This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Firefox proxy settings keep changing. [Solved]

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:51:23 PM, on 1/3/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINNT\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1199318644546
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: opnlMdBU - Invalid registry found
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\System32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 5496 bytes
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back shortly with a response.
Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")

Please disable any real-time anti-virus, anti-spyware, etc. programs before carrying out a fix as they may interfere.

  • aswMBR

    • Please download aswMBR.exe and save it to your desktop.
    • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
    • When prompted to download virus definitions, please do so.
    • Click Scan. Note: Do NOT attempt any Fix yet.
    • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • OTL

    Download OTL by OldTimer to your Desktop.

    If you already have a copy of OTL, delete it and use this version.

    • Launch OTL.exe.
    • Check the following.
    • Scan all users.
    • Standard Output.
    • Lop check.
    • Purity check.
  • Under Extra Registry section, select Use SafeList
  • Click the Run Scan button and wait for the scan to finish (usually about 10-15 minutes).
  • When finished it will produce two logs.
    • OTL.txt (open on your desktop)
    • Extras.txt (minimized in your taskbar)
  • Please post me both logs.

Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")

Please disable any real-time anti-virus, anti-spyware, etc. programs before carrying out a fix as they may interfere.

  • aswMBR

    • Please download aswMBR.exe and save it to your desktop.
    • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
    • When prompted to download virus definitions, please do so.
    • Click Scan. Note: Do NOT attempt any Fix yet.
    • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • OTL

    Download OTL by OldTimer to your Desktop.

    If you already have a copy of OTL, delete it and use this version.

    • Launch OTL.exe.
    • Check the following.
    • Scan all users.
    • Standard Output.
    • Lop check.
    • Purity check.
  • Under Extra Registry section, select Use SafeList
  • Click the Run Scan button and wait for the scan to finish (usually about 10-15 minutes).
  • When finished it will produce two logs.
    • OTL.txt (open on your desktop)
    • Extras.txt (minimized in your taskbar)
  • Please post me both logs.


this says for "Vista and Windows 7 users". i use windows xp.
Hi WyandotteWyno, Don't worry about the instructions for Vista and 7 users - just go ahead and run the programs as you would any other by double-clicking them. ;)
aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-09 03:18:20
—————————–
03:18:20.038 OS Version: Windows 5.1.2600 Service Pack 3
03:18:20.038 Number of processors: 1 586 0x209
03:18:20.038 ComputerName: YOUR-3B54ED6EDD UserName: Owner
03:18:21.148 Initialize success
03:20:54.851 AVAST engine defs: 12010900
03:21:02.960 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
03:21:02.960 Disk 0 Vendor: WDC_WD400EB-11CPF0 06.04G06 Size: 38166MB BusType: 3
03:21:03.226 Disk 0 MBR read successfully
03:21:03.242 Disk 0 MBR scan
03:21:03.570 Disk 0 Windows XP default MBR code
03:21:03.648 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 38162 MB offset 63
03:21:03.820 Disk 0 scanning sectors +78156225
03:21:04.023 Disk 0 scanning C:\WINNT\system32\drivers
03:21:51.663 Service scanning
03:21:53.882 Service MpKsldd2d8606 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKsldd2d8606.sys **LOCKED** 32
03:21:54.679 Modules scanning
03:22:08.163 Disk 0 trace - called modules:
03:22:08.195 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
03:22:08.195 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86379ab8]
03:22:08.195 3 CLASSPNP.SYS[f765bfd7] -> nt!IofCallDriver -> \Device\0000006a[0x863aa030]
03:22:08.195 5 ACPI.sys[f75c2620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x863e2d98]
03:22:08.898 AVAST engine scan C:\WINNT
03:22:39.632 AVAST engine scan C:\WINNT\system32
03:30:43.007 AVAST engine scan C:\WINNT\system32\drivers
03:31:40.585 AVAST engine scan C:\Documents and Settings\Owner
03:33:02.242 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
03:33:02.242 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"



OTL logfile created on: 1/9/2012 3:36:19 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.73 Mb Total Physical Memory | 375.67 Mb Available Physical Memory | 37.02% Memory free
1.88 Gb Paging File | 1.39 Gb Available in Paging File | 73.97% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 23.32 Gb Free Space | 62.57% Space Free | Partition Type: NTFS

Computer Name: YOUR-3B54ED6EDD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/09 03:34:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\desktop\OTL.exe
PRC - [2011/11/14 18:45:19 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINNT\explorer.exe
PRC - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINNT\wanmpsvc.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/28 21:24:24 | 008,527,008 | —- | M] () – C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/11/14 18:45:17 | 001,989,592 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (AOLService)
SRV - File not found [Disabled | Stopped] – – (AOL ACS)
SRV - File not found [Disabled | Stopped] – – (ACDaemon)
SRV - File not found [Disabled | Stopped] – – (aawservice)
SRV - [2011/12/24 17:50:18 | 000,652,872 | —- | M] (Malwarebytes Corporation) [Auto | Stopped] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2009/11/29 21:24:28 | 000,603,904 | —- | M] (TuneUp Software) [Disabled | Stopped] – C:\WINNT\system32\TUProgSt.exe – (TuneUp.ProgramStatisticsSvc)
SRV - [2009/01/27 12:26:42 | 000,398,336 | —- | M] (Ares Development Group) [On_Demand | Stopped] – C:\Program Files\Ares\chatServer.exe – (AresChatServer)
SRV - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [On_Demand | Stopped] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2007/01/04 15:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [On_Demand | Stopped] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2004/10/15 16:24:42 | 000,206,048 | —- | M] (Symantec Corporation) [Disabled | Stopped] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINNT\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2003/03/03 12:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Running] – – (MpKsl2341df66)
DRV - [2012/01/09 03:15:59 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKsldd2d8606.sys – (MpKsldd2d8606)
DRV - [2012/01/08 06:11:25 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys – (MpKslc414cb9b)
DRV - [2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\WINNT\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2010/05/20 14:27:24 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2010/03/15 20:28:27 | 000,095,024 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\WINNT\system32\drivers\SBREDrv.sys – (SBRE)
DRV - [2010/02/11 06:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINNT\system32\drivers\tcpip6.sys – (Tcpip6)
DRV - [2007/10/11 05:20:56 | 000,000,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\atwpkt2.sys – (ATWPKT2)
DRV - [2007/10/02 16:45:04 | 004,109,376 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\alcxwdm.sys – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 23:41:39 | 000,013,776 | —- | M] (Smart Link) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\recagent.sys – (RecAgent)
DRV - [2004/05/13 18:01:23 | 000,028,352 | —- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\System32\drivers\MxlW2k.sys – (MxlW2k)
DRV - [2003/05/20 12:23:10 | 000,210,592 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\mtlmnt5.sys – (Mtlmnt5)
DRV - [2003/05/20 12:21:44 | 001,295,472 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\mtlstrm.sys – (Mtlstrm)
DRV - [2003/05/20 12:19:24 | 000,085,688 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\slnthal.sys – (SlNtHal)
DRV - [2003/05/19 14:30:02 | 000,169,120 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\ntmtlfax.sys – (NtMtlFax)
DRV - [2003/05/13 09:58:34 | 000,521,408 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slntamr.sys – (Slntamr)
DRV - [2003/01/16 23:19:32 | 000,039,348 | —- | M] (Vireo Software) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slwdmsup.sys – (SlWdmSup)
DRV - [2003/01/10 16:13:04 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [1999/09/10 05:06:00 | 000,025,244 | —- | M] (Adaptec) [Kernel | Auto | Running] – C:\WINNT\System32\drivers\aspi32.sys – (Aspi32)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://my.aol.com/?ncid=aolmas00050000000002 [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://my.aol.com/?ncid=aolmas00050000000002 [binary data]
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 59636
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINNT\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/14 18:45:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/15 03:27:53 | 000,000,000 | —D | M]

[2008/07/02 13:47:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/01/05 22:54:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions
[2011/11/12 20:09:02 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/03/12 14:01:35 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\[removed]
[2011/01/13 12:01:00 | 000,000,000 | —D | M] (Vacuum Places Improved) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\[removed]
[2011/06/24 20:08:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\HK5TJ3JO.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/14 18:45:20 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/04/16 11:07:12 | 000,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2011/11/14 18:45:12 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/14 18:45:11 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: AOL Media Playback Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Gmail = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

O1 HOSTS File: ([2009/11/04 20:41:25 | 000,350,719 | R— | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.123haustiereundmehr.com
O1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 12024 more lines…
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] Narrator.exe File not found
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] Narrator.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - mswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - mswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1199318644546 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong Solitaire http://download.games.yahoo.com/games/clients/y/mjst4_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC7BC81B-A70D-4700-8CBA-E1D77637A0FA}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) -C:\WINNT\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - File not found
O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - File not found
O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - File not found
O20 - Winlogon\Notify\opnlMdBU: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - File not found
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - File not found
O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - File not found
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\WRNotifier: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll File not found
O29 - HKLM SecurityProviders - (msapsspc.dll) - File not found
O29 - HKLM SecurityProviders - (schannel.dll) - File not found
O29 - HKLM SecurityProviders - (digest.dll) - File not found
O29 - HKLM SecurityProviders - (msnsspc.dll) - File not found
O30 - LSA: Authentication Packages - (C:\WINNT\system32\ssqRJCSM) - File not found
O32 - HKLM CDRom: AutoRun - 0
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/09 03:34:48 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/09 03:17:15 | 004,713,472 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/08 21:58:32 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2012/01/04 21:37:25 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\MpSigStub.exe
[2012/01/04 21:31:54 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/01/04 21:28:53 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\mseinstall.exe
[2012/01/03 19:51:56 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.com
[2012/01/03 19:50:17 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HijackThis.exe
[2012/01/03 19:46:00 | 000,509,440 | —- | C] (Tech Support Guy System) – C:\Documents and Settings\Owner\Desktop\SysInfo.exe
[2012/01/03 04:54:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/03 04:54:11 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2012/01/03 04:54:10 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/03 04:52:52 | 010,847,608 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/03 04:40:48 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/03 04:36:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/01/03 04:26:01 | 000,000,000 | —D | C] – C:\Program Files\505B1
[2012/01/03 04:25:18 | 000,000,000 | —D | C] – C:\Program Files\LP
[2012/01/03 04:25:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\F4250
[2008/06/01 17:56:09 | 001,030,144 | —- | C] (Microsoft Corporation) – C:\Program Files\dbghelp.dll
[2008/06/01 17:56:09 | 000,626,688 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcr80.dll
[2008/06/01 17:56:09 | 000,548,864 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcp80.dll
[2008/06/01 17:56:09 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcm80.dll
[2003/07/01 19:02:45 | 000,014,976 | —- | C] ( ) – C:\WINNT\System32\drivers\winddx.sys
[1979/12/31 23:00:00 | 001,295,472 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlstrm.sys
[1979/12/31 23:00:00 | 000,521,408 | —- | C] ( ) – C:\WINNT\System32\drivers\slntamr.sys
[1979/12/31 23:00:00 | 000,210,592 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlmnt5.sys
[1979/12/31 23:00:00 | 000,169,120 | —- | C] ( ) – C:\WINNT\System32\drivers\ntmtlfax.sys
[1979/12/31 23:00:00 | 000,085,688 | —- | C] ( ) – C:\WINNT\System32\drivers\slnthal.sys
[1979/12/31 23:00:00 | 000,045,056 | —- | C] ( ) – C:\WINNT\System32\slserv.exe
[1 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/09 03:34:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/09 03:33:02 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2012/01/09 03:21:01 | 000,000,424 | -H– | M] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/09 03:17:54 | 004,713,472 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/09 03:17:17 | 000,000,978 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003UA.job
[2012/01/08 04:17:00 | 000,000,926 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003Core.job
[2012/01/07 05:22:05 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/07 05:22:04 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2012/01/04 22:00:56 | 000,000,207 | -HS- | M] () – C:\boot.ini
[2012/01/04 21:53:14 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2012/01/04 21:33:04 | 000,001,945 | —- | M] () – C:\WINNT\epplauncher.mif
[2012/01/04 21:31:31 | 000,001,158 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2012/01/04 21:29:05 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\mseinstall.exe
[2012/01/03 19:55:56 | 000,302,592 | —- | M] () – C:\Documents and Settings\Owner\Desktop\44f0pxph.exe
[2012/01/03 19:51:56 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.com
[2012/01/03 19:50:18 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HijackThis.exe
[2012/01/03 19:46:00 | 000,509,440 | —- | M] (Tech Support Guy System) – C:\Documents and Settings\Owner\Desktop\SysInfo.exe
[2012/01/03 13:40:54 | 000,433,414 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2012/01/03 13:40:54 | 000,068,244 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2012/01/03 04:53:24 | 010,847,608 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.60.0.1800.exe
[2011/12/14 07:05:01 | 000,001,393 | —- | M] () – C:\WINNT\imsins.BAK
[2011/12/13 23:42:09 | 000,221,632 | —- | M] () – C:\WINNT\System32\FNTCACHE.DAT
[2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[1 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/09 03:33:02 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2012/01/04 21:37:52 | 000,000,424 | -H– | C] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/04 21:33:04 | 000,001,945 | —- | C] () – C:\WINNT\epplauncher.mif
[2012/01/04 21:32:20 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/01/03 19:55:54 | 000,302,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\44f0pxph.exe
[2010/07/31 15:14:26 | 000,212,400 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/04/30 19:37:32 | 000,256,368 | —- | C] () – C:\Program Files\WinRAR.chm
[2010/04/30 19:37:32 | 000,141,824 | —- | C] () – C:\Program Files\RarExt.dll
[2010/04/30 19:37:32 | 000,052,224 | —- | C] () – C:\Program Files\RarExt64.dll
[2010/04/30 19:37:32 | 000,000,495 | —- | C] () – C:\Program Files\File_Id.diz
[2010/01/09 21:27:08 | 000,000,056 | -H– | C] () – C:\WINNT\System32\ezsidmv.dat
[2008/08/31 19:13:08 | 000,073,220 | —- | C] () – C:\WINNT\System32\EPPICPrinterDB.dat
[2008/08/31 19:13:08 | 000,000,097 | —- | C] () – C:\WINNT\System32\PICSDK.ini
[2008/08/31 19:13:07 | 000,031,053 | —- | C] () – C:\WINNT\System32\EPPICPattern131.dat
[2008/08/31 19:13:07 | 000,029,114 | —- | C] () – C:\WINNT\System32\EPPICPattern1.dat
[2008/08/31 19:13:07 | 000,027,417 | —- | C] () – C:\WINNT\System32\EPPICPattern121.dat
[2008/08/31 19:13:07 | 000,021,021 | —- | C] () – C:\WINNT\System32\EPPICPattern3.dat
[2008/08/31 19:13:07 | 000,015,670 | —- | C] () – C:\WINNT\System32\EPPICPattern5.dat
[2008/08/31 19:13:07 | 000,013,280 | —- | C] () – C:\WINNT\System32\EPPICPattern2.dat
[2008/08/31 19:13:07 | 000,010,673 | —- | C] () – C:\WINNT\System32\EPPICPattern4.dat
[2008/08/31 19:13:07 | 000,004,943 | —- | C] () – C:\WINNT\System32\EPPICPattern6.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_PT.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_BP.dat
[2008/08/31 19:13:07 | 000,001,137 | —- | C] () – C:\WINNT\System32\EPPICPresetData_ES.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_FR.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_CF.dat
[2008/08/31 19:13:07 | 000,001,104 | —- | C] () – C:\WINNT\System32\EPPICPresetData_EN.dat
[2008/08/31 19:11:38 | 000,000,044 | —- | C] () – C:\WINNT\EPSNX400.ini
[2008/06/19 23:32:00 | 000,001,160 | —- | C] () – C:\WINNT\mozver.dat
[2008/06/02 17:23:38 | 000,021,312 | —- | C] () – C:\WINNT\choice.exe
[2008/06/01 17:56:28 | 000,018,464 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox.dat
[2008/06/01 17:56:28 | 000,001,056 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox2.dat
[2008/06/01 16:24:37 | 000,594,427 | -HS- | C] () – C:\WINNT\System32\MSCJRqss.ini
[2008/05/29 23:48:08 | 000,001,217 | -HS- | C] () – C:\WINNT\System32\egNWwGgh.ini
[2008/05/16 13:59:02 | 000,000,374 | —- | C] () – C:\WINNT\wininit.ini
[2008/03/11 16:20:45 | 000,000,121 | —- | C] () – C:\WINNT\winzipsp.ini
[2008/02/08 02:00:14 | 000,000,080 | —- | C] () – C:\WINNT\SuperUtil.ini
[2008/02/08 01:51:36 | 000,000,000 | —- | C] () – C:\WINNT\System32\suupdate.dat
[2008/02/08 01:51:35 | 000,000,000 | —- | C] () – C:\WINNT\System32\mssurun.dat
[2007/12/05 03:08:52 | 001,446,464 | —- | C] () – C:\Program Files\Silverlight.exe
[2007/10/20 19:08:23 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys
[2007/10/20 18:25:18 | 000,049,152 | —- | C] () – C:\WINNT\System32\ChCfg.exe
[2007/10/20 18:23:14 | 000,147,456 | —- | C] () – C:\WINNT\System32\RtlCPAPI.dll
[2007/10/18 00:00:21 | 000,055,949 | —- | C] () – C:\WINNT\System32\x264-uninstall.exe
[2007/10/11 05:20:56 | 000,000,000 | —- | C] () – C:\WINNT\System32\drivers\atwpkt2.sys
[2007/03/02 16:03:53 | 000,001,763 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/12 22:02:29 | 000,000,116 | —- | C] () – C:\WINNT\NeroDigital.ini
[2007/01/15 01:25:20 | 000,000,079 | —- | C] () – C:\WINNT\xptools.ini
[2007/01/15 01:21:58 | 000,000,120 | —- | C] () – C:\WINNT\System32\bn.dll
[2007/01/08 18:20:12 | 000,014,848 | —- | C] () – C:\WINNT\System32\BASSMOD.dll
[2006/12/18 03:43:12 | 000,000,022 | —- | C] () – C:\Program Files\zipnew.dat
[2006/12/18 03:43:12 | 000,000,020 | —- | C] () – C:\Program Files\rarnew.dat
[2006/12/18 03:42:56 | 001,039,360 | —- | C] () – C:\Program Files\WinRAR.exe
[2006/12/18 03:42:56 | 000,378,880 | —- | C] () – C:\Program Files\Rar.exe
[2006/12/18 03:42:56 | 000,246,272 | —- | C] () – C:\Program Files\UnRAR.exe
[2006/12/18 03:42:56 | 000,120,832 | —- | C] () – C:\Program Files\Uninstall.exe
[2006/12/18 03:42:56 | 000,092,672 | —- | C] () – C:\Program Files\Default.SFX
[2006/12/18 03:42:56 | 000,074,240 | —- | C] () – C:\Program Files\Zip.SFX
[2006/12/18 03:42:56 | 000,069,632 | —- | C] () – C:\Program Files\WinCon.SFX
[2006/12/18 03:42:56 | 000,045,056 | —- | C] () – C:\Program Files\RarExtLoader.exe
[2006/12/18 03:42:55 | 000,003,271 | —- | C] () – C:\Program Files\Order.htm
[2006/12/18 03:42:55 | 000,001,088 | —- | C] () – C:\Program Files\RarFiles.lst
[2006/12/18 03:42:55 | 000,001,063 | —- | C] () – C:\Program Files\Descript.ion
[2006/12/18 03:42:55 | 000,000,639 | —- | C] () – C:\Program Files\Uninstall.lst
[2006/11/07 20:52:05 | 000,000,044 | —- | C] () – C:\WINNT\liveup.ini
[2006/08/12 22:09:45 | 000,004,096 | —- | C] () – C:\WINNT\d3dx.dat
[2006/07/16 17:08:08 | 000,000,627 | —- | C] () – C:\Program Files\playlist.xml
[2006/03/23 19:13:53 | 000,052,490 | —- | C] () – C:\WINNT\DcArt32presets.ini
[2006/03/05 01:46:11 | 000,001,610 | —- | C] () – C:\WINNT\GPlrLanc.dat
[2005/12/13 17:30:33 | 000,122,535 | —- | C] () – C:\WINNT\RSEDNClientUninstaller.exe
[2005/11/22 00:41:22 | 000,000,784 | —- | C] () – C:\Documents and Settings\Owner\Application Data\mpauth.dat
[2005/09/26 18:27:37 | 000,000,028 | —- | C] () – C:\WINNT\Systems.ini
[2005/08/31 18:05:37 | 000,000,075 | —- | C] () – C:\WINNT\System32\sysogg.dll
[2005/07/09 06:00:53 | 000,000,008 | —- | C] () – C:\WINNT\System32\wtl.dat
[2005/07/09 05:25:40 | 000,000,004 | —- | C] () – C:\WINNT\System32\micr0st.dll
[2005/07/09 05:16:13 | 000,129,024 | —- | C] () – C:\WINNT\UNWISE.EXE
[2005/06/29 14:53:05 | 000,005,460 | —- | C] () – C:\WINNT\kwv2.dat
[2005/06/27 17:37:46 | 000,187,512 | —- | C] () – C:\WINNT\System32\u3ldgpnu.dat
[2005/06/27 17:37:46 | 000,026,736 | —- | C] () – C:\WINNT\System32\4qlv6iqe.dat
[2005/06/27 17:37:46 | 000,003,864 | —- | C] () – C:\WINNT\System32\ahkhsbsu.dat
[2005/06/27 17:37:46 | 000,002,715 | —- | C] () – C:\WINNT\System32\mvkl8s1u.dat
[2005/06/27 17:37:46 | 000,000,000 | —- | C] () – C:\WINNT\System32\g8k3i4ve.dat
[2005/06/27 17:37:38 | 000,000,035 | —- | C] () – C:\WINNT\System32\01ii4bjf.ini
[2005/06/27 17:37:37 | 000,003,485 | —- | C] () – C:\WINNT\System32\mdeaf9ej.ini
[2005/05/20 21:35:09 | 000,000,056 | RHS- | C] () – C:\WINNT\System32\566097EC98.sys
[2005/03/21 20:59:40 | 000,000,715 | —- | C] () – C:\WINNT\aolback.exe.lnk
[2005/03/21 20:53:31 | 000,000,335 | —- | C] () – C:\WINNT\nsreg.dat
[2005/02/18 16:53:48 | 000,000,000 | —- | C] () – C:\WINNT\impborl.dll
[2005/02/08 14:42:45 | 000,000,092 | —- | C] () – C:\Program Files\play.rbn.rm&proto;=rtsp
[2005/01/13 22:23:53 | 000,001,131 | —- | C] () – C:\WINNT\System32\vh.dat
[2005/01/04 16:19:13 | 000,001,100 | —- | C] () – C:\WINNT\dhstatus.dat
[2004/12/15 08:22:09 | 000,149,504 | —- | C] () – C:\WINNT\System32\UNWISE.EXE
[2004/10/31 18:32:17 | 000,001,100 | —- | C] () – C:\WINNT\checkip.dat
[2004/10/31 18:29:50 | 000,001,393 | —- | C] () – C:\WINNT\ipconfig.dat
[2004/09/25 22:23:36 | 000,004,569 | —- | C] () – C:\WINNT\System32\secupd.dat
[2004/08/29 21:52:13 | 000,131,072 | —- | C] () – C:\WINNT\System32\SpoonUninstall.exe
[2004/08/25 17:53:06 | 000,000,032 | —- | C] () – C:\WINNT\easecdripper.ini
[2004/08/25 17:28:05 | 000,003,082 | —- | C] () – C:\WINNT\System32\affv6628p4now.sys
[2004/08/17 01:56:38 | 000,122,880 | —- | C] () – C:\WINNT\UnGins.exe
[2004/08/13 03:53:41 | 000,000,014 | —- | C] () – C:\WINNT\msoffice.ini
[2004/07/21 21:54:24 | 000,001,125 | —- | C] () – C:\WINNT\winamp.ini
[2004/05/26 14:42:25 | 000,000,048 | —- | C] () – C:\WINNT\upth.ini
[2004/05/26 14:42:25 | 000,000,028 | —- | C] () – C:\WINNT\atid.ini
[2004/02/11 07:50:12 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/02/07 14:41:59 | 000,082,944 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/01/22 12:00:28 | 000,012,635 | —- | C] () – C:\WINNT\System32\DAntivirus.ini
[2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\{419EC9B7-3209-4445-9EEC-01B25AAF5B29}.dat
[2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\System32\{0D36DCD8-9C7D-430C-A8AA-BD8DF873A105}.dat
[2003/10/25 14:37:35 | 000,067,857 | —- | C] () – C:\WINNT\cdPlayer.ini
[2003/10/22 10:05:08 | 000,000,030 | —- | C] () – C:\WINNT\Morphexe.INI
[2003/10/08 13:34:26 | 000,121,440 | —- | C] () – C:\WINNT\System32\MSDRMCtrl.dll
[2003/08/27 18:06:58 | 000,000,027 | —- | C] () – C:\WINNT\UP9ASP.INI
[2003/08/27 17:33:30 | 000,006,550 | —- | C] () – C:\WINNT\jautoexp.dat
[2003/08/27 16:45:53 | 000,065,536 | —- | C] () – C:\WINNT\System32\YCRWin32.dll
[2003/08/27 14:24:03 | 000,000,242 | —- | C] () – C:\WINNT\qwimp.ini
[2003/08/26 16:10:20 | 000,000,120 | —- | C] () – C:\WINNT\SIERRA.INI
[2003/08/23 13:49:22 | 000,000,396 | —- | C] () – C:\WINNT\intuprof.ini
[2003/08/23 13:48:46 | 000,000,880 | —- | C] () – C:\WINNT\QUICKEN.INI
[2003/08/22 20:05:57 | 000,002,241 | —- | C] () – C:\WINNT\hpdj5600.ini
[2003/08/22 20:05:25 | 000,000,414 | —- | C] () – C:\WINNT\hpbvspst.ini
[2003/07/16 14:22:18 | 000,000,061 | —- | C] () – C:\WINNT\smscfg.ini
[2003/07/14 13:30:28 | 000,197,120 | —- | C] () – C:\WINNT\patchw32.dll
[2003/07/14 13:30:27 | 000,034,816 | —- | C] () – C:\WINNT\patch.exe
[2003/07/01 19:23:27 | 000,000,000 | —- | C] () – C:\WINNT\System32\a3d.dll
[2003/07/01 19:10:07 | 000,000,370 | —- | C] () – C:\WINNT\ODBC.INI
[2003/07/01 19:07:33 | 000,282,624 | —- | C] () – C:\WINNT\System32\PCDrSystemInformation.dll
[2003/07/01 19:05:00 | 000,094,208 | —- | C] () – C:\WINNT\System32\PCDrKernelModeServices.dll
[2003/07/01 19:05:00 | 000,077,824 | —- | C] () – C:\WINNT\System32\ProgressTrace.dll
[2003/07/01 19:03:46 | 000,000,561 | —- | C] () – C:\WINNT\System32\OEMINFO.INI
[2003/07/01 19:02:45 | 000,466,944 | —- | C] () – C:\WINNT\System32\SLLights.dll
[2003/07/01 19:02:45 | 000,376,832 | —- | C] () – C:\WINNT\System32\slmh.exe
[2003/07/01 19:02:45 | 000,167,936 | —- | C] () – C:\WINNT\System32\minirec.exe
[2003/07/01 19:02:45 | 000,151,552 | —- | C] () – C:\WINNT\System32\amr_cpl.dll
[2003/07/01 19:02:45 | 000,061,440 | —- | C] () – C:\WINNT\SmCfg.exe
[2003/05/16 11:56:01 | 000,000,770 | —- | C] () – C:\WINNT\orun32.ini
[2003/05/16 10:34:34 | 000,002,048 | –S- | C] () – C:\WINNT\bootstat.dat
[2003/05/16 10:26:45 | 000,021,640 | —- | C] () – C:\WINNT\System32\emptyregdb.dat
[2003/05/16 10:20:03 | 000,004,073 | —- | C] () – C:\WINNT\ODBCINST.INI
[2003/05/16 10:18:53 | 000,221,632 | —- | C] () – C:\WINNT\System32\FNTCACHE.DAT
[2003/03/27 15:28:44 | 000,004,955 | —- | C] () – C:\WINNT\System32\DProg.ini
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINNT\System32\unrar.dll
[2002/10/06 12:42:58 | 000,237,568 | —- | C] () – C:\WINNT\System32\OggDS.dll
[2002/10/04 17:04:26 | 000,921,600 | —- | C] () – C:\WINNT\System32\VorbisEnc.dll
[2002/10/04 17:04:26 | 000,188,416 | —- | C] () – C:\WINNT\System32\vorbis.dll
[2002/10/04 17:04:18 | 000,045,056 | —- | C] () – C:\WINNT\System32\ogg.dll
[2002/09/06 10:36:16 | 000,233,472 | —- | C] () – C:\WINNT\System32\lame_enc.dll
[2002/05/15 18:38:40 | 000,091,136 | —- | C] () – C:\WINNT\System32\mp4fil32.dll
[2002/05/04 08:19:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\avisynthEx.dll
[2002/04/19 09:23:26 | 000,106,137 | —- | C] () – C:\WINNT\System32\libpostproc.dll
[2001/08/29 18:57:40 | 000,155,648 | —- | C] () – C:\WINNT\System32\addurl41.DLL
[2001/07/10 13:43:16 | 000,018,432 | —- | C] () – C:\WINNT\System32\winwatch.DLL
[2001/06/22 06:06:02 | 000,167,936 | —- | C] () – C:\WINNT\System32\MPEG2DEC.dll
[2000/09/08 16:53:50 | 000,073,839 | —- | C] () – C:\WINNT\System32\KodakOneTouch.dll
[1979/12/31 23:00:00 | 013,107,200 | —- | C] () – C:\WINNT\System32\oembios.bin
[1979/12/31 23:00:00 | 000,673,088 | —- | C] () – C:\WINNT\System32\mlang.dat
[1979/12/31 23:00:00 | 000,433,414 | —- | C] () – C:\WINNT\System32\perfh009.dat
[1979/12/31 23:00:00 | 000,272,128 | —- | C] () – C:\WINNT\System32\perfi009.dat
[1979/12/31 23:00:00 | 000,218,003 | —- | C] () – C:\WINNT\System32\dssec.dat
[1979/12/31 23:00:00 | 000,188,416 | —- | C] () – C:\WINNT\System32\slextspk.dll
[1979/12/31 23:00:00 | 000,159,744 | —- | C] () – C:\WINNT\System32\SLGen.dll
[1979/12/31 23:00:00 | 000,068,244 | —- | C] () – C:\WINNT\System32\perfc009.dat
[1979/12/31 23:00:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\coinst.dll
[1979/12/31 23:00:00 | 000,046,258 | —- | C] () – C:\WINNT\System32\mib.bin
[1979/12/31 23:00:00 | 000,028,626 | —- | C] () – C:\WINNT\System32\perfd009.dat
[1979/12/31 23:00:00 | 000,024,576 | —- | C] () – C:\WINNT\slrundll.exe
[1979/12/31 23:00:00 | 000,005,114 | —- | C] () – C:\WINNT\System32\oembios.dat
[1979/12/31 23:00:00 | 000,001,804 | —- | C] () – C:\WINNT\System32\dcache.bin
[1979/12/31 23:00:00 | 000,000,741 | —- | C] () – C:\WINNT\System32\noise.dat

========== LOP Check ==========

[2008/12/11 17:53:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/06/11 18:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2010/07/21 19:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/08/31 21:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2007/01/06 14:15:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2005/08/09 17:00:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/05/10 22:09:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2011/10/09 18:18:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/07 18:05:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2010/07/07 19:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/11/06 19:22:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/01/03 05:06:09 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/10/18 21:27:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/12/07 18:04:51 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2003/07/01 19:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\InterTrust
[2009/12/07 19:00:01 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2006/03/04 04:39:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2007/01/04 23:35:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2010/06/21 16:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DC++
[2008/09/05 16:57:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eBookPro6
[2012/01/03 05:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\F4250
[2010/07/07 21:12:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2003/08/05 22:50:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/08/31 21:25:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leader Technologies
[2008/08/31 19:20:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/02/16 23:56:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\minimem
[2011/09/05 15:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/05/09 07:48:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCToolsFirewallPlus
[2008/08/15 02:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PhotoParade
[2009/11/28 20:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Playrix Entertainment
[2009/10/19 00:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SharePod
[2009/01/04 23:43:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skinux
[2009/05/02 11:38:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skunk Studios
[2011/05/09 07:47:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spam Monitor
[2009/11/29 21:02:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sudden Games
[2009/04/15 01:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Systweak
[2009/09/26 16:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TikisLab
[2005/12/15 03:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TuneUp Software
[2008/02/12 04:06:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Uniblue
[2007/01/20 03:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2011/06/29 14:26:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart Digital Photo Viewer
[2007/10/07 11:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Walgreens
[2006/08/12 22:14:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wildfire
[2012/01/09 03:21:01 | 000,000,424 | -H– | M] () – C:\WINNT\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Program Files\play.rbn.rm&proto;=rtsp:SummaryInformation
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84

< End of report >





OTL Extras logfile created on: 1/9/2012 3:36:19 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.73 Mb Total Physical Memory | 375.67 Mb Available Physical Memory | 37.02% Memory free
1.88 Gb Paging File | 1.39 Gb Available in Paging File | 73.97% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 23.32 Gb Free Space | 62.57% Space Free | Partition Type: NTFS

Computer Name: YOUR-3B54ED6EDD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.reg [@ = regfile] – regedit.exe "%1"

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1
piffile [open] – "%1" %*
regfile [open] – regedit.exe "%1"
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2234:TCP" = 2234:TCP:*:Enabled:Soulseek
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"9420:TCP" = 9420:TCP:*:Enabled:RSP
"1035:TCP" = 1035:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\Program Files\DC++\DCPlusPlus.exe" = F:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application – (www.sopcast.com)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\twc\medicsp2\bin\sprtcmd.exe" = C:\Program Files\twc\medicsp2\bin\sprtcmd.exe:*:Enabled:sprtcmd
"C:\Program Files\twc\medicsp2\bin\sprtsvc.exe" = C:\Program Files\twc\medicsp2\bin\sprtsvc.exe:*:Enabled:sprtsvc
"C:\Program Files\twc\medicsp2\agent\bin\bcont.exe" = C:\Program Files\twc\medicsp2\agent\bin\bcont.exe:*:Enabled:bcont
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
"C:\Program Files\Common Files\AOL\1141465714\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1141465714\ee\aolsoftware.exe:*:Enabled:AOL Services
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL Connectivity Service
"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information
"C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys" = C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys:*:Enabled:PnkBstrK.sys – ()
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares – (Ares Development Group)
"C:\Program Files\SoulseekNS\slsk.exe" = C:\Program Files\SoulseekNS\slsk.exe:*:Enabled:SoulSeek – ()
"C:\WINNT\system32\spool\drivers\w32x86\3\E_DUPA30.EXE" = C:\WINNT\system32\spool\drivers\w32x86\3\E_DUPA30.EXE:*:Enabled:EPSON Driver Update – (SEIKO EPSON CORPORATION)
"C:\WINNT\system32\mmc.exe" = C:\WINNT\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeTray.exe" = C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{1CB92574-96F2-467B-B793-5CEB35C40C29}" = Image Resizer Powertoy for Windows XP
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7169B8E4-2632-46B1-AA5F-167CB5FE5029}" = Symantec Network Drivers Update
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7EE9DE0D-9228-4C33-B80E-FDD1773600DF}" = Microsoft Works Suite Add-in for Microsoft Word
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.7
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management client
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AIM_6" = AIM 6
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"Ares" = Ares 2.1.5
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DC++" = DC++ 0.761
"EPSON Scanner" = EPSON Scan
"EPSON Stylus NX400 Series" = EPSON Stylus NX400 Series Printer Uninstall
"hp print screen utility" = hp print screen utility
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InterActual Player" = InterActual Player
"IrfanView" = IrfanView (remove only)
"LTCM Client" = LTCM Client
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoParade.exe" = PhotoParade Player
"Portraits" = Portraits Screen Saver
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 12.0" = RealPlayer
"RSNet EDN" = Red Swoosh EDN Client (lol remove only)
"Shockwave" = Shockwave
"Silent Package Run-Time Sample" = EPSON NX400 User's Guide
"SLAMRMO" = Smart Link 56K Modem
"SopCast" = SopCast 3.2.4
"Soulseek2" = SoulSeek 157 NS 13c
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Works2003Setup" = Microsoft Works 2003 Setup Launcher
"X264 H.264/AVC Video Codec" = X264 H.264/AVC Video Codec (remove only)
"Yahoo! Software Update" = Yahoo! Software Update
"yBook_is1" = yBook

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/9/2011 10:26:20 AM | Computer Name = YOUR-3B54ED6EDD | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/9/2011 1:33:19 PM | Computer Name = YOUR-3B54ED6EDD | Source = Application Error | ID = 1000
Description = Faulting application applesyncnotifier.exe, version 1.6.72.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 2/10/2011 7:15:35 AM | Computer Name = YOUR-3B54ED6EDD | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/10/2011 7:15:40 AM | Computer Name = YOUR-3B54ED6EDD | Source = Application Error | ID = 1000
Description = Faulting application applesyncnotifier.exe, version 1.6.72.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 2/21/2011 1:44:31 AM | Computer Name = YOUR-3B54ED6EDD | Source = Application Error | ID = 1000
Description = Faulting application applesyncnotifier.exe, version 1.6.72.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 2/21/2011 1:44:33 AM | Computer Name = YOUR-3B54ED6EDD | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

[ System Events ]
Error - 1/4/2012 11:55:20 PM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7022
Description = The MSCamSvc service hung on starting.

Error - 1/4/2012 11:55:21 PM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SuperMounter TfFsMon TFSysMon

Error - 1/4/2012 11:59:55 PM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7034
Description = The MSCamSvc service terminated unexpectedly. It has done this 1
time(s).

Error - 1/5/2012 7:12:23 AM | Computer Name = YOUR-3B54ED6EDD | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0007E9438D70 has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).

Error - 1/5/2012 7:12:54 AM | Computer Name = YOUR-3B54ED6EDD | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.2 on
the Network Card with network address 0007E9438D70.

Error - 1/7/2012 6:50:57 AM | Computer Name = YOUR-3B54ED6EDD | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0007E9438D70 has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).

Error - 1/8/2012 11:58:30 PM | Computer Name = YOUR-3B54ED6EDD | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.117.2462.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7903.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 1/9/2012 5:15:07 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.

Error - 1/9/2012 5:15:20 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7034
Description = The MBAMService service terminated unexpectedly. It has done this
1 time(s).

Error - 1/9/2012 5:15:34 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 2 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.

[ TuneUp Events ]
Error - 2/12/2010 8:59:58 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/16/2010 12:42:08 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/16/2010 12:45:32 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/17/2010 2:03:32 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/17/2010 10:23:36 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/28/2010 9:07:54 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 3/2/2010 4:58:56 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 4/18/2010 2:45:02 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:45:02', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','3340',0)

Error - 4/18/2010 2:47:06 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:47:06', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','3080',0)

Error - 4/18/2010 2:50:22 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:50:22', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2620',0)


< End of report >
  • P2P

    You have P2P/file sharing programs installed on your computer, like Ares and SoulSeek. P2P applications are the largest source of malware we see.

    A reference for the risk of these programs can be found here: http://www.internetworldstats.com/articles/art053.htm

    Please do not use them until your computer is cleaned.

  • TDSSKiller

    Please read carefully and follow these steps.

  • ComboFix


    • Download ComboFix from one of the following locations:

      Link 1
      Link 2

    • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

    • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here.
    • Double click on ComboFix.exe & follow the prompts.

    • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]

    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
    • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
    • Should there be issues with internet afterward:

      In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

      In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
—-

In your next reply, please include the logs for:

  • TDSSKiller
  • ComboFix
How is your computer running now?
17:52:13.0242 1500 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
17:52:13.0726 1500 ============================================================
17:52:13.0726 1500 Current date / time: 2012/01/09 17:52:13.0726
17:52:13.0726 1500 SystemInfo:
17:52:13.0726 1500
17:52:13.0726 1500 OS Version: 5.1.2600 ServicePack: 3.0
17:52:13.0726 1500 Product type: Workstation
17:52:13.0726 1500 ComputerName: YOUR-3B54ED6EDD
17:52:13.0726 1500 UserName: Owner
17:52:13.0726 1500 Windows directory: C:\WINNT
17:52:13.0726 1500 System windows directory: C:\WINNT
17:52:13.0726 1500 Processor architecture: Intel x86
17:52:13.0726 1500 Number of processors: 1
17:52:13.0726 1500 Page size: 0x1000
17:52:13.0726 1500 Boot type: Normal boot
17:52:13.0726 1500 ============================================================
17:52:16.0788 1500 Initialize success
17:52:39.0163 2672 ============================================================
17:52:39.0163 2672 Scan started
17:52:39.0163 2672 Mode: Manual;
17:52:39.0163 2672 ============================================================
17:52:39.0726 2672 Abiosdsk - ok
17:52:39.0992 2672 abp480n5 - ok
17:52:40.0335 2672 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINNT\system32\drivers\ac97intc.sys
17:52:40.0367 2672 ac97intc - ok
17:52:40.0804 2672 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINNT\system32\DRIVERS\ACPI.sys
17:52:40.0867 2672 ACPI - ok
17:52:41.0210 2672 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINNT\system32\drivers\ACPIEC.sys
17:52:41.0210 2672 ACPIEC - ok
17:52:41.0570 2672 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINNT\system32\DRIVERS\adpu160m.sys
17:52:41.0585 2672 adpu160m - ok
17:52:41.0992 2672 aec (8bed39e3c35d6a489438b8141717a557) C:\WINNT\system32\drivers\aec.sys
17:52:42.0023 2672 aec - ok
17:52:42.0429 2672 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINNT\System32\drivers\afd.sys
17:52:42.0476 2672 AFD - ok
17:52:42.0851 2672 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINNT\system32\DRIVERS\agp440.sys
17:52:42.0867 2672 agp440 - ok
17:52:43.0210 2672 Aha154x - ok
17:52:43.0460 2672 aic78u2 - ok
17:52:43.0726 2672 aic78xx - ok
17:52:45.0382 2672 ALCXWDM (8e100402761df99e6a432bf31a8331d3) C:\WINNT\system32\drivers\ALCXWDM.SYS
17:52:46.0851 2672 ALCXWDM - ok
17:52:47.0195 2672 AliIde - ok
17:52:47.0460 2672 amsint - ok
17:52:47.0742 2672 asc - ok
17:52:48.0007 2672 asc3350p - ok
17:52:48.0257 2672 asc3550 - ok
17:52:48.0585 2672 Aspi32 (b979979ab8027f7f53fb16ec4229b7db) C:\WINNT\system32\drivers\Aspi32.sys
17:52:48.0601 2672 Aspi32 - ok
17:52:48.0960 2672 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINNT\system32\DRIVERS\asyncmac.sys
17:52:48.0960 2672 AsyncMac - ok
17:52:49.0351 2672 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINNT\system32\DRIVERS\atapi.sys
17:52:49.0351 2672 atapi - ok
17:52:49.0663 2672 Atdisk - ok
17:52:49.0976 2672 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINNT\system32\DRIVERS\atmarpc.sys
17:52:49.0992 2672 Atmarpc - ok
17:52:50.0398 2672 ATWPKT2 - ok
17:52:50.0804 2672 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINNT\system32\DRIVERS\audstub.sys
17:52:50.0804 2672 audstub - ok
17:52:51.0163 2672 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINNT\system32\drivers\Beep.sys
17:52:51.0163 2672 Beep - ok
17:52:51.0492 2672 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINNT\system32\drivers\cbidf2k.sys
17:52:51.0601 2672 cbidf2k - ok
17:52:51.0945 2672 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINNT\system32\DRIVERS\CCDECODE.sys
17:52:51.0960 2672 CCDECODE - ok
17:52:52.0413 2672 cd20xrnt - ok
17:52:52.0695 2672 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINNT\system32\drivers\Cdaudio.sys
17:52:52.0695 2672 Cdaudio - ok
17:52:53.0023 2672 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINNT\system32\drivers\Cdfs.sys
17:52:53.0023 2672 Cdfs - ok
17:52:53.0507 2672 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINNT\system32\DRIVERS\cdrom.sys
17:52:53.0523 2672 Cdrom - ok
17:52:53.0820 2672 Changer - ok
17:52:54.0117 2672 CmdIde - ok
17:52:54.0492 2672 Cpqarray - ok
17:52:54.0742 2672 dac2w2k - ok
17:52:54.0992 2672 dac960nt - ok
17:52:55.0304 2672 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINNT\system32\DRIVERS\disk.sys
17:52:55.0304 2672 Disk - ok
17:52:56.0070 2672 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINNT\system32\drivers\dmboot.sys
17:52:56.0445 2672 dmboot - ok
17:52:56.0867 2672 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINNT\system32\drivers\dmio.sys
17:52:56.0913 2672 dmio - ok
17:52:57.0257 2672 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINNT\system32\drivers\dmload.sys
17:52:57.0257 2672 dmload - ok
17:52:57.0710 2672 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINNT\system32\drivers\DMusic.sys
17:52:57.0726 2672 DMusic - ok
17:52:58.0023 2672 dpti2o - ok
17:52:58.0320 2672 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINNT\system32\drivers\drmkaud.sys
17:52:58.0320 2672 drmkaud - ok
17:52:58.0820 2672 E100B (ac9cf17ee2ae003c98eb4f5336c38058) C:\WINNT\system32\DRIVERS\e100b325.sys
17:52:58.0867 2672 E100B - ok
17:52:59.0242 2672 Fastfat (38d332a6d56af32635675f132548343e) C:\WINNT\system32\drivers\Fastfat.sys
17:52:59.0288 2672 Fastfat - ok
17:52:59.0679 2672 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINNT\system32\DRIVERS\fdc.sys
17:52:59.0679 2672 Fdc - ok
17:53:00.0023 2672 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINNT\system32\drivers\Fips.sys
17:53:00.0038 2672 Fips - ok
17:53:00.0382 2672 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINNT\system32\DRIVERS\flpydisk.sys
17:53:00.0398 2672 Flpydisk - ok
17:53:00.0867 2672 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINNT\system32\drivers\fltmgr.sys
17:53:00.0882 2672 FltMgr - ok
17:53:01.0195 2672 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINNT\system32\drivers\Fs_Rec.sys
17:53:01.0195 2672 Fs_Rec - ok
17:53:01.0507 2672 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINNT\system32\DRIVERS\ftdisk.sys
17:53:01.0523 2672 Ftdisk - ok
17:53:01.0851 2672 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINNT\system32\DRIVERS\msgpc.sys
17:53:01.0867 2672 Gpc - ok
17:53:02.0195 2672 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINNT\system32\DRIVERS\hidusb.sys
17:53:02.0195 2672 HidUsb - ok
17:53:02.0507 2672 hpn - ok
17:53:02.0945 2672 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINNT\system32\Drivers\HTTP.sys
17:53:03.0023 2672 HTTP - ok
17:53:03.0335 2672 i2omgmt - ok
17:53:03.0585 2672 i2omp - ok
17:53:03.0913 2672 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINNT\system32\DRIVERS\i8042prt.sys
17:53:03.0929 2672 i8042prt - ok
17:53:04.0398 2672 ialm (737da0be27652c4482ac5cde099bfce9) C:\WINNT\system32\DRIVERS\ialmnt5.sys
17:53:04.0570 2672 ialm - ok
17:53:05.0023 2672 iaStor (18e3972d9632485d80d609d4674f9d83) C:\WINNT\system32\DRIVERS\iaStor.sys
17:53:05.0070 2672 iaStor - ok
17:53:05.0445 2672 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINNT\system32\DRIVERS\imapi.sys
17:53:05.0460 2672 Imapi - ok
17:53:05.0804 2672 ini910u - ok
17:53:06.0117 2672 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINNT\system32\DRIVERS\intelide.sys
17:53:06.0117 2672 IntelIde - ok
17:53:06.0460 2672 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINNT\system32\DRIVERS\intelppm.sys
17:53:06.0476 2672 intelppm - ok
17:53:06.0820 2672 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINNT\system32\drivers\ip6fw.sys
17:53:06.0835 2672 Ip6Fw - ok
17:53:07.0163 2672 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINNT\system32\DRIVERS\ipfltdrv.sys
17:53:07.0179 2672 IpFilterDriver - ok
17:53:07.0538 2672 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINNT\system32\DRIVERS\ipinip.sys
17:53:07.0554 2672 IpInIp - ok
17:53:07.0945 2672 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINNT\system32\DRIVERS\ipnat.sys
17:53:07.0976 2672 IpNat - ok
17:53:08.0320 2672 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINNT\system32\DRIVERS\ipsec.sys
17:53:08.0351 2672 IPSec - ok
17:53:08.0710 2672 IPVNMon (f60af0f89204a9177d110e3b2bd9fa0b) C:\WINNT\system32\drivers\IPVNMon.sys
17:53:08.0710 2672 IPVNMon - ok
17:53:09.0085 2672 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINNT\system32\DRIVERS\irenum.sys
17:53:09.0085 2672 IRENUM - ok
17:53:09.0398 2672 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINNT\system32\DRIVERS\isapnp.sys
17:53:09.0398 2672 isapnp - ok
17:53:09.0773 2672 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINNT\system32\DRIVERS\kbdclass.sys
17:53:09.0773 2672 Kbdclass - ok
17:53:10.0132 2672 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINNT\system32\DRIVERS\kbdhid.sys
17:53:10.0132 2672 kbdhid - ok
17:53:10.0538 2672 kmixer (692bcf44383d056aed41b045a323d378) C:\WINNT\system32\drivers\kmixer.sys
17:53:10.0601 2672 kmixer - ok
17:53:11.0023 2672 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINNT\system32\drivers\KSecDD.sys
17:53:11.0023 2672 KSecDD - ok
17:53:11.0351 2672 lbrtfdc - ok
17:53:11.0726 2672 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINNT\system32\drivers\mbam.sys
17:53:11.0726 2672 MBAMProtector - ok
17:53:12.0023 2672 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINNT\system32\drivers\mnmdd.sys
17:53:12.0038 2672 mnmdd - ok
17:53:12.0335 2672 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINNT\system32\drivers\Modem.sys
17:53:12.0335 2672 Modem - ok
17:53:12.0804 2672 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINNT\system32\DRIVERS\mouclass.sys
17:53:12.0820 2672 Mouclass - ok
17:53:13.0148 2672 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINNT\system32\DRIVERS\mouhid.sys
17:53:13.0148 2672 mouhid - ok
17:53:13.0523 2672 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINNT\system32\drivers\MountMgr.sys
17:53:13.0523 2672 MountMgr - ok
17:53:13.0913 2672 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINNT\system32\DRIVERS\MpFilter.sys
17:53:13.0976 2672 MpFilter - ok
17:53:14.0101 2672 MpKsl2341df66 - ok
17:53:14.0210 2672 MpKslc414cb9b (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys
17:53:14.0210 2672 MpKslc414cb9b - ok
17:53:14.0288 2672 MpKsldd2d8606 (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKsldd2d8606.sys
17:53:14.0288 2672 MpKsldd2d8606 - ok
17:53:14.0617 2672 mraid35x - ok
17:53:14.0992 2672 mrtRate - ok
17:53:15.0351 2672 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINNT\system32\DRIVERS\mrxdav.sys
17:53:15.0445 2672 MRxDAV - ok
17:53:16.0054 2672 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINNT\system32\DRIVERS\mrxsmb.sys
17:53:16.0179 2672 MRxSmb - ok
17:53:16.0554 2672 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINNT\system32\drivers\Msfs.sys
17:53:16.0554 2672 Msfs - ok
17:53:16.0898 2672 MSHUSBVideo (5119ffc2a6b51089cdb0efdc75808c97) C:\WINNT\system32\Drivers\nx6000.sys
17:53:16.0913 2672 MSHUSBVideo - ok
17:53:17.0273 2672 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINNT\system32\drivers\MSKSSRV.sys
17:53:17.0273 2672 MSKSSRV - ok
17:53:17.0632 2672 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINNT\system32\drivers\MSPCLOCK.sys
17:53:17.0632 2672 MSPCLOCK - ok
17:53:18.0085 2672 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINNT\system32\drivers\MSPQM.sys
17:53:18.0085 2672 MSPQM - ok
17:53:18.0460 2672 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINNT\system32\DRIVERS\mssmbios.sys
17:53:18.0460 2672 mssmbios - ok
17:53:18.0804 2672 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINNT\system32\drivers\MSTEE.sys
17:53:18.0804 2672 MSTEE - ok
17:53:19.0242 2672 Mtlmnt5 (8bc576bf81628ad9b03621bd381eb3c8) C:\WINNT\system32\DRIVERS\Mtlmnt5.sys
17:53:19.0288 2672 Mtlmnt5 - ok
17:53:20.0070 2672 Mtlstrm (b5f8b93fa9556a371f20721c80b70cd3) C:\WINNT\system32\DRIVERS\Mtlstrm.sys
17:53:20.0492 2672 Mtlstrm - ok
17:53:20.0945 2672 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINNT\system32\drivers\Mup.sys
17:53:20.0960 2672 Mup - ok
17:53:21.0351 2672 MxlW2k (88f57a15b786bf2af9458f7903768085) C:\WINNT\system32\drivers\MxlW2k.sys
17:53:21.0351 2672 MxlW2k - ok
17:53:21.0726 2672 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINNT\system32\DRIVERS\NABTSFEC.sys
17:53:21.0757 2672 NABTSFEC - ok
17:53:22.0195 2672 NDIS (1df7f42665c94b825322fae71721130d) C:\WINNT\system32\drivers\NDIS.sys
17:53:22.0242 2672 NDIS - ok
17:53:22.0617 2672 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINNT\system32\DRIVERS\NdisIP.sys
17:53:22.0617 2672 NdisIP - ok
17:53:23.0054 2672 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINNT\system32\DRIVERS\ndistapi.sys
17:53:23.0054 2672 NdisTapi - ok
17:53:23.0445 2672 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINNT\system32\DRIVERS\ndisuio.sys
17:53:23.0445 2672 Ndisuio - ok
17:53:23.0820 2672 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINNT\system32\DRIVERS\ndiswan.sys
17:53:23.0867 2672 NdisWan - ok
17:53:24.0226 2672 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINNT\system32\drivers\NDProxy.sys
17:53:24.0226 2672 NDProxy - ok
17:53:24.0538 2672 Netaapl - ok
17:53:24.0867 2672 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINNT\system32\DRIVERS\netbios.sys
17:53:24.0882 2672 NetBIOS - ok
17:53:25.0288 2672 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINNT\system32\DRIVERS\netbt.sys
17:53:25.0335 2672 NetBT - ok
17:53:25.0773 2672 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINNT\system32\drivers\Npfs.sys
17:53:25.0773 2672 Npfs - ok
17:53:26.0335 2672 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINNT\system32\drivers\Ntfs.sys
17:53:26.0507 2672 Ntfs - ok
17:53:26.0960 2672 NtMtlFax (d4c9a61408da38652267648d51739fdb) C:\WINNT\system32\DRIVERS\NtMtlFax.sys
17:53:27.0007 2672 NtMtlFax - ok
17:53:27.0351 2672 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINNT\system32\drivers\Null.sys
17:53:27.0351 2672 Null - ok
17:53:28.0304 2672 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINNT\system32\DRIVERS\nv4_mini.sys
17:53:29.0007 2672 nv - ok
17:53:29.0367 2672 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINNT\system32\DRIVERS\nwlnkflt.sys
17:53:29.0382 2672 NwlnkFlt - ok
17:53:29.0710 2672 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINNT\system32\DRIVERS\nwlnkfwd.sys
17:53:29.0710 2672 NwlnkFwd - ok
17:53:30.0101 2672 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINNT\system32\DRIVERS\parport.sys
17:53:30.0117 2672 Parport - ok
17:53:30.0460 2672 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINNT\system32\drivers\PartMgr.sys
17:53:30.0460 2672 PartMgr - ok
17:53:30.0804 2672 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINNT\system32\drivers\ParVdm.sys
17:53:30.0804 2672 ParVdm - ok
17:53:31.0148 2672 PCI (a219903ccf74233761d92bef471a07b1) C:\WINNT\system32\DRIVERS\pci.sys
17:53:31.0163 2672 PCI - ok
17:53:31.0476 2672 PCIDump - ok
17:53:31.0773 2672 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINNT\system32\DRIVERS\pciide.sys
17:53:31.0773 2672 PCIIde - ok
17:53:32.0163 2672 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINNT\system32\drivers\Pcmcia.sys
17:53:32.0210 2672 Pcmcia - ok
17:53:32.0538 2672 PDCOMP - ok
17:53:32.0804 2672 PDFRAME - ok
17:53:33.0085 2672 PDRELI - ok
17:53:33.0351 2672 PDRFRAME - ok
17:53:33.0601 2672 perc2 - ok
17:53:33.0867 2672 perc2hib - ok
17:53:34.0210 2672 Point32 (dcdf0421a1c14f2923e298a30fd7636d) C:\WINNT\system32\DRIVERS\point32.sys
17:53:34.0226 2672 Point32 - ok
17:53:34.0601 2672 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINNT\system32\DRIVERS\raspptp.sys
17:53:34.0617 2672 PptpMiniport - ok
17:53:34.0976 2672 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINNT\system32\DRIVERS\processr.sys
17:53:34.0992 2672 Processor - ok
17:53:35.0367 2672 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINNT\system32\DRIVERS\psched.sys
17:53:35.0382 2672 PSched - ok
17:53:35.0773 2672 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINNT\system32\DRIVERS\ptilink.sys
17:53:35.0773 2672 Ptilink - ok
17:53:36.0117 2672 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINNT\system32\DRIVERS\PxHelp20.sys
17:53:36.0117 2672 PxHelp20 - ok
17:53:36.0429 2672 ql1080 - ok
17:53:36.0695 2672 Ql10wnt - ok
17:53:36.0960 2672 ql12160 - ok
17:53:37.0226 2672 ql1240 - ok
17:53:37.0492 2672 ql1280 - ok
17:53:37.0788 2672 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINNT\system32\DRIVERS\rasacd.sys
17:53:37.0788 2672 RasAcd - ok
17:53:38.0148 2672 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINNT\system32\DRIVERS\rasl2tp.sys
17:53:38.0163 2672 Rasl2tp - ok
17:53:38.0538 2672 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINNT\system32\DRIVERS\raspppoe.sys
17:53:38.0538 2672 RasPppoe - ok
17:53:38.0867 2672 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINNT\system32\DRIVERS\raspti.sys
17:53:38.0867 2672 Raspti - ok
17:53:39.0273 2672 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINNT\system32\DRIVERS\rdbss.sys
17:53:39.0335 2672 Rdbss - ok
17:53:39.0648 2672 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINNT\system32\DRIVERS\RDPCDD.sys
17:53:39.0663 2672 RDPCDD - ok
17:53:40.0054 2672 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINNT\system32\drivers\RDPWD.sys
17:53:40.0101 2672 RDPWD - ok
17:53:40.0492 2672 RecAgent (e9aaa0092d74a9d371659c4c38882e12) C:\WINNT\System32\DRIVERS\RecAgent.sys
17:53:40.0492 2672 RecAgent - ok
17:53:40.0882 2672 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINNT\system32\DRIVERS\redbook.sys
17:53:40.0898 2672 redbook - ok
17:53:41.0335 2672 SBRE (4019149e4e296072831c8855605d9fdc) C:\WINNT\system32\drivers\SBREdrv.sys
17:53:41.0351 2672 SBRE - ok
17:53:41.0726 2672 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINNT\system32\DRIVERS\secdrv.sys
17:53:41.0742 2672 Secdrv - ok
17:53:42.0148 2672 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINNT\system32\DRIVERS\serenum.sys
17:53:42.0148 2672 serenum - ok
17:53:42.0523 2672 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINNT\system32\DRIVERS\serial.sys
17:53:42.0538 2672 Serial - ok
17:53:42.0913 2672 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINNT\system32\drivers\Sfloppy.sys
17:53:42.0976 2672 Sfloppy - ok
17:53:43.0320 2672 Simbad - ok
17:53:43.0648 2672 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINNT\system32\DRIVERS\SLIP.sys
17:53:43.0648 2672 SLIP - ok
17:53:44.0179 2672 Slntamr (9d3805cbf16056359a52dfb37a71aa49) C:\WINNT\system32\DRIVERS\slntamr.sys
17:53:44.0304 2672 Slntamr - ok
17:53:44.0726 2672 SlNtHal (0f3536110d1027e8bb07e0adb9058039) C:\WINNT\system32\DRIVERS\Slnthal.sys
17:53:44.0757 2672 SlNtHal - ok
17:53:45.0132 2672 SlWdmSup (3b4a3b282f62fe5d75127d22b26909ed) C:\WINNT\system32\DRIVERS\SlWdmSup.sys
17:53:45.0148 2672 SlWdmSup - ok
17:53:45.0476 2672 Sparrow - ok
17:53:45.0820 2672 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINNT\system32\drivers\splitter.sys
17:53:45.0835 2672 splitter - ok
17:53:46.0257 2672 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINNT\system32\DRIVERS\sr.sys
17:53:46.0273 2672 sr - ok
17:53:46.0695 2672 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINNT\system32\DRIVERS\srv.sys
17:53:46.0820 2672 Srv - ok
17:53:47.0195 2672 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINNT\system32\DRIVERS\StreamIP.sys
17:53:47.0195 2672 streamip - ok
17:53:47.0523 2672 SuperMounter - ok
17:53:47.0820 2672 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINNT\system32\DRIVERS\swenum.sys
17:53:47.0820 2672 swenum - ok
17:53:48.0195 2672 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINNT\system32\drivers\swmidi.sys
17:53:48.0210 2672 swmidi - ok
17:53:48.0538 2672 symc810 - ok
17:53:48.0788 2672 symc8xx - ok
17:53:49.0054 2672 sym_hi - ok
17:53:49.0320 2672 sym_u3 - ok
17:53:49.0632 2672 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINNT\system32\drivers\sysaudio.sys
17:53:49.0663 2672 sysaudio - ok
17:53:50.0163 2672 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINNT\system32\DRIVERS\tcpip.sys
17:53:50.0257 2672 Tcpip - ok
17:53:50.0695 2672 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINNT\system32\DRIVERS\tcpip6.sys
17:53:50.0757 2672 Tcpip6 - ok
17:53:51.0179 2672 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINNT\system32\drivers\TDPIPE.sys
17:53:51.0179 2672 TDPIPE - ok
17:53:51.0554 2672 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINNT\system32\drivers\TDTCP.sys
17:53:51.0570 2672 TDTCP - ok
17:53:51.0929 2672 TermDD (88155247177638048422893737429d9e) C:\WINNT\system32\DRIVERS\termdd.sys
17:53:51.0945 2672 TermDD - ok
17:53:52.0288 2672 TfFsMon - ok
17:53:52.0554 2672 TfNetMon - ok
17:53:52.0820 2672 TFSysMon - ok
17:53:53.0085 2672 TosIde - ok
17:53:53.0413 2672 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINNT\system32\DRIVERS\tunmp.sys
17:53:53.0413 2672 tunmp - ok
17:53:53.0788 2672 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINNT\system32\drivers\Udfs.sys
17:53:53.0804 2672 Udfs - ok
17:53:54.0195 2672 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINNT\system32\DRIVERS\ultra.sys
17:53:54.0195 2672 ultra - ok
17:53:54.0663 2672 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINNT\system32\DRIVERS\update.sys
17:53:54.0788 2672 Update - ok
17:53:55.0163 2672 USBAAPL - ok
17:53:55.0476 2672 usbaudio (e919708db44ed8543a7c017953148330) C:\WINNT\system32\drivers\usbaudio.sys
17:53:55.0492 2672 usbaudio - ok
17:53:55.0867 2672 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINNT\system32\DRIVERS\usbccgp.sys
17:53:55.0882 2672 usbccgp - ok
17:53:56.0288 2672 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINNT\system32\DRIVERS\usbehci.sys
17:53:56.0288 2672 usbehci - ok
17:53:56.0663 2672 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINNT\system32\DRIVERS\usbhub.sys
17:53:56.0679 2672 usbhub - ok
17:53:57.0054 2672 usbprint (a717c8721046828520c9edf31288fc00) C:\WINNT\system32\DRIVERS\usbprint.sys
17:53:57.0070 2672 usbprint - ok
17:53:57.0429 2672 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINNT\system32\DRIVERS\usbscan.sys
17:53:57.0445 2672 usbscan - ok
17:53:57.0804 2672 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINNT\system32\DRIVERS\USBSTOR.SYS
17:53:57.0820 2672 USBSTOR - ok
17:53:58.0210 2672 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINNT\system32\DRIVERS\usbuhci.sys
17:53:58.0226 2672 usbuhci - ok
17:53:58.0585 2672 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINNT\system32\Drivers\usbvideo.sys
17:53:58.0617 2672 usbvideo - ok
17:53:59.0007 2672 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINNT\System32\drivers\vga.sys
17:53:59.0007 2672 VgaSave - ok
17:53:59.0382 2672 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINNT\system32\DRIVERS\viaide.sys
17:53:59.0382 2672 ViaIde - ok
17:53:59.0710 2672 VMUVC - ok
17:54:00.0054 2672 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINNT\system32\drivers\VolSnap.sys
17:54:00.0054 2672 VolSnap - ok
17:54:00.0382 2672 vvftUVC - ok
17:54:00.0710 2672 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINNT\system32\DRIVERS\wanarp.sys
17:54:00.0710 2672 Wanarp - ok
17:54:01.0179 2672 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINNT\system32\DRIVERS\wanatw4.sys
17:54:01.0179 2672 wanatw - ok
17:54:01.0710 2672 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINNT\system32\Drivers\wdf01000.sys
17:54:01.0851 2672 Wdf01000 - ok
17:54:02.0210 2672 WDICA - ok
17:54:02.0538 2672 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINNT\system32\drivers\wdmaud.sys
17:54:02.0554 2672 wdmaud - ok
17:54:03.0023 2672 WpdUsb (d7467f619f574ab36286d2903e751deb) C:\WINNT\system32\Drivers\wpdusb.sys
17:54:03.0038 2672 WpdUsb - ok
17:54:03.0382 2672 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINNT\System32\drivers\ws2ifsl.sys
17:54:03.0382 2672 WS2IFSL - ok
17:54:03.0726 2672 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINNT\system32\DRIVERS\WSTCODEC.SYS
17:54:03.0726 2672 WSTCODEC - ok
17:54:04.0132 2672 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINNT\system32\DRIVERS\WudfPf.sys
17:54:04.0148 2672 WudfPf - ok
17:54:04.0523 2672 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINNT\system32\DRIVERS\wudfrd.sys
17:54:04.0538 2672 WudfRd - ok
17:54:04.0976 2672 {6080A529-897E-4629-A488-ABA0C29B635E} (e6c22d34baef5196e1b23a4492c275b7) C:\WINNT\system32\drivers\ialmsbw.sys
17:54:05.0023 2672 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
17:54:05.0429 2672 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (6e53bd96b0ebad721cdd6320dbfc3f5f) C:\WINNT\system32\drivers\ialmkchw.sys
17:54:05.0460 2672 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
17:54:05.0492 2672 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
17:54:05.0742 2672 \Device\Harddisk0\DR0 - ok
17:54:05.0757 2672 Boot (0x1200) (d7258f56a3eea298871c51c4cbfeeac0) \Device\Harddisk0\DR0\Partition0
17:54:05.0757 2672 \Device\Harddisk0\DR0\Partition0 - ok
17:54:05.0757 2672 ============================================================
17:54:05.0757 2672 Scan finished
17:54:05.0757 2672 ============================================================
17:54:05.0773 2648 Detected object count: 0
17:54:05.0773 2648 Actual detected object count: 0




ComboFix 12-01-09.06 - Owner 01/09/2012 18:20:57.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.686 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Owner\WINDOWS
c:\program files\LP
c:\program files\LP\015F\A4A.tmp
c:\program files\LP\015F\A4B.tmp
c:\program files\LP\015F\A4C.tmp
c:\program files\LP\015F\A4D.tmp
c:\program files\Uninstall.exe
c:\winnt\$NtUninstallKB11512$
c:\winnt\$NtUninstallKB11512$\1404534607\@
c:\winnt\$NtUninstallKB11512$\1404534607\bckfg.tmp
c:\winnt\$NtUninstallKB11512$\1404534607\cfg.ini
c:\winnt\$NtUninstallKB11512$\1404534607\Desktop.ini
c:\winnt\$NtUninstallKB11512$\1404534607\keywords
c:\winnt\$NtUninstallKB11512$\1404534607\kwrd.dll
c:\winnt\$NtUninstallKB11512$\1404534607\L\ijesxoym
c:\winnt\$NtUninstallKB11512$\1404534607\U\00000001.@
c:\winnt\$NtUninstallKB11512$\1404534607\U\00000002.@
c:\winnt\$NtUninstallKB11512$\1404534607\U\00000004.@
c:\winnt\$NtUninstallKB11512$\1404534607\U\80000000.@
c:\winnt\$NtUninstallKB11512$\1404534607\U\80000004.@
c:\winnt\$NtUninstallKB11512$\1404534607\U\80000032.@
c:\winnt\$NtUninstallKB11512$\3816632881
c:\winnt\alcrmv.exe
c:\winnt\Downloaded Program Files\ODCTOOLS
c:\winnt\Downloaded Program Files\ODCTOOLS\ef6b26db-344d-4ad3-ba24-aca0bdaa999a.cab
c:\winnt\Downloaded Program Files\ODCTOOLS\f04d289f-c60a-422b-8396-6c372047042e.cab
c:\winnt\iun6002.exe
c:\winnt\patch.exe
c:\winnt\system32\drivers\etc\hosts.ics
c:\winnt\system32\egNWwGgh.ini
c:\winnt\system32\MSCJRqss.ini
c:\winnt\system32\PowerToyReadme.htm
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_AFPANSI
——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_ZESOFT
.
.
((((((((((((((((((((((((( Files Created from 2011-12-10 to 2012-01-10 )))))))))))))))))))))))))))))))
.
.
2012-01-10 00:40 . 2012-01-10 00:40 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\offreg.dll
2012-01-09 03:58 . 2012-01-09 03:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2012-01-08 12:09 . 2011-11-21 08:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\mpengine.dll
2012-01-06 04:04 . 2011-11-21 08:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-05 03:37 . 2010-10-19 20:51 222080 ——w- c:\winnt\system32\MpSigStub.exe
2012-01-05 03:31 . 2012-01-05 03:32 ——– d—–w- c:\program files\Microsoft Security Client
2012-01-03 10:54 . 2011-12-10 21:24 20464 —-a-w- c:\winnt\system32\drivers\mbam.sys
2012-01-03 10:54 . 2012-01-03 10:54 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-01-03 10:26 . 2012-01-03 11:11 ——– d—–w- c:\program files\505B1
2012-01-03 10:25 . 2012-01-03 11:11 ——– d—–w- c:\documents and settings\Owner\Application Data\F4250
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-29 03:24 . 2011-07-23 03:16 414368 —-a-w- c:\winnt\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25 . 1980-01-01 05:00 1859584 —-a-w- c:\winnt\system32\win32k.sys
2011-11-04 19:20 . 2004-02-06 23:05 916992 —-a-w- c:\winnt\system32\wininet.dll
2011-11-04 19:20 . 1980-01-01 05:00 43520 —-a-w- c:\winnt\system32\licmgr10.dll
2011-11-04 19:20 . 1980-01-01 05:00 1469440 —-a-w- c:\winnt\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 05:59 385024 —-a-w- c:\winnt\system32\html.iec
2011-11-01 16:07 . 2004-04-15 23:09 1288704 —-a-w- c:\winnt\system32\ole32.dll
2011-10-28 05:31 . 1980-01-01 05:00 33280 —-a-w- c:\winnt\system32\csrsrv.dll
2011-10-25 13:33 . 1980-01-01 05:00 2192768 —-a-w- c:\winnt\system32\ntoskrnl.exe
2011-10-25 12:52 . 2002-08-29 06:04 2069376 —-a-w- c:\winnt\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2002-11-26 19:15 186880 —-a-w- c:\winnt\system32\encdec.dll
2010-03-15 16:28 . 2010-05-01 01:37 52224 -c–a-w- c:\program files\RarExt64.dll
2010-03-15 16:28 . 2006-12-18 09:42 45056 -c–a-w- c:\program files\RarExtLoader.exe
2010-03-15 16:28 . 2010-05-01 01:37 141824 —-a-w- c:\program files\RarExt.dll
2010-03-15 16:28 . 2006-12-18 09:42 74240 -c–a-w- c:\program files\Zip.SFX
2010-03-15 16:28 . 2006-12-18 09:42 92672 -c–a-w- c:\program files\Default.SFX
2010-03-15 16:27 . 2006-12-18 09:42 69632 -c–a-w- c:\program files\WinCon.SFX
2010-03-15 16:26 . 2006-12-18 09:42 378880 -c–a-w- c:\program files\Rar.exe
2010-03-15 16:26 . 2006-12-18 09:42 246272 -c–a-w- c:\program files\UnRAR.exe
2010-03-15 16:26 . 2006-12-18 09:42 1039360 —-a-w- c:\program files\WinRAR.exe
2007-12-05 09:08 . 2007-12-05 09:08 1446464 -c–a-w- c:\program files\Silverlight.exe
2007-05-28 21:47 . 2008-06-01 23:56 626688 -c–a-w- c:\program files\msvcr80.dll
2007-05-28 21:47 . 2008-06-01 23:56 548864 -c–a-w- c:\program files\msvcp80.dll
2007-05-28 21:47 . 2008-06-01 23:56 479232 -c–a-w- c:\program files\msvcm80.dll
2007-05-28 21:47 . 2008-06-01 23:56 1030144 -c–a-w- c:\program files\dbghelp.dll
2011-11-15 00:45 . 2011-11-15 00:45 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fsproflt]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
backup=c:\winnt\pss\Billminder.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
backup=c:\winnt\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
backup=c:\winnt\pss\Quicken Startup.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Admanager Controller
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Byqwdiza
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\G40ZeWMDF
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IST Service
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mdeaf9ej
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfAccuracy
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XP Tools
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³#  L"h'þ9Óœð3rÅWC:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³#  L"h'þ9Óœð3rÅWC:\Program Files
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³#  L"h'þ9Óœð3rÅWc:\program files\ISTsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2008-10-31 19:22 50480 —-a-w- c:\program files\AIM6\aim6.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-19 05:09 133104 —-atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-01-23 16:31 126976 -c–a-w- c:\winnt\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-01-23 16:36 155648 -c–a-w- c:\winnt\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-12-24 23:50 460872 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2005-10-12 23:13 7086080 —-a-w- c:\program files\MSN Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 16:17 421888 -c–a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KodakCCS"=2 (0x2)
"AOL ACS"=2 (0x2)
"ACDaemon"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" /background
"Aim6"="c:\program files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
"ctfmon.exe"=c:\winnt\system32\ctfmon.exe
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"AOLDialer"=c:\program files\Common Files\AOL\ACS\AOLDial.exe
"HostManager"="c:\program files\Common Files\AOL\1141465714\ee\AOLSoftware.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"MSConfig"=c:\winnt\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
"HP Software Update"=c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
"HPDJ Taskbar Utility"=c:\winnt\System32\spool\drivers\w32x86\3\hpztsb08.exe
"medicsp2"="c:\program files\twc\medicsp2\bin\sprtcmd.exe" /P medicsp2
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"HotKeysCmds"=c:\winnt\system32\hkcmd.exe
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\PnkBstrK.sys"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\WINNT\\system32\\spool\\drivers\\w32x86\\3\\E_DUPA30.EXE"=
"c:\\WINNT\\system32\\mmc.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2234:TCP"= 2234:TCP:Soulseek
"9420:TCP"= 9420:TCP:RSP
"1035:TCP"= 1035:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 SBRE;SBRE;c:\winnt\system32\drivers\SBREDrv.sys [2/10/2010 11:24 PM 95024]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/3/2012 4:54 AM 652872]
R3 MBAMProtector;MBAMProtector;c:\winnt\system32\drivers\mbam.sys [1/3/2012 4:54 AM 20464]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\winnt\system32\drivers\nx6000.sys [1/20/2010 7:43 PM 30576]
S0 TfFsMon;TfFsMon;c:\winnt\system32\drivers\TfFsMon.sys –> c:\winnt\system32\drivers\TfFsMon.sys [?]
S0 TFSysMon;TfSysMon;c:\winnt\system32\drivers\TfSysMon.sys –> c:\winnt\system32\drivers\TfSysMon.sys [?]
S1 MpKslc414cb9b;MpKslc414cb9b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys [?]
S1 SuperMounter;SuperMounter; [x]
S2 mrtRate;mrtRate; [x]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\winnt\system32\DRIVERS\netaapl.sys –> c:\winnt\system32\DRIVERS\netaapl.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\winnt\system32\drivers\TfNetMon.sys –> c:\winnt\system32\drivers\TfNetMon.sys [?]
S3 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/12/2007 2:37 PM 24652]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\winnt\system32\Drivers\VMUVC.sys –> c:\winnt\system32\Drivers\VMUVC.sys [?]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\winnt\system32\drivers\vvftUVC.sys –> c:\winnt\system32\drivers\vvftUVC.sys [?]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-09 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-19 05:09]
.
2012-01-09 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-19 05:09]
.
2007-09-07 c:\winnt\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2007-02-05 23:52]
.
2012-01-10 c:\winnt\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 21:39]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
uStart Page = hxxp://www.rr.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
TCP: DhcpNameServer = [removed] [removed]
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: Yahoo! Chat - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 59636
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 600000
FF - user.js: nglayout.initialpaint.delay - 600
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Notify-opnlMdBU - (no file)
Notify-WRNotifier - (no file)
MSConfigStartUp-AOLDialer - c:\program files\Common Files\AOL\ACS\AOLDial.exe
MSConfigStartUp-HostManager - c:\program files\Common Files\AOL\1141465714\ee\AOLSoftware.exe
MSConfigStartUp-M0r2RXftX - ds3b2res.exe
MSConfigStartUp-msxct - msxct.exe
MSConfigStartUp-Symantec NetDriver Monitor - c:\progra~1\SYMNET~1\SNDMon.exe
MSConfigStartUp-istsvc - (no file)
AddRemove-AOL Uninstaller - c:\program files\Common Files\AOL\uninstaller.exe
AddRemove-DC++ - f:\program files\DC++\uninstall.exe
AddRemove-WinRAR archiver - c:\program files\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-09 18:42
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2036)
c:\winnt\system32\WININET.dll
c:\winnt\system32\ieframe.dll
c:\winnt\system32\webcheck.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\winnt\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\winnt\wanmpsvc.exe
.
**************************************************************************
.
Completion time: 2012-01-09 18:53:03 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-10 00:52
.
Pre-Run: 24,869,371,904 bytes free
Post-Run: 24,935,002,112 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - CB054CA466496F0868728C4798591FEA


—————————————————————————————————————————————

The problem is still present.
Hi WyandotteWyno,

Do you have any idea what the folders c:\program files\505B1 or c:\documents and settings\Owner\Application Data\F4250 are? They seem to have been created last Tuesday.

—-

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DirLook::
c:\program files\505B1
c:\documents and settings\Owner\Application Data\F4250
Firefox::
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 59636
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Admanager Controller]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Byqwdiza]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\G40ZeWMDF]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mdeaf9ej]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfAccuracy]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# L"h'þ9Óœð3rÅWC:]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# L"h'þ9Óœð3rÅWC:\Program Files]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# L"h'þ9Óœð3rÅWc:\program files\ISTsvc]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
I have the slightest idea what those folders are.



ComboFix 12-01-09.07 - Owner 01/10/2012 1:23.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.648 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-12-10 to 2012-01-10 )))))))))))))))))))))))))))))))
.
.
2012-01-10 00:40 . 2012-01-10 00:40 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\offreg.dll
2012-01-09 03:58 . 2012-01-09 03:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2012-01-08 12:09 . 2011-11-21 08:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\mpengine.dll
2012-01-06 04:04 . 2011-11-21 08:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-05 03:37 . 2010-10-19 20:51 222080 ——w- c:\winnt\system32\MpSigStub.exe
2012-01-05 03:31 . 2012-01-05 03:32 ——– d—–w- c:\program files\Microsoft Security Client
2012-01-03 10:54 . 2011-12-10 21:24 20464 —-a-w- c:\winnt\system32\drivers\mbam.sys
2012-01-03 10:54 . 2012-01-03 10:54 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-01-03 10:26 . 2012-01-03 11:11 ——– d—–w- c:\program files\505B1
2012-01-03 10:25 . 2012-01-03 11:11 ——– d—–w- c:\documents and settings\Owner\Application Data\F4250
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-29 03:24 . 2011-07-23 03:16 414368 —-a-w- c:\winnt\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25 . 1980-01-01 05:00 1859584 —-a-w- c:\winnt\system32\win32k.sys
2011-11-04 19:20 . 2004-02-06 23:05 916992 —-a-w- c:\winnt\system32\wininet.dll
2011-11-04 19:20 . 1980-01-01 05:00 43520 —-a-w- c:\winnt\system32\licmgr10.dll
2011-11-04 19:20 . 1980-01-01 05:00 1469440 —-a-w- c:\winnt\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 05:59 385024 —-a-w- c:\winnt\system32\html.iec
2011-11-01 16:07 . 2004-04-15 23:09 1288704 —-a-w- c:\winnt\system32\ole32.dll
2011-10-28 05:31 . 1980-01-01 05:00 33280 —-a-w- c:\winnt\system32\csrsrv.dll
2011-10-25 13:33 . 1980-01-01 05:00 2192768 —-a-w- c:\winnt\system32\ntoskrnl.exe
2011-10-25 12:52 . 2002-08-29 06:04 2069376 —-a-w- c:\winnt\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2002-11-26 19:15 186880 —-a-w- c:\winnt\system32\encdec.dll
2010-03-15 16:28 . 2010-05-01 01:37 52224 -c–a-w- c:\program files\RarExt64.dll
2010-03-15 16:28 . 2006-12-18 09:42 45056 -c–a-w- c:\program files\RarExtLoader.exe
2010-03-15 16:28 . 2010-05-01 01:37 141824 —-a-w- c:\program files\RarExt.dll
2010-03-15 16:28 . 2006-12-18 09:42 74240 -c–a-w- c:\program files\Zip.SFX
2010-03-15 16:28 . 2006-12-18 09:42 92672 -c–a-w- c:\program files\Default.SFX
2010-03-15 16:27 . 2006-12-18 09:42 69632 -c–a-w- c:\program files\WinCon.SFX
2010-03-15 16:26 . 2006-12-18 09:42 378880 -c–a-w- c:\program files\Rar.exe
2010-03-15 16:26 . 2006-12-18 09:42 246272 -c–a-w- c:\program files\UnRAR.exe
2010-03-15 16:26 . 2006-12-18 09:42 1039360 —-a-w- c:\program files\WinRAR.exe
2007-12-05 09:08 . 2007-12-05 09:08 1446464 -c–a-w- c:\program files\Silverlight.exe
2007-05-28 21:47 . 2008-06-01 23:56 626688 -c–a-w- c:\program files\msvcr80.dll
2007-05-28 21:47 . 2008-06-01 23:56 548864 -c–a-w- c:\program files\msvcp80.dll
2007-05-28 21:47 . 2008-06-01 23:56 479232 -c–a-w- c:\program files\msvcm80.dll
2007-05-28 21:47 . 2008-06-01 23:56 1030144 -c–a-w- c:\program files\dbghelp.dll
2011-11-15 00:45 . 2011-11-15 00:45 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\Owner\Application Data\F4250 —-
.
2012-01-03 10:25 . 2012-01-03 10:53 7035 —-a-w- c:\documents and settings\Owner\Application Data\F4250\05B1.425
.
—- Directory of c:\program files\505B1 —-
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fsproflt]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
backup=c:\winnt\pss\Billminder.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
backup=c:\winnt\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
backup=c:\winnt\pss\Quicken Startup.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2008-10-31 19:22 50480 —-a-w- c:\program files\AIM6\aim6.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-19 05:09 133104 —-atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-01-23 16:31 126976 -c–a-w- c:\winnt\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-01-23 16:36 155648 -c–a-w- c:\winnt\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-12-24 23:50 460872 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2005-10-12 23:13 7086080 —-a-w- c:\program files\MSN Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 16:17 421888 -c–a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KodakCCS"=2 (0x2)
"AOL ACS"=2 (0x2)
"ACDaemon"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" /background
"Aim6"="c:\program files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
"ctfmon.exe"=c:\winnt\system32\ctfmon.exe
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"AOLDialer"=c:\program files\Common Files\AOL\ACS\AOLDial.exe
"HostManager"="c:\program files\Common Files\AOL\1141465714\ee\AOLSoftware.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"MSConfig"=c:\winnt\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
"HP Software Update"=c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
"HPDJ Taskbar Utility"=c:\winnt\System32\spool\drivers\w32x86\3\hpztsb08.exe
"medicsp2"="c:\program files\twc\medicsp2\bin\sprtcmd.exe" /P medicsp2
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"HotKeysCmds"=c:\winnt\system32\hkcmd.exe
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\PnkBstrK.sys"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\WINNT\\system32\\spool\\drivers\\w32x86\\3\\E_DUPA30.EXE"=
"c:\\WINNT\\system32\\mmc.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2234:TCP"= 2234:TCP:Soulseek
"9420:TCP"= 9420:TCP:RSP
"1035:TCP"= 1035:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 SBRE;SBRE;c:\winnt\system32\drivers\SBREDrv.sys [2/10/2010 11:24 PM 95024]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/3/2012 4:54 AM 652872]
R3 MBAMProtector;MBAMProtector;c:\winnt\system32\drivers\mbam.sys [1/3/2012 4:54 AM 20464]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\winnt\system32\drivers\nx6000.sys [1/20/2010 7:43 PM 30576]
S0 TfFsMon;TfFsMon;c:\winnt\system32\drivers\TfFsMon.sys –> c:\winnt\system32\drivers\TfFsMon.sys [?]
S0 TFSysMon;TfSysMon;c:\winnt\system32\drivers\TfSysMon.sys –> c:\winnt\system32\drivers\TfSysMon.sys [?]
S1 MpKslc414cb9b;MpKslc414cb9b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys [?]
S1 SuperMounter;SuperMounter; [x]
S2 mrtRate;mrtRate; [x]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\winnt\system32\DRIVERS\netaapl.sys –> c:\winnt\system32\DRIVERS\netaapl.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\winnt\system32\drivers\TfNetMon.sys –> c:\winnt\system32\drivers\TfNetMon.sys [?]
S3 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/12/2007 2:37 PM 24652]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\winnt\system32\Drivers\VMUVC.sys –> c:\winnt\system32\Drivers\VMUVC.sys [?]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\winnt\system32\drivers\vvftUVC.sys –> c:\winnt\system32\drivers\vvftUVC.sys [?]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-09 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-19 05:09]
.
2012-01-10 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-19 05:09]
.
2007-09-07 c:\winnt\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2007-02-05 23:52]
.
2012-01-10 c:\winnt\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 21:39]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
uStart Page = hxxp://www.rr.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
TCP: DhcpNameServer = [removed] [removed]
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: Yahoo! Chat - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 600000
FF - user.js: nglayout.initialpaint.delay - 600
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-10 01:36
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3388)
c:\winnt\system32\WININET.dll
c:\winnt\system32\ieframe.dll
c:\winnt\system32\webcheck.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
Completion time: 2012-01-10 01:44:07
ComboFix-quarantined-files.txt 2012-01-10 07:44
ComboFix2.txt 2012-01-10 00:53
.
Pre-Run: 24,868,884,480 bytes free
Post-Run: 24,867,037,184 bytes free
.
- - End Of File - - 1F7221552CE2D75E4791E7A7D172BB7C
Open notepad and copy/paste the text in the code box below into it (including the URL, excluding "CODE"):

http://forums.whatthetech.com/index.php?showtopic=121892&st=0&p=767711&#entry767711

Collect::
c:\documents and settings\Owner\Application Data\F4250\05B1.425
Folder::
c:\documents and settings\Owner\Application Data\F4250
c:\program files\505B1

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Referring to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
—-

Does your problem still persist?
the problem is still present.

—————————————————————–

ComboFix 12-01-10.02 - Owner 01/10/2012 18:03:23.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.643 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript2.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
file zipped: c:\documents and settings\Owner\Application Data\F4250\05B1.425
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Owner\Application Data\F4250
c:\documents and settings\Owner\Application Data\F4250\05B1.425
c:\program files\505B1
.
.
((((((((((((((((((((((((( Files Created from 2011-12-11 to 2012-01-11 )))))))))))))))))))))))))))))))
.
.
2012-01-10 00:40 . 2012-01-11 00:18 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\offreg.dll
2012-01-09 03:58 . 2012-01-09 03:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2012-01-08 12:09 . 2011-11-21 08:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\mpengine.dll
2012-01-06 04:04 . 2011-11-21 08:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-05 03:37 . 2010-10-19 20:51 222080 ——w- c:\winnt\system32\MpSigStub.exe
2012-01-05 03:31 . 2012-01-05 03:32 ——– d—–w- c:\program files\Microsoft Security Client
2012-01-03 10:54 . 2011-12-10 21:24 20464 —-a-w- c:\winnt\system32\drivers\mbam.sys
2012-01-03 10:54 . 2012-01-03 10:54 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-29 03:24 . 2011-07-23 03:16 414368 —-a-w- c:\winnt\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25 . 1980-01-01 05:00 1859584 —-a-w- c:\winnt\system32\win32k.sys
2011-11-04 19:20 . 2004-02-06 23:05 916992 —-a-w- c:\winnt\system32\wininet.dll
2011-11-04 19:20 . 1980-01-01 05:00 43520 —-a-w- c:\winnt\system32\licmgr10.dll
2011-11-04 19:20 . 1980-01-01 05:00 1469440 —-a-w- c:\winnt\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 05:59 385024 —-a-w- c:\winnt\system32\html.iec
2011-11-01 16:07 . 2004-04-15 23:09 1288704 —-a-w- c:\winnt\system32\ole32.dll
2011-10-28 05:31 . 1980-01-01 05:00 33280 —-a-w- c:\winnt\system32\csrsrv.dll
2011-10-25 13:33 . 1980-01-01 05:00 2192768 —-a-w- c:\winnt\system32\ntoskrnl.exe
2011-10-25 12:52 . 2002-08-29 06:04 2069376 —-a-w- c:\winnt\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2002-11-26 19:15 186880 —-a-w- c:\winnt\system32\encdec.dll
2010-03-15 16:28 . 2010-05-01 01:37 52224 -c–a-w- c:\program files\RarExt64.dll
2010-03-15 16:28 . 2006-12-18 09:42 45056 -c–a-w- c:\program files\RarExtLoader.exe
2010-03-15 16:28 . 2010-05-01 01:37 141824 —-a-w- c:\program files\RarExt.dll
2010-03-15 16:28 . 2006-12-18 09:42 74240 -c–a-w- c:\program files\Zip.SFX
2010-03-15 16:28 . 2006-12-18 09:42 92672 -c–a-w- c:\program files\Default.SFX
2010-03-15 16:27 . 2006-12-18 09:42 69632 -c–a-w- c:\program files\WinCon.SFX
2010-03-15 16:26 . 2006-12-18 09:42 378880 -c–a-w- c:\program files\Rar.exe
2010-03-15 16:26 . 2006-12-18 09:42 246272 -c–a-w- c:\program files\UnRAR.exe
2010-03-15 16:26 . 2006-12-18 09:42 1039360 —-a-w- c:\program files\WinRAR.exe
2007-12-05 09:08 . 2007-12-05 09:08 1446464 -c–a-w- c:\program files\Silverlight.exe
2007-05-28 21:47 . 2008-06-01 23:56 626688 -c–a-w- c:\program files\msvcr80.dll
2007-05-28 21:47 . 2008-06-01 23:56 548864 -c–a-w- c:\program files\msvcp80.dll
2007-05-28 21:47 . 2008-06-01 23:56 479232 -c–a-w- c:\program files\msvcm80.dll
2007-05-28 21:47 . 2008-06-01 23:56 1030144 -c–a-w- c:\program files\dbghelp.dll
2011-11-15 00:45 . 2011-11-15 00:45 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-10_00.41.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-11 00:21 . 2012-01-11 00:21 16384 c:\winnt\Temp\Perflib_Perfdata_5a4.dat
+ 2012-01-11 00:19 . 2012-01-11 00:19 16384 c:\winnt\Temp\Perflib_Perfdata_4a4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fsproflt]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
backup=c:\winnt\pss\Billminder.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
backup=c:\winnt\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
backup=c:\winnt\pss\Quicken Startup.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2008-10-31 19:22 50480 —-a-w- c:\program files\AIM6\aim6.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-19 05:09 133104 —-atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-01-23 16:31 126976 -c–a-w- c:\winnt\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-01-23 16:36 155648 -c–a-w- c:\winnt\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-12-24 23:50 460872 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2005-10-12 23:13 7086080 —-a-w- c:\program files\MSN Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 16:17 421888 -c–a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KodakCCS"=2 (0x2)
"AOL ACS"=2 (0x2)
"ACDaemon"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" /background
"Aim6"="c:\program files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
"ctfmon.exe"=c:\winnt\system32\ctfmon.exe
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"AOLDialer"=c:\program files\Common Files\AOL\ACS\AOLDial.exe
"HostManager"="c:\program files\Common Files\AOL\1141465714\ee\AOLSoftware.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"MSConfig"=c:\winnt\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
"HP Software Update"=c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
"HPDJ Taskbar Utility"=c:\winnt\System32\spool\drivers\w32x86\3\hpztsb08.exe
"medicsp2"="c:\program files\twc\medicsp2\bin\sprtcmd.exe" /P medicsp2
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"HotKeysCmds"=c:\winnt\system32\hkcmd.exe
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\PnkBstrK.sys"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\WINNT\\system32\\spool\\drivers\\w32x86\\3\\E_DUPA30.EXE"=
"c:\\WINNT\\system32\\mmc.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2234:TCP"= 2234:TCP:Soulseek
"9420:TCP"= 9420:TCP:RSP
"1035:TCP"= 1035:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 SBRE;SBRE;c:\winnt\system32\drivers\SBREDrv.sys [2/10/2010 11:24 PM 95024]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/3/2012 4:54 AM 652872]
R3 MBAMProtector;MBAMProtector;c:\winnt\system32\drivers\mbam.sys [1/3/2012 4:54 AM 20464]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\winnt\system32\drivers\nx6000.sys [1/20/2010 7:43 PM 30576]
S0 TfFsMon;TfFsMon;c:\winnt\system32\drivers\TfFsMon.sys –> c:\winnt\system32\drivers\TfFsMon.sys [?]
S0 TFSysMon;TfSysMon;c:\winnt\system32\drivers\TfSysMon.sys –> c:\winnt\system32\drivers\TfSysMon.sys [?]
S1 MpKslc414cb9b;MpKslc414cb9b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys [?]
S1 SuperMounter;SuperMounter; [x]
S2 mrtRate;mrtRate; [x]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\winnt\system32\DRIVERS\netaapl.sys –> c:\winnt\system32\DRIVERS\netaapl.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\winnt\system32\drivers\TfNetMon.sys –> c:\winnt\system32\drivers\TfNetMon.sys [?]
S3 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/12/2007 2:37 PM 24652]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\winnt\system32\Drivers\VMUVC.sys –> c:\winnt\system32\Drivers\VMUVC.sys [?]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\winnt\system32\drivers\vvftUVC.sys –> c:\winnt\system32\drivers\vvftUVC.sys [?]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-10 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-19 05:09]
.
2012-01-10 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-19 05:09]
.
2007-09-07 c:\winnt\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2007-02-05 23:52]
.
2012-01-11 c:\winnt\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 21:39]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
uStart Page = hxxp://www.rr.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
TCP: DhcpNameServer = [removed] [removed]
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: Yahoo! Chat - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 59636
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 600000
FF - user.js: nglayout.initialpaint.delay - 600
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-10 18:21
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3332)
c:\winnt\system32\WININET.dll
c:\winnt\system32\ieframe.dll
c:\winnt\system32\webcheck.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\winnt\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\winnt\wanmpsvc.exe
.
**************************************************************************
.
Completion time: 2012-01-10 18:31:00 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-11 00:30
ComboFix2.txt 2012-01-10 07:44
ComboFix3.txt 2012-01-10 00:53
.
Pre-Run: 24,968,273,920 bytes free
Post-Run: 24,963,932,160 bytes free
.
- - End Of File - - F48E02B83719C51BBE6446AC0B652848
Upload was successful
Reset your Router:
  • This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
  • Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
  • If you don’t know the router's default password, you can look it up. HERE
  • You also need to reconfigure any security settings you had in place prior to the reset.
  • You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.
NEXT

Please download MiniToolBox, save it to your desktop and run it.

Place a checkmark in the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.


Note: When using the "Reset FF Proxy Settings" option, Firefox should be closed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI