This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Trojan? [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello WTT helpers,

It seems like an accidental misclick has invited some sort of trojan or malware into my system. This came after some ad appeared on my computer and I closed it, then clicked "OK" on the dialog box that followed (should have X-ed it, I suppose). Then my system froze for a bit and I restarted it….

As far as I know, my system is operating normally, with one exception: My Avast antivirus has been completely disabled and efforts to bring it back online came to nought (I tried some simple methods suggested online like repairing the install, but nothing worked).

Since my antivirus usually doesn't break so easily, I'm not quite sure what is the problem here and have a lingering worry that there is malware on my system. Could you guys help me check things out? Thanks a lot!

My HijackThis log is as follows:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:06:18 AM, on 1/26/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliType

Pro\itype.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\HP Software

Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Common Files\Java\Java

Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital

Imaging\bin\hpqtra08.exe
C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
C:\Program Files\Microsoft IntelliType

Pro\dpupdchk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web

Printing\hpswp_clipbook.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend

Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection

Wizard,ShellNext = http://codecs.r8.org/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-

C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-

4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!

\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-

BF09-768834316C61} - C:\Program Files\HP\Digital

Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-

A596-FA578C2EBDC3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-

6F74-2D53-2644-206D7942484F} - C:\PROGRA~1

\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-

90988571CECB} - (no file)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D

-D17F00898D06} - C:\Program Files\AVAST

Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-

4C02-4ABF-8ECC-5164760863C6} - C:\Program

Files\Common Files\Microsoft Shared\Windows

Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-

4d91-8333-CF10577473F7} - C:\Program

Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-

7D58-4638-B6FA-CE66B5AD205D} - C:\Program

Files\Google\GoogleToolbarNotifier\5.7.7227.1100

\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper -

{DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program

Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-

4C07-BC86-EABFE594F69C} - C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B

-BDC2-0E72E116A856} - C:\Program Files\HP\Digital

Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2

-892F-0090271D4F88} - C:\Program Files\Yahoo!

\Companion\Installs\cpn\yt.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-

C132-4136-9E9A-4E364A424E17} - C:\Program

Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-

AC2D-D17F00898D06} - C:\Program Files\AVAST

Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4

-9B18-009027A5CD4F} - C:\Program

Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IMJPMIG8.1]

"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil

/RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync]

C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32

\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [GEST] m‘|\ü
O4 - HKLM\..\Run: [NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [itype] "C:\Program

Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [Microsoft Pinyin IME Migration]

C:\PROGRA~1\COMMON~1\MICROS~1\IME12L~1

\imesc\IMSCMig.exe /INSTALL
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction

Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program

Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST

Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program

Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c

start http://www.avg.com/ww.special-uninstallation

-feedback-appf?

lic=NFVIMlctM1NYM0UtR0hHWDktQUZISjMtUFcyUU4tWjlLSDQ

"&"inst=NzctNjMxMjAxNDg4LVQxOC1LVjMrNy1CQSsxLVhMKzE

tQkFSOUcrMS1UQjkrMi1GTCs5LUYxME0rNS1RSVgxKzQtWDIwMT

ArMi1MSUMrMTEtU1AxKzEtRkwxMCsxLVRVRyszLVNQMVMyKzEtU

1VEKzEtUzFJKzEtU1UzKzE"&"prod=90"&"ver=10.0.1382
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program

Files\Windows Live\Messenger\msnmsgr.exe"

/background
O4 - HKCU\..\Run: [swg] "C:\Program

Files\Google\GoogleToolbarNotifier\GoogleToolbarNot

ifier.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program

Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32

\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program

Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [KB984221.exe]

"C:\Documents and

Settings\NetworkService\Application

Data\KB984221.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [KB984221.exe]

"C:\Documents and

Settings\NetworkService\Application

Data\KB984221.exe" (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk.disabled
O4 - Global Startup: HP Digital Imaging Monitor.lnk

= C:\Program Files\HP\Digital

Imaging\bin\hpqtra08.exe
O4 - Global Startup: Belkin F5D8053 N Wireless USB

Adapter Utility.lnk = C:\Program

Files\Belkin\F5D8053\Belkinwcui.exe
O9 - Extra button: HP Smart Select - {DDE87865-

83C5-48c4-8357-2F5B1AA84522} - C:\Program

Files\HP\Digital Imaging\Smart Web

Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4

-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1

\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search &

Destroy Configuration - {DFB852A3-47F8-48C4-A200-

58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134

-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2

-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.area00.com
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: dbsd2pay.dbs.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A}

(SOE Web Installer) -

http://launch.soe.com/plugin/web/SOEWebInstaller.ca

b
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}

(Facebook Photo Uploader 5 Control) -

http://upload.facebook.com/controls/2008.10.10_v5.5

.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}

(System Requirements Lab) -

http://www.nvidia.com/content/DriverDownload/srl/3.

0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}

(WUWebControl Class) -

http://www.update.microsoft.com/windowsupdate/v6/V5

Controls/en/x86/client/wuweb_site.cab?1215078914796
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}

(OnlineScanner Control) -

http://download.eset.com/special/eos-

beta/OnlineScanner.cab
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC}

(EPSON Web Printer-SelfTest Control Class) -

http://selftest.support2.epson.net/For_English/Prg/

ESTPTest.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}

(Facebook Photo Uploader 5 Control) -

http://upload.facebook.com/controls/2009.07.28_v5.5

.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}

(get_atlcom Class) -

http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.

cab
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D}

(SysInfo Class) -

http://content.systemrequirementslab.com.s3.amazona

ws.com/global/bin/srldetect_cyri_4.5.1.0.cab
O22 - SharedTaskScheduler: Browseui preloader -

{438755C2-A8BA-11D1-B96B-00A0C90312E1} -

C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories

cache daemon - {8C7461EF-2B13-11d2-BE35-

3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software -

C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Crypkey License - CrypKey (Canada)

Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Google Update Service (gupdate)

(gupdate) - Google Inc. - C:\Program

Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem)

(gupdatem) - Google Inc. - C:\Program

Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) -

Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager

(IDriverT) - Macrovision Corporation - C:\Program

Files\Common Files\InstallShield\Driver\1150\Intel

32\IDriverT.exe
O23 - Service: Java Quick Starter

(JavaQuickStarterService) - Sun Microsystems, Inc.

- C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc)

- Unknown owner - C:\WINDOWS\system32

\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service

(NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32

\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program

Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 11076 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to Start>Control Panel>Folder Options>View
  • Choose to "Show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
Hello jeffce, thanks for answering my call for help! My antivirus is still not working - no updates, all shields down, unable to scan. So there's really nothing much else to disable on my computer. But I don't see any other problems so far… anyway here are the logs as requested:

DDS:
.
DDS (Ver_2011-08-26.01) - FAT32x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 0:48:29 on 2012-01-28
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3582.2851 [GMT 8:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\svchost.exe -k HPService
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://codecs.r8.org/
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!

\companion\installs\cpn\yt.dll
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web

printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft

shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google

toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program

files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6

\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web

printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: Ant.com Download Toolbar: {2e924f4f-67f0-4bd8-9560-49f468e843d2} - c:\program files\ant.com\ie add-on\AntToolbar.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [GEST] m‘|\ü
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [Microsoft Pinyin IME Migration] c:\progra~1\common~1\micros~1\ime12l~1\imesc\IMSCMig.exe /INSTALL
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-appf?

lic=NFVIMlctM1NYM0UtR0hHWDktQUZISjMtUFcyUU4tWjlLSDQ"&"inst=NzctNjMxMjAxNDg4LVQxOC1LVjMrNy1CQSsxLVhMKzEtQkFSOUcrMS1UQjkrMi1GTC

s5LUYxME0rNS1RSVgxKzQtWDIwMTArMi1MSUMrMTEtU1AxKzEtRkwxMCsxLVRVRyszLVNQMVMyKzEtU1
VEKzEtUzFJKzEtU1UzKzE"&"prod=90"&"ver=10.0.13

82
dRun: [KB984221.exe] "c:\documents and settings\networkservice\application data\KB984221.exe"
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Logitech SetPoint.lnk.disabled
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital

imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\belkin~1.lnk - c:\program files\belkin\f5d8053\Belkinwcui.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital

imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: area00.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: dbs.com\dbsd2pay
Trusted Zone: enets.sg\www
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} - hxxp://launch.soe.com/plugin/web/SOEWebInstaller.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} -

hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-

f7252adaa4f2/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} -

hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -

hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215078914796
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} - hxxp://selftest.support2.epson.net/For_English/Prg/ESTPTest.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -

hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -

hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} -

hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{7EBEB968-16B6-4E34-8598-7EC6155AA707} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{D05AE06E-DD10-4174-97E9-8040AD343390} : DhcpNameServer = 192.168.1.254
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\l7mv0q2m.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\user\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.93\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\windows\downloaded program files\npsoe.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-6-14 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-6-14 314456]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-4-12 218688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-6-14 20568]
R2 AWISp50;AWISp50 NDIS Protocol Driver;c:\windows\system32\drivers\AWISp50.sys [2006-3-15 17664]
R3 AtmElan;ATM Emulated LAN;c:\windows\system32\drivers\atmlane.sys [2004-8-4 55808]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-7-28 517632]
S2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-6-14 44768]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-8 135664]
S3 AmeAtmPc;AmeAtmPc;c:\windows\system32\drivers\ameatmpc.sys [2008-7-3 118391]
S3 AtmLane;ATM LAN Emulation;c:\windows\system32\drivers\atmlane.sys [2004-8-4 55808]
S3 epflt15;epflt15;c:\windows\system32\drivers\epflt15.sys [2008-9-20 14968]
S3 esflt15;esflt15;c:\windows\system32\drivers\esflt15.sys [2008-9-20 14888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-8 135664]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-7-6 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-7-6 8320]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service

[?]
.
=============== Created Last 30 ================
.
2012-01-24 09:59:02 ——– d-sh–w- C:\FOUND.007
2012-01-22 04:59:42 ——– d-sh–w- C:\FOUND.006
2012-01-19 13:36:06 ——– d-sh–w- C:\FOUND.005
2012-01-17 19:01:14 15360 —-a-r- c:\documents and settings\user\application

data\microsoft\installer\{dd8408e9-9421-484f-979d-db6361e3e828}\IconDD8408E910.exe
2012-01-17 19:01:14 11264 —-a-r- c:\documents and settings\user\application

data\microsoft\installer\{dd8408e9-9421-484f-979d-db6361e3e828}\IconDD8408E96.exe
2012-01-17 04:14:07 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll
2012-01-17 04:14:07 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll
2012-01-17 04:14:07 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll
2012-01-17 04:14:07 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll
2012-01-12 04:08:34 ——– d-sh–w- C:\FOUND.004
2012-01-11 18:09:56 6144 —-a-r- c:\documents and settings\user\application

data\microsoft\installer\{83f12f73-d52e-40c0-93b1-463c311c4e17}\Icon83F12F734.exe
2012-01-11 18:09:56 15360 —-a-r- c:\documents and settings\user\application

data\microsoft\installer\{83f12f73-d52e-40c0-93b1-463c311c4e17}\Icon83F12F738.exe
2012-01-11 18:09:56 10752 —-a-r- c:\documents and settings\user\application

data\microsoft\installer\{83f12f73-d52e-40c0-93b1-463c311c4e17}\Icon8255BBAC1.exe
2012-01-09 10:53:28 ——– d-sh–w- C:\FOUND.003
2012-01-09 10:45:38 ——– d-sh–w- C:\FOUND.002
2012-01-06 15:06:40 ——– d-sh–w- C:\FOUND.001
2012-01-03 13:10:44 182672 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2012-01-03 13:10:44 182672 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2012-01-03 07:07:48 ——– d-sh–w- C:\FOUND.000
2011-12-30 14:17:34 ——– d-sh–w- C:\FOUND.219
2011-12-29 03:18:18 ——– d-sh–w- C:\FOUND.218
.
==================== Find3M ====================
.
2012-01-27 12:40:10 4736 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2012-01-17 19:03:46 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2011-12-20 03:16:24 252328 —-a-w- c:\windows\system32\nvdrsdb0.bin
2011-12-20 03:16:24 1 —-a-w- c:\windows\system32\nvdrssel.bin
2011-12-20 03:16:22 252328 —-a-w- c:\windows\system32\nvdrsdb1.bin
2011-12-17 18:45:42 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 07:24:06 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-28 18:01:26 41184 —-a-w- c:\windows\avastSS.scr
2011-11-28 17:53:54 435032 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-25 21:57:20 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35:08 60416 —-a-w- c:\windows\system32\packager.exe
2011-11-16 14:21:44 354816 —-a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21:44 152064 —-a-w- c:\windows\system32\schannel.dll
2011-11-04 19:20:52 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:52 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:52 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:24:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-03 15:28:36 386048 —-a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28:36 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
.
============= FINISH: 0:49:16.34 ===============

aswMBR:

aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software
Run date: 2012-01-28 00:52:43
—————————–
00:52:43.875 OS Version: Windows 5.1.2600 Service Pack 3
00:52:43.875 Number of processors: 4 586 0x1707
00:52:43.875 ComputerName: USER-EE7ECB5E1A UserName: user
00:52:44.343 Initialize success
00:52:44.515 AVAST engine defs: 12012500
00:53:34.921 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
00:53:34.921 Disk 0 Vendor: ST3160021A 8.01 Size: 152627MB BusType: 3
00:53:34.937 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-1f
00:53:34.937 Disk 1 Vendor: Hitachi_HDT725032VLA360 V54OA7EA Size: 305244MB BusType: 3
00:53:34.937 Disk 1 MBR read successfully
00:53:34.937 Disk 1 MBR scan
00:53:35.343 Disk 1 Windows XP default MBR code
00:53:35.375 Disk 1 Partition 1 80 (A) 0C FAT32 LBA MSWIN4.1 120738 MB offset 63
00:53:35.671 Disk 1 Partition - 00 0F Extended LBA 184504 MB offset 247272480
00:53:35.687 Disk 1 Partition 2 00 0B FAT32 MSWIN4.1 184504 MB offset 247272543
00:53:35.843 Disk 1 scanning sectors +625137345
00:53:35.953 Disk 1 scanning C:\WINDOWS\system32\drivers
00:53:45.609 Service scanning
00:53:46.437 Modules scanning
00:53:51.531 Disk 1 trace - called modules:
00:53:51.546 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
00:53:51.546 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8b28f758]
00:53:51.546 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> \Device\0000007d[0x8b268e00]
00:53:51.546 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-1f[0x8b1d8940]
00:53:52.203 AVAST engine scan C:\WINDOWS
00:54:03.640 AVAST engine scan C:\WINDOWS\system32
00:55:07.203 AVAST engine scan C:\WINDOWS\system32\drivers
00:55:12.906 AVAST engine scan C:\Documents and Settings\user
00:58:43.218 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\user\Desktop\MBR.dat"
00:58:43.218 The log file has been saved successfully to "C:\Documents and Settings\user\Desktop\aswMBR.txt"

Is that all for aswMBR? It seemed to end pretty quickly after initialisation - or should I have waited longer? (Also, the attach.txt file is er… as attached. Hehe. :))

Thanks once again.

Attachments:

Hi Foxtrot,

Good job getting those logs. :)
———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
Hmm, ComboFix says that my Avast! is running, when I see a huge red "X" over its system tray icon. I decided to right-click on it, and disabled my Avast! permanently… (or so it says). Can I continue with ComboFix?
Okay, here goes:

ComboFix 12-01-27.01 - user 01/28/2012 2:00.5.4 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3582.2825 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\1CA73D29.TMP
c:\documents and settings\All Users\Application Data\TEMP\C31F31E6.TMP
.
.
((((((((((((((((((((((((( Files Created from 2011-12-27 to 2012-01-27 )))))))))))))))))))))))))))))))
.
.
2012-01-24 09:59 . 2012-01-24 09:59 ——– d—–w- C:\FOUND.007
2012-01-22 04:59 . 2012-01-22 04:59 ——– d—–w- C:\FOUND.006
2012-01-19 13:36 . 2012-01-19 13:36 ——– d—–w- C:\FOUND.005
2012-01-17 19:01 . 2012-01-17 19:01 15360 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe
2012-01-17 19:01 . 2012-01-17 19:01 11264 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe
2012-01-17 04:14 . 2012-01-17 04:14 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-17 04:14 . 2012-01-17 04:14 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-17 04:14 . 2012-01-17 04:14 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-17 04:14 . 2012-01-17 04:14 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-01-12 04:08 . 2012-01-12 04:08 ——– d—–w- C:\FOUND.004
2012-01-11 18:09 . 2012-01-11 18:09 6144 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F734.exe
2012-01-11 18:09 . 2012-01-11 18:09 15360 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F738.exe
2012-01-11 18:09 . 2012-01-11 18:09 10752 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon8255BBAC1.exe
2012-01-09 10:53 . 2012-01-09 10:53 ——– d—–w- C:\FOUND.003
2012-01-09 10:45 . 2012-01-09 10:45 ——– d—–w- C:\FOUND.002
2012-01-06 15:06 . 2012-01-06 15:06 ——– d—–w- C:\FOUND.001
2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2012-01-03 07:07 . 2012-01-03 07:07 ——– d—–w- C:\FOUND.000
2011-12-30 14:17 . 2011-12-30 14:17 ——– d—–w- C:\FOUND.219
2011-12-29 03:18 . 2011-12-29 03:18 ——– d—–w- C:\FOUND.218
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-27 12:40 . 2011-06-15 12:36 4736 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2012-01-17 19:03 . 2008-08-23 04:22 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2011-12-17 18:45 . 2011-12-17 15:20 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 07:24 . 2011-06-15 11:43 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-28 18:01 . 2011-06-14 15:36 41184 —-a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-06-14 15:36 199816 —-a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-06-14 15:36 435032 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-06-14 15:36 314456 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-06-14 15:36 34392 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-06-14 15:36 52952 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-06-14 15:36 111320 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:52 . 2011-06-14 15:36 105176 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2011-06-14 15:36 20568 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2011-06-14 15:36 30808 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2004-08-04 03:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2004-08-04 03:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2004-08-04 03:00 60416 —-a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2004-08-04 03:00 354816 —-a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2004-08-04 03:00 152064 —-a-w- c:\windows\system32\schannel.dll
2011-11-04 19:20 . 2004-08-04 03:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-04 03:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-04 03:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:24 . 2004-08-04 03:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2004-08-04 03:00 386048 —-a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-08-04 03:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2004-08-04 03:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2012-01-17 04:14 . 2011-05-13 17:03 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-13 68856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
"Microsoft Pinyin IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12L~1\imesc\IMSCMig.exe" [2008-04-11 38448]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-07 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-07 13880424]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1382" [?]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk.disabled [2008-10-31 1596]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Belkin F5D8053 N Wireless USB Adapter Utility.lnk - c:\program files\Belkin\F5D8053\Belkinwcui.exe [2007-9-17 1732608]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 06:39 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-07-13 11:21 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"f:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Microsoft Games\\Mechwarrior Mercenaries\\MW4Mercs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\USER\\Local Settings\\Application Data\\Xenocode\\Sandbox\\2.2.3337.18747\\2009.02.19T16.33\\Native\\STUBEXE\\@PROGRAMFILES@\\Microsoft Games\\Allegiance\\ALLEGIANCE.EXE"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"e:\\Dawn of War II\\DOW2.exe"=
"e:\\Warhammer 40000 Dawn of War II - Chaos Rising\\DOW2.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=
"c:\\Documents and Settings\\user\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\StarCraft II\\StarCraft II.exe"=
"e:\\StarCraft II\\Versions\\Base16939\\SC2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\javaw.exe"=
"e:\\DoWar2R\\DOW2.exe"=
"e:\command & conquer 4 tiberian twilight\CNC4.exe"= e:\command & conquer 4 tiberian twilight\CNC4.exe:127.0.0.1/255.255.255.255:Enabled:Command & Conquer™ 4 Tiberian Twilight
"e:\\Command & Conquer 4 Tiberian Twilight\\Data\\CNC4.game"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"f:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"e:\\W40k.exe"=
"e:\\W40kWA.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58241:TCP"= 58241:TCP:Pando Media Booster
"58241:UDP"= 58241:UDP:Pando Media Booster
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [6/14/2011 11:36 PM 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6/14/2011 11:36 PM 314456]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [4/12/2011 2:05 AM 218688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2011 11:36 PM 20568]
R2 AWISp50;AWISp50 NDIS Protocol Driver;c:\windows\system32\drivers\AWISp50.sys [3/15/2006 4:35 PM 17664]
R3 AtmElan;ATM Emulated LAN;c:\windows\system32\drivers\atmlane.sys [8/4/2004 11:00 AM 55808]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/8/2010 4:34 PM 135664]
S3 AmeAtmPc;AmeAtmPc;c:\windows\system32\drivers\ameatmpc.sys [7/3/2008 9:29 PM 118391]
S3 AtmLane;ATM LAN Emulation;c:\windows\system32\drivers\atmlane.sys [8/4/2004 11:00 AM 55808]
S3 epflt15;epflt15;c:\windows\system32\drivers\epflt15.sys [9/20/2008 4:31 PM 14968]
S3 esflt15;esflt15;c:\windows\system32\drivers\esflt15.sys [9/20/2008 4:31 PM 14888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/8/2010 4:34 PM 135664]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [7/6/2009 9:19 AM 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [7/6/2009 9:19 AM 8320]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [7/5/2008 2:56 PM 717296]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 08:33]
.
2012-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 08:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://codecs.r8.org/
Trusted Zone: area00.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: dbs.com\dbsd2pay
Trusted Zone: enets.sg\www
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\l7mv0q2m.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
.
- - - - ORPHANS REMOVED - - - -
.
HKU-Default-Run-KB984221.exe - c:\documents and settings\NetworkService\Application Data\KB984221.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-28 02:13
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-117609710-1993962763-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a1,14,ae,4e,46,61,8e,29,5e,ec,10,b6,d1,8c,31,73,cb,38,0d,47,84,70,a5,
44,ff,39,83,bf,72,4a,5d,2e,03,5b,70,b2,9c,b8,ce,d7,43,64,a8,f7,26,10,28,db,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
.
[HKEY_USERS\S-1-5-21-117609710-1993962763-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:aa,bc,3d,2b,8c,f1,9b,f7,f1,4c,a3,7d,77,ff,9d,04,03,cb,a9,89,97,
fe,e7,c4,c1,ac,04,3e,3a,cc,18,4d,72,71,da,0e,70,6a,56,de,7e,fc,d1,04,bb,51,\
"rkeysecu"=hex:bf,0d,15,12,0d,b6,9a,43,7c,a9,48,eb,b1,c0,1d,5e
.
Completion time: 2012-01-28 02:18:58
ComboFix-quarantined-files.txt 2012-01-27 18:18
.
Pre-Run: 3,288,662,016 bytes free
Post-Run: 4,633,821,184 bytes free
.
- - End Of File - - 0C469D6E173F61C4F7410EC3E67DFA11
Hi foxtrot,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
    TB: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File
    TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
    dRun: [KB984221.exe] "c:\documents and settings\networkservice\application data\KB984221.exe"
    Trusted Zone: area00.com
    Trusted Zone: clonewarsadventures.com
    Trusted Zone: dbs.com\dbsd2pay
    Trusted Zone: enets.sg\www
    Trusted Zone: freerealms.com
    Trusted Zone: soe.com
    Trusted Zone: sony.com
    
    Folder::
    C:\FOUND.007
    C:\FOUND.006
    C:\FOUND.005
    C:\FOUND.004
    C:\FOUND.003
    C:\FOUND.002
    C:\FOUND.001
    C:\FOUND.000
    C:\FOUND.219
    C:\FOUND.218
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "58241:TCP"=-
    "58241:UDP"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Here it is:

ComboFix 12-01-27.01 - user 01/28/2012 11:42:58.6.4 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3582.2813 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\FOUND.000
c:\found.000\FILE0000.CHK
c:\found.000\FILE0001.CHK
c:\found.000\FILE0002.CHK
C:\FOUND.001
c:\found.001\FILE0000.CHK
c:\found.001\FILE0001.CHK
c:\found.001\FILE0002.CHK
c:\found.001\FILE0003.CHK
c:\found.001\FILE0004.CHK
c:\found.001\FILE0005.CHK
C:\FOUND.002
c:\found.002\FILE0000.CHK
c:\found.002\FILE0001.CHK
c:\found.002\FILE0002.CHK
c:\found.002\FILE0003.CHK
c:\found.002\FILE0004.CHK
c:\found.002\FILE0005.CHK
c:\found.002\FILE0006.CHK
c:\found.002\FILE0007.CHK
c:\found.002\FILE0008.CHK
c:\found.002\FILE0009.CHK
c:\found.002\FILE0010.CHK
c:\found.002\FILE0011.CHK
c:\found.002\FILE0012.CHK
c:\found.002\FILE0013.CHK
c:\found.002\FILE0014.CHK
c:\found.002\FILE0015.CHK
c:\found.002\FILE0016.CHK
c:\found.002\FILE0017.CHK
c:\found.002\FILE0018.CHK
c:\found.002\FILE0019.CHK
c:\found.002\FILE0020.CHK
c:\found.002\FILE0021.CHK
c:\found.002\FILE0022.CHK
c:\found.002\FILE0023.CHK
c:\found.002\FILE0024.CHK
c:\found.002\FILE0025.CHK
c:\found.002\FILE0026.CHK
c:\found.002\FILE0027.CHK
c:\found.002\FILE0028.CHK
c:\found.002\FILE0029.CHK
c:\found.002\FILE0030.CHK
c:\found.002\FILE0031.CHK
c:\found.002\FILE0032.CHK
c:\found.002\FILE0033.CHK
c:\found.002\FILE0034.CHK
C:\FOUND.003
c:\found.003\FILE0000.CHK
C:\FOUND.004
c:\found.004\FILE0000.CHK
c:\found.004\FILE0001.CHK
c:\found.004\FILE0002.CHK
c:\found.004\FILE0003.CHK
c:\found.004\FILE0004.CHK
c:\found.004\FILE0005.CHK
c:\found.004\FILE0006.CHK
c:\found.004\FILE0007.CHK
c:\found.004\FILE0008.CHK
c:\found.004\FILE0009.CHK
c:\found.004\FILE0010.CHK
c:\found.004\FILE0011.CHK
c:\found.004\FILE0012.CHK
c:\found.004\FILE0013.CHK
C:\FOUND.005
c:\found.005\FILE0000.CHK
C:\FOUND.006
c:\found.006\FILE0000.CHK
c:\found.006\FILE0001.CHK
c:\found.006\FILE0002.CHK
c:\found.006\FILE0003.CHK
c:\found.006\FILE0004.CHK
c:\found.006\FILE0005.CHK
c:\found.006\FILE0006.CHK
c:\found.006\FILE0007.CHK
c:\found.006\FILE0008.CHK
c:\found.006\FILE0009.CHK
c:\found.006\FILE0010.CHK
C:\FOUND.007
c:\found.007\FILE0000.CHK
C:\FOUND.218
c:\found.218\FILE0000.CHK
C:\FOUND.219
c:\found.219\FILE0000.CHK
c:\found.219\FILE0001.CHK
c:\found.219\FILE0002.CHK
c:\found.219\FILE0003.CHK
c:\found.219\FILE0004.CHK
.
.
((((((((((((((((((((((((( Files Created from 2011-12-28 to 2012-01-28 )))))))))))))))))))))))))))))))
.
.
2012-01-17 19:01 . 2012-01-17 19:01 15360 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe
2012-01-17 19:01 . 2012-01-17 19:01 11264 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe
2012-01-17 04:14 . 2012-01-17 04:14 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-17 04:14 . 2012-01-17 04:14 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-17 04:14 . 2012-01-17 04:14 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-17 04:14 . 2012-01-17 04:14 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-01-11 18:09 . 2012-01-11 18:09 6144 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F734.exe
2012-01-11 18:09 . 2012-01-11 18:09 15360 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F738.exe
2012-01-11 18:09 . 2012-01-11 18:09 10752 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon8255BBAC1.exe
2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-27 12:40 . 2011-06-15 12:36 4736 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2012-01-17 19:03 . 2008-08-23 04:22 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2011-12-17 18:45 . 2011-12-17 15:20 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 07:24 . 2011-06-15 11:43 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-28 18:01 . 2011-06-14 15:36 41184 —-a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-06-14 15:36 199816 —-a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-06-14 15:36 435032 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-06-14 15:36 314456 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-06-14 15:36 34392 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-06-14 15:36 52952 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-06-14 15:36 111320 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:52 . 2011-06-14 15:36 105176 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2011-06-14 15:36 20568 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2011-06-14 15:36 30808 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2004-08-04 03:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2004-08-04 03:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2004-08-04 03:00 60416 —-a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2004-08-04 03:00 354816 —-a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2004-08-04 03:00 152064 —-a-w- c:\windows\system32\schannel.dll
2011-11-04 19:20 . 2004-08-04 03:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-04 03:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-04 03:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:24 . 2004-08-04 03:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2004-08-04 03:00 386048 —-a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-08-04 03:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2004-08-04 03:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2012-01-17 04:14 . 2011-05-13 17:03 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-13 68856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
"Microsoft Pinyin IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12L~1\imesc\IMSCMig.exe" [2008-04-11 38448]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-07 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-07 13880424]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1382" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"KB984221.exe"="c:\documents and settings\NetworkService\Application Data\KB984221.exe" [BU]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk.disabled [2008-10-31 1596]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Belkin F5D8053 N Wireless USB Adapter Utility.lnk - c:\program files\Belkin\F5D8053\Belkinwcui.exe [2007-9-17 1732608]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 06:39 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-07-13 11:21 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"f:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Microsoft Games\\Mechwarrior Mercenaries\\MW4Mercs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\USER\\Local Settings\\Application Data\\Xenocode\\Sandbox\\2.2.3337.18747\\2009.02.19T16.33\\Native\\STUBEXE\\@PROGRAMFILES@\\Microsoft Games\\Allegiance\\ALLEGIANCE.EXE"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"e:\\Dawn of War II\\DOW2.exe"=
"e:\\Warhammer 40000 Dawn of War II - Chaos Rising\\DOW2.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=
"c:\\Documents and Settings\\user\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\StarCraft II\\StarCraft II.exe"=
"e:\\StarCraft II\\Versions\\Base16939\\SC2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\javaw.exe"=
"e:\\DoWar2R\\DOW2.exe"=
"e:\command & conquer 4 tiberian twilight\CNC4.exe"= e:\command & conquer 4 tiberian twilight\CNC4.exe:127.0.0.1/255.255.255.255:Enabled:Command & Conquer™ 4 Tiberian Twilight
"e:\\Command & Conquer 4 Tiberian Twilight\\Data\\CNC4.game"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"f:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"e:\\W40k.exe"=
"e:\\W40kWA.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [6/14/2011 11:36 PM 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6/14/2011 11:36 PM 314456]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [4/12/2011 2:05 AM 218688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2011 11:36 PM 20568]
R2 AWISp50;AWISp50 NDIS Protocol Driver;c:\windows\system32\drivers\AWISp50.sys [3/15/2006 4:35 PM 17664]
R3 AtmElan;ATM Emulated LAN;c:\windows\system32\drivers\atmlane.sys [8/4/2004 11:00 AM 55808]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/8/2010 4:34 PM 135664]
S3 AmeAtmPc;AmeAtmPc;c:\windows\system32\drivers\ameatmpc.sys [7/3/2008 9:29 PM 118391]
S3 AtmLane;ATM LAN Emulation;c:\windows\system32\drivers\atmlane.sys [8/4/2004 11:00 AM 55808]
S3 epflt15;epflt15;c:\windows\system32\drivers\epflt15.sys [9/20/2008 4:31 PM 14968]
S3 esflt15;esflt15;c:\windows\system32\drivers\esflt15.sys [9/20/2008 4:31 PM 14888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/8/2010 4:34 PM 135664]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [7/6/2009 9:19 AM 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [7/6/2009 9:19 AM 8320]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [7/5/2008 2:56 PM 717296]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 08:33]
.
2012-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 08:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://codecs.r8.org/
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\l7mv0q2m.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-28 11:55
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-117609710-1993962763-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a1,14,ae,4e,46,61,8e,29,5e,ec,10,b6,d1,8c,31,73,cb,38,0d,47,84,70,a5,
44,ff,39,83,bf,72,4a,5d,2e,03,5b,70,b2,9c,b8,ce,d7,43,64,a8,f7,26,10,28,db,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
.
[HKEY_USERS\S-1-5-21-117609710-1993962763-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:aa,bc,3d,2b,8c,f1,9b,f7,f1,4c,a3,7d,77,ff,9d,04,03,cb,a9,89,97,
fe,e7,c4,c1,ac,04,3e,3a,cc,18,4d,72,71,da,0e,70,6a,56,de,7e,fc,d1,04,bb,51,\
"rkeysecu"=hex:bf,0d,15,12,0d,b6,9a,43,7c,a9,48,eb,b1,c0,1d,5e
.
Completion time: 2012-01-28 12:00:27
ComboFix-quarantined-files.txt 2012-01-28 04:00
.
Pre-Run: 4,642,865,152 bytes free
Post-Run: 4,663,017,472 bytes free
.
- - End Of File - - B90C5C9A3261EAC83141B092CAE03656
Hi foxtrot,

I see that you have Malwarebytes on your system. Please open Malwarebytes, update it and then run a Quick Scan. Please save the log that is created for your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by Malwarebytes and ESET online scan. :)
Hey jeffce, I seem to have run into a tiny problem: ESET Online Scanner is unable to update itself - it asks me if my proxy is configured. I don't remember changing any connection settings or anything.
Hi,

Glad to hear that Malwarebytes came back clean. Let's try a different online scan. :)
————-

Do an online scan with BitDefender QuickScan.
Please be patient as scanning may take some time. If you have problem running the scan, you might want to disable any real time protection that you have.
  • Click here to go to BitDefender QuickScan page.
  • For Firefox users:
    • Click on Free Scan Now. You will be prompted to install a plug-in. Please Allow. In case you get stuck, please refresh the page to try again.
    • A Software Installation window will appear. Click Install Now and the plugin will be installed as an Add-on.
    • Restart Firefox when done. Go back to the BitDefender QuickScan page again and click on Free Scan Now and proceed accordingly.
  • For Internet Explorer users:
    • Click on Free Scan Now. You will be prompted to install an ActiveX control. Please install.
    • The page will refresh. Click on Free Scan Now again and proceed accordingly.
  • When scan has completed, click on View report and a Notepad log shall open.
  • If there are any infections found, you will get a warning and the link to the report will be displayed as the number of infections. Click on it.
  • Post back the contents of this report. It can also be found at C:\Documents and Settings\\Application Data\QuickScan, is the Windows log-in name.
Alright, here are the logs from MBAM and QuickScan: Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.28.04 Windows XP Service Pack 3 x86 FAT32 Internet Explorer 8.0.6001.18702 user :: USER-EE7ECB5E1A [administrator] 1/28/2012 11:49:14 PM mbam-log-2012-01-28 (23-49-14).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 170416 Time elapsed: 3 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ********** QuickScan 32-bit v0.9.9.105 ————————— Scan date: Sun Jan 29 21:34:22 2012 Machine ID: 3B5611DD No infection found. ——————- Processes ——— hpwuSchd Application 1904 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe avast! Antivirus 1928 C:\Program Files\AVAST Software\Avast\AvastUI.exe Belkin Wireless Client Utility 152 C:\Program Files\Belkin\F5D8053\Belkinwcui.exe CrypKey Software Licensing System 788 C:\WINDOWS\System32\Crypserv.exe DAEMON Tools Lite 1988 C:\Program Files\DAEMON Tools Lite\DTLite.exe hp digital imaging - hp all-in-one seri 132 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe HP Smart Web Printing 3028 C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe Java™ Platform SE 6 U29 1588 C:\Program Files\Java\jre6\bin\jqs.exe Java™ Platform SE Auto Updater 2 0 1960 C:\Program Files\Common Files\Java\Java Update\jusched.exe Microsoft IntelliPoint 2028 C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe Microsoft IntelliType Pro 1872 C:\Program Files\Microsoft IntelliType Pro\itype.exe Microsoft® Windows® Operating System 600 C:\WINDOWS\System32\spoolsv.exe NVIDIA Driver Helper Service, Version 2 1136 C:\WINDOWS\System32\nvsvc32.exe Realtek HD Audio Sound Effect Manager 1856 C:\WINDOWS\RTHDCPL.EXE (verified) Microsoft® Windows® Operating System 1672 C:\WINDOWS\Explorer.EXE (verified) Microsoft® Windows® Operating System 2748 C:\WINDOWS\System32\alg.exe (verified) Microsoft® Windows® Operating System 904 C:\WINDOWS\System32\csrss.exe (verified) Microsoft® Windows® Operating System 2004 C:\WINDOWS\System32\ctfmon.exe (verified) Microsoft® Windows® Operating System 984 C:\WINDOWS\System32\lsass.exe (verified) Microsoft® Windows® Operating System 1912 C:\WINDOWS\System32\RUNDLL32.EXE (verified) Microsoft® Windows® Operating System 972 C:\WINDOWS\System32\services.exe (verified) Microsoft® Windows® Operating System 688 C:\WINDOWS\System32\smss.exe (verified) Microsoft® Windows® Operating System 1644 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1852 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 752 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 876 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1180 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1188 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1212 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1256 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1296 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1340 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1388 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1420 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1472 C:\WINDOWS\System32\svchost.exe (verified) Microsoft® Windows® Operating System 928 C:\WINDOWS\System32\winlogon.exe (verified) Windows® Internet Explorer 1576 C:\Program Files\Internet Explorer\IEXPLORE.EXE (verified) Windows® Internet Explorer 828 C:\Program Files\Internet Explorer\IEXPLORE.EXE (verified) Windows® Internet Explorer 3692 C:\Program Files\Internet Explorer\IEXPLORE.EXE Network activity —————- Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> 91.199.104.31 Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> [removed] Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> [removed] Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> [removed] Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> [removed] Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> [removed] Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> [removed] Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> [removed] Process IEXPLORE.EXE (3692) connected on port 443 (HTTP over SSL) –> [removed] Process IEXPLORE.EXE (3692) connected on port 80 (HTTP) –> [removed] Process svchost.exe (1256) listens on ports: 135 (RPC) Process svchost.exe (1472) listens on ports: 2869 (SSDP event notification, UPNP) Autoruns and critical files ————————— hpwuSchd Application C:\Program Files\HP\HP Software Update\hpwuSchd2.exe Adobe Reader and Acrobat Manager C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastUI.exe Belkin Wireless Client Utility C:\Program Files\Belkin\F5D8053\Belkinwcui.exe DAEMON Tools Lite C:\Program Files\DAEMON Tools Lite\DTLite.exe hp digital imaging - hp all-in-one seri C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe Java™ Platform SE Auto Updater 2 0 C:\Program Files\Common Files\Java\Java Update\jusched.exe Logitech SetPoint C:\WINDOWS\KHALMNPR.EXE Microsoft IntelliType Pro C:\Program Files\Microsoft IntelliType Pro\itype.exe Microsoft Pinyin IME 2007 C:\PROGRA~1\COMMON~1\MICROS~1\IME12L~1\imesc\IMSCMig.exe Microsoft® Windows® Operating System C:\WINDOWS\system32\CRYPT32.dll Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll Microsoft® Windows® Operating System C:\WINDOWS\System32\CSCDLL.dll Microsoft® Windows® Operating System C:\WINDOWS\System32\dimsntfy.dll Microsoft® Windows® Operating System C:\WINDOWS\system32\SHELL32.dll Microsoft® Windows® Operating System c:\windows\system32\userinit.exe Microsoft® Windows® Operating System C:\WINDOWS\system32\WlNotify.dll NVIDIA Compatible Windows 2000 Display C:\WINDOWS\system32\NvCpl.dll NVIDIA Media Center Library C:\WINDOWS\system32\NvMcTray.dll Realtek HD Audio Sound Effect Manager C:\WINDOWS\RTHDCPL.EXE 新注音 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE (verified) Ahead Software Gmbh NeroCheck C:\WINDOWS\system32\NeroCheck.exe (verified) Google Update C:\Program Files\Google\Update\GoogleUpdate.exe (verified) GoogleToolbarNotifier C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (verified) Microsoft IME 2002 C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\BROWSEUI.dll (verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\cmd.exe (verified) Microsoft® Windows® Operating System C:\WINDOWS\System32\ctfmon.exe (verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe (verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll (verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll (verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\WPDShServiceObj.dll (verified) Windows® Internet Explorer C:\WINDOWS\system32\webcheck.dll Browser plugins ————— AcroIEHelperShim Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll Adobe Acrobat C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll avast! WebRep C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BitDefender QuickScan C:\WINDOWS\Downloaded Program Files\qsax.dll DivX Player Netscape Plugin C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll DivX Web Player C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll Facebook Photo Uploader 5 C:\WINDOWS\Downloaded Program Files\ImageUploader5.ocx Facebook Photo Uploader 5 C:\WINDOWS\Downloaded Program Files\PhotoUploader5.ocx Facebook Photo Uploader 5 C:\WINDOWS\Downloaded Program Files\PhotoUploader55.ocx Google Toolbar for Internet Explorer C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll Google Update C:\Program Files\Google\Update\1.3.21.93\npGoogleUpdate3.dll GoogleToolbarNotifier C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll HP Smart Web Printing C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll HP Smart Web Printing C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll IEAWSDC.DLL C:\WINDOWS\Downloaded Program Files\IEAWSDC.DLL Java Deployment Toolkit 6.0.290.11 C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll Java™ Platform SE 6 U29 C:\Program Files\Java\jre6\bin\jp2ssv.dll Java™ Platform SE 6 U29 C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll Java™ Platform SE 6 U29 C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll Messenger C:\Program Files\Messenger\msmsgs.exe Microsoft® Windows® Operating System C:\WINDOWS\System32\mswsock.dll Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll Microsoft® Windows® Operating System C:\WINDOWS\System32\winrnr.dll Nexon Game Controller C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll npsoe.dll C:\WINDOWS\Downloaded Program Files\npsoe.dll NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll RealJukebox NS Plugin C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll RealJukebox NS Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll RealPlayer™ G2 LiveConnect-Enabled P C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll RealPlayer™ G2 LiveConnect-Enabled P C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll SDHelper.dll C:\Program Files\Spybot - Search & Destroy\SDHelper.dll Shockwave for Director C:\WINDOWS\system32\Adobe\Director\np32dsw.dll System Requirements Lab C:\WINDOWS\Downloaded Program Files\sysreqlab_nvd.dll TVU Web Player for FireFox C:\WINDOWS\system32\TVUAx\npTVUAx.dll Unity Player C:\Documents and Settings\user\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll Windows Presentation Foundation C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll Windows® Internet Explorer C:\WINDOWS\system32\IEFRAME.dll Yahoo! Toolbar c:\program files\yahoo!\companion\installs\cpn\yt.dll (verified) Microsoft® Windows Live Login Helper C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (verified) Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (verified) QuickTime Plug-in 7.6.6 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (verified) QuickTime Plug-in 7.6.6 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (verified) QuickTime Plug-in 7.6.6 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (verified) QuickTime Plug-in 7.6.6 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (verified) QuickTime Plug-in 7.6.6 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (verified) QuickTime Plug-in 7.6.6 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (verified) RealPlayer Version Plugin C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll (verified) RealPlayer Version Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll Missing files ————- File not found: m‘|\ü –> HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"GEST" Scan —- MD5: f4dcc3149ef542af4e55b4e9def96736 C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll MD5: abe43645a327bd9e8942d2034a054b06 C:\Documents and Settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll MD5: a63259925adb2a1181c712513ebfb8ed C:\Documents and Settings\user\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll MD5: 8082f66dc9c8167ff1aa548736f58457 C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll MD5: ffaa62e671f4604f729063640befd039 C:\Program Files\AVAST Software\Avast\1033\Base.dll MD5: cd76996b881fb8e96b4ec2210e6934b8 C:\Program Files\AVAST Software\Avast\1033\UILangRes.dll MD5: 9e9898d12608f8fbbd3ab3b9cde010c6 C:\Program Files\AVAST Software\Avast\Aavm4h.dll MD5: b0e0b1b2f651e3c3917d4bec88be57f4 C:\Program Files\AVAST Software\Avast\AavmRpch.dll MD5: ca4ddb5cb61b905a4407c5fb76527437 C:\Program Files\AVAST Software\Avast\ashBase.dll MD5: 7a4a6056b53f36db50bcb8a334bad2b6 C:\Program Files\AVAST Software\Avast\ashShell.dll MD5: b821ced9f11f12f5dff8e983fc32aea2 C:\Program Files\AVAST Software\Avast\ashTask.dll MD5: bef4f20a11c0fe612d2d521a502cca52 C:\Program Files\AVAST Software\Avast\ashTaskEx.dll MD5: 1d352baff5a4b2e5e163bb6e652daf49 C:\Program Files\AVAST Software\Avast\aswAux.dll MD5: 5a996ce86bda5ff1b628b21b9871287a C:\Program Files\AVAST Software\Avast\aswCmnBS.dll MD5: 85e7f7d95de30a2008c75726cfc3ad61 C:\Program Files\AVAST Software\Avast\aswCmnIS.dll MD5: 928f0fc896d10b099588a1d5aa46b1bf C:\Program Files\AVAST Software\Avast\aswCmnOS.dll MD5: bdf5080dc5de21a5f662e45d57926233 C:\Program Files\AVAST Software\Avast\aswData.dll MD5: 09cb9ae8bbc2512d9818987e721abe32 C:\Program Files\AVAST Software\Avast\aswEngLdr.dll MD5: 4f91c0b574919537defdb406ffd94430 C:\Program Files\AVAST Software\Avast\aswLog.dll MD5: aee62a34b70cbea34ebe384d529312cb C:\Program Files\AVAST Software\Avast\aswProperty.dll MD5: 388d8dd599c04577edff52e79c451bd7 C:\Program Files\AVAST Software\Avast\aswSqLt.dll MD5: 99d5d540f154f29896c2f570938c6ceb C:\Program Files\AVAST Software\Avast\aswUtil.dll MD5: 328bc79bc53ba7a284c818dde88945d7 C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll MD5: 996e6d052438e8d8dfd501f31560b2e0 C:\Program Files\AVAST Software\Avast\AvastSvc.exe MD5: f7226aa410954185160067d5fa82f3f2 C:\Program Files\AVAST Software\Avast\AvastUI.exe MD5: c4b742a1bac5f35d9223619f94acb45f C:\Program Files\AVAST Software\Avast\CommonRes.dll MD5: 707e5bf1e3f53ea4c17cd44f9b602a1a C:\Program Files\AVAST Software\Avast\defs\12012500\uiExt.dll MD5: 4ab33334ecbce65b1097c47f5f3da330 C:\Program Files\Belkin\F5D8053\BelkinHWStatus.dll MD5: 26b5e3509912e2518f3a0490bd0f12a7 C:\Program Files\Belkin\F5D8053\Belkinwcui.exe MD5: b0767ff3887e2dcd580645d7bf662168 C:\Program Files\Belkin\F5D8053\BelkinwcuiDLL.dll MD5: bd8f2b808ceed4f04575aa885fef302b C:\Program Files\Belkin\F5D8053\blkwcarc.DLL MD5: 78b3dd4e17883cfe0185d3c948f55f0c C:\Program Files\Belkin\F5D8053\W32N55.dll MD5: bea99c8ce8583bd99d0e73ab018f204e C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll MD5: 8a3ba48b5be893e1d81bfac17a3c1b1f C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll MD5: b8e421c0890356cd4a793d8a346d9096 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe MD5: 6e3245df783e58375b3465f03274743e C:\Program Files\Common Files\Java\Java Update\jusched.exe MD5: 7cfc00b4501a14cf369f869ab8e79e68 C:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll MD5: 36b7dddfb2bb90c88ebbb7cb1db306bf C:\Program Files\DAEMON Tools Lite\DTCommonRes.dll MD5: a07e8935cc8dce6db787dc99129ca17c C:\Program Files\DAEMON Tools Lite\DTLite.exe MD5: 5d7e779b3323659d70228446598b3505 C:\Program Files\DAEMON Tools Lite\Engine.dll MD5: 047d41187e1278e5bb8de12b56967917 C:\Program Files\DAEMON Tools Lite\ImgEngine.dll MD5: f841f32ad816dbf130f10d86fab99b1a C:\Program Files\DAEMON Tools Lite\mfc100u.dll MD5: 03e9314004f504a14a61c3d364b62f66 C:\Program Files\DAEMON Tools Lite\MSVCP100.dll MD5: 67ec459e42d3081dd8fd34356f7cafc1 C:\Program Files\DAEMON Tools Lite\MSVCR100.dll MD5: 6827ca29d7ad3595660271f3f05c79b5 C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll MD5: 64c1481b867cc7b45e10a74cc9eb46e4 C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_32_248D3CEB7C787E4E.dll MD5: 3a913a99c665a6c3610241c09439f281 C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_F5A70B61FC3A2BB0.dll MD5: 61980095ae5d02b1e9d2ed604a90c1bf C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll MD5: ab3668c159e1cfea184f72650bd66807 C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll MD5: b92f91fb6cfc4bdfe3af7ffff5356d1f C:\Program Files\Google\Update\1.3.21.93\npGoogleUpdate3.dll MD5: 22f34306124c4d40142b60d6a28c40da C:\Program Files\Google\Update\1.3.21.93\psmachine.dll MD5: 9be4d06394e0861a61399a4becafb9dd C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll MD5: 3814a567bac346d8d210edffeb8cf2ec C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc MD5: e1f37a47dcb2434b519448115a12b084 C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll MD5: 0a3c6aa4a9fc38c20ba4eac2c3351c05 c:\program files\hp\digital imaging\bin\hpqcxs08.dll MD5: 159fac880722b49645e056a558b03e26 C:\Program Files\HP\Digital Imaging\bin\hpqddcmn.dll MD5: 7da3211ac63edd90b8eca1ca1abfd43b c:\program files\hp\digital imaging\bin\hpqddsvc.dll MD5: d03398b8d124ddff53a6ec542175bab5 C:\Program Files\HP\Digital Imaging\bin\hpqddusr.dll MD5: ba3663e73391164d4ced47fb4405a758 C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll MD5: 3c69ce161c7007e9ad53a325492d446a C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll MD5: bc0281d8fee466527b3b9123b5243a1d C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll MD5: 22a6446883efb70f82ad96e510ad5a1c C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe MD5: b380b5a981d2bfd688fbd97e6f6b39cc C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc MD5: f58f770cab0d8ab4141f95528b7a7a5a C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll MD5: 94152fa61600cd39ece51f620b82342f C:\Program Files\HP\Digital Imaging\bin\hpqusg.dll MD5: 14229263aa19c704e0d6d2e7404a8455 c:\program files\hp\digital imaging\bin\hpslpsvc32.dll MD5: d389c7bd09a403857465509d20aa6e3c C:\Program Files\HP\Digital Imaging\Smart Web Printing\ClipBookDBComponent.dll MD5: c285b5064f4fccc95e0354345681d906 C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll MD5: a24bb1432cd4f6e202dbb5428ea97a0d C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe MD5: 9b4c1dd94be0d6bd64025f39a8f1cd65 C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll MD5: b33ffec7dc55d0445897433c82ceef29 C:\Program Files\HP\Digital Imaging\Smart Web Printing\NeoLoggingLib.dll MD5: b8e4d2756905157f0d034e1355c42d10 C:\Program Files\HP\Digital Imaging\Smart Web Printing\RsrcLoaderLib.dll MD5: 6614a034bb3286ffbcf964267c14e93c C:\Program Files\HP\Digital Imaging\Smart Web Printing\SatelliteENU.dll MD5: 6589c90ffc8eb543586a3099d09261f4 C:\Program Files\HP\Digital Imaging\Smart Web Printing\UtilityLib.dll MD5: 21293443961a4e2597453ee7a9347f22 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe MD5: 69a3f07fad1fed82fb70b561593bbf54 C:\Program Files\Internet Explorer\ieproxy.dll MD5: 53fe2d34b143efdb80685281e751b91c C:\Program Files\Internet Explorer\plugins\nppdf32.dll MD5: 89b42ab664ddd9d69f1a7cb94f0d5985 C:\Program Files\Internet Explorer\xpshims.dll MD5: dc365b6e595683f67bc21a203432e336 C:\Program Files\Java\jre6\bin\jp2ssv.dll MD5: 381b25dc8e958d905b33130d500bbf29 C:\Program Files\Java\jre6\bin\jqs.exe MD5: 1e96525ae85d402f9f8047f8caef5f06 C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll MD5: e3a7850421a4ab8b15fc174eb587bc6b C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll MD5: 3e930c641079443d4de036167a69caa2 C:\Program Files\Messenger\msmsgs.exe MD5: 28a2c0798a72c944d2b2459f28221377 C:\Program Files\Microsoft IntelliType Pro\Components\Commands\dpghnt\dpghnt.dll MD5: 3b027f7898de90e6231eb8fd0922e805 C:\Program Files\Microsoft IntelliType Pro\dpgcmd.dll MD5: 927811921bf32c9a2dfce1134243288e C:\Program Files\Microsoft IntelliType Pro\dpgmkb.dll MD5: 47bf93aa6a6cf1ff6762fb99a2f57eff C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe MD5: 25c3ec3380b80a697660871529c8d28a C:\Program Files\Microsoft IntelliType Pro\itype.exe MD5: d1a573a0c14f57da106e798a525fe0fe C:\Program Files\Microsoft IntelliType Pro\srres.dll MD5: 47aff25b68ce4885fec6cfdef8febb5c C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll MD5: ad2e6fb5da47fb720f39186282dbe4fd C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll MD5: 53fe2d34b143efdb80685281e751b91c C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll MD5: 29b060079a9129553e3fa75edb8243bb C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll MD5: 4c23e74ef7f99d8b07c9aa7dc087e200 C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll MD5: 58d5bfdf3adf49fe9cabd78cc61d92f6 C:\Program Files\PC Connectivity Solution\ServiceLayer.exe MD5: 29b060079a9129553e3fa75edb8243bb C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll MD5: 4c23e74ef7f99d8b07c9aa7dc087e200 C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll MD5: 5a9e77c71d6d7030bc170dd7cf04cf5d c:\program files\yahoo!\companion\installs\cpn\yt.dll MD5: 5d7b1592036c80535872d6a20931ca7a C:\PROGRA~1\COMMON~1\MICROS~1\IME12L~1\imesc\IMSCMig.exe MD5: 310c15fd8358b2c4cd7a5b98a112883f C:\WINDOWS\AppPatch\AcGenral.DLL MD5: bcd0a5c3c1715c363cb3f321abe31514 C:\WINDOWS\Downloaded Program Files\IEAWSDC.DLL MD5: c34d0189e37cde86947b889fbeb81c7a C:\WINDOWS\Downloaded Program Files\ImageUploader5.ocx MD5: 26faa936a2e366bc0873c7b32fd37fb5 C:\WINDOWS\Downloaded Program Files\npsoe.dll MD5: bb7fcdcd4de287340b5c1bb1949ad3c6 C:\WINDOWS\Downloaded Program Files\qsax.dll MD5: 5c230948dd6652228f88ca7ae6cb276c C:\WINDOWS\gdrv.sys MD5: f6d01b49cefe36286a1fd8bae8f2d6a3 C:\WINDOWS\KHALMNPR.EXE MD5: ab87eeffd18f2baafc274e7075ea6c67 C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll MD5: a6543bd31e3b48f70da57fb01f13d934 C:\WINDOWS\RTHDCPL.EXE MD5: f475daa3cf6d19da49be7bac0a966db3 C:\WINDOWS\system32\Adobe\Director\np32dsw.dll MD5: 21918247c1fc32f3a1cb1d0e90e3e4f5 C:\WINDOWS\system32\AegisE5.dll MD5: 1ede3c09fba9e11cc215fa8f4fb5999d C:\WINDOWS\system32\ckldrv.sys MD5: 93afb83fbc1f9443cac722fca63d73bf C:\WINDOWS\system32\COMCTL32.dll MD5: ed0c0df222209e43ad9afbf3fe87dde0 C:\WINDOWS\system32\comsvcs.dll MD5: 8fcf03e4d7be9b5587ccf11719959006 C:\WINDOWS\system32\corpol.dll MD5: 133f82b6391f3390becfa429c23fb2be C:\WINDOWS\System32\Crypserv.exe MD5: 51dc06501a0b661f29d11dea6aaa5c54 C:\WINDOWS\system32\CRYPT32.dll MD5: c14350fc0d47d806699c4f907fc6785b C:\WINDOWS\system32\cryptnet.dll MD5: 515a7fae2070c2b0242b2353443e2f11 C:\WINDOWS\System32\CSCDLL.dll MD5: dd40363abad230a84c5e2178b11efa88 C:\WINDOWS\system32\CSRSRV.dll MD5: 0607cbc6fa20114cb491efe4b2f9efad C:\WINDOWS\system32\d3d9.dll MD5: 56adb11f7d4d0816c0be1e701c1b5e52 C:\WINDOWS\system32\D3DIM700.DLL MD5: e2092f0a1d7abc243f9c2362483d150d C:\WINDOWS\System32\dimsntfy.dll MD5: 389496118b3b03c2328024af320132ac C:\WINDOWS\system32\DNSAPI.dll MD5: 5f7e24fa9eab896051ffb87f840730d2 c:\windows\system32\dnsrslvr.dll MD5: 15e655baa989444f56787ef558823643 C:\WINDOWS\system32\DRIVERS\AegisP.sys MD5: 1e44bc1e83d8fd2305f8d452db109cf9 C:\WINDOWS\System32\drivers\afd.sys MD5: 8e6f9123631db9b4a7b1cd99f7ee694f C:\WINDOWS\system32\DRIVERS\AmeAtmPc.sys MD5: ae76348a2605fb197fa8ff1d6f547836 C:\WINDOWS\system32\DRIVERS\atmlane.sys MD5: e7ef69b38d17ba01f914ae8f66216a38 C:\WINDOWS\system32\DRIVERS\atmuni.sys MD5: 1fb582b783650ad538560e0c279c3078 C:\WINDOWS\System32\Drivers\AWISp50.sys MD5: 4a8a2aa0706b659175169decf198e9d7 C:\WINDOWS\system32\drivers\ccdcmb.sys MD5: fd3e61831095ac62e6840d986b5a2016 C:\WINDOWS\system32\drivers\ccdcmbo.sys MD5: 555e54ac2f601a8821cef58961653991 C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys MD5: fd9fc82f134b1c91004ffc76a5ae494b C:\WINDOWS\system32\DRIVERS\ENTECH.sys MD5: 9671f1c61fc014f6232eb6ea246be3c3 C:\WINDOWS\System32\DRIVERS\epflt15.SYS MD5: ce6ec335286da93338e43acff2c5c120 C:\WINDOWS\System32\DRIVERS\esflt15.SYS MD5: d03d10f7ded688fecf50f8fbf1ea9b8a C:\WINDOWS\system32\DRIVERS\HPZid412.sys MD5: 89f41658929393487b6b7d13c8528ce3 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys MD5: 3fa98339e8d9e007726be62f231e2015 C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys MD5: f259f758e04d8fb8d48c6cdbe45223e8 C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys MD5: ca26e46ec8891058c9e10363df4e4650 C:\WINDOWS\System32\Drivers\LUsbFilt.Sys MD5: 7d304a5eb4344ebeeab53a2fe3ffb9f0 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys MD5: fbbb1a51eb6e43b40144a05932766d6c C:\WINDOWS\System32\DRIVERS\MS1000.sys MD5: 0109c4f3850dfbab279542515386ae22 C:\WINDOWS\system32\DRIVERS\ndistapi.sys MD5: 02e96113511171ba7559386d10d3daea C:\WINDOWS\system32\drivers\nmwcdnsu.sys MD5: fb09150cfc7a499a53c308d04841a3bd C:\WINDOWS\system32\drivers\nmwcdnsuc.sys MD5: 18c9b152da7bea76b2f9e4b6412e0aaf C:\WINDOWS\system32\DRIVERS\nv4_mini.sys MD5: fd2041e9ba03db7764b2248f02475079 C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys MD5: 01524cd237223b18adbb48f70083f101 C:\WINDOWS\system32\DRIVERS\rawwan.sys MD5: c2a6f7f35e617744a65dbfb0c0a64adc C:\WINDOWS\system32\DRIVERS\rt2870.sys MD5: 89619ef503f949fae09252a8b883ee11 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys MD5: 08baf30f6de95814f58af9ce7bbc5614 C:\WINDOWS\system32\drivers\RtkHDAud.sys MD5: 71e276f6d189413266ea22171806597b C:\WINDOWS\System32\Drivers\sptd.sys MD5: 47ddfc2f003f7f9f0592c6874962a2e7 C:\WINDOWS\system32\DRIVERS\srv.sys MD5: 587e643a4e2ffd9a00f114b057ceb773 C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys MD5: fca6a196d47cb972a0e4adc0db9cd17c C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys MD5: 6ff66513d372d479ef1810223c8d20ce C:\WINDOWS\system32\DRIVERS\WudfPf.sys MD5: 2b1d4e15d5143757c494ba05832fb4a6 C:\WINDOWS\system32\EBPMON24.DLL MD5: f5b754cdea20bbb3a31e16a776ede6d6 C:\WINDOWS\system32\ESENT.dll MD5: 0a0c8331e26f1ec7741cce6a91e9167d C:\WINDOWS\system32\hpf3l082.dll MD5: 986f5143b56b8e4889cac91ea81583dd C:\WINDOWS\system32\hpwwiax5.dll MD5: 2969d26eee289be7422aa46fc55f4e38 c:\windows\system32\hpzinw12.dll MD5: bafc9706bdf425a02b66468ab2605c59 c:\windows\system32\hpzipm12.dll MD5: 0b8fb29cda02015448c9f5260a013f19 C:\WINDOWS\system32\IEFRAME.dll MD5: 515aaa9c87d5c475b06dfeba3706d74f C:\WINDOWS\system32\iepeers.dll MD5: 1ab894fa897e26b23ca53beed72f61f4 C:\WINDOWS\system32\iertutil.dll MD5: 024dc0f68df5fd6ae9dd82dfbaf479d6 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE MD5: 0689622e6484934eb6e5f4d3a96311f9 C:\WINDOWS\system32\jscript.dll MD5: 9722c23fded742913fd13ed1504d6d86 C:\WINDOWS\system32\jsproxy.dll MD5: a525c96c51d55111fdf3bea9ffffc7ae C:\WINDOWS\system32\kerberos.dll MD5: bd31dc6dbe9333c4fbd4bdf0899f2160 C:\WINDOWS\system32\LSASRV.dll MD5: e9f427ef46965d33e878a507a2f5ccb6 C:\WINDOWS\system32\Macromed\Flash\Flash11e.ocx MD5: de3745a51b7ac7fedc356a83f76c8023 C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll MD5: 3f790874a85819e94574f3e7af9c5806 C:\WINDOWS\system32\msctfime.ime MD5: 561b3e96164c918e0564cab3d21ce871 C:\WINDOWS\system32\msfeeds.dll MD5: dd8d655e1881b70a5259a23a6018a6c2 C:\WINDOWS\system32\mshtml.dll MD5: 8c22083ed515dc94d575438662f0be6a C:\WINDOWS\system32\msi.dll MD5: 943337d786a56729263071623bbb9de5 C:\WINDOWS\System32\mswsock.dll MD5: 062f837c1fbdb6a0a75f82efc2ee8e74 C:\WINDOWS\system32\netshell.dll MD5: f8f0d25ca553e39dde485d8fc7fcce89 C:\WINDOWS\system32\ntdll.dll MD5: 3da3f03e76a6d9630c148efe0fc74230 C:\WINDOWS\system32\nvapi.dll MD5: 229ef72a47f7ef9233f3a52fa519e01b C:\WINDOWS\system32\NvCpl.dll MD5: 0e2752b270f5a68d459f7927a81b5afa C:\WINDOWS\system32\NvMcTray.dll MD5: a8c1e6ff53fb0628a302843ea5fa5ab6 C:\WINDOWS\System32\nvsvc32.exe MD5: 40b0f98bad16ad5def894e88c3ef8014 C:\WINDOWS\system32\ODBC32.dll MD5: 6bad1bed9872e62049e487fb91ae2f3a C:\WINDOWS\system32\ole32.dll MD5: 20200ee3cfe10e9f0c028d8653be11c6 C:\WINDOWS\system32\OLEACC.dll MD5: 1b2be5777f69a71778f52ffee1c798d6 C:\WINDOWS\system32\OLEAUT32.dll MD5: d4502f124289a31976130cccb014c9aa C:\WINDOWS\system32\RPCRT4.dll MD5: 72451fd61ddbb0a1fb071b7c3cde5594 C:\WINDOWS\system32\rsvpsp.dll MD5: a645a78fcdabad67067324d7e6cd9f79 C:\WINDOWS\system32\schannel.dll MD5: 26cb10fa893f940ab09713ff46dcdade C:\WINDOWS\system32\SHDOCVW.dll MD5: e86423aa9aa8c382af02b94a058dc2aa C:\WINDOWS\system32\SHELL32.dll MD5: 99bc0b50f511924348be19c7c7313bbf C:\WINDOWS\system32\SHSVCS.dll MD5: 73347eca7a6d327ba43c40cb56bca659 C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpfpp082.dll MD5: 60784f891563fb1b767f70117fc2428f C:\WINDOWS\System32\spoolsv.exe MD5: 3a7c3cbe5d96b8ae96ce81f0b22fb527 c:\windows\system32\srvsvc.dll MD5: 3caeae7608f1bd7ba873a3b02895b106 C:\WINDOWS\system32\sti.dll MD5: 496ce99bbbb7680323921df30b405c36 C:\WINDOWS\system32\urlmon.dll MD5: a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\system32\userinit.exe MD5: 9e03dc5ab51cfd0190541ce2038d819d C:\WINDOWS\system32\USP10.dll MD5: 2c1d59933077ba0d8a64cb1fb9ef8638 C:\WINDOWS\system32\wdfmgr.exe MD5: 684559a03cbc1d05ba120a18b0d8ba5d c:\windows\system32\WINHTTP.dll MD5: 552263502ea8c24d301a0c43ff90b3ed C:\WINDOWS\system32\WININET.dll MD5: 4a953f13942867ba8fb41f141ec1b80c C:\WINDOWS\system32\WINMM.dll MD5: d72b9ec3337b247a666f098f3d6b43de C:\WINDOWS\System32\winrnr.dll MD5: 8c7dca4b158bf16894120786a7a5f366 C:\WINDOWS\system32\winsrv.dll MD5: 3df48b4e91f361ed22abeb3dde366e30 C:\WINDOWS\system32\WINTRUST.dll MD5: 2cc34e8bb667eef78899546e12649196 C:\WINDOWS\system32\WlNotify.dll MD5: eed1b6c2b6dd5c2fc1f6709102dc3191 c:\windows\system32\WUDFPlatform.dll MD5: 16403217ab6fc5c30c14c6b12098ad4b C:\WINDOWS\system32\xpsp2res.dll MD5: d5e459bed3db9cf7fc6cc1455f177d2d C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.DLL MD5: 0b3595a4ff0b36d68e5fc67fd7d70fdc C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCP80.dll MD5: c9564cf4976e7e96b4052737aa2492b4 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll MD5: 4c39358ebdd2ffcd9132a30e1ec31e16 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\MSVCP90.dll MD5: cdbe9690cf2b8409facad94fac9479c9 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\MSVCR90.dll MD5: ca6ade4f7761bb15b3325356dc3b82bb C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll MD5: fbfca1a574d47ee575448b719cbbf2e4 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\MFC90ENU.DLL MD5: 736b12b725aeb2b07f0241a9f680cb10 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll MD5: 33d9b7bb7ba323bafe489df033dac824 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\gdiplus.dll The following file(s) must be uploaded for server-side scanning: C:\WINDOWS\system32\ckldrv.sys Upload started - 1 file(s) ckldrv.sys (21638) Upload speed - 5 KB/s Upload finished - 1 uploaded, 0 failed The uploaded file(s) were found clean. Scan finished - communication took 6 sec Total traffic - 0.03 MB sent, 0.84 KB recvd Scanned 630 files and modules - 40 seconds ============================================================================== Just to let you know my Avast antivirus is still in a disabled state (I haven't dared to try and re-enable anything).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI