This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ran tddskiller and now can't get online [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm assuming you have access to another computer where you can download the tools and transfer to the infected computer via USB?


Please do the following:

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Farbar Service Scanner Ran by [removed] (administrator) on 15-01-2012 at 10:22:48 Microsoft Windows XP Home Edition Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Dnscache Service is not running. Checking service configuration: The start type of Dnscache service is OK. The ImagePath of Dnscache service is OK. The ServiceDll of Dnscache service is OK. Dhcp Service is not running. Checking service configuration: The start type of Dhcp service is OK. The ImagePath of Dhcp service is OK. The ServiceDll of Dhcp service is OK. Tcpip Service is not running. Checking service configuration: The start type of Tcpip service is OK. The ImagePath of Tcpip service is OK. Connection Status: ============== Localhost is blocked. There is no connection to network. Attempt to access Google IP returned error: Other errors Attempt to access Yahoo IP returend error: Other errors Windows Firewall: ============= sharedaccess Service is not running. Checking service configuration: The start type of sharedaccess service is OK. The ImagePath of sharedaccess service is OK. The ServiceDll of sharedaccess service is OK. Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: =========== cryptsvc Service is not running. Checking service configuration: The start type of cryptsvc service is set to Demand. The default start type is Auto. The ImagePath of cryptsvc service is OK. The ServiceDll of cryptsvc service is OK. File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= AegisP(12) Gpc(6) IPSec(5) MDC8021X(9) mfetdi2k(14) NetBT(5) PSched(7) SYMTDI(8) Tcpip(3) 0x0E000000040000000100000002000000030000000E0000000B0000000A00000008000000050000 000600000007000000090000000D0000000C000000 Attention! IpSec Tag value should be 4 **** End of log ****
please re-run Farbar Service Scanner

copy/paste the following into the search window:

IpSec

Now press the "Export Service" button

post the contents of the resulting log
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\Ipsec] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,73,00,65,00,63,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="IPSEC driver" "Group"="PNP_TDI" "Description"="IPSEC driver" [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\Ipsec\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\Ipsec\Enum] "0"="Root\\LEGACY_IPSEC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Ipsec] "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Ipsec\0000] "Service"="IPSec" "Legacy"=dword:00000001 "ConfigFlags"=dword:00000000 "Class"="LegacyDriver" "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}" "DeviceDesc"="IPSEC driver" "Capabilities"=dword:00000000 "Driver"="{8ECC055D-047F-11D1-A537-0000F8753ED1}\\0012" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Ipsec\0000\LogConf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Ipsec\0000\Control] "ActiveService"="IPSec"
Backup Your Registry:

Download ERUNT to your Desktop (right-click the link, select Save Link/Target As…, select your Desktop and press Save)
Right-click erunt.zip, choose Extract All… and follow the prompts to unzip the program.
Open the erunt folder on your Desktop and double-click ERUNT.exe to start the program
Click OK for all the prompts to back up your registry to the default location.

Note: if it becomes necessary to restore the registry, open the backup folder and start ERDNT.exe



NEXT


Click WinKey + R to open a run box > type notepad into the open run box > OK > this will open Notepad

Click Format and make certain that Word Wrap is NOT checked.

Copy/Paste the text inside of the code box into the open Notepad


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\Ipsec]
"Tag"=dword:00000004

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in fixme.reg as the file name, then choose All Files as the save as file type.
Then click the save button.

Once you have clicked the save button, close Notepad.

You should now see a file on your desktop that looks like this:

[external image: Posted Image]

Locate the fixme.reg icon on your desktop and double click it, an information box will pop up asking if you want to merge the information in the file into the registry, click YES.

Once the file has run, the information will have merged with your registry so you can delete fixme.reg from your desktop as you won't be needing it any more.


You should now be able to connect

please rerun Farbar Service Scan and run the following diagnostic logs to make sure you are clean of malware


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
Farbar Service Scanner Ran by [removed] (administrator) on 15-01-2012 at 14:16:21 Microsoft Windows XP Home Edition Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Yahoo IP is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: =========== cryptsvc Service is not running. Checking service configuration: The start type of cryptsvc service is set to Demand. The default start type is Auto. The ImagePath of cryptsvc service is OK. The ServiceDll of cryptsvc service is OK. File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= AegisP(12) Gpc(6) IPSec(4) MDC8021X(9) mfetdi2k(14) NetBT(5) PSched(7) SYMTDI(8) Tcpip(3) 0x0E000000040000000100000002000000030000000E0000000B0000000A00000008000000050000 000600000007000000090000000D0000000C000000 IpSec Tag value is correct. **** End of log **** . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 14:17:00 on 2012-01-15 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1634 [GMT -8:00] . AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Firewall *Enabled* FW: ZoneAlarm Firewall *Disabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe C:\WINDOWS\system32\mfevtps.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Vpskeys\VPSKEYS.EXE C:\Program Files\NETGEAR\WG111T\wlan111t.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Cox, Inc\Cox PC HealthCheck\DesktopClient.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\admin\Desktop\Farbar\FSS.exe C:\WINDOWS\system32\notepad.exe . ============== Pseudo HJT Report =============== . uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/ uInternet Settings,ProxyServer = http=127.0.0.1:4619 uInternet Settings,ProxyOverride = uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p;=%s BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20111216172118.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [VPSKEYS] c:\program files\vpskeys\VPSKEYS.EXE uRun: [pyyhysaogoylpd] c:\documents and settings\admin\local settings\application data\hnmerqmq\gjyhjvs.exe uRun: [Google Update] "c:\documents and settings\admin\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4.0\OpwareSE4.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe mRun: [Samsung PanelMgr] c:\windows\samsung\panelmgr\SSMMgr.exe /autorun mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u dRun: [ccpmgpyo] c:\documents and settings\networkservice\local settings\application data\ckiryhcwx\mmclqnrtssd.exe dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\admin\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\admin\startm~1\programs\startup\coxpch~1.lnk - c:\program files\cox, inc\cox pc healthcheck\DesktopClient.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111t\wlan111t.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} IE: {3C34EBD2-038D-4d4f-B081-16D99D8BE2B4} - {361D6100-9833-4ABA-BB50-7015F325BBF0} - c:\windows\downloaded program files\IEPrint.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL LSP: mswsock.dll DPF: IEPrint - hxxp://www.visiontech.ltd.uk/software/download/IEPrint.CAB DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.costcophotocenter.com/CostcoActivia.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {F9CD2233-6744-47C1-A6AE-00C30A35F73D} - hxxps://myaccount.cox.net/internettools/scripts/Inspector.cab TCP: DhcpNameServer = 192.168.1.1 [removed] [removed] [removed] TCP: Interfaces\{3DD33601-AA8D-4591-81C9-1C1A22964F53} : DhcpNameServer = 192.168.1.1 [removed] [removed] [removed] Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: igfxcui - igfxdev.dll Notify: intelsusb - ntusbw32.dll Notify: ntusbw32 - ntusbw32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\admin\application data\mozilla\firefox\profiles\bqo97wwp.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;= FF - prefs.js: browser.search.selectedEngine - Secure Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p;= FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll FF - plugin: c:\documents and settings\admin\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll FF - plugin: c:\program files\microsoft silverlight\4.0.51204.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPCIG.dll . ============= SERVICES / DRIVERS =============== . R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-13 459728] R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-12-16 84200] R2 COX CommunicationsMonitoringService;COX Communications Monitoring Service;c:\program files\cox, inc\cox pc healthcheck\PCMonitoringService.exe [2010-11-17 14456] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-12-16 271480] R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-12-16 271480] R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-12-16 271480] R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-12-16 271480] R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-12-16 171168] R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-12-16 188136] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-12-16 148520] R3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [2011-2-21 816672] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-12-16 56064] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-22 153280] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-22 52320] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-12-16 314088] R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2011-12-16 88736] S0 78561617;78561617;c:\windows\system32\drivers\09465183.sys –> c:\windows\system32\drivers\09465183.sys [?] S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys –> c:\windows\system32\drivers\SSPORT.sys [?] S3 ATHFMWDL;NETGEAR WG111T bootloader driver;c:\windows\system32\drivers\athfmwdl.sys –> c:\windows\system32\drivers\ATHFMWDL.sys [?] S3 cpuz132;cpuz132;\??\c:\docume~1\admin\locals~1\temp\cpuz132\cpuz132_x32.sys –> c:\docume~1\admin\locals~1\temp\cpuz132\cpuz132_x32.sys [?] S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2005-9-9 17149] S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2011-12-16 88736] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-12-16 84488] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-22 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-22 40552] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-10 14336] . =============== Created Last 30 ================ . 2011-12-17 17:54:44 116224 —-a-w- c:\windows\system32\dllcache\xrxwiadr.dll 2011-12-17 17:54:39 23040 —-a-w- c:\windows\system32\dllcache\xrxwbtmp.dll 2011-12-17 17:54:37 18944 —-a-w- c:\windows\system32\dllcache\xrxscnui.dll 2011-12-17 17:54:32 27648 —-a-w- c:\windows\system32\dllcache\xrxftplt.exe 2011-12-17 17:54:28 4608 —-a-w- c:\windows\system32\dllcache\xrxflnch.exe 2011-12-17 17:54:21 99865 —-a-w- c:\windows\system32\dllcache\xlog.exe 2011-12-17 17:54:17 16970 —-a-w- c:\windows\system32\dllcache\xem336n5.sys 2011-12-17 17:54:15 19455 —-a-w- c:\windows\system32\dllcache\wvchntxx.sys 2011-12-17 17:54:12 19200 —-a-w- c:\windows\system32\dllcache\wstcodec.sys 2011-12-17 17:54:10 12063 —-a-w- c:\windows\system32\dllcache\wsiintxx.sys 2011-12-17 17:54:09 8192 —-a-w- c:\windows\system32\dllcache\wshirda.dll 2011-12-17 17:52:59 12415 —-a-w- c:\windows\system32\dllcache\wadv01nt.sys 2011-12-17 17:52:53 16925 —-a-w- c:\windows\system32\dllcache\w940nd.sys 2011-12-17 17:52:48 19016 —-a-w- c:\windows\system32\dllcache\w926nd.sys 2011-12-17 17:52:42 48256 —-a-w- c:\windows\system32\dllcache\w32.dll 2011-12-17 17:52:42 19528 —-a-w- c:\windows\system32\dllcache\w840nd.sys 2011-12-17 17:52:37 64605 —-a-w- c:\windows\system32\dllcache\vvoice.sys 2011-12-17 17:52:31 397502 —-a-w- c:\windows\system32\dllcache\vpctcom.sys 2011-12-17 17:52:26 604253 —-a-w- c:\windows\system32\dllcache\vmodem.sys 2011-12-17 17:52:20 249402 —-a-w- c:\windows\system32\dllcache\vinwm.sys 2011-12-17 17:52:15 24576 —-a-w- c:\windows\system32\dllcache\viairda.sys 2011-12-17 17:52:13 53760 —-a-w- c:\windows\system32\dllcache\vfwwdm32.dll 2011-12-17 17:52:06 687999 —-a-w- c:\windows\system32\dllcache\usrwdxjs.sys 2011-12-17 17:52:01 765884 —-a-w- c:\windows\system32\dllcache\usrti.sys 2011-12-17 17:50:59 69632 —-a-w- c:\windows\system32\dllcache\umaxu12.dll 2011-12-17 17:50:54 50688 —-a-w- c:\windows\system32\dllcache\umaxscan.dll 2011-12-17 17:50:49 22912 —-a-w- c:\windows\system32\dllcache\umaxpcls.sys 2011-12-17 17:50:44 50176 —-a-w- c:\windows\system32\dllcache\umaxp60.dll 2011-12-17 17:50:39 47616 —-a-w- c:\windows\system32\dllcache\umaxcam.dll 2011-12-17 17:50:34 211968 —-a-w- c:\windows\system32\dllcache\um54scan.dll 2011-12-17 17:50:28 216064 —-a-w- c:\windows\system32\dllcache\um34scan.dll 2011-12-17 17:50:23 11520 —-a-w- c:\windows\system32\dllcache\twotrack.sys 2011-12-17 17:50:22 14336 —-a-w- c:\windows\system32\dllcache\tsprof.exe 2011-12-17 17:50:15 166784 —-a-w- c:\windows\system32\dllcache\tridxpm.sys 2011-12-17 17:50:10 525568 —-a-w- c:\windows\system32\dllcache\tridxp.dll 2011-12-17 17:50:05 159232 —-a-w- c:\windows\system32\dllcache\tridkbm.sys 2011-12-17 17:50:00 440576 —-a-w- c:\windows\system32\dllcache\tridkb.dll 2011-12-17 17:48:59 149376 —-a-w- c:\windows\system32\dllcache\tffsport.sys 2011-12-17 17:47:57 53760 —-a-w- c:\windows\system32\dllcache\sw_wheel.dll 2011-12-17 17:47:52 41472 —-a-w- c:\windows\system32\dllcache\sw_effct.dll 2011-12-17 17:47:50 15232 —-a-w- c:\windows\system32\dllcache\streamip.sys 2011-12-17 17:47:45 155648 —-a-w- c:\windows\system32\dllcache\stlnprop.dll 2011-12-17 17:47:41 53248 —-a-w- c:\windows\system32\dllcache\stlncoin.dll 2011-12-17 17:47:36 285760 —-a-w- c:\windows\system32\dllcache\stlnata.sys 2011-12-17 17:47:31 16896 —-a-w- c:\windows\system32\dllcache\stcusb.sys 2011-12-17 17:47:25 48736 —-a-w- c:\windows\system32\dllcache\srwlnd5.sys 2011-12-17 17:47:20 99328 —-a-w- c:\windows\system32\dllcache\srusd.dll 2011-12-17 17:47:20 101376 —-a-w- c:\windows\system32\dllcache\srusbusd.dll 2011-12-17 17:47:14 24660 —-a-w- c:\windows\system32\dllcache\spxupchk.dll 2011-12-17 17:47:08 61824 —-a-w- c:\windows\system32\dllcache\speed.sys 2011-12-17 17:47:03 106584 —-a-w- c:\windows\system32\dllcache\spdports.dll 2011-12-17 17:45:59 6784 —-a-w- c:\windows\system32\dllcache\smbhc.sys 2011-12-17 17:44:57 150144 —-a-w- c:\windows\system32\dllcache\sis6306v.dll 2011-12-17 17:44:52 68608 —-a-w- c:\windows\system32\dllcache\sis6306p.sys 2011-12-17 17:44:48 252032 —-a-w- c:\windows\system32\dllcache\sis300iv.dll 2011-12-17 17:44:44 101760 —-a-w- c:\windows\system32\dllcache\sis300ip.sys 2011-12-17 17:44:43 18944 —-a-w- c:\windows\system32\dllcache\simptcp.dll 2011-12-17 17:44:34 161568 —-a-w- c:\windows\system32\dllcache\sgsmusb.sys 2011-12-17 17:44:29 18400 —-a-w- c:\windows\system32\dllcache\sgsmld.sys 2011-12-17 17:44:25 98080 —-a-w- c:\windows\system32\dllcache\sgiulnt5.sys 2011-12-17 17:44:20 386560 —-a-w- c:\windows\system32\dllcache\sgiul50.dll 2011-12-17 17:44:16 36480 —-a-w- c:\windows\system32\dllcache\sfmanm.sys 2011-12-17 17:44:10 6784 —-a-w- c:\windows\system32\dllcache\serscan.sys 2011-12-17 17:44:05 26112 —-a-w- c:\windows\system32\dllcache\EXCH_seos.dll 2011-12-17 17:44:05 17664 —-a-w- c:\windows\system32\dllcache\sermouse.sys 2011-12-17 17:42:59 179264 —-a-w- c:\windows\system32\dllcache\s3sav3d.dll 2011-12-17 17:41:58 3840 —-a-w- c:\windows\system32\dllcache\rpfun.sys 2011-12-17 17:40:59 128286 —-a-w- c:\windows\system32\dllcache\ptserli.sys 2011-12-17 17:39:58 16384 —-a-w- c:\windows\system32\dllcache\philcam1.dll 2011-12-17 17:38:59 39424 —-a-w- c:\windows\system32\dllcache\ovcoms.exe 2011-12-17 17:37:56 123776 —-a-w- c:\windows\system32\dllcache\nv3.dll 2011-12-17 17:36:58 85248 —-a-w- c:\windows\system32\dllcache\nabtsfec.sys 2011-12-17 17:35:57 103296 —-a-w- c:\windows\system32\dllcache\mtxvideo.sys 2011-12-17 17:35:50 5504 —-a-w- c:\windows\system32\dllcache\mstee.sys 2011-12-17 17:35:49 49024 —-a-w- c:\windows\system32\dllcache\mstape.sys 2011-12-17 17:35:43 12416 —-a-w- c:\windows\system32\dllcache\msriffwv.sys 2011-12-17 17:35:36 2944 —-a-w- c:\windows\system32\dllcache\msmpu401.sys 2011-12-17 17:35:34 22016 —-a-w- c:\windows\system32\dllcache\msircomm.sys 2011-12-17 17:35:25 35200 —-a-w- c:\windows\system32\dllcache\msgame.sys 2011-12-17 17:35:20 6016 —-a-w- c:\windows\system32\dllcache\msfsio.sys 2011-12-17 17:35:19 51200 —-a-w- c:\windows\system32\dllcache\msdv.sys 2011-12-17 17:35:12 15232 —-a-w- c:\windows\system32\dllcache\mpe.sys 2011-12-17 17:35:05 16128 —-a-w- c:\windows\system32\dllcache\modemcsa.sys 2011-12-17 17:33:59 576746 —-a-w- c:\windows\system32\dllcache\ltmdmntl.sys 2011-12-17 17:32:59 23552 —-a-w- c:\windows\system32\dllcache\irmk7.sys 2011-12-17 17:32:58 88192 —-a-w- c:\windows\system32\dllcache\irda.sys 2011-12-17 17:32:58 151552 —-a-w- c:\windows\system32\dllcache\irftp.exe 2011-12-17 17:32:53 45632 —-a-w- c:\windows\system32\dllcache\ip5515.sys 2011-12-17 17:32:50 90200 —-a-w- c:\windows\system32\dllcache\io8ports.dll 2011-12-17 17:32:47 38784 —-a-w- c:\windows\system32\dllcache\io8.sys 2011-12-17 17:32:44 13056 —-a-w- c:\windows\system32\dllcache\inport.sys 2011-12-17 17:29:58 28700 —-a-w- c:\windows\system32\dllcache\ibmexmp.sys 2011-12-17 17:28:57 150239 —-a-w- c:\windows\system32\dllcache\hsf_amos.sys 2011-12-17 17:28:53 19456 —-a-w- c:\windows\system32\dllcache\hr1w.dll 2011-12-17 17:28:50 5760 —-a-w- c:\windows\system32\dllcache\hpt4qic.sys 2011-12-17 17:28:47 13312 —-a-w- c:\windows\system32\dllcache\hpsjmcro.dll 2011-12-17 17:28:45 324608 —-a-w- c:\windows\system32\dllcache\hpojwia.dll 2011-12-17 17:28:26 32768 —-a-w- c:\windows\system32\dllcache\hpgtmcro.dll 2011-12-17 17:28:22 68608 —-a-w- c:\windows\system32\dllcache\hpgt53tk.dll 2011-12-17 17:28:19 165888 —-a-w- c:\windows\system32\dllcache\hpgt53.dll 2011-12-17 17:28:15 31232 —-a-w- c:\windows\system32\dllcache\hpgt42tk.dll 2011-12-17 17:28:12 93696 —-a-w- c:\windows\system32\dllcache\hpgt42.dll 2011-12-17 17:28:08 126976 —-a-w- c:\windows\system32\dllcache\hpgt34tk.dll 2011-12-17 17:28:04 101376 —-a-w- c:\windows\system32\dllcache\hpgt34.dll 2011-12-17 17:28:01 48128 —-a-w- c:\windows\system32\dllcache\hpgt33tk.dll 2011-12-17 17:26:58 455296 —-a-w- c:\windows\system32\dllcache\fusbbase.sys 2011-12-17 17:25:59 45568 —-a-w- c:\windows\system32\dllcache\esunib.dll 2011-12-17 17:24:58 283904 —-a-w- c:\windows\system32\dllcache\emu10k1m.sys 2011-12-17 17:23:58 23808 —-a-w- c:\windows\system32\dllcache\dot4usb.sys 2011-12-17 17:22:59 65622 —-a-w- c:\windows\system32\dllcache\digiasyn.dll 2011-12-17 17:21:58 3072 —-a-w- c:\windows\system32\dllcache\cwbase.sys 2011-12-17 17:20:59 46108 —-a-w- c:\windows\system32\dllcache\cben5.sys 2011-12-17 17:19:58 41472 —-a-w- c:\windows\system32\dllcache\brmfusb.dll 2011-12-17 17:18:53 5632 —-a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll 2011-12-17 01:33:55 ——– d—–w- c:\documents and settings\admin\local settings\application data\PlumChoice, Inc 2011-12-17 01:32:45 ——– d—–w- c:\program files\Cox, Inc 2011-12-17 01:31:25 ——– d—–w- c:\program files\Microsoft WSE 2011-12-17 01:21:18 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll 2011-12-17 01:21:17 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2011-12-17 01:21:10 88736 —-a-w- c:\windows\system32\drivers\mfendisk.sys 2011-12-17 01:21:10 84488 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2011-12-17 01:21:10 84200 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys 2011-12-17 01:21:10 56064 —-a-w- c:\windows\system32\drivers\cfwids.sys 2011-12-17 01:21:10 314088 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2011-12-17 01:21:02 ——– d—–w- c:\program files\common files\Mcafee 2011-12-17 01:21:01 ——– d—–w- c:\program files\McAfee.com 2011-12-17 01:20:35 ——– d—–w- c:\program files\McAfee 2011-12-17 01:10:52 148520 —-a-w- c:\windows\system32\mfevtps.exe 2011-12-17 00:19:13 ——– d—–w- c:\windows\Internet Logs . ==================== Find3M ==================== . 2012-01-14 16:50:14 75264 —-a-w- c:\windows\system32\drivers\ipsec.sys 2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35:08 60416 —-a-w- c:\windows\system32\packager.exe 2011-11-16 14:21:44 354816 —-a-w- c:\windows\system32\winhttp.dll 2011-11-16 14:21:44 152064 —-a-w- c:\windows\system32\schannel.dll 2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20:51 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20:51 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23:59 385024 —-a-w- c:\windows\system32\html.iec 2011-11-03 15:28:36 386048 —-a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28:36 1292288 —-a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll 1956-09-09 16:26:23 3198976 -c–a-w- c:\program files\ViewSonicregistration.exe . ============= FINISH: 14:19:20.21 =============== aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-15 14:26:50 —————————– 14:26:50.078 OS Version: Windows 5.1.2600 Service Pack 3 14:26:50.078 Number of processors: 1 586 0x401 14:26:50.078 ComputerName: DDS2M981 UserName: admin 14:26:51.031 Initialize success 14:29:35.484 AVAST engine defs: 12011501 14:30:19.265 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 14:30:19.265 Disk 0 Vendor: ST340014A 8.16 Size: 38146MB BusType: 3 14:30:19.281 Disk 0 MBR read successfully 14:30:19.296 Disk 0 MBR scan 14:30:19.328 Disk 0 Windows XP default MBR code 14:30:19.343 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 31 MB offset 63 14:30:19.359 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 38107 MB offset 64260 14:30:19.359 Disk 0 scanning sectors +78108030 14:30:19.437 Disk 0 scanning C:\WINDOWS\system32\drivers 14:30:35.859 Service scanning 14:30:36.984 Modules scanning 14:30:51.703 Disk 0 trace - called modules: 14:30:51.734 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 14:30:52.234 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a82dab8] 14:30:52.234 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a83bb00] 14:30:52.468 AVAST engine scan C:\WINDOWS 14:30:59.718 AVAST engine scan C:\WINDOWS\system32 14:33:08.625 AVAST engine scan C:\WINDOWS\system32\drivers 14:33:27.921 AVAST engine scan C:\Documents and Settings\admin 14:41:32.937 AVAST engine scan C:\Documents and Settings\All Users 14:42:23.546 Scan finished successfully 14:50:30.234 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\admin\Desktop\MBR.dat" 14:50:30.265 The log file has been saved successfully to "C:\Documents and Settings\admin\Desktop\aswMBR.txt"
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
After I ran the combofix, it needed to be rebooted and I forgot that I had set my AntiVirus to turn back on after a restart. So when my pc booted back up, the combofix was finishing with the AntiVirus back on. Should I rerun the combofix?
No, that's OK It should have produced a log for you please post the contents of the log If the log didn't pop open it can be located at C:\combofix.txt if there is no log, then please re-run ComboFix
ComboFix 12-01-15.01 - admin 01/15/2012 15:41:27.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1481 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\admin\WINDOWS
C:\install.exe
c:\windows\$NtUninstallKB22421$
c:\windows\$NtUninstallKB22421$\3051610742\@
c:\windows\$NtUninstallKB22421$\3051610742\bckfg.tmp
c:\windows\$NtUninstallKB22421$\3051610742\cfg.ini
c:\windows\$NtUninstallKB22421$\3051610742\Desktop.ini
c:\windows\$NtUninstallKB22421$\3051610742\keywords
c:\windows\$NtUninstallKB22421$\3051610742\kwrd.dll
c:\windows\$NtUninstallKB22421$\3051610742\L\odetmngk
c:\windows\$NtUninstallKB22421$\3051610742\lsflt7.ver
c:\windows\$NtUninstallKB22421$\3051610742\U\00000001.@
c:\windows\$NtUninstallKB22421$\3051610742\U\00000002.@
c:\windows\$NtUninstallKB22421$\3051610742\U\00000004.@
c:\windows\$NtUninstallKB22421$\3051610742\U\80000000.@
c:\windows\$NtUninstallKB22421$\3051610742\U\80000004.@
c:\windows\$NtUninstallKB22421$\3051610742\U\80000032.@
c:\windows\$NtUninstallKB22421$\837058940
c:\windows\iun6002.exe
c:\windows\system32\SETDB5D.tmp
c:\windows\system32\SETDB69.tmp
c:\windows\system32\SETDBB1.tmp
c:\windows\system32\ukhook.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-12-15 to 2012-01-15 )))))))))))))))))))))))))))))))
.
.
2011-12-24 20:32 . 2011-12-24 20:32 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-12-17 17:20 . 2001-08-17 20:13 46108 —-a-w- c:\windows\system32\dllcache\cben5.sys
2011-12-17 17:19 . 2001-08-18 06:36 41472 —-a-w- c:\windows\system32\dllcache\brmfusb.dll
2011-12-17 17:18 . 2001-08-17 20:11 46112 —-a-w- c:\windows\system32\dllcache\adptsf50.sys
2011-12-17 01:33 . 2011-12-17 01:33 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\PlumChoice, Inc
2011-12-17 01:32 . 2011-12-17 01:32 ——– d—–w- c:\program files\Cox, Inc
2011-12-17 01:31 . 2011-12-17 01:31 ——– d—–w- c:\program files\Microsoft WSE
2011-12-17 01:21 . 2011-04-14 22:01 24376 —-a-w- c:\program files\Mozilla Firefox\components\Scriptff.dll
2011-12-17 01:21 . 2011-04-14 22:01 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-12-17 01:21 . 2011-04-14 22:01 88736 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2011-12-17 01:21 . 2011-04-14 22:01 84488 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2011-12-17 01:21 . 2011-04-14 22:01 84200 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-12-17 01:21 . 2011-04-14 22:01 56064 —-a-w- c:\windows\system32\drivers\cfwids.sys
2011-12-17 01:21 . 2011-04-14 22:01 314088 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2011-12-17 01:21 . 2011-12-17 01:21 ——– d—–w- c:\program files\Common Files\Mcafee
2011-12-17 01:20 . 2011-12-17 02:09 ——– d—–w- c:\program files\McAfee
2011-12-17 01:10 . 2011-03-13 19:45 148520 —-a-w- c:\windows\system32\mfevtps.exe
2011-12-17 00:19 . 2011-12-17 00:19 ——– d—–w- c:\windows\Internet Logs
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-14 16:50 . 2004-08-10 17:51 75264 —-a-w- c:\windows\system32\drivers\ipsec.sys
2011-11-25 21:57 . 2004-08-10 17:51 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2004-08-10 17:51 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2004-08-10 17:51 60416 —-a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2004-08-10 17:51 354816 —-a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2004-08-10 17:51 152064 —-a-w- c:\windows\system32\schannel.dll
2011-11-04 19:20 . 2004-08-10 17:51 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-10 17:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-10 17:51 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-10 17:51 385024 —-a-w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2004-08-10 17:51 386048 —-a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-08-10 17:51 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2004-08-10 17:51 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-10 17:50 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2004-08-10 17:51 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-04 03:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2004-08-10 17:51 186880 —-a-w- c:\windows\system32\encdec.dll
1956-09-09 16:26 . 2006-10-15 01:17 3198976 -c–a-w- c:\program files\ViewSonicregistration.exe
2008-06-19 09:16 . 2008-06-19 09:16 118784 -c–a-w- c:\program files\mozilla firefox\plugins\MyCamera.dll
2011-12-21 07:24 . 2011-12-28 04:24 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 22:01 . 2011-12-17 01:21 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VPSKEYS"="c:\program files\Vpskeys\VPSKEYS.EXE" [2003-03-29 102400]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-09-12 180269]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 155648]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-08-06 155648]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2011-04-15 618496]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-09-24 1195408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
c:\documents and settings\admin\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-12-10 113664]
Cox PC HealthCheck.lnk - c:\program files\Cox, Inc\Cox PC HealthCheck\DesktopClient.exe [2010-11-17 53880]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
NETGEAR WG111T Smart Wizard.lnk - c:\program files\NETGEAR\WG111T\wlan111t.exe [2011-2-19 884840]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^admin^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=c:\documents and settings\admin\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=c:\windows\pss\PowerReg Scheduler.exeStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 16:36 114688 —-a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-20 16:35 94208 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-08-06 18:03 155648 —-a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-09-06 22:09 413696 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2003-11-19 22:48 32881 -c–a-w- c:\program files\Java\j2re1.4.2_03\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
2005-08-31 04:31 100056 -c–a-w- c:\progra~1\SYMNET~1\SNDMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2005-09-12 03:58 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"TrkWks"=2 (0x2)
"ShellHWDetection"=2 (0x2)
"SharedAccess"=2 (0x2)
"SENS"=2 (0x2)
"SamSs"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"dmserver"=3 (0x3)
"dmadmin"=3 (0x3)
"CryptSvc"=3 (0x3)
"CiSvc"=3 (0x3)
"Adobe LM Service"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [12/16/2011 5:21 PM 84200]
R2 COX CommunicationsMonitoringService;COX Communications Monitoring Service;c:\program files\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe [11/17/2010 6:56 AM 14456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [12/16/2011 5:21 PM 271480]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [12/16/2011 5:21 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [12/16/2011 5:21 PM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [12/16/2011 5:21 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [12/16/2011 5:10 PM 148520]
R3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [2/21/2011 9:50 AM 816672]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [12/16/2011 5:21 PM 56064]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [12/16/2011 5:21 PM 314088]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [12/16/2011 5:21 PM 88736]
S0 78561617;78561617;c:\windows\system32\drivers\09465183.sys –> c:\windows\system32\drivers\09465183.sys [?]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys –> c:\windows\system32\Drivers\ATHFMWDL.sys [?]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [9/9/2005 6:20 PM 17149]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [12/16/2011 5:21 PM 88736]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [12/16/2011 5:21 PM 84488]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [8/10/2004 9:51 AM 14336]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
intelusbs3 REG_MULTI_SZ intelusb3
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1649451728-3284657741-3551875713-1006Core.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-12 15:48]
.
2012-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1649451728-3284657741-3551875713-1006UA.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-12 15:48]
.
2012-01-15 c:\windows\Tasks\User_Feed_Synchronization-{4BC30354-82BA-47A2-B4EF-23DF1DA65451}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:31]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyServer = http=127.0.0.1:4619
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p;=%s
IE: {{3C34EBD2-038D-4d4f-B081-16D99D8BE2B4} - {361D6100-9833-4ABA-BB50-7015F325BBF0} - c:\windows\Downloaded Program Files\IEPrint.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed] [removed]
DPF: IEPrint - hxxp://www.visiontech.ltd.uk/software/download/IEPrint.CAB
DPF: {F9CD2233-6744-47C1-A6AE-00C30A35F73D} - hxxps://myaccount.cox.net/internettools/scripts/Inspector.cab
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;=
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p;=
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe
HKCU-Run-pyyhysaogoylpd - c:\documents and settings\admin\local settings\application data\hnmerqmq\gjyhjvs.exe
Notify-intelsusb - ntusbw32.dll
Notify-ntusbw32 - ntusbw32.dll
SafeBoot-78561617.sys
SafeBoot-klmdb.sys
MSConfigStartUp-AnyDVD - c:\program files\SlySoft\AnyDVD\AnyDVD.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
AddRemove-Easy CD-DA Extractor 7.5 - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-15 15:58
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,78,18,99,a7,f4,2c,5d,42,a5,7d,36,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,78,18,99,a7,f4,2c,5d,42,a5,7d,36,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3564)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\program files\Vpskeys\VPSKM32.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ImgUtil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-01-15 16:08:08 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-16 00:08
.
Pre-Run: 12,954,148,864 bytes free
Post-Run: 15,322,583,040 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 3AA60224AFCA1036B17E493D46B1774E
Hi

Please do the following:

  • Go to Control Panel and select Internet Options
  • Select the Connections TAB
  • Select LAN settings button
  • Ensure there is no tick in the Proxy Server box
  • Select OK


In I.E.
  • Check internet options settings.
  • Tools > Internet Options > Connections
  • LAN settings
  • Choose "automatically detect settings"
  • uncheck both proxy settings boxes



NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.15.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 admin :: DDS2M981 [administrator] 1/15/2012 4:41:26 PM mbam-log-2012-01-15 (16-41-26).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 161682 Time elapsed: 4 minute(s), 53 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI