This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE and Firefox Redirects, Audio/Ads in Background [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:50:29 PM, on 7/20/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTDCPL.EXE
C:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.htagateway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Microsoft Forefront Client Security Antimalware Service] "c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe" -hide
O4 - HKLM\..\Run: [IMSS] "C:\Program Files\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTDCPL.EXE
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: CardMinder Viewer.lnk = ?
O4 - Global Startup: Conversion to PDF with ScanSnap Organizer.lnk = ?
O4 - Global Startup: ScanSnap Manager.lnk = ?
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.hometownamerica.com
O15 - Trusted Zone: *.hometownamerica.net
O15 - Trusted Zone: *.htagateway.com
O15 - Trusted Zone: *.htaonline.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1342729240296
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://akamaicdn.webex.com/client/WBXclien…ort/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe

–
End of file - 9166 bytes


DDS:


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 16:45:11.50 on Fri 07/20/2012
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_31
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3241.1942 [GMT -4:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Forefront Client Security *Enabled/Updated* {926A3D4F-E4E7-4F47-9902-4EDD55FFE1AF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTDCPL.EXE
C:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Townhome\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = https://www.htagateway.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Microsoft Forefront Client Security Antimalware Service] "c:\program files\microsoft forefront\client security\client\antimalware\MSASCui.exe" -hide
mRun: [IMSS] "c:\program files\intel\intel® management engine components\imss\PIconStartup.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTDCPL.EXE
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\oem\12.0\sharedcom\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "c:\program files\roxio\oem\roxio burn\RoxioBurnLauncher.exe"
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\cardmi~1.lnk - c:\program files\pfu\scansnap\cardminder\CardLauncher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\conver~1.lnk - c:\program files\pfu\scansnap\organizer\PfuSsOrgOcrChk.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\scansn~1.lnk - c:\program files\pfu\scansnap\driver\PfuSsMon.exe
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: hometownamerica.com
Trusted Zone: hometownamerica.net
Trusted Zone: htagateway.com
Trusted Zone: htaonline.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342729240296
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} - hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://akamaicdn.webex.com/client/WBXclient-T27L10NSP24-10113/support/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\townhome\applic~1\mozilla\firefox\profiles\uhwj9837.default\
FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\windows\npMSDM.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1165635.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll
.
============= SERVICES / DRIVERS ===============
.
R2 FCSAM;Microsoft Forefront Client Security Antimalware Service;c:\program files\microsoft forefront\client security\client\antimalware\MsMpEng.exe [2011-1-8 16896]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2011-4-18 2656280]
R3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\drivers\e1c5132.sys [2011-4-18 174248]
R3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2011-4-18 260864]
R3 MEI;Intel® Management Engine Interface;c:\windows\system32\drivers\HECI.sys [2011-4-18 41088]
R3 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 71296]
S0 cerc6;cerc6; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\common files\roxio shared\oem\12.0\sharedcom\RoxWatch12OEM.exe [2010-9-4 219632]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-30 250056]
S3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [2011-10-24 829152]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-7-20 113120]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files\common files\roxio shared\oem\12.0\sharedcom\RoxMediaDB12OEM.exe [2010-9-4 1116656]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 FcsSas;Microsoft Forefront Client Security State Assessment Service;c:\program files\microsoft forefront\client security\client\ssa\FcsSas.exe [2007-4-6 73120]
.
=============== Created Last 30 ================
.
2012-07-20 20:42:34 6891424 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft forefront\client security\client\antimalware\definition updates\{10c5411b-ba7d-4ade-9d0b-62936e93c4a6}\mpengine.dll
2012-07-20 16:40:57 ——– d—–w- c:\docume~1\townhome\applic~1\AVG
2012-07-20 16:29:02 ——– d–h–w- c:\docume~1\alluse~1\applic~1\Common Files
2012-07-20 16:29:02 ——– d—–w- c:\docume~1\alluse~1\applic~1\MFAData
2012-07-19 20:17:25 ——– d—–w- c:\program files\Trend Micro
2012-07-19 19:04:13 ——– d-sha-r- C:\cmdcons
2012-07-19 19:01:30 98816 —-a-w- c:\windows\sed.exe
2012-07-19 19:01:30 518144 —-a-w- c:\windows\SWREG.exe
2012-07-19 19:01:30 256000 —-a-w- c:\windows\PEV.exe
2012-07-19 19:01:30 208896 —-a-w- c:\windows\MBR.exe
2012-07-19 18:46:55 ——– d—–w- c:\docume~1\townhome\applic~1\Malwarebytes
2012-07-19 16:47:39 ——– d-sh–w- c:\documents and settings\townhome\IECompatCache
2012-07-18 21:58:26 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\Mozilla
2012-07-18 19:38:39 ——– d—–w- c:\docume~1\townhome\applic~1\Windows Search
2012-07-18 19:01:21 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\Temp
2012-07-18 16:25:14 ——– d—–w- c:\docume~1\townhome\applic~1\PCPro
2012-07-18 16:25:07 ——– d—–w- c:\docume~1\townhome\applic~1\Easy Thumbnails
2012-07-18 16:25:00 ——– d—–w- c:\docume~1\townhome\applic~1\com.essexreddevelopment.mergepdfmac
2012-07-18 16:23:15 ——– d—–w- c:\documents and settings\townhome\usrusmt2.tmp
2012-07-18 16:00:02 99840 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\usmt\iconlib.dll
2012-07-18 15:59:22 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\LogMeIn Rescue Applet
2012-07-18 15:58:17 ——– d-sh–w- c:\documents and settings\townhome\PrivacIE
2012-07-18 15:58:16 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\Conduit
2012-07-18 15:58:00 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\Adobe
2012-07-18 15:58:00 ——– d—–w- c:\docume~1\townhome\applic~1\Fujitsu
2012-07-18 15:30:04 ——– d—–w- C:\TedBackup
2012-07-18 14:47:51 ——– d—–w- c:\program files\Conduit
2012-07-16 20:59:54 ——– dc-h–w- c:\windows\ie8
2012-07-16 19:42:15 ——– d—–w- c:\program files\Spybot - Search & Destroy
2012-07-16 19:42:15 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2012-07-16 19:38:08 4269368 —-a-w- c:\windows\uninst.exe
2012-07-16 19:38:07 ——– d—–w- c:\docume~1\alluse~1\applic~1\PC1Data
2012-07-13 15:22:10 ——– d—–w- c:\windows\system32\Adobe
2012-07-12 20:08:26 ——– d—–w- c:\program files\MSECache
2012-07-12 20:06:04 ——– d—–w- c:\program files\Microsoft Download Manager
.
==================== Find3M ====================
.
2012-07-19 16:20:52 90112 —-a-w- c:\windows\DUMP38a4.tmp
2012-07-11 18:16:06 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 18:16:05 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:29:09 1875072 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50:25 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50:25 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 21:35:26 222448 —-a-w- c:\windows\system32\muweb.dll
2012-06-04 04:32:08 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19:44 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19:38 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:18:58 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18:58 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08:26 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42:33 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42:33 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:02 385024 ——w- c:\windows\system32\html.iec
2012-05-04 13:24:46 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:41:08 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST95005620AS rev.DEM3 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8AC344B1]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8ac3b93c]; MOV EAX, [0x8ac3bab0]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1B0] -> \Device\Harddisk0\DR0[0x8AF68AB8]
3 CLASSPNP[0xB98E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1B0] -> [0x8A8428E0]
\Driver\atapi[0x8AC532D8] -> IRP_MJ_CREATE -> 0x8AC344B1
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8AC342E2
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:46:43.85 ===============
OTL logfile created on: 7/20/2012 4:36:20 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Townhome\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.16 Gb Total Physical Memory | 2.04 Gb Available Physical Memory | 64.36% Memory free
5.01 Gb Paging File | 4.05 Gb Available in Paging File | 80.92% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 432.25 Gb Free Space | 92.81% Space Free | Partition Type: NTFS

Computer Name: F9RLFQ1-1455 | User Name: Townhome | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Townhome\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\WINDOWS\RTDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
PRC - C:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
PRC - C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - c:\Program Files\Common Files\Roxio Shared\DLLShared\SQLite352.dll ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\PfuSsConfig.dll ()
MOD - C:\Program Files\PFU\ScanSnap\CardMinder\CardPath.dll ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\PfuSsExtention.dll ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\PfuUpdater.dll ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\P2IATRES.DLL ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\SSsltsa.dll ()
MOD - C:\WINDOWS\SSDriver\fi5110\fjiplA6.dll ()
MOD - C:\WINDOWS\SSDriver\fi5110\fjipl.dll ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\PfuSsImgIO.dll ()
MOD - C:\Program Files\Common Files\PFU\ScanSnap\OCR\FJ\F5BDKAKU.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (FCSAM) – c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (RoxWatch12) – C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) – C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (FcsSas) – C:\Program Files\Microsoft Forefront\Client Security\Client\SSA\FcsSas.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (cerc6) – File not found
DRV - (catchme) – C:\DOCUME~1\Townhome\LOCALS~1\Temp\catchme.sys File not found
DRV - (MEI) Intel® – C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
DRV - (IntcDAud) Intel® – C:\WINDOWS\system32\drivers\IntcDAud.sys (Intel® Corporation)
DRV - (e1cexpress) Intel® – C:\WINDOWS\system32\drivers\e1c5132.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtDHDAud.sys (Realtek Semiconductor Corp.)
DRV - (AE1000) – C:\WINDOWS\system32\drivers\AE1000XP.sys (Ralink Technology, Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.htagateway.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C8 7F 5C 24 FE 64 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {F5865D15-DD9B-4C12-8251-A80C93B50D63}
IE - HKCU\..\SearchScopes\{F5865D15-DD9B-4C12-8251-A80C93B50D63}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1165635.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/DownloadManager,version=1.1: C:\WINDOWS\ [2012/07/20 15:07:02 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/06/08 11:53:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/20 15:40:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/08 11:53:32 | 000,000,000 | —D | M]

[2012/07/20 15:49:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Townhome\Application Data\Mozilla\Extensions
[2012/07/18 12:25:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Townhome\Application Data\Mozilla\Firefox\Profiles\36rrluxo.default\extensions
[2012/07/18 12:25:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Townhome\Application Data\Mozilla\Firefox\Profiles\36rrluxo.default\extensions\{cce665dd-f6dd-4808-968e-eaec971f70ef}
[2012/07/20 15:40:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/13 20:17:47 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/03/03 15:08:37 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/07/13 20:16:36 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/13 20:16:36 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/07/19 15:14:24 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IMSS] C:\Program Files\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [Microsoft Forefront Client Security Antimalware Service] c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTDCPL.EXE (Realtek Semiconductor Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CardMinder Viewer.lnk = C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk = C:\Program Files\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ScanSnap Manager.lnk = C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: hometownamerica.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: hometownamerica.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: htagateway.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: htaonline.com ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1342729240296 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} http://download.microsoft.com/download/C/9…loadManager.cab (Microsoft Download Manager ActiveX control)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclien…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{21419632-14DB-47B2-A01C-0246C2899741}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABB40359-FE6E-4CD9-B2BB-D9A9EFE72FE4}: DhcpNameServer = 192.168.1.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Townhome\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Townhome\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/15 17:57:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/20 16:31:25 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Townhome\Desktop\OTL.exe
[2012/07/20 16:04:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CyberLink PowerDVD 9.5
[2012/07/20 15:40:15 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/07/20 15:02:59 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/07/20 12:40:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\AVG
[2012/07/20 12:39:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/07/20 12:29:02 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/07/20 12:29:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/07/19 16:17:25 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2012/07/19 16:17:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
[2012/07/19 15:36:57 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Townhome\Recent
[2012/07/19 15:36:21 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/07/19 15:04:13 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/07/19 15:01:30 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/07/19 15:01:30 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/07/19 15:01:30 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/07/19 15:01:30 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/07/19 14:59:27 | 000,000,000 | —D | C] – C:\Qoobox
[2012/07/19 14:59:23 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\Start Menu\Programs\Administrative Tools
[2012/07/19 14:57:01 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2012/07/19 14:46:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Malwarebytes
[2012/07/19 12:47:39 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Townhome\IECompatCache
[2012/07/19 12:14:56 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2012/07/18 18:20:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/07/18 18:20:22 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/07/18 17:58:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Local Settings\Application Data\Mozilla
[2012/07/18 15:38:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Windows Search
[2012/07/18 15:01:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Local Settings\Application Data\Temp
[2012/07/18 12:46:51 | 000,000,000 | –SD | C] – C:\Documents and Settings\Townhome\My Documents\My ScanSnap
[2012/07/18 12:46:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\My Documents\My Videos
[2012/07/18 12:42:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\My Documents\My Downloads
[2012/07/18 12:42:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\My Documents\Downloads
[2012/07/18 12:42:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\My Documents\CyberLink
[2012/07/18 12:42:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\My Documents\CardMinder
[2012/07/18 12:41:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\My Documents\gegl-0.0
[2012/07/18 12:27:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Desktop\Ted To File
[2012/07/18 12:25:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Sun
[2012/07/18 12:25:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\PCPro
[2012/07/18 12:25:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Desktop\CapX
[2012/07/18 12:25:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Mozilla
[2012/07/18 12:25:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Easy Thumbnails
[2012/07/18 12:25:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\CyberLink
[2012/07/18 12:25:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\com.essexreddevelopment.mergepdfmac
[2012/07/18 12:13:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Apple Computer
[2012/07/18 11:59:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Local Settings\Application Data\LogMeIn Rescue Applet
[2012/07/18 11:58:17 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Townhome\PrivacIE
[2012/07/18 11:58:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Local Settings\Application Data\Conduit
[2012/07/18 11:58:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Fujitsu
[2012/07/18 11:58:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Local Settings\Application Data\Adobe
[2012/07/18 11:58:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Adobe
[2012/07/18 11:57:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Local Settings\Application Data\Identities
[2012/07/18 11:57:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Windows Desktop Search
[2012/07/18 11:57:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\PFU
[2012/07/18 11:57:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Roxio
[2012/07/18 11:57:41 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Townhome\IETldCache
[2012/07/18 11:57:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Identities
[2012/07/18 11:57:20 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\My Documents\My Music
[2012/07/18 11:57:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\My Documents\My Pictures
[2012/07/18 11:57:10 | 000,000,000 | –SD | C] – C:\Documents and Settings\Townhome\Application Data\Microsoft
[2012/07/18 11:57:10 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Townhome\Application Data
[2012/07/18 11:57:10 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\Favorites
[2012/07/18 11:57:10 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Townhome\Cookies
[2012/07/18 11:57:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Local Settings\Application Data\Microsoft Help
[2012/07/18 11:57:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Local Settings\Application Data\Microsoft
[2012/07/18 11:57:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Application Data\Macromedia
[2012/07/18 11:57:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Townhome\Desktop
[2012/07/18 11:57:09 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Townhome\SendTo
[2012/07/18 11:57:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\Start Menu\Programs\Startup
[2012/07/18 11:57:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\Start Menu
[2012/07/18 11:57:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\My Documents
[2012/07/18 11:57:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\Townhome\Start Menu\Programs\Accessories
[2012/07/18 11:57:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Townhome\Templates
[2012/07/18 11:57:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Townhome\PrintHood
[2012/07/18 11:57:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Townhome\NetHood
[2012/07/18 11:57:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Townhome\Local Settings
[2012/07/18 11:30:04 | 000,000,000 | —D | C] – C:\TedBackup
[2012/07/18 10:47:51 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2012/07/16 16:59:54 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2012/07/16 15:42:15 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2012/07/16 15:42:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2012/07/16 15:38:08 | 004,269,368 | —- | C] (PC Cleaners) – C:\WINDOWS\uninst.exe
[2012/07/16 15:38:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2012/07/13 11:22:10 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2012/07/12 16:08:26 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2012/07/12 16:06:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Download Manager
[2012/07/12 16:06:04 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Download Manager
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Townhome\*.tmp files -> C:\Documents and Settings\Townhome\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/20 16:37:00 | 000,000,990 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1482476501-1417001333-1003UA.job
[2012/07/20 16:31:27 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Townhome\Desktop\OTL.exe
[2012/07/20 16:30:55 | 000,625,664 | —- | M] () – C:\Documents and Settings\Townhome\Desktop\dds.scr
[2012/07/20 16:16:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/20 16:04:36 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/20 15:51:22 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/07/20 15:40:17 | 000,000,742 | —- | M] () – C:\Documents and Settings\Townhome\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/07/20 15:40:17 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/07/20 15:09:39 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Quick Scan.job
[2012/07/20 15:09:39 | 000,000,412 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Signature Update.job
[2012/07/20 15:09:38 | 000,000,406 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/07/20 15:06:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/20 14:37:00 | 000,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1482476501-1417001333-1003Core.job
[2012/07/20 12:33:31 | 000,027,520 | —- | M] () – C:\Documents and Settings\Townhome\Local Settings\Application Data\dt.dat
[2012/07/19 17:55:15 | 000,004,608 | —- | M] () – C:\Documents and Settings\Townhome\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/19 16:17:25 | 000,001,734 | —- | M] () – C:\Documents and Settings\Townhome\My Documents\HijackThis.lnk
[2012/07/19 15:14:24 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/07/19 15:04:20 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2012/07/19 15:01:01 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/07/18 12:54:13 | 000,001,092 | —- | M] () – C:\Documents and Settings\Townhome\Local Settings\Application Data\FASTWiz.html
[2012/07/18 11:57:40 | 000,000,815 | —- | M] () – C:\Documents and Settings\Townhome\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/07/18 11:57:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\Townhome\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/07/18 10:50:17 | 000,131,272 | —- | M] () – C:\Documents and Settings\Townhome\My Documents\cc_20120718_105013.reg
[2012/07/18 10:48:06 | 000,000,009 | —- | M] () – C:\END
[2012/07/16 15:37:57 | 004,269,368 | —- | M] (PC Cleaners) – C:\WINDOWS\uninst.exe
[2012/07/11 14:16:06 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/11 14:16:05 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/11 12:20:11 | 000,316,360 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Townhome\*.tmp files -> C:\Documents and Settings\Townhome\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/20 16:30:52 | 000,625,664 | —- | C] () – C:\Documents and Settings\Townhome\Desktop\dds.scr
[2012/07/20 15:40:17 | 000,000,742 | —- | C] () – C:\Documents and Settings\Townhome\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/07/20 15:40:17 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/07/20 15:40:17 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/07/20 12:33:31 | 000,027,520 | —- | C] () – C:\Documents and Settings\Townhome\Local Settings\Application Data\dt.dat
[2012/07/19 17:55:13 | 000,004,608 | —- | C] () – C:\Documents and Settings\Townhome\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/19 16:17:25 | 000,001,734 | —- | C] () – C:\Documents and Settings\Townhome\My Documents\HijackThis.lnk
[2012/07/19 15:04:20 | 000,000,211 | —- | C] () – C:\Boot.bak
[2012/07/19 15:04:15 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/07/19 15:01:30 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/07/19 15:01:30 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/07/19 15:01:30 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/07/19 15:01:30 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/07/19 15:01:30 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/07/18 18:08:08 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/07/18 12:51:59 | 000,001,092 | —- | C] () – C:\Documents and Settings\Townhome\Local Settings\Application Data\FASTWiz.html
[2012/07/18 11:57:40 | 000,000,815 | —- | C] () – C:\Documents and Settings\Townhome\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/07/18 11:57:40 | 000,000,803 | —- | C] () – C:\Documents and Settings\Townhome\Start Menu\Programs\Internet Explorer.lnk
[2012/07/18 11:57:40 | 000,000,079 | —- | C] () – C:\Documents and Settings\Townhome\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/07/18 11:57:11 | 000,001,599 | —- | C] () – C:\Documents and Settings\Townhome\Start Menu\Programs\Remote Assistance.lnk
[2012/07/18 11:57:11 | 000,000,788 | —- | C] () – C:\Documents and Settings\Townhome\Start Menu\Programs\Windows Media Player.lnk
[2012/07/18 10:50:14 | 000,131,272 | —- | C] () – C:\Documents and Settings\Townhome\My Documents\cc_20120718_105013.reg
[2012/07/18 10:48:06 | 000,000,009 | —- | C] () – C:\END
[2012/02/14 16:41:03 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/24 18:39:28 | 000,014,051 | —- | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2011/08/08 17:05:50 | 000,066,704 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/06/29 12:52:55 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/06/24 17:45:39 | 000,000,161 | —- | C] () – C:\WINDOWS\DISPARAM.INI
[2011/04/18 10:46:55 | 000,783,644 | —- | C] () – C:\WINDOWS\System32\igkrng600.bin
[2011/04/18 10:46:55 | 000,201,496 | —- | C] () – C:\WINDOWS\System32\igfcg600m.bin
[2011/04/18 10:46:55 | 000,145,804 | —- | C] () – C:\WINDOWS\System32\igcompkrng600.bin
[2011/04/18 10:46:55 | 000,004,096 | —- | C] ( ) – C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/04/18 10:46:55 | 000,000,151 | —- | C] () – C:\WINDOWS\System32\GfxUI.exe.config
[2011/04/18 10:46:28 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\drivers\IntelMEFWVer.dll
[2011/04/15 17:59:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/15 17:55:18 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/15 12:49:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/15 12:48:39 | 000,316,360 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2012/07/20 12:29:02 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/07/20 15:04:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/07/16 15:38:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2012/05/11 17:16:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2012/07/20 15:00:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/04/18 11:24:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/08/08 16:55:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/20 12:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Townhome\Application Data\AVG
[2012/07/18 12:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Townhome\Application Data\com.essexreddevelopment.mergepdfmac
[2012/07/18 12:25:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Townhome\Application Data\Easy Thumbnails
[2012/07/18 11:58:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Townhome\Application Data\Fujitsu
[2012/07/18 12:25:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Townhome\Application Data\PCPro
[2012/07/18 11:57:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Townhome\Application Data\PFU
[2012/07/18 11:57:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Townhome\Application Data\Windows Desktop Search
[2012/07/18 15:38:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Townhome\Application Data\Windows Search
[2012/07/20 15:09:39 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job
[2012/07/20 15:09:38 | 000,000,406 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2012/07/20 15:09:39 | 000,000,412 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Signature Update.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2011/04/15 17:57:45 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/07/19 15:01:01 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/07/19 15:04:20 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/07/19 15:18:29 | 000,021,418 | —- | M] () – C:\ComboFix.txt
[2011/04/15 17:57:45 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/07/18 10:48:06 | 000,000,009 | —- | M] () – C:\END
[2011/04/15 17:57:45 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/04/15 17:57:45 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 03:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 03:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/07/20 15:06:00 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/04/18 10:51:40 | 000,002,089 | —- | M] () – C:\RHDSetup.log
[2012/07/19 15:20:34 | 000,000,392 | —- | M] () – C:\rkill.log

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011/04/15 17:57:28 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/02/09 15:46:28 | 000,049,152 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2011/04/15 12:47:53 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2011/04/15 12:47:53 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2011/04/15 12:47:53 | 000,909,312 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/04/15 17:57:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/07/18 11:57:40 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Townhome\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2012/07/18 11:57:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\Townhome\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/07/20 16:31:27 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Townhome\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-19 15:39:25

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

DDS

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 16:45:11.50 on Fri 07/20/2012
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_31
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3241.1942 [GMT -4:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Forefront Client Security *Enabled/Updated* {926A3D4F-E4E7-4F47-9902-4EDD55FFE1AF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTDCPL.EXE
C:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Townhome\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = https://www.htagateway.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Microsoft Forefront Client Security Antimalware Service] "c:\program files\microsoft forefront\client security\client\antimalware\MSASCui.exe" -hide
mRun: [IMSS] "c:\program files\intel\intel® management engine components\imss\PIconStartup.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTDCPL.EXE
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\oem\12.0\sharedcom\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "c:\program files\roxio\oem\roxio burn\RoxioBurnLauncher.exe"
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\cardmi~1.lnk - c:\program files\pfu\scansnap\cardminder\CardLauncher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\conver~1.lnk - c:\program files\pfu\scansnap\organizer\PfuSsOrgOcrChk.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\scansn~1.lnk - c:\program files\pfu\scansnap\driver\PfuSsMon.exe
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: hometownamerica.com
Trusted Zone: hometownamerica.net
Trusted Zone: htagateway.com
Trusted Zone: htaonline.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342729240296
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} - hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://akamaicdn.webex.com/client/WBXclient-T27L10NSP24-10113/support/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\townhome\applic~1\mozilla\firefox\profiles\uhwj9837.default\
FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\windows\npMSDM.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1165635.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll
.
============= SERVICES / DRIVERS ===============
.
R2 FCSAM;Microsoft Forefront Client Security Antimalware Service;c:\program files\microsoft forefront\client security\client\antimalware\MsMpEng.exe [2011-1-8 16896]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2011-4-18 2656280]
R3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\drivers\e1c5132.sys [2011-4-18 174248]
R3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2011-4-18 260864]
R3 MEI;Intel® Management Engine Interface;c:\windows\system32\drivers\HECI.sys [2011-4-18 41088]
R3 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 71296]
S0 cerc6;cerc6; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\common files\roxio shared\oem\12.0\sharedcom\RoxWatch12OEM.exe [2010-9-4 219632]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-30 250056]
S3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [2011-10-24 829152]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-7-20 113120]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files\common files\roxio shared\oem\12.0\sharedcom\RoxMediaDB12OEM.exe [2010-9-4 1116656]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 FcsSas;Microsoft Forefront Client Security State Assessment Service;c:\program files\microsoft forefront\client security\client\ssa\FcsSas.exe [2007-4-6 73120]
.
=============== Created Last 30 ================
.
2012-07-20 20:42:34 6891424 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft forefront\client security\client\antimalware\definition updates\{10c5411b-ba7d-4ade-9d0b-62936e93c4a6}\mpengine.dll
2012-07-20 16:40:57 ——– d—–w- c:\docume~1\townhome\applic~1\AVG
2012-07-20 16:29:02 ——– d–h–w- c:\docume~1\alluse~1\applic~1\Common Files
2012-07-20 16:29:02 ——– d—–w- c:\docume~1\alluse~1\applic~1\MFAData
2012-07-19 20:17:25 ——– d—–w- c:\program files\Trend Micro
2012-07-19 19:04:13 ——– d-sha-r- C:\cmdcons
2012-07-19 19:01:30 98816 —-a-w- c:\windows\sed.exe
2012-07-19 19:01:30 518144 —-a-w- c:\windows\SWREG.exe
2012-07-19 19:01:30 256000 —-a-w- c:\windows\PEV.exe
2012-07-19 19:01:30 208896 —-a-w- c:\windows\MBR.exe
2012-07-19 18:46:55 ——– d—–w- c:\docume~1\townhome\applic~1\Malwarebytes
2012-07-19 16:47:39 ——– d-sh–w- c:\documents and settings\townhome\IECompatCache
2012-07-18 21:58:26 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\Mozilla
2012-07-18 19:38:39 ——– d—–w- c:\docume~1\townhome\applic~1\Windows Search
2012-07-18 19:01:21 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\Temp
2012-07-18 16:25:14 ——– d—–w- c:\docume~1\townhome\applic~1\PCPro
2012-07-18 16:25:07 ——– d—–w- c:\docume~1\townhome\applic~1\Easy Thumbnails
2012-07-18 16:25:00 ——– d—–w- c:\docume~1\townhome\applic~1\com.essexreddevelopment.mergepdfmac
2012-07-18 16:23:15 ——– d—–w- c:\documents and settings\townhome\usrusmt2.tmp
2012-07-18 16:00:02 99840 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\usmt\iconlib.dll
2012-07-18 15:59:22 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\LogMeIn Rescue Applet
2012-07-18 15:58:17 ——– d-sh–w- c:\documents and settings\townhome\PrivacIE
2012-07-18 15:58:16 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\Conduit
2012-07-18 15:58:00 ——– d—–w- c:\docume~1\townhome\locals~1\applic~1\Adobe
2012-07-18 15:58:00 ——– d—–w- c:\docume~1\townhome\applic~1\Fujitsu
2012-07-18 15:30:04 ——– d—–w- C:\TedBackup
2012-07-18 14:47:51 ——– d—–w- c:\program files\Conduit
2012-07-16 20:59:54 ——– dc-h–w- c:\windows\ie8
2012-07-16 19:42:15 ——– d—–w- c:\program files\Spybot - Search & Destroy
2012-07-16 19:42:15 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2012-07-16 19:38:08 4269368 —-a-w- c:\windows\uninst.exe
2012-07-16 19:38:07 ——– d—–w- c:\docume~1\alluse~1\applic~1\PC1Data
2012-07-13 15:22:10 ——– d—–w- c:\windows\system32\Adobe
2012-07-12 20:08:26 ——– d—–w- c:\program files\MSECache
2012-07-12 20:06:04 ——– d—–w- c:\program files\Microsoft Download Manager
.
==================== Find3M ====================
.
2012-07-19 16:20:52 90112 —-a-w- c:\windows\DUMP38a4.tmp
2012-07-11 18:16:06 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 18:16:05 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:29:09 1875072 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50:25 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50:25 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 21:35:26 222448 —-a-w- c:\windows\system32\muweb.dll
2012-06-04 04:32:08 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19:44 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19:38 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:18:58 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18:58 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08:26 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42:33 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42:33 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:02 385024 ——w- c:\windows\system32\html.iec
2012-05-04 13:24:46 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:41:08 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST95005620AS rev.DEM3 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8AC344B1]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8ac3b93c]; MOV EAX, [0x8ac3bab0]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1B0] -> \Device\Harddisk0\DR0[0x8AF68AB8]
3 CLASSPNP[0xB98E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1B0] -> [0x8A8428E0]
\Driver\atapi[0x8AC532D8] -> IRP_MJ_CREATE -> 0x8AC344B1
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8AC342E2
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:46:43.85 ===============
Hi tedjhammond,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download the latest version of TDSSKiller from here and save it to your Desktop.



A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI