This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Firefox proxy settings keep changing. [Solved]

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

MiniToolBox by Farbar Ran by [removed] (administrator) on 10-01-2012 at 23:25:35 Microsoft Windows XP Home Edition Service Pack 3 (X86) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= FF Proxy Settings: ============================== "network.proxy.http", "127.0.0.1" "network.proxy.http_port", 59636 "network.proxy.type", 0 "Reset FF Proxy Settings": Firefox Proxy settings were reset. ========================= Hosts content: ================================= 127.0.0.1 localhost ========================= IP Configuration: ================================ Intel® PRO/100 VE Network Connection = Local Area Connection (Connected) # ———————————- # Interface IP Configuration # ———————————- pushd interface ip # Interface IP Configuration for "Local Area Connection" set address name="Local Area Connection" source=dhcp set dns name="Local Area Connection" source=dhcp register=PRIMARY set wins name="Local Area Connection" source=dhcp popd # End of interface IP configuration Windows IP Configuration Host Name . . . . . . . . . . . . : YOUR-3B54ED6EDD Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : kc.rr.com Ethernet adapter Local Area Connection: Connection-specific DNS Suffix . : kc.rr.com Description . . . . . . . . . . . : Intel® PRO/100 VE Network Connection Physical Address. . . . . . . . . : 00-07-E9-43-8D-70 Dhcp Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes IP Address. . . . . . . . . . . . : [removed] Subnet Mask . . . . . . . . . . . : 255.255.224.0 IP Address. . . . . . . . . . . . : fe80::207:e9ff:fe43:8d70%4 Default Gateway . . . . . . . . . : [removed] DHCP Server . . . . . . . . . . . : [removed] DNS Servers . . . . . . . . . . . : [removed] 209.18.47.62 fec0:0:0:ffff::1%1 fec0:0:0:ffff::2%1 fec0:0:0:ffff::3%1 Lease Obtained. . . . . . . . . . : Tuesday, January 10, 2012 12:48:29 PM Lease Expires . . . . . . . . . . : Wednesday, January 11, 2012 12:33:53 AM Tunnel adapter Teredo Tunneling Pseudo-Interface: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : FF-FF-FF-FF-FF-FF-FF-FF Dhcp Enabled. . . . . . . . . . . : No IP Address. . . . . . . . . . . . : fe80::ffff:ffff:fffd%5 Default Gateway . . . . . . . . . : NetBIOS over Tcpip. . . . . . . . : Disabled Server: dns-cac-lb-01.rr.com Address: [removed] Name: google.com Addresses: 74.125.113.99, 74.125.113.103, 74.125.113.104, 74.125.113.105 74.125.113.106, 74.125.113.147 Pinging google.com [74.125.115.104] with 32 bytes of data: Reply from 74.125.115.104: bytes=32 time=62ms TTL=50 Reply from 74.125.115.104: bytes=32 time=59ms TTL=50 Ping statistics for 74.125.115.104: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 59ms, Maximum = 62ms, Average = 60ms Server: dns-cac-lb-01.rr.com Address: 209.18.47.61 Name: yahoo.com Addresses: 98.139.180.149, 209.191.122.70, 72.30.2.43, 98.137.149.56 Pinging yahoo.com [72.30.2.43] with 32 bytes of data: Reply from 72.30.2.43: bytes=32 time=91ms TTL=54 Reply from 72.30.2.43: bytes=32 time=91ms TTL=54 Ping statistics for 72.30.2.43: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 91ms, Maximum = 91ms, Average = 91ms Server: dns-cac-lb-01.rr.com Address: 209.18.47.61 Name: bleepingcomputer.com Address: 208.43.87.2 Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data: Reply from 208.43.87.2: Destination host unreachable. Reply from 208.43.87.2: Destination host unreachable. Ping statistics for 208.43.87.2: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 0x1 ……………………… MS TCP Loopback interface 0x2 …00 07 e9 43 8d 70 …… Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport =========================================================================== =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 [removed] [removed] 1 [removed] 255.255.224.0 [removed] [removed] 20 [removed] 255.255.255.255 127.0.0.1 127.0.0.1 20 [removed] 255.255.255.255 [removed] [removed] 20 127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1 169.254.0.0 255.255.0.0 [removed] [removed] 20 224.0.0.0 240.0.0.0 [removed] [removed] 20 255.255.255.255 255.255.255.255 [removed] [removed] 1 Default Gateway: [removed] =========================================================================== Persistent Routes: None ========================= Event log errors: =============================== Application errors: ================== Error: (01/10/2012 06:30:31 PM) (Source: MPSampleSubmission) (User: ) Description: EventType mptelemetry, P1 80080005, P2 beginsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1. Error: (01/09/2012 06:52:04 PM) (Source: MPSampleSubmission) (User: ) Description: EventType mptelemetry, P1 80080005, P2 beginsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1. Error: (01/09/2012 06:29:08 PM) (Source: MPSampleSubmission) (User: ) Description: EventType mptelemetry, P1 80080005, P2 beginsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1. Error: (01/08/2012 09:58:32 PM) (Source: MPSampleSubmission) (User: ) Description: EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1. Error: (01/04/2012 10:55:43 PM) (Source: MPSampleSubmission) (User: ) Description: EventType mptelemetry, P1 0, P2 moaccapability, P3 3.0.8402.0, P4 0, P5 0, P6 unspecified, P7 unspecified, P8 NIL, P9 mptelemetry0, P10 mptelemetry1. Error: (01/04/2012 09:43:02 PM) (Source: Application Hang) (User: ) Description: Hanging application msseces.exe, version 2.1.1116.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (01/04/2012 09:43:01 PM) (Source: Application Hang) (User: ) Description: Hanging application msseces.exe, version 2.1.1116.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (01/04/2012 09:43:01 PM) (Source: Application Hang) (User: ) Description: Hanging application msseces.exe, version 2.1.1116.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (01/04/2012 09:43:00 PM) (Source: Application Hang) (User: ) Description: Hanging application msseces.exe, version 2.1.1116.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (01/04/2012 09:43:00 PM) (Source: Application Hang) (User: ) Description: Hanging application msseces.exe, version 2.1.1116.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. System errors: ============= Error: (01/10/2012 06:30:29 PM) (Source: Microsoft Antimalware) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.117.2462.0 Update Source: %NT AUTHORITY59 Update Stage: 3.0.8402.00 Source Path: 3.0.8402.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (01/10/2012 06:30:29 PM) (Source: DCOM) (User: SYSTEM) Description: The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register with DCOM within the required timeout. Error: (01/10/2012 06:29:59 PM) (Source: Service Control Manager) (User: ) Description: The Automatic Updates service terminated with the following error: %%126 Error: (01/10/2012 06:29:59 PM) (Source: DCOM) (User: SYSTEM) Description: The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register with DCOM within the required timeout. Error: (01/10/2012 06:29:29 PM) (Source: Service Control Manager) (User: ) Description: The Automatic Updates service terminated with the following error: %%126 Error: (01/10/2012 06:20:57 PM) (Source: Service Control Manager) (User: ) Description: The following boot-start or system-start driver(s) failed to load: SuperMounter TfFsMon TFSysMon Error: (01/10/2012 06:20:57 PM) (Source: Service Control Manager) (User: ) Description: The MSCamSvc service hung on starting. Error: (01/10/2012 06:19:28 PM) (Source: Service Control Manager) (User: ) Description: The Automatic Updates service terminated with the following error: %%126 Error: (01/10/2012 06:19:28 PM) (Source: Service Control Manager) (User: ) Description: The mrtRate service failed to start due to the following error: %%2 Error: (01/09/2012 06:52:02 PM) (Source: Microsoft Antimalware) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.117.2462.0 Update Source: %NT AUTHORITY59 Update Stage: 3.0.8402.00 Source Path: 3.0.8402.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Microsoft Office Sessions: ========================= Error: (01/10/2012 06:30:31 PM) (Source: MPSampleSubmission)(User: ) Description: mptelemetry80080005beginsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL Error: (01/09/2012 06:52:04 PM) (Source: MPSampleSubmission)(User: ) Description: mptelemetry80080005beginsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL Error: (01/09/2012 06:29:08 PM) (Source: MPSampleSubmission)(User: ) Description: mptelemetry80080005beginsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL Error: (01/08/2012 09:58:32 PM) (Source: MPSampleSubmission)(User: ) Description: mptelemetry8024402cendsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL Error: (01/04/2012 10:55:43 PM) (Source: MPSampleSubmission)(User: ) Description: mptelemetry0moaccapability3.0.8402.000unspecifiedunspecifiedNILNILNIL Error: (01/04/2012 09:43:02 PM) (Source: Application Hang)(User: ) Description: msseces.exe2.1.1116.0hungapp0.0.0.000000000 Error: (01/04/2012 09:43:01 PM) (Source: Application Hang)(User: ) Description: msseces.exe2.1.1116.0hungapp0.0.0.000000000 Error: (01/04/2012 09:43:01 PM) (Source: Application Hang)(User: ) Description: msseces.exe2.1.1116.0hungapp0.0.0.000000000 Error: (01/04/2012 09:43:00 PM) (Source: Application Hang)(User: ) Description: msseces.exe2.1.1116.0hungapp0.0.0.000000000 Error: (01/04/2012 09:43:00 PM) (Source: Application Hang)(User: ) Description: msseces.exe2.1.1116.0hungapp0.0.0.000000000 =========================== Installed Programs ============================ Acrobat.com (Version: 0.0.0) Acrobat.com (Version: 1.1.377) Adobe AIR (Version: 1.0.4990) Adobe AIR (Version: 1.0.8.4990) Adobe Flash Player 10 ActiveX (Version: 10.0.32.18) Adobe Flash Player 11 Plugin (Version: 11.1.102.55) Adobe Reader 9.5.0 (Version: 9.5.0) Adobe Shockwave Player 11 (Version: 11) AIM 6 Ares 2.1.5 (Version: 2.1.5-Build#3039) Bonjour (Version: 2.0.3.0) EPSON NX400 User's Guide EPSON Scan EPSON Stylus NX400 Series Printer Uninstall HighMAT Extension to Microsoft Windows XP CD Writing Wizard (Version: 1.1.1905.1) HLPPDOCK (Version: 5.03.0000.0001) hp print screen utility Image Resizer Powertoy for Windows XP (Version: 1.00.0001) Intel® Extreme Graphics Driver Intel® PRO Network Adapters and Drivers Intel® PROSet (Version: 6.05.2001) InterActual Player IrfanView (remove only) Java™ 6 Update 17 (Version: 6.0.170) Java™ SE Runtime Environment 6 Update 1 (Version: 1.6.0.10) LTCM Client Malwarebytes Anti-Malware version 1.60.0.1800 (Version: 1.60.0.1800) Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729) Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft Antimalware (Version: 3.0.8402.2) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Corporation (Version: 9.1.0.0) Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft LifeCam (Version: 3.22.270.0) Microsoft National Language Support Downlevel APIs Microsoft Office PowerPoint Viewer 2003 (Version: 11.0.8305.0) Microsoft Security Client (Version: 2.1.1116.0) Microsoft Security Essentials (Version: 2.1.1116.0) Microsoft Silverlight (Version: 4.0.60831.0) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Windows Journal Viewer (Version: 1.5.2315.3) Microsoft Word 2002 (Version: 10.0.6626.0) Microsoft Works 2003 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word (Version: 2.0.0.0000) Mozilla Firefox 8.0 (x86 en-US) (Version: 8.0) MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) PC-Doctor for Windows PhotoParade Player Portraits Screen Saver QuickTime (Version: 7.68.75.0) RealPlayer Realtek AC'97 Audio (Version: 5.35) RealUpgrade 1.0 (Version: 1.0.0) Red Swoosh EDN Client (lol remove only) Segoe UI (Version: 14.0.4327.805) Skype™ 5.0 (Version: 5.0.152) Smart Link 56K Modem SopCast 3.2.4 (Version: 3.2.4) SoulSeek 157 NS 13c Symantec Network Drivers Update (Version: 5.4.3.11) Viewpoint Manager (Remove Only) Viewpoint Media Player Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01) WebFldrs XP (Version: 9.50.6513) Windows Defender Signatures (Version: 1.20.1459.12) Windows Genuine Advantage v1.3.0254.0 (Version: 1.3.0254.0) Windows Internet Explorer 8 (Version: 20090308.140743) Windows Live Call (Version: 14.0.8064.0206) Windows Live Communications Platform (Version: 14.0.8098.930) Windows Live Essentials (Version: 14.0.8089.0726) Windows Live Essentials (Version: 14.0.8089.726) Windows Live Sign-in Assistant (Version: 5.000.818.5) Windows Live Upload Tool (Version: 14.0.8014.1029) Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player Firefox Plugin (Version: 1.0.0.8) Windows Rights Management client (Version: 3.0.3281) Works Suite OS Pack (Version: 3.0.0.0000) X264 H.264/AVC Video Codec (remove only) Yahoo! Software Update yBook ========================= Memory info: =================================== Percentage of memory in use: 37% Total physical RAM: 1014.73 MB Available physical RAM: 629.3 MB Total Pagefile: 1920.96 MB Available Pagefile: 1632.47 MB Total Virtual: 2047.88 MB Available Virtual: 1973.13 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:37.27 GB) (Free:23.07 GB) NTFS ========================= Users: ======================================== User accounts for \\YOUR-3B54ED6EDD Administrator ASPNET Guest HelpAssistant Owner SUPPORT_388945a0 ========================= Minidump Files ================================== C:\WINNT\Minidump\Mini102411-01.dmp **** End of log ****
I regret to inform you that your machine is infected with a backdoor trojan. This type of malware is particularly nasty in that it aims to steal sensitive information from its victim. At the very least, I advise you to cease using all Internet banking websites, change passwords to all sites with sensitive information from a clean computer, and phone your bank to inform them that you may be a victim of identity theft. As the remote attacker has access to this machine, do NOT change your passwords or make any transactions on this computer. It may be prudent to backup your information, reformat, and reinstall, as when dealing with backdoor trojans there is no guarantee your computer will ever be completely clean, regardless of what the logs indicate.

If you opt to reformat, please let me know and I will guide you along the process. Otherwise, if you wish to carry out the disinfection, please continue with the following instructions.


You'll need a CD and a USB flashdrive that has some space on it. We will not be changing any of the data on the usb device just using it for a file.

You will also need to use FireFox to download a file as Internet Explorer seems to mangle the download.

If you have any problems with these steps please let me know. It may look complicated but it's fairly straight forward and for the most part automated.


Download GETxPUD.exe to your desktop
  • Run GETxPUD.exe by double clicking it.
  • A new folder will appear on the desktop.
  • Open the GETxPUD folder and click on the get&burn.bat
  • The program will download xpud_0.9.2.iso, and when finished, it will open BurnCDCC which will be ready to burn the image.
  • Click on Start and follow the prompts to burn the image to your CD

Using FireFox, please download and save dumpit to your usb device.

You may want to print out this part as you will not be able to view these instructions once booted with the CD you just made.
  • Leave the usb device attached to the computer
  • Now boot your computer with the CD you just burned
    • with the CD in the computer, restart the computer
  • The computer must be set to boot from the CD,depending on your computer you can either do this by pressing F12 and selecting the CD as the first boot option or it can be set in the BIOS
  • Once you have the computer set to boot from the CD allow it to boot
  • A Welcome to xPUD screen will appear
  • Click on File
  • Expand mnt
  • sda1,or sda2…usually corresponds to your HDD
  • sdb1 is likely your USB
  • Click on the folder that represents your USB drive (sdb1 ?)
    (you will be able to tell if it the right one as the screen will populate with your files)
  • Locate the file you downloaded and saved earlier, dumpit
  • double click it to run it
  • a black window will open, follow the instructions to close the window when it's finished
  • a file called MBR.zip should now be placed in the right hand panel
  • Click the Home icon at top
  • Remove the CD and click Power off
  • Click restart

Once the computer has rebooted open the usb device and attach the MBR.zip file to your next reply.
i downloaded dumpit and saved it to my usb drive, restarted the cpu with the cd and GETxPud started. i then clicked file, expanded mnt, selected sdbl and there was no dumpit file. yet when i checked under "my computer" for it it showed up as if it were on my usb drive. also when i restarted my cpu the file just disappears from the usb drive for some reason. what am I doing wrong?
If it is an option, reformat your USB drive. Grab a new copy of dumpit using Firefox and try again. Make sure your USB drive is inserted when you boot into xPUD. If the drive is still not being detected properly, try pulling it out and reinserting.
That sometimes happen with xPUD. We'll use Puppy Linux instead.

Please create this bootable CD.

  • Save these files to your Desktop
  • Open BurnCDCC and Extract All files to to its own folder
  • Double Click BurnCDCC
  • Click Browse and navigate to the Puppy Linux ISO file you just downloaded
  • click on it and click Open
  • IMPORTANT: Adjust the speed bar to CD: 4x DVD: 1x
  • Click Start
  • Your CD Burner Tray will open automatically
  • Insert a blank CD and close the tray
  • Click OK
The CD should eject when finished.

Download and save pldumpit.exe to your USB device.

To use the CD

  • Insert the CD and restart the computer
  • When the computer first starts please press the key indicated on the screen to enter the bios or setup.
  • Make the necessary changes to make the CD first in the boot order
  • Save the changes and exit the bios/setup
  • Your computer will restart and boot from the Puppy Linux Live CD
You can save these instructions to a notepad on your usb device. Once you have mounted the drives you should be able view them by clicking on them.

  • Set your language, time. etc preferences and continue
  • Click the Mount Icon located at the top left of your desktop (should be 3rd from the left top row)
  • A Window will open, click mount for each drive listed
  • if you have a USB Flash Drive connected it's usually automatically mounted upon boot, but click the "usbdrv" tab and make sure it is mounted.

In the lower left you will see some icons with a green light on them. Click on the one that represents your usb device.
  • locate pldumpit.exe
  • right click it and select rename
  • please remove only the .exe from the file path
  • click rename
  • click on pldumpit
  • a window will open please hit enter when told to to close the window
  • there should now be a file named mbr.zip in the list of files
  • close all windows
  • click menu
  • highlight shutdown
  • click reboot
  • use the arrow key to select Do not save
  • hit enter
  • remove the CD before the computer restarts and allow the computer to boot

Please attach MBR.zip to your next reply.
Hi,

I notice you have Spybot's TeaTimer on your computer. We have to make absolutely certain it is disabled before continuing. You can find guidelines on how to disable it HERE.

  • DDS

    Please download DDS and save it to your desktop.
    • Disable any script blocking protection
    • Double click dds.scr to run the tool.
    • When done, DDS.txt will open.
    • Click Yes at the next prompt for Optional Scan.
    • Save both reports to your desktop.
    —————————————————

    Please Please copy / paste the scan reults.

    DDS.txt

    Please attach the second file; Attach.txt. To attach a file, do the following:
    • Under the reply panel is the Attachments Panel
    • Browse for the attachment file you want to upload, then click the green Upload button
    • Once it has uploaded, click the Manage Current Attachments drop down box
    • Click on [external image: Posted Image] to insert the attachment into your post
  • GMER

    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Launch GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
      • IAT/EAT
      • All drives/partitions except C:\)
      • Show All (don't miss this one)
    • Then click the Scan button & wait for it to finish.
    • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
    • Save it where you can easily find it, such as your desktop, and attach it in your reply.
    **Caution**
    Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


  • TDSSKiller

    Please read carefully and follow these steps.

—-

Please describe in detail any oustanding issues you are experiencing.
. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 13:37:46.20 on Sun 01/15/2012 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.453 [GMT -6:00] . AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . C:\WINNT\system32\svchost.exe -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\WINNT\system32\svchost.exe -k WudfServiceGroup C:\WINNT\System32\svchost.exe -k netsvcs C:\WINNT\System32\svchost.exe -k NetworkService C:\WINNT\Explorer.EXE svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\WINNT\System32\svchost.exe -k imgsvc C:\WINNT\wanmpsvc.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINNT\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Owner\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7 uStart Page = hxxp://www.rr.com/ uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRunOnce: [RunNarrator] Narrator.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe DPF: DirectAnimation Java Classes DPF: Microsoft XML Parser for Java DPF: Yahoo! Chat - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab DPF: Yahoo! MahJong Solitaire - hxxp://download.games.yahoo.com/games/clients/y/mjst4_x.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://dcode.support.microsoft.com/dcode/ActiveX/MSDcode.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199318644546 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\hk5tj3jo.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;= FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 59636 FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll . —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.notify.interval - 600000 FF - user.js: content.switch.threshold - 600000 FF - user.js: nglayout.initialpaint.delay - 600 . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\winnt\system32\drivers\MpFilter.sys [2011-4-18 165648] R1 MpKslaf23d29b;MpKslaf23d29b;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{39f5d8b1-72a1-4f15-8f75-9ba4f51ad7b5}\MpKslaf23d29b.sys [2012-1-14 29904] R1 SBRE;SBRE;c:\winnt\system32\drivers\SBREDrv.sys [2010-2-10 95024] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-1-3 652872] R3 MBAMProtector;MBAMProtector;c:\winnt\system32\drivers\mbam.sys [2012-1-3 20464] R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\winnt\system32\drivers\nx6000.sys [2010-1-20 30576] S0 TfFsMon;TfFsMon;c:\winnt\system32\drivers\tffsmon.sys –> c:\winnt\system32\drivers\TfFsMon.sys [?] S0 TFSysMon;TfSysMon;c:\winnt\system32\drivers\tfsysmon.sys –> c:\winnt\system32\drivers\TfSysMon.sys [?] S1 MpKslc414cb9b;MpKslc414cb9b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{54e79fd9-7fe8-46fd-b13d-e63b75aaa7c6}\mpkslc414cb9b.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{54e79fd9-7fe8-46fd-b13d-e63b75aaa7c6}\MpKslc414cb9b.sys [?] S1 SuperMounter;SuperMounter; [x] S2 mrtRate;mrtRate; [x] S3 Netaapl;Apple Mobile Device Ethernet Service;c:\winnt\system32\drivers\netaapl.sys –> c:\winnt\system32\drivers\netaapl.sys [?] S3 TfNetMon;TfNetMon;\??\c:\winnt\system32\drivers\tfnetmon.sys –> c:\winnt\system32\drivers\TfNetMon.sys [?] S3 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-2-12 24652] S3 VMUVC;Vimicro Camera Service VMUVC;c:\winnt\system32\drivers\vmuvc.sys –> c:\winnt\system32\drivers\VMUVC.sys [?] S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\winnt\system32\drivers\vvftuvc.sys –> c:\winnt\system32\drivers\vvftUVC.sys [?] S4 aawservice;Ad-Aware 2007 Service; [x] . =============== Created Last 30 ================ . 2012-01-14 20:51:13 29904 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{39f5d8b1-72a1-4f15-8f75-9ba4f51ad7b5}\MpKslaf23d29b.sys 2012-01-14 20:51:03 56200 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{39f5d8b1-72a1-4f15-8f75-9ba4f51ad7b5}\offreg.dll 2012-01-14 04:23:07 6823496 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{39f5d8b1-72a1-4f15-8f75-9ba4f51ad7b5}\mpengine.dll 2012-01-14 04:23:04 ——– dc—-w- C:\c1d7fc001171605dddde 2012-01-10 00:04:49 ——– dcsha-r- C:\cmdcons 2012-01-10 00:01:05 98816 —-a-w- c:\winnt\sed.exe 2012-01-10 00:01:05 518144 —-a-w- c:\winnt\SWREG.exe 2012-01-10 00:01:05 256000 —-a-w- c:\winnt\PEV.exe 2012-01-10 00:01:05 208896 —-a-w- c:\winnt\MBR.exe 2012-01-06 04:04:53 6823496 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2012-01-05 03:37:25 222080 ——w- c:\winnt\system32\MpSigStub.exe 2012-01-05 03:31:54 ——– d—–w- c:\program files\Microsoft Security Client 2012-01-03 14:22:02 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2012-01-03 14:22:02 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2012-01-03 10:54:11 20464 —-a-w- c:\winnt\system32\drivers\mbam.sys 2012-01-03 10:54:10 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware . ==================== Find3M ==================== . 2011-11-29 03:24:24 414368 —-a-w- c:\winnt\system32\FlashPlayerCPLApp.cpl 2011-11-23 13:25:32 1859584 —-a-w- c:\winnt\system32\win32k.sys 2011-11-04 19:20:51 916992 —-a-w- c:\winnt\system32\wininet.dll 2011-11-04 19:20:51 43520 —-a-w- c:\winnt\system32\licmgr10.dll 2011-11-04 19:20:51 1469440 —-a-w- c:\winnt\system32\inetcpl.cpl 2011-11-04 11:23:59 385024 —-a-w- c:\winnt\system32\html.iec 2011-11-01 16:07:10 1288704 —-a-w- c:\winnt\system32\ole32.dll 2011-10-28 05:31:48 33280 —-a-w- c:\winnt\system32\csrsrv.dll 2011-10-25 13:33:08 2192768 —-a-w- c:\winnt\system32\ntoskrnl.exe 2011-10-25 12:52:03 2069376 —-a-w- c:\winnt\system32\ntkrnlpa.exe 2011-10-18 11:13:22 186880 —-a-w- c:\winnt\system32\encdec.dll 2010-03-15 16:28:25 52224 -c–a-w- c:\program files\RarExt64.dll 2010-03-15 16:28:23 45056 -c–a-w- c:\program files\RarExtLoader.exe 2010-03-15 16:28:22 141824 —-a-w- c:\program files\RarExt.dll 2010-03-15 16:28:03 74240 -c–a-w- c:\program files\Zip.SFX 2010-03-15 16:28:02 92672 -c–a-w- c:\program files\Default.SFX 2010-03-15 16:27:00 69632 -c–a-w- c:\program files\WinCon.SFX 2010-03-15 16:26:53 378880 -c–a-w- c:\program files\Rar.exe 2010-03-15 16:26:53 246272 -c–a-w- c:\program files\UnRAR.exe 2010-03-15 16:26:37 1039360 —-a-w- c:\program files\WinRAR.exe 2007-12-05 09:08:43 1446464 -c–a-w- c:\program files\Silverlight.exe 2007-05-28 21:47:38 626688 -c–a-w- c:\program files\msvcr80.dll 2007-05-28 21:47:38 548864 -c–a-w- c:\program files\msvcp80.dll 2007-05-28 21:47:38 479232 -c–a-w- c:\program files\msvcm80.dll 2007-05-28 21:47:38 1030144 -c–a-w- c:\program files\dbghelp.dll . ============= FINISH: 13:38:45.45 =============== 15:48:59.0343 2044 TDSS rootkit removing tool 2.7.1.0 Jan 13 2012 15:24:05 15:48:59.0750 2044 ============================================================ 15:48:59.0750 2044 Current date / time: 2012/01/15 15:48:59.0750 15:48:59.0750 2044 SystemInfo: 15:48:59.0750 2044 15:48:59.0750 2044 OS Version: 5.1.2600 ServicePack: 3.0 15:48:59.0750 2044 Product type: Workstation 15:48:59.0750 2044 ComputerName: YOUR-3B54ED6EDD 15:48:59.0750 2044 UserName: Owner 15:48:59.0750 2044 Windows directory: C:\WINNT 15:48:59.0750 2044 System windows directory: C:\WINNT 15:48:59.0750 2044 Processor architecture: Intel x86 15:48:59.0750 2044 Number of processors: 1 15:48:59.0750 2044 Page size: 0x1000 15:48:59.0750 2044 Boot type: Normal boot 15:48:59.0750 2044 ============================================================ 15:49:02.0437 2044 Drive \Device\Harddisk0\DR0 - Size: 0x9516AE000, SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K', Flags 0x00000054 15:49:02.0578 2044 Initialize success 15:49:31.0171 2596 ============================================================ 15:49:31.0171 2596 Scan started 15:49:31.0171 2596 Mode: Manual; 15:49:31.0171 2596 ============================================================ 15:49:31.0687 2596 Abiosdsk - ok 15:49:31.0968 2596 abp480n5 - ok 15:49:32.0296 2596 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINNT\system32\drivers\ac97intc.sys 15:49:32.0328 2596 ac97intc - ok 15:49:32.0734 2596 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINNT\system32\DRIVERS\ACPI.sys 15:49:32.0734 2596 ACPI - ok 15:49:33.0093 2596 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINNT\system32\drivers\ACPIEC.sys 15:49:33.0093 2596 ACPIEC - ok 15:49:33.0437 2596 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINNT\system32\DRIVERS\adpu160m.sys 15:49:33.0437 2596 adpu160m - ok 15:49:33.0828 2596 aec (8bed39e3c35d6a489438b8141717a557) C:\WINNT\system32\drivers\aec.sys 15:49:33.0875 2596 aec - ok 15:49:34.0421 2596 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINNT\System32\drivers\afd.sys 15:49:34.0421 2596 AFD - ok 15:49:34.0796 2596 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINNT\system32\DRIVERS\agp440.sys 15:49:34.0796 2596 agp440 - ok 15:49:35.0125 2596 Aha154x - ok 15:49:35.0390 2596 aic78u2 - ok 15:49:35.0656 2596 aic78xx - ok 15:49:37.0375 2596 ALCXWDM (8e100402761df99e6a432bf31a8331d3) C:\WINNT\system32\drivers\ALCXWDM.SYS 15:49:37.0437 2596 ALCXWDM - ok 15:49:37.0765 2596 AliIde - ok 15:49:38.0031 2596 amsint - ok 15:49:38.0312 2596 asc - ok 15:49:38.0562 2596 asc3350p - ok 15:49:38.0828 2596 asc3550 - ok 15:49:39.0156 2596 Aspi32 (b979979ab8027f7f53fb16ec4229b7db) C:\WINNT\system32\drivers\Aspi32.sys 15:49:39.0156 2596 Aspi32 - ok 15:49:39.0531 2596 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINNT\system32\DRIVERS\asyncmac.sys 15:49:39.0546 2596 AsyncMac - ok 15:49:39.0921 2596 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINNT\system32\DRIVERS\atapi.sys 15:49:39.0921 2596 atapi - ok 15:49:40.0234 2596 Atdisk - ok 15:49:40.0546 2596 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINNT\system32\DRIVERS\atmarpc.sys 15:49:40.0578 2596 Atmarpc - ok 15:49:40.0984 2596 ATWPKT2 - ok 15:49:41.0343 2596 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINNT\system32\DRIVERS\audstub.sys 15:49:41.0343 2596 audstub - ok 15:49:41.0687 2596 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINNT\system32\drivers\Beep.sys 15:49:41.0687 2596 Beep - ok 15:49:41.0703 2596 catchme - ok 15:49:42.0015 2596 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINNT\system32\drivers\cbidf2k.sys 15:49:42.0015 2596 cbidf2k - ok 15:49:42.0484 2596 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINNT\system32\DRIVERS\CCDECODE.sys 15:49:42.0500 2596 CCDECODE - ok 15:49:42.0828 2596 cd20xrnt - ok 15:49:43.0125 2596 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINNT\system32\drivers\Cdaudio.sys 15:49:43.0140 2596 Cdaudio - ok 15:49:43.0484 2596 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINNT\system32\drivers\Cdfs.sys 15:49:43.0484 2596 Cdfs - ok 15:49:43.0843 2596 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINNT\system32\DRIVERS\cdrom.sys 15:49:43.0843 2596 Cdrom - ok 15:49:44.0171 2596 Changer - ok 15:49:44.0468 2596 CmdIde - ok 15:49:44.0843 2596 Cpqarray - ok 15:49:45.0109 2596 dac2w2k - ok 15:49:45.0375 2596 dac960nt - ok 15:49:45.0718 2596 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINNT\system32\DRIVERS\disk.sys 15:49:45.0718 2596 Disk - ok 15:49:46.0359 2596 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINNT\system32\drivers\dmboot.sys 15:49:46.0625 2596 dmboot - ok 15:49:47.0078 2596 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINNT\system32\drivers\dmio.sys 15:49:47.0125 2596 dmio - ok 15:49:47.0546 2596 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINNT\system32\drivers\dmload.sys 15:49:47.0546 2596 dmload - ok 15:49:47.0859 2596 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINNT\system32\drivers\DMusic.sys 15:49:47.0875 2596 DMusic - ok 15:49:48.0234 2596 dpti2o - ok 15:49:48.0546 2596 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINNT\system32\drivers\drmkaud.sys 15:49:48.0562 2596 drmkaud - ok 15:49:48.0953 2596 E100B (ac9cf17ee2ae003c98eb4f5336c38058) C:\WINNT\system32\DRIVERS\e100b325.sys 15:49:48.0953 2596 E100B - ok 15:49:49.0437 2596 Fastfat (38d332a6d56af32635675f132548343e) C:\WINNT\system32\drivers\Fastfat.sys 15:49:49.0437 2596 Fastfat - ok 15:49:49.0812 2596 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINNT\system32\DRIVERS\fdc.sys 15:49:49.0812 2596 Fdc - ok 15:49:50.0218 2596 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINNT\system32\drivers\Fips.sys 15:49:50.0218 2596 Fips - ok 15:49:50.0609 2596 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINNT\system32\DRIVERS\flpydisk.sys 15:49:50.0609 2596 Flpydisk - ok 15:49:51.0109 2596 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINNT\system32\drivers\fltmgr.sys 15:49:51.0109 2596 FltMgr - ok 15:49:51.0484 2596 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINNT\system32\drivers\Fs_Rec.sys 15:49:51.0484 2596 Fs_Rec - ok 15:49:51.0906 2596 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINNT\system32\DRIVERS\ftdisk.sys 15:49:51.0906 2596 Ftdisk - ok 15:49:52.0343 2596 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINNT\system32\DRIVERS\msgpc.sys 15:49:52.0343 2596 Gpc - ok 15:49:52.0718 2596 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINNT\system32\DRIVERS\hidusb.sys 15:49:52.0718 2596 HidUsb - ok 15:49:53.0031 2596 hpn - ok 15:49:53.0484 2596 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINNT\system32\Drivers\HTTP.sys 15:49:53.0484 2596 HTTP - ok 15:49:53.0828 2596 i2omgmt - ok 15:49:54.0093 2596 i2omp - ok 15:49:54.0437 2596 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINNT\system32\DRIVERS\i8042prt.sys 15:49:54.0437 2596 i8042prt - ok 15:49:54.0984 2596 ialm (737da0be27652c4482ac5cde099bfce9) C:\WINNT\system32\DRIVERS\ialmnt5.sys 15:49:54.0984 2596 ialm - ok 15:49:55.0421 2596 iaStor (18e3972d9632485d80d609d4674f9d83) C:\WINNT\system32\DRIVERS\iaStor.sys 15:49:55.0437 2596 iaStor - ok 15:49:55.0828 2596 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINNT\system32\DRIVERS\imapi.sys 15:49:55.0828 2596 Imapi - ok 15:49:56.0234 2596 ini910u - ok 15:49:56.0546 2596 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINNT\system32\DRIVERS\intelide.sys 15:49:56.0546 2596 IntelIde - ok 15:49:56.0906 2596 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINNT\system32\DRIVERS\intelppm.sys 15:49:56.0921 2596 intelppm - ok 15:49:57.0296 2596 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINNT\system32\drivers\ip6fw.sys 15:49:57.0296 2596 Ip6Fw - ok 15:49:57.0640 2596 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINNT\system32\DRIVERS\ipfltdrv.sys 15:49:57.0656 2596 IpFilterDriver - ok 15:49:57.0968 2596 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINNT\system32\DRIVERS\ipinip.sys 15:49:57.0984 2596 IpInIp - ok 15:49:58.0406 2596 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINNT\system32\DRIVERS\ipnat.sys 15:49:58.0406 2596 IpNat - ok 15:49:58.0781 2596 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINNT\system32\DRIVERS\ipsec.sys 15:49:58.0781 2596 IPSec - ok 15:49:59.0140 2596 IPVNMon (f60af0f89204a9177d110e3b2bd9fa0b) C:\WINNT\system32\drivers\IPVNMon.sys 15:49:59.0140 2596 IPVNMon - ok 15:49:59.0531 2596 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINNT\system32\DRIVERS\irenum.sys 15:49:59.0531 2596 IRENUM - ok 15:49:59.0921 2596 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINNT\system32\DRIVERS\isapnp.sys 15:49:59.0921 2596 isapnp - ok 15:50:00.0328 2596 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINNT\system32\DRIVERS\kbdclass.sys 15:50:00.0328 2596 Kbdclass - ok 15:50:00.0718 2596 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINNT\system32\DRIVERS\kbdhid.sys 15:50:00.0718 2596 kbdhid - ok 15:50:01.0156 2596 kmixer (692bcf44383d056aed41b045a323d378) C:\WINNT\system32\drivers\kmixer.sys 15:50:01.0156 2596 kmixer - ok 15:50:01.0656 2596 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINNT\system32\drivers\KSecDD.sys 15:50:01.0656 2596 KSecDD - ok 15:50:01.0984 2596 lbrtfdc - ok 15:50:02.0312 2596 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINNT\system32\drivers\mbam.sys 15:50:02.0312 2596 MBAMProtector - ok 15:50:02.0656 2596 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINNT\system32\drivers\mnmdd.sys 15:50:02.0656 2596 mnmdd - ok 15:50:02.0968 2596 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINNT\system32\drivers\Modem.sys 15:50:02.0968 2596 Modem - ok 15:50:03.0343 2596 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINNT\system32\DRIVERS\mouclass.sys 15:50:03.0343 2596 Mouclass - ok 15:50:03.0687 2596 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINNT\system32\DRIVERS\mouhid.sys 15:50:03.0703 2596 mouhid - ok 15:50:04.0078 2596 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINNT\system32\drivers\MountMgr.sys 15:50:04.0078 2596 MountMgr - ok 15:50:04.0500 2596 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINNT\system32\DRIVERS\MpFilter.sys 15:50:04.0531 2596 MpFilter - ok 15:50:04.0734 2596 MpKslaf23d29b (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39F5D8B1-72A1-4F15-8F75-9BA4F51AD7B5}\MpKslaf23d29b.sys 15:50:04.0734 2596 MpKslaf23d29b - ok 15:50:04.0765 2596 MpKslc414cb9b - ok 15:50:05.0421 2596 mraid35x - ok 15:50:05.0734 2596 mrtRate - ok 15:50:06.0140 2596 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINNT\system32\DRIVERS\mrxdav.sys 15:50:06.0203 2596 MRxDAV - ok 15:50:06.0718 2596 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINNT\system32\DRIVERS\mrxsmb.sys 15:50:06.0734 2596 MRxSmb - ok 15:50:07.0109 2596 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINNT\system32\drivers\Msfs.sys 15:50:07.0109 2596 Msfs - ok 15:50:07.0484 2596 MSHUSBVideo (5119ffc2a6b51089cdb0efdc75808c97) C:\WINNT\system32\Drivers\nx6000.sys 15:50:07.0484 2596 MSHUSBVideo - ok 15:50:07.0843 2596 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINNT\system32\drivers\MSKSSRV.sys 15:50:07.0843 2596 MSKSSRV - ok 15:50:08.0265 2596 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINNT\system32\drivers\MSPCLOCK.sys 15:50:08.0281 2596 MSPCLOCK - ok 15:50:08.0656 2596 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINNT\system32\drivers\MSPQM.sys 15:50:08.0656 2596 MSPQM - ok 15:50:09.0015 2596 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINNT\system32\DRIVERS\mssmbios.sys 15:50:09.0031 2596 mssmbios - ok 15:50:09.0406 2596 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINNT\system32\drivers\MSTEE.sys 15:50:09.0406 2596 MSTEE - ok 15:50:09.0812 2596 Mtlmnt5 (8bc576bf81628ad9b03621bd381eb3c8) C:\WINNT\system32\DRIVERS\Mtlmnt5.sys 15:50:09.0812 2596 Mtlmnt5 - ok 15:50:10.0578 2596 Mtlstrm (b5f8b93fa9556a371f20721c80b70cd3) C:\WINNT\system32\DRIVERS\Mtlstrm.sys 15:50:11.0031 2596 Mtlstrm - ok 15:50:11.0484 2596 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINNT\system32\drivers\Mup.sys 15:50:11.0484 2596 Mup - ok 15:50:11.0859 2596 MxlW2k (88f57a15b786bf2af9458f7903768085) C:\WINNT\system32\drivers\MxlW2k.sys 15:50:11.0859 2596 MxlW2k - ok 15:50:12.0265 2596 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINNT\system32\DRIVERS\NABTSFEC.sys 15:50:12.0296 2596 NABTSFEC - ok 15:50:12.0734 2596 NDIS (1df7f42665c94b825322fae71721130d) C:\WINNT\system32\drivers\NDIS.sys 15:50:12.0734 2596 NDIS - ok 15:50:13.0078 2596 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINNT\system32\DRIVERS\NdisIP.sys 15:50:13.0078 2596 NdisIP - ok 15:50:13.0453 2596 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINNT\system32\DRIVERS\ndistapi.sys 15:50:13.0453 2596 NdisTapi - ok 15:50:13.0812 2596 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINNT\system32\DRIVERS\ndisuio.sys 15:50:13.0812 2596 Ndisuio - ok 15:50:14.0203 2596 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINNT\system32\DRIVERS\ndiswan.sys 15:50:14.0203 2596 NdisWan - ok 15:50:14.0593 2596 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINNT\system32\drivers\NDProxy.sys 15:50:14.0593 2596 NDProxy - ok 15:50:14.0937 2596 Netaapl - ok 15:50:15.0281 2596 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINNT\system32\DRIVERS\netbios.sys 15:50:15.0281 2596 NetBIOS - ok 15:50:15.0703 2596 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINNT\system32\DRIVERS\netbt.sys 15:50:15.0703 2596 NetBT - ok 15:50:16.0187 2596 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINNT\system32\drivers\Npfs.sys 15:50:16.0187 2596 Npfs - ok 15:50:16.0765 2596 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINNT\system32\drivers\Ntfs.sys 15:50:16.0781 2596 Ntfs - ok 15:50:17.0203 2596 NtMtlFax (d4c9a61408da38652267648d51739fdb) C:\WINNT\system32\DRIVERS\NtMtlFax.sys 15:50:17.0265 2596 NtMtlFax - ok 15:50:17.0609 2596 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINNT\system32\drivers\Null.sys 15:50:17.0609 2596 Null - ok 15:50:18.0546 2596 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINNT\system32\DRIVERS\nv4_mini.sys 15:50:19.0250 2596 nv - ok 15:50:19.0609 2596 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINNT\system32\DRIVERS\nwlnkflt.sys 15:50:19.0609 2596 NwlnkFlt - ok 15:50:19.0890 2596 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINNT\system32\DRIVERS\nwlnkfwd.sys 15:50:19.0906 2596 NwlnkFwd - ok 15:50:20.0265 2596 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINNT\system32\DRIVERS\parport.sys 15:50:20.0265 2596 Parport - ok 15:50:20.0625 2596 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINNT\system32\drivers\PartMgr.sys 15:50:20.0640 2596 PartMgr - ok 15:50:20.0953 2596 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINNT\system32\drivers\ParVdm.sys 15:50:20.0953 2596 ParVdm - ok 15:50:21.0312 2596 PCI (a219903ccf74233761d92bef471a07b1) C:\WINNT\system32\DRIVERS\pci.sys 15:50:21.0328 2596 PCI - ok 15:50:21.0625 2596 PCIDump - ok 15:50:21.0921 2596 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINNT\system32\DRIVERS\pciide.sys 15:50:21.0921 2596 PCIIde - ok 15:50:22.0343 2596 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINNT\system32\drivers\Pcmcia.sys 15:50:22.0390 2596 Pcmcia - ok 15:50:22.0718 2596 PDCOMP - ok 15:50:23.0000 2596 PDFRAME - ok 15:50:23.0265 2596 PDRELI - ok 15:50:23.0531 2596 PDRFRAME - ok 15:50:23.0796 2596 perc2 - ok 15:50:24.0062 2596 perc2hib - ok 15:50:24.0406 2596 Point32 (dcdf0421a1c14f2923e298a30fd7636d) C:\WINNT\system32\DRIVERS\point32.sys 15:50:24.0406 2596 Point32 - ok 15:50:24.0781 2596 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINNT\system32\DRIVERS\raspptp.sys 15:50:24.0781 2596 PptpMiniport - ok 15:50:25.0125 2596 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINNT\system32\DRIVERS\processr.sys 15:50:25.0140 2596 Processor - ok 15:50:25.0562 2596 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINNT\system32\DRIVERS\psched.sys 15:50:25.0562 2596 PSched - ok 15:50:25.0906 2596 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINNT\system32\DRIVERS\ptilink.sys 15:50:25.0906 2596 Ptilink - ok 15:50:26.0312 2596 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINNT\system32\DRIVERS\PxHelp20.sys 15:50:26.0312 2596 PxHelp20 - ok 15:50:26.0625 2596 ql1080 - ok 15:50:26.0890 2596 Ql10wnt - ok 15:50:27.0140 2596 ql12160 - ok 15:50:27.0421 2596 ql1240 - ok 15:50:27.0687 2596 ql1280 - ok 15:50:27.0984 2596 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINNT\system32\DRIVERS\rasacd.sys 15:50:27.0984 2596 RasAcd - ok 15:50:28.0359 2596 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINNT\system32\DRIVERS\rasl2tp.sys 15:50:28.0359 2596 Rasl2tp - ok 15:50:28.0734 2596 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINNT\system32\DRIVERS\raspppoe.sys 15:50:28.0750 2596 RasPppoe - ok 15:50:29.0062 2596 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINNT\system32\DRIVERS\raspti.sys 15:50:29.0062 2596 Raspti - ok 15:50:29.0515 2596 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINNT\system32\DRIVERS\rdbss.sys 15:50:29.0515 2596 Rdbss - ok 15:50:29.0843 2596 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINNT\system32\DRIVERS\RDPCDD.sys 15:50:29.0859 2596 RDPCDD - ok 15:50:30.0218 2596 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINNT\system32\drivers\RDPWD.sys 15:50:30.0265 2596 RDPWD - ok 15:50:30.0656 2596 RecAgent (e9aaa0092d74a9d371659c4c38882e12) C:\WINNT\System32\DRIVERS\RecAgent.sys 15:50:30.0656 2596 RecAgent - ok 15:50:31.0031 2596 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINNT\system32\DRIVERS\redbook.sys 15:50:31.0031 2596 redbook - ok 15:50:31.0484 2596 SBRE (4019149e4e296072831c8855605d9fdc) C:\WINNT\system32\drivers\SBREdrv.sys 15:50:31.0484 2596 SBRE - ok 15:50:31.0875 2596 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINNT\system32\DRIVERS\secdrv.sys 15:50:31.0875 2596 Secdrv - ok 15:50:32.0296 2596 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINNT\system32\DRIVERS\serenum.sys 15:50:32.0296 2596 serenum - ok 15:50:32.0656 2596 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINNT\system32\DRIVERS\serial.sys 15:50:32.0656 2596 Serial - ok 15:50:33.0031 2596 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINNT\system32\drivers\Sfloppy.sys 15:50:33.0031 2596 Sfloppy - ok 15:50:33.0375 2596 Simbad - ok 15:50:33.0671 2596 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINNT\system32\DRIVERS\SLIP.sys 15:50:33.0687 2596 SLIP - ok 15:50:34.0171 2596 Slntamr (9d3805cbf16056359a52dfb37a71aa49) C:\WINNT\system32\DRIVERS\slntamr.sys 15:50:34.0171 2596 Slntamr - ok 15:50:34.0593 2596 SlNtHal (0f3536110d1027e8bb07e0adb9058039) C:\WINNT\system32\DRIVERS\Slnthal.sys 15:50:34.0625 2596 SlNtHal - ok 15:50:35.0000 2596 SlWdmSup (3b4a3b282f62fe5d75127d22b26909ed) C:\WINNT\system32\DRIVERS\SlWdmSup.sys 15:50:35.0000 2596 SlWdmSup - ok 15:50:35.0343 2596 Sparrow - ok 15:50:35.0656 2596 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINNT\system32\drivers\splitter.sys 15:50:35.0656 2596 splitter - ok 15:50:36.0031 2596 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINNT\system32\DRIVERS\sr.sys 15:50:36.0031 2596 sr - ok 15:50:36.0484 2596 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINNT\system32\DRIVERS\srv.sys 15:50:36.0500 2596 Srv - ok 15:50:36.0859 2596 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINNT\system32\DRIVERS\StreamIP.sys 15:50:36.0859 2596 streamip - ok 15:50:37.0218 2596 SuperMounter - ok 15:50:37.0531 2596 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINNT\system32\DRIVERS\swenum.sys 15:50:37.0531 2596 swenum - ok 15:50:37.0875 2596 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINNT\system32\drivers\swmidi.sys 15:50:37.0890 2596 swmidi - ok 15:50:38.0218 2596 symc810 - ok 15:50:38.0484 2596 symc8xx - ok 15:50:38.0750 2596 sym_hi - ok 15:50:39.0015 2596 sym_u3 - ok 15:50:39.0328 2596 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINNT\system32\drivers\sysaudio.sys 15:50:39.0328 2596 sysaudio - ok 15:50:39.0796 2596 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINNT\system32\DRIVERS\tcpip.sys 15:50:39.0796 2596 Tcpip - ok 15:50:40.0234 2596 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINNT\system32\DRIVERS\tcpip6.sys 15:50:40.0234 2596 Tcpip6 - ok 15:50:40.0609 2596 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINNT\system32\drivers\TDPIPE.sys 15:50:40.0609 2596 TDPIPE - ok 15:50:40.0968 2596 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINNT\system32\drivers\TDTCP.sys 15:50:40.0984 2596 TDTCP - ok 15:50:41.0390 2596 TermDD (88155247177638048422893737429d9e) C:\WINNT\system32\DRIVERS\termdd.sys 15:50:41.0390 2596 TermDD - ok 15:50:41.0718 2596 TfFsMon - ok 15:50:41.0984 2596 TfNetMon - ok 15:50:42.0250 2596 TFSysMon - ok 15:50:42.0531 2596 TosIde - ok 15:50:42.0859 2596 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINNT\system32\DRIVERS\tunmp.sys 15:50:42.0859 2596 tunmp - ok 15:50:43.0218 2596 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINNT\system32\drivers\Udfs.sys 15:50:43.0250 2596 Udfs - ok 15:50:43.0656 2596 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINNT\system32\DRIVERS\ultra.sys 15:50:43.0656 2596 ultra - ok 15:50:44.0125 2596 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINNT\system32\DRIVERS\update.sys 15:50:44.0125 2596 Update - ok 15:50:44.0484 2596 USBAAPL - ok 15:50:44.0812 2596 usbaudio (e919708db44ed8543a7c017953148330) C:\WINNT\system32\drivers\usbaudio.sys 15:50:44.0812 2596 usbaudio - ok 15:50:45.0171 2596 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINNT\system32\DRIVERS\usbccgp.sys 15:50:45.0171 2596 usbccgp - ok 15:50:45.0531 2596 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINNT\system32\DRIVERS\usbehci.sys 15:50:45.0531 2596 usbehci - ok 15:50:45.0843 2596 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINNT\system32\DRIVERS\usbhub.sys 15:50:45.0843 2596 usbhub - ok 15:50:46.0218 2596 usbprint (a717c8721046828520c9edf31288fc00) C:\WINNT\system32\DRIVERS\usbprint.sys 15:50:46.0250 2596 usbprint - ok 15:50:46.0640 2596 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINNT\system32\DRIVERS\usbscan.sys 15:50:46.0656 2596 usbscan - ok 15:50:47.0015 2596 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINNT\system32\DRIVERS\USBSTOR.SYS 15:50:47.0015 2596 USBSTOR - ok 15:50:47.0421 2596 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINNT\system32\DRIVERS\usbuhci.sys 15:50:47.0421 2596 usbuhci - ok 15:50:47.0812 2596 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINNT\system32\Drivers\usbvideo.sys 15:50:47.0812 2596 usbvideo - ok 15:50:48.0171 2596 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINNT\System32\drivers\vga.sys 15:50:48.0171 2596 VgaSave - ok 15:50:48.0593 2596 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINNT\system32\DRIVERS\viaide.sys 15:50:48.0593 2596 ViaIde - ok 15:50:48.0921 2596 VMUVC - ok 15:50:49.0234 2596 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINNT\system32\drivers\VolSnap.sys 15:50:49.0234 2596 VolSnap - ok 15:50:49.0578 2596 vvftUVC - ok 15:50:49.0906 2596 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINNT\system32\DRIVERS\wanarp.sys 15:50:49.0906 2596 Wanarp - ok 15:50:50.0265 2596 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINNT\system32\DRIVERS\wanatw4.sys 15:50:50.0265 2596 wanatw - ok 15:50:50.0781 2596 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINNT\system32\Drivers\wdf01000.sys 15:50:50.0921 2596 Wdf01000 - ok 15:50:51.0281 2596 WDICA - ok 15:50:51.0609 2596 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINNT\system32\drivers\wdmaud.sys 15:50:51.0609 2596 wdmaud - ok 15:50:52.0046 2596 WpdUsb (d7467f619f574ab36286d2903e751deb) C:\WINNT\system32\Drivers\wpdusb.sys 15:50:52.0078 2596 WpdUsb - ok 15:50:52.0453 2596 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINNT\System32\drivers\ws2ifsl.sys 15:50:52.0453 2596 WS2IFSL - ok 15:50:52.0812 2596 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINNT\system32\DRIVERS\WSTCODEC.SYS 15:50:52.0812 2596 WSTCODEC - ok 15:50:53.0203 2596 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINNT\system32\DRIVERS\WudfPf.sys 15:50:53.0218 2596 WudfPf - ok 15:50:53.0640 2596 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINNT\system32\DRIVERS\wudfrd.sys 15:50:53.0656 2596 WudfRd - ok 15:50:54.0093 2596 {6080A529-897E-4629-A488-ABA0C29B635E} (e6c22d34baef5196e1b23a4492c275b7) C:\WINNT\system32\drivers\ialmsbw.sys 15:50:54.0140 2596 {6080A529-897E-4629-A488-ABA0C29B635E} - ok 15:50:54.0562 2596 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (6e53bd96b0ebad721cdd6320dbfc3f5f) C:\WINNT\system32\drivers\ialmkchw.sys 15:50:54.0593 2596 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok 15:50:54.0640 2596 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 15:50:54.0859 2596 \Device\Harddisk0\DR0 - ok 15:50:54.0875 2596 Boot (0x1200) (d7258f56a3eea298871c51c4cbfeeac0) \Device\Harddisk0\DR0\Partition0 15:50:54.0875 2596 \Device\Harddisk0\DR0\Partition0 - ok 15:50:54.0890 2596 ============================================================ 15:50:54.0890 2596 Scan finished 15:50:54.0890 2596 ============================================================ 15:50:54.0906 2568 Detected object count: 0 15:50:54.0906 2568 Actual detected object count: 0 —————————–
  • Malwarebytes' Anti-Malware

    I see you already have MBAM on your computer. Please do the following:

    • Once the program has loaded, click the Update tab and Check for Updates.
    • Click the Scanner tab, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. This log is saved by MBAM and can be viewed by clicking the Logs tab.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. Please paste the results in your next reply.
    • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
  • ESET Online Scanner

    Please disable any real-time security programs such as your anti-virus before proceeding with this scan.

    • Open Internet Explorer.
    • Download ESET Online Scanner.
    • Put a checkmark in the checkbox next to YES, I accept the Terms of Use.
    • Click Start.
    • When prompted by your web browser, click Install.
    • Uncheck Remove found threats.
    • Check Scan archives.
    • Click Start and let the scanner finish downloading virus signatures. The scan will begin afterward.
    • When the scan completes, click List of found threats.
    • Click Export to text file… and save the file to your desktop.
    • Click Back.
    • Click Finish.
  • OTL

    • Launch OTL.exe.
    • Check the following.
    • Scan all users.
    • Standard Output.
    • Lop check.
    • Purity check.
  • Under Extra Registry section, select Use SafeList
  • Click the Run Scan button and wait for the scan to finish (usually about 10-15 minutes).
  • When finished it will produce a log.
    • OTL.txt (open on your desktop)
  • Please post me this log.
Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.15.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: YOUR-3B54ED6EDD [administrator]

Protection: Disabled

1/15/2012 8:58:51 PM
mbam-log-2012-01-15 (20-58-51).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 181703
Time elapsed: 23 minute(s), 9 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)













C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\11\2ec8364b-436705c6 multiple threats
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\18\7845b2d2-5e5350d0 a variant of Java/TrojanDownloader.Agent.NAN trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\19\79571f53-3f0364f1 probably a variant of Win32/Agent.DYXWUMY trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\2\1f3f8202-784112ea a variant of Java/TrojanDownloader.Agent.NAN trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\24\4ec49a58-4b618d31 Java/Agent.BV trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\40\1fd53268-66b1d6ee probably a variant of Win32/Agent.DYXWUMY trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\5\1eedf745-5f872c94 multiple threats
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\54\2cd50f76-1e2b97a5 Java/Agent.BV trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\6\5b3d5486-54d68b57 a variant of Java/TrojanDownloader.Agent.NAN trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\60\5c2bd6bc-51e7045d probably a variant of Win32/Agent.FQRCZBA trojan
C:\Qoobox\Quarantine\C\WINNT\system32\egNWwGgh.ini.vir Win32/Adware.Virtumonde.NEO application
C:\Qoobox\Quarantine\C\WINNT\system32\MSCJRqss.ini.vir Win32/Adware.Virtumonde.NEO application
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001257.LNK LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001258.LNK LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001259.LNK LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001260.lnk LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001261.lnk LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001262.lnk LNK/URL.B trojan
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001683.ini Win32/Adware.Virtumonde.NEO application
C:\System Volume Information\_restore{CF79470C-79F7-4821-8E34-8E6EA7D3E7B5}\RP6\A0001684.ini Win32/Adware.Virtumonde.NEO application










OTL logfile created on: 1/16/2012 1:03:03 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.73 Mb Total Physical Memory | 452.42 Mb Available Physical Memory | 44.59% Memory free
1.88 Gb Paging File | 1.50 Gb Available in Paging File | 80.01% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 20.28 Gb Free Space | 54.42% Space Free | Partition Type: NTFS

Computer Name: YOUR-3B54ED6EDD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/09 03:34:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\desktop\OTL.exe
PRC - [2011/12/24 17:50:18 | 000,652,872 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINNT\explorer.exe
PRC - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINNT\wanmpsvc.exe


========== Modules (No Company Name) ==========

MOD - [2010/03/15 10:28:22 | 000,141,824 | —- | M] () – C:\Program Files\RarExt.dll
MOD - [2008/04/13 18:11:59 | 000,014,336 | —- | M] () – C:\WINNT\system32\msdmo.dll
MOD - [2008/04/13 18:11:51 | 000,059,904 | —- | M] () – C:\WINNT\system32\devenum.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (wuauserv)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - File not found [Disabled | Stopped] – – (AOLService)
SRV - File not found [Disabled | Stopped] – – (AOL ACS)
SRV - File not found [Disabled | Stopped] – – (ACDaemon)
SRV - File not found [Disabled | Stopped] – – (aawservice)
SRV - [2011/12/24 17:50:18 | 000,652,872 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2009/11/29 21:24:28 | 000,603,904 | —- | M] (TuneUp Software) [Disabled | Stopped] – C:\WINNT\system32\TUProgSt.exe – (TuneUp.ProgramStatisticsSvc)
SRV - [2009/01/27 12:26:42 | 000,398,336 | —- | M] (Ares Development Group) [On_Demand | Stopped] – C:\Program Files\Ares\chatServer.exe – (AresChatServer)
SRV - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [On_Demand | Stopped] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2007/01/04 15:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [On_Demand | Stopped] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2004/10/15 16:24:42 | 000,206,048 | —- | M] (Symantec Corporation) [Disabled | Stopped] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINNT\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2003/03/03 12:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)


========== Driver Services (SafeList) ==========

DRV - [2012/01/14 14:51:13 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39F5D8B1-72A1-4F15-8F75-9BA4F51AD7B5}\MpKslaf23d29b.sys – (MpKslaf23d29b)
DRV - [2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\WINNT\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2010/05/20 14:27:24 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2010/03/15 20:28:27 | 000,095,024 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\WINNT\system32\drivers\SBREDrv.sys – (SBRE)
DRV - [2010/02/11 06:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINNT\system32\drivers\tcpip6.sys – (Tcpip6)
DRV - [2007/10/11 05:20:56 | 000,000,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\atwpkt2.sys – (ATWPKT2)
DRV - [2007/10/02 16:45:04 | 004,109,376 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\alcxwdm.sys – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 23:41:39 | 000,013,776 | —- | M] (Smart Link) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\recagent.sys – (RecAgent)
DRV - [2004/05/13 18:01:23 | 000,028,352 | —- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\System32\drivers\MxlW2k.sys – (MxlW2k)
DRV - [2003/05/20 12:23:10 | 000,210,592 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\mtlmnt5.sys – (Mtlmnt5)
DRV - [2003/05/20 12:21:44 | 001,295,472 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\mtlstrm.sys – (Mtlstrm)
DRV - [2003/05/20 12:19:24 | 000,085,688 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\slnthal.sys – (SlNtHal)
DRV - [2003/05/19 14:30:02 | 000,169,120 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\ntmtlfax.sys – (NtMtlFax)
DRV - [2003/05/13 09:58:34 | 000,521,408 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slntamr.sys – (Slntamr)
DRV - [2003/01/16 23:19:32 | 000,039,348 | —- | M] (Vireo Software) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slwdmsup.sys – (SlWdmSup)
DRV - [2003/01/10 16:13:04 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [1999/09/10 05:06:00 | 000,025,244 | —- | M] (Adaptec) [Kernel | Auto | Running] – C:\WINNT\System32\drivers\aspi32.sys – (Aspi32)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://my.aol.com/?ncid=aolmas00050000000002 [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 59636
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINNT\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/14 18:45:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/10 23:21:23 | 000,000,000 | —D | M]

[2008/07/02 13:47:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/01/05 22:54:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions
[2011/11/12 20:09:02 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/03/12 14:01:35 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\[removed]
[2011/01/13 12:01:00 | 000,000,000 | —D | M] (Vacuum Places Improved) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\[removed]
[2011/06/24 20:08:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\HK5TJ3JO.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/14 18:45:20 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/04/16 11:07:12 | 000,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2011/11/14 18:45:12 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/14 18:45:11 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: AOL Media Playback Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Gmail = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/01/10 18:19:38 | 000,000,027 | —- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINNT\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINNT\System32\narrator.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1199318644546 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong Solitaire http://download.games.yahoo.com/games/clients/y/mjst4_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC7BC81B-A70D-4700-8CBA-E1D77637A0FA}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) -C:\WINNT\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINNT\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/15 21:48:13 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/01/14 14:20:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\lupu
[2012/01/14 14:12:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\BurnCDCC
[2012/01/13 22:23:04 | 000,000,000 | —D | C] – C:\c1d7fc001171605dddde
[2012/01/13 21:15:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Aunt Wanda
[2012/01/13 17:32:39 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/01/13 16:56:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GETxPUD
[2012/01/10 23:19:52 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/01/09 18:04:49 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/01/09 18:01:05 | 000,518,144 | —- | C] (SteelWerX) – C:\WINNT\SWREG.exe
[2012/01/09 18:01:05 | 000,406,528 | —- | C] (SteelWerX) – C:\WINNT\SWSC.exe
[2012/01/09 18:01:05 | 000,212,480 | —- | C] (SteelWerX) – C:\WINNT\SWXCACLS.exe
[2012/01/09 18:01:05 | 000,060,416 | —- | C] (NirSoft) – C:\WINNT\NIRCMD.exe
[2012/01/09 18:00:02 | 000,000,000 | —D | C] – C:\WINNT\ERDNT
[2012/01/09 17:59:53 | 000,000,000 | —D | C] – C:\Qoobox
[2012/01/09 17:57:45 | 004,377,322 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/01/09 17:51:54 | 001,972,528 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2012/01/09 03:34:48 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/09 03:17:15 | 004,713,472 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/08 21:58:32 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2012/01/04 21:37:25 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\MpSigStub.exe
[2012/01/04 21:31:54 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/01/04 21:28:53 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\mseinstall.exe
[2012/01/03 19:51:56 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.com
[2012/01/03 19:50:17 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HijackThis.exe
[2012/01/03 19:46:00 | 000,509,440 | —- | C] (Tech Support Guy System) – C:\Documents and Settings\Owner\Desktop\SysInfo.exe
[2012/01/03 04:54:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/03 04:54:11 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2012/01/03 04:54:10 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/03 04:52:52 | 010,847,608 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/03 04:40:48 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/03 04:36:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2008/06/01 17:56:09 | 001,030,144 | —- | C] (Microsoft Corporation) – C:\Program Files\dbghelp.dll
[2008/06/01 17:56:09 | 000,626,688 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcr80.dll
[2008/06/01 17:56:09 | 000,548,864 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcp80.dll
[2008/06/01 17:56:09 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcm80.dll
[2003/07/01 19:02:45 | 000,014,976 | —- | C] ( ) – C:\WINNT\System32\drivers\winddx.sys
[1979/12/31 23:00:00 | 001,295,472 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlstrm.sys
[1979/12/31 23:00:00 | 000,521,408 | —- | C] ( ) – C:\WINNT\System32\drivers\slntamr.sys
[1979/12/31 23:00:00 | 000,210,592 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlmnt5.sys
[1979/12/31 23:00:00 | 000,169,120 | —- | C] ( ) – C:\WINNT\System32\drivers\ntmtlfax.sys
[1979/12/31 23:00:00 | 000,085,688 | —- | C] ( ) – C:\WINNT\System32\drivers\slnthal.sys
[1979/12/31 23:00:00 | 000,045,056 | —- | C] ( ) – C:\WINNT\System32\slserv.exe
[1 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/16 00:17:03 | 000,000,978 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003UA.job
[2012/01/15 15:48:12 | 001,953,112 | —- | M] () – C:\Documents and Settings\Owner\Desktop\tdsskiller(1).zip
[2012/01/15 13:43:57 | 000,294,216 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2012/01/15 13:37:19 | 000,625,664 | —- | M] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2012/01/15 05:40:00 | 000,000,424 | -H– | M] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/15 04:17:00 | 000,000,926 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003Core.job
[2012/01/14 14:52:20 | 000,001,158 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2012/01/14 14:50:51 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2012/01/13 16:55:44 | 000,497,272 | —- | M] () – C:\Documents and Settings\Owner\Desktop\GETxPUD.exe
[2012/01/13 15:24:32 | 001,972,528 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2012/01/10 23:24:07 | 000,396,071 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MiniToolBox.exe
[2012/01/10 23:21:23 | 000,001,725 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/10 18:19:38 | 000,000,027 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2012/01/10 17:59:02 | 004,377,322 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/01/09 18:05:00 | 000,000,323 | RHS- | M] () – C:\boot.ini
[2012/01/09 17:51:40 | 001,558,406 | —- | M] () – C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2012/01/09 03:34:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/09 03:33:02 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2012/01/09 03:17:54 | 004,713,472 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/07 05:22:05 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/07 05:22:04 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2012/01/04 22:00:56 | 000,000,207 | —- | M] () – C:\Boot.bak
[2012/01/04 21:33:04 | 000,001,945 | —- | M] () – C:\WINNT\epplauncher.mif
[2012/01/04 21:29:05 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\mseinstall.exe
[2012/01/03 19:55:56 | 000,302,592 | —- | M] () – C:\Documents and Settings\Owner\Desktop\44f0pxph.exe
[2012/01/03 19:51:56 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.com
[2012/01/03 19:50:18 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HijackThis.exe
[2012/01/03 19:46:00 | 000,509,440 | —- | M] (Tech Support Guy System) – C:\Documents and Settings\Owner\Desktop\SysInfo.exe
[2012/01/03 13:40:54 | 000,433,414 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2012/01/03 13:40:54 | 000,068,244 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2012/01/03 04:53:24 | 010,847,608 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.60.0.1800.exe
[1 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/15 15:47:46 | 001,953,112 | —- | C] () – C:\Documents and Settings\Owner\Desktop\tdsskiller(1).zip
[2012/01/15 13:44:14 | 000,302,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2012/01/15 13:43:48 | 000,294,216 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2012/01/15 13:37:03 | 000,625,664 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2012/01/13 16:55:34 | 000,497,272 | —- | C] () – C:\Documents and Settings\Owner\Desktop\GETxPUD.exe
[2012/01/10 23:24:05 | 000,396,071 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MiniToolBox.exe
[2012/01/10 23:21:23 | 000,002,307 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2012/01/10 23:21:23 | 000,001,725 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/09 18:05:00 | 000,000,207 | —- | C] () – C:\Boot.bak
[2012/01/09 18:04:56 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/01/09 18:01:05 | 000,256,000 | —- | C] () – C:\WINNT\PEV.exe
[2012/01/09 18:01:05 | 000,208,896 | —- | C] () – C:\WINNT\MBR.exe
[2012/01/09 18:01:05 | 000,098,816 | —- | C] () – C:\WINNT\sed.exe
[2012/01/09 18:01:05 | 000,080,412 | —- | C] () – C:\WINNT\grep.exe
[2012/01/09 18:01:05 | 000,068,096 | —- | C] () – C:\WINNT\zip.exe
[2012/01/09 17:51:22 | 001,558,406 | —- | C] () – C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2012/01/09 03:33:02 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2012/01/04 21:37:52 | 000,000,424 | -H– | C] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/04 21:33:04 | 000,001,945 | —- | C] () – C:\WINNT\epplauncher.mif
[2012/01/04 21:32:20 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/01/03 19:55:54 | 000,302,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\44f0pxph.exe
[2010/07/31 15:14:26 | 000,212,400 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/04/30 19:37:32 | 000,256,368 | —- | C] () – C:\Program Files\WinRAR.chm
[2010/04/30 19:37:32 | 000,141,824 | —- | C] () – C:\Program Files\RarExt.dll
[2010/04/30 19:37:32 | 000,052,224 | —- | C] () – C:\Program Files\RarExt64.dll
[2010/04/30 19:37:32 | 000,000,495 | —- | C] () – C:\Program Files\File_Id.diz
[2010/01/09 21:27:08 | 000,000,056 | -H– | C] () – C:\WINNT\System32\ezsidmv.dat
[2008/08/31 19:13:08 | 000,073,220 | —- | C] () – C:\WINNT\System32\EPPICPrinterDB.dat
[2008/08/31 19:13:08 | 000,000,097 | —- | C] () – C:\WINNT\System32\PICSDK.ini
[2008/08/31 19:13:07 | 000,031,053 | —- | C] () – C:\WINNT\System32\EPPICPattern131.dat
[2008/08/31 19:13:07 | 000,029,114 | —- | C] () – C:\WINNT\System32\EPPICPattern1.dat
[2008/08/31 19:13:07 | 000,027,417 | —- | C] () – C:\WINNT\System32\EPPICPattern121.dat
[2008/08/31 19:13:07 | 000,021,021 | —- | C] () – C:\WINNT\System32\EPPICPattern3.dat
[2008/08/31 19:13:07 | 000,015,670 | —- | C] () – C:\WINNT\System32\EPPICPattern5.dat
[2008/08/31 19:13:07 | 000,013,280 | —- | C] () – C:\WINNT\System32\EPPICPattern2.dat
[2008/08/31 19:13:07 | 000,010,673 | —- | C] () – C:\WINNT\System32\EPPICPattern4.dat
[2008/08/31 19:13:07 | 000,004,943 | —- | C] () – C:\WINNT\System32\EPPICPattern6.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_PT.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_BP.dat
[2008/08/31 19:13:07 | 000,001,137 | —- | C] () – C:\WINNT\System32\EPPICPresetData_ES.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_FR.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_CF.dat
[2008/08/31 19:13:07 | 000,001,104 | —- | C] () – C:\WINNT\System32\EPPICPresetData_EN.dat
[2008/08/31 19:11:38 | 000,000,044 | —- | C] () – C:\WINNT\EPSNX400.ini
[2008/06/19 23:32:00 | 000,001,160 | —- | C] () – C:\WINNT\mozver.dat
[2008/06/02 17:23:38 | 000,021,312 | —- | C] () – C:\WINNT\choice.exe
[2008/06/01 17:56:28 | 000,018,464 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox.dat
[2008/06/01 17:56:28 | 000,001,056 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox2.dat
[2008/05/16 13:59:02 | 000,000,374 | —- | C] () – C:\WINNT\wininit.ini
[2008/03/11 16:20:45 | 000,000,121 | —- | C] () – C:\WINNT\winzipsp.ini
[2008/02/08 02:00:14 | 000,000,080 | —- | C] () – C:\WINNT\SuperUtil.ini
[2008/02/08 01:51:36 | 000,000,000 | —- | C] () – C:\WINNT\System32\suupdate.dat
[2008/02/08 01:51:35 | 000,000,000 | —- | C] () – C:\WINNT\System32\mssurun.dat
[2007/12/05 03:08:52 | 001,446,464 | —- | C] () – C:\Program Files\Silverlight.exe
[2007/10/20 19:08:23 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys
[2007/10/20 18:25:18 | 000,049,152 | —- | C] () – C:\WINNT\System32\ChCfg.exe
[2007/10/20 18:23:14 | 000,147,456 | —- | C] () – C:\WINNT\System32\RtlCPAPI.dll
[2007/10/18 00:00:21 | 000,055,949 | —- | C] () – C:\WINNT\System32\x264-uninstall.exe
[2007/10/11 05:20:56 | 000,000,000 | —- | C] () – C:\WINNT\System32\drivers\atwpkt2.sys
[2007/03/02 16:03:53 | 000,001,763 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/12 22:02:29 | 000,000,116 | —- | C] () – C:\WINNT\NeroDigital.ini
[2007/01/15 01:25:20 | 000,000,079 | —- | C] () – C:\WINNT\xptools.ini
[2007/01/15 01:21:58 | 000,000,120 | —- | C] () – C:\WINNT\System32\bn.dll
[2007/01/08 18:20:12 | 000,014,848 | —- | C] () – C:\WINNT\System32\BASSMOD.dll
[2006/12/18 03:43:12 | 000,000,022 | —- | C] () – C:\Program Files\zipnew.dat
[2006/12/18 03:43:12 | 000,000,020 | —- | C] () – C:\Program Files\rarnew.dat
[2006/12/18 03:42:56 | 001,039,360 | —- | C] () – C:\Program Files\WinRAR.exe
[2006/12/18 03:42:56 | 000,378,880 | —- | C] () – C:\Program Files\Rar.exe
[2006/12/18 03:42:56 | 000,246,272 | —- | C] () – C:\Program Files\UnRAR.exe
[2006/12/18 03:42:56 | 000,092,672 | —- | C] () – C:\Program Files\Default.SFX
[2006/12/18 03:42:56 | 000,074,240 | —- | C] () – C:\Program Files\Zip.SFX
[2006/12/18 03:42:56 | 000,069,632 | —- | C] () – C:\Program Files\WinCon.SFX
[2006/12/18 03:42:56 | 000,045,056 | —- | C] () – C:\Program Files\RarExtLoader.exe
[2006/12/18 03:42:55 | 000,003,271 | —- | C] () – C:\Program Files\Order.htm
[2006/12/18 03:42:55 | 000,001,088 | —- | C] () – C:\Program Files\RarFiles.lst
[2006/12/18 03:42:55 | 000,001,063 | —- | C] () – C:\Program Files\Descript.ion
[2006/12/18 03:42:55 | 000,000,639 | —- | C] () – C:\Program Files\Uninstall.lst
[2006/11/07 20:52:05 | 000,000,044 | —- | C] () – C:\WINNT\liveup.ini
[2006/08/12 22:09:45 | 000,004,096 | —- | C] () – C:\WINNT\d3dx.dat
[2006/07/16 17:08:08 | 000,000,627 | —- | C] () – C:\Program Files\playlist.xml
[2006/03/23 19:13:53 | 000,052,490 | —- | C] () – C:\WINNT\DcArt32presets.ini
[2006/03/05 01:46:11 | 000,001,610 | —- | C] () – C:\WINNT\GPlrLanc.dat
[2005/12/13 17:30:33 | 000,122,535 | —- | C] () – C:\WINNT\RSEDNClientUninstaller.exe
[2005/11/22 00:41:22 | 000,000,784 | —- | C] () – C:\Documents and Settings\Owner\Application Data\mpauth.dat
[2005/09/26 18:27:37 | 000,000,028 | —- | C] () – C:\WINNT\Systems.ini
[2005/08/31 18:05:37 | 000,000,075 | —- | C] () – C:\WINNT\System32\sysogg.dll
[2005/07/09 06:00:53 | 000,000,008 | —- | C] () – C:\WINNT\System32\wtl.dat
[2005/07/09 05:25:40 | 000,000,004 | —- | C] () – C:\WINNT\System32\micr0st.dll
[2005/07/09 05:16:13 | 000,129,024 | —- | C] () – C:\WINNT\UNWISE.EXE
[2005/06/29 14:53:05 | 000,005,460 | —- | C] () – C:\WINNT\kwv2.dat
[2005/06/27 17:37:46 | 000,187,512 | —- | C] () – C:\WINNT\System32\u3ldgpnu.dat
[2005/06/27 17:37:46 | 000,026,736 | —- | C] () – C:\WINNT\System32\4qlv6iqe.dat
[2005/06/27 17:37:46 | 000,003,864 | —- | C] () – C:\WINNT\System32\ahkhsbsu.dat
[2005/06/27 17:37:46 | 000,002,715 | —- | C] () – C:\WINNT\System32\mvkl8s1u.dat
[2005/06/27 17:37:46 | 000,000,000 | —- | C] () – C:\WINNT\System32\g8k3i4ve.dat
[2005/06/27 17:37:38 | 000,000,035 | —- | C] () – C:\WINNT\System32\01ii4bjf.ini
[2005/06/27 17:37:37 | 000,003,485 | —- | C] () – C:\WINNT\System32\mdeaf9ej.ini
[2005/05/20 21:35:09 | 000,000,056 | RHS- | C] () – C:\WINNT\System32\566097EC98.sys
[2005/03/21 20:59:40 | 000,000,715 | —- | C] () – C:\WINNT\aolback.exe.lnk
[2005/03/21 20:53:31 | 000,000,335 | —- | C] () – C:\WINNT\nsreg.dat
[2005/02/18 16:53:48 | 000,000,000 | —- | C] () – C:\WINNT\impborl.dll
[2005/02/08 14:42:45 | 000,000,092 | —- | C] () – C:\Program Files\play.rbn.rm&proto;=rtsp
[2005/01/13 22:23:53 | 000,001,131 | —- | C] () – C:\WINNT\System32\vh.dat
[2005/01/04 16:19:13 | 000,001,100 | —- | C] () – C:\WINNT\dhstatus.dat
[2004/12/15 08:22:09 | 000,149,504 | —- | C] () – C:\WINNT\System32\UNWISE.EXE
[2004/10/31 18:32:17 | 000,001,100 | —- | C] () – C:\WINNT\checkip.dat
[2004/10/31 18:29:50 | 000,001,393 | —- | C] () – C:\WINNT\ipconfig.dat
[2004/09/25 22:23:36 | 000,004,569 | —- | C] () – C:\WINNT\System32\secupd.dat
[2004/08/29 21:52:13 | 000,131,072 | —- | C] () – C:\WINNT\System32\SpoonUninstall.exe
[2004/08/25 17:53:06 | 000,000,032 | —- | C] () – C:\WINNT\easecdripper.ini
[2004/08/25 17:28:05 | 000,003,082 | —- | C] () – C:\WINNT\System32\affv6628p4now.sys
[2004/08/17 01:56:38 | 000,122,880 | —- | C] () – C:\WINNT\UnGins.exe
[2004/08/13 03:53:41 | 000,000,014 | —- | C] () – C:\WINNT\msoffice.ini
[2004/07/21 21:54:24 | 000,001,125 | —- | C] () – C:\WINNT\winamp.ini
[2004/05/26 14:42:25 | 000,000,048 | —- | C] () – C:\WINNT\upth.ini
[2004/05/26 14:42:25 | 000,000,028 | —- | C] () – C:\WINNT\atid.ini
[2004/02/11 07:50:12 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/02/07 14:41:59 | 000,082,944 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/01/22 12:00:28 | 000,012,635 | —- | C] () – C:\WINNT\System32\DAntivirus.ini
[2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\{419EC9B7-3209-4445-9EEC-01B25AAF5B29}.dat
[2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\System32\{0D36DCD8-9C7D-430C-A8AA-BD8DF873A105}.dat
[2003/10/25 14:37:35 | 000,067,857 | —- | C] () – C:\WINNT\cdPlayer.ini
[2003/10/22 10:05:08 | 000,000,030 | —- | C] () – C:\WINNT\Morphexe.INI
[2003/10/08 13:34:26 | 000,121,440 | —- | C] () – C:\WINNT\System32\MSDRMCtrl.dll
[2003/08/27 18:06:58 | 000,000,027 | —- | C] () – C:\WINNT\UP9ASP.INI
[2003/08/27 17:33:30 | 000,006,550 | —- | C] () – C:\WINNT\jautoexp.dat
[2003/08/27 16:45:53 | 000,065,536 | —- | C] () – C:\WINNT\System32\YCRWin32.dll
[2003/08/27 14:24:03 | 000,000,242 | —- | C] () – C:\WINNT\qwimp.ini
[2003/08/26 16:10:20 | 000,000,120 | —- | C] () – C:\WINNT\SIERRA.INI
[2003/08/23 13:49:22 | 000,000,396 | —- | C] () – C:\WINNT\intuprof.ini
[2003/08/23 13:48:46 | 000,000,880 | —- | C] () – C:\WINNT\QUICKEN.INI
[2003/08/22 20:05:57 | 000,002,241 | —- | C] () – C:\WINNT\hpdj5600.ini
[2003/08/22 20:05:25 | 000,000,414 | —- | C] () – C:\WINNT\hpbvspst.ini
[2003/07/16 14:22:18 | 000,000,061 | —- | C] () – C:\WINNT\smscfg.ini
[2003/07/14 13:30:28 | 000,197,120 | —- | C] () – C:\WINNT\patchw32.dll
[2003/07/01 19:23:27 | 000,000,000 | —- | C] () – C:\WINNT\System32\a3d.dll
[2003/07/01 19:10:07 | 000,000,370 | —- | C] () – C:\WINNT\ODBC.INI
[2003/07/01 19:07:33 | 000,282,624 | —- | C] () – C:\WINNT\System32\PCDrSystemInformation.dll
[2003/07/01 19:05:00 | 000,094,208 | —- | C] () – C:\WINNT\System32\PCDrKernelModeServices.dll
[2003/07/01 19:05:00 | 000,077,824 | —- | C] () – C:\WINNT\System32\ProgressTrace.dll
[2003/07/01 19:03:46 | 000,000,561 | —- | C] () – C:\WINNT\System32\OEMINFO.INI
[2003/07/01 19:02:45 | 000,466,944 | —- | C] () – C:\WINNT\System32\SLLights.dll
[2003/07/01 19:02:45 | 000,376,832 | —- | C] () – C:\WINNT\System32\slmh.exe
[2003/07/01 19:02:45 | 000,167,936 | —- | C] () – C:\WINNT\System32\minirec.exe
[2003/07/01 19:02:45 | 000,151,552 | —- | C] () – C:\WINNT\System32\amr_cpl.dll
[2003/07/01 19:02:45 | 000,061,440 | —- | C] () – C:\WINNT\SmCfg.exe
[2003/05/16 11:56:01 | 000,000,770 | —- | C] () – C:\WINNT\orun32.ini
[2003/05/16 10:34:34 | 000,002,048 | –S- | C] () – C:\WINNT\bootstat.dat
[2003/05/16 10:26:45 | 000,021,640 | —- | C] () – C:\WINNT\System32\emptyregdb.dat
[2003/05/16 10:20:03 | 000,004,073 | —- | C] () – C:\WINNT\ODBCINST.INI
[2003/05/16 10:18:53 | 000,221,632 | —- | C] () – C:\WINNT\System32\FNTCACHE.DAT
[2003/03/27 15:28:44 | 000,004,955 | —- | C] () – C:\WINNT\System32\DProg.ini
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINNT\System32\unrar.dll
[2002/10/06 12:42:58 | 000,237,568 | —- | C] () – C:\WINNT\System32\OggDS.dll
[2002/10/04 17:04:26 | 000,921,600 | —- | C] () – C:\WINNT\System32\VorbisEnc.dll
[2002/10/04 17:04:26 | 000,188,416 | —- | C] () – C:\WINNT\System32\vorbis.dll
[2002/10/04 17:04:18 | 000,045,056 | —- | C] () – C:\WINNT\System32\ogg.dll
[2002/09/06 10:36:16 | 000,233,472 | —- | C] () – C:\WINNT\System32\lame_enc.dll
[2002/05/15 18:38:40 | 000,091,136 | —- | C] () – C:\WINNT\System32\mp4fil32.dll
[2002/05/04 08:19:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\avisynthEx.dll
[2002/04/19 09:23:26 | 000,106,137 | —- | C] () – C:\WINNT\System32\libpostproc.dll
[2001/08/29 18:57:40 | 000,155,648 | —- | C] () – C:\WINNT\System32\addurl41.DLL
[2001/07/10 13:43:16 | 000,018,432 | —- | C] () – C:\WINNT\System32\winwatch.DLL
[2001/06/22 06:06:02 | 000,167,936 | —- | C] () – C:\WINNT\System32\MPEG2DEC.dll
[2000/09/08 16:53:50 | 000,073,839 | —- | C] () – C:\WINNT\System32\KodakOneTouch.dll
[1979/12/31 23:00:00 | 013,107,200 | —- | C] () – C:\WINNT\System32\oembios.bin
[1979/12/31 23:00:00 | 000,673,088 | —- | C] () – C:\WINNT\System32\mlang.dat
[1979/12/31 23:00:00 | 000,433,414 | —- | C] () – C:\WINNT\System32\perfh009.dat
[1979/12/31 23:00:00 | 000,272,128 | —- | C] () – C:\WINNT\System32\perfi009.dat
[1979/12/31 23:00:00 | 000,218,003 | —- | C] () – C:\WINNT\System32\dssec.dat
[1979/12/31 23:00:00 | 000,188,416 | —- | C] () – C:\WINNT\System32\slextspk.dll
[1979/12/31 23:00:00 | 000,159,744 | —- | C] () – C:\WINNT\System32\SLGen.dll
[1979/12/31 23:00:00 | 000,068,244 | —- | C] () – C:\WINNT\System32\perfc009.dat
[1979/12/31 23:00:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\coinst.dll
[1979/12/31 23:00:00 | 000,046,258 | —- | C] () – C:\WINNT\System32\mib.bin
[1979/12/31 23:00:00 | 000,028,626 | —- | C] () – C:\WINNT\System32\perfd009.dat
[1979/12/31 23:00:00 | 000,024,576 | —- | C] () – C:\WINNT\slrundll.exe
[1979/12/31 23:00:00 | 000,005,114 | —- | C] () – C:\WINNT\System32\oembios.dat
[1979/12/31 23:00:00 | 000,001,804 | —- | C] () – C:\WINNT\System32\dcache.bin
[1979/12/31 23:00:00 | 000,000,741 | —- | C] () – C:\WINNT\System32\noise.dat

========== LOP Check ==========

[2008/12/11 17:53:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/06/11 18:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2010/07/21 19:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/08/31 21:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2007/01/06 14:15:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2005/08/09 17:00:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/05/10 22:09:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2009/12/07 18:05:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2010/07/07 19:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/11/06 19:22:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/01/03 05:06:09 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/10/18 21:27:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/12/07 18:04:51 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2003/07/01 19:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\InterTrust
[2009/12/07 19:00:01 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2006/03/04 04:39:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2007/01/04 23:35:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2010/06/21 16:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DC++
[2008/09/05 16:57:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eBookPro6
[2010/07/07 21:12:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2003/08/05 22:50:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/08/31 21:25:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leader Technologies
[2008/08/31 19:20:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/02/16 23:56:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\minimem
[2011/09/05 15:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/05/09 07:48:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCToolsFirewallPlus
[2008/08/15 02:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PhotoParade
[2009/11/28 20:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Playrix Entertainment
[2009/10/19 00:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SharePod
[2009/01/04 23:43:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skinux
[2009/05/02 11:38:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skunk Studios
[2011/05/09 07:47:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spam Monitor
[2009/11/29 21:02:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sudden Games
[2009/04/15 01:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Systweak
[2009/09/26 16:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TikisLab
[2005/12/15 03:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TuneUp Software
[2008/02/12 04:06:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Uniblue
[2007/01/20 03:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2011/06/29 14:26:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart Digital Photo Viewer
[2007/10/07 11:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Walgreens
[2006/08/12 22:14:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wildfire
[2012/01/15 05:40:00 | 000,000,424 | -H– | M] () – C:\WINNT\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Program Files\play.rbn.rm&proto;=rtsp:SummaryInformation

< End of report >
  • OTL

    Run OTL.exe.

    • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      FF - prefs.js..network.proxy.http: "127.0.0.1"
      FF - prefs.js..network.proxy.http_port: 59636
      FF - prefs.js..network.proxy.type: 0
      [2005/06/29 14:53:05 | 000,005,460 | —- | C] () – C:\WINNT\kwv2.dat
      O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
      O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
      O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
      [2005/06/27 17:37:46 | 000,187,512 | —- | C] () – C:\WINNT\System32\u3ldgpnu.dat
      [2005/06/27 17:37:46 | 000,026,736 | —- | C] () – C:\WINNT\System32\4qlv6iqe.dat
      [2005/06/27 17:37:46 | 000,003,864 | —- | C] () – C:\WINNT\System32\ahkhsbsu.dat
      [2005/06/27 17:37:46 | 000,002,715 | —- | C] () – C:\WINNT\System32\mvkl8s1u.dat
      [2005/06/27 17:37:46 | 000,000,000 | —- | C] () – C:\WINNT\System32\g8k3i4ve.dat
      [2005/06/27 17:37:38 | 000,000,035 | —- | C] () – C:\WINNT\System32\01ii4bjf.ini
      [2005/06/27 17:37:37 | 000,003,485 | —- | C] () – C:\WINNT\System32\mdeaf9ej.ini
      [2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\{419EC9B7-3209-4445-9EEC-01B25AAF5B29}.dat
      [2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\System32\{0D36DCD8-9C7D-430C-A8AA-BD8DF873A105}.dat
      
      :Commands
      [createrestorepoint]
      [purity]
      [emptytemp]
    • Click the Run Fix button.
    • OTL will now process the instructions.
    • When finished a box will open asking you to open the fix log, click OK.
    • The fix log will open.
    • Copy/Paste the log in your next reply please.

    Note: If necessary, OTL may reboot your computer, or request that you do so. If it does, please go ahead and reboot your machine. After rebooting, open up Windows Explorer (Windows Key +E) and navigate to C:\_OTL\MovedFiles. Within, you should find a .log file with the format mmddyyyy_hhmmss, which represents the date and time the fix was run. Please copy and paste the contents of that file, making sure Word Wrap is off beforehand, if necessary.


    For the next step, it will likely be necessary to:

  • Show hidden files/folders

    • Click Start.
    • Open My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Show hidden files and folders.
    • Uncheck the Hide protected operating system files (recommended) option.
    • Click Yes to confirm.
    • Click OK.
  • VirusTotal

    We need to upload a file to VirusTotal for inspection.

    • Please visit VirusTotal by clicking here.
    • Click the Choose File button and search for the following file:
      • C:\WINNT\System32\566097EC98.sys
    • Click Open.
    • Click Scan it!
    • Please be patient while the file is scanned.
    • If VirusTotal tells you that the file has already been scanned, click "reanalyse now".
    • Once scanned, copy and paste the link to the results page in your next reply.
    If you're having trouble loading VirusTotal, try VirSCAN or Jotti.

  • SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.

    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:

      :filefind
      wuauserv.dll
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
—-

In your next reply, please include:

  • The logs for OTL and SystemLook.
  • The link to the VirusTotal report.
  • A report on any outstanding issues you are experiencing.
All processes killed
========== OTL ==========
Prefs.js: "127.0.0.1" removed from network.proxy.http
Prefs.js: 59636 removed from network.proxy.http_port
Prefs.js: 0 removed from network.proxy.type
C:\WINNT\kwv2.dat moved successfully.
Registry value HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
Registry value HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ not found.
Registry value HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
C:\WINNT\system32\u3ldgpnu.dat moved successfully.
C:\WINNT\system32\4qlv6iqe.dat moved successfully.
C:\WINNT\system32\ahkhsbsu.dat moved successfully.
C:\WINNT\system32\mvkl8s1u.dat moved successfully.
C:\WINNT\system32\g8k3i4ve.dat moved successfully.
C:\WINNT\system32\01ii4bjf.ini moved successfully.
C:\WINNT\system32\mdeaf9ej.ini moved successfully.
C:\WINNT\{419EC9B7-3209-4445-9EEC-01B25AAF5B29}.dat moved successfully.
C:\WINNT\system32\{0D36DCD8-9C7D-430C-A8AA-BD8DF873A105}.dat moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users
->Flash cache emptied: 35 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 373795 bytes
->Flash cache emptied: 405 bytes

User: NetworkService
->Temp folder emptied: 43038 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 405 bytes

User: Owner
->Temp folder emptied: 74820 bytes
->Temporary Internet Files folder emptied: 33656111 bytes
->Java cache emptied: 124125473 bytes
->FireFox cache emptied: 452212220 bytes
->Google Chrome cache emptied: 340686329 bytes
->Flash cache emptied: 2897000 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 74418 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 2166127 bytes
RecycleBin emptied: 141786929 bytes

Total Files Cleaned = 1,047.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01162012_233939

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…














SystemLook 30.07.11 by jpshortstuff
Log created at 00:04 on 17/01/2012 by Owner
Administrator - Elevation successful

========== filefind ==========

Searching for "wuauserv.dll"
C:\WINNT\ServicePackFiles\i386\wuauserv.dll —–c- 6656 bytes [07:56 04/08/2004] [00:12 14/04/2008] 35321FB577CDC98CE3EB3A3EB9E4610A
C:\WINNT\system32\wuauserv.dll –a—- 6656 bytes [16:24 16/05/2003] [00:12 14/04/2008] 35321FB577CDC98CE3EB3A3EB9E4610A

-= EOF =-










https://www.virustotal.com/file/4877b6073ec…sis/1326780016/






proxy settings are still set to manual when trying to connect using firefox.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI