This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer initiating comunications on its own [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Priority—Time————————————–Message
[INFO]—-Mon May 21 14:18:16 2012——Blocked outgoing ICMP packet (ICMP type 3) from 192.168.200.3 to [removed]
[INFO]—-Mon May 21 14:18:16 2012——Blocked outgoing ICMP packet (ICMP type 3) from 192.168.200.3 to [removed]
[INFO]—-Mon May 21 14:18:14 2012——Blocked outgoing ICMP packet (ICMP type 3) from 192.168.200.3 to [removed]
[INFO]—-Mon May 21 14:18:04 2012——Above message repeated 3 times
[INFO]—-Mon May 21 14:18:04 2012——Blocked outgoing ICMP packet (ICMP type 3) from 192.168.200.3 to [removed]
[INFO]—-Mon May 21 14:15:48 2012——Blocked outgoing ICMP packet (ICMP type 3) from 192.168.200.3 to [removed]
[INFO]—-Mon May 21 14:15:46 2012——Above message repeated 1 times
[INFO]—-Mon May 21 14:15:46 2012——Blocked outgoing ICMP packet (ICMP type 3) from 192.168.200.3 to [removed]
[INFO]—-Mon May 21 14:15:39 2012——Blocked outgoing ICMP packet (ICMP type 3) from 192.168.200.3 to [removed]
[INFO]—-Mon May 21 14:15:37 2012——Above message repeated 1 times

I connect to the router and start to look at the router's log As soon as I connect this particular computer to the net, this starts to happen. The list is huge.
If I shutdown this computer and start another computer attached to the same router, when I monitor the router's log (from this other computer) it does not happen. I think that the fact that I have my communications are well set up and I have many preventive measures in place, the malware has not been able to migrate to the other computer. I have used Malwarebytes' Anti-Malware v1.61.0.1400 and Superantispyware Pro v5.0.1150 to try detect this malware. Results were negative.

It was difficult for me to download Hijack This using Firefox because every time I tried it outputted a message telling me that because of low memory it couldn't be carried out. I downloaded it with Free Download Manager. Here are the logs you asked for:

OTL logfile created on: 5/21/2012 3:43:13 AM - Run 1
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Administrator1\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

16.00 Gb Total Physical Memory | 13.21 Gb Available Physical Memory | 82.57% Memory free
32.00 Gb Paging File | 29.33 Gb Available in Paging File | 91.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.14 Gb Total Space | 47.48 Gb Free Space | 39.85% Space Free | Partition Type: NTFS
Drive D: | 931.31 Gb Total Space | 663.33 Gb Free Space | 71.23% Space Free | Partition Type: NTFS
Drive E: | 931.31 Gb Total Space | 118.90 Gb Free Space | 12.77% Space Free | Partition Type: NTFS

Computer Name: TOWER-1 | User Name: Administrator1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Administrator1\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
PRC - C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
PRC - C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe (American Power Conversion Corporation)
PRC - C:\Program Files (x86)\Anti Tracks\AntiTracks.exe (RIGHT Utilities, Inc.)
PRC - C:\Program Files (x86)\epson\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files (x86)\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files (x86)\MRU-Blaster\scheduler.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Acronis\TrueImageHome\Common\resource.dll ()
MOD - C:\Program Files (x86)\Acronis\TrueImageHome\Common\rpc_client.dll ()
MOD - C:\Program Files (x86)\Acronis\TrueImageHome\Common\thread_pool.dll ()
MOD - C:\Program Files (x86)\SpywareGuard\sgmain.exe ()
MOD - C:\Program Files (x86)\SpywareGuard\sgbhp.exe ()
MOD - C:\Program Files (x86)\MRU-Blaster\scheduler.exe ()
MOD - C:\Windows\SysWOW64\DM15_50.bpl ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (acssrv) – C:\Program Files\Agnitum\Outpost Firewall Pro\acs.exe (Agnitum Ltd.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AMD FUEL Service) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (3DM2) – C:\Program Files\3ware\3DM2/3dm2.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (McShield) – C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeEngineService) – C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe (McAfee, Inc.)
SRV - (afcdpsrv) – C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (AcrSch2Svc) – C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (McAfeeFramework) – C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (APC UPS Service) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (ASWFilt) – C:\Windows\SysNative\Filt\ASWFilt64.dll (Agnitum Ltd.)
DRV:64bit: - (SandBox) – C:\Windows\SysNative\drivers\SandBox64.sys (Agnitum Ltd.)
DRV:64bit: - (afwcore) – C:\Windows\SysNative\drivers\afwcore.sys (Agnitum Ltd.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (AODDriver4.01) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV:64bit: - (afw) – C:\Windows\SysNative\drivers\afw.sys (Agnitum Ltd.)
DRV:64bit: - (DKRtWrt) – C:\Windows\SysNative\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (pbfilter) – C:\Program Files\PeerBlock\pbfilter.sys ()
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mfetdik) – C:\Windows\SysNative\drivers\mfetdik.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (afcdp) – C:\Windows\SysNative\drivers\afcdp.sys (Acronis)
DRV:64bit: - (tdrpman258) Acronis Try&Decide; and Restore Points filter (build 258) – C:\Windows\SysNative\drivers\tdrpm258.sys (Acronis)
DRV:64bit: - (timounter) – C:\Windows\SysNative\drivers\timntr.sys (Acronis)
DRV:64bit: - (snapman) – C:\Windows\SysNative\drivers\snapman.sys (Acronis)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (amdiox64) – C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (NmPar) – C:\Windows\SysNative\drivers\NmPar.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (nmserial) – C:\Windows\SysNative\drivers\NmSerial.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (3wareDrv) – C:\Windows\SysNative\drivers\3wareDrv.sys (AMCC)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (mf) – C:\Windows\SysNative\drivers\mf.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BioNTDrv) – C:\Program Files (x86)\Paragon Software\Migrate OS to SSD\program\biontdrv.sys (Paragon Software GmbH)
DRV - (TVICHW64) – C:\Windows\SysWOW64\drivers\TVicHW64.sys (EnTech Taiwan)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 89 45 B1 AB 54 0C CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Ask"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: {4BBDD651-70CF-4821-84F8-2B918CF89CA3}:[removed]
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3
FF - prefs.js..extensions.enabledItems: [removed]:1.1.4
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.4.1
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:10.0.0
FF - prefs.js..extensions.enabledItems: {455D905A-D37C-4643-A9E2-F6FEFAA0424A}:0.8.16
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.4.4
FF - prefs.js..extensions.enabledItems: [removed]:1.3.0
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.6.4
FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31
FF - prefs.js..extensions.enabledItems: [removed]:2.0.5
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll File not found
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/05 02:46:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/05 02:46:41 | 000,000,000 | —D | M]

[2011/01/31 02:46:19 | 000,000,000 | —D | M] (No name found) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Extensions
[2012/05/20 04:03:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions
[2012/05/19 03:03:11 | 000,000,000 | —D | M] (FlashGot) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2012/01/19 21:35:50 | 000,000,000 | —D | M] (RefControl) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}
[2012/01/11 20:43:37 | 000,000,000 | —D | M] (FEBE) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2012/05/19 03:03:11 | 000,000,000 | —D | M] (NoScript) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2012/02/28 03:48:41 | 000,000,000 | —D | M] (ReloadEvery) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2012/01/19 21:35:46 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2012/01/21 00:34:13 | 000,000,000 | —D | M] (Torbutton) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2012/01/19 21:35:46 | 000,000,000 | —D | M] (Element Hiding Helper for Adblock Plus) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\[removed]
[2012/05/18 15:14:01 | 000,000,000 | —D | M] (HTTPS-Everywhere) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\[removed]
[2012/01/11 20:43:47 | 000,000,000 | —D | M] (Redirect Cleaner) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\[removed]
[2012/02/28 03:48:43 | 000,000,000 | —D | M] (SkipScreen) – C:\Users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\extensions\SkipScreen@SkipScreen
[2012/05/05 02:46:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/09 01:52:22 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/18 23:51:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2012/02/28 01:38:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012/02/28 01:38:00 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2012/05/21 01:42:16 | 000,445,809 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 192.168.1.2 TOWER-1
O1 - Hosts: 192.168.1.3 TOWER-2
O1 - Hosts: 192.168.1.4 TOWER-3
O1 - Hosts: 192.168.1.5 TOWER-4
O1 - Hosts: 192.168.1.8 TOWER-5
O1 - Hosts: 192.168.1.9 TOWER-6
O1 - Hosts: 192.168.1.10 PS-104AD7
O1 - Hosts: 127.0.0.1 teredo.ipv6.microsoft.com
O1 - Hosts: 15303 more lines…
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files (x86)\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [OutpostFeedBack] ; "C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe" /dump:os_startup File not found
O4:64bit: - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe (Agnitum Ltd.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [WinAVAlarm] C:\Program Files\3ware\3DM2\WinAVAlarm.exe (LSI)
O4 - HKLM..\Run: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe (American Power Conversion Corporation)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\epson\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\Administrator1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PartMetBackup.lnk = C:\Program Files (x86)\Java\jre6\bin\javaw.exe (Sun Microsystems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWebServices = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoOnlinePrintsWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPublishingWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O8:64bit: - Extra context menu item: Download all with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8:64bit: - Extra context menu item: Download selected with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8:64bit: - Extra context menu item: Download video with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8:64bit: - Extra context menu item: Download with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BDF8E48F-B546-4D78-86A0-AA76366BCD6B}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EAA4334D-8B7A-4B81-AA05-7DDA353A7BB8}: NameServer = 208.67.222.222,208.67.220.220
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files (x86)\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/09/11 01:14:23 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.avis - C:\Windows\SysWow64\ff_acm.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/05/21 03:34:04 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Administrator1\Desktop\HiJackThis.exe
[2012/05/21 03:33:41 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Users\Administrator1\Desktop\OTL.exe
[2012/05/21 03:30:57 | 000,000,000 | —D | C] – C:\Downloads
[2012/05/21 01:52:52 | 000,000,000 | —D | C] – C:\Users\Administrator1\AppData\Roaming\SUPERAntiSpyware.com
[2012/05/21 01:51:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/05/21 01:51:27 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2012/05/21 01:51:27 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/05/14 20:56:17 | 000,000,000 | —D | C] – C:\Users\Administrator1\AppData\Roaming\Malwarebytes
[2012/05/14 20:55:47 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/05/12 20:36:21 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/05/12 20:36:21 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/05/12 20:36:20 | 002,311,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/05/12 20:36:20 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/05/12 20:36:19 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/05/12 20:36:19 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/05/12 20:36:19 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/05/12 20:36:19 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/05/12 20:36:18 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/05/12 20:36:18 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/05/12 20:36:18 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/05/12 20:35:38 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2012/05/12 20:35:37 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2012/05/12 20:35:36 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012/05/12 20:22:49 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2012/05/12 20:22:46 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/05/12 20:22:45 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/12 20:22:45 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe

========== Files - Modified Within 30 Days ==========

[2012/05/21 03:32:27 | 000,625,664 | —- | M] () – C:\Users\Administrator1\Desktop\dds.scr
[2012/05/21 03:30:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Administrator1\Desktop\HiJackThis.exe
[2012/05/21 03:13:05 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Administrator1\Desktop\OTL.exe
[2012/05/21 02:18:10 | 000,023,200 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/21 02:18:10 | 000,023,200 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/21 02:09:35 | 000,067,584 | —- | M] () – C:\Windows\bootstat.dat
[2012/05/21 02:09:31 | 4294,316,030 | -HS- | M] () – C:\hiberfil.sys
[2012/05/21 02:00:08 | 000,000,528 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task e281d69b-c853-4795-ab5a-20b9ceb0059c.job
[2012/05/21 01:51:38 | 000,001,847 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
[2012/05/21 01:42:16 | 000,445,809 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/05/21 01:15:41 | 000,007,608 | —- | M] () – C:\Users\Administrator1\AppData\Local\resmon.resmoncfg
[2012/05/12 20:42:10 | 000,274,320 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/09 15:41:53 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/09 15:41:51 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/05/05 02:46:48 | 000,002,002 | —- | M] () – C:\Users\Administrator1\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/05/05 02:46:48 | 000,001,978 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/28 01:50:16 | 000,445,577 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20120519-030750.backup

========== Files Created - No Company Name ==========

[2012/05/21 03:34:04 | 000,625,664 | —- | C] () – C:\Users\Administrator1\Desktop\dds.scr
[2012/05/21 01:53:24 | 000,000,528 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task e281d69b-c853-4795-ab5a-20b9ceb0059c.job
[2012/05/21 01:51:38 | 000,001,847 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
[2011/12/05 22:35:10 | 000,204,960 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2011/12/05 22:35:10 | 000,157,152 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2011/12/05 22:04:00 | 000,059,904 | —- | C] () – C:\Windows\SysWow64\OpenVideo.dll
[2011/12/05 22:03:52 | 000,054,784 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/09/12 19:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2010/08/24 02:25:49 | 000,003,406 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/06/28 05:43:46 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2010/06/28 05:43:46 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD5280DW.DAT
[2010/06/23 12:35:52 | 000,790,528 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/06/23 12:35:52 | 000,134,144 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/06/22 10:30:44 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/06/19 03:17:55 | 000,000,000 | —- | C] () – C:\Users\Administrator1\AppData\Roaming\chrtmp
[2010/06/16 19:46:01 | 000,000,091 | —- | C] () – C:\Windows\WININIT.INI
[2010/06/16 19:30:59 | 000,007,608 | —- | C] () – C:\Users\Administrator1\AppData\Local\resmon.resmoncfg
[2010/06/15 03:16:15 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat

========== LOP Check ==========

[2010/06/19 06:13:33 | 000,000,000 | —D | M] – C:\Users\Administrator1\AppData\Roaming\Acronis
[2010/07/02 02:01:53 | 000,000,000 | —D | M] – C:\Users\Administrator1\AppData\Roaming\BACS.exe
[2010/12/01 18:12:02 | 000,000,000 | —D | M] – C:\Users\Administrator1\AppData\Roaming\EPSON
[2012/05/21 03:31:52 | 000,000,000 | —D | M] – C:\Users\Administrator1\AppData\Roaming\Free Download Manager
[2010/06/18 04:35:34 | 000,000,000 | —D | M] – C:\Users\Administrator1\AppData\Roaming\PingPlotter
[2010/06/17 03:38:56 | 000,000,000 | —D | M] – C:\Users\Administrator1\AppData\Roaming\Scooter Software
[2010/06/17 02:48:34 | 000,000,000 | —D | M] – C:\Users\Administrator1\AppData\Roaming\URSoft
[2010/07/04 01:29:15 | 000,000,000 | —D | M] – C:\Users\Administrator1\AppData\Roaming\Win7codecs
[2009/07/14 01:08:49 | 000,012,856 | —- | M] () – C:\Windows\Tasks\SCHEDLGU(19).TXT
[2010/07/02 02:03:07 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU(21).TXT
[2012/03/20 20:57:50 | 000,032,626 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/05/21 02:00:08 | 000,000,528 | —- | M] () – C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e281d69b-c853-4795-ab5a-20b9ceb0059c.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/06/18 05:48:03 | 000,357,376 | —- | M] () – C:\7da61253031530.bup
[2010/06/18 07:02:36 | 000,357,376 | —- | M] () – C:\7da61272243870.bup
[2010/06/20 22:43:37 | 000,095,744 | —- | M] () – C:\7da614162b2524d0.bup
[2010/07/25 22:10:22 | 000,134,144 | —- | M] () – C:\7da71916a161260.bup
[2010/07/26 18:52:44 | 000,175,616 | —- | M] () – C:\7da71a12342c22d0.bup
[2010/07/10 02:30:19 | 000,357,376 | —- | M] () – C:\7da7a21e1336c0.bup
[2010/08/17 01:50:12 | 000,114,176 | —- | M] () – C:\7da811132c3760.bup
[2010/08/05 13:43:52 | 000,143,360 | —- | M] () – C:\7da85d2b3439b0.bup
[2010/08/05 13:44:14 | 000,143,360 | —- | M] () – C:\7da85d2ce11b0.bup
[2012/05/21 02:09:31 | 4294,316,030 | -HS- | M] () – C:\hiberfil.sys
[2012/05/21 02:09:32 | 4294,103,037 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/11 05:14:17 | 000,000,221 | -HS- | M] () – C:\Users\Administrator1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/07/13 21:39:29 | 000,427,008 | —- | M] (Microsoft Corporation) – C:\Users\Administrator1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\regedit.exe

< %USERPROFILE%\Desktop\*.exe >
[2012/05/21 03:30:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Administrator1\Desktop\HiJackThis.exe
[2012/05/21 03:13:05 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Administrator1\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:F8D65F32
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
——————————————————————————————————-
OTL Extras logfile created on: 5/21/2012 3:43:13 AM - Run 1
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Administrator1\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

16.00 Gb Total Physical Memory | 13.21 Gb Available Physical Memory | 82.57% Memory free
32.00 Gb Paging File | 29.33 Gb Available in Paging File | 91.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.14 Gb Total Space | 47.48 Gb Free Space | 39.85% Space Free | Partition Type: NTFS
Drive D: | 931.31 Gb Total Space | 663.33 Gb Free Space | 71.23% Space Free | Partition Type: NTFS
Drive E: | 931.31 Gb Total Space | 118.90 Gb Free Space | 12.77% Space Free | Partition Type: NTFS

Computer Name: TOWER-1 | User Name: Administrator1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{4277929B-8147-4236-9AFB-042BDFE2FD9E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B27960CB-A145-4692-B38A-9AB2C28CC5DD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{911EA7F3-3E8F-4AB8-8B31-8D8ED9C5BAC4}" = protocol=6 | dir=in | app=c:\program files (x86)\active data recovery software\active undelete7 enterprise\undelete.exe |
"{F7244407-C028-4206-9F6C-44B7890D9394}" = protocol=17 | dir=in | app=c:\program files (x86)\active data recovery software\active undelete7 enterprise\undelete.exe |
"TCP Query User{525ABE60-D11B-4AFD-8032-F21ED9D3EC4A}C:\program files (x86)\active data recovery software\active undelete7 enterprise\undelete.exe" = protocol=6 | dir=in | app=c:\program files (x86)\active data recovery software\active undelete7 enterprise\undelete.exe |
"TCP Query User{58C7E43E-1FD3-4B94-A11D-4C075F8D306D}C:\program files\foxit software\pdf editor\pdfedit.exe" = protocol=6 | dir=in | app=c:\program files\foxit software\pdf editor\pdfedit.exe |
"TCP Query User{62BA4ED8-BB0C-4357-8486-8A67567C09B9}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{82871265-3171-493D-BD5B-35E7BD4C4D9E}C:\windows\system32\ftp.exe" = protocol=6 | dir=in | app=c:\windows\system32\ftp.exe |
"UDP Query User{07A67406-8AAE-4028-B2AA-D7C86965AAEE}C:\windows\system32\ftp.exe" = protocol=17 | dir=in | app=c:\windows\system32\ftp.exe |
"UDP Query User{3C97E8A4-2E1B-4135-9E57-E948CCA2F95F}C:\program files (x86)\active data recovery software\active undelete7 enterprise\undelete.exe" = protocol=17 | dir=in | app=c:\program files (x86)\active data recovery software\active undelete7 enterprise\undelete.exe |
"UDP Query User{866B4C56-7B22-4594-A438-A601F807F236}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{AF9A943D-AB79-441C-B4B5-3AD0D5DF85B9}C:\program files\foxit software\pdf editor\pdfedit.exe" = protocol=17 | dir=in | app=c:\program files\foxit software\pdf editor\pdfedit.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = Media Player Classic - Home Cinema v1.3.2058.0 x64
"{31E8F586-4EF7-4500-844D-BA8756474FF1}" = Windows Automated Installation Kit
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62882B03-FFFB-4F33-836E-1AFE4EFD9496}" = Diskeeper 2011
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{825C7AAC-C5D5-B89B-EBA1-D4DFC5E46D6C}" = AMD Drag and Drop Transcoding
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{9E3B2120-0BD8-9865-0387-E9BAC2A53AD3}" = ccc-utility64
"{ABE286AE-C65D-B7DE-C8D1-DF79584169B4}" = AMD Fuel
"{BE882A12-5A45-3DFF-9FD0-306DE65EB8A5}" = AMD Catalyst Install Manager
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{EF393943-0CCE-9CD9-6181-96DF4E4428EF}" = AMD Media Foundation Decoders
"2413fd9e47cb8b2cac9f39dddd0aeb5a-995347964" = 3ware Disk Management Tools
"Agnitum Outpost Firewall Pro_is1" = Outpost Firewall Pro 7.5.2
"CANONIJINBOXADDON100" = Canon Inkjet Printer Driver Add-On Module
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0D97F8D1-2102-53D2-5633-C992D6086801}" = CCC Help Chinese Traditional
"{0EA00EA7-42C0-ED9C-9110-2C04B8EDBA66}" = CCC Help Italian
"{0EB86B70-91FF-39BF-633C-785DF2218CC6}" = CCC Help French
"{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}" = McAfee VirusScan Enterprise
"{1686C07D-C2BB-A8B2-C5ED-32C4EE1A3E62}" = CCC Help Spanish
"{18B6A9F8-25BC-5978-6B42-A50FA2CABC18}" = CCC Help English
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{298C6691-46B2-2065-0DD7-1E7B3B669A47}" = CCC Help Finnish
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2DFA85ED-588F-4CE3-A175-29E52C3804A8}}_is1" = Folder Size 1.4.0.0
"{2ECA81CA-D932-4AD3-AD59-BF5CCF099C83}" = Catalyst Control Center - Branding
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{400C5445-1AE8-1A41-CAC6-AB114341F65D}" = CCC Help Swedish
"{448B1C6D-02C2-7681-66B2-624E58B25375}" = CCC Help Turkish
"{46CBBDF8-55B5-40DB-B459-7B848394309C}" = EPSON File Manager
"{46EB9D45-FC1A-2635-1693-176E6FA1C672}" = CCC Help Portuguese
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = EPSON Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{624EA87E-9946-4DFF-8A3F-9C8346A185D3}" = PrintFolders 2.3
"{651F43AA-3F06-9277-6F1B-8E8155017463}" = CCC Help Polish
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{68DE32E1-292B-6A02-6A53-935BFAE70C99}" = CCC Help Chinese Standard
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{818212BA-7F8C-DDF9-64BE-F6D0B6F46D29}" = CCC Help German
"{84F4542C-ED64-28AC-49B3-1A9BAB395AB4}" = CCC Help Hungarian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8C0CAA7A-3272-4991-A808-2C7559DE3409}" = Win7codecs
"{9C41195F-11B3-8EEC-6634-7183BE6CB1B1}" = CCC Help Japanese
"{A33A89D0-2F48-FD1C-A243-9073EE0592E0}" = Catalyst Control Center InstallProxy
"{A66FB6C7-B689-AFD5-21BA-7CAF8E44E6E6}" = Catalyst Control Center Graphics Previews Common
"{AA951B10-7089-4D60-B288-516E641F48E6}" = McAfee Agent
"{AE136F7F-7DC6-600F-9DF9-BFA0DF516135}" = Catalyst Control Center Localization All
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B440D659-FECA-4BDD-A12B-5C9F05790FF3}" = Snagit 9.1.2
"{B4CF00AE-2622-7BC6-24EC-4E5A0A8C9135}" = CCC Help Czech
"{BAE1C0A8-634D-CFF1-0E0C-893092427D34}" = CCC Help Danish
"{C2DEC505-79A9-E952-32B0-31B67B83E231}" = CCC Help Korean
"{C2FB14FB-DF6B-287D-BDC3-C7BEC86F539E}" = AMD VISION Engine Control Center
"{CCEFAE22-4D01-0084-D1CA-AC14AA743A97}" = CCC Help Greek
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{D4378A80-C713-11DF-9399-005056C00008}" = Paragon Migrate OS to SSD™
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{DE460826-5E72-2357-154F-E376F9926008}" = CCC Help Norwegian
"{E21FFD29-D231-3BD3-6941-15710E44BED4}" = CCC Help Dutch
"{E2486DE6-CC2E-48C0-AD20-C2C142FA1636}" = APC PowerChute Personal Edition v2.2
"{E3E313C7-0AE2-7F44-52E8-528D4EDC74B2}" = CCC Help Thai
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F9929777-7B6E-F53D-3105-1C06E5120CA1}" = CCC Help Russian
"Active@ UNDELETE 7 Enterprise" = Active@ UNDELETE 7 Enterprise
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Anti Tracks_is1" = Anti Tracks 6.9.23
"BeyondCompare3_is1" = Beyond Compare Version 3.1.10
"ControlCenter_is1" = ControlCenter
"EPSON Scanner" = EPSON Scan
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Foxit PDF Editor" = Foxit PDF Editor
"Free Download Manager_is1" = Free Download Manager 3.0
"HashCalc_is1" = HashCalc 2.02
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"JDownloader" = JDownloader
"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise Module
"MetFileRegenerator" = MetFileRegenerator v3.0.16
"Mozilla Firefox (3.6.28)" = Mozilla Firefox (3.6.28)
"MRU-Blaster_is1" = MRU-Blaster v1.5 (Database 3/28/2004)
"PingPlotter Pro" = PingPlotter Pro 3.20p
"Privoxy" = Privoxy (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.6
"SpywareGuard_is1" = SpywareGuard v2.2
"The Blocklist Manager_is1" = BLM 2.6.5
"Tor" = Tor 0.2.2.35
"UltraISO_is1" = UltraISO Premium V9.36
"Vidalia" = Vidalia 0.2.15
"WZCLINE" = WinZip Command Line Support Add-On 3.1
"XLink/Win_is1" = XLink/Win Version 2.7b
"YU2010_is1" = Your Uninstaller! 2010

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
————————————————————————————————————————————-
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:38:19 AM, on 5/21/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MRU-Blaster\scheduler.exe
C:\Program Files (x86)\SpywareGuard\sgmain.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\epson\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files (x86)\Anti Tracks\AntiTracks.exe
C:\Program Files (x86)\SpywareGuard\sgbhp.exe
C:\Users\Administrator1\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files (x86)\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\scriptsn.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe (User 'Default user')
O4 - Startup: PartMetBackup.lnk = C:\Program Files (x86)\Java\jre6\bin\javaw.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files (x86)\APC\APC PowerChute Personal Edition\Display.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{BDF8E48F-B546-4D78-86A0-AA76366BCD6B}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\..\{EAA4334D-8B7A-4B81-AA05-7DDA353A7BB8}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: 3ware 3DM2 (3DM2) - LSI - C:\Program Files\3ware\3DM2/3dm2.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 10426 bytes
————————————————————————————————–
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 4:44:44.06 on Mon 05/21/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16383.13278 [GMT -4:00]
.
AV: McAfee VirusScan Enterprise *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee VirusScan Enterprise Antispyware Module *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: Outpost Firewall Pro *Enabled* {D4D1EAE8-EA68-0A9F-FEFA-AB61226EC615}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\3ware\3DM2\3dm2.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe
C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mfeann.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\MRU-Blaster\scheduler.exe
C:\Program Files (x86)\SpywareGuard\sgmain.exe
C:\Program Files\PeerBlock\peerblock.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\epson\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\3ware\3DM2\WinAVAlarm.exe
C:\Program Files (x86)\Anti Tracks\AntiTracks.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\SpywareGuard\sgbhp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\Administrator1\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uWindow Title =
mWinlogon: Userinit=userinit.exe
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - C:\Program Files (x86)\SpywareGuard\dlprotect.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\scriptsn.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
mRun: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [EEventManager] C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe
mRun: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
dRun: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe
StartupFolder: C:\Users\ADMINI~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PARTME~1.LNK - C:\Program Files (x86)\Java\jre6\bin\javaw.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\APCUPS~1.LNK - C:\Program Files (x86)\APC\APC PowerChute Personal Edition\Display.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: NoWebServices = 1 (0x1)
mPolicies-explorer: NoOnlinePrintsWizard = 1 (0x1)
mPolicies-explorer: NoPublishingWizard = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: {BDF8E48F-B546-4D78-86A0-AA76366BCD6B} = 208.67.222.222,208.67.220.220
TCP: {EAA4334D-8B7A-4B81-AA05-7DDA353A7BB8} = 208.67.222.222,208.67.220.220
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - C:\Program Files (x86)\SpywareGuard\spywareguard.dll
BHO-X64: SnagIt Toolbar Loader: {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\scriptsn.dll
BHO-X64: scriptproxy - No File
TB-X64: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
mRun-x64: [Acronis Scheduler2 Service] "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
mRun-x64: [WinAVAlarm] C:\Program Files\3ware\3DM2\WinAVAlarm.exe
mRun-x64: [OutpostFeedBack] ; "C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe" /dump:os_startup
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
mRun-x64: [OutpostMonitor] "C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe" /tray /noservice
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 192.168.1.2 TOWER-1
Hosts: 192.168.1.3 TOWER-2
Hosts: 192.168.1.4 TOWER-3
Hosts: 192.168.1.5 TOWER-4
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\ADMINI~1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - about:blank
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\npjpi160_31.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
FF - plugin: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
FF - plugin: C:\Windows\system32\Wat\npWatWeb.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
FF - Ext: FEBE: {4BBDD651-70CF-4821-84F8-2B918CF89CA3} - %profile%\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Element Hiding Helper for Adblock Plus: [removed] - %profile%\extensions\[removed]
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
FF - Ext: RefControl: {455D905A-D37C-4643-A9E2-F6FEFAA0424A} - %profile%\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: Redirect Cleaner: [removed] - %profile%\extensions\[removed]
FF - Ext: SkipScreen: SkipScreen@SkipScreen - %profile%\extensions\SkipScreen@SkipScreen
FF - Ext: Torbutton: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca} - %profile%\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
FF - Ext: HTTPS-Everywhere: [removed] - %profile%\extensions\[removed]
.
============= SERVICES / DRIVERS ===============
.
R0 3wareDrv;3wareDrv;C:\Windows\System32\drivers\3wareDrv.sys [2009-8-31 102400]
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2010-6-14 470808]
R0 tdrpman258;Acronis Try&Decide; and Restore Points filter (build 258);C:\Windows\System32\drivers\tdrpm258.sys [2010-6-19 1477728]
R1 afw;Agnitum Firewall Driver;C:\Windows\System32\drivers\afw.sys [2010-6-16 38488]
R1 SandBox;SandBox;C:\Windows\System32\drivers\SandBox64.sys [2010-6-16 1266544]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 3DM2;3ware 3DM2;C:\Program Files\3ware\3DM2\3dm2.exe [2010-9-14 1801224]
R2 acssrv;Agnitum Client Security Service;C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe [2010-6-16 3268416]
R2 afcdpsrv;Acronis Nonstop Backup service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-6-19 2480048]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-12-5 235520]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-12-5 361984]
R2 AODDriver4.01;AODDriver4.01;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2011-6-24 55424]
R2 McAfeeEngineService;McAfee Engine Service;C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe [2010-8-25 20792]
R2 McAfeeFramework;McAfee Framework Service;C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [2009-8-25 103744]
R2 McShield;McAfee McShield;C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe [2010-8-25 181480]
R2 McTaskManager;McAfee Task Manager;C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe [2010-8-25 66880]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\System32\mfevtps.exe [2010-6-14 77968]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-1-2 1153368]
R3 afcdp;afcdp;C:\Windows\System32\drivers\afcdp.sys [2010-6-19 252512]
R3 afwcore;afwcore;C:\Windows\System32\drivers\afwcore.sys [2010-6-16 444504]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2011-3-2 46136]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2011-12-5 10720256]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2011-12-5 327168]
R3 DKRtWrt;DKRtWrt;C:\Windows\System32\drivers\DKRtWrt.sys [2012-1-8 44624]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2010-6-14 120224]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-1-22 77824]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-1-22 180224]
R3 pbfilter;pbfilter;C:\Program Files\PeerBlock\pbfilter.sys [2010-6-15 24176]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2011-3-2 47232]
S3 ASWFilt;ASWFilt;C:\Windows\System32\Filt\ASWFilt64.dll [2010-6-16 66184]
S3 BioNTDrv;BioNTDrv;C:\Program Files (x86)\Paragon Software\Migrate OS to SSD\program\biontdrv.sys [2011-3-1 19024]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\System32\drivers\mferkdet.sys [2010-6-14 78768]
S3 NmPar;Unusable Parallel Port;C:\Windows\System32\drivers\NmPar.sys [2010-1-12 95744]
S3 nmserial;PCI Serial Port;C:\Windows\System32\drivers\NmSerial.sys [2010-1-7 75264]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-7-8 20992]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-9-20 349800]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-8 59392]
S3 TVICHW64;TVICHW64;C:\Windows\SysWOW64\drivers\TVicHW64.sys [2010-6-6 21200]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-3 1255736]
.
=============== Created Last 30 ================
.
2012-05-21 07:30:57 ——– d—–w- C:\Downloads
2012-05-21 05:52:52 ——– d—–w- C:\Users\ADMINI~1\AppData\Roaming\SUPERAntiSpyware.com
2012-05-21 05:51:27 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2012-05-21 05:51:27 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com
2012-05-15 00:56:17 ——– d—–w- C:\Users\ADMINI~1\AppData\Roaming\Malwarebytes
2012-05-15 00:55:47 ——– d—–w- C:\PROGRA~3\Malwarebytes
2012-05-13 00:35:38 23408 —-a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-05-13 00:35:37 81408 —-a-w- C:\Windows\System32\imagehlp.dll
2012-05-13 00:35:37 159232 —-a-w- C:\Windows\SysWow64\imagehlp.dll
2012-05-13 00:35:36 5120 —-a-w- C:\Windows\SysWow64\wmi.dll
2012-05-13 00:35:36 5120 —-a-w- C:\Windows\System32\wmi.dll
2012-05-13 00:35:36 220672 —-a-w- C:\Windows\System32\wintrust.dll
2012-05-13 00:35:36 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-05-13 00:35:06 8917360 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{497C28AB-E0ED-4A4B-B44C-539F42A940A3}\mpengine.dll
2012-05-13 00:22:49 1544704 —-a-w- C:\Windows\System32\DWrite.dll
2012-05-13 00:22:48 1077248 —-a-w- C:\Windows\SysWow64\DWrite.dll
2012-05-13 00:22:46 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-13 00:22:45 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-13 00:22:45 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-13 00:22:45 3146240 —-a-w- C:\Windows\System32\win32k.sys
2012-05-13 00:22:42 936960 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-05-13 00:22:42 1367552 —-a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-13 00:22:39 1918320 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-05-13 00:22:37 75120 —-a-w- C:\Windows\System32\drivers\partmgr.sys
2012-05-05 06:46:43 25048 —-a-w- C:\Program Files (x86)\Mozilla Firefox\components\browserdirprovider.dll
2012-05-05 06:46:43 140248 —-a-w- C:\Program Files (x86)\Mozilla Firefox\components\brwsrcmp.dll
.
==================== Find3M ====================
.
2012-05-09 19:41:53 419488 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-09 19:41:51 70304 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-28 06:56:48 2311168 —-a-w- C:\Windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 —-a-w- C:\Windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-02-28 05:37:58 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-02-28 01:18:55 1799168 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-02-23 14:18:36 279656 ——w- C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 4:45:18.09 ===============
Posted Image


DO NOT use any TOOLS such as Combofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


Next:

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Hello Forum God, Thanks for your help. Is an honor to be helped by you. I am a computer tech with over 20 years of experience, but every day I come to realize I know very little about the computer field and I have set what time I have left in this world to learn as much as I can. Mine is a computer assembled by myself. It has three hard disks. First drive is a 320gb single drive partitioned as a 90 GB drive, C:\ (to make an SSD future transition easier). The other two are 1Tb drives each in a RAID 10 configuration and partitioned as D:\ and E:\. No GPT used. Volumes D:\ and E:\ contain lots of zip and rar archives (some exe files, too) collected from the net for a personal project that involves documenting the scene and for learning/testing purposes. For this reasons is very important to be sure I have no malware installed and that changes done to the system are not unnecessary invasive. Damage to the data should be minimized. I have McAfee Viruscan antivirus installed and updated daily. SpyBot S&D and SpywareBlaster , updated at least weekly. SpywareGuard and MRUBlaster, as well as AntiTracks are installed. Prior to registering on your forum, I had MBAM installed and updated. On repeated scans, detection was negative, so I uninstalled it and installed SuperAntiSpyware. After updating SAS, all scans were negative. Seen that I could not diagnose the infection and feeling some strange behavior on my system, I turn to you. I feel I have a rootkit installed. I already had trouble trying to download Hijack This to comply with the first post and I had similar behavior while trying to download TFC but I did it using FDM (like I already described in the first post). None of the two links you provided for ComboFix works for me. For the time being I will run TFC and post the requested log in the next post.
ComboFix run notes: Even when the name of the user I use is Administrator1, it does not have administrative powers. Its a regular user account. I chose not to enable the Administrator account of this system. As far as I can remember, ComboFix was Run As Administrator. On Access Scan was disabled, but combo fix insisted that the antivirus be disabled. So, I had to stop its services and the McAfee Validation Trust Protection Service could not be stopped. ComboFix still complained that the antivirus had to disabled. Why did ComboFix chose to delete lmhosts from the C:Windows\system32\drivers\etc folder? I created this file, but I did not had a chance to examine the file contents before quarantine. When comboFix was stopping, a message was shown in a small window. It read: Windows could not find NIRKMD. Make sure you typed the name correctly and try again. and an OK button was displayed. Do this message means something to you? What does it means? There is a catchme.log inside the Quarantine folder produced bty ComboFix. This log only contains: ——– 2012-05-28 - 01:15:03 ————- Can you tell me what do you see in this log, apart form the obvious stuff? ComboFix log: ComboFix 12-05-27.03 - Administrator1 05/28/2012 1:16.1.6 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16383.14101 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: McAfee VirusScan Enterprise *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: Outpost Firewall Pro *Enabled* {D4D1EAE8-EA68-0A9F-FEFA-AB61226EC615} SP: McAfee VirusScan Enterprise Antispyware Module *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Outpost Firewall Pro *Disabled/Updated* {578B8A29-863D-0449-EF15-3926A73ACBD3} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Administrator1\AppData\Roaming\chrtmp c:\users\Administrator1\AppData\Roaming\Undelete7EnterpriseSetup.exe c:\windows\system32\drivers\etc\lmhosts . . ((((((((((((((((((((((((( Files Created from 2012-04-28 to 2012-05-28 ))))))))))))))))))))))))))))))) . . 2012-05-24 08:56 . 2012-05-27 06:40 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{497C28AB-E0ED-4A4B-B44C-539F42A940A3}\offreg.dll 2012-05-21 07:30 . 2012-05-21 07:30 ——– d—–w- C:\Downloads 2012-05-21 05:52 . 2012-05-21 05:52 ——– d—–w- c:\users\Administrator1\AppData\Roaming\SUPERAntiSpyware.com 2012-05-21 05:51 . 2012-05-21 05:52 ——– d—–w- c:\program files\SUPERAntiSpyware 2012-05-21 05:51 . 2012-05-21 05:51 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2012-05-15 00:56 . 2012-05-15 00:56 ——– d—–w- c:\users\Administrator1\AppData\Roaming\Malwarebytes 2012-05-15 00:55 . 2012-05-15 00:55 ——– d—–w- c:\programdata\Malwarebytes 2012-05-13 00:35 . 2012-03-01 06:46 23408 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-05-13 00:35 . 2012-03-01 06:33 81408 —-a-w- c:\windows\system32\imagehlp.dll 2012-05-13 00:35 . 2012-03-01 05:33 159232 —-a-w- c:\windows\SysWow64\imagehlp.dll 2012-05-13 00:35 . 2012-03-01 06:38 220672 —-a-w- c:\windows\system32\wintrust.dll 2012-05-13 00:35 . 2012-03-01 06:28 5120 —-a-w- c:\windows\system32\wmi.dll 2012-05-13 00:35 . 2012-03-01 05:37 172544 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-05-13 00:35 . 2012-03-01 05:29 5120 —-a-w- c:\windows\SysWow64\wmi.dll 2012-05-13 00:35 . 2012-04-13 08:46 8917360 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{497C28AB-E0ED-4A4B-B44C-539F42A940A3}\mpengine.dll 2012-05-13 00:22 . 2012-03-03 06:35 1544704 —-a-w- c:\windows\system32\DWrite.dll 2012-05-13 00:22 . 2012-03-03 05:31 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll 2012-05-13 00:22 . 2012-03-31 06:05 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-13 00:22 . 2012-03-31 04:39 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-13 00:22 . 2012-03-31 04:39 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-13 00:22 . 2012-03-31 03:10 3146240 —-a-w- c:\windows\system32\win32k.sys 2012-05-13 00:22 . 2012-03-31 05:40 1367552 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2012-05-13 00:22 . 2012-03-31 04:29 936960 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2012-05-13 00:22 . 2012-03-30 11:35 1918320 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-05-13 00:22 . 2012-03-17 07:58 75120 —-a-w- c:\windows\system32\drivers\partmgr.sys 2012-05-05 06:46 . 2012-03-06 17:27 140248 —-a-w- c:\program files (x86)\Mozilla Firefox\components\brwsrcmp.dll 2012-05-05 06:46 . 2012-03-06 17:27 25048 —-a-w- c:\program files (x86)\Mozilla Firefox\components\browserdirprovider.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-09 19:41 . 2012-04-01 06:33 419488 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-05-09 19:41 . 2012-02-28 07:44 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-02-28 05:37 . 2010-06-18 06:29 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-05-16 4787072] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ShStatEXE"="c:\program files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2010-08-26 124224] "TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-03-27 5107232] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632] "NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-01-22 106496] "EEventManager"="c:\program files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2006-10-12 102400] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-12-06 343168] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "PeerBlock"="c:\program files\PeerBlock\peerblock.exe" [2010-11-07 2646128] . c:\users\Administrator1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ PartMetBackup.lnk - c:\program files (x86)\Java\jre6\bin\javaw.exe [2012-2-28 149280] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ APC UPS Status.lnk - c:\program files (x86)\APC\APC PowerChute Personal Edition\Display.exe [2009-1-6 267576] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoWebServices"= 1 (0x1) "NoOnlinePrintsWizard"= 1 (0x1) "NoPublishingWizard"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService] @="Service" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "McAfeeUpdaterUI"="c:\program files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey . R3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt64.dll [x] R3 BioNTDrv;BioNTDrv;c:\program files (x86)\Paragon Software\Migrate OS to SSD\program\BioNTDrv.SYS [2011-03-01 19024] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] R3 NmPar;Unusable Parallel Port;c:\windows\system32\DRIVERS\NmPar.sys [x] R3 nmserial;PCI Serial Port;c:\windows\system32\DRIVERS\nmserial.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 Tcpz-x64;Tcpz-x64;c:\users\ADMINI~1\AppData\Local\Temp\Tcpz-x64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 TVICHW64;TVICHW64;c:\windows\SysWOW64\Drivers\TVicHW64.sys [2010-06-07 21200] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 3wareDrv;3wareDrv;c:\windows\system32\DRIVERS\3wareDrv.sys [x] S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [x] S1 afw;Agnitum Firewall Driver;c:\windows\system32\DRIVERS\afw.sys [x] S1 SandBox;SandBox;c:\windows\system32\drivers\SandBox64.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672] S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [2012-02-17 3268416] S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-06-19 2480048] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-12-06 361984] S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2011-06-24 55424] S2 McAfeeEngineService;McAfee Engine Service;c:\program files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe [2010-08-26 20792] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x] S3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [x] S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [x] S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x] S3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2010-11-07 24176] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - PBFILTER *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-05-27 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task e281d69b-c853-4795-ab5a-20b9ceb0059c.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-03-27 362232] "WinAVAlarm"="c:\program files\3ware\3DM2\WinAVAlarm.exe" [2010-01-29 548872] "OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2012-05-12 0] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-10-05 11474024] "OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2012-02-17 4366360] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm TCP: Interfaces\{BDF8E48F-B546-4D78-86A0-AA76366BCD6B}: NameServer = 208.67.222.222,208.67.220.220 TCP: Interfaces\{EAA4334D-8B7A-4B81-AA05-7DDA353A7BB8}: NameServer = 208.67.222.222,208.67.220.220 FF - ProfilePath - c:\users\Administrator1\AppData\Roaming\Mozilla\Firefox\Profiles\cqcxg6g8.default\ FF - prefs.js: browser.search.selectedEngine - Ask FF - prefs.js: browser.startup.homepage - about:blank FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} FF - Ext: FEBE: {4BBDD651-70CF-4821-84F8-2B918CF89CA3} - %profile%\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: Element Hiding Helper for Adblock Plus: [removed] - %profile%\extensions\[removed] FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644} FF - Ext: RefControl: {455D905A-D37C-4643-A9E2-F6FEFAA0424A} - %profile%\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A} FF - Ext: Redirect Cleaner: [removed] - %profile%\extensions\[removed] FF - Ext: SkipScreen: SkipScreen@SkipScreen - %profile%\extensions\SkipScreen@SkipScreen FF - Ext: Torbutton: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca} - %profile%\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca} FF - Ext: HTTPS-Everywhere: [removed] - %profile%\extensions\[removed] . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\3DM2] "ImagePath"="c:\program files\3ware\3DM2/3dm2.exe" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe c:\program files (x86)\McAfee\Common Framework\FrameworkService.exe c:\program files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe c:\program files (x86)\McAfee\Common Framework\naPrdMgr.exe c:\program files (x86)\MRU-Blaster\scheduler.exe c:\program files (x86)\SpywareGuard\sgmain.exe c:\program files (x86)\SpywareGuard\sgbhp.exe . ************************************************************************** . Completion time: 2012-05-28 01:28:17 - machine was rebooted ComboFix-quarantined-files.txt 2012-05-28 05:28 . Pre-Run: 49,553,043,456 bytes free Post-Run: 49,396,822,016 bytes free . - - End Of File - - 0E4B2D7E1F8D6648E205AEF3C65DCE3F
Blocked outgoing ICMP packet (ICMP type 3)

There are many Google search hits for that.
Here's just a few that might apply.


http://www.geekstogo.com/forum/topic/30758…et-icmp-type-3/

http://www.dslreports.com/forum/r23894097-…rottling-issue-

http://www.neowin.net/forum/topic/564832-icmp-type-3-errors/

go to the machine in question, open a command windows and use:
netstat -a
to see all current connections.

The port used may be a clue to what app is sending the icmp packets.



I'm not seeing anything bad in the CF scan results.

As for the Host file, it's one of the most that the bad guys use to Hijack the computer.
Some of the tools we use will reset the host back to the default.

I'm not seeing anything bad in the CF scan results.

As for the Host file, it's one of the most that the bad guys use to Hijack the computer.
Some of the tools we use will reset the host back to the default.

Hosts file is very important to many of us. This system's was guarded by SpyBot S&D and lots of entries were written there by SpyBot S&D and by myself. I'm glad you told me that some tools resets this file. The backup that SpyBot creates was gone too. I was able to recover the file using a backup from another machine I have. Otherwise, I would have lost a lot of work I did over the years.

I my system, when this file is reset some of my best protection is gone.

I will suggest you to include a direct statement within the information you convey to the person you are about to help, warning them that this is about to happen.

As for the state of the system, I agree with you. I think is clean.

I delayed a bit because I discovered that an update to the firewall I use introduced a bug. Luckily I think I can fix this by uninstalling the firewall and doing a full install, like I did in the other machine I have.

Thank you for you help. The time you put into this is very appreciated. Thank you for your altruism. :)

Now, all is left to do please, is for you to direct me on how to do the housekeeping process.
For Vista / Windows 7
  • Click START Search
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.


Here's my usual final post

To be on the safe side, I would also change all my passwords.

This infection appears to have been cleaned, but as the malware could be configured to run any program a remote attacker requires, it's impossible to be 100% sure that any machine is clean.


Log looks good :D


  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.
  • Securing Your Web Browser
    This paper will help you configure your web browser for safer internet surfing.

  • Using a secure browser plugin M86 SecureBrowsing makes it safe to search, surf and socialize online. This free browser plug-in displays security icons next to links on search engines and social networking sites like Facebook, Twitter and LinkedIn, so you'll know which pages are safe and which ones to avoid.

    •Free browser plug-in for Internet Explorer and Firefox
    •Real-time safety ratings
    •Ideal for Facebook, Twitter and LinkedIn

  • JAVA Click this link and click on the Free JAVA Download

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

Only run one Anti-Virus and Firewall program.
Hi, As I executed the Combofix Uninstall, what seems to be the root kit started what seems to be an install of files into my system. Files like Hidec.3xe, etc. Are those ComboFix files? Also, McAfee Viruscan flagged iexplorer.exe, firefox.exe and explorer.exe as virus and quarantined them. I did a full scan with SuperAntiSpyware. Only two tracking cookies detected. Am I infected again or that is the normal ComboFix Uninstall? BTW, uninstall completed. System seems to be clean.

Also, McAfee Viruscan flagged iexplorer.exe, firefox.exe and explorer.exe as virus and quarantined them.

AV's will do that with tools like CF, that's why we ask it be disabled when working with the tools.

Am I infected again or that is the normal ComboFix Uninstall?

Normal

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI