This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't open some programmes, can't access some websites [Solved

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Background info: I normally use Chrome for browsing, although sometimes I use Firefox; and my default broswer is actually set to IE 6. I'm running WIndows XP.

I was browsing in Firefox when a popup somehow managed to slip past the popup blocker. I didn't see what exactly was on it, because at that point Firefox decided to start using 100% of my CPU. This went on for a while until I killed it in Task manager. Then I started getting Windows Update icons popping up in the system tray - which is odd, because I have automatic updates disabled. Killing wuauclt.exe made them disappear for a while, but then the process kept restarting itself and popping up again. I tried turning updates off via Services in the Control Panel, and they turned themselves back on again. So I tried deleting wuauclt.exe itself; it wouldn't let me delete it whilst it was running, but stopping it via Services left me enough time to delete before it started itself again. I think it was about this time that IE6 tried to open itself, too, and I kept receiving the Dial Up Connection box (which is silly, as I'm on broadband).

Then I tried opening Google Chrome. Nothing doing - double click the icon, nothing happens. I decided to try reinstalling it. Reinstalled it, (set it to my default browser partway through) but still double clicking the icon does nothing.

So I restarted my computer.

My computer took ages to restart, sitting there huffing and puffing so long I thought it was completely broken. But eventually, it managed to restart properly. Google Chrome still does nothing, and I get an error message from DAEMON Tools Lite when it tries to autostart itself.

Reinstall Google again, and this time it's pointing at new_chrome.exe instead of chrome.exe, and it opens fine; except when I try to open it via the "Internet" button on the Start Menu, in which case it opens the "Open With" thing.

But now DAEMON, Atlas (translation software) and Sophos (my antivirus) won't start. Atlas and Sophos do the same as chrome.exe; they just do nothing, or appear on the process list in Task manager for a tiny amount of time before disappearing again. DAEMON Tools Lite gives me an error message:
"Initialization error 2. This programme requires at least Windows 2000 with SPTD 1.53 or higher. Kernel debugger must be deactivated."

Searching for information with Google, I notice that I now get an "Oops!" Google Chrome can't connect to this website message for a variety of sites, including microsoft, a few help forums, and Norton's site. can still view the Google cached versions.

I tried uninstalling and reinstalling DAEMON Tools Lite. It uninstalled fine, but when I came to reinstall I get a new error message - "Internal Setup Error. Error Code: 14. Contact support."

Upon restarting my computer, several programmes that automatically startup - DivX Updates, Adobe Updates, Veoh - instead caused the Dial Up Connection box to appear, which I cancelled out of. I ended up removing all the non essential stuff from starting up to stop them keep appearing.

I ran a Malwarebytes' scan, getting the following logfile:


Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3955

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

18/03/2012 01:22:05
mbam-log-2012-03-18 (01-22-05).txt

Scan type: Full scan (C:\|)
Objects scanned: 2019
Time elapsed: 1 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\isvrqwhh (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

Then I ran another one after restarting, getting this logfile:

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3955

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

18/03/2012 01:47:21
mbam-log-2012-03-18 (01-47-21).txt

Scan type: Quick scan
Objects scanned: 123609
Time elapsed: 18 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\isvrqwhh (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe (Trojan.FakeAlert.H) -> Delete on reboot.
C:\Documents and Settings\Owner\Local Settings\Temp\PRAGMA3d8f.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\0.098872653900412.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

The same items appear when doing subsequent scans, and the Dial Up Connection box appears when I click to remove them for some reason.

Here's my HijackThis log:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 03:09:07, on 18/03/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\new_chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\new_chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\new_chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\new_chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\new_chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\new_chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\new_chrome.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\new_chrome.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: ATLAS Toolbar - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V14\ATLIECP.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9?C??90988571CECB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9?C??90988571CECB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9,°90988571CECB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9,°90988571CECB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9クー90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ATLAS Toolbar - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V14\ATLIECP.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [IsvRqwhh] C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: ZDWlan.lnk = ?
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra button: ATLAS Translation - {B7707A72-4355-11D4-82BD-00000EBBEF8D} - C:\Program Files\ATLAS V14\Atlscript.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ActiveGS.cab - http://activegs.freetoolsassociation.com/ActiveGS.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227198024355
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} (Java Plug-in 1.6.0_15) - 
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll

–
End of file - 7152 bytes
Hello Showsni and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again Showsni

Run HijackThis

Open HijackThis and click Do a system scan only.

Place a check mark next to:

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe,
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9?C ?? 90988571CECB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9?C ?? 90988571CECB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9, ° 90988571CECB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9, ° 90988571CECB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9ク ー 90988571CECB} - (no file)
O4 - HKCU\..\Run: [IsvRqwhh] C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe


Close all windows except for HijackThis and click Fix checked.

===================================================

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again
  • download RogueKiller by tigzy and save it to your desktop
  • close all programs
  • double-click RogueKiller.exe
  • wait until Prescan has finished
  • click on Scan
  • when the scan is complete click report
Please post the log.

===================================================

Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

RKreport.txt
OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Thanks for your reply!

Here is the RogueKiller log:

RogueKiller V7.3.1 [03/10/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Owner [Admin rights]
Mode: Scan – Date: 03/18/2012 15:14:45

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 5 ¤¤¤
[SUSP PATH] HKCU\[…]\Run : IsvRqwhh (C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-1012008372-3885175467-2977226436-1003[…]\Run : IsvRqwhh (C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe) -> FOUND
[SUSP PATH] HKLM\[…]\Winlogon : Userinit (C:\WINDOWS\SYSTEM32\Userinit.exe,,C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe) -> FOUND
[PROXY IE] HKCU\[…]\Internet Settings : ProxyServer (hxxp=127.0.0.1:5555) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[41] : NtCreateKey @ 0x8057791D -> HOOKED (\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\phwyphpt.sys @ 0xF87896AC)
SSDT[119] : NtOpenKey @ 0x80572BF4 -> HOOKED (\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\phwyphpt.sys @ 0xF8789562)
IRP[IRP_MJ_CREATE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_CLOSE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_SYSTEM_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_DEVICE_CHANGE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)

¤¤¤ Infection :  ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1	   localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: Maxtor 6Y080L0 +++++
— User —
[MBR] 7899034f22bfd9456b8dcfc0d6cd3c5d
[BSP] e5a73de1d2879431563847cc0e47e969 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 63 | Size: 4584 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 9389520 | Size: 73577 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt

Here is OTL.txt:

OTL logfile created on: 18/03/2012 15:20:37 - Run 1
OTL by OldTimer - Version 3.2.39.1	 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
511.48 Mb Total Physical Memory | 317.08 Mb Available Physical Memory | 61.99% Memory free
1.30 Gb Paging File | 1.04 Gb Available in Paging File | 80.08% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.85 Gb Total Space | 4.24 Gb Free Space | 5.90% Space Free | Partition Type: NTFS
Drive D: | 4.47 Gb Total Space | 1.09 Gb Free Space | 24.49% Space Free | Partition Type: FAT32
Drive G: | 931.28 Gb Total Space | 563.68 Gb Free Space | 60.53% Space Free | Partition Type: FAT32
 
Computer Name: DANIEL | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.exe ()
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\Program Files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.exe ()
MOD - C:\Program Files\ZyDAS\ZD1211 802.11g Utility\dot1x_dll.dll ()
MOD - C:\Program Files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.dll ()
MOD - C:\Program Files\ZyDAS\ZD1211 802.11g Utility\ssleay32.dll ()
MOD - C:\Program Files\ZyDAS\ZD1211 802.11g Utility\libeay32.dll ()
MOD - C:\Program Files\VDMSound\LaunchPad.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (CiscoVpnInstallService) – C:\DOCUME~1\Owner\LOCALS~1\Temp\WZSE0.TMP\INSTAL~1.EXE File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (swi_service) – C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Plc)
SRV - (IMFservice) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (Giraffic) – C:\Program Files\Giraffic\Veoh_GirafficWatchdog.exe (Giraffic)
SRV - (SAVAdminService) – C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
SRV - (Sophos AutoUpdate Service) – C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
SRV - (nosGetPlusHelper) getPlus(R) – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (SAVService) – C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (SymWSC) – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (WDICA) –  File not found
DRV - (PRAGMAxnqweeixui) – C:\WINDOWS\PRAGMAxnqweeixui\PRAGMAd.sys File not found
DRV - (PRAGMAtspwixrnsk) – C:\WINDOWS\PRAGMAtspwixrnsk\PRAGMAd.sys File not found
DRV - (PRAGMAmxnlprpuyc) – C:\WINDOWS\PRAGMAmxnlprpuyc\PRAGMAd.sys File not found
DRV - (PDRFRAME) –  File not found
DRV - (PDRELI) –  File not found
DRV - (PDFRAME) –  File not found
DRV - (PDCOMP) –  File not found
DRV - (PCIDump) –  File not found
DRV - (PCAMPR5) – C:\WINDOWS\system32\PCAMPR5.SYS File not found
DRV - (Micorsoft Windows Service) – C:\DOCUME~1\Owner\LOCALS~1\Temp\phwyphpt.sys File not found
DRV - (lbrtfdc) –  File not found
DRV - (i2omgmt) –  File not found
DRV - (Changer) –  File not found
DRV - (puodsnjl) – C:\WINDOWS\system32\drivers\sensvcdo.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys ()
DRV - (FileMonitor) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys (IObit)
DRV - (UrlFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys (IObit.com)
DRV - (RegFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys (IObit.com)
DRV - (SAVOnAccessControl) – C:\WINDOWS\system32\drivers\savonaccesscontrol.sys (Sophos Plc)
DRV - (SAVOnAccessFilter) – C:\WINDOWS\system32\drivers\savonaccessfilter.sys (Sophos Plc)
DRV - (nv_agp) – C:\WINDOWS\system32\drivers\nv_agp.SYS (NVIDIA Corporation)
DRV - (onyfwev) – C:\WINDOWS\system32\drivers\ocltoijp.sys ()
DRV - (sosf) – C:\WINDOWS\system32\drivers\vexl.sys ()
DRV - (yxyhfv) – C:\WINDOWS\system32\drivers\ulmqni.sys ()
DRV - (Lbd) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (SASKUTIL) – C:\Documents and Settings\Owner\Local Settings\Temp\SAS_SelfExtract\saskutil.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Documents and Settings\Owner\Local Settings\Temp\SAS_SelfExtract\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (tap0901) – C:\WINDOWS\system32\drivers\tap0901.sys (The OpenVPN Project)
DRV - (FStarForce) – C:\WINDOWS\system32\drivers\FStarForce.sys (SNEG)
DRV - (CVPNDRVA) – C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (SophosBootDriver) – C:\WINDOWS\system32\drivers\SophosBootDriver.sys (Sophos Plc)
DRV - (UnlockerDriver5) – C:\Program Files\Unlocker\UnlockerDriver5.sys ()
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs, LLC)
DRV - (CVirtA) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (SUPERWEBCAM) – C:\WINDOWS\system32\drivers\superwebcam.sys (Windows (R) 2000 DDK provider)
DRV - (ZD1211U(ZyDAS)) ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (WLAN(WLAN)) XPC 802.11b/g Wireless Kit Driver(WLAN) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (DSDrv4) – C:\Program Files\K!TV\Plugins\S_Bt8x8\DSDrv4.sys ()
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (ZDBRGSYS) – C:\WINDOWS\system32\ZDBRGSYS.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ZDPNDIS5) – C:\WINDOWS\system32\ZDPNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (FsVga) – C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems)
DRV - (viaagp1) – C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.87
FF - prefs.js..extensions.enabledItems: exportcookies@aag:1.2
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.36.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.1.10
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:4.1.6
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veoh.com/VeohTVPlugin: C:\Program Files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@veoh.com/VeohWebPlayer: C:\Program Files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll (Veoh)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2012/03/16 18:57:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 23:46:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/16 19:09:45 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Veoh Networks\VeohWebPlayer\FFVideoFinder [2008/11/24 22:53:05 | 000,000,000 | —D | M]
 
[2009/11/10 03:20:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/03/15 11:51:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\extensions
[2009/11/16 04:03:55 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/03/15 02:06:33 | 000,000,000 | —D | M] (Fast Video Download (with SearchMenu)) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2010/08/05 04:00:50 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2)
[2010/08/07 13:28:21 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus(R))) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/06/28 02:46:14 | 000,000,000 | —D | M] (Ant Video Downloader) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\extensions\[removed]
[2011/11/03 16:15:30 | 000,000,000 | —D | M] (Export Cookies) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\extensions\exportcookies@aag
[2012/03/15 01:48:07 | 000,000,000 | —D | M] ("Freecorder YouTube Download Wizard") – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\extensions\[removed]
[2012/03/15 02:17:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/09/12 01:37:33 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2012/03/16 18:57:20 | 000,000,000 | —D | M] (Google Gears) – C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX
[2008/12/06 23:09:16 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/07/19 04:05:25 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/26 00:00:13 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/12/26 00:00:13 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/12/26 00:00:13 | 000,000,769 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/12/26 00:00:13 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: getPlusPlus for Adobe 16287 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Disabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Veoh Web Player Beta (Enabled) = C:\Program Files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.18_0\
CHR - Extension: APNG = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ehkepjiconegkhpodgoaeamnpckdbblp\0.7.0_0\
CHR - Extension: AdBlock = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.22_0\
CHR - Extension: Browser Button for AdBlock = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\picdndbpdnapajibahnnogkjofaeooof\0.0.11_0\
CHR - Extension: Gmail = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2012/03/18 01:10:47 | 000,000,736 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1	   localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Reg Error: Value error.) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O2 - BHO: (ATLAS Toolbar) - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V14\ATLIECP.DLL (FUJITSU LIMITED)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9¸°90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9C‹90988571CECB} - No CLSID value found.
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (ATLAS Toolbar) - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V14\ATLIECP.DLL (FUJITSU LIMITED)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\justtest.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [IsvRqwhh] C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZDWlan.lnk = C:\Program Files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  = 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: ATLAS Translation - {B7707A72-4355-11D4-82BD-00000EBBEF8D} - C:\Program Files\ATLAS V14\atlscript.html ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227198024355 (WUWebControl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: ActiveGS.cab http://activegs.freetoolsassociation.com/ActiveGS.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5D7689EC-9534-4364-99EE-9010E53A8305}: DhcpNameServer = 192.168.1.254
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\Userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe) - C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe File not found
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/01/01 22:03:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 22:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/10 19:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2008/04/01 13:53:24 | 000,000,071 | -H– | M] () - G:\autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2008/04/25 20:42:26 | 000,000,000 | —D | M] - G:\autorun – [ FAT32 ]
O33 - MountPoints2\{2c587188-b65f-11dd-a6c1-806d6172696f}\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 13:54:58 | 000,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{410b1a43-b661-11dd-a6c2-000c7603a08b}\Shell\AutoRun\command - "" = G:\wd_windows_tools\WDSetup.exe – [2008/03/31 10:39:56 | 001,774,550 | —- | M] (Western Digital Corporation																													)
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\wd_windows_tools\WDSetup.exe – [2008/03/31 10:39:56 | 001,774,550 | —- | M] (Western Digital Corporation																													)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
 
NetSvcs: 6to4 -  File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: Irmon -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/03/18 15:17:15 | 000,594,432 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/03/18 15:13:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\RK_Quarantine
[2012/03/18 15:09:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\backups
[2012/03/18 03:06:49 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2012/03/18 00:50:58 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2012/03/18 00:32:26 | 000,000,000 | —D | C] – C:\Program Files\Norton AntiVirus
[2012/03/17 22:00:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\shortcuts
[2012/03/17 16:36:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\project64 1.6
[2012/03/15 15:28:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\IObit Malware Fighter
[2012/03/15 15:28:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\IObit
[2012/03/15 15:28:15 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2012/03/15 15:20:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\Google Chrome
[2012/03/15 02:13:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln
[2012/03/15 02:01:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\New Folder
[2012/03/15 01:46:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Freecorder
[2012/03/15 01:46:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\FLVService
[2012/03/10 02:18:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\sol-fa-soft
[2012/03/10 01:40:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\.swt
[2012/02/26 17:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Smogon
[2012/02/18 02:44:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AutoUpdate
[2012/02/18 02:43:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Eltima Software
[2012/02/18 02:43:47 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/18 02:43:30 | 000,000,000 | —D | C] – C:\Program Files\Eltima Software
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/03/18 15:25:00 | 000,000,414 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2012/03/18 15:17:11 | 000,594,432 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/03/18 15:12:41 | 001,219,072 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RogueKiller.exe
[2012/03/18 15:05:02 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1012008372-3885175467-2977226436-1003UA.job
[2012/03/18 12:05:01 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1012008372-3885175467-2977226436-1003Core.job
[2012/03/18 03:22:02 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\sensvcdo.sys
[2012/03/18 03:06:44 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2012/03/18 02:09:07 | 000,168,960 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/18 01:52:51 | 000,000,199 | -HS- | M] () – C:\boot.ini
[2012/03/18 01:52:30 | 000,088,566 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2012/03/18 01:52:25 | 000,002,447 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2012/03/18 01:52:23 | 000,000,249 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2012/03/18 01:51:54 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/18 01:51:50 | 536,399,872 | -HS- | M] () – C:\hiberfil.sys
[2012/03/18 01:10:47 | 000,000,736 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/18 00:43:04 | 000,111,808 | -H– | M] () – C:\WINDOWS\System32\ohNIy23
[2012/03/17 22:49:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/03/17 22:00:00 | 000,001,297 | —- | M] () – C:\Documents and Settings\Owner\Desktop\WinXP_EXE_Fix.reg
[2012/03/15 15:45:12 | 000,002,303 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/02/18 02:43:47 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/03/18 15:11:04 | 001,219,072 | —- | C] () – C:\Documents and Settings\Owner\Desktop\RogueKiller.exe
[2012/03/18 03:22:01 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\sensvcdo.sys
[2012/03/17 23:55:08 | 000,111,808 | -H– | C] () – C:\WINDOWS\System32\ohNIy23
[2012/03/17 22:00:10 | 000,001,297 | —- | C] () – C:\Documents and Settings\Owner\Desktop\WinXP_EXE_Fix.reg
[2012/03/15 15:45:12 | 000,002,303 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/12 06:21:41 | 000,000,090 | —- | C] () – C:\WINDOWS\impsave.ini
[2011/08/03 02:33:15 | 000,001,070 | —- | C] () – C:\WINDOWS\_ISENV31.INI
[2011/08/03 02:33:15 | 000,000,521 | —- | C] () – C:\WINDOWS\_iserr31.ini
[2011/08/03 02:33:15 | 000,000,127 | —- | C] () – C:\WINDOWS\_delis43.ini
[2011/07/21 20:32:16 | 000,000,085 | —- | C] () – C:\WINDOWS\lagarith.ini
[2011/07/02 16:08:48 | 000,000,054 | —- | C] () – C:\WINDOWS\Composer.INI
[2011/04/29 01:52:18 | 000,000,018 | —- | C] () – C:\WINDOWS\gfact.ini
[2010/12/19 01:05:14 | 000,065,536 | —- | C] () – C:\WINDOWS\TADSUINS.EXE
[2010/09/25 21:53:39 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2010/09/21 23:25:16 | 000,056,320 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2010/07/18 00:42:51 | 000,002,100 | —- | C] () – C:\WINDOWS\ladydata.dat
[2010/06/18 02:38:51 | 000,695,642 | —- | C] () – C:\WINDOWS\unins000.exe
[2010/06/18 02:38:51 | 000,121,344 | —- | C] ( ) – C:\WINDOWS\System32\lagarith.dll
[2010/06/18 02:38:51 | 000,001,784 | —- | C] () – C:\WINDOWS\unins000.dat
[2010/06/18 02:36:32 | 000,695,578 | —- | C] () – C:\WINDOWS\System32\unins000.exe
[2010/06/18 02:36:32 | 000,001,070 | —- | C] () – C:\WINDOWS\System32\unins000.dat
[2010/06/15 19:49:55 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\ocltoijp.sys
[2010/06/15 19:34:16 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\vexl.sys
[2010/06/15 19:16:39 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\ulmqni.sys
[2010/06/15 18:09:24 | 000,011,485 | —- | C] () – C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll
[2010/06/13 02:56:38 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/06/02 00:50:23 | 000,000,004 | —- | C] () – C:\Documents and Settings\Owner\Application Data\ovczpx.dat
[2010/05/31 00:22:22 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/04/19 05:28:12 | 000,000,157 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/04/13 04:56:19 | 000,010,854 | —- | C] () – C:\WINDOWS\gloria.dat
[2010/04/13 03:57:23 | 000,003,052 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\72eRTTYEh4Og
[2010/04/13 03:57:23 | 000,003,052 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\72eRTTYEh4Og
[2010/04/12 00:05:38 | 000,004,160 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\1nsO3pTQCOnL
[2010/04/12 00:05:38 | 000,004,160 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1nsO3pTQCOnL
[2010/04/10 03:18:42 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
 
========== LOP Check ==========
 
[2012/02/18 02:44:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AutoUpdate
[2008/12/06 23:13:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2011/11/20 03:54:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Giraffic
[2010/09/25 20:26:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/04/11 22:31:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sophos
[2011/04/11 22:33:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sophos Web Intelligence
[2010/01/02 06:05:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/12 21:42:02 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2009/06/16 13:11:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AoishiroTrial
[2012/03/15 15:04:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2010/01/10 02:26:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BoneTown
[2010/08/14 02:44:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CCS64
[2011/10/28 00:49:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Clickteam
[2008/12/06 23:31:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DAEMON Tools
[2011/12/01 05:50:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Downloaded Installations
[2009/01/10 10:11:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Fujitsu
[2010/12/07 02:43:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Idmu
[2010/10/11 01:50:32 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Owner\Application Data\IFViewer
[2009/06/19 01:27:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ijjigame
[2010/08/21 05:35:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Independent
[2003/01/01 23:08:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterTrust
[2011/07/01 22:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2012/03/15 15:28:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IObit
[2009/02/03 18:44:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Magic Set Editor
[2012/03/02 05:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Rags
[2011/06/23 21:15:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\RenPy
[2003/01/01 23:31:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2011/01/04 00:14:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Smart Reading
[2012/03/10 02:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\sol-fa-soft
[2009/07/10 02:05:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sylph
[2010/09/23 02:04:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TECH GIAN
[2011/01/20 07:48:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2010/10/12 13:05:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Turbine
[2010/11/24 02:06:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ufis
[2003/01/01 22:59:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2012/03/17 22:49:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%\*.* >
[2012/03/18 01:51:45 | 000,015,531 | —- | M] () – C:\aaw7boot.log
[2008/04/05 02:55:58 | 000,028,160 | —- | M] () – C:\agth.dll
[2008/04/05 02:56:10 | 000,124,416 | —- | M] () – C:\agth.exe
[2010/07/31 14:58:52 | 000,000,344 | —- | M] () – C:\AlphaDiscLog.txt
[2010/02/02 02:46:08 | 000,000,000 | —- | M] () – C:\asoutput.log
[2008/07/19 04:42:46 | 000,113,597 | —- | M] () – C:\atlas-and-agth-tutorial-36561.html
[2008/08/03 19:03:39 | 000,000,400 | —- | M] () – C:\Atlas___AGTH_readme.txt
[2003/01/01 22:03:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/13 20:45:34 | 001,539,011 | —- | M] () – C:\Battle.mp3
[2011/11/14 19:35:50 | 002,450,370 | —- | M] () – C:\Battle1.mp3
[2012/03/18 01:52:51 | 000,000,199 | -HS- | M] () – C:\boot.ini
[2003/01/01 22:03:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/09/22 06:03:21 | 000,000,039 | —- | M] () – C:\debug.txt
[2012/02/16 23:34:39 | 003,145,784 | —- | M] () – C:\fb_0.bmp
[2012/02/16 23:34:39 | 003,145,856 | —- | M] () – C:\fb_0.dds
[2003/02/13 03:55:56 | 000,000,301 | —- | M] () – C:\FINIS_IT.TXT
[2011/04/01 02:15:15 | 000,000,006 | —- | M] () – C:\FS1
[2011/04/02 10:12:17 | 000,000,003 | —- | M] () – C:\FS2
[2012/02/16 22:46:17 | 000,005,205 | —- | M] () – C:\fs_3_6.zip
[2011/03/30 00:28:35 | 000,001,148 | —- | M] () – C:\game.ini
[2012/03/18 01:51:50 | 536,399,872 | -HS- | M] () – C:\hiberfil.sys
[2003/01/01 22:03:08 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/27 05:40:44 | 005,172,084 | R— | M] () – C:\kaiu.ttf
[2011/03/30 01:04:26 | 001,049,088 | —- | M] () – C:\Lady Sword (J) [a1].pce
[2003/01/01 22:03:08 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/11/21 07:44:06 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/09/27 20:50:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2003/01/02 02:37:55 | 000,000,000 | —- | M] () – C:\nvlog.txt
[2012/03/18 15:13:57 | 887,095,296 | -HS- | M] () – C:\pagefile.sys
[2010/08/28 18:58:53 | 000,002,728 | —- | M] () – C:\rapport.txt
[2010/09/07 12:25:05 | 000,000,777 | —- | M] () – C:\rkill.log
[2009/04/02 22:46:02 | 000,000,770 | —- | M] () – C:\Shortcut to My Documents.lnk
[2012/03/15 11:17:08 | 000,042,750 | —- | M] () – C:\TDSSKiller.2.3.2.0_15.03.2012_11.15.37_log.txt
[2010/06/15 22:05:26 | 000,039,966 | —- | M] () – C:\TDSSKiller.2.3.2.0_15.06.2010_23.01.05_log.txt
 
< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
 
< %systemroot%\Fonts\*.dll >
 
< %systemroot%\Fonts\*.ini >
[2003/01/01 22:02:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
 
< %systemroot%\Fonts\*.ini2 >
 
< %systemroot%\Fonts\*.exe >
 
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 10:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
 
< %systemroot%\REPAIR\*.bak1 >
 
< %systemroot%\REPAIR\*.ini >
 
< %systemroot%\system32\*.jpg  >
 
< %systemroot%\*.jpg  >
 
< %systemroot%\*.png  >
 
< %systemroot%\*.scr >
 
< %systemroot%\*._sy >
 
< %APPDATA%\Adobe\Update\*.* >
 
< %ALLUSERSPROFILE%\Favorites\*.* >
 
< %APPDATA%\Microsoft\*.* >
 
< %PROGRAMFILES%\*.* >
 
< %APPDATA%\Update\*.* >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\System32\config\*.sav  >
[2003/01/01 21:54:07 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2003/01/01 21:54:07 | 000,602,112 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2003/01/01 21:54:07 | 000,385,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav
 
< %PROGRAMFILES%\bak. /s >
 
< %systemroot%\system32\bak. /s >
 
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x  >
[2009/09/27 20:59:37 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2003/02/13 03:45:20 | 000,001,992 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\New Office Document.lnk
[2003/02/13 03:45:20 | 000,002,002 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Open Office Document.lnk
[2009/09/27 20:59:37 | 000,001,574 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2012/03/15 15:28:31 | 000,000,895 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Uninstall Programs.lnk
[2003/01/01 22:03:14 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2010/08/25 05:41:51 | 000,001,518 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
 
< %systemroot%\system32\config\systemprofile\*.dat /x >
 
< %systemroot%\*.config >
 
< %systemroot%\system32\*.db >
 
< %PROGRAMFILES%\Internet Explorer\*.dat >
 
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
 
< %USERPROFILE%\Deskuop\*.exe >
 
< %PROGRAMFILES%\Common Files\*.* >
 
< %systemroot%\*.src >
 
< %systemroot%\install\*.* >
 
< %systemroot%\system32\DLL\*.* >
 
< %systemroot%\system32\HelpFiles\*.* >
 
< %systemroot%\system32\rundll\*.* >
 
< %systemroot%\winn32\*.* >
 
< %systemroot%\Java\*.* >
 
< %systemroot%\system32\test\*.* >
 
< %systemroot%\system32\Rundll32\*.*  >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-10-03 05:45:07
 
< %USERPROFILE%\..|smtmp;true;true;true /FP >
 
< %temp%\smtmp\*.* /s > >
 
< MD5 for: EXPLORER.EX_  >
[2002/09/21 05:30:00 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\i386\EXPLORER.EX_
[2002/09/21 19:30:00 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\WINDOWS\I386\EXPLORER.EX_
 
< MD5 for: EXPLORER.EXE  >
[2008/04/14 00:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 00:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 07:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
 
< MD5 for: EXPLORER.SC_  >
[2002/09/21 05:30:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_
[2002/09/21 19:30:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\WINDOWS\I386\EXPLORER.SC_
 
< MD5 for: EXPLORER.SCF  >
[2002/09/21 05:30:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
 
< MD5 for: IEXPLORE.CH_  >
[2002/09/21 01:34:00 | 000,161,725 | —- | M] () MD5=D94018D849BDF25E7ADB8CD46DA3DC7F – C:\i386\IEXPLORE.CH_
[2002/09/21 15:34:00 | 000,161,725 | —- | M] () MD5=D94018D849BDF25E7ADB8CD46DA3DC7F – C:\WINDOWS\I386\IEXPLORE.CH_
 
< MD5 for: IEXPLORE.CHM  >
[2004/07/17 18:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 18:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
 
< MD5 for: IEXPLORE.EX_  >
[2002/09/21 01:34:00 | 000,036,925 | —- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 – C:\i386\IEXPLORE.EX_
[2002/09/21 15:34:00 | 000,036,925 | —- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 – C:\WINDOWS\I386\IEXPLORE.EX_
 
< MD5 for: IEXPLORE.EXE  >
[2008/04/14 00:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\Program Files\Internet Explorer\iexplore.exe
[2008/04/14 00:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2008/04/14 00:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/04 07:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
 
< MD5 for: IEXPLORE.EXE.HDMP  >
[2010/08/04 22:46:49 | 085,054,007 | —- | M] () MD5=09A1ED08BFA88C522C7356962BAB248F – C:\Documents and Settings\Owner\Local Settings\Temp\WER8168.dir00\iexplore.exe.hdmp
 
< MD5 for: IEXPLORE.EXE.MDMP  >
[2010/08/04 22:45:43 | 000,101,200 | —- | M] () MD5=E979A73D665C619485A7B07A8CBF00AC – C:\Documents and Settings\Owner\Local Settings\Temp\WER8168.dir00\iexplore.exe.mdmp
 
< MD5 for: IEXPLORE.EXE-2D97EBE6.PF  >
[2012/03/15 15:28:58 | 000,105,348 | —- | M] () MD5=3DC40B918EEBCC531B025E66D4BA5D2A – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
 
< MD5 for: IEXPLORE.HL_  >
[2002/09/21 01:34:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\i386\IEXPLORE.HL_
[2002/09/21 15:34:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\WINDOWS\I386\IEXPLORE.HL_
 
< MD5 for: IEXPLORE.HLP  >
[2002/09/21 01:34:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
 
< MD5 for: WINLOGON.EX_  >
[2002/09/30 10:58:48 | 000,271,067 | —- | M] () MD5=C73F996304F177262B0C2B70A7DCB66C – C:\i386\WINLOGON.EX_
[2002/10/01 00:58:48 | 000,271,067 | —- | M] () MD5=C73F996304F177262B0C2B70A7DCB66C – C:\WINDOWS\I386\WINLOGON.EX_
 
< MD5 for: WINLOGON.EXE  >
[2004/08/04 07:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 00:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 00:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WINLOGON.REG  >
[2001/10/23 21:49:08 | 000,000,278 | —- | M] () MD5=329635F24C2EB6E4B850598AC7CC7AA4 – C:\hp\bin\winlogon.reg
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:364682BC

< End of report >

Here is Extras.txt:

OTL Extras logfile created on: 18/03/2012 15:20:37 - Run 1
OTL by OldTimer - Version 3.2.39.1	 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
511.48 Mb Total Physical Memory | 317.08 Mb Available Physical Memory | 61.99% Memory free
1.30 Gb Paging File | 1.04 Gb Available in Paging File | 80.08% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.85 Gb Total Space | 4.24 Gb Free Space | 5.90% Space Free | Partition Type: NTFS
Drive D: | 4.47 Gb Total Space | 1.09 Gb Free Space | 24.49% Space Free | Partition Type: FAT32
Drive G: | 931.28 Gb Total Space | 563.68 Gb Free Space | 60.53% Space Free | Partition Type: FAT32
 
Computer Name: DANIEL | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile [edit] – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0x00000000
"FirewallDisableNotify" = 0x00000000
"UpdatesDisableNotify" = 0x00000000
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"" = 
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"57080:TCP" = 57080:TCP:*:Enabled:Pando Media Booster
"57080:UDP" = 57080:UDP:*:Enabled:Pando Media Booster
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"55555:TCP" = 55555:TCP:*:Enabled:az
"57080:TCP" = 57080:TCP:*:Enabled:Pando Media Booster
"57080:UDP" = 57080:UDP:*:Enabled:Pando Media Booster
"55000:TCP" = 55000:TCP:*:Enabled:Testmule
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Magic Workstation\MWSPlay.exe" = C:\Program Files\Magic Workstation\MWSPlay.exe:*:Enabled:Magic Workstation Play Module – (Magi-Soft Development)
"C:\WINDOWS\Downloaded Program Files\PLauncher.exe" = C:\WINDOWS\Downloaded Program Files\PLauncher.exe:*:Enabled:PLauncher Application – (NHN Corporation)
"C:\WINDOWS\Downloaded Program Files\PurpleBean.exe" = C:\WINDOWS\Downloaded Program Files\PurpleBean.exe:*:Enabled:PurpleBean.exe – ()
"K:\Backup\Memeo\Daniel's Backup\C_\Documents and Settings\Owner.DANIEL\My Documents\Archive\Pokemon\TGB_Dual.exe" = K:\Backup\Memeo\Daniel's Backup\C_\Documents and Settings\Owner.DANIEL\My Documents\Archive\Pokemon\TGB_Dual.exe:*:Enabled:TGB Dual
"C:\Team17\Worms2\frontend.exe" = C:\Team17\Worms2\frontend.exe:*:Enabled:Worms 2 Frontend – (Team17 Software Ltd)
"C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\Emulator\NESTCL95.EXE" = C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\Emulator\NESTCL95.EXE:*:Disabled:NESTCL95 – ()
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC – (mIRC Co. Ltd.)
"C:\WINDOWS\system32\dxdiag.exe" = C:\WINDOWS\system32\dxdiag.exe:*:Enabled:Microsoft DirectX Diagnostic Tool – (Microsoft Corporation)
"C:\WINDOWS\system32\dpnsvr.exe" = C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server – (Microsoft Corporation)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze – (Vuze Inc.)
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule – (http://www.emule-project.net)
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player  – (Veoh Networks)
"C:\Program Files\Giraffic\Veoh_Giraffic.exe" = C:\Program Files\Giraffic\Veoh_Giraffic.exe:*:Enabled:Veoh Giraffic (Agent) – (Giraffic)
"C:\Program Files\Giraffic\Veoh_GirafficWatchdog.exe" = C:\Program Files\Giraffic\Veoh_GirafficWatchdog.exe:*:Enabled:Veoh Giraffic (Watchdog) – (Giraffic)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002F7118-53A9-486A-88AB-14F38EBD72F9}" = 冥色の隷姫
"{0044AEC7-8924-4FB1-B4F7-FD14A5FEA9E4}" = RPGツクール2003 ランタイムパッケージ
"{01A2E33A-8ADA-42D1-9173-8F65149E952F}" = Microsoft Money
"{0280F0D8-1542-4DAA-913C-8529E2A3835D}" = The Longest Journey
"{02CA7E66-1AD1-4DE9-BA9E-86A0EEB019C7}" = Microsoft Money System Pack
"{035A0014-3975-4267-9F39-1DC4745090B7}" = Microsoft Encarta Encyclopedia Standard - WE 2003
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = RecordNow Update Manager
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0DCFC7D5-8608-478C-8082-1FF848B978AF}" = USB Storage RW
"{12754F66-0AD9-4FFE-9B7A-9EED417476F9}" = Rags Suite
"{12905F20-5A31-499A-9463-71E5C3EF950B}" = SmartOCR Lite Edition 1.0
"{1526D87C-A955-4FAB-BF18-697BA457E352}" = Norton WMI Update
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{19FA71B0-F38E-435E-9F70-CE8D27F77F4B}" = Rags Suite
"{1DCC7418-2089-4BDD-B321-3771956160FC}" = ijji Auto Installer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22277E6E-9EFA-47CC-A16B-6D8AF85FEB8E}" = 冥色の隷姫 Append Disk
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 27
"{2B5DDB2C-0807-47FD-9C11-80EA761902C0}" = easy Internet sign-up
"{2C08D7E7-9EE1-4A08-AFE0-745F02DCD6A4}_is1" = Pokemon Online 1.0.53
"{2E4BFFE6-5CCA-4568-A862-37D9FC337AB9}_is1" = Tilem v.10
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{33F7A957-A66D-45A1-BADF-6576083B14E2}" = RPGツクール2000 ランタイムパッケージ
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{369B36BE-3D64-4641-9AEA-808D436FE132}" = Microsoft Picture It! Photo 7.0
"{36F4AF22-A159-4E0F-AABE-67638D2B939D}" = Super Webcam
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E9C2463-454A-3D20-A8AB-FDF544A829F9}" = Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - JPN
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A935817-099C-4E8C-AEA8-1D9F88FBA91C}" = blueMSX
"{4C643986-DE3C-4737-8472-CCEC36CCC267}" = Studio Content CD
"{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}" = Cisco Systems VPN Client 5.0.04.0300
"{53EF6570-21A4-47ED-A40A-E6470A5677A3}" = Studio 8
"{581CE7EA-A30D-11D6-8496-000000120101}" = ZD1211 802.11g Wireless LAN - USB
"{5A9FE525-8B8F-4701-A937-7F6745A4E9C7}" = RGSS-RTP Standard
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = MyDVD
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63537A32-BF50-4A79-908E-E7334A58F91B}" = Rags Suite
"{6652750B-AA69-49B7-9D09-C0A28B6FFC9F}" = ATLAS Translation Standard V14.0 Trial Version
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{7EE9DE0D-9228-4C33-B80E-FDD1773600DF}" = Microsoft Works Suite Add-in for Microsoft Word
"{8027B590-CD2B-3C7E-9F00-CDC0916CC915}" = Microsoft .NET Framework 3.5 Language Pack - jpn
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8214CC02-6271-4DC8-B8DD-779933450264}" = RecordNow
"{840BDB7F-6994-4316-8750-39DA41E202C7}" = Rags Suite
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics Driver Software
"{8D5D99B8-DFA2-4018-ADE9-A6B83E655C65}" = 
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{9BE2669E-2BD8-4164-A8B5-C904C864B403}" = WA Update v3.50 beta2
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B7B5A370-3DFF-4F0E-AE11-FD267C4938AA}" = CCS64 V3.7
"{BDE90251-93EB-4F6A-89D8-086E2D91DC56}" = Coloreal
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2878DE1-173A-3042-9C2C-3F2B958F61AA}" = Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - JPN
"{C3592426-531E-4110-911D-BFECE2CE284C}" = osu!
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{D751B34C-058F-42EF-BE95-14EBB0D2C585}" = Dreamfall
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E21F0BCA-12DD-493C-862E-6546C242EA74}" = HPD_404_Patch
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{EF53DD60-C4E2-11DB-3D6C-167690F54AE1}" = Notation Composer 2.6.3 (Trial Version)
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.20)
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7F2DC0A-C22E-49AD-AD37-797309A54E7B}" = Microsoft AutoRoute 2002
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"12bbe590-c890-11d9-9669-0800200c9a66_is1" = The Lord of the Rings Online™ v03.02.03.8013
"8461-7759-5462-8226" = Vuze
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity_is1" = Audacity 1.2.6
"BackWeb-137903 Uninstaller" = hp center
"BeebEm_is1" = BeebEm V4.0
"CamStudio" = CamStudio
"CamStudio Lossless Codec_is1" = CamStudio Lossless Codec v1.4
"Cheat Engine 5.5_is1" = Cheat Engine 5.5
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2011-06-26
"Cpukiller3_is1" = Cpukiller3 v1.0.5
"Cute Knight Kingdom Demo_is1" = Cute Knight Kingdom Demo version 1.06
"devkitProUpdater" = devkitProUpdater 1.5.0
"Digital - A Love Story" = Digital - A Love Story 1.1
"DivX Setup.divx.com" = DivX Setup
"eMule" = eMule
"Explorer Suite_is1" = Explorer Suite III
"Fate-stay night English" = Fate/stay night English v3.2
"ffdshow_is1" = ffdshow v1.1.3476 [2010-06-15]
"Flash Decompiler Trillix_is1" = Flash Decompiler Trillix
"FullAni" = フルアニ
"Gargoyle" = Gargoyle
"Giraffic" = Veoh Giraffic Video Accelerator
"HashCheck Shell Extension" = HashCheck Shell Extension (x86-32)
"Hollywood FX 4.6" = Pinnacle Hollywood FX 4.6
"Hospital" = Theme Hospital
"htmltads.exe" = HTML TADS Player Kit
"Indeo® Software" = Indeo® Software
"InstallShield_{002F7118-53A9-486A-88AB-14F38EBD72F9}" = 冥色の隷姫
"InstallShield_{22277E6E-9EFA-47CC-A16B-6D8AF85FEB8E}" = 冥色の隷姫 Append Disk
"IObit Malware Fighter_is1" = IObit Malware Fighter
"Jisei Demo" = Jisei Demo 1
"K!TV" = K!TV
"KINGDOM" = 恋する王国
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.3.4 (Full)
"Kudos 2 Demo_is1" = Kudos 2 Demo
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Launch of the Screaming Narwhal" = Tales of Monkey Island - Launch of the Screaming Narwhal
"LennaJobHDotTheater" = レナジョブえっちドットシアター
"Lightning Warrior Raidy" = Lightning Warrior Raidy
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 1.80 (Symantec Corporation)
"Lunia" = Lunia
"Magic Set Editor 2_is1" = Magic Set Editor 2 - 0.3.8 beta
"Magic Workstation_is1" = Magic Workstation 0.94f
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack - jpn" = Microsoft .NET Framework 3.5 Language Pack - 日本語
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"mIRC" = mIRC
"mmm" = 最強御主人様!
"Mozilla Firefox (3.6.25)" = Mozilla Firefox (3.6.25)
"Naughty Tic Tac Toe_is1" = Naughty Tic Tac Toe 3.0
"Nude School Dating Sim 2.00" = Nude School Dating Sim 2.00
"NVIDIA Drivers" = NVIDIA Drivers
"piajan" = ぴあ雀 の削除
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"RAGS Suite" = RAGS Suite 0.9.9.2
"RealPlayer 12.0" = RealPlayer
"RGSS-RTP Standard_is1" = RGSS-RTP Standard
"Risk WarZone Client" = Risk WarZone Client
"RollerCoaster Tycoon Setup" = Roll
"RPG Maker 2000 1.07b" = RPG Maker 2000 1.07b
"RPG Maker 2003_is1" = RPG Maker 2003 v1.08
"RPG Maker VX RTP_is1" = RPG Maker VX RTP
"RPG Maker VX_is1" = RPG Maker VX
"RPGVXAce_RTP_is1" = RPG MAKER VX Ace RTP
"RPGツクールVX RTP_is1" = RPGツクールVX RTP
"RTP for RM2K (Png, Wav, Midi, Fonts)" = RTP for RM2K (Png, Wav, Midi, Fonts)
"S3Display" = S3Display
"S3Gamma2" = S3Gamma2
"S3Info2" = S3Info2
"S3Overlay" = S3Overlay
"sakura editor_is1" = sakura editor(サクラエディタ)
"Sengoku Rance English_is1" = Sengoku Rance English v1.0
"Shockwave" = Shockwave
"ST6UNST #1" = ADRIFT Runner
"SUPER ゥ" = SUPER ゥ Version 2009.bld.36 (June 10, 2009)
"SystemRequirementsLab" = System Requirements Lab
"Tears to Tiara" = Tears to Tiara
"Thief and Sword_is1" = Thief and Sword
"Universal Extractor_is1" = Universal Extractor 1.6.1
"Unlocker" = Unlocker 1.8.7
"VDMSound" = VDMSound
"Veoh Video Compass" = Veoh Video Compass
"Veoh Web Player Beta" = Veoh Web Player
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Works2003Setup" = Microsoft Works 2003 Setup Launcher
"Worms Armageddon" = Worms Armageddon
"Worms2" = Worms2
"X-Change 2" = X-Change 2
"X-Change 3" = X-Change 3
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"Yin-Yang - X-Change Alternateive" = Yin-Yang - X-Change Alternateive
"アオイシロ(体験版)_is1" = アオイシロ(体験版)
"学園迷宮エロはぷにんぐ! ~イクぜ!性技のダンジョン攻略~_is1" = 学園迷宮エロはぷにんぐ! ~イクぜ!性技のダンジョン攻略~ 1.00
"調教神ユーリ-俺様の肉便器奴隷にしてやるぜ!!-_is1" = 調教神ユーリ-俺様の肉便器奴隷にしてやるぜ!!-1.0
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Shoddy Battle" = Shoddy Battle
"Spirited Heart Demo" = Spirited Heart Demo
"Yume Nikki 0.10 English" = Yume Nikki 0.10 English
"小影の伝説" = 小影の伝説
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 28/04/2011 20:27:01 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application quickatlas.exe, version 14.10.1.0, faulting module
 ntdll.dll, version 5.1.2600.5755, fault address 0x00011689.
 
Error - 29/04/2011 17:25:05 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application pokemon-online.exe, version 0.0.0.0, faulting
 module qtgui4.dll, version 4.6.3.0, fault address 0x004407dd.
 
Error - 05/05/2011 11:21:39 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module 
ntdll.dll, version 5.1.2600.5755, fault address 0x0001b21a.
 
Error - 07/05/2011 00:18:13 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application quickatlas.exe, version 14.10.1.0, faulting module
 ntdll.dll, version 5.1.2600.5755, fault address 0x0001072f.
 
Error - 07/05/2011 00:19:07 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application quickatlas.exe, version 14.10.1.0, faulting module
 ntdll.dll, version 5.1.2600.5755, fault address 0x0001072f.
 
Error - 07/05/2011 00:19:50 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application quickatlas.exe, version 14.10.1.0, faulting module
 ntdll.dll, version 5.1.2600.5755, fault address 0x00010a1b.
 
Error - 07/05/2011 00:25:54 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application quickatlas.exe, version 14.10.1.0, faulting module
 ntdll.dll, version 5.1.2600.5755, fault address 0x0001aa21.
 
Error - 07/05/2011 00:27:46 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application quickatlas.exe, version 14.10.1.0, faulting module
 ntdll.dll, version 5.1.2600.5755, fault address 0x0001aa21.
 
Error - 08/05/2011 21:09:17 | Computer Name = DANIEL | Source = Application Error | ID = 1000
Description = Faulting application quickatlas.exe, version 14.10.1.0, faulting module
 ntdll.dll, version 5.1.2600.5755, fault address 0x0001aa21.
 
Error - 14/05/2011 21:26:13 | Computer Name = DANIEL | Source = Application Hang | ID = 1002
Description = Hanging application mplayerc.exe, version 6.4.9.1, hang module hungapp,
 version 0.0.0.0, hang address 0x00000000.
 
[ System Events ]
Error - 18/03/2012 01:21:16 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:06:51 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:09:53 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:10:28 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:11:15 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:11:50 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:14:59 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:17:46 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:18:59 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
Error - 18/03/2012 11:19:59 | Computer Name = DANIEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdatem with
 arguments "/comsvc"  in order to run the server:  {E225E692-4B47-4777-9BED-4FD7FE257F0E}
 
 
< End of report >

When I ran aswMBR it asked me to update the Avast virus definitions. I chose Yes, which caused the Dial-Up Connection box to appear (even though I was already connected to the internet). Choosing to Dial the default Broadband Connection resulted in it failing; when I clicked Cancel, the Scan button remained greyed out in aswMBR. Here is the log, anyway:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-03-18 15:55:16
—————————–
15:55:16.156	OS Version: Windows 5.1.2600 Service Pack 3
15:55:16.156	Number of processors: 1 586 0x207
15:55:16.156	ComputerName: DANIEL  UserName: Owner
15:55:16.703	Initialize success
16:12:59.359	The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
Hi

I recommend that you uninstall IObit. It is has been proved to be untrustworthy in its programming and is pretty ineffective now that it can no longer be propped up by MBAM

See:

http://forums.malwarebytes.org/index.php?showtopic=29681
http://forums.malwarebytes.org/index.php?showtopic=30989
http://forums.malwarebytes.org/index.php?showtopic=33217

=====================================

Re-run RogueKiller

Run the scan again and when it finishes click on the “Registry” tab and UN-tick the entry below:

[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND – UNTICK

Leave the ticks by these then press the Delete tab, as I only want these suspicious entries dealt with:

[SUSP PATH] HKCU\[…]\Run : IsvRqwhh (C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-1012008372-3885175467-2977226436-1003[…]\Run : IsvRqwhh (C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe) -> FOUND
[SUSP PATH] HKLM\[…]\Winlogon : Userinit (C:\WINDOWS\SYSTEM32\Userinit.exe,,C:\Documents and Settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe) -> FOUND
[PROXY IE] HKCU\[…]\Internet Settings : ProxyServer (hxxp=127.0.0.1:5555) -> FOUND

NEXT


Click on the “Drivers” tab and UN-tick all EXCEPT these:

SSDT[41] : NtCreateKey @ 0x8057791D -> HOOKED (\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\phwyphpt.sys @ 0xF87896AC)
SSDT[119] : NtOpenKey @ 0x80572BF4 -> HOOKED (\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\phwyphpt.sys @ 0xF8789562)


Press Delete

NEXT

Click on the “Proxy” tab and if this entry is there, press ProxyFix:

[PROXY IE] HKCU\[…]\Internet Settings : ProxyServer (hxxp=127.0.0.1:5555) -> FOUND

When this is complete, please send a new RogueKiller log.

=====================================

Run aswMBR

The last log was incomplete. Don’t bother updating the Avast virus definitions, just run a scan.

When you post back with the logs, please don’t put them in “Code” boxes, just copy and paste them into the post.

Thanks

Satchfan
RogueKiller log:

RogueKiller V7.3.1 [03/10/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Owner [Admin rights]
Mode: Remove – Date: 03/19/2012 17:54:23

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤
IRP[IRP_MJ_CREATE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_CLOSE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_SYSTEM_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)
IRP[IRP_MJ_DEVICE_CHANGE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xF82F9B40)

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: Maxtor 6Y080L0 +++++
— User —
[MBR] 7899034f22bfd9456b8dcfc0d6cd3c5d
[BSP] e5a73de1d2879431563847cc0e47e969 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 63 | Size: 4584 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 9389520 | Size: 73577 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[7].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt ;
RKreport[6].txt ; RKreport[7].txt

aswMBR log:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-03-19 17:57:09
—————————–
17:57:09.320 OS Version: Windows 5.1.2600 Service Pack 3
17:57:09.320 Number of processors: 1 586 0x207
17:57:09.320 ComputerName: DANIEL UserName: Owner
17:57:09.961 Initialize success
17:57:13.242 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
17:57:13.242 Disk 0 Vendor: Maxtor_6Y080L0 YAR41VW0 Size: 78167MB BusType: 3
17:57:13.258 Disk 0 MBR read successfully
17:57:13.273 Disk 0 MBR scan
17:57:13.273 Disk 0 unknown MBR code
17:57:13.273 Disk 0 Partition 1 00 0B FAT32 RECOVERY 4584 MB offset 63
17:57:13.289 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 73577 MB offset 9389520
17:57:13.289 Disk 0 scanning sectors +160075440
17:57:13.383 Disk 0 scanning C:\WINDOWS\system32\drivers
17:57:24.117 Service scanning
17:57:38.226 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
17:57:42.711 Modules scanning
17:57:52.711 Disk 0 trace - called modules:
17:57:52.726 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys span.sys >>UNKNOWN [0x82adf938]<<
17:57:52.742 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82a20ab8]
17:57:52.742 3 CLASSPNP.SYS[f84effd7] -> nt!IofCallDriver -> \Device\00000072[0x82a24f18]
17:57:52.758 5 ACPI.sys[f833e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82a6a940]
17:57:52.758 Scan finished successfully
17:58:05.414 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
17:58:05.414 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR2.txt"
Hi Showsni

There are a few entries there that I need more information about.

First though, there is also a Norton entry that might interfere with the proceedings so we need to get rid of it.

Remove remnants of Norton
  • download the Norton Removal Tool from here and save it to your desktop.
  • double click on Norton_Removal_Tool.exe to run the tool.
  • follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.

======================================================

Run TDSSKiller

Please download TDSSKiller.zip
  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan
    • only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
    • then click Continue > Reboot now
  • copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
======================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • see this Link for programs that need to be disabled and instruction on how to disable them.
  • remember to re-enable them when we're done.
  • double click on ComboFix.exe & follow the prompts.
  • as part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please also remember to include the TDSSKiller log and let me know whether there are any changes and if anything is any different.

Thanks

Satchfan
Thanks for the reply!

TDSSkiller log:


23:02:03.0218 2364 TDSS rootkit removing tool 2.7.20.0 Mar 9 2012 17:10:43
23:02:04.0281 2364 ============================================================
23:02:04.0281 2364 Current date / time: 2012/03/19 23:02:04.0281
23:02:04.0281 2364 SystemInfo:
23:02:04.0281 2364
23:02:04.0281 2364 OS Version: 5.1.2600 ServicePack: 3.0
23:02:04.0281 2364 Product type: Workstation
23:02:04.0281 2364 ComputerName: DANIEL
23:02:04.0281 2364 UserName: Owner
23:02:04.0281 2364 Windows directory: C:\WINDOWS
23:02:04.0281 2364 System windows directory: C:\WINDOWS
23:02:04.0281 2364 Processor architecture: Intel x86
23:02:04.0281 2364 Number of processors: 1
23:02:04.0281 2364 Page size: 0x1000
23:02:04.0281 2364 Boot type: Normal boot
23:02:04.0281 2364 ============================================================
23:02:06.0640 2364 Drive \Device\Harddisk0\DR0 - Size: 0x1315740000 (76.34 Gb), SectorSize: 0x200, Cylinders: 0x295B, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000054
23:02:06.0781 2364 Drive \Device\Harddisk5\DR7 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
23:02:07.0359 2364 \Device\Harddisk0\DR0:
23:02:07.0375 2364 MBR used
23:02:07.0375 2364 \Device\Harddisk0\DR0\Partition0: MBR, Type 0xB, StartLBA 0x3F, BlocksNum 0x8F4591
23:02:07.0375 2364 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x8F45D0, BlocksNum 0x8FB48E0
23:02:07.0375 2364 \Device\Harddisk5\DR7:
23:02:07.0375 2364 MBR used
23:02:07.0375 2364 \Device\Harddisk5\DR7\Partition0: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x74705982
23:02:07.0406 2364 Initialize success
23:02:07.0406 2364 ============================================================
23:02:16.0312 1944 ============================================================
23:02:16.0312 1944 Scan started
23:02:16.0312 1944 Mode: Manual;
23:02:16.0312 1944 ============================================================
23:02:17.0000 1944 Abiosdsk - ok
23:02:17.0140 1944 abp480n5 - ok
23:02:17.0265 1944 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:02:17.0281 1944 ACPI - ok
23:02:17.0468 1944 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
23:02:17.0468 1944 ACPIEC - ok
23:02:17.0593 1944 adpu160m - ok
23:02:17.0687 1944 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
23:02:17.0703 1944 aec - ok
23:02:17.0875 1944 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
23:02:17.0875 1944 AFD - ok
23:02:18.0062 1944 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
23:02:18.0062 1944 agp440 - ok
23:02:18.0203 1944 Aha154x - ok
23:02:18.0359 1944 aic78u2 - ok
23:02:18.0468 1944 aic78xx - ok
23:02:18.0781 1944 ALCXWDM (8d6c30e515717248e0e52b85fd7ac466) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
23:02:18.0812 1944 ALCXWDM - ok
23:02:18.0937 1944 AliIde - ok
23:02:19.0015 1944 AmdK7 (8fce268cdbdd83b23419d1f35f42c7b1) C:\WINDOWS\system32\DRIVERS\amdk7.sys
23:02:19.0015 1944 AmdK7 - ok
23:02:19.0078 1944 amsint - ok
23:02:19.0187 1944 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
23:02:19.0187 1944 Arp1394 - ok
23:02:19.0265 1944 asc - ok
23:02:19.0359 1944 asc3350p - ok
23:02:19.0468 1944 asc3550 - ok
23:02:19.0578 1944 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:02:19.0578 1944 AsyncMac - ok
23:02:19.0765 1944 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
23:02:19.0765 1944 atapi - ok
23:02:19.0890 1944 Atdisk - ok
23:02:19.0968 1944 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:02:19.0968 1944 Atmarpc - ok
23:02:20.0140 1944 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
23:02:20.0140 1944 audstub - ok
23:02:20.0343 1944 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
23:02:20.0343 1944 Beep - ok
23:02:20.0500 1944 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
23:02:20.0500 1944 cbidf2k - ok
23:02:20.0734 1944 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
23:02:20.0734 1944 CCDECODE - ok
23:02:20.0875 1944 cd20xrnt - ok
23:02:21.0031 1944 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
23:02:21.0031 1944 Cdaudio - ok
23:02:21.0171 1944 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
23:02:21.0171 1944 Cdfs - ok
23:02:21.0281 1944 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:02:21.0281 1944 Cdrom - ok
23:02:21.0437 1944 Changer - ok
23:02:21.0593 1944 CmdIde - ok
23:02:21.0671 1944 Cpqarray - ok
23:02:21.0750 1944 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
23:02:21.0765 1944 CVirtA - ok
23:02:21.0921 1944 CVPNDRVA (720482888c3778f26eeb83d286a6cdc3) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
23:02:21.0921 1944 CVPNDRVA - ok
23:02:22.0062 1944 dac2w2k - ok
23:02:22.0109 1944 dac960nt - ok
23:02:22.0187 1944 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
23:02:22.0203 1944 Disk - ok
23:02:22.0375 1944 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
23:02:22.0390 1944 dmboot - ok
23:02:22.0562 1944 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
23:02:22.0562 1944 dmio - ok
23:02:22.0734 1944 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
23:02:22.0734 1944 dmload - ok
23:02:22.0890 1944 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
23:02:22.0890 1944 DMusic - ok
23:02:23.0062 1944 DNE (86d52c32a308f84bbc626bff7c1fb710) C:\WINDOWS\system32\DRIVERS\dne2000.sys
23:02:23.0078 1944 DNE - ok
23:02:23.0218 1944 dpti2o - ok
23:02:23.0281 1944 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
23:02:23.0281 1944 drmkaud - ok
23:02:23.0484 1944 DSDrv4 (692ef4d0dc4b2b722e967b1a355564f0) C:\PROGRA~1\K!TV\Plugins\S_Bt8x8\DSDrv4.sys
23:02:23.0500 1944 DSDrv4 - ok
23:02:23.0671 1944 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
23:02:23.0687 1944 EL90XBC - ok
23:02:23.0859 1944 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
23:02:23.0859 1944 Fastfat - ok
23:02:24.0031 1944 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
23:02:24.0031 1944 Fdc - ok
23:02:24.0171 1944 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
23:02:24.0171 1944 Fips - ok
23:02:24.0312 1944 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
23:02:24.0312 1944 Flpydisk - ok
23:02:24.0453 1944 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
23:02:24.0468 1944 FltMgr - ok
23:02:24.0656 1944 FStarForce (12af49276e2c07505dce63ec0342f267) C:\WINDOWS\system32\DRIVERS\FStarForce.sys
23:02:24.0656 1944 FStarForce - ok
23:02:24.0859 1944 FsVga (455f778ee14368468560bd7cb8c854d0) C:\WINDOWS\system32\DRIVERS\fsvga.sys
23:02:24.0859 1944 FsVga - ok
23:02:25.0046 1944 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:02:25.0046 1944 Fs_Rec - ok
23:02:25.0203 1944 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:02:25.0218 1944 Ftdisk - ok
23:02:25.0421 1944 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:02:25.0421 1944 Gpc - ok
23:02:25.0625 1944 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
23:02:25.0625 1944 HidUsb - ok
23:02:25.0765 1944 hpn - ok
23:02:25.0906 1944 HSFHWBS2 (5ca8ac1409ec583d44e01751a26a331c) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
23:02:25.0906 1944 HSFHWBS2 - ok
23:02:26.0171 1944 HSF_DP (f5bc71977dc2d43995567998084af8e6) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
23:02:26.0234 1944 HSF_DP - ok
23:02:26.0484 1944 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
23:02:26.0484 1944 HTTP - ok
23:02:26.0625 1944 i2omgmt - ok
23:02:26.0687 1944 i2omp - ok
23:02:26.0765 1944 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:02:26.0765 1944 i8042prt - ok
23:02:26.0921 1944 ialm (ba8a1050e0df758b02cdfbd11f6b4464) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
23:02:26.0937 1944 ialm - ok
23:02:27.0125 1944 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
23:02:27.0125 1944 Imapi - ok
23:02:27.0281 1944 ini910u - ok
23:02:27.0390 1944 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
23:02:27.0406 1944 IntelIde - ok
23:02:27.0578 1944 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:02:27.0578 1944 intelppm - ok
23:02:27.0750 1944 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
23:02:27.0765 1944 ip6fw - ok
23:02:27.0921 1944 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:02:27.0921 1944 IpFilterDriver - ok
23:02:28.0093 1944 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:02:28.0093 1944 IpInIp - ok
23:02:28.0265 1944 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:02:28.0296 1944 IpNat - ok
23:02:28.0468 1944 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:02:28.0468 1944 IPSec - ok
23:02:28.0625 1944 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
23:02:28.0625 1944 IRENUM - ok
23:02:28.0796 1944 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:02:28.0796 1944 isapnp - ok
23:02:28.0968 1944 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:02:28.0984 1944 Kbdclass - ok
23:02:29.0125 1944 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
23:02:29.0140 1944 kmixer - ok
23:02:29.0375 1944 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys
23:02:29.0375 1944 KSecDD - ok
23:02:29.0546 1944 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
23:02:29.0546 1944 Lbd - ok
23:02:29.0703 1944 lbrtfdc - ok
23:02:29.0906 1944 mdmxsdk (a1e9d936eac07ee9386e87bac1377fad) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
23:02:29.0906 1944 mdmxsdk - ok
23:02:30.0062 1944 Micorsoft Windows Service - ok
23:02:30.0218 1944 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
23:02:30.0218 1944 mnmdd - ok
23:02:30.0390 1944 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
23:02:30.0390 1944 Modem - ok
23:02:30.0562 1944 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:02:30.0562 1944 Mouclass - ok
23:02:30.0734 1944 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
23:02:30.0734 1944 mouhid - ok
23:02:30.0921 1944 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
23:02:30.0937 1944 MountMgr - ok
23:02:31.0093 1944 mraid35x - ok
23:02:31.0265 1944 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:02:31.0281 1944 MRxDAV - ok
23:02:31.0500 1944 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:02:31.0531 1944 MRxSmb - ok
23:02:31.0703 1944 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
23:02:31.0703 1944 Msfs - ok
23:02:31.0890 1944 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:02:31.0890 1944 MSKSSRV - ok
23:02:32.0031 1944 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:02:32.0031 1944 MSPCLOCK - ok
23:02:32.0203 1944 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
23:02:32.0203 1944 MSPQM - ok
23:02:32.0359 1944 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:02:32.0359 1944 mssmbios - ok
23:02:32.0546 1944 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
23:02:32.0562 1944 MSTEE - ok
23:02:32.0718 1944 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
23:02:32.0750 1944 Mup - ok
23:02:32.0968 1944 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
23:02:32.0968 1944 NABTSFEC - ok
23:02:33.0125 1944 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
23:02:33.0125 1944 NDIS - ok
23:02:33.0296 1944 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
23:02:33.0296 1944 NdisIP - ok
23:02:33.0562 1944 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:02:33.0562 1944 NdisTapi - ok
23:02:33.0718 1944 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:02:33.0734 1944 Ndisuio - ok
23:02:33.0906 1944 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:02:33.0906 1944 NdisWan - ok
23:02:34.0078 1944 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
23:02:34.0078 1944 NDProxy - ok
23:02:34.0250 1944 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
23:02:34.0250 1944 NetBIOS - ok
23:02:34.0437 1944 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
23:02:34.0453 1944 NetBT - ok
23:02:34.0640 1944 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
23:02:34.0640 1944 NIC1394 - ok
23:02:34.0875 1944 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
23:02:34.0875 1944 Npfs - ok
23:02:35.0046 1944 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
23:02:35.0140 1944 Ntfs - ok
23:02:35.0375 1944 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
23:02:35.0390 1944 Null - ok
23:02:35.0750 1944 nv (ba1b732c1a70cfea0c1b64f2850bf44f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
23:02:36.0484 1944 nv - ok
23:02:36.0640 1944 nv_agp (db36442c20793c53b4128eb85f9a3d32) C:\WINDOWS\system32\DRIVERS\nv_agp.sys
23:02:36.0656 1944 nv_agp - ok
23:02:36.0781 1944 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:02:36.0796 1944 NwlnkFlt - ok
23:02:36.0921 1944 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:02:36.0937 1944 NwlnkFwd - ok
23:02:37.0031 1944 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
23:02:37.0031 1944 ohci1394 - ok
23:02:37.0203 1944 onyfwev (e6d35f3aa51a65eb35c1f2340154a25e) C:\WINDOWS\system32\drivers\ocltoijp.sys
23:02:37.0203 1944 onyfwev - ok
23:02:37.0312 1944 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
23:02:37.0328 1944 Parport - ok
23:02:37.0484 1944 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
23:02:37.0484 1944 PartMgr - ok
23:02:37.0671 1944 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
23:02:37.0671 1944 ParVdm - ok
23:02:37.0765 1944 PCAMPR5 - ok
23:02:37.0890 1944 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
23:02:37.0906 1944 PCI - ok
23:02:38.0031 1944 PCIDump - ok
23:02:38.0328 1944 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\System32\DRIVERS\pciide.sys
23:02:38.0328 1944 PCIIde - ok
23:02:38.0515 1944 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
23:02:38.0515 1944 Pcmcia - ok
23:02:38.0640 1944 PDCOMP - ok
23:02:38.0750 1944 PDFRAME - ok
23:02:38.0875 1944 PDRELI - ok
23:02:38.0984 1944 PDRFRAME - ok
23:02:39.0125 1944 perc2 - ok
23:02:39.0234 1944 perc2hib - ok
23:02:39.0437 1944 pfc (da86016f0672ada925f589ede715f185) C:\WINDOWS\system32\drivers\pfc.sys
23:02:39.0437 1944 pfc - ok
23:02:39.0625 1944 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:02:39.0625 1944 PptpMiniport - ok
23:02:39.0750 1944 PRAGMAmxnlprpuyc - ok
23:02:39.0796 1944 PRAGMAtspwixrnsk - ok
23:02:39.0859 1944 PRAGMAxnqweeixui - ok
23:02:39.0968 1944 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
23:02:39.0968 1944 Processor - ok
23:02:40.0125 1944 Ps2 (bffdb363485501a38f0bca83aec810db) C:\WINDOWS\system32\DRIVERS\PS2.sys
23:02:40.0125 1944 Ps2 - ok
23:02:40.0250 1944 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
23:02:40.0250 1944 PSched - ok
23:02:40.0359 1944 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:02:40.0375 1944 Ptilink - ok
23:02:40.0531 1944 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
23:02:40.0531 1944 PxHelp20 - ok
23:02:40.0671 1944 ql1080 - ok
23:02:40.0765 1944 Ql10wnt - ok
23:02:40.0859 1944 ql12160 - ok
23:02:40.0937 1944 ql1240 - ok
23:02:41.0078 1944 ql1280 - ok
23:02:41.0218 1944 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:02:41.0218 1944 RasAcd - ok
23:02:41.0406 1944 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:02:41.0406 1944 Rasl2tp - ok
23:02:41.0671 1944 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:02:41.0671 1944 RasPppoe - ok
23:02:41.0828 1944 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
23:02:41.0828 1944 Raspti - ok
23:02:41.0984 1944 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:02:42.0000 1944 Rdbss - ok
23:02:42.0140 1944 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:02:42.0140 1944 RDPCDD - ok
23:02:42.0375 1944 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
23:02:42.0375 1944 RDPWD - ok
23:02:42.0531 1944 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
23:02:42.0531 1944 redbook - ok
23:02:42.0687 1944 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
23:02:42.0687 1944 rtl8139 - ok
23:02:42.0875 1944 S3Psddr (0dbcc071a268e0340a2ba6bdd98bace4) C:\WINDOWS\system32\DRIVERS\s3gnbm.sys
23:02:42.0890 1944 S3Psddr - ok
23:02:43.0093 1944 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\DOCUME~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS
23:02:43.0093 1944 SASDIFSV - ok
23:02:43.0296 1944 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\DOCUME~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS
23:02:43.0296 1944 SASKUTIL - ok
23:02:43.0546 1944 SAVOnAccessControl (d9df915972694b5274facc8d00492acd) C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys
23:02:43.0546 1944 SAVOnAccessControl - ok
23:02:43.0687 1944 SAVOnAccessFilter (31b35cca652a3553fa4fb99ea79c35bf) C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys
23:02:43.0687 1944 SAVOnAccessFilter - ok
23:02:43.0875 1944 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:02:43.0875 1944 Secdrv - ok
23:02:44.0046 1944 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
23:02:44.0062 1944 serenum - ok
23:02:44.0296 1944 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
23:02:44.0296 1944 Serial - ok
23:02:44.0484 1944 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
23:02:44.0484 1944 Sfloppy - ok
23:02:44.0625 1944 Simbad - ok
23:02:44.0703 1944 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
23:02:44.0703 1944 SLIP - ok
23:02:44.0953 1944 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
23:02:44.0953 1944 SONYPVU1 - ok
23:02:45.0093 1944 SophosBootDriver (3bdf94e0827d13e44249a646f6c0eb7c) C:\WINDOWS\system32\DRIVERS\SophosBootDriver.sys
23:02:45.0093 1944 SophosBootDriver - ok
23:02:45.0265 1944 sosf (e6d35f3aa51a65eb35c1f2340154a25e) C:\WINDOWS\system32\drivers\vexl.sys
23:02:45.0265 1944 sosf - ok
23:02:45.0406 1944 Sparrow - ok
23:02:45.0484 1944 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
23:02:45.0484 1944 splitter - ok
23:02:45.0640 1944 sptd (71e276f6d189413266ea22171806597b) C:\WINDOWS\system32\Drivers\sptd.sys
23:02:45.0640 1944 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
23:02:45.0640 1944 sptd ( LockedFile.Multi.Generic ) - warning
23:02:45.0640 1944 sptd - detected LockedFile.Multi.Generic (1)
23:02:45.0796 1944 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
23:02:45.0796 1944 sr - ok
23:02:46.0031 1944 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys
23:02:46.0031 1944 Srv - ok
23:02:46.0187 1944 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
23:02:46.0187 1944 streamip - ok
23:02:46.0328 1944 SUPERWEBCAM (88a75bff38e6da6975950c8576442842) C:\WINDOWS\system32\DRIVERS\superwebcam.sys
23:02:46.0328 1944 SUPERWEBCAM - ok
23:02:46.0468 1944 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
23:02:46.0468 1944 swenum - ok
23:02:46.0546 1944 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
23:02:46.0546 1944 swmidi - ok
23:02:46.0640 1944 symc810 - ok
23:02:46.0750 1944 symc8xx - ok
23:02:46.0812 1944 sym_hi - ok
23:02:46.0859 1944 sym_u3 - ok
23:02:46.0953 1944 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
23:02:46.0953 1944 sysaudio - ok
23:02:47.0109 1944 tap0901 (34f1bcb847a924a161422f106a79b9ff) C:\WINDOWS\system32\DRIVERS\tap0901.sys
23:02:47.0109 1944 tap0901 - ok
23:02:47.0328 1944 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:02:47.0343 1944 Tcpip - ok
23:02:47.0484 1944 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
23:02:47.0484 1944 TDPIPE - ok
23:02:47.0625 1944 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
23:02:47.0625 1944 TDTCP - ok
23:02:47.0875 1944 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
23:02:47.0890 1944 TermDD - ok
23:02:48.0015 1944 TosIde - ok
23:02:48.0125 1944 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
23:02:48.0125 1944 Udfs - ok
23:02:48.0218 1944 ultra - ok
23:02:48.0312 1944 UnlockerDriver5 (4847639d852763ee39415c929470f672) C:\Program Files\Unlocker\UnlockerDriver5.sys
23:02:48.0312 1944 UnlockerDriver5 - ok
23:02:48.0531 1944 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
23:02:48.0546 1944 Update - ok
23:02:48.0734 1944 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
23:02:48.0734 1944 usbehci - ok
23:02:48.0890 1944 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
23:02:48.0890 1944 usbhub - ok
23:02:49.0078 1944 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
23:02:49.0078 1944 usbohci - ok
23:02:49.0218 1944 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:02:49.0218 1944 usbscan - ok
23:02:49.0343 1944 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
23:02:49.0359 1944 USBSTOR - ok
23:02:49.0546 1944 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
23:02:49.0546 1944 usbuhci - ok
23:02:49.0687 1944 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
23:02:49.0687 1944 VgaSave - ok
23:02:49.0812 1944 viaagp1 (f76ea9ae8d32ec50159795d29674465e) C:\WINDOWS\system32\DRIVERS\viaagp1.sys
23:02:49.0828 1944 viaagp1 - ok
23:02:49.0968 1944 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
23:02:49.0968 1944 ViaIde - ok
23:02:50.0125 1944 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
23:02:50.0125 1944 VolSnap - ok
23:02:50.0296 1944 vsdatant (0354ba3a5ba5e28cc247eb5f5dd8793c) C:\WINDOWS\system32\vsdatant.sys
23:02:50.0343 1944 vsdatant - ok
23:02:50.0531 1944 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:02:50.0531 1944 Wanarp - ok
23:02:50.0671 1944 WDICA - ok
23:02:50.0812 1944 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
23:02:50.0812 1944 wdmaud - ok
23:02:51.0000 1944 winachsf (ca4ccfbeab7a0b76e2335e113860e8ee) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
23:02:51.0031 1944 winachsf - ok
23:02:51.0234 1944 WLAN(WLAN) (b183823cfa0ec393556261a817cd4ad8) C:\WINDOWS\system32\DRIVERS\zd1211u.sys
23:02:51.0250 1944 WLAN(WLAN) - ok
23:02:51.0500 1944 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
23:02:51.0500 1944 WSTCODEC - ok
23:02:51.0687 1944 yxyhfv (e6d35f3aa51a65eb35c1f2340154a25e) C:\WINDOWS\system32\drivers\ulmqni.sys
23:02:51.0687 1944 yxyhfv - ok
23:02:51.0843 1944 ZD1211U(ZyDAS) (b183823cfa0ec393556261a817cd4ad8) C:\WINDOWS\system32\DRIVERS\zd1211u.sys
23:02:51.0859 1944 ZD1211U(ZyDAS) - ok
23:02:51.0968 1944 ZDBRGSYS (f506a40dc8890f61cc6660efbecc0810) C:\WINDOWS\system32\ZDBRGSYS.SYS
23:02:51.0984 1944 ZDBRGSYS - ok
23:02:52.0093 1944 ZDPNDIS5 (29c917279d79848b3dd94909fc00e2a8) C:\WINDOWS\system32\ZDPNDIS5.SYS
23:02:52.0093 1944 ZDPNDIS5 - ok
23:02:52.0250 1944 {6080A529-897E-4629-A488-ABA0C29B635E} (7829319b296adc8a3bd99f4824effda9) C:\WINDOWS\system32\drivers\ialmsbw.sys
23:02:52.0250 1944 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
23:02:52.0359 1944 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (b8c99f314372be1425468d844ce45cee) C:\WINDOWS\system32\drivers\ialmkchw.sys
23:02:52.0359 1944 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
23:02:52.0406 1944 MBR (0x1B8) (24bf22b59c30b9b11e1af62cfc3c418e) \Device\Harddisk0\DR0
23:02:52.0421 1944 \Device\Harddisk0\DR0 - ok
23:02:53.0000 1944 MBR (0x1B8) (8ff255184f078c9c04e6a2ce66117c5c) \Device\Harddisk5\DR7
23:02:53.0015 1944 \Device\Harddisk5\DR7 - ok
23:02:53.0031 1944 Boot (0x1200) (c798bd728ce08d6f512e0100988f2fbf) \Device\Harddisk0\DR0\Partition0
23:02:53.0031 1944 \Device\Harddisk0\DR0\Partition0 - ok
23:02:53.0046 1944 Boot (0x1200) (8f9670f3e54c5fd21d61cc4e06b3f4f7) \Device\Harddisk0\DR0\Partition1
23:02:53.0046 1944 \Device\Harddisk0\DR0\Partition1 - ok
23:02:53.0062 1944 Boot (0x1200) (c14cc738c2806f3c80d5725ba61e6ea1) \Device\Harddisk5\DR7\Partition0
23:02:53.0093 1944 \Device\Harddisk5\DR7\Partition0 - ok
23:02:53.0093 1944 ============================================================
23:02:53.0093 1944 Scan finished
23:02:53.0093 1944 ============================================================
23:02:53.0125 1340 Detected object count: 1
23:02:53.0125 1340 Actual detected object count: 1
23:03:30.0484 1340 sptd ( LockedFile.Multi.Generic ) - skipped by user
23:03:30.0484 1340 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
23:03:36.0765 2648 Deinitialize success

ComboFix log:


ComboFix 12-03-18.04 - Owner 19/03/2012 23:20:32.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.932.81.1033.18.511.231 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *Disabled/Updated* {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
Error: Cfiles.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\pragmamfeklnmal.dll
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe
c:\documents and settings\Owner\Local Settings\Application Data\ctgwylaw.log
c:\documents and settings\Owner\Local Settings\Application Data\jwyjrymg.log
c:\documents and settings\Owner\Local Settings\Application Data\kndwnvtd.log
c:\documents and settings\Owner\Local Settings\Application Data\lksmldww.log
c:\documents and settings\Owner\Local Settings\Application Data\odtetrgx.log
c:\documents and settings\Owner\Local Settings\Application Data\vmwnloxt.log
c:\documents and settings\Owner\Local Settings\Application Data\xfqhxncw.log
c:\documents and settings\Owner\Local Settings\Tempals_inst.exe
c:\documents and settings\Owner\My Documents\~WRL3292.tmp
c:\documents and settings\Owner\WINDOWS
c:\windows\apppatch\AppLoc.exe
c:\windows\PRAGMAmxnlprpuyc
c:\windows\PRAGMAtspwixrnsk
c:\windows\PRAGMAtspwixrnsk\pragmabbr.dll
c:\windows\PRAGMAtspwixrnsk\PRAGMAc.dll
c:\windows\PRAGMAtspwixrnsk\PRAGMAcfg.ini
c:\windows\PRAGMAtspwixrnsk\pragmaserf.dll
c:\windows\PRAGMAtspwixrnsk\PRAGMAsrcr.dat
c:\windows\PRAGMAxnqweeixui
c:\windows\PRAGMAxnqweeixui\PRAGMAc.dll
c:\windows\PRAGMAxnqweeixui\PRAGMAcfg.ini
c:\windows\PRAGMAxnqweeixui\PRAGMAsrcr.dat
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\ps2.bat
D:\Autorun.inf
G:\autorun.inf
G:\setup.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_MICORSOFT_WINDOWS_SERVICE
——-\Legacy_PRAGMAmxnlprpuyc
——-\Legacy_PRAGMATSPWIXRNSK
——-\Legacy_PRAGMAXNQWEEIXUI
——-\Legacy_SVCHOST
——-\Service_Micorsoft Windows Service
——-\Service_PRAGMAmxnlprpuyc
——-\Service_PRAGMAtspwixrnsk
——-\Service_PRAGMAxnqweeixui
.
.
((((((((((((((((((((((((( Files Created from 2012-02-19 to 2012-03-19 )))))))))))))))))))))))))))))))
.
.
2012-03-18 00:32 . 2012-03-18 00:32 ——– d—–w- c:\program files\Norton AntiVirus
2012-03-18 00:11 . 2012-03-18 00:11 717296 —-a-w- c:\windows\system32\drivers\sptd.sys
2012-03-17 23:55 . 2012-03-18 00:43 111808 —ha-w- c:\windows\system32\ohNIy23
2012-03-17 16:36 . 2012-03-17 16:36 139264 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2012-03-17 16:36 . 2012-03-17 16:36 139264 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2012-03-15 15:28 . 2012-03-15 15:28 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2012-03-15 15:28 . 2012-03-15 15:28 ——– d—–w- c:\program files\IObit
2012-03-15 02:13 . 2012-03-19 23:40 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\alsdfqln
2012-03-15 01:46 . 2012-03-15 01:46 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\FLVService
2012-03-10 02:18 . 2012-03-10 02:18 ——– d—–w- c:\documents and settings\Owner\Application Data\sol-fa-soft
2012-03-10 01:40 . 2012-03-10 01:40 ——– d—–w- c:\documents and settings\Owner\.swt
2012-02-26 17:07 . 2012-02-27 01:00 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Smogon
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-18 02:43 . 2012-02-18 02:43 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-16 22:46 . 2012-02-16 22:46 5205 —-a-w- C:\fs_3_6.zip
2006-05-03 09:06 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 216064 –sh–r- c:\windows\system32\nbDX.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IsvRqwhh"="c:\documents and settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe" [2012-03-19 97364]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
isvrqwhh.exe [2012-3-15 97364]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico [2009-4-3 6144]
ZDWlan.lnk - c:\program files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.exe [2008-12-6 438272]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= firefox.exe
"2"= opera.exe
"3"= chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,,c:\documents and settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe"
.
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KYE_Showicon]
c:\program files\USB Storage RW\shwicon.exe -tKYE\USB Storage RW [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rappkill]
它| [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-16 02:58 136176 —-atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2002-10-16 13:05 114688 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IsvRqwhh]
2012-03-19 23:40 97364 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\alsdfqln\isvrqwhh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2001-07-07 03:56 159744 —-a-w- c:\hp\KBD\kbd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-25 04:20 126976 —-a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 12:22 1622016 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-09-24 21:19 2969496 —-a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-10-16 22:57 81920 —-a-w- c:\windows\system32\ps2.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 04:42 212992 —-a-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sophos AutoUpdate Monitor]
2010-09-21 15:16 439536 —-a-w- c:\program files\Sophos\AutoUpdate\ALMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2002-06-18 14:01 253952 —-a-w- c:\program files\VERITAS Software\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 12:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2011-08-25 11:13 2816328 —-a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WCOLOREAL]
2002-11-27 00:14 233472 —-a-w- c:\program files\Coloreal\COLOREAL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"swi_service"=2 (0x2)
"Sophos AutoUpdate Service"=3 (0x3)
"SAVService"=3 (0x3)
"SAVAdminService"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"CVPND"=2 (0x2)
"CiscoVpnInstallService"=2 (0x2)
"dmadmin"=3 (0x3)
"IMFservice"=2 (0x2)
"Giraffic"=2 (0x2)
"NVSvc"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Magic Workstation\\MWSPlay.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PLauncher.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=
"c:\\Team17\\Worms2\\frontend.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\Stuff from Uncle Peter\\Emulator\\NESTCL95.EXE"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Giraffic\\Veoh_Giraffic.exe"=
"c:\\Program Files\\Giraffic\\Veoh_GirafficWatchdog.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"55555:TCP"= 55555:TCP:az
"57080:TCP"= 57080:TCP:Pando Media Booster
"57080:UDP"= 57080:UDP:Pando Media Booster
"55000:TCP"= 55000:TCP:Testmule
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/06/2010 21:49 64288]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18/03/2012 00:11 717296]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [19/11/2008 17:46 153344]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [19/11/2008 17:46 24064]
R3 FStarForce;FStarForce;c:\windows\system32\drivers\FStarForce.sys [13/07/2009 20:57 9216]
R3 SUPERWEBCAM;SuperWebcam, WDM Virtual Video Capture Device;c:\windows\system32\drivers\superwebcam.sys [03/07/2010 03:48 31872]
R3 WLAN(WLAN);XPC 802.11b/g Wireless Kit Driver(WLAN);c:\windows\system32\drivers\ZD1211U.sys [06/12/2008 14:26 278016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [13/02/2003 00:55 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;c:\windows\system32\ZDBRGSYS.sys [06/12/2008 14:26 19200]
S4 Giraffic;Veoh Giraffic Video Accelerator;c:\program files\Giraffic\Veoh_GirafficWatchdog.exe –service –> c:\program files\Giraffic\Veoh_GirafficWatchdog.exe –service [?]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [17/07/2009 16:03 133104]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [17/07/2009 16:03 133104]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 15:52 1352832]
S4 onyfwev;onyfwev;c:\windows\system32\drivers\ocltoijp.sys [15/06/2010 19:49 54016]
S4 SASDIFSV;SASDIFSV;\??\c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S4 SASKUTIL;SASKUTIL;\??\c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS –> c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S4 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [08/10/2010 14:15 163056]
S4 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [04/06/2010 10:23 97520]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [19/11/2008 17:46 14976]
S4 sosf;sosf;c:\windows\system32\drivers\vexl.sys [15/06/2010 19:34 54016]
S4 swi_service;Sophos Web Intelligence Service;c:\program files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [21/02/2012 11:48 1543704]
S4 yxyhfv;yxyhfv;c:\windows\system32\drivers\ulmqni.sys [15/06/2010 19:16 54016]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MICORSOFT_WINDOWS_SERVICE
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 21:50]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-17 16:03]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-17 16:03]
.
2012-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1012008372-3885175467-2977226436-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-07 02:58]
.
2012-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1012008372-3885175467-2977226436-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-07 02:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 192.168.1.254
DPF: ActiveGS.cab - hxxp://activegs.freetoolsassociation.com/ActiveGS.cab
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Google Gears: {000a9d1c-beef-4f90-9363-039d445309b8} - c:\program files\Google\Google Gears\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: Export Cookies: exportcookies@aag - %profile%\extensions\exportcookies@aag
FF - Ext: Freecorder YouTube Download Wizard: [removed] - %profile%\extensions\[removed]
FF - Ext: Fast Video Download (with SearchMenu): {c50ca3c4-5656-43c2-a061-13e717f73fc8} - %profile%\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{5C255C8A-E604-49b4-9?C - (no file)
MSConfigStartUp-IObit Malware Fighter - c:\program files\IObit\IObit Malware Fighter\IMF.exe
MSConfigStartUp-Malwarebytes Anti-Malware (rootkit-scan) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
MSConfigStartUp-wmsdk64_32 - c:\docume~1\Owner\LOCALS~1\Temp\wmsdk64_32.exe
MSConfigStartUp-{90C39418-57AC-668B-05A8-414E6CE9FF55} - c:\documents and settings\Owner\Application Data\Idmu\ohivo.exe
AddRemove-Naughty Tic Tac Toe_is1 - k:\backup\Memeo\Daniel's Backup\C_\Documents and Settings\Owner.DANIEL\My Documents\Archive\Folder\Naughty Tic Tac Toe\unins000.exe
AddRemove-{2E4BFFE6-5CCA-4568-A862-37D9FC337AB9}_is1 - c:\documents and settings\Owner\My Documents\Archive\Pokemon\hack\Tilem\unins000.exe
AddRemove-{EF53DD60-C4E2-11DB-3D6C-167690F54AE1} - c:\program files\Notation\Uninst_Notation Composer 2.6.3
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-19 23:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\windows\system32\wuaucpl.cpl.mui 15072 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\softhouse-seal\f[Wョ[ィ0・o0w0k0・P0 *^、0ッ0\0'`€bn0タ0・ク0・・;eeu^]
"Order"=hex:08,00,00,00,02,00,00,00,78,01,00,00,01,00,00,00,02,00,00,00,bc,00,
00,00,00,00,00,00,ae,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,9c,00,36,\
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\SecuROM\License information*]
"datasecu"=hex:07,7b,10,b9,38,0d,cf,97,fe,26,a7,27,27,69,3c,d9,05,3d,47,61,3e,
97,3f,8d,c2,c5,bf,c3,b4,a0,e5,31,2a,20,78,a1,bc,18,90,8e,df,53,9b,58,fe,6c,\
"rkeysecu"=hex:45,d4,e0,c3,78,f1,ab,40,a7,ad,d7,d6,d5,93,1a,74
.
———————— Other Running Processes ————————
.
c:\windows\system32\conime.exe
.
**************************************************************************
.
Completion time: 2012-03-19 23:57:35 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-19 23:57
.
Pre-Run: 3,121,037,312 bytes free
Post-Run: 4,651,986,944 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - A643DC469CB6732DDE7CF42EC9512922


An error message appeared after ComboFix rebooted the machine; it said something like "Windows No Disk Exception Processing Message c0000013 Parameters 75b6b7c 4 75b6bf7c 75b6bf7c"

I've also noticed that Windows Media Player and Media Player Classic don't work; Media Player says:

"The file wmplayer.exe has a version number of 9.0.0.3250 where 9.0.0.4503 was expected. Windows Media Player is not installed correctly and must be reinstalled. Do you want to install the Player from the Microsoft Web site?"

(I selected No.)

Media Player Classic says:

"Microsoft Visual C++ Runtime Library
Runtime Error!
Programme: C:…
R6002
-floating point support not loaded"
IMPORTANT NOTE: Having looked at your current logs, and I’m afraid you have some very bad infections on your computer, some of which are backdoor trojans, password stealers and keyloggers.

Backdoor Trojan are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information.

If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • from a clean computer, change All your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
  • consider what other private information could possibly have been taken from your computer and take appropriate steps
As I previously said, these infections can possibly be cleaned, but it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting both system partitions and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

======================================

P2P - I see you have P2P software, (emule), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

Also, you should delete Azureus from your Programs folder.

======================================

Restore Safe Mode
  • download SafeBoot.zip to your Desktop
  • click on SafeBoot.zip to open the Zip file
  • extract SafeBoot.reg also to your Desktop
  • double-click on the icon
  • you will receive a prompt similar to: "Do you wish to merge the information into the registry?": answer Yes and wait for a message to appear similar to Merged Successfully.
  • reboot your machine
======================================

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
c:\documents and settings\Owner\Start Menu\Programs\Startup\isvrqwhh.exe
C:\WINDOWS\system32\drivers\ocltoijp.sys

Folder::
c:\documents and settings\Owner\Local Settings\Application Data\alsdfqln

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IsvRqwhh"=-
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,"
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IsvRqwhh]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" =dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000

Driver::
onyfwev

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

======================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Logs to include in your next post:

ComboFix.txt
CKFiles.txt


Satchfan
Thanks again! Uninstalled eMule; not sure why I had it in the first place…

Combofix log:


ComboFix 12-03-18.04 - Owner 20/03/2012 17:48:05.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.932.81.1033.18.511.250 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Sophos Anti-Virus *Disabled/Updated* {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
FILE ::
"c:\documents and settings\Owner\Start Menu\Programs\Startup\isvrqwhh.exe"
"c:\windows\system32\drivers\ocltoijp.sys"
.
Error: Cfiles.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Owner\Local Settings\Application Data\alsdfqln
c:\documents and settings\Owner\Local Settings\Application Data\ctgwylaw.log
c:\documents and settings\Owner\Local Settings\Application Data\jwyjrymg.log
c:\documents and settings\Owner\Local Settings\Application Data\kndwnvtd.log
c:\documents and settings\Owner\Local Settings\Application Data\lksmldww.log
c:\documents and settings\Owner\Local Settings\Application Data\odtetrgx.log
c:\documents and settings\Owner\Local Settings\Application Data\vmwnloxt.log
c:\documents and settings\Owner\Local Settings\Application Data\xfqhxncw.log
c:\documents and settings\Owner\Start Menu\Programs\Startup\isvrqwhh.exe
c:\windows\system32\drivers\ocltoijp.sys
.
Infected copy of c:\windows\system32\kernel32.dll was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\kernel32.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_MICORSOFT_WINDOWS_SERVICE
——-\Legacy_ONYFWEV
——-\Service_Micorsoft Windows Service
——-\Service_onyfwev
.
.
((((((((((((((((((((((((( Files Created from 2012-02-20 to 2012-03-20 )))))))))))))))))))))))))))))))
.
.
2012-03-20 18:05 . 2012-03-20 18:05 433376 —ha-w- c:\documents and settings\Owner\gweYaDG
2012-03-19 23:42 . 2009-08-06 19:24 15072 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-03-18 00:32 . 2012-03-18 00:32 ——– d—–w- c:\program files\Norton AntiVirus
2012-03-18 00:11 . 2012-03-18 00:11 717296 —-a-w- c:\windows\system32\drivers\sptd.sys
2012-03-17 23:55 . 2012-03-18 00:43 111808 —ha-w- c:\windows\system32\ohNIy23
2012-03-17 16:36 . 2012-03-17 16:36 139264 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2012-03-17 16:36 . 2012-03-17 16:36 139264 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2012-03-15 15:28 . 2012-03-15 15:28 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2012-03-15 15:28 . 2012-03-15 15:28 ——– d—–w- c:\program files\IObit
2012-03-15 01:46 . 2012-03-15 01:46 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\FLVService
2012-03-10 02:18 . 2012-03-10 02:18 ——– d—–w- c:\documents and settings\Owner\Application Data\sol-fa-soft
2012-03-10 01:40 . 2012-03-10 01:40 ——– d—–w- c:\documents and settings\Owner\.swt
2012-02-26 17:07 . 2012-02-27 01:00 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Smogon
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-18 02:43 . 2012-02-18 02:43 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-16 22:46 . 2012-02-16 22:46 5205 —-a-w- C:\fs_3_6.zip
2006-05-03 09:06 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 216064 –sh–r- c:\windows\system32\nbDX.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-03-19_23.40.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2003-02-13 00:54 . 2009-03-21 14:18 986112 c:\windows\system32\kernel32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico [2009-4-3 6144]
ZDWlan.lnk - c:\program files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.exe [2008-12-6 540672]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= firefox.exe
"2"= opera.exe
"3"= chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KYE_Showicon]
c:\program files\USB Storage RW\shwicon.exe -tKYE\USB Storage RW [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rappkill]
它| [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-16 02:58 136176 —-atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2002-10-16 13:05 114688 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2001-07-07 03:56 159744 —-a-w- c:\hp\KBD\kbd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-25 04:20 126976 —-a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 12:22 1622016 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-09-24 21:19 2969496 —-a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-10-16 22:57 81920 —-a-w- c:\windows\system32\ps2.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 04:42 212992 —-a-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sophos AutoUpdate Monitor]
2010-09-21 15:16 439536 —-a-w- c:\program files\Sophos\AutoUpdate\ALMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2002-06-18 14:01 253952 —-a-w- c:\program files\VERITAS Software\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 12:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2011-08-25 11:13 2816328 —-a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WCOLOREAL]
2002-11-27 00:14 233472 —-a-w- c:\program files\Coloreal\COLOREAL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"swi_service"=2 (0x2)
"Sophos AutoUpdate Service"=3 (0x3)
"SAVService"=3 (0x3)
"SAVAdminService"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"CVPND"=2 (0x2)
"CiscoVpnInstallService"=2 (0x2)
"dmadmin"=3 (0x3)
"IMFservice"=2 (0x2)
"Giraffic"=2 (0x2)
"NVSvc"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Magic Workstation\\MWSPlay.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PLauncher.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=
"c:\\Team17\\Worms2\\frontend.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\Stuff from Uncle Peter\\Emulator\\NESTCL95.EXE"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Giraffic\\Veoh_Giraffic.exe"=
"c:\\Program Files\\Giraffic\\Veoh_GirafficWatchdog.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"55555:TCP"= 55555:TCP:az
"57080:TCP"= 57080:TCP:Pando Media Booster
"57080:UDP"= 57080:UDP:Pando Media Booster
"55000:TCP"= 55000:TCP:Testmule
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/06/2010 21:49 64288]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18/03/2012 00:11 717296]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [19/11/2008 17:46 153344]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [19/11/2008 17:46 24064]
R3 FStarForce;FStarForce;c:\windows\system32\drivers\FStarForce.sys [13/07/2009 20:57 9216]
R3 SUPERWEBCAM;SuperWebcam, WDM Virtual Video Capture Device;c:\windows\system32\drivers\superwebcam.sys [03/07/2010 03:48 31872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [13/02/2003 00:55 14336]
S3 WLAN(WLAN);XPC 802.11b/g Wireless Kit Driver(WLAN);c:\windows\system32\drivers\ZD1211U.sys [06/12/2008 14:26 278016]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;c:\windows\system32\ZDBRGSYS.sys [06/12/2008 14:26 19200]
S4 Giraffic;Veoh Giraffic Video Accelerator;c:\program files\Giraffic\Veoh_GirafficWatchdog.exe –service –> c:\program files\Giraffic\Veoh_GirafficWatchdog.exe –service [?]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [17/07/2009 16:03 133104]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [17/07/2009 16:03 133104]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 15:52 1352832]
S4 SASDIFSV;SASDIFSV;\??\c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S4 SASKUTIL;SASKUTIL;\??\c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS –> c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S4 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [08/10/2010 14:15 163056]
S4 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [04/06/2010 10:23 97520]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [19/11/2008 17:46 14976]
S4 sosf;sosf;c:\windows\system32\drivers\vexl.sys [15/06/2010 19:34 54016]
S4 swi_service;Sophos Web Intelligence Service;c:\program files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [21/02/2012 11:48 1543704]
S4 yxyhfv;yxyhfv;c:\windows\system32\drivers\ulmqni.sys [15/06/2010 19:16 54016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 21:50]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-17 16:03]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-17 16:03]
.
2012-03-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1012008372-3885175467-2977226436-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-07 02:58]
.
2012-03-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1012008372-3885175467-2977226436-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-07 02:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 192.168.1.254
DPF: ActiveGS.cab - hxxp://activegs.freetoolsassociation.com/ActiveGS.cab
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Google Gears: {000a9d1c-beef-4f90-9363-039d445309b8} - c:\program files\Google\Google Gears\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: Export Cookies: exportcookies@aag - %profile%\extensions\exportcookies@aag
FF - Ext: Freecorder YouTube Download Wizard: [removed] - %profile%\extensions\[removed]
FF - Ext: Fast Video Download (with SearchMenu): {c50ca3c4-5656-43c2-a061-13e717f73fc8} - %profile%\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{5C255C8A-E604-49b4-9?C - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-20 18:06
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\softhouse-seal\f[Wョ[ィ0・o0w0k0・P0 *^、0ッ0\0'`€bn0タ0・ク0・・;eeu^]
"Order"=hex:08,00,00,00,02,00,00,00,78,01,00,00,01,00,00,00,02,00,00,00,bc,00,
00,00,00,00,00,00,ae,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,9c,00,36,\
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\SecuROM\License information*]
"datasecu"=hex:07,7b,10,b9,38,0d,cf,97,fe,26,a7,27,27,69,3c,d9,05,3d,47,61,3e,
97,3f,8d,c2,c5,bf,c3,b4,a0,e5,31,2a,20,78,a1,bc,18,90,8e,df,53,9b,58,fe,6c,\
"rkeysecu"=hex:45,d4,e0,c3,78,f1,ab,40,a7,ad,d7,d6,d5,93,1a,74
.
———————— Other Running Processes ————————
.
c:\windows\system32\conime.exe
.
**************************************************************************
.
Completion time: 2012-03-20 18:13:40 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-20 18:13
ComboFix2.txt 2012-03-19 23:57
.
Pre-Run: 1,461,964,800 bytes free
Post-Run: 1,452,773,376 bytes free
.
- - End Of File - - 47F0DCF3073545C1163426597A358007

CKFiles:[./b]


CKScanner - Additional Security Risks - These are not necessarily bad
c:\documents and settings\owner\application data\azureus\torrents\bonetown_crack.4862748.tpb.torrent
c:\documents and settings\owner\application data\macromedia\flash player\macromedia.com\support\flashplayer\sys\#crackle.com\settings.sol
c:\documents and settings\owner\logs\pikachuoncrack vs showsni–04 november 2011 at 00h35.html
c:\ijji\english\lunia\display\effect\boss\qillin\crack\bronzedustap.xml
c:\ijji\english\lunia\display\effect\boss\qillin\crack\keepercrack.xml
c:\ijji\english\lunia\display\effect\boss\qillin\crack\keeperlock.xml
c:\ijji\english\lunia\display\effect\firecracker\a_type.xml
c:\ijji\english\lunia\display\effect\firecracker\b_type.xml
c:\ijji\english\lunia\display\effect\firecracker\c_type.xml
c:\ijji\english\lunia\display\effect\particles\firecrack01.xml
c:\ijji\english\lunia\display\effect\particles\firecrack02.xml
c:\ijji\english\lunia\display\effect\particles\firecrack03.xml
c:\ijji\english\lunia\display\effect\particles\firecrack04.xml
c:\ijji\english\lunia\display\effect\particles\firecrack05.xml
c:\ijji\english\lunia\display\effect\particles\firecrack06.xml
c:\ijji\english\lunia\display\effect\particles\firecrack07.xml
c:\ijji\english\lunia\display\effect\particles\firecrack08.xml
c:\ijji\english\lunia\display\effect\particles\firecrack09.xml
c:\ijji\english\lunia\display\effect\particles\firecrack10.xml
c:\ijji\english\lunia\display\effect\particles\firecrack11.xml
c:\ijji\english\lunia\display\effect\particles\firecrack12.xml
c:\ijji\english\lunia\display\effect\particles\firecrack13.xml
c:\ijji\english\lunia\display\effect\polygons\keepercrack.material.xml
c:\ijji\english\lunia\display\effect\polygons\keepercrack_clip1.animation
c:\ijji\english\lunia\display\effect\polygons\keepercrack_polysurfaceshape1.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_polysurfaceshape3.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_polysurfaceshape6.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape1.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape10.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape11.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape12.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape13.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape14.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape15.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape16.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape18.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape19.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape2.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape3.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape4.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape5.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape6.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape7.mesh
c:\ijji\english\lunia\display\effect\polygons\keepercrack_shardshape9.mesh
c:\ijji\english\lunia\mapping\fallingcrackcrag.dds
c:\ijji\english\lunia\mapping\fallingcrackcrag_raid.dds
c:\ijji\english\lunia\mapping\fallingcrackcrag_raid2.dds
c:\ijji\english\lunia\sounds\ambience\myth_treecrack.ogg
scanner sequence 3.ZZ.11.JEAPVS
—– EOF —–

Additionally, when rebooting after the Combofix I received an error message that my Wireless Adaptor software (I think it's called ZDWLan.exe) was unable to start properly, and to terminate the application. I set up the Windows Network Connections to manage it instead.
That’s looking a bit better but I’m a bit concerned that different malware has appeared so we’ll get rid of that first and take it from there.

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
c:\documents and settings\Owner\gweYaDG
c:\windows\system32\ohNIy23
c:\windows\system32\drivers\ulmqni.sys

Registry::
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"=-
"2"=-
"3"=-

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000

Driver::
yxyhfv

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

Can you also tell me how things are running now.

Satchfan
Combofix log:


ComboFix 12-03-18.04 - Owner 21/03/2012 16:25:03.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.932.81.1033.18.511.264 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Sophos Anti-Virus *Disabled/Updated* {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
FILE ::
"c:\documents and settings\Owner\gweYaDG"
"c:\windows\system32\drivers\ulmqni.sys"
"c:\windows\system32\ohNIy23"
.
Error: Cfiles.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Owner\gweYaDG
c:\windows\system32\drivers\ulmqni.sys
c:\windows\system32\ohNIy23
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_YXYHFV
——-\Service_yxyhfv
.
.
((((((((((((((((((((((((( Files Created from 2012-02-21 to 2012-03-21 )))))))))))))))))))))))))))))))
.
.
2012-03-19 23:42 . 2009-08-06 19:24 15072 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-03-18 00:32 . 2012-03-18 00:32 ——– d—–w- c:\program files\Norton AntiVirus
2012-03-18 00:11 . 2012-03-18 00:11 717296 —-a-w- c:\windows\system32\drivers\sptd.sys
2012-03-17 16:36 . 2012-03-17 16:36 139264 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2012-03-17 16:36 . 2012-03-17 16:36 139264 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2012-03-15 15:28 . 2012-03-15 15:28 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2012-03-15 15:28 . 2012-03-15 15:28 ——– d—–w- c:\program files\IObit
2012-03-15 01:46 . 2012-03-15 01:46 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\FLVService
2012-03-10 02:18 . 2012-03-10 02:18 ——– d—–w- c:\documents and settings\Owner\Application Data\sol-fa-soft
2012-03-10 01:40 . 2012-03-10 01:40 ——– d—–w- c:\documents and settings\Owner\.swt
2012-02-26 17:07 . 2012-02-27 01:00 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Smogon
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-18 02:43 . 2012-02-18 02:43 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-16 22:46 . 2012-02-16 22:46 5205 —-a-w- C:\fs_3_6.zip
2006-05-03 09:06 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 216064 –sh–r- c:\windows\system32\nbDX.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-03-19_23.40.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2003-02-13 00:54 . 2009-03-21 14:18 986112 c:\windows\system32\kernel32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico [2009-4-3 6144]
ZDWlan.lnk - c:\program files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.exe [2008-12-6 540672]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KYE_Showicon]
c:\program files\USB Storage RW\shwicon.exe -tKYE\USB Storage RW [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rappkill]
它| [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-16 02:58 136176 —-atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2002-10-16 13:05 114688 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2001-07-07 03:56 159744 —-a-w- c:\hp\KBD\kbd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-25 04:20 126976 —-a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 12:22 1622016 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-09-24 21:19 2969496 —-a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-10-16 22:57 81920 —-a-w- c:\windows\system32\ps2.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 04:42 212992 —-a-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sophos AutoUpdate Monitor]
2010-09-21 15:16 439536 —-a-w- c:\program files\Sophos\AutoUpdate\ALMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2002-06-18 14:01 253952 —-a-w- c:\program files\VERITAS Software\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 12:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2011-08-25 11:13 2816328 —-a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WCOLOREAL]
2002-11-27 00:14 233472 —-a-w- c:\program files\Coloreal\COLOREAL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"swi_service"=2 (0x2)
"Sophos AutoUpdate Service"=3 (0x3)
"SAVService"=3 (0x3)
"SAVAdminService"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"CVPND"=2 (0x2)
"CiscoVpnInstallService"=2 (0x2)
"dmadmin"=3 (0x3)
"IMFservice"=2 (0x2)
"Giraffic"=2 (0x2)
"NVSvc"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Magic Workstation\\MWSPlay.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PLauncher.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=
"c:\\Team17\\Worms2\\frontend.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\Stuff from Uncle Peter\\Emulator\\NESTCL95.EXE"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Giraffic\\Veoh_Giraffic.exe"=
"c:\\Program Files\\Giraffic\\Veoh_GirafficWatchdog.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"55555:TCP"= 55555:TCP:az
"57080:TCP"= 57080:TCP:Pando Media Booster
"57080:UDP"= 57080:UDP:Pando Media Booster
"55000:TCP"= 55000:TCP:Testmule
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/06/2010 21:49 64288]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18/03/2012 00:11 717296]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [19/11/2008 17:46 153344]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [19/11/2008 17:46 24064]
R3 FStarForce;FStarForce;c:\windows\system32\drivers\FStarForce.sys [13/07/2009 20:57 9216]
R3 SUPERWEBCAM;SuperWebcam, WDM Virtual Video Capture Device;c:\windows\system32\drivers\superwebcam.sys [03/07/2010 03:48 31872]
R3 WLAN(WLAN);XPC 802.11b/g Wireless Kit Driver(WLAN);c:\windows\system32\drivers\ZD1211U.sys [06/12/2008 14:26 278016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [13/02/2003 00:55 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;c:\windows\system32\ZDBRGSYS.sys [06/12/2008 14:26 19200]
S4 Giraffic;Veoh Giraffic Video Accelerator;c:\program files\Giraffic\Veoh_GirafficWatchdog.exe –service –> c:\program files\Giraffic\Veoh_GirafficWatchdog.exe –service [?]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [17/07/2009 16:03 133104]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [17/07/2009 16:03 133104]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 15:52 1352832]
S4 SASDIFSV;SASDIFSV;\??\c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S4 SASKUTIL;SASKUTIL;\??\c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS –> c:\docume~1\Owner\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S4 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [08/10/2010 14:15 163056]
S4 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [04/06/2010 10:23 97520]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [19/11/2008 17:46 14976]
S4 sosf;sosf;c:\windows\system32\drivers\vexl.sys [15/06/2010 19:34 54016]
S4 swi_service;Sophos Web Intelligence Service;c:\program files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [21/02/2012 11:48 1543704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-20 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 21:50]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-17 16:03]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-17 16:03]
.
2012-03-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1012008372-3885175467-2977226436-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-07 02:58]
.
2012-03-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1012008372-3885175467-2977226436-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-07 02:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 192.168.22.22 192.168.22.23
DPF: ActiveGS.cab - hxxp://activegs.freetoolsassociation.com/ActiveGS.cab
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\361vwpjh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Google Gears: {000a9d1c-beef-4f90-9363-039d445309b8} - c:\program files\Google\Google Gears\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: Export Cookies: exportcookies@aag - %profile%\extensions\exportcookies@aag
FF - Ext: Freecorder YouTube Download Wizard: [removed] - %profile%\extensions\[removed]
FF - Ext: Fast Video Download (with SearchMenu): {c50ca3c4-5656-43c2-a061-13e717f73fc8} - %profile%\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{5C255C8A-E604-49b4-9?C - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-21 16:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\softhouse-seal\f[Wョ[ィ0・o0w0k0・P0 *^、0ッ0\0'`€bn0タ0・ク0・・;eeu^]
"Order"=hex:08,00,00,00,02,00,00,00,78,01,00,00,01,00,00,00,02,00,00,00,bc,00,
00,00,00,00,00,00,ae,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,9c,00,36,\
.
[HKEY_USERS\S-1-5-21-1012008372-3885175467-2977226436-1003\Software\SecuROM\License information*]
"datasecu"=hex:07,7b,10,b9,38,0d,cf,97,fe,26,a7,27,27,69,3c,d9,05,3d,47,61,3e,
97,3f,8d,c2,c5,bf,c3,b4,a0,e5,31,2a,20,78,a1,bc,18,90,8e,df,53,9b,58,fe,6c,\
"rkeysecu"=hex:45,d4,e0,c3,78,f1,ab,40,a7,ad,d7,d6,d5,93,1a,74
.
———————— Other Running Processes ————————
.
c:\windows\system32\conime.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-03-21 16:50:01 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-21 16:49
ComboFix2.txt 2012-03-20 18:13
ComboFix3.txt 2012-03-19 23:57
.
Pre-Run: 1,531,469,824 bytes free
Post-Run: 1,519,116,288 bytes free
.
- - End Of File - - 95D9D230150C09DE00F9E8E32ECF9B79


I can now visit microsoft.com and other websites (bleepingcomputer, symantec, etc) that were previously blocked without a problem. Many programmes are giving an error message when attempting to use them, though - most are giving a box that says

(Programme name) - Application Error

The application failed to initialize properly. (0xc0000005). Click on OK to terminate the application.

This occurs with, for instance, Microsoft Works Spreadsheet, Pokemon Online, Theme Hospital, Atlas, Microsoft Picture It! Photo 7.0, ZDWLan, etc.

Some other programmes give a "Progamme name has encountered a problem and needs to close. We are sorry for the inconvenience." as soon as I try to open them. This occurs with, for instance, Microsoft Encarta, Microsoft Word, Media Player Classic, etc.

Some things work fine - Microsoft Hearts, Notepad, Sound Recorder, Google Chrome, etc. Sophos also seems to open okay now.
Download Dr.Web CureIt to the desktop:
  • doubleclick the drweb-cureit icon to start the program
  • press start
  • allow the program to run the initial express scan
  • this will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan.
Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
  • once the scan is complete, the results will be displayed
  • If infections are found you will be able to save a report
  • on the menu bar, click file and choose report list.
  • save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum
  • close Dr.Web Cureit
  • please post the Dr.Web.txt report in your next reply
Satchfan
DrWeb Report:


Aoishiro_eng.exe;C:\Documents and Settings\Owner\My Documents\aoishiro_pc_eng_patch\aoishiro_pc_eng;Trojan.Rmnet.1;Deleted.;
AoUtil_eng.exe;C:\Documents and Settings\Owner\My Documents\aoishiro_pc_eng_patch\aoishiro_pc_eng;Trojan.Rmnet.1;Deleted.;
PokePic.exe;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Elite Map v3.7a\EliteMap;Trojan.Rmnet.1;Deleted.;
unLZ.GBA.exe;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Elite Map v3.7a\EliteMap;Trojan.Rmnet.1;Deleted.;
PokePic.exe;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\EliteMap;Trojan.Rmnet.1;Deleted.;
msvcm90.dll;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
python26.dll;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
tilem.exe;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
w9xpopen.exe;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
wxbase28uh_net_vc.dll;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
wxbase28uh_vc.dll;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
wxmsw28uh_adv_vc.dll;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
wxmsw28uh_core_vc.dll;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
wxmsw28uh_html_vc.dll;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\junk\Tilem;Trojan.Rmnet.1;Deleted.;
mid2agb.exe;C:\Documents and Settings\Owner\My Documents\Archive\Pokemon\hack\Midi2GBA;Trojan.Rmnet.1;Deleted.;
Dwarf Fortress.exe;C:\Documents and Settings\Owner\My Documents\df_31_12_win;Trojan.Rmnet.1;Deleted.;
libtiff-3.dll;C:\Documents and Settings\Owner\My Documents\df_31_12_win;Trojan.Rmnet.1;Deleted.;
msvcm80.dll;C:\Documents and Settings\Owner\My Documents\df_31_12_win;Trojan.Rmnet.1;Deleted.;
msvcm90.dll;C:\Documents and Settings\Owner\My Documents\df_31_12_win;Trojan.Rmnet.1;Deleted.;
msvcp80.dll;C:\Documents and Settings\Owner\My Documents\df_31_12_win;Trojan.Rmnet.1;Deleted.;
msvcr80.dll;C:\Documents and Settings\Owner\My Documents\df_31_12_win;Trojan.Rmnet.1;Deleted.;
msvcrt.dll;C:\Documents and Settings\Owner\My Documents\df_31_12_win;Trojan.Rmnet.1;Deleted.;
SDL.dll;C:\Documents and Settings\Owner\My Documents\df_31_12_win;Trojan.Rmnet.1;Deleted.;
DW.exe;C:\Documents and Settings\Owner\My Documents\Downloads;Trojan.Rmnet.1;Deleted.;
audiere.dll;C:\Documents and Settings\Owner\My Documents\eversion;Trojan.Rmnet.1;Deleted.;
eversion.exe;C:\Documents and Settings\Owner\My Documents\eversion;Trojan.Rmnet.1;Deleted.;
SDL.dll;C:\Documents and Settings\Owner\My Documents\eversion;Trojan.Rmnet.1;Deleted.;
scite.exe;C:\Documents and Settings\Owner\My Documents\Flash\renpy-5.6.4-full\renpy-6.3.1-full\renpy-6.6.2-full\editor;Trojan.Rmnet.1;Deleted.;
glfw.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-5.6.4-full\renpy-6.3.1-full\renpy-6.6.2-full\MorningStarZwei120;Trojan.Rmnet.1;Deleted.;
OpenAL32.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-5.6.4-full\renpy-6.3.1-full\renpy-6.6.2-full\MorningStarZwei120;Trojan.Rmnet.1;Deleted.;
wrap_oal.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-5.6.4-full\renpy-6.3.1-full\renpy-6.6.2-full\MorningStarZwei120;Trojan.Rmnet.1;Deleted.;
csgl.native.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-5.6.4-full\renpy-6.3.1-full\renpy-6.6.2-full\MorningStar_Release9\Morn;Trojan.Rmnet.1;Deleted.;
Game.exe;C:\Documents and Settings\Owner\My Documents\Flash\renpy-5.6.4-full\renpy-6.3.1-full\renpy-6.6.2-full\RpgM[1].org_Idolcraft\Ido;Trojan.Rmnet.1;Deleted.;
console.exe;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.0;Trojan.Rmnet.1;Deleted.;
python26.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.0;Trojan.Rmnet.1;Deleted.;
renpy.exe;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.0;Trojan.Rmnet.1;Deleted.;
console.exe;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.2;Trojan.Rmnet.1;Deleted.;
python26.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.2;Trojan.Rmnet.1;Deleted.;
renpy.exe;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.2;Trojan.Rmnet.1;Deleted.;
avcodec-52.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.2\lib\windows-x86;Trojan.Rmnet.1;Deleted.;
avformat-52.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.2\lib\windows-x86;Trojan.Rmnet.1;Deleted.;
avutil-50.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.2\lib\windows-x86;Trojan.Rmnet.1;Deleted.;
swscale-0.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.11.2\lib\windows-x86;Trojan.Rmnet.1;Deleted.;
charaex.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.9.3\AnimeGen\AnimeGen;Trojan.Rmnet.1;Deleted.;
imgctl.dll;C:\Documents and Settings\Owner\My Documents\Flash\renpy-6.9.3\AnimeGen\AnimeGen;Trojan.Rmnet.1;Deleted.;
notepad++.exe;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi;Trojan.Rmnet.1;Deleted.;
SciLexer.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi;Trojan.Rmnet.1;Deleted.;
ComparePlugin.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi\plugins;Trojan.Rmnet.1;Deleted.;
LightExplorer.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi\plugins;Trojan.Rmnet.1;Deleted.;
mimeToolsA.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi\plugins;Trojan.Rmnet.1;Deleted.;
NppExec.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi\plugins;Trojan.Rmnet.1;Deleted.;
NppTextFXA.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi\plugins;Trojan.Rmnet.1;Deleted.;
PluginManager.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi\plugins;Trojan.Rmnet.1;Deleted.;
SpellChecker.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi\plugins;Trojan.Rmnet.1;Deleted.;
gpup.exe;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\ansi\updater;Trojan.Rmnet.1;Deleted.;
notepad++.exe;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\unicode;Trojan.Rmnet.1;Deleted.;
SciLexer.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\unicode;Trojan.Rmnet.1;Deleted.;
ComparePlugin.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\unicode\plugins;Trojan.Rmnet.1;Deleted.;
mimeTools.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\unicode\plugins;Trojan.Rmnet.1;Deleted.;
NppTextFX.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\unicode\plugins;Trojan.Rmnet.1;Deleted.;
PluginManager.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\unicode\plugins;Trojan.Rmnet.1;Deleted.;
SpellChecker.dll;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\unicode\plugins;Trojan.Rmnet.1;Deleted.;
gpup.exe;C:\Documents and Settings\Owner\My Documents\npp.5.6.8.bin\unicode\updater;Trojan.Rmnet.1;Deleted.;
PokeRNGDP.exe;C:\Documents and Settings\Owner\My Documents\RNGReporter_710;Trojan.Rmnet.1;Deleted.;
AutoRun.exe;C:\Documents and Settings\Owner\My Documents\RPGMakerVX1.02\RPGMakerVX1.02;Trojan.Rmnet.1;Deleted.;
Game.exe;C:\Documents and Settings\Owner\My Documents\RPGMakerVX1.02\RPGMakerVX1.02\Extra\SampleMap;Trojan.Rmnet.1;Deleted.;
Game.exe;C:\Documents and Settings\Owner\My Documents\RPGVX\Fairy Tales;Trojan.Rmnet.1;Deleted.;
Process.exe;C:\Documents and Settings\Owner\My Documents\SmitfraudFix;Trojan.Rmnet.1;Deleted.;
restart.exe;C:\Documents and Settings\Owner\My Documents\SmitfraudFix;Tool.ShutDown.14;;
mame.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter;Trojan.Rmnet.1;Deleted.;
SPIDER.EXE;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter;Trojan.Rmnet.1;Deleted.;
winterm.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\cdiemu-0.5.2;Trojan.Rmnet.1;Deleted.;
NESTCL95.EXE;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\Emulator;Trojan.Rmnet.1;Deleted.;
fceu.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\fceu-0.98.12.win;Trojan.Rmnet.1;Deleted.;
7zxa.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\Nestopia139bin;Trojan.Rmnet.1;Deleted.;
nestopia.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\Nestopia139bin;Trojan.Rmnet.1;Deleted.;
wcdiemu.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\Philips CD-I\Philips CD-I\cd-i emu 0.5.2 full;Trojan.Rmnet.1;Deleted.;
winterm.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\Philips CD-I\Philips CD-I\cd-i emu 0.5.2 full;Trojan.Rmnet.1;Deleted.;
msvcp71.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\satourne_beta_3_update\satourne release;Trojan.Rmnet.1;Deleted.;
msvcp71d.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\satourne_beta_3_update\satourne release;Trojan.Rmnet.1;Deleted.;
msvcr71.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\satourne_beta_3_update\satourne release;Trojan.Rmnet.1;Deleted.;
msvcr71d.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\satourne_beta_3_update\satourne release;Trojan.Rmnet.1;Deleted.;
satourne_3_win32.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\satourne_beta_3_update\satourne release;Trojan.Rmnet.1;Deleted.;
Snes9XW.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\snes\SNES\SNES9x;Trojan.Rmnet.1;Deleted.;
SSF.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\SSF_010_beta_Type2\SSF_010_beta_Type2;Trojan.Rmnet.1;Deleted.;
SSFV_Encoder.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\SSF_010_beta_Type2\SSF_010_beta_Type2;Trojan.Rmnet.1;Deleted.;
ZIP_Decoder.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\SSF_010_beta_Type2\SSF_010_beta_Type2;Trojan.Rmnet.1;Deleted.;
SSF.exe;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\SSF_010_prototype\SSF_010_prototype;Trojan.Rmnet.1;Deleted.;
ZIP_Decoder.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\SSF_010_prototype\SSF_010_prototype;Trojan.Rmnet.1;Deleted.;
glut32.dll;C:\Documents and Settings\Owner\My Documents\Stuff from Uncle Peter\yabause-0.9.10-win;Trojan.Rmnet.1;Deleted.;
agth.exe;C:\;Trojan.Rmnet.1;Deleted.;
ff_vfw.dll;c:\program files\combined community codec pack\filters\ffdshow;Trojan.Rmnet.1;Deleted.;
msitss.dll;c:\program files\common files\microsoft shared\information retrieval;Trojan.Rmnet.1;Deleted.;
msonsext.dll;c:\program files\common files\microsoft shared\web folders;Trojan.Rmnet.1;Deleted.;
gears.dll;c:\program files\google\google gears\internet explorer\0.5.36.0;Trojan.Rmnet.1;Deleted.;
npdocbox.dll;c:\program files\internet explorer\plugins;Trojan.Rmnet.1;Deleted.;
msmsgs.exe;c:\program files\messenger;Trojan.Rmnet.1;Deleted.;
launchpad.dll;c:\program files\vdmsound;Trojan.Rmnet.1;Deleted.;
Unfortunately, the scan confirms what I had feared, the presence of a serious viral infection known as Ramnit. Although the scan shows infections as being "deleted", this infection will not go away which is what I feared when we cleaned the malware and more appeared.

At this time Ramnit can not be cleaned and the only option is a reformat, not just a windows repair install

Infection information
.

Win32/Ramnit is a file infector which infects .exe, and .HTML/HTM files, and opens a back door that compromises your computer. Using this backdoor, a remote attacker can access and instruct the infected computer to download and execute more malicious files.

The malware injects code in legitimate files similar to the Virut virus and in many cases the infected files, (which could number in the thousands), cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files often become corrupted and the system may become unstable or irreparable. The longer Ramnit. remains on a computer, the more files it infects and corrupts so the degree of infection can vary. Further, your machine has likely been compromised by the backdoor Trojan and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if your anti-virus reports that the malware appears to have been removed.

Right now, the best thing you can do is to backup all your important data, documents, pictures, movies, and songs, preferably to CD, then reformat and reinstall Windows.

DO NOT backup any applications or installers and DO NOT backup any files with the following extensions:

* .exe
* .scr
* .htm
* .html
* .xml
* .zip
* .rar


If you need information on how to carry out a format and reinstall, please see here

==================================================

Firewall

You had no firewall on your computer. Even if you had enabled Windows firewall, on an XP system this is not adequate.

I suggest you install a more robust third party firewall that filters both incoming and outgoing traffic.

Download and install one of the following freeware firewalls from below:

Sygate Personal Firewall Free Edition:
Zone Alarm Free:
Comodo Personal Firewall:

NOTE only install one firewall. Having more than one could cause many programs to stop working altogether. Also, the firewalls may get in each others' way and cause some security holes that would not be there with just one firewall.

==================================================

Internet Explorer

You have IE6 on your computer at present which is also a security risk. I suggest you get the most recent version when you have re-installed Windows.


I'm sorry we didn't have a better outcome here. Please let me know if you have any more questions. If I don't hear from you, I'll close this thread.

Regards

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI