57:02.0919 0788 System windows directory: C:\WINDOWS 09:57:02.0919 0788 Processor architecture: Intel x86 09:57:02.0919 0788 Number of processors: 2 09:57:02.0919 0788 Page size: 0x1000 09:57:02.0919 0788 Boot type: Normal boot 09:57:02.0919 0788 ============================================================ 09:57:05.0076 0788 Initialize success 09:57:16.0373 2628 ============================================================ 09:57:16.0373 2628 Scan started 09:57:16.0373 2628 Mode: Manual; 09:57:16.0373 2628 ============================================================ 09:57:16.0841 2628 Abiosdsk - ok 09:57:16.0857 2628 abp480n5 - ok 09:57:16.0888 2628 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 09:57:16.0888 2628 ACPI - ok 09:57:16.0888 2628 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 09:57:16.0888 2628 ACPIEC - ok 09:57:16.0904 2628 adpu160m - ok 09:57:16.0935 2628 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 09:57:16.0935 2628 aec - ok 09:57:16.0966 2628 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 09:57:16.0966 2628 AFD - ok 09:57:16.0966 2628 Aha154x - ok 09:57:16.0982 2628 aic78u2 - ok 09:57:16.0982 2628 aic78xx - ok 09:57:16.0998 2628 AliIde - ok 09:57:17.0076 2628 ALSysIO - ok 09:57:17.0091 2628 amsint - ok 09:57:17.0091 2628 asc - ok 09:57:17.0107 2628 asc3350p - ok 09:57:17.0107 2628 asc3550 - ok 09:57:17.0138 2628 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 09:57:17.0138 2628 AsyncMac - ok 09:57:17.0169 2628 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 09:57:17.0169 2628 atapi - ok 09:57:17.0169 2628 Atdisk - ok 09:57:17.0201 2628 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 09:57:17.0201 2628 Atmarpc - ok 09:57:17.0216 2628 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 09:57:17.0216 2628 audstub - ok 09:57:17.0232 2628 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 09:57:17.0232 2628 Beep - ok 09:57:17.0248 2628 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 09:57:17.0248 2628 cbidf2k - ok 09:57:17.0248 2628 cd20xrnt - ok 09:57:17.0263 2628 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 09:57:17.0263 2628 Cdaudio - ok 09:57:17.0279 2628 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 09:57:17.0279 2628 Cdfs - ok 09:57:17.0310 2628 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 09:57:17.0310 2628 Cdrom - ok 09:57:17.0310 2628 Changer - ok 09:57:17.0326 2628 CmdIde - ok 09:57:17.0326 2628 Cpqarray - ok 09:57:17.0341 2628 dac2w2k - ok 09:57:17.0341 2628 dac960nt - ok 09:57:17.0357 2628 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 09:57:17.0373 2628 Disk - ok 09:57:17.0404 2628 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 09:57:17.0419 2628 dmboot - ok 09:57:17.0435 2628 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 09:57:17.0435 2628 dmio - ok 09:57:17.0451 2628 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 09:57:17.0451 2628 dmload - ok 09:57:17.0466 2628 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 09:57:17.0466 2628 DMusic - ok 09:57:17.0482 2628 dpti2o - ok 09:57:17.0482 2628 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 09:57:17.0482 2628 drmkaud - ok 09:57:17.0513 2628 esgiguard - ok 09:57:17.0529 2628 ET5Drv (e5030e34de21a6818e8586bfb7dd4b60) C:\WINDOWS\system32\Drivers\ET5Drv.sys 09:57:17.0529 2628 ET5Drv - ok 09:57:17.0560 2628 f5ipfw (1bba2dbb1eaa92c4068dfa35c2f22456) C:\WINDOWS\system32\drivers\urfltw2k.sys 09:57:17.0560 2628 f5ipfw - ok 09:57:17.0576 2628 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 09:57:17.0576 2628 Fastfat - ok 09:57:17.0591 2628 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 09:57:17.0591 2628 Fdc - ok 09:57:17.0607 2628 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 09:57:17.0607 2628 Fips - ok 09:57:17.0623 2628 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 09:57:17.0623 2628 Flpydisk - ok 09:57:17.0638 2628 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 09:57:17.0638 2628 FltMgr - ok 09:57:17.0654 2628 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 09:57:17.0654 2628 Fs_Rec - ok 09:57:17.0669 2628 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 09:57:17.0669 2628 Ftdisk - ok 09:57:17.0685 2628 gdrv (5c230948dd6652228f88ca7ae6cb276c) C:\WINDOWS\gdrv.sys 09:57:17.0701 2628 gdrv - ok 09:57:17.0716 2628 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 09:57:17.0716 2628 GEARAspiWDM - ok 09:57:17.0748 2628 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 09:57:17.0748 2628 Gpc - ok 09:57:17.0763 2628 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 09:57:17.0763 2628 HDAudBus - ok 09:57:17.0779 2628 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 09:57:17.0779 2628 HidUsb - ok 09:57:17.0779 2628 hpn - ok 09:57:17.0810 2628 HPZid412 (5faba4775d4c61e55ec669d643ffc71f) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 09:57:17.0810 2628 HPZid412 - ok 09:57:17.0810 2628 HPZipr12 (a3c43980ee1f1beac778b44ea65dbdd4) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 09:57:17.0810 2628 HPZipr12 - ok 09:57:17.0841 2628 HPZius12 (2906949bd4e206f2bb0dd1896ce9f66f) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 09:57:17.0841 2628 HPZius12 - ok 09:57:17.0873 2628 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 09:57:17.0873 2628 HTTP - ok 09:57:17.0873 2628 i2omgmt - ok 09:57:17.0888 2628 i2omp - ok 09:57:17.0904 2628 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 09:57:17.0904 2628 i8042prt - ok 09:57:17.0919 2628 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 09:57:17.0919 2628 Imapi - ok 09:57:17.0935 2628 InCDfs (98e96b6f095e6289c3293b99d0f926b2) C:\WINDOWS\system32\drivers\InCDFs.sys 09:57:17.0935 2628 InCDfs - ok 09:57:17.0935 2628 InCDPass (0b3e2517cf826020688650d46adf5b05) C:\WINDOWS\system32\drivers\InCDPass.sys 09:57:17.0935 2628 InCDPass - ok 09:57:17.0951 2628 InCDrec (00ee363ea793a9d8dab5254acbd7d8e6) C:\WINDOWS\system32\drivers\InCDRec.sys 09:57:17.0951 2628 InCDrec - ok 09:57:17.0966 2628 incdrm (d41ab5be8861aff53851594de58dddfa) C:\WINDOWS\system32\drivers\InCDRm.sys 09:57:17.0966 2628 incdrm - ok 09:57:17.0966 2628 ini910u - ok 09:57:18.0060 2628 IntcAzAudAddService (557e20484a095d949912883f5ab29e88) C:\WINDOWS\system32\drivers\RtkHDAud.sys 09:57:18.0091 2628 IntcAzAudAddService - ok 09:57:18.0091 2628 IntelIde - ok 09:57:18.0107 2628 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 09:57:18.0107 2628 intelppm - ok 09:57:18.0123 2628 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 09:57:18.0123 2628 Ip6Fw - ok 09:57:18.0138 2628 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 09:57:18.0138 2628 IpFilterDriver - ok 09:57:18.0169 2628 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 09:57:18.0169 2628 IpInIp - ok 09:57:18.0201 2628 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 09:57:18.0201 2628 IpNat - ok 09:57:18.0232 2628 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 09:57:18.0232 2628 IPSec - ok 09:57:18.0263 2628 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 09:57:18.0263 2628 IRENUM - ok 09:57:18.0263 2628 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 09:57:18.0263 2628 isapnp - ok 09:57:18.0279 2628 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 09:57:18.0279 2628 Kbdclass - ok 09:57:18.0294 2628 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 09:57:18.0294 2628 kbdhid - ok 09:57:18.0310 2628 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 09:57:18.0310 2628 kmixer - ok 09:57:18.0341 2628 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 09:57:18.0341 2628 KSecDD - ok 09:57:18.0357 2628 lbrtfdc - ok 09:57:18.0373 2628 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\WINDOWS\system32\drivers\mbam.sys 09:57:18.0373 2628 MBAMProtector - ok 09:57:18.0388 2628 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 09:57:18.0388 2628 mnmdd - ok 09:57:18.0404 2628 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 09:57:18.0404 2628 Modem - ok 09:57:18.0419 2628 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 09:57:18.0419 2628 Mouclass - ok 09:57:18.0435 2628 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 09:57:18.0435 2628 mouhid - ok 09:57:18.0435 2628 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 09:57:18.0435 2628 MountMgr - ok 09:57:18.0451 2628 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 09:57:18.0451 2628 MpFilter - ok 09:57:18.0544 2628 MpKsl05309e57 - ok 09:57:18.0544 2628 MpKsl2714a0e1 - ok 09:57:18.0544 2628 MpKsl2f23e610 - ok 09:57:18.0544 2628 MpKsl354afefd - ok 09:57:18.0576 2628 MpKsl432b342d (a69630d039c38018689190234f866d77) C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{06C695D0-FB47-4A3A-B93B-226642FBF3E5}\MpKsl432b342d.sys 09:57:18.0576 2628 MpKsl432b342d - ok 09:57:18.0591 2628 MpKsl5f1c8bed - ok 09:57:18.0591 2628 MpKsl6d86a591 - ok 09:57:18.0591 2628 MpKsl7990e691 - ok 09:57:18.0591 2628 MpKsl836b7f90 - ok 09:57:18.0607 2628 MpKsl88e6af3b - ok 09:57:18.0607 2628 MpKsl944debed - ok 09:57:18.0607 2628 MpKsl99c0f781 - ok 09:57:18.0607 2628 MpKsl9ed29e84 - ok 09:57:18.0607 2628 MpKslaae793a0 - ok 09:57:18.0623 2628 MpKslcbd862da - ok 09:57:18.0623 2628 MpKslce097d11 - ok 09:57:18.0623 2628 MpKsld45cf3e6 - ok 09:57:18.0623 2628 MpKsldaa75e46 - ok 09:57:18.0638 2628 MpKsle7be0667 - ok 09:57:18.0638 2628 MpKslecb2ba95 - ok 09:57:18.0638 2628 mraid35x - ok 09:57:18.0701 2628 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS 09:57:18.0701 2628 MREMP50 - ok 09:57:18.0701 2628 MREMPR5 - ok 09:57:18.0701 2628 MRENDIS5 - ok 09:57:18.0716 2628 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS 09:57:18.0716 2628 MRESP50 - ok 09:57:18.0732 2628 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 09:57:18.0732 2628 MRxDAV - ok 09:57:18.0763 2628 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 09:57:18.0763 2628 MRxSmb - ok 09:57:18.0826 2628 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 09:57:18.0826 2628 Msfs - ok 09:57:18.0857 2628 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 09:57:18.0857 2628 MSKSSRV - ok 09:57:18.0873 2628 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 09:57:18.0873 2628 MSPCLOCK - ok 09:57:18.0888 2628 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 09:57:18.0888 2628 MSPQM - ok 09:57:18.0919 2628 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 09:57:18.0919 2628 mssmbios - ok 09:57:18.0951 2628 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 09:57:18.0951 2628 Mup - ok 09:57:18.0966 2628 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 09:57:18.0966 2628 NDIS - ok 09:57:18.0982 2628 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 09:57:18.0982 2628 NdisTapi - ok 09:57:18.0998 2628 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 09:57:18.0998 2628 Ndisuio - ok 09:57:19.0029 2628 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 09:57:19.0029 2628 NdisWan - ok 09:57:19.0060 2628 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 09:57:19.0060 2628 NDProxy - ok 09:57:19.0076 2628 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 09:57:19.0076 2628 NetBIOS - ok 09:57:19.0123 2628 NetBT (0ae50956b77a07dd5ceb5c850b98b765) C:\WINDOWS\system32\DRIVERS\netbt.sys 09:57:19.0123 2628 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\netbt.sys. Real md5: 0ae50956b77a07dd5ceb5c850b98b765, Fake md5: 74b2b2f5bea5e9a3dc021d685551bd3d 09:57:19.0123 2628 NetBT ( Rootkit.Win32.ZAccess.k ) - infected 09:57:19.0123 2628 NetBT - detected Rootkit.Win32.ZAccess.k (0) 09:57:19.0154 2628 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS\system32\drivers\NPF.sys 09:57:19.0154 2628 NPF - ok 09:57:19.0169 2628 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 09:57:19.0169 2628 Npfs - ok 09:57:19.0185 2628 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 09:57:19.0201 2628 Ntfs - ok 09:57:19.0216 2628 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 09:57:19.0216 2628 Null - ok 09:57:19.0404 2628 nv (30913cbf518396912e54c2c9f1dd0f09) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 09:57:19.0544 2628 nv - ok 09:57:19.0576 2628 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 09:57:19.0576 2628 NwlnkFlt - ok 09:57:19.0591 2628 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 09:57:19.0591 2628 NwlnkFwd - ok 09:57:19.0607 2628 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 09:57:19.0623 2628 Parport - ok 09:57:19.0638 2628 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 09:57:19.0638 2628 PartMgr - ok 09:57:19.0638 2628 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 09:57:19.0654 2628 ParVdm - ok 09:57:19.0669 2628 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 09:57:19.0669 2628 PCI - ok 09:57:19.0669 2628 PCIDump - ok 09:57:19.0685 2628 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 09:57:19.0685 2628 PCIIde - ok 09:57:19.0716 2628 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 09:57:19.0716 2628 Pcmcia - ok 09:57:19.0716 2628 PDCOMP - ok 09:57:19.0732 2628 PDFRAME - ok 09:57:19.0732 2628 PDRELI - ok 09:57:19.0748 2628 PDRFRAME - ok 09:57:19.0748 2628 perc2 - ok 09:57:19.0748 2628 perc2hib - ok 09:57:19.0779 2628 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 09:57:19.0794 2628 PptpMiniport - ok 09:57:19.0810 2628 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 09:57:19.0810 2628 PSched - ok 09:57:19.0810 2628 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 09:57:19.0810 2628 Ptilink - ok 09:57:19.0826 2628 ql1080 - ok 09:57:19.0826 2628 Ql10wnt - ok 09:57:19.0841 2628 ql12160 - ok 09:57:19.0841 2628 ql1240 - ok 09:57:19.0841 2628 ql1280 - ok 09:57:19.0857 2628 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 09:57:19.0857 2628 RasAcd - ok 09:57:19.0857 2628 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 09:57:19.0857 2628 Rasl2tp - ok 09:57:19.0873 2628 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 09:57:19.0873 2628 RasPppoe - ok 09:57:19.0888 2628 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 09:57:19.0888 2628 Raspti - ok 09:57:19.0904 2628 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 09:57:19.0904 2628 Rdbss - ok 09:57:19.0904 2628 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 09:57:19.0904 2628 RDPCDD - ok 09:57:19.0919 2628 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 09:57:19.0919 2628 rdpdr - ok 09:57:19.0951 2628 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 09:57:19.0951 2628 RDPWD - ok 09:57:19.0966 2628 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 09:57:19.0966 2628 redbook - ok 09:57:19.0982 2628 RTLE8023xp (89619ef503f949fae09252a8b883ee11) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 09:57:19.0982 2628 RTLE8023xp - ok 09:57:20.0013 2628 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 09:57:20.0013 2628 Secdrv - ok 09:57:20.0013 2628 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 09:57:20.0013 2628 serenum - ok 09:57:20.0044 2628 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 09:57:20.0044 2628 Serial - ok 09:57:20.0044 2628 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 09:57:20.0044 2628 Sfloppy - ok 09:57:20.0060 2628 Simbad - ok 09:57:20.0060 2628 Sparrow - ok 09:57:20.0076 2628 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 09:57:20.0076 2628 splitter - ok 09:57:20.0091 2628 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 09:57:20.0091 2628 sr - ok 09:57:20.0107 2628 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 09:57:20.0123 2628 Srv - ok 09:57:20.0138 2628 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 09:57:20.0138 2628 swenum - ok 09:57:20.0138 2628 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 09:57:20.0138 2628 swmidi - ok 09:57:20.0154 2628 symc810 - ok 09:57:20.0154 2628 symc8xx - ok 09:57:20.0169 2628 SymIM - ok 09:57:20.0169 2628 SymIMMP - ok 09:57:20.0185 2628 sym_hi - ok 09:57:20.0185 2628 sym_u3 - ok 09:57:20.0201 2628 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 09:57:20.0201 2628 sysaudio - ok 09:57:20.0232 2628 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 09:57:20.0248 2628 Tcpip - ok 09:57:20.0263 2628 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 09:57:20.0263 2628 TDPIPE - ok 09:57:20.0279 2628 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 09:57:20.0279 2628 TDTCP - ok 09:57:20.0294 2628 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 09:57:20.0294 2628 TermDD - ok 09:57:20.0310 2628 TosIde - ok 09:57:20.0357 2628 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys 09:57:20.0357 2628 TuneUpUtilitiesDrv - ok 09:57:20.0388 2628 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 09:57:20.0388 2628 Udfs - ok 09:57:20.0388 2628 ultra - ok 09:57:20.0419 2628 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 09:57:20.0435 2628 Update - ok 09:57:20.0451 2628 urvpndrv (01ebd235c3bb80d315ed13f4ca50f61b) C:\WINDOWS\system32\DRIVERS\covpndrv.sys 09:57:20.0451 2628 urvpndrv - ok 09:57:20.0482 2628 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 09:57:20.0482 2628 USBAAPL - ok 09:57:20.0513 2628 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 09:57:20.0513 2628 usbccgp - ok 09:57:20.0529 2628 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 09:57:20.0529 2628 usbehci - ok 09:57:20.0544 2628 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 09:57:20.0544 2628 usbhub - ok 09:57:20.0560 2628 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 09:57:20.0560 2628 usbprint - ok 09:57:20.0591 2628 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 09:57:20.0591 2628 usbscan - ok 09:57:20.0623 2628 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 09:57:20.0623 2628 usbstor - ok 09:57:20.0638 2628 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 09:57:20.0638 2628 usbuhci - ok 09:57:20.0638 2628 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 09:57:20.0638 2628 VgaSave - ok 09:57:20.0654 2628 ViaIde - ok 09:57:20.0669 2628 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 09:57:20.0669 2628 VolSnap - ok 09:57:20.0685 2628 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 09:57:20.0685 2628 Wanarp - ok 09:57:20.0685 2628 WDICA - ok 09:57:20.0701 2628 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 09:57:20.0701 2628 wdmaud - ok 09:57:20.0748 2628 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys 09:57:20.0748 2628 WpdUsb - ok 09:57:20.0763 2628 WRkrn (20fe8507d2c728191f1e02b590a590bf) C:\WINDOWS\system32\drivers\WRkrn.sys 09:57:20.0763 2628 WRkrn - ok 09:57:20.0779 2628 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 09:57:20.0779 2628 WudfPf - ok 09:57:20.0794 2628 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 09:57:20.0794 2628 WudfRd - ok 09:57:20.0810 2628 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 09:57:20.0826 2628 \Device\Harddisk0\DR0 - ok 09:57:20.0841 2628 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 09:57:20.0982 2628 \Device\Harddisk1\DR1 - ok 09:57:20.0982 2628 Boot (0x1200) (a7c79b5bf9c9f9c1e44ce3f56557b3fc) \Device\Harddisk0\DR0\Partition0 09:57:20.0982 2628 \Device\Harddisk0\DR0\Partition0 - ok 09:57:20.0982 2628 Boot (0x1200) (68ad208b9449514f2630f09ee5e77b2f) \Device\Harddisk1\DR1\Partition0 09:57:20.0982 2628 \Device\Harddisk1\DR1\Partition0 - ok 09:57:21.0013 2628 Boot (0x1200) (ce5b1bb060799eb896ff2cb757a1a0da) \Device\Harddisk1\DR1\Partition1 09:57:21.0013 2628 \Device\Harddisk1\DR1\Partition1 - ok 09:57:21.0029 2628 Boot (0x1200) (0294f8a1a1354be60d03d8d9f853d8e2) \Device\Harddisk1\DR1\Partition2 09:57:21.0029 2628 \Device\Harddisk1\DR1\Partition2 - ok 09:57:21.0029 2628 ============================================================ 09:57:21.0029 2628 Scan finished 09:57:21.0029 2628 ============================================================ 09:57:21.0029 3608 Detected object count: 1 09:57:21.0029 3608 Actual detected object count: 1 09:57:41.0701 3608 NetBT ( Rootkit.Win32.ZAccess.k ) - skipped by user 09:57:41.0701 3608 NetBT ( Rootkit.Win32.ZAccess.k ) - User select action: Skip 09:57:56.0044 3080 Deinitialize success

Attachments:

Hi DeViouS,

Next, Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
ComboFix 11-12-23.01 - Patricia 12/23/2011 20:39:55.2.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2917 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\windows\system32\drivers\npf.sys
c:\windows\system32\oobe\isperror\ispcnerr.htm
c:\windows\system32\oobe\isperror\ispdtone.htm
c:\windows\system32\oobe\isperror\isphdshk.htm
c:\windows\system32\oobe\isperror\ispins.htm
c:\windows\system32\oobe\isperror\ispnoanw.htm
c:\windows\system32\oobe\isperror\isppberr.htm
c:\windows\system32\oobe\isperror\ispphbsy.htm
c:\windows\system32\oobe\isperror\ispsbusy.htm
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_NPF
——-\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))
.
.
2011-12-23 23:29 . 2011-12-23 23:29 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\MpKslf1e23d93.sys
2011-12-23 23:27 . 2011-12-23 23:27 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\MpKsl93a3f44a.sys
2011-12-23 14:59 . 2011-11-21 07:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\mpengine.dll
2011-12-22 14:30 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\BNVxEJta.sys
2011-12-20 13:58 . 2011-12-14 11:46 28992 —-a-w- c:\windows\system32\uxtuneup.dll
2011-12-20 13:34 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\BineenXt.sys
2011-12-20 01:31 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\srvlnASy.sys
2011-12-19 04:27 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\xocVqFMR.sys
2011-12-19 04:27 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\odcgeLCR.sys
2011-12-19 00:33 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\VGlxxmhq.sys
2011-12-18 21:17 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\tftUsCuh.sys
2011-12-18 21:12 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\UtNACVPB.sys
2011-12-18 20:58 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\tkGBMHJb.sys
2011-12-16 00:24 . 2011-12-16 00:24 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-12-11 15:35 . 2011-12-11 15:35 ——– d—–w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2011-12-10 15:09 . 2011-12-10 15:09 ——– d—–w- c:\program files\Common Files\DivX Shared
2011-12-05 10:18 . 2011-12-11 11:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-12-04 15:31 . 2011-12-14 11:47 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2011-12-04 15:30 . 2011-12-04 15:30 ——– d—–w- c:\documents and settings\Patricia\Application Data\TuneUp Software
2011-12-04 15:30 . 2011-12-20 13:59 ——– d—–w- c:\program files\TuneUp Utilities 2012
2011-12-04 15:29 . 2011-12-04 15:31 ——– d—–w- c:\documents and settings\All Users\Application Data\TuneUp Software
2011-12-04 15:28 . 2011-12-04 15:28 ——– d-sh–w- c:\documents and settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-12-04 14:11 . 2011-12-04 14:11 41680 —-a-w- c:\windows\system32\drivers\ubxxitam.sys
2011-12-03 22:05 . 2011-12-03 22:05 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-03 19:49 . 2011-12-03 19:49 ——– d—–w- c:\documents and settings\Patricia\Application Data\Malwarebytes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-23 23:48 . 2010-04-27 03:49 16608 —-a-w- c:\windows\gdrv.sys
2011-11-23 13:25 . 2004-08-04 04:17 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 07:47 . 2011-09-19 13:26 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-01 16:07 . 2004-08-04 05:56 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-04 05:56 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-04 04:18 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 19:29 . 2011-10-24 19:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29 . 2011-10-24 19:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-23 17:08 . 2011-06-02 03:07 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 11:13 . 2004-08-04 05:56 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2010-04-26 06:53 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 05:56 599040 -c–a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-30 00:59 611328 -c–a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2001-08-23 12:00 220160 -c–a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2001-08-23 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...r=9.0.872" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 04:07 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 ——r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 08:42 2808832 ——r- c:\windows\alcwzrd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-09-27 12:22 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Core Temp]
2011-09-02 04:29 722384 —-a-w- c:\program files\Core Temp\Core Temp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GEST]
2007-12-14 18:46 236040 —-a-w- c:\program files\GIGABYTE\GEST\run.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2008-02-18 18:36 1057064 —-a-w- e:\program files\Nero\Nero 7\InCD\InCD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-01-24 16:32 2289664 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 19:16 997920 -c–a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-02-27 17:03 570664 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-04-04 02:23 13670504 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-04-04 02:23 110696 —-a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeachtreePrefetcher.exe]
2011-02-22 00:05 29512 —-a-r- e:\programs\Sage\Peachtree\PeachtreePrefetcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-06-27 03:23 16875008 ——w- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
2008-02-18 18:36 1629480 —-a-w- e:\program files\Nero\Nero 7\InCD\NBHGui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ——w- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WRSVC"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"UxTuneUp"=2 (0x2)
"TuneUp.UtilitiesSvc"=2 (0x2)
"psqlWGE"=2 (0x2)
"Peachtree SmartPosting 2011"=2 (0x2)
"osppsvc"=3 (0x3)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NeroRegInCDSrv"=2 (0x2)
"NBService"=3 (0x3)
"MsMpSvc"=2 (0x2)
"McciCMService"=2 (0x2)
"LightScribeService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"InCDsrv"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"GEST Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\Programs\\BitTorrent\\bittorrent.exe"=
"e:\\Program Files\\StarCraft II Beta\\StarCraft II.exe"=
"c:\\Program Files\\Adobe\\Acrobat_com\\Acrobat_com.exe"=
"e:\\Program Files\\StarCraft II\\StarCraft II.exe"=
"e:\\Program Files\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
"c:\\Documents and Settings\\DeViouS\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"e:\\Program Files\\PFPortChecker\\PFPortChecker.exe"=
"f:\\Programs\\Office\\Office14\\GROOVE.EXE"=
"f:\\Programs\\Office\\Office14\\ONENOTE.EXE"=
"f:\\Programs\\Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Pervasive Software\\PSQL\\bin\\w3dbsmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"e:\\Program Files\\StarCraft II\\Versions\\Base18092\\SC2.exe"=
"f:\\Programs\\XBMC\\XBMC.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"1583:TCP"= 1583:TCP:Pervasive DBEngine
"3351:TCP"= 3351:TCP:Pervasive DBEngine
.
R1 MpKslf1e23d93;MpKslf1e23d93;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\MpKslf1e23d93.sys [12/23/2011 6:29 PM 29904]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [6/11/2010 2:02 PM 35448]
S1 MpKsl05309e57;MpKsl05309e57;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C584BAA6-E20E-44BE-9141-61D6417B9B42}\MpKsl05309e57.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C584BAA6-E20E-44BE-9141-61D6417B9B42}\MpKsl05309e57.sys [?]
S1 MpKsl2714a0e1;MpKsl2714a0e1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDBB7FC4-3C2A-4E0B-80AD-4E490922CEE0}\MpKsl2714a0e1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDBB7FC4-3C2A-4E0B-80AD-4E490922CEE0}\MpKsl2714a0e1.sys [?]
S1 MpKsl2f23e610;MpKsl2f23e610;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKsl2f23e610.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKsl2f23e610.sys [?]
S1 MpKsl354afefd;MpKsl354afefd;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01751214-B360-4F2B-A0F5-14A514A2D6ED}\MpKsl354afefd.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01751214-B360-4F2B-A0F5-14A514A2D6ED}\MpKsl354afefd.sys [?]
S1 MpKsl6d86a591;MpKsl6d86a591;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32AA8DF5-FBC5-4DB8-A871-71FEADDE419F}\MpKsl6d86a591.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32AA8DF5-FBC5-4DB8-A871-71FEADDE419F}\MpKsl6d86a591.sys [?]
S1 MpKsl7990e691;MpKsl7990e691;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{803F0683-2921-4BA4-B339-847EB250CEB5}\MpKsl7990e691.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{803F0683-2921-4BA4-B339-847EB250CEB5}\MpKsl7990e691.sys [?]
S1 MpKsl836b7f90;MpKsl836b7f90;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29D607B1-73F8-4C69-B41D-CC62685AB812}\MpKsl836b7f90.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29D607B1-73F8-4C69-B41D-CC62685AB812}\MpKsl836b7f90.sys [?]
S1 MpKsl88e6af3b;MpKsl88e6af3b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E8C76270-AC80-4A45-9ACE-65C7AF84BC87}\MpKsl88e6af3b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E8C76270-AC80-4A45-9ACE-65C7AF84BC87}\MpKsl88e6af3b.sys [?]
S1 MpKsl944debed;MpKsl944debed;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4DBB258C-2BDE-43D7-9CAA-61BA55584DA1}\MpKsl944debed.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4DBB258C-2BDE-43D7-9CAA-61BA55584DA1}\MpKsl944debed.sys [?]
S1 MpKsl99c0f781;MpKsl99c0f781;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F8AF1B56-0C99-4AC0-B79F-FB5D0C0C8140}\MpKsl99c0f781.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F8AF1B56-0C99-4AC0-B79F-FB5D0C0C8140}\MpKsl99c0f781.sys [?]
S1 MpKsl9ed29e84;MpKsl9ed29e84;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FD73EE98-D8CA-4DB1-B49A-189292D885AF}\MpKsl9ed29e84.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FD73EE98-D8CA-4DB1-B49A-189292D885AF}\MpKsl9ed29e84.sys [?]
S1 MpKslaae793a0;MpKslaae793a0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKslaae793a0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKslaae793a0.sys [?]
S1 MpKslcbd862da;MpKslcbd862da;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042CAF0A-EA2F-4642-BD5C-D436C09B9ADD}\MpKslcbd862da.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042CAF0A-EA2F-4642-BD5C-D436C09B9ADD}\MpKslcbd862da.sys [?]
S1 MpKslce097d11;MpKslce097d11;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A1B535F4-7BF2-4167-8573-7720AA6F42D6}\MpKslce097d11.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A1B535F4-7BF2-4167-8573-7720AA6F42D6}\MpKslce097d11.sys [?]
S1 MpKsld45cf3e6;MpKsld45cf3e6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB8B7EBC-2B9E-4937-8142-4BE51F0EBF69}\MpKsld45cf3e6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB8B7EBC-2B9E-4937-8142-4BE51F0EBF69}\MpKsld45cf3e6.sys [?]
S1 MpKsldaa75e46;MpKsldaa75e46;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F17962E0-8376-4980-9AD4-622C9950922F}\MpKsldaa75e46.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F17962E0-8376-4980-9AD4-622C9950922F}\MpKsldaa75e46.sys [?]
S1 MpKsle7be0667;MpKsle7be0667;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17C6ADC8-1EE4-4A18-BCE9-821F136857ED}\MpKsle7be0667.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17C6ADC8-1EE4-4A18-BCE9-821F136857ED}\MpKsle7be0667.sys [?]
S1 MpKslecb2ba95;MpKslecb2ba95;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB483246-1CD6-4DB2-896F-12372FF095CF}\MpKslecb2ba95.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB483246-1CD6-4DB2-896F-12372FF095CF}\MpKslecb2ba95.sys [?]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\Patricia\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\Patricia\LOCALS~1\Temp\ALSysIO.sys [?]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys –> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [12/12/2010 9:31 AM 10744]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [4/17/2011 1:33 PM 22216]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;f:\programs\Office\Office14\GROOVE.EXE [6/12/2011 10:15 AM 31125880]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [11/8/2011 9:25 PM 10064]
S4 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [4/26/2010 10:50 PM 47624]
S4 MBAMService;MBAMService;f:\programs\Malwarebytes' Anti-Malware\mbamservice.exe [4/17/2011 1:33 PM 366152]
S4 NeroRegInCDSrv;Nero Registry InCD Service;e:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe –> e:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe [?]
S4 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S4 Peachtree SmartPosting 2011;Peachtree SmartPosting 2011;e:\programs\Sage\Peachtree\SmartPostingService2011.exe [9/13/2010 7:55 PM 43848]
S4 psqlWGE;Pervasive PSQL Workgroup Engine;c:\program files\Pervasive Software\PSQL\bin\w3dbsmgr.exe [6/6/2008 1:03 PM 435496]
S4 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [12/14/2011 6:47 AM 1514304]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-01-24 16:30 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 22:57]
.
2011-12-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride =
LSP: mswsock.dll
TCP: DhcpNameServer = 10.0.0.1
DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {49EC7987-E331-44E3-B170-748B58A268B9} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
FF - ProfilePath - c:\documents and settings\Patricia\Application Data\Mozilla\Firefox\Profiles\wkqja21d.default\
.
.
——- File Associations ——-
.
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-WRSVC - c:\program files\Webroot\WRSA.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-23 20:45
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(1016)
c:\windows\system32\mswsock.dll
mswsock.dll 71a50000 258048 \\.\globalroot\systemroot\system32\mswsock.dll
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(2676)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
f:\programs\Office\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-12-23 20:47:21 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-24 01:47
.
Pre-Run: 1,033,240,576 bytes free
Post-Run: 1,040,334,848 bytes free
.
- - End Of File - - 258D942832E8D7A13CDC40A38596ABE8
Hi DeViouS,

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: c:\windows\system32\drivers\BNVxEJta.sys
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Repeat this process with the following file: c:\windows\system32\drivers\ubxxitam.sys

Please post the results in your next reply.

===================================================

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    netbt.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Sorry about the format. Let me know if you need the information formatted differently.


c:\windows\system32\drivers\BNVxEJta.sys

Antivirus Version Last Update Result
AhnLab-V3 2011.12.23.00 2011.12.23 -
AntiVir 7.11.19.252 2011.12.23 -
Antiy-AVL 2.0.3.7 2011.12.24 -
Avast 6.0.1289.0 2011.12.23 -
AVG 10.0.0.1190 2011.12.23 -
BitDefender 7.2 2011.12.24 -
ByteHero 1.0.0.1 2011.12.07 -
CAT-QuickHeal 12.00 2011.12.23 -
ClamAV 0.97.3.0 2011.12.24 -
Commtouch 5.3.2.6 2011.12.23 -
Comodo 11068 2011.12.24 -
DrWeb 5.0.2.03300 2011.12.24 -
Emsisoft 5.1.0.11 2011.12.24 -
eSafe 7.0.17.0 2011.12.22 -
eTrust-Vet 37.0.9642 2011.12.23 -
F-Prot 4.6.5.141 2011.12.23 -
F-Secure 9.0.16440.0 2011.12.24 -
Fortinet 4.3.388.0 2011.12.24 -
GData 22 2011.12.24 -
Ikarus T3.1.1.109.0 2011.12.23 -
Jiangmin 13.0.900 2011.12.23 -
K7AntiVirus 9.120.5757 2011.12.23 -
Kaspersky 9.0.0.837 2011.12.24 -
Compact
Prev 1 Next
VirusTotal - Free Online Virus, Malware and URL Scanner http://www.virustotal.com/file-scan/report…b71f98b4122be...
1 of 5 12/23/2011 11:07 PM
Additional information Show all
McAfee 5.400.0.1158 2011.12.24 -
McAfee-GW-Edition 2010.1E 2011.12.23 -
Microsoft 1.7903 2011.12.23 -
NOD32 6738 2011.12.24 -
Norman 6.07.13 2011.12.23 -
nProtect 2011-12-22.01 2011.12.22 -
Panda 10.0.3.5 2011.12.23 -
PCTools 8.0.0.5 2011.12.24 -
Prevx 3.0 2011.12.24 -
Rising 23.89.04.02 2011.12.23 -
Sophos 4.72.0 2011.12.23 -
SUPERAntiSpyware 4.40.0.1006 2011.12.24 -
Symantec 20111.2.0.82 2011.12.24 -
TheHacker 6.7.0.1.362 2011.12.22 -
TrendMicro 9.500.0.1008 2011.12.24 -
TrendMicro-HouseCall 9.500.0.1008 2011.12.24 -
VBA32 3.12.16.4 2011.12.22 -
VIPRE 11295 2011.12.23 -
ViRobot 2011.12.24.4844 2011.12.24 -
VirusBuster 14.1.131.0 2011.12.23 -
MD5 : 74b2b2f5bea5e9a3dc021d685551bd3d
SHA1 : 9d2e1a5fbe165725c366ffadb0b64f400b8cbc1d
SHA256: 7932b71f98b4122be88f576bf6d745a757ae378a48924b7f4358837b75640a82
ssdeep: 3072:jnSpn2UKUlz/h9tgZY0Dv0DzxOpyveIn0C2cJaJFs0r9gkJKqDm+TAnBRjvt:2dKUlbzwA
0C2ckJ4f+iBRjv
File size : 162816 bytes
First seen: 2009-03-25 04:30:16
Last seen : 2011-12-24 03:54:42
TrID:
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher….: Microsoft Corporation
copyright….: © Microsoft Corporation. All rights reserved.
product……: Microsoft_ Windows_ Operating System
description..: MBT Transport driver
original name: netbt.sys
internal name: netbt.sys
file version.: 5.1.2600.5512 (xpsp.080413-0852)
VirusTotal - Free Online Virus, Malware and URL Scanner http://www.virustotal.com/file-scan/report…b71f98b4122be...
2 of 5 12/23/2011 11:07 PM
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x23F85
timedatestamp….: 0x48025D1B (Sun Apr 13 19:20:59 2008)
machinetype……: 0x14c (I386)
[[ 8 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x380, 0x1ACCA, 0x1AD00, 6.53, 814e5d432879088384f90eaf8a7a54ac
.rdata, 0x1B080, 0x35C, 0x380, 4.38, 6d0ebaacf46b926568d00f25e01f9993
.data, 0x1B400, 0x658, 0x680, 0.44, 1931b61397a82a1afd0ac4c3666770be
PAGE, 0x1BA80, 0x7DF6, 0x7E00, 6.46, 6076ed33ca51d29e5fbee153b72883ed
PAGENBT, 0x23880, 0x6C4, 0x700, 6.33, 9cc5efd844632e2f9ba8ac7d5890d3d4
INIT, 0x23F80, 0x1A0A, 0x1A80, 6.05, 9fa43a68c2395b50f016ce7351ce0132
.rsrc, 0x25A00, 0x3E0, 0x400, 3.35, 7c7115325d458f7c85ab72b05f4270fe
.reloc, 0x25E00, 0x1DE0, 0x1E00, 6.78, 5038f4ae584f4e238e840154827fd825
[[ 3 import(s) ]]
HAL.dll: KfReleaseSpinLock, KfLowerIrql, KfRaiseIrql, KeGetCurrentIrql, KfAcquireSpinLock
ntoskrnl.exe: _alldiv, SeDeassignSecurity, RtlFreeOemString,
RtlUpcaseUnicodeStringToOemString, DbgPrint, RtlAnsiStringToUnicodeString,
RtlUnicodeStringToAnsiString, RtlOemStringToUnicodeString, RtlInitString,
MmMapLockedPagesSpecifyCache, RtlAppendStringToString, RtlInitAnsiString, strchr, strncpy,
KeCancelTimer, ZwClose, ZwCancelTimer, ZwSetTimer, ZwCreateTimer, _aulldiv, _allmul,
IofCompleteRequest, IofCallDriver, IoBuildDeviceIoControlRequest, ObfReferenceObject,
IoGetDeviceObjectPointer, RtlInitUnicodeString, KeSetTimer, KeInitializeDpc,
KeInitializeTimer, IoDeleteDevice, KeClearEvent, ExDeleteResourceLite, IoFreeIrp,
IoGetRelatedDeviceObject, ProbeForWrite, _except_handler3, RtlCopyUnicodeString,
DbgBreakPoint, ZwCreateKey, memchr, ZwReadFile, ZwQueryInformationFile, RtlFreeUnicodeString,
ZwCreateFile, IoRemoveShareAccess, SeAssignSecurity, RtlExtendedLargeIntegerDivide,
IoCheckShareAccess, SeAccessCheck, ObReferenceObjectByHandle, NtWaitForSingleObject,
ZwDeviceIoControlFile, ZwCreateEvent, wcslen, ExfInterlockedPushEntryList,
ExRaiseAccessViolation, MmUserProbeAddress, IoFileObjectType, PsGetCurrentThread,
ExQueueWorkItem, KeInsertQueueDpc, IoAllocateIrp, RtlCompareUnicodeString,
RtlAppendUnicodeStringToString, RtlIntegerToUnicodeString, RtlExtendedMagicDivide,
MmBuildMdlForNonPagedPool, IoWriteErrorLogEntry, IoAllocateErrorLogEntry, swprintf, sprintf,
RtlAddAccessAllowedAce, RtlCreateAcl, RtlLengthSid, SeExports, RtlMapGenericMask,
IoGetFileObjectGenericMapping, SeSetSecurityDescriptorInfo, RtlSetDaclSecurityDescriptor,
RtlCreateSecurityDescriptor, IoCreateDevice, RtlAppendUnicodeToString, ZwOpenKey,
ZwQueryValueKey, memmove, IoBuildPartialMdl, MmUnmapLockedPages, KeDelayExecutionThread,
MmLockPagableDataSection, KeTickCount, KeBugCheckEx, IoCancelIrp, IoAllocateMdl,
ExfInterlockedInsertHeadList, PsGetCurrentProcess, KeAttachProcess, KeDetachProcess,
ExfInterlockedInsertTailList, ObfDereferenceObject, IoFreeMdl, KeWaitForSingleObject,
KeResetEvent, KeSetEvent, KeInitializeSpinLock, ExSystemTimeToLocalTime, KeInitializeEvent,
ExInitializeResourceLite, strrchr, RtlCompareMemory, KeQuerySystemTime,
KefReleaseSpinLockFromDpcLevel, KefAcquireSpinLockAtDpcLevel, IoAcquireCancelSpinLock,
IoReleaseCancelSpinLock, KeEnterCriticalRegion, ExAcquireResourceExclusiveLite,
ExReleaseResourceLite, KeLeaveCriticalRegion, strncmp, ExAllocatePoolWithTag,
IoSetShareAccess, ExFreePoolWithTag
TDI.SYS: TdiRegisterNetAddress, TdiProviderReady, TdiInitialize, TdiRegisterProvider,
TdiRegisterPnPHandlers, TdiMapUserRequest, TdiDeregisterPnPHandlers, TdiDeregisterProvider,
TdiRegisterDeviceObject, TdiDefaultDisconnectHandler, TdiDefaultErrorHandler,
TdiDefaultReceiveHandler, TdiDefaultRcvExpeditedHandler, TdiDefaultSendPossibleHandler,
VirusTotal - Free Online Virus, Malware and URL Scanner http://www.virustotal.com/file-scan/report…b71f98b4122be...
3 of 5 12/23/2011 11:07 PM
User:
Reputation:
Comment date:
TdiCopyMdlToBuffer, TdiCopyBufferToMdl, TdiDefaultRcvDatagramHandler, TdiBuildNetbiosAddress,
TdiDeregisterDeviceObject, TdiDeregisterNetAddress, TdiPnPPowerComplete,
TdiEnumerateAddresses, TdiDefaultConnectHandler, TdiPnPPowerRequest
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 150656
CompanyName: Microsoft Corporation
EntryPoint: 0x23f85
FileDescription: MBT Transport driver
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 159 kB
FileSubtype: 7
FileType: Win32 EXE
FileVersion: 5.1.2600.5512 (xpsp.080413-0852)
FileVersionNumber: 5.1.2600.5512
ImageVersion: 5.1
InitializedDataSize: 11264
InternalName: netbt.sys
LanguageCode: English (U.S.)
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 7.1
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 5.1
ObjectFileType: Driver
OriginalFilename: netbt.sys
PEType: PE32
ProductName: Microsoft Windows Operating System
ProductVersion: 5.1.2600.5512
ProductVersionNumber: 5.1.2600.5512
Subsystem: Native
SubsystemVersion: 5.1
TimeStamp: 2008:04:13 21:20:59+02:00
UninitializedDataSize: 0

c:\windows\system32\drivers\ubxxitam.sys

Antivirus Version Last Update Result
AhnLab-V3 2011.12.23.00 2011.12.23 -
AntiVir 7.11.19.252 2011.12.23 -
Antiy-AVL 2.0.3.7 2011.12.24 -
Avast 6.0.1289.0 2011.12.23 -
AVG 10.0.0.1190 2011.12.23 -
BitDefender 7.2 2011.12.24 -
ByteHero 1.0.0.1 2011.12.07 -
CAT-QuickHeal 12.00 2011.12.23 -
ClamAV 0.97.3.0 2011.12.24 -
Commtouch 5.3.2.6 2011.12.23 -
Comodo 11068 2011.12.24 -
DrWeb 5.0.2.03300 2011.12.24 -
Emsisoft 5.1.0.11 2011.12.24 -
eSafe 7.0.17.0 2011.12.22 -
eTrust-Vet 37.0.9642 2011.12.23 -
F-Prot 4.6.5.141 2011.12.23 -
F-Secure 9.0.16440.0 2011.12.24 -
Fortinet 4.3.388.0 2011.12.24 -
GData 22.317/22.600 2011.12.24 -
Ikarus T3.1.1.109.0 2011.12.23 -
Jiangmin 13.0.900 2011.12.23 -
K7AntiVirus 9.120.5757 2011.12.23 -
Kaspersky 9.0.0.837 2011.12.24 -
McAfee 5.400.0.1158 2011.12.24 -
McAfee-GW-Edition 2010.1E 2011.12.23 -
Microsoft 1.7903 2011.12.23 -
NOD32 6738 2011.12.24 -
Norman 6.07.13 2011.12.23 -
nProtect 2011-12-22.01 2011.12.22 -
Panda 10.0.3.5 2011.12.23 -
PCTools 8.0.0.5 2011.12.24 -
Prevx 3.0 2011.12.24 -
Rising 23.89.04.02 2011.12.23 -
Sophos 4.72.0 2011.12.23 -
SUPERAntiSpyware 4.40.0.1006 2011.12.24 -
Symantec 20111.2.0.82 2011.12.24 -
TheHacker 6.7.0.1.362 2011.12.22 -
TrendMicro 9.500.0.1008 2011.12.24 -
TrendMicro-HouseCall 9.500.0.1008 2011.12.24 -
VBA32 3.12.16.4 2011.12.22 -
VIPRE 11295 2011.12.23 -
ViRobot 2011.12.24.4844 2011.12.24 -
VirusBuster 14.1.131.0 2011.12.23 -
Additional information
MD5 : ad48d313e56f4cc7c67a6c0dd9047b03
SHA1 : 11b328e1fe3ea223a93f306df8b0bad1726922bf
SHA256: b2a9aa3d8b41f3a2cb6aa9d689256e4a92af3efecdf2fc99f1b18a1ee50e47e3
ssdeep: 768:VRmmOj5snoEJc+nh9ZnYuQojSwxpMeBHb6FjpvH5:VQ1jOK+n7ZnYNoj7eeR6F5Z
File size : 41680 bytes
First seen: 2011-08-17 11:11:40
Last seen : 2011-12-24 04:02:23
TrID:
Clipper DOS Executable (33.3%)
Generic Win/DOS Executable (33.0%)
DOS Executable Generic (33.0%)
VXD Driver (0.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher….: Microsoft Corporation
copyright….: © Microsoft Corporation. All rights reserved.
product……: Microsoft Malware Protection
description..: Boot Time Removal Tool
original name: BTR.sys
internal name: BootTimeRemoval
file version.: 1.1.0006.0
comments…..: n/a
signers……: Microsoft Corporation
Microsoft Code Signing PCA
Microsoft Root Authority
signing date.: 6:49 28/07/2011
verified…..: -
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x80D2
timedatestamp….: 0x4E30F0F5 (Thu Jul 28 05:17:41 2011)
machinetype……: 0x14c (I386)

[[ 7 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x480, 0x484A, 0x4880, 5.71, 2a5cd1f979ff3a1bd54feeee463f3062
.rdata, 0x4D00, 0x2DF8, 0x2E00, 7.65, 5cd30f5a30467e8799b4538eed1ee055
.data, 0x7B00, 0x2F0, 0x300, 1.19, 25192538aa56ec4750d33c96f333529f
PAGER32C, 0x7E00, 0x23C, 0x280, 5.49, cdce2be2e2566bedd7d01ed0a7a0452a
INIT, 0x8080, 0x2CC, 0x300, 5.48, 3450fd9c80c0364f00e485d94e7d9519
.rsrc, 0x8380, 0x3A8, 0x400, 3.04, 2d452d1fdd9228bf0791e8a33d0ef323
.reloc, 0x8780, 0x3A8, 0x400, 5.28, ce333d69ae8ea045e098268209efc163

[[ 1 import(s) ]]
ntoskrnl.exe: RtlInitUnicodeString, ZwOpenKey, ZwDeleteKey, NtClose, ZwDeleteValueKey, ZwCreateKey, ZwSetValueKey, ZwQueryValueKey, _vsnwprintf, NtCreateFile, NtOpenFile, NtReadFile, NtWriteFile, NtQueryInformationFile, NtSetInformationFile, ZwDeleteFile, ZwClose, ExAllocatePoolWithTag, ExFreePoolWithTag, KeTickCount, KeBugCheckEx
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 19968
CompanyName: Microsoft Corporation
EntryPoint: 0x80d2
FileDescription: Boot Time Removal Tool
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 41 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 1.1.0006.0
FileVersionNumber: 1.1.6.0
ImageVersion: 6.2
InitializedDataSize: 14592
InternalName: BootTimeRemoval
LanguageCode: English (U.S.)
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 10.1
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 6.2
ObjectFileType: Executable application
OriginalFilename: BTR.sys
PEType: PE32
ProductName: Microsoft Malware Protection
ProductVersion: 1.1.0006.0
ProductVersionNumber: 1.1.6.0
Subsystem: Native
SubsystemVersion: 5.0
TimeStamp: 2011:07:28 07:17:41+02:00
UninitializedDataSize: 0

SystemLook 30.07.11 by jpshortstuff
Log created at 23:14 on 23/12/2011 by Patricia
Administrator - Elevation successful

No Context: CODE

========== filefind ==========

Searching for "netbt.sys"
C:\WINDOWS\ServicePackFiles\i386\netbt.sys ——- 162816 bytes [19:21 13/04/2008] [19:21 13/04/2008] 74B2B2F5BEA5E9A3DC021D685551BD3D
C:\WINDOWS\system32\dllcache\netbt.sys –a—- 162816 bytes [04:14 04/08/2004] [19:21 13/04/2008] 74B2B2F5BEA5E9A3DC021D685551BD3D
C:\WINDOWS\system32\drivers\netbt.sys –a—- 162816 bytes [04:14 04/08/2004] [19:21 13/04/2008] 74B2B2F5BEA5E9A3DC021D685551BD3D

-= EOF =-
Sure Here's the log, I updated the virus definitions as well. aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-23 09:54:49 —————————– 09:54:49.732 OS Version: Windows 5.1.2600 Service Pack 3 09:54:49.732 Number of processors: 2 586 0x170A 09:54:49.732 ComputerName: THE-BEAST UserName: Patricia 09:54:50.123 Initialize success 09:55:35.654 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 09:55:35.654 Disk 0 Vendor: SAMSUNG_SP0802N TK100-23 Size: 76350MB BusType: 3 09:55:35.654 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T1L0-19 09:55:35.654 Disk 1 Vendor: WDC_WD3200AAKS-00B3A0 01.03A01 Size: 305244MB BusType: 3 09:55:37.654 Disk 1 MBR read successfully 09:55:37.654 Disk 1 MBR scan 09:55:37.654 Disk 1 Windows XP default MBR code 09:55:37.654 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 12001 MB offset 63 09:55:37.654 Disk 0 Partition - 00 0F Extended LBA 119059 MB offset 24579450 09:55:37.685 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 174181 MB offset 268414020 09:55:37.701 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 119059 MB offset 24579513 09:55:37.701 Disk 1 scanning sectors +625137345 09:55:37.763 Disk 1 scanning C:\WINDOWS\system32\drivers 09:55:45.357 File: C:\WINDOWS\system32\drivers\netbt.sys **SUSPICIOUS** 09:55:48.966 Service scanning 09:55:49.451 Service MpKsl432b342d C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{06C695D0-FB47-4A3A-B93B-226642FBF3E5}\MpKsl432b342d.sys **LOCKED** 32 09:55:49.576 Service WRkrn C:\WINDOWS\System32\drivers\WRkrn.sys **LOCKED** 32 09:55:50.076 Modules scanning 09:55:52.669 Module: C:\WINDOWS\system32\DRIVERS\netbt.sys **SUSPICIOUS** 09:55:53.779 Disk 1 trace - called modules: 09:55:53.794 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a4c5f10]<< 09:55:53.794 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8b218ab8] 09:55:53.794 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> [0x8a778e10] 09:55:53.794 \Driver\00000772[0x8b0ae5a0] -> IRP_MJ_CREATE -> 0x8a4c5f10 09:55:53.794 Scan finished successfully 09:56:08.748 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\Patricia\Desktop\MBR.dat" 09:56:08.763 The log file has been saved successfully to "C:\Documents and Settings\Patricia\Desktop\aswMBR.txt" aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-24 00:06:39 —————————– 00:06:39.937 OS Version: Windows 5.1.2600 Service Pack 3 00:06:39.937 Number of processors: 2 586 0x170A 00:06:39.937 ComputerName: THE-BEAST UserName: Patricia 00:06:40.171 Initialize success 00:12:09.781 AVAST engine defs: 11122301 00:12:18.171 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 00:12:18.171 Disk 0 Vendor: SAMSUNG_SP0802N TK100-23 Size: 76350MB BusType: 3 00:12:18.171 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T1L0-19 00:12:18.171 Disk 1 Vendor: WDC_WD3200AAKS-00B3A0 01.03A01 Size: 305244MB BusType: 3 00:12:20.187 Disk 1 MBR read successfully 00:12:20.187 Disk 1 MBR scan 00:12:20.203 Disk 1 Windows XP default MBR code 00:12:20.203 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 12001 MB offset 63 00:12:20.203 Disk 0 Partition - 00 0F Extended LBA 119059 MB offset 24579450 00:12:20.218 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 174181 MB offset 268414020 00:12:20.234 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 119059 MB offset 24579513 00:12:20.234 Disk 1 scanning sectors +625137345 00:12:20.296 Disk 1 scanning C:\WINDOWS\system32\drivers 00:12:26.671 File: C:\WINDOWS\system32\drivers\netbt.sys **INFECTED** Win32:Aluroot [Rtk] 00:12:28.265 File: C:\WINDOWS\system32\drivers\tkGBMHJb.sys **INFECTED** Win32:Aluroot [Rtk] 00:12:29.218 Service scanning 00:12:30.000 Modules scanning 00:12:31.312 Module: C:\WINDOWS\system32\DRIVERS\netbt.sys **SUSPICIOUS** 00:12:32.531 Disk 1 trace - called modules: 00:12:32.546 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a6b8f10]<< 00:12:32.546 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8b3e5ab8] 00:12:32.546 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> [0x8a6ee6d0] 00:12:32.546 \Driver\00000692[0x8a8adaa0] -> IRP_MJ_CREATE -> 0x8a6b8f10 00:12:32.875 AVAST engine scan C:\WINDOWS 00:12:36.078 AVAST engine scan C:\WINDOWS\system32 00:13:30.828 AVAST engine scan C:\WINDOWS\system32\drivers 00:13:37.453 File: C:\WINDOWS\system32\drivers\netbt.sys **INFECTED** Win32:Aluroot [Rtk] 00:13:39.203 File: C:\WINDOWS\system32\drivers\tkGBMHJb.sys **INFECTED** Win32:Aluroot [Rtk] 00:13:40.625 AVAST engine scan C:\Documents and Settings\Patricia 00:14:03.531 AVAST engine scan C:\Documents and Settings\All Users 00:16:37.593 Scan finished successfully 00:17:30.953 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\Patricia\Desktop\MBR.dat" 00:17:30.953 The log file has been saved successfully to "C:\Documents and Settings\Patricia\Desktop\aswMBR.txt"
Hi DeViouS,

Please delete ComboFix from your desktop and download a fresh copy from one of the two links below:
Link 1
Link 2

Run ComboFix again and post the log.
Here's the log from combo fix.

ComboFix 11-12-23.01 - Patricia 12/24/2011 0:56.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2015 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))
.
.
2011-12-24 04:08 . 2011-12-24 04:12 ——– d—–w- c:\documents and settings\Patricia\Local Settings\Application Data\CutePDF Writer
2011-12-23 23:29 . 2011-12-23 23:29 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\MpKslf1e23d93.sys
2011-12-23 23:27 . 2011-12-23 23:27 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\MpKsl93a3f44a.sys
2011-12-23 14:59 . 2011-11-21 07:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\mpengine.dll
2011-12-22 14:30 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\BNVxEJta.sys
2011-12-20 13:58 . 2011-12-14 11:46 28992 —-a-w- c:\windows\system32\uxtuneup.dll
2011-12-20 13:34 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\BineenXt.sys
2011-12-20 01:31 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\srvlnASy.sys
2011-12-19 04:27 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\xocVqFMR.sys
2011-12-19 04:27 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\odcgeLCR.sys
2011-12-19 00:33 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\VGlxxmhq.sys
2011-12-18 21:17 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\tftUsCuh.sys
2011-12-18 21:12 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\UtNACVPB.sys
2011-12-18 20:58 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\tkGBMHJb.sys
2011-12-16 00:24 . 2011-12-16 00:24 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-12-11 15:35 . 2011-12-11 15:35 ——– d—–w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2011-12-10 15:09 . 2011-12-10 15:09 ——– d—–w- c:\program files\Common Files\DivX Shared
2011-12-05 10:18 . 2011-12-11 11:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-12-04 15:31 . 2011-12-14 11:47 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2011-12-04 15:30 . 2011-12-04 15:30 ——– d—–w- c:\documents and settings\Patricia\Application Data\TuneUp Software
2011-12-04 15:30 . 2011-12-20 13:59 ——– d—–w- c:\program files\TuneUp Utilities 2012
2011-12-04 15:29 . 2011-12-04 15:31 ——– d—–w- c:\documents and settings\All Users\Application Data\TuneUp Software
2011-12-04 15:28 . 2011-12-04 15:28 ——– d-sh–w- c:\documents and settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-12-04 14:11 . 2011-12-04 14:11 41680 —-a-w- c:\windows\system32\drivers\ubxxitam.sys
2011-12-03 22:05 . 2011-12-03 22:05 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-03 19:49 . 2011-12-03 19:49 ——– d—–w- c:\documents and settings\Patricia\Application Data\Malwarebytes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-23 23:48 . 2010-04-27 03:49 16608 —-a-w- c:\windows\gdrv.sys
2011-11-23 13:25 . 2004-08-04 04:17 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 07:47 . 2011-09-19 13:26 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-01 16:07 . 2004-08-04 05:56 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-04 05:56 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-04 04:18 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 19:29 . 2011-10-24 19:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29 . 2011-10-24 19:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-23 17:08 . 2011-06-02 03:07 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 11:13 . 2004-08-04 05:56 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2010-04-26 06:53 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 05:56 599040 -c–a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-30 00:59 611328 -c–a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2001-08-23 12:00 220160 -c–a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2001-08-23 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...r=9.0.872" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 04:07 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 ——r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 08:42 2808832 ——r- c:\windows\alcwzrd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-09-27 12:22 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Core Temp]
2011-09-02 04:29 722384 —-a-w- c:\program files\Core Temp\Core Temp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GEST]
2007-12-14 18:46 236040 —-a-w- c:\program files\GIGABYTE\GEST\run.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2008-02-18 18:36 1057064 —-a-w- e:\program files\Nero\Nero 7\InCD\InCD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-01-24 16:32 2289664 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 19:16 997920 -c–a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-02-27 17:03 570664 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-04-04 02:23 13670504 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-04-04 02:23 110696 —-a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeachtreePrefetcher.exe]
2011-02-22 00:05 29512 —-a-r- e:\programs\Sage\Peachtree\PeachtreePrefetcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-06-27 03:23 16875008 ——w- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
2008-02-18 18:36 1629480 —-a-w- e:\program files\Nero\Nero 7\InCD\NBHGui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ——w- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WRSVC"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"UxTuneUp"=2 (0x2)
"TuneUp.UtilitiesSvc"=2 (0x2)
"psqlWGE"=2 (0x2)
"Peachtree SmartPosting 2011"=2 (0x2)
"osppsvc"=3 (0x3)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NeroRegInCDSrv"=2 (0x2)
"NBService"=3 (0x3)
"MsMpSvc"=2 (0x2)
"McciCMService"=2 (0x2)
"LightScribeService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"InCDsrv"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"GEST Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\Programs\\BitTorrent\\bittorrent.exe"=
"e:\\Program Files\\StarCraft II Beta\\StarCraft II.exe"=
"c:\\Program Files\\Adobe\\Acrobat_com\\Acrobat_com.exe"=
"e:\\Program Files\\StarCraft II\\StarCraft II.exe"=
"e:\\Program Files\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
"c:\\Documents and Settings\\DeViouS\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"e:\\Program Files\\PFPortChecker\\PFPortChecker.exe"=
"f:\\Programs\\Office\\Office14\\GROOVE.EXE"=
"f:\\Programs\\Office\\Office14\\ONENOTE.EXE"=
"f:\\Programs\\Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Pervasive Software\\PSQL\\bin\\w3dbsmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"e:\\Program Files\\StarCraft II\\Versions\\Base18092\\SC2.exe"=
"f:\\Programs\\XBMC\\XBMC.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"1583:TCP"= 1583:TCP:Pervasive DBEngine
"3351:TCP"= 3351:TCP:Pervasive DBEngine
.
R1 MpKslf1e23d93;MpKslf1e23d93;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\MpKslf1e23d93.sys [12/23/2011 6:29 PM 29904]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [6/11/2010 2:02 PM 35448]
S1 MpKsl05309e57;MpKsl05309e57;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C584BAA6-E20E-44BE-9141-61D6417B9B42}\MpKsl05309e57.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C584BAA6-E20E-44BE-9141-61D6417B9B42}\MpKsl05309e57.sys [?]
S1 MpKsl2714a0e1;MpKsl2714a0e1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDBB7FC4-3C2A-4E0B-80AD-4E490922CEE0}\MpKsl2714a0e1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDBB7FC4-3C2A-4E0B-80AD-4E490922CEE0}\MpKsl2714a0e1.sys [?]
S1 MpKsl2f23e610;MpKsl2f23e610;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKsl2f23e610.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKsl2f23e610.sys [?]
S1 MpKsl354afefd;MpKsl354afefd;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01751214-B360-4F2B-A0F5-14A514A2D6ED}\MpKsl354afefd.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01751214-B360-4F2B-A0F5-14A514A2D6ED}\MpKsl354afefd.sys [?]
S1 MpKsl6d86a591;MpKsl6d86a591;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32AA8DF5-FBC5-4DB8-A871-71FEADDE419F}\MpKsl6d86a591.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32AA8DF5-FBC5-4DB8-A871-71FEADDE419F}\MpKsl6d86a591.sys [?]
S1 MpKsl7990e691;MpKsl7990e691;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{803F0683-2921-4BA4-B339-847EB250CEB5}\MpKsl7990e691.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{803F0683-2921-4BA4-B339-847EB250CEB5}\MpKsl7990e691.sys [?]
S1 MpKsl836b7f90;MpKsl836b7f90;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29D607B1-73F8-4C69-B41D-CC62685AB812}\MpKsl836b7f90.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29D607B1-73F8-4C69-B41D-CC62685AB812}\MpKsl836b7f90.sys [?]
S1 MpKsl88e6af3b;MpKsl88e6af3b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E8C76270-AC80-4A45-9ACE-65C7AF84BC87}\MpKsl88e6af3b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E8C76270-AC80-4A45-9ACE-65C7AF84BC87}\MpKsl88e6af3b.sys [?]
S1 MpKsl944debed;MpKsl944debed;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4DBB258C-2BDE-43D7-9CAA-61BA55584DA1}\MpKsl944debed.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4DBB258C-2BDE-43D7-9CAA-61BA55584DA1}\MpKsl944debed.sys [?]
S1 MpKsl99c0f781;MpKsl99c0f781;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F8AF1B56-0C99-4AC0-B79F-FB5D0C0C8140}\MpKsl99c0f781.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F8AF1B56-0C99-4AC0-B79F-FB5D0C0C8140}\MpKsl99c0f781.sys [?]
S1 MpKsl9ed29e84;MpKsl9ed29e84;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FD73EE98-D8CA-4DB1-B49A-189292D885AF}\MpKsl9ed29e84.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FD73EE98-D8CA-4DB1-B49A-189292D885AF}\MpKsl9ed29e84.sys [?]
S1 MpKslaae793a0;MpKslaae793a0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKslaae793a0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKslaae793a0.sys [?]
S1 MpKslcbd862da;MpKslcbd862da;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042CAF0A-EA2F-4642-BD5C-D436C09B9ADD}\MpKslcbd862da.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042CAF0A-EA2F-4642-BD5C-D436C09B9ADD}\MpKslcbd862da.sys [?]
S1 MpKslce097d11;MpKslce097d11;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A1B535F4-7BF2-4167-8573-7720AA6F42D6}\MpKslce097d11.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A1B535F4-7BF2-4167-8573-7720AA6F42D6}\MpKslce097d11.sys [?]
S1 MpKsld45cf3e6;MpKsld45cf3e6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB8B7EBC-2B9E-4937-8142-4BE51F0EBF69}\MpKsld45cf3e6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB8B7EBC-2B9E-4937-8142-4BE51F0EBF69}\MpKsld45cf3e6.sys [?]
S1 MpKsldaa75e46;MpKsldaa75e46;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F17962E0-8376-4980-9AD4-622C9950922F}\MpKsldaa75e46.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F17962E0-8376-4980-9AD4-622C9950922F}\MpKsldaa75e46.sys [?]
S1 MpKsle7be0667;MpKsle7be0667;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17C6ADC8-1EE4-4A18-BCE9-821F136857ED}\MpKsle7be0667.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17C6ADC8-1EE4-4A18-BCE9-821F136857ED}\MpKsle7be0667.sys [?]
S1 MpKslecb2ba95;MpKslecb2ba95;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB483246-1CD6-4DB2-896F-12372FF095CF}\MpKslecb2ba95.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB483246-1CD6-4DB2-896F-12372FF095CF}\MpKslecb2ba95.sys [?]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\Patricia\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\Patricia\LOCALS~1\Temp\ALSysIO.sys [?]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys –> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [12/12/2010 9:31 AM 10744]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [4/17/2011 1:33 PM 22216]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;f:\programs\Office\Office14\GROOVE.EXE [6/12/2011 10:15 AM 31125880]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [11/8/2011 9:25 PM 10064]
S4 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [4/26/2010 10:50 PM 47624]
S4 MBAMService;MBAMService;f:\programs\Malwarebytes' Anti-Malware\mbamservice.exe [4/17/2011 1:33 PM 366152]
S4 NeroRegInCDSrv;Nero Registry InCD Service;e:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe –> e:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe [?]
S4 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S4 Peachtree SmartPosting 2011;Peachtree SmartPosting 2011;e:\programs\Sage\Peachtree\SmartPostingService2011.exe [9/13/2010 7:55 PM 43848]
S4 psqlWGE;Pervasive PSQL Workgroup Engine;c:\program files\Pervasive Software\PSQL\bin\w3dbsmgr.exe [6/6/2008 1:03 PM 435496]
S4 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [12/14/2011 6:47 AM 1514304]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - aswMBR
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-01-24 16:30 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 22:57]
.
2011-12-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 10.0.0.1
DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {49EC7987-E331-44E3-B170-748B58A268B9} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
FF - ProfilePath - c:\documents and settings\Patricia\Application Data\Mozilla\Firefox\Profiles\wkqja21d.default\
.
.
——- File Associations ——-
.
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-24 00:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(1016)
c:\windows\system32\mswsock.dll
mswsock.dll 71a50000 258048 \\.\globalroot\systemroot\system32\mswsock.dll
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1872)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
f:\programs\Office\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-24 00:59:56
ComboFix-quarantined-files.txt 2011-12-24 05:59
ComboFix2.txt 2011-12-24 01:47
.
Pre-Run: 505,425,920 bytes free
Post-Run: 968,822,784 bytes free
.
- - End Of File - - 727114DD7BBA7F6B913A05DBD5C6987E
Hi DeViouS,

Sorry for the late reply. The developer of ComboFix just updated it to include some of the suspicious files we are seeing in your logs, so I'd like you to delete your copy of ComboFix from your desktop one last time and download a fresh copy from here. Please run it, then post the logs.
Take your time, thanks for help me!! Here's the log:

ComboFix 11-12-24.05 - Patricia 12/24/2011 14:02:46.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2540 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))
.
.
2011-12-24 04:08 . 2011-12-24 04:12 ——– d—–w- c:\documents and settings\Patricia\Local Settings\Application Data\CutePDF Writer
2011-12-23 23:27 . 2011-12-23 23:27 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\MpKsl93a3f44a.sys
2011-12-23 14:59 . 2011-11-21 07:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C05FD28C-9EBF-43FD-B316-CE4DCE91D915}\mpengine.dll
2011-12-22 14:30 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\BNVxEJta.sys
2011-12-20 13:58 . 2011-12-14 11:46 28992 —-a-w- c:\windows\system32\uxtuneup.dll
2011-12-20 13:34 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\BineenXt.sys
2011-12-20 01:31 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\srvlnASy.sys
2011-12-19 04:27 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\xocVqFMR.sys
2011-12-19 04:27 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\odcgeLCR.sys
2011-12-19 00:33 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\VGlxxmhq.sys
2011-12-18 21:17 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\tftUsCuh.sys
2011-12-18 21:12 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\UtNACVPB.sys
2011-12-18 20:58 . 2008-04-13 19:21 162816 —-a-w- c:\windows\system32\drivers\tkGBMHJb.sys
2011-12-16 00:24 . 2011-12-16 00:24 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-12-11 15:35 . 2011-12-11 15:35 ——– d—–w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2011-12-10 15:09 . 2011-12-10 15:09 ——– d—–w- c:\program files\Common Files\DivX Shared
2011-12-05 10:18 . 2011-12-11 11:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-12-04 15:31 . 2011-12-14 11:47 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2011-12-04 15:30 . 2011-12-04 15:30 ——– d—–w- c:\documents and settings\Patricia\Application Data\TuneUp Software
2011-12-04 15:30 . 2011-12-20 13:59 ——– d—–w- c:\program files\TuneUp Utilities 2012
2011-12-04 15:29 . 2011-12-04 15:31 ——– d—–w- c:\documents and settings\All Users\Application Data\TuneUp Software
2011-12-04 15:28 . 2011-12-04 15:28 ——– d-sh–w- c:\documents and settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-12-04 14:11 . 2011-12-04 14:11 41680 —-a-w- c:\windows\system32\drivers\ubxxitam.sys
2011-12-03 22:05 . 2011-12-03 22:05 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-03 19:49 . 2011-12-03 19:49 ——– d—–w- c:\documents and settings\Patricia\Application Data\Malwarebytes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-23 23:48 . 2010-04-27 03:49 16608 —-a-w- c:\windows\gdrv.sys
2011-11-23 13:25 . 2004-08-04 04:17 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 07:47 . 2011-09-19 13:26 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-01 16:07 . 2004-08-04 05:56 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-04 05:56 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-04 04:18 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 19:29 . 2011-10-24 19:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29 . 2011-10-24 19:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-23 17:08 . 2011-06-02 03:07 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 11:13 . 2004-08-04 05:56 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2010-04-26 06:53 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 05:56 599040 -c–a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-30 00:59 611328 -c–a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2001-08-23 12:00 220160 -c–a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2001-08-23 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-24_01.45.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-03 22:07 . 2011-12-24 18:40 223744 c:\windows\$NtUninstallKB10581$\383139715\kwrd.dll
- 2011-12-03 22:07 . 2011-12-24 01:44 223744 c:\windows\$NtUninstallKB10581$\383139715\kwrd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...r=9.0.872" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 04:07 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 ——r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 08:42 2808832 ——r- c:\windows\alcwzrd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-09-27 12:22 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Core Temp]
2011-09-02 04:29 722384 —-a-w- c:\program files\Core Temp\Core Temp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GEST]
2007-12-14 18:46 236040 —-a-w- c:\program files\GIGABYTE\GEST\run.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2008-02-18 18:36 1057064 —-a-w- e:\program files\Nero\Nero 7\InCD\InCD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-01-24 16:32 2289664 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 19:16 997920 -c–a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-02-27 17:03 570664 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-04-04 02:23 13670504 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-04-04 02:23 110696 —-a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeachtreePrefetcher.exe]
2011-02-22 00:05 29512 —-a-r- e:\programs\Sage\Peachtree\PeachtreePrefetcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-06-27 03:23 16875008 ——w- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
2008-02-18 18:36 1629480 —-a-w- e:\program files\Nero\Nero 7\InCD\NBHGui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ——w- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WRSVC"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"UxTuneUp"=2 (0x2)
"TuneUp.UtilitiesSvc"=2 (0x2)
"psqlWGE"=2 (0x2)
"Peachtree SmartPosting 2011"=2 (0x2)
"osppsvc"=3 (0x3)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NeroRegInCDSrv"=2 (0x2)
"NBService"=3 (0x3)
"MsMpSvc"=2 (0x2)
"McciCMService"=2 (0x2)
"LightScribeService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"InCDsrv"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"GEST Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\Programs\\BitTorrent\\bittorrent.exe"=
"e:\\Program Files\\StarCraft II Beta\\StarCraft II.exe"=
"c:\\Program Files\\Adobe\\Acrobat_com\\Acrobat_com.exe"=
"e:\\Program Files\\StarCraft II\\StarCraft II.exe"=
"e:\\Program Files\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
"c:\\Documents and Settings\\DeViouS\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"e:\\Program Files\\PFPortChecker\\PFPortChecker.exe"=
"f:\\Programs\\Office\\Office14\\GROOVE.EXE"=
"f:\\Programs\\Office\\Office14\\ONENOTE.EXE"=
"f:\\Programs\\Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Pervasive Software\\PSQL\\bin\\w3dbsmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"e:\\Program Files\\StarCraft II\\Versions\\Base18092\\SC2.exe"=
"f:\\Programs\\XBMC\\XBMC.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"1583:TCP"= 1583:TCP:Pervasive DBEngine
"3351:TCP"= 3351:TCP:Pervasive DBEngine
.
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [6/11/2010 2:02 PM 35448]
S1 MpKsl05309e57;MpKsl05309e57;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C584BAA6-E20E-44BE-9141-61D6417B9B42}\MpKsl05309e57.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C584BAA6-E20E-44BE-9141-61D6417B9B42}\MpKsl05309e57.sys [?]
S1 MpKsl2714a0e1;MpKsl2714a0e1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDBB7FC4-3C2A-4E0B-80AD-4E490922CEE0}\MpKsl2714a0e1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BDBB7FC4-3C2A-4E0B-80AD-4E490922CEE0}\MpKsl2714a0e1.sys [?]
S1 MpKsl2f23e610;MpKsl2f23e610;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKsl2f23e610.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKsl2f23e610.sys [?]
S1 MpKsl354afefd;MpKsl354afefd;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01751214-B360-4F2B-A0F5-14A514A2D6ED}\MpKsl354afefd.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01751214-B360-4F2B-A0F5-14A514A2D6ED}\MpKsl354afefd.sys [?]
S1 MpKsl6d86a591;MpKsl6d86a591;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32AA8DF5-FBC5-4DB8-A871-71FEADDE419F}\MpKsl6d86a591.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32AA8DF5-FBC5-4DB8-A871-71FEADDE419F}\MpKsl6d86a591.sys [?]
S1 MpKsl7990e691;MpKsl7990e691;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{803F0683-2921-4BA4-B339-847EB250CEB5}\MpKsl7990e691.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{803F0683-2921-4BA4-B339-847EB250CEB5}\MpKsl7990e691.sys [?]
S1 MpKsl836b7f90;MpKsl836b7f90;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29D607B1-73F8-4C69-B41D-CC62685AB812}\MpKsl836b7f90.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29D607B1-73F8-4C69-B41D-CC62685AB812}\MpKsl836b7f90.sys [?]
S1 MpKsl88e6af3b;MpKsl88e6af3b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E8C76270-AC80-4A45-9ACE-65C7AF84BC87}\MpKsl88e6af3b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E8C76270-AC80-4A45-9ACE-65C7AF84BC87}\MpKsl88e6af3b.sys [?]
S1 MpKsl944debed;MpKsl944debed;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4DBB258C-2BDE-43D7-9CAA-61BA55584DA1}\MpKsl944debed.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4DBB258C-2BDE-43D7-9CAA-61BA55584DA1}\MpKsl944debed.sys [?]
S1 MpKsl99c0f781;MpKsl99c0f781;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F8AF1B56-0C99-4AC0-B79F-FB5D0C0C8140}\MpKsl99c0f781.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F8AF1B56-0C99-4AC0-B79F-FB5D0C0C8140}\MpKsl99c0f781.sys [?]
S1 MpKsl9ed29e84;MpKsl9ed29e84;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FD73EE98-D8CA-4DB1-B49A-189292D885AF}\MpKsl9ed29e84.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FD73EE98-D8CA-4DB1-B49A-189292D885AF}\MpKsl9ed29e84.sys [?]
S1 MpKslaae793a0;MpKslaae793a0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKslaae793a0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F58CEBD7-EACF-4D02-9D28-00E891847310}\MpKslaae793a0.sys [?]
S1 MpKslcbd862da;MpKslcbd862da;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042CAF0A-EA2F-4642-BD5C-D436C09B9ADD}\MpKslcbd862da.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{042CAF0A-EA2F-4642-BD5C-D436C09B9ADD}\MpKslcbd862da.sys [?]
S1 MpKslce097d11;MpKslce097d11;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A1B535F4-7BF2-4167-8573-7720AA6F42D6}\MpKslce097d11.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A1B535F4-7BF2-4167-8573-7720AA6F42D6}\MpKslce097d11.sys [?]
S1 MpKsld45cf3e6;MpKsld45cf3e6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB8B7EBC-2B9E-4937-8142-4BE51F0EBF69}\MpKsld45cf3e6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB8B7EBC-2B9E-4937-8142-4BE51F0EBF69}\MpKsld45cf3e6.sys [?]
S1 MpKsldaa75e46;MpKsldaa75e46;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F17962E0-8376-4980-9AD4-622C9950922F}\MpKsldaa75e46.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F17962E0-8376-4980-9AD4-622C9950922F}\MpKsldaa75e46.sys [?]
S1 MpKsle7be0667;MpKsle7be0667;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17C6ADC8-1EE4-4A18-BCE9-821F136857ED}\MpKsle7be0667.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17C6ADC8-1EE4-4A18-BCE9-821F136857ED}\MpKsle7be0667.sys [?]
S1 MpKslecb2ba95;MpKslecb2ba95;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB483246-1CD6-4DB2-896F-12372FF095CF}\MpKslecb2ba95.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB483246-1CD6-4DB2-896F-12372FF095CF}\MpKslecb2ba95.sys [?]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys –> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [12/12/2010 9:31 AM 10744]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [4/17/2011 1:33 PM 22216]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;f:\programs\Office\Office14\GROOVE.EXE [6/12/2011 10:15 AM 31125880]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [11/8/2011 9:25 PM 10064]
S4 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [4/26/2010 10:50 PM 47624]
S4 MBAMService;MBAMService;f:\programs\Malwarebytes' Anti-Malware\mbamservice.exe [4/17/2011 1:33 PM 366152]
S4 NeroRegInCDSrv;Nero Registry InCD Service;e:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe –> e:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe [?]
S4 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S4 Peachtree SmartPosting 2011;Peachtree SmartPosting 2011;e:\programs\Sage\Peachtree\SmartPostingService2011.exe [9/13/2010 7:55 PM 43848]
S4 psqlWGE;Pervasive PSQL Workgroup Engine;c:\program files\Pervasive Software\PSQL\bin\w3dbsmgr.exe [6/6/2008 1:03 PM 435496]
S4 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [12/14/2011 6:47 AM 1514304]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-01-24 16:30 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 22:57]
.
2011-12-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 10.0.0.1
DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {49EC7987-E331-44E3-B170-748B58A268B9} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
FF - ProfilePath - c:\documents and settings\Patricia\Application Data\Mozilla\Firefox\Profiles\wkqja21d.default\
.
.
——- File Associations ——-
.
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-24 14:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(1060)
c:\windows\system32\mswsock.dll
mswsock.dll 71a50000 258048 \\.\globalroot\systemroot\system32\mswsock.dll
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(2284)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
f:\programs\Office\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-24 14:08:26
ComboFix-quarantined-files.txt 2011-12-24 19:08
ComboFix2.txt 2011-12-24 05:59
ComboFix3.txt 2011-12-24 01:47
.
Pre-Run: 516,902,912 bytes free
Post-Run: 838,426,624 bytes free
.
- - End Of File - - 4C488B2A252854DB80B1D16326F8D8E6
Hi DeViouS,

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/index.php?showtopic=121671&st=0&gopid=764822&#entry764822

Collect::
c:\windows\system32\drivers\BNVxEJta.sys
c:\windows\system32\drivers\BineenXt.sys
c:\windows\system32\drivers\srvlnASy.sys
c:\windows\system32\drivers\xocVqFMR.sys
c:\windows\system32\drivers\odcgeLCR.sys
c:\windows\system32\drivers\VGlxxmhq.sys
c:\windows\system32\drivers\tftUsCuh.sys
c:\windows\system32\drivers\UtNACVPB.sys
c:\windows\system32\drivers\tkGBMHJb.sys
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI