This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows XP "system progressive protection" already fixed by

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got this backup '02 XP Professional computer up and running (though I'm sure there are still nasties on it I can't see). It was originally infected with "system progressive protection". Standard symptoms: no .exe files, no control panel, giving us ridiculous over-explanatory warnings like "Do you want to visit this unsecure site and allow keyloggers to send your personal info?".

First, off a self-help tutorial, I logged into safe mode w/ networking, ran rKill, and then ran mbam. Malwarebytes found 5 things to remove (fairly easy to find things any beginner could remove by just doing a windows search of the virus name), but the system was still infected with no visible change when I got back into normal mode.
Later (without turning off our firewall or disabling windows automatic virus protection, it's been awhile and I'm trying to re-learn everything I forgot a decade ago), I got into safemode w/ networking, made sure there was no proxy server listed under our IE LAN settings, ran exe-fix.bat, ran Kapersky, then rKill, then mbam. They found nothing. Somewhere along the line, windows' built in virus killer that I should have disabled said it cleaned something off the computer…and now it appears to be running fine now.

We also have a newer windows 7 computer infected with (in my novice opinion) a more malicious virus that did things like kill my alt+f4 option and make me hard boot my computer after it wouldn't even let me shut it down. I plan to post it in it's own thread like I'm supposed to after our "cleaner" computer gets fixed, I'm just trying to offer the option of starting with that computer instead if someone here thinks that would be a better idea for whatever reason. I also have the past logs from the scans above saved on this older computer if they'd be helpful.

I can't stay online past 9pm PST, but I will definitely be back each new day this takes and staying until the end of the fix. Thanks to all of you that take the time to help us all!

OTL logs from 2002 Windows XP Professional with Service Pack 3 on a 32-bit computer:

OTL.Txt:

OTL logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS

Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Services (SafeList) ==========

SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\User\LOCALS~1\Temp\catchme.sys File not found
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EE 11 8B DA 82 F7 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4%7D:3.0.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/20 18:52:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/20 18:50:50 | 000,000,000 | —D | M]

[2013/01/08 16:04:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2013/01/10 21:02:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions
[2013/01/20 16:56:17 | 000,004,020 | —- | M] () (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi
[2013/01/20 18:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/20 18:52:01 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/01/04 19:45:12 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/01/04 19:45:12 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2013/01/20 17:38:43 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] J:\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = File not found
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230409023906 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{05DCF09B-B7E7-470F-884D-25C0A0CAA390}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/27 12:02:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/20 19:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\CC Support Logs
[2013/01/20 18:50:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/01/20 18:31:08 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/01/20 17:44:07 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\PCHealth
[2013/01/20 17:33:34 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/01/20 17:32:27 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/01/20 17:32:27 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/01/20 17:32:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/01/20 17:32:27 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/01/20 17:25:39 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/20 17:25:25 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/01/20 17:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2013/01/12 20:17:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/12 20:17:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/01/12 20:17:52 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/01/12 20:17:52 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/12 20:15:31 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2013/01/11 10:50:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Scansoft
[2013/01/10 21:03:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/10 21:01:35 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Sun
[2013/01/10 18:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2013/01/10 18:21:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2013/01/09 18:22:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Adobe
[2013/01/09 18:18:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2013/01/09 18:12:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2013/01/09 18:00:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2013/01/09 18:00:27 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/09 16:46:19 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\newebay
[2013/01/09 16:19:18 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Start Menu\Programs\IrfanView
[2013/01/09 16:19:16 | 000,000,000 | —D | C] – C:\Program Files\IrfanView
[2013/01/09 16:02:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Ahead
[2013/01/09 15:21:54 | 000,000,000 | R–D | C] – C:\Documents and Settings\User\Start Menu\Programs\Administrative Tools
[2013/01/09 14:45:03 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2013/01/09 14:45:02 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2013/01/09 12:40:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2013/01/09 12:40:13 | 000,779,704 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:40:12 | 000,859,072 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:40:12 | 000,260,528 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:40:06 | 000,174,000 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:40:06 | 000,173,992 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:40:06 | 000,093,640 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2013/01/09 12:32:01 | 020,293,080 | —- | C] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:37:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:36:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series User Registration
[2013/01/09 10:35:23 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/01/09 10:34:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2013/01/09 10:34:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\ScanSoft
[2013/01/09 10:34:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ScanSoft OmniPage SE 4
[2013/01/09 10:34:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2013/01/09 10:34:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2013/01/09 10:34:17 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2013/01/09 10:33:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2013/01/09 10:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2013/01/09 10:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series Manual
[2013/01/09 10:30:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:30:45 | 000,215,040 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM8U.DLL
[2013/01/09 10:30:42 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2013/01/09 10:30:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series
[2013/01/09 10:30:39 | 000,200,704 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470L.DLL
[2013/01/09 10:30:39 | 000,188,416 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\CNC470O.DLL
[2013/01/09 10:30:39 | 000,098,304 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470I.DLL
[2013/01/09 10:30:38 | 001,400,832 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470C.DLL
[2013/01/09 10:30:29 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/01/09 10:30:02 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/01/08 18:04:24 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/08 18:04:24 | 000,074,248 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/08 17:35:18 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/01/08 16:59:52 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2013/01/08 16:59:29 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/01/08 16:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Mozilla
[2013/01/08 16:04:48 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Mozilla
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/21 10:34:30 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 19:55:15 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2013/01/20 19:50:08 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/20 19:50:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/20 17:38:43 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2013/01/10 18:21:42 | 000,001,771 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/01/10 18:21:42 | 000,001,765 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/01/09 18:17:34 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 18:00:00 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\defrag.job
[2013/01/09 17:07:40 | 000,003,584 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/09 16:19:18 | 000,000,685 | —- | M] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:39:55 | 000,093,640 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:51 | 000,260,528 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:39:50 | 000,174,000 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:39:50 | 000,173,992 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:39:50 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/09 12:39:49 | 000,859,072 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:39:49 | 000,779,704 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:35:39 | 000,000,742 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:36:55 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | M] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | M] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/09 10:27:11 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2013/01/08 18:23:34 | 000,178,648 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/08 18:08:17 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/08 18:04:25 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/08 18:04:24 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 18:34:38 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2013/01/20 17:33:37 | 000,000,211 | —- | C] () – C:\Boot.bak
[2013/01/20 17:33:34 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/01/20 17:32:27 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/01/20 17:32:27 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/01/20 17:32:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/01/20 17:32:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/01/20 17:32:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/01/10 18:21:42 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/01/10 18:21:36 | 000,001,765 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/01/09 18:17:33 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/01/09 18:17:33 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | C] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:35:39 | 000,000,742 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2013/01/09 10:36:55 | 000,001,685 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/12/18 18:42:08 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/12/13 20:37:49 | 000,003,584 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/04 10:39:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\User\Application Data\wklnhst.dat

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/10/15 17:00:10 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 04:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/20 17:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/09 10:30:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:37:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:34:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/12/04 11:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\OpenOffice.org
[2013/01/09 10:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ScanSoft

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.SCF >
[2004/08/04 04:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2007/04/02 21:09:24 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2009/06/28 23:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 21:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2QFE\iexplore.exe
[2009/04/24 21:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 21:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/06/29 00:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2GDR\iexplore.exe
[2009/02/27 20:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\erdnt\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/27 20:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/24 21:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\iexplore.exe

< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2010/03/09 10:41:40 | 000,012,532 | —- | M] () MD5=C911CCDCFD72B36DCA1B99005E32E8C3 – C:\Program Files\Internet Explorer\iexplore.exe.exp.log

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-0A31FE70.PF >
[2013/01/20 17:25:32 | 000,017,902 | —- | M] () MD5=353F3AB8AA9281BE6FFA467C1EBE081A – C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/01/21 10:16:55 | 000,092,130 | —- | M] () MD5=14FFE76CCE0BD0BF18FD5851F514D5F5 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/04 04:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 11:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.CNF >
[2003/02/13 19:43:03 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb\_vti_pvt\services.cnf
[2003/07/15 14:54:19 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb2\_vti_pvt\services.cnf
[2003/07/15 15:10:48 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb3\_vti_pvt\services.cnf
[2003/07/15 15:27:05 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb4\_vti_pvt\services.cnf
[2003/07/15 15:32:39 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb5\_vti_pvt\services.cnf
[2003/11/05 11:58:40 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb6\_vti_pvt\services.cnf
[2003/11/05 12:00:32 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb7\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb8\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,074 | —- | M] () MD5=C781AE0262BEB173EFFB27E59A6E6F17 – C:\Documents and Settings\User\My Documents\My Webs\_vti_pvt\services.cnf

< MD5 for: SERVICES.EXE >
[2009/02/06 03:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.LNK >
[2008/12/27 12:03:05 | 000,001,602 | —- | M] () MD5=74AD18AA5CB38E317767841416B45580 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2004/08/04 04:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: SERVICES.RDB >
[2008/09/30 17:46:24 | 005,406,720 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2008/09/30 17:55:38 | 000,262,144 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb

< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/27 11:56:48 | 000,000,211 | —- | M] () – C:\Boot.bak
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2013/01/20 17:39:58 | 000,013,832 | —- | M] () – C:\ComboFix.txt
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 21:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 23:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/01/20 19:49:58 | 1509,138,432 | -HS- | M] () – C:\pagefile.sys
[2013/01/20 17:23:44 | 000,072,056 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_17.23.20_log.txt
[2013/01/20 19:28:07 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt
[2013/01/20 19:30:22 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.30.02_log.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/12/27 12:02:25 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/01 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8U.DLL
[2007/04/01 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8U.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/12/27 03:51:12 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/12/27 03:51:12 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/12/27 03:51:12 | 000,913,408 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/27 12:03:05 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/08/31 10:02:48 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/08/31 10:02:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2010/03/05 14:15:23 | 001,688,360 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\User\Desktop\SkypeSetup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-01-21 02:01:40

< End of report >

Extras.Txt:

OTL Extras logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS

Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP470_series" = Canon MP470 series
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.01)
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Canon MP470 series User Registration" = Canon MP470 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 18.0.1 (x86 en-US)" = Mozilla Firefox 18.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"S3" = VIA/S3G Display Driver
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTOverlay" = S3 S3Overlay

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/9/2010 2:35:03 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:35:27 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:36:48 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:38:13 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:38:42 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/9/2010 2:39:51 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:39:57 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:40:45 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:41:10 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:41:40 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

[ System Events ]
Error - 1/20/2013 10:31:27 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 10:39:24 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/20/2013 11:19:35 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/20/2013 11:19:51 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:20:52 PM | Computer Name = JOANIESYS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AmdK7 Fips MpFilter

Error - 1/20/2013 11:27:22 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:29:36 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:29:53 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:30:39 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:49:04 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}


< End of report >
Hello StellaLynn,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
10-4 OCD, Thank you! I'll be good. :notworthy: Also, in the time since my posting I've also noticed our flash player isn't working and our DSL internet connection seems to go out a lot. Some of my google searches are getting redirected. We're not symptom free at all.
Hi StellaLynn,

Let's get this computer clean first, then we can focus on the other machine(s).

= = = = = = = = = = = = = = = = = = = =

  • Please go to Start > Control Panel > Add Remove Programs.
  • Locate the following programs:
    • Java™ 6 Update 7
    • Java™ 6 Update 11
  • Click Remove and allow Windows to completely remove each one in turn.Then reboot your computer to complete this part of the process.
Next

There is a vulnerability with regards to Java and web browsers. Therefore, we recommend to disable java in web browsers.
More information can be found here: http://www.techsupportforum.com/forums/f50…ers-683721.html

Disable Java in Web Browsers

  • Click on the Start button and then click on the Control Panel option.
  • In the Control Panel Search enter Java Control Panel.
  • Click on the Java icon to open the Java Control Panel.
[external image: Posted Image]

Disable Java through the Java Control Panel

  • In the Java Control Panel, click on the Security tab.
  • Deselect the check box for Enable Java content in the browser. This will disable the Java plug-in in the browser.
  • Click Apply. When the Windows User Account Control (UAC) dialog appears, allow permissions to make the changes.
  • Click OK in the Java Plug-in confirmation window.
  • Restart the browser for changes to take effect.
[external image: Posted Image]

Next

I see from your logs that you have run both ComboFix and TDSSKiller. Locate the following logs and post them in you next reply.

  • C:\ComboFix.txt
  • C:\TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt
Next

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

In your next post please provide the following:
  • ComboFix.txt
  • TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt
  • aswMBR log
  • How is your computer running at the moment?
Wow, I"m sorry OCD. I didn't know that had been run. ComboFix anyway, glad we still have a computer I guess. I have assurance from the family that it won't happen again and nothing else has been downloaded or run that I don't know about. Geez, I had no idea about Java, I feel like a dolt.

Browser looks unhijacked, but flash is still down. Internet connection was a fairly infrequent problem, but so far, so good.

C:\ComboFix.txt

ComboFix 13-01-17.04 - User 01/20/2013 17:34:49.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.610 [GMT -8:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\User\Application Data\weaprt.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-12-21 to 2013-01-21 )))))))))))))))))))))))))))))))
.
.
2013-01-21 01:23 . 2013-01-21 01:23 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8620E2A7-9612-4BD5-B777-98F68F04A388}\MpKsl950deae0.sys
2013-01-21 01:18 . 2013-01-21 01:18 54016 —-a-w- c:\windows\system32\drivers\ruegmkm.sys
2013-01-21 01:08 . 2013-01-21 01:08 ——– d—–w- c:\documents and settings\User\Application Data\Malwarebytes
2013-01-21 00:41 . 2013-01-21 00:56 60872 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8620E2A7-9612-4BD5-B777-98F68F04A388}\offreg.dll
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-01-13 04:17 . 2012-12-15 00:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-01-13 04:15 . 2013-01-13 04:16 ——– d—–w- c:\documents and settings\Administrator
2013-01-11 18:50 . 2013-01-11 18:50 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Scansoft
2013-01-11 05:03 . 2013-01-21 01:18 ——– d—–w- c:\documents and settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
2013-01-11 05:01 . 2013-01-11 05:01 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Sun
2013-01-11 02:22 . 2013-01-11 02:22 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2013-01-11 02:09 . 2012-11-19 09:04 6812136 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8620E2A7-9612-4BD5-B777-98F68F04A388}\mpengine.dll
2013-01-10 02:22 . 2013-01-10 02:22 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Adobe
2013-01-10 02:18 . 2013-01-10 02:18 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2013-01-10 02:16 . 2013-01-10 02:16 ——– d—–w- c:\program files\Common Files\Adobe
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\MSXML 4.0
2013-01-10 00:19 . 2013-01-10 00:19 ——– d—–w- c:\program files\IrfanView
2013-01-10 00:02 . 2013-01-10 00:02 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Ahead
2013-01-09 22:45 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2013-01-09 22:45 . 2008-04-14 13:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2013-01-09 20:40 . 2013-01-09 20:39 779704 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 859072 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 93640 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-09 20:39 . 2013-01-09 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2013-01-09 18:37 . 2013-01-09 18:37 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2013-01-09 18:35 . 2008-04-14 08:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2013-01-09 18:35 . 2008-04-14 08:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\User\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\ScanSoft
2013-01-09 18:33 . 2013-01-09 18:33 ——– d—–w- c:\program files\Common Files\CANON
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2013-01-09 18:30 . 2007-04-02 05:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 215040 —-a-w- c:\windows\system32\CNMLM8U.DLL
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-09 18:30 . 2007-03-23 16:29 98304 —-a-w- c:\windows\system32\CNC470I.DLL
2013-01-09 18:30 . 2007-03-19 10:21 200704 —-a-w- c:\windows\system32\CNC470L.DLL
2013-01-09 18:30 . 2007-03-15 14:12 188416 —-a-w- c:\windows\system32\CNC470O.DLL
2013-01-09 18:30 . 2007-03-23 16:30 1400832 —-a-w- c:\windows\system32\CNC470C.DLL
2013-01-09 18:30 . 2013-01-09 18:37 ——– d—–w- c:\program files\Canon
2013-01-09 02:04 . 2013-01-09 02:04 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-09 02:04 . 2013-01-09 02:04 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-09 01:35 . 2012-11-01 12:17 521728 -c—-w- c:\windows\system32\dllcache\jsdbgui.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2013-01-09 01:30 . 2012-11-19 09:04 6812136 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-09 00:59 . 2008-04-14 08:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2013-01-09 00:04 . 2013-01-09 00:04 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Mozilla
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 20:39 . 2008-12-27 20:36 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-12-16 12:23 . 2008-04-14 12:39 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-13 01:25 . 2008-04-14 08:00 1866368 —-a-w- c:\windows\system32\win32k.sys
2012-11-06 02:01 . 2008-04-14 12:42 1371648 —-a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:02 . 2008-04-14 12:41 375296 —-a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 12:42 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-01 12:17 . 2008-04-14 12:42 916992 —-a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 12:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-11-01 00:35 . 2008-04-14 07:07 385024 —-a-w- c:\windows\system32\html.iec
2013-01-05 03:45 . 2013-01-09 20:35 262704 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware (cleanup)"="c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll" [2012-12-15 1091432]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.285\SSScheduler.exe [N/A]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R1 MpKsl950deae0;MpKsl950deae0;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8620E2A7-9612-4BD5-B777-98F68F04A388}\MpKsl950deae0.sys [1/20/2013 5:23 PM 29904]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\McAfee Security Scan\3.0.285\McCHSvc.exe" –> c:\program files\McAfee Security Scan\3.0.285\McCHSvc.exe [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 86847787
*NewlyCreated* - MPKSL950DEAE0
*Deregistered* - 86847787
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-10 c:\windows\Tasks\defrag.job
- c:\windows\system32\cmd.exe [2008-04-14 12:42]
.
2013-01-21 c:\windows\Tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\
FF - ExtSQL: 2013-01-20 16:56; {3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}; c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-weaprt - c:\documents and settings\User\Application Data\weaprt.dll
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-20 17:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-01-20 17:39:57
ComboFix-quarantined-files.txt 2013-01-21 01:39
.
Pre-Run: 68,061,167,616 bytes free
Post-Run: 68,254,285,824 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - DEB9934EE223B473B51CDCE8C642E503

TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt

19:27:41.0343 0452 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
19:27:41.0359 0452 ============================================================
19:27:41.0359 0452 Current date / time: 2013/01/20 19:27:41.0359
19:27:41.0359 0452 SystemInfo:
19:27:41.0359 0452
19:27:41.0359 0452 OS Version: 5.1.2600 ServicePack: 3.0
19:27:41.0359 0452 Product type: Workstation
19:27:41.0359 0452 ComputerName: JOANIESYS
19:27:41.0359 0452 UserName: Administrator
19:27:41.0359 0452 Windows directory: C:\WINDOWS
19:27:41.0359 0452 System windows directory: C:\WINDOWS
19:27:41.0359 0452 Processor architecture: Intel x86
19:27:41.0359 0452 Number of processors: 1
19:27:41.0359 0452 Page size: 0x1000
19:27:41.0359 0452 Boot type: Safe boot with network
19:27:41.0359 0452 ============================================================
19:27:43.0890 0452 Drive \Device\Harddisk0\DR0 - Size: 0x1315740000 (76.34 Gb), SectorSize: 0x200, Cylinders: 0x295B, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000054
19:27:44.0015 0452 Drive \Device\Harddisk5\DR10 - Size: 0xE8200000 (3.63 Gb), SectorSize: 0x1000, Cylinders: 0x3B, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:27:44.0015 0452 ============================================================
19:27:44.0015 0452 \Device\Harddisk0\DR0:
19:27:44.0015 0452 MBR partitions:
19:27:44.0015 0452 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x98A5361
19:27:44.0015 0452 \Device\Harddisk5\DR10:
19:27:44.0031 0452 MBR partitions:
19:27:44.0031 0452 \Device\Harddisk5\DR10\Partition1: MBR, Type 0xB, StartLBA 0x3, BlocksNum 0xE81FD
19:27:44.0031 0452 ============================================================
19:27:44.0046 0452 C: <-> \Device\Harddisk0\DR0\Partition1
19:27:44.0046 0452 ============================================================
19:27:44.0046 0452 Initialize success
19:27:44.0046 0452 ============================================================
19:27:45.0890 0448 ============================================================
19:27:45.0890 0448 Scan started
19:27:45.0890 0448 Mode: Manual;
19:27:45.0890 0448 ============================================================
19:27:46.0968 0448 ================ Scan system memory ========================
19:27:46.0968 0448 System memory - ok
19:27:46.0984 0448 ================ Scan services =============================
19:27:47.0046 0448 Abiosdsk - ok
19:27:47.0078 0448 abp480n5 - ok
19:27:47.0156 0448 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
19:27:47.0156 0448 ACPI - ok
19:27:47.0218 0448 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
19:27:47.0218 0448 ACPIEC - ok
19:27:47.0250 0448 adpu160m - ok
19:27:47.0312 0448 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
19:27:47.0312 0448 aec - ok
19:27:47.0375 0448 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
19:27:47.0390 0448 AFD - ok
19:27:47.0484 0448 [ 9C9D3B7A05445B1AB2DF4D0C4D6B77E8 ] AgereModemAudio C:\Program Files\LSI SoftModem\agrsmsvc.exe
19:27:47.0484 0448 AgereModemAudio - ok
19:27:47.0578 0448 [ 35C391E40471A0B479328FC7B1B5F40F ] AgereSoftModem C:\WINDOWS\system32\DRIVERS\AGRSM.sys
19:27:47.0609 0448 AgereSoftModem - ok
19:27:47.0656 0448 Aha154x - ok
19:27:47.0671 0448 aic78u2 - ok
19:27:47.0703 0448 aic78xx - ok
19:27:47.0828 0448 [ 8D6C30E515717248E0E52B85FD7AC466 ] ALCXWDM C:\WINDOWS\system32\drivers\ALCXWDM.SYS
19:27:47.0890 0448 ALCXWDM - ok
19:27:47.0968 0448 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
19:27:47.0968 0448 Alerter - ok
19:27:48.0015 0448 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
19:27:48.0015 0448 ALG - ok
19:27:48.0046 0448 AliIde - ok
19:27:48.0078 0448 [ 8FCE268CDBDD83B23419D1F35F42C7B1 ] AmdK7 C:\WINDOWS\system32\DRIVERS\amdk7.sys
19:27:48.0078 0448 AmdK7 - ok
19:27:48.0109 0448 amsint - ok
19:27:48.0156 0448 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
19:27:48.0171 0448 AppMgmt - ok
19:27:48.0203 0448 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
19:27:48.0218 0448 Arp1394 - ok
19:27:48.0234 0448 asc - ok
19:27:48.0265 0448 asc3350p - ok
19:27:48.0296 0448 asc3550 - ok
19:27:48.0343 0448 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
19:27:48.0343 0448 AsyncMac - ok
19:27:48.0390 0448 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
19:27:48.0390 0448 atapi - ok
19:27:48.0421 0448 Atdisk - ok
19:27:48.0437 0448 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
19:27:48.0437 0448 Atmarpc - ok
19:27:48.0484 0448 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
19:27:48.0484 0448 AudioSrv - ok
19:27:48.0546 0448 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
19:27:48.0546 0448 audstub - ok
19:27:48.0625 0448 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
19:27:48.0625 0448 Beep - ok
19:27:48.0687 0448 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
19:27:48.0734 0448 BITS - ok
19:27:48.0812 0448 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
19:27:48.0812 0448 Browser - ok
19:27:48.0984 0448 catchme - ok
19:27:49.0031 0448 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
19:27:49.0031 0448 cbidf2k - ok
19:27:49.0062 0448 cd20xrnt - ok
19:27:49.0093 0448 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
19:27:49.0093 0448 Cdaudio - ok
19:27:49.0140 0448 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
19:27:49.0140 0448 Cdfs - ok
19:27:49.0187 0448 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
19:27:49.0187 0448 Cdrom - ok
19:27:49.0203 0448 Changer - ok
19:27:49.0250 0448 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
19:27:49.0250 0448 CiSvc - ok
19:27:49.0281 0448 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
19:27:49.0281 0448 ClipSrv - ok
19:27:49.0312 0448 CmdIde - ok
19:27:49.0359 0448 COMSysApp - ok
19:27:49.0406 0448 Cpqarray - ok
19:27:49.0468 0448 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
19:27:49.0468 0448 CryptSvc - ok
19:27:49.0500 0448 dac2w2k - ok
19:27:49.0531 0448 dac960nt - ok
19:27:49.0609 0448 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
19:27:49.0625 0448 DcomLaunch - ok
19:27:49.0656 0448 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
19:27:49.0656 0448 Dhcp - ok
19:27:49.0718 0448 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
19:27:49.0718 0448 Disk - ok
19:27:49.0750 0448 dmadmin - ok
19:27:49.0812 0448 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
19:27:49.0843 0448 dmboot - ok
19:27:49.0875 0448 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
19:27:49.0875 0448 dmio - ok
19:27:49.0906 0448 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
19:27:49.0921 0448 dmload - ok
19:27:49.0937 0448 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
19:27:49.0937 0448 dmserver - ok
19:27:50.0000 0448 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
19:27:50.0000 0448 DMusic - ok
19:27:50.0046 0448 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
19:27:50.0046 0448 Dnscache - ok
19:27:50.0093 0448 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
19:27:50.0093 0448 Dot3svc - ok
19:27:50.0125 0448 dpti2o - ok
19:27:50.0156 0448 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
19:27:50.0156 0448 drmkaud - ok
19:27:50.0187 0448 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
19:27:50.0187 0448 EapHost - ok
19:27:50.0234 0448 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
19:27:50.0234 0448 ERSvc - ok
19:27:50.0296 0448 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
19:27:50.0312 0448 Eventlog - ok
19:27:50.0375 0448 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
19:27:50.0390 0448 EventSystem - ok
19:27:50.0437 0448 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
19:27:50.0437 0448 Fastfat - ok
19:27:50.0515 0448 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
19:27:50.0531 0448 FastUserSwitchingCompatibility - ok
19:27:50.0562 0448 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
19:27:50.0562 0448 Fdc - ok
19:27:50.0640 0448 [ E7072827D0B5F9BD99D6961571A38973 ] FET5X86V C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
19:27:50.0640 0448 FET5X86V - ok
19:27:50.0656 0448 [ E7072827D0B5F9BD99D6961571A38973 ] FETND5BV C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
19:27:50.0656 0448 FETND5BV - ok
19:27:50.0718 0448 [ E9648254056BCE81A85380C0C3647DC4 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5.sys
19:27:50.0718 0448 FETNDIS - ok
19:27:50.0750 0448 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
19:27:50.0750 0448 Fips - ok
19:27:50.0781 0448 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
19:27:50.0781 0448 Flpydisk - ok
19:27:50.0859 0448 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
19:27:50.0859 0448 FltMgr - ok
19:27:50.0890 0448 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
19:27:50.0890 0448 Fs_Rec - ok
19:27:50.0921 0448 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
19:27:50.0937 0448 Ftdisk - ok
19:27:51.0000 0448 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
19:27:51.0000 0448 Gpc - ok
19:27:51.0062 0448 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
19:27:51.0078 0448 helpsvc - ok
19:27:51.0093 0448 HidServ - ok
19:27:51.0171 0448 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
19:27:51.0171 0448 hidusb - ok
19:27:51.0203 0448 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
19:27:51.0218 0448 hkmsvc - ok
19:27:51.0234 0448 hpn - ok
19:27:51.0296 0448 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
19:27:51.0312 0448 HTTP - ok
19:27:51.0375 0448 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
19:27:51.0375 0448 HTTPFilter - ok
19:27:51.0406 0448 i2omgmt - ok
19:27:51.0437 0448 i2omp - ok
19:27:51.0500 0448 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
19:27:51.0500 0448 i8042prt - ok
19:27:51.0609 0448 [ 2F95BEF56AEEEB45DE55EC44668E2695 ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
19:27:51.0609 0448 IJPLMSVC - ok
19:27:51.0656 0448 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
19:27:51.0656 0448 Imapi - ok
19:27:51.0703 0448 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
19:27:51.0718 0448 ImapiService - ok
19:27:51.0765 0448 ini910u - ok
19:27:51.0812 0448 IntelIde - ok
19:27:51.0859 0448 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
19:27:51.0859 0448 Ip6Fw - ok
19:27:51.0890 0448 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
19:27:51.0890 0448 IpFilterDriver - ok
19:27:51.0921 0448 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
19:27:51.0921 0448 IpInIp - ok
19:27:51.0968 0448 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
19:27:51.0968 0448 IpNat - ok
19:27:52.0031 0448 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
19:27:52.0031 0448 IPSec - ok
19:27:52.0078 0448 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
19:27:52.0078 0448 IRENUM - ok
19:27:52.0140 0448 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
19:27:52.0140 0448 isapnp - ok
19:27:52.0296 0448 [ 6F9AE59017FAE7E111265394967E846E ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
19:27:52.0328 0448 JavaQuickStarterService - ok
19:27:52.0375 0448 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
19:27:52.0375 0448 Kbdclass - ok
19:27:52.0421 0448 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
19:27:52.0421 0448 kbdhid - ok
19:27:52.0468 0448 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
19:27:52.0484 0448 kmixer - ok
19:27:52.0531 0448 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
19:27:52.0531 0448 KSecDD - ok
19:27:52.0578 0448 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
19:27:52.0593 0448 LanmanServer - ok
19:27:52.0656 0448 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
19:27:52.0656 0448 lanmanworkstation - ok
19:27:52.0687 0448 lbrtfdc - ok
19:27:52.0765 0448 [ 9696786759C4B43FA5C894747E893EA2 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
19:27:52.0765 0448 LightScribeService - ok
19:27:52.0796 0448 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
19:27:52.0812 0448 LmHosts - ok
19:27:52.0843 0448 McComponentHostService - ok
19:27:52.0890 0448 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
19:27:52.0890 0448 Messenger - ok
19:27:52.0921 0448 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
19:27:52.0937 0448 mnmdd - ok
19:27:52.0968 0448 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
19:27:52.0968 0448 mnmsrvc - ok
19:27:53.0031 0448 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
19:27:53.0031 0448 Modem - ok
19:27:53.0093 0448 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
19:27:53.0093 0448 Mouclass - ok
19:27:53.0140 0448 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
19:27:53.0140 0448 mouhid - ok
19:27:53.0156 0448 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
19:27:53.0156 0448 MountMgr - ok
19:27:53.0234 0448 [ 730A519505621DF46BCBF9CDAC9FB6AD ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
19:27:53.0234 0448 MozillaMaintenance - ok
19:27:53.0281 0448 [ FEE0BADED54222E9F1DAE9541212AAB1 ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys
19:27:53.0296 0448 MpFilter - ok
19:27:53.0312 0448 mraid35x - ok
19:27:53.0375 0448 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
19:27:53.0390 0448 MRxDAV - ok
19:27:53.0468 0448 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
19:27:53.0500 0448 MRxSmb - ok
19:27:53.0562 0448 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
19:27:53.0562 0448 MSDTC - ok
19:27:53.0593 0448 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
19:27:53.0593 0448 Msfs - ok
19:27:53.0625 0448 MSIServer - ok
19:27:53.0687 0448 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
19:27:53.0687 0448 MSKSSRV - ok
19:27:53.0796 0448 [ CFCE43B70CA0CC4DCC8ADB62B792B173 ] MsMpSvc c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
19:27:53.0796 0448 MsMpSvc - ok
19:27:53.0843 0448 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
19:27:53.0859 0448 MSPCLOCK - ok
19:27:53.0890 0448 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
19:27:53.0890 0448 MSPQM - ok
19:27:53.0937 0448 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
19:27:53.0937 0448 mssmbios - ok
19:27:53.0984 0448 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
19:27:53.0984 0448 Mup - ok
19:27:54.0046 0448 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
19:27:54.0046 0448 napagent - ok
19:27:54.0093 0448 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
19:27:54.0093 0448 NDIS - ok
19:27:54.0156 0448 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
19:27:54.0156 0448 NdisTapi - ok
19:27:54.0187 0448 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
19:27:54.0187 0448 Ndisuio - ok
19:27:54.0218 0448 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
19:27:54.0218 0448 NdisWan - ok
19:27:54.0265 0448 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
19:27:54.0265 0448 NDProxy - ok
19:27:54.0296 0448 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
19:27:54.0296 0448 NetBIOS - ok
19:27:54.0359 0448 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
19:27:54.0359 0448 NetBT - ok
19:27:54.0406 0448 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
19:27:54.0421 0448 NetDDE - ok
19:27:54.0453 0448 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
19:27:54.0453 0448 NetDDEdsdm - ok
19:27:54.0531 0448 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
19:27:54.0531 0448 Netlogon - ok
19:27:54.0578 0448 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
19:27:54.0578 0448 Netman - ok
19:27:54.0625 0448 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
19:27:54.0625 0448 NIC1394 - ok
19:27:54.0687 0448 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
19:27:54.0703 0448 Nla - ok
19:27:54.0734 0448 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
19:27:54.0734 0448 Npfs - ok
19:27:54.0781 0448 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
19:27:54.0812 0448 Ntfs - ok
19:27:54.0828 0448 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
19:27:54.0843 0448 NtLmSsp - ok
19:27:54.0906 0448 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
19:27:54.0921 0448 NtmsSvc - ok
19:27:54.0953 0448 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
19:27:54.0953 0448 Null - ok
19:27:55.0000 0448 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
19:27:55.0000 0448 NwlnkFlt - ok
19:27:55.0031 0448 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
19:27:55.0031 0448 NwlnkFwd - ok
19:27:55.0062 0448 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
19:27:55.0062 0448 ohci1394 - ok
19:27:55.0125 0448 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
19:27:55.0125 0448 Parport - ok
19:27:55.0156 0448 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
19:27:55.0156 0448 PartMgr - ok
19:27:55.0187 0448 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
19:27:55.0187 0448 ParVdm - ok
19:27:55.0218 0448 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
19:27:55.0218 0448 PCI - ok
19:27:55.0250 0448 PCIDump - ok
19:27:55.0296 0448 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
19:27:55.0296 0448 PCIIde - ok
19:27:55.0359 0448 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
19:27:55.0359 0448 Pcmcia - ok
19:27:55.0390 0448 PDCOMP - ok
19:27:55.0421 0448 PDFRAME - ok
19:27:55.0453 0448 PDRELI - ok
19:27:55.0484 0448 PDRFRAME - ok
19:27:55.0515 0448 perc2 - ok
19:27:55.0531 0448 perc2hib - ok
19:27:55.0640 0448 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
19:27:55.0656 0448 PlugPlay - ok
19:27:55.0687 0448 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
19:27:55.0687 0448 PolicyAgent - ok
19:27:55.0703 0448 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
19:27:55.0703 0448 PptpMiniport - ok
19:27:55.0734 0448 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
19:27:55.0750 0448 ProtectedStorage - ok
19:27:55.0765 0448 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
19:27:55.0781 0448 PSched - ok
19:27:55.0812 0448 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
19:27:55.0812 0448 Ptilink - ok
19:27:55.0828 0448 ql1080 - ok
19:27:55.0859 0448 Ql10wnt - ok
19:27:55.0906 0448 ql12160 - ok
19:27:55.0937 0448 ql1240 - ok
19:27:55.0953 0448 ql1280 - ok
19:27:55.0984 0448 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
19:27:55.0984 0448 RasAcd - ok
19:27:56.0031 0448 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
19:27:56.0046 0448 RasAuto - ok
19:27:56.0078 0448 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
19:27:56.0078 0448 Rasl2tp - ok
19:27:56.0125 0448 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
19:27:56.0140 0448 RasMan - ok
19:27:56.0171 0448 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
19:27:56.0171 0448 RasPppoe - ok
19:27:56.0203 0448 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
19:27:56.0203 0448 Raspti - ok
19:27:56.0250 0448 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
19:27:56.0250 0448 Rdbss - ok
19:27:56.0281 0448 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
19:27:56.0281 0448 RDPCDD - ok
19:27:56.0328 0448 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
19:27:56.0343 0448 rdpdr - ok
19:27:56.0406 0448 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
19:27:56.0406 0448 RDPWD - ok
19:27:56.0453 0448 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
19:27:56.0468 0448 RDSessMgr - ok
19:27:56.0500 0448 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
19:27:56.0500 0448 redbook - ok
19:27:56.0562 0448 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
19:27:56.0562 0448 RemoteAccess - ok
19:27:56.0625 0448 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
19:27:56.0625 0448 RemoteRegistry - ok
19:27:56.0671 0448 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
19:27:56.0671 0448 RpcLocator - ok
19:27:56.0734 0448 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
19:27:56.0750 0448 RpcSs - ok
19:27:56.0781 0448 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
19:27:56.0796 0448 RSVP - ok
19:27:56.0859 0448 [ D507C1400284176573224903819FFDA3 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
19:27:56.0859 0448 rtl8139 - ok
19:27:56.0875 0448 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
19:27:56.0875 0448 SamSs - ok
19:27:56.0906 0448 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
19:27:56.0921 0448 SCardSvr - ok
19:27:56.0968 0448 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
19:27:56.0984 0448 Schedule - ok
19:27:57.0031 0448 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
19:27:57.0031 0448 Secdrv - ok
19:27:57.0062 0448 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
19:27:57.0062 0448 seclogon - ok
19:27:57.0093 0448 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
19:27:57.0093 0448 SENS - ok
19:27:57.0156 0448 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
19:27:57.0156 0448 serenum - ok
19:27:57.0187 0448 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
19:27:57.0187 0448 Serial - ok
19:27:57.0250 0448 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
19:27:57.0250 0448 Sfloppy - ok
19:27:57.0296 0448 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
19:27:57.0312 0448 SharedAccess - ok
19:27:57.0343 0448 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
19:27:57.0359 0448 ShellHWDetection - ok
19:27:57.0390 0448 Simbad - ok
19:27:57.0421 0448 Sparrow - ok
19:27:57.0484 0448 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
19:27:57.0484 0448 splitter - ok
19:27:57.0546 0448 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
19:27:57.0546 0448 Spooler - ok
19:27:57.0593 0448 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
19:27:57.0593 0448 sr - ok
19:27:57.0625 0448 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
19:27:57.0640 0448 srservice - ok
19:27:57.0718 0448 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
19:27:57.0718 0448 Srv - ok
19:27:57.0781 0448 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
19:27:57.0781 0448 SSDPSRV - ok
19:27:57.0859 0448 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
19:27:57.0859 0448 stisvc - ok
19:27:57.0906 0448 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
19:27:57.0906 0448 swenum - ok
19:27:57.0937 0448 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
19:27:57.0937 0448 swmidi - ok
19:27:57.0968 0448 SwPrv - ok
19:27:58.0000 0448 symc810 - ok
19:27:58.0031 0448 symc8xx - ok
19:27:58.0062 0448 sym_hi - ok
19:27:58.0078 0448 sym_u3 - ok
19:27:58.0125 0448 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
19:27:58.0125 0448 sysaudio - ok
19:27:58.0203 0448 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
19:27:58.0203 0448 SysmonLog - ok
19:27:58.0250 0448 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
19:27:58.0265 0448 TapiSrv - ok
19:27:58.0328 0448 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
19:27:58.0343 0448 Tcpip - ok
19:27:58.0390 0448 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
19:27:58.0406 0448 TDPIPE - ok
19:27:58.0437 0448 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
19:27:58.0437 0448 TDTCP - ok
19:27:58.0468 0448 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
19:27:58.0468 0448 TermDD - ok
19:27:58.0531 0448 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
19:27:58.0531 0448 TermService - ok
19:27:58.0578 0448 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
19:27:58.0578 0448 Themes - ok
19:27:58.0640 0448 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
19:27:58.0656 0448 TlntSvr - ok
19:27:58.0671 0448 TosIde - ok
19:27:58.0703 0448 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
19:27:58.0718 0448 TrkWks - ok
19:27:58.0765 0448 [ D85938F272D1BCF3DB3A31FC0A048928 ] uagp35 C:\WINDOWS\system32\DRIVERS\uagp35.sys
19:27:58.0765 0448 uagp35 - ok
19:27:58.0796 0448 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
19:27:58.0796 0448 Udfs - ok
19:27:58.0812 0448 ultra - ok
19:27:58.0906 0448 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
19:27:58.0921 0448 Update - ok
19:27:58.0968 0448 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
19:27:58.0968 0448 upnphost - ok
19:27:59.0000 0448 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
19:27:59.0000 0448 UPS - ok
19:27:59.0078 0448 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
19:27:59.0078 0448 usbccgp - ok
19:27:59.0125 0448 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
19:27:59.0125 0448 usbehci - ok
19:27:59.0171 0448 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
19:27:59.0171 0448 usbhub - ok
19:27:59.0203 0448 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
19:27:59.0203 0448 usbprint - ok
19:27:59.0250 0448 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
19:27:59.0250 0448 usbscan - ok
19:27:59.0281 0448 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
19:27:59.0281 0448 usbstor - ok
19:27:59.0296 0448 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
19:27:59.0312 0448 usbuhci - ok
19:27:59.0328 0448 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
19:27:59.0343 0448 VgaSave - ok
19:27:59.0375 0448 [ 949F86F5A8E493574BBB830C3D18E4A9 ] viagfx C:\WINDOWS\system32\DRIVERS\vtmini.sys
19:27:59.0375 0448 viagfx - ok
19:27:59.0406 0448 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
19:27:59.0406 0448 ViaIde - ok
19:27:59.0437 0448 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
19:27:59.0437 0448 VolSnap - ok
19:27:59.0500 0448 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
19:27:59.0515 0448 VSS - ok
19:27:59.0562 0448 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
19:27:59.0578 0448 W32Time - ok
19:27:59.0625 0448 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
19:27:59.0625 0448 Wanarp - ok
19:27:59.0671 0448 WDICA - ok
19:27:59.0703 0448 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
19:27:59.0718 0448 wdmaud - ok
19:27:59.0750 0448 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
19:27:59.0750 0448 WebClient - ok
19:27:59.0843 0448 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
19:27:59.0843 0448 winmgmt - ok
19:27:59.0953 0448 [ C7E39EA41233E9F5B86C8DA3A9F1E4A8 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
19:27:59.0953 0448 WmdmPmSN - ok
19:28:00.0031 0448 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
19:28:00.0062 0448 Wmi - ok
19:28:00.0125 0448 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
19:28:00.0140 0448 WmiApSrv - ok
19:28:00.0203 0448 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
19:28:00.0203 0448 WS2IFSL - ok
19:28:00.0250 0448 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
19:28:00.0250 0448 wscsvc - ok
19:28:00.0312 0448 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
19:28:00.0328 0448 wuauserv - ok
19:28:00.0390 0448 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
19:28:00.0421 0448 WZCSVC - ok
19:28:00.0484 0448 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
19:28:00.0484 0448 xmlprov - ok
19:28:00.0515 0448 ================ Scan global ===============================
19:28:00.0625 0448 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
19:28:00.0671 0448 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
19:28:00.0703 0448 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
19:28:00.0734 0448 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
19:28:00.0750 0448 [Global] - ok
19:28:00.0750 0448 ================ Scan MBR ==================================
19:28:00.0781 0448 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
19:28:00.0937 0448 \Device\Harddisk0\DR0 - ok
19:28:00.0984 0448 [ 0519801742033545B239298C04AE2289 ] \Device\Harddisk5\DR10
19:28:01.0015 0448 \Device\Harddisk5\DR10 - ok
19:28:01.0031 0448 ================ Scan VBR ==================================
19:28:01.0046 0448 [ 6F8625BCB7EB9F52CA78992668593D28 ] \Device\Harddisk0\DR0\Partition1
19:28:01.0046 0448 \Device\Harddisk0\DR0\Partition1 - ok
19:28:01.0062 0448 [ C3E4A1591C5D7962E7FF8AE1E10647D7 ] \Device\Harddisk5\DR10\Partition1
19:28:01.0062 0448 \Device\Harddisk5\DR10\Partition1 - ok
19:28:01.0078 0448 ============================================================
19:28:01.0078 0448 Scan finished
19:28:01.0078 0448 ============================================================
19:28:01.0109 0456 Detected object count: 0
19:28:01.0109 0456 Actual detected object count: 0
19:28:07.0062 0468 Deinitialize success

Attachments:

Hi StellaLynn,

Please do not attach the logs unless requested to do so. Copy and paste the logs into the reply window.

The aswMBR log you attached is not the correct file. I need to see the log located here:
C:\Documents and Settings\User\Desktop\aswMBR.txt

Locate the MBR.dat file on your desktop, zip (compress) the file and attach to your next reply

Next

Please go to: VirusTotal
  • [external image: Posted Image]

  • Click the Browse button and search for the following file: c:\windows\system32\drivers\ruegmkm.sys
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Next

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

http://forums.whatthetech.com/index.php?showtopic=125349

File::
c:\Program files\McAfee Security Scan\3.0.285\McCHSvc.exe

Folder::
c:\Program files\McAfee Security Scan

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"=-

Driver::
McComponentHostService

Suspect::
c:\windows\system32\drivers\ruegmkm.sys

ClearJavaCache::

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.

Next

Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices >> select Only Problems
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.

In your next post please provide the following:
  • aswMBR.txt
  • Attach the MBR.zip file
  • VirusTotal results
  • ComboFix.txt
  • Result.txt
  • How is the computer running?
Sorry. Here's the .txt file, but I can't find the .dat anywhere! I'm showing extensions and hidden files in the folder options, but I don't see it on the desktop or in window search for the name or just data files. aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-01-23 14:49:47 —————————– 14:49:47.171 OS Version: Windows 5.1.2600 Service Pack 3 14:49:47.171 Number of processors: 1 586 0xA00 14:49:47.171 ComputerName: JOANIESYS UserName: User 14:49:47.890 Initialize success 14:53:33.046 AVAST engine defs: 13012300 14:58:11.828 The log file has been saved successfully to "C:\Documents and Settings\User\Desktop\aswMBR.txt"
Don't mean to bump, but should I move on to the Virus total / Combofix steps even if I can't find the .dat from the last scan, or do I need to run the last scan again?
Hi StellaLynn,

That log for aswMBR appears incomplete, let's try a different tool. If you should have trouble getting a tool to run, skip it and continue on with the remaining steps.

= = = = = = = = = = = = = = = = = = = =

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.

Next

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

http://forums.whatthetech.com/index.php?showtopic=125349

File::
c:\Program files\McAfee Security Scan\3.0.285\McCHSvc.exe

Folder::
c:\Program files\McAfee Security Scan

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"=-

Driver::
McComponentHostService

Suspect::
c:\windows\system32\drivers\ruegmkm.sys

ClearJavaCache::

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.

Next

Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices >> select Only Problems
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.

In your next post please provide the following:
  • GMER.txt
  • ComboFix.txt
  • Result.txt
  • How is the computer running?
Browsers still seems unhijacked and stable
New changes for the better: No need for random DSL logins after disconnected from the net today. Flash player still tells us we need a plugin, but it will actually run after the error message.
No problems that I see.

ComboFix 13-01-24.02 - User 01/24/2013 19:43:31.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.606 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\program files\McAfee Security Scan\3.0.285\McCHSvc.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_MCCOMPONENTHOSTSERVICE
——-\Service_McComponentHostService
.
.
((((((((((((((((((((((((( Files Created from 2012-12-25 to 2013-01-25 )))))))))))))))))))))))))))))))
.
.
2013-01-21 02:22 . 2013-01-08 04:57 6991832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1D764C39-A028-4D7A-A3D1-4C8B4AE84B27}\mpengine.dll
2013-01-21 01:44 . 2013-01-21 01:44 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\PCHealth
2013-01-21 01:08 . 2013-01-21 01:08 ——– d—–w- c:\documents and settings\User\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-01-13 04:17 . 2012-12-15 00:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-01-13 04:15 . 2013-01-21 03:20 ——– d—–w- c:\documents and settings\Administrator
2013-01-11 18:50 . 2013-01-11 18:50 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Scansoft
2013-01-11 05:03 . 2013-01-21 01:18 ——– d—–w- c:\documents and settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
2013-01-11 05:01 . 2013-01-11 05:01 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Sun
2013-01-11 02:22 . 2013-01-11 02:22 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2013-01-10 02:22 . 2013-01-10 02:22 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Adobe
2013-01-10 02:18 . 2013-01-10 02:18 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2013-01-10 02:16 . 2013-01-10 02:16 ——– d—–w- c:\program files\Common Files\Adobe
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\MSXML 4.0
2013-01-10 00:19 . 2013-01-10 00:19 ——– d—–w- c:\program files\IrfanView
2013-01-10 00:02 . 2013-01-10 00:02 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Ahead
2013-01-09 22:45 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2013-01-09 22:45 . 2008-04-14 13:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2013-01-09 20:40 . 2013-01-09 20:39 779704 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 859072 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 93640 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-09 20:39 . 2013-01-09 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2013-01-09 20:35 . 2013-01-22 02:27 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-01-09 18:37 . 2013-01-09 18:37 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2013-01-09 18:35 . 2008-04-14 08:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2013-01-09 18:35 . 2008-04-14 08:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\User\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\ScanSoft
2013-01-09 18:33 . 2013-01-09 18:33 ——– d—–w- c:\program files\Common Files\CANON
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2013-01-09 18:30 . 2007-04-02 05:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 215040 —-a-w- c:\windows\system32\CNMLM8U.DLL
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-09 18:30 . 2007-03-23 16:29 98304 —-a-w- c:\windows\system32\CNC470I.DLL
2013-01-09 18:30 . 2007-03-19 10:21 200704 —-a-w- c:\windows\system32\CNC470L.DLL
2013-01-09 18:30 . 2007-03-15 14:12 188416 —-a-w- c:\windows\system32\CNC470O.DLL
2013-01-09 18:30 . 2007-03-23 16:30 1400832 —-a-w- c:\windows\system32\CNC470C.DLL
2013-01-09 18:30 . 2013-01-09 18:37 ——– d—–w- c:\program files\Canon
2013-01-09 02:04 . 2013-01-09 02:04 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-09 02:04 . 2013-01-09 02:04 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-09 01:35 . 2012-11-01 12:17 521728 -c—-w- c:\windows\system32\dllcache\jsdbgui.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2013-01-09 01:30 . 2012-11-19 09:04 6812136 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-09 00:59 . 2008-04-14 08:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2013-01-09 00:04 . 2013-01-09 00:04 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Mozilla
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 20:39 . 2008-12-27 20:36 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-12-16 12:23 . 2008-04-14 12:39 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-13 01:25 . 2008-04-14 08:00 1866368 —-a-w- c:\windows\system32\win32k.sys
2012-11-06 02:01 . 2008-04-14 12:42 1371648 —-a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:02 . 2008-04-14 12:41 375296 —-a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 12:42 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-01 12:17 . 2008-04-14 12:42 916992 —-a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 12:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-11-01 00:35 . 2008-04-14 07:07 385024 —-a-w- c:\windows\system32\html.iec
2013-01-21 02:52 . 2013-01-21 02:50 262552 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.285\SSScheduler.exe [N/A]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
S1 MpKsldcf968be;MpKsldcf968be;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1D764C39-A028-4D7A-A3D1-4C8B4AE84B27}\MpKsldcf968be.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1D764C39-A028-4D7A-A3D1-4C8B4AE84B27}\MpKsldcf968be.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-24 c:\windows\Tasks\defrag.job
- c:\windows\system32\cmd.exe [2008-04-14 12:42]
.
2013-01-25 c:\windows\Tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
——- Supplementary Scan ——-
.
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\
FF - ExtSQL: 2013-01-20 16:56; {3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}; c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre7\bin\jusched.exe
AddRemove-Malwarebytes' Anti-Malware_is1 - j:\malwarebytes' anti-malware\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-24 19:49
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3112)
c:\windows\system32\WININET.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\VTTimer.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2013-01-24 19:51:24 - machine was rebooted
ComboFix-quarantined-files.txt 2013-01-25 03:51
ComboFix2.txt 2013-01-23 23:30
.
Pre-Run: 65,995,231,232 bytes free
Post-Run: 66,055,557,120 bytes free
.
- - End Of File - - 19C565E45C7C489CBB10315037789D0A


MiniToolBox by Farbar Version:10-01-2013
Ran by [removed] (administrator) on 24-01-2013 at 20:04:35
Running from "C:\Documents and Settings\User\My Documents\Downloads"
Microsoft Windows XP Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================


Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================

127.0.0.1 localhost

========================= IP Configuration: ================================

1394 Net Adapter = 1394 Connection (Connected)
Realtek RTL8139 Family PCI Fast Ethernet NIC = Local Area Connection 3 (Connected)
VIA Rhine II Fast Ethernet Adapter = Local Area Connection 2 (Media disconnected)


# ———————————-
# Interface IP Configuration
# ———————————-
pushd interface ip


# Interface IP Configuration for "Local Area Connection 2"

set address name="Local Area Connection 2" source=dhcp
set dns name="Local Area Connection 2" source=dhcp register=PRIMARY
set wins name="Local Area Connection 2" source=dhcp

# Interface IP Configuration for "Local Area Connection 3"

set address name="Local Area Connection 3" source=dhcp
set dns name="Local Area Connection 3" source=dhcp register=PRIMARY
set wins name="Local Area Connection 3" source=dhcp


popd
# End of interface IP configuration




Windows IP Configuration



Host Name . . . . . . . . . . . . : JOANIESYS

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Local Area Connection 2:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : VIA Rhine II Fast Ethernet Adapter

Physical Address. . . . . . . . . : 00-11-2F-20-D2-F5



Ethernet adapter Local Area Connection 3:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Realtek RTL8139 Family PCI Fast Ethernet NIC

Physical Address. . . . . . . . . : 00-30-BD-2D-31-F7

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.1.64

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.1.254

DHCP Server . . . . . . . . . . . : 192.168.1.254

DNS Servers . . . . . . . . . . . : 192.168.1.254

Lease Obtained. . . . . . . . . . : Thursday, January 24, 2013 6:36:35 PM

Lease Expires . . . . . . . . . . : Friday, January 25, 2013 6:36:35 PM

DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 192.168.1.254

Name: google.com
Addresses: [removed], [removed], [removed], [removed]
173.194.46.0, 173.194.46.1, 173.194.46.2, 173.194.46.3, 173.194.46.4
173.194.46.5, 173.194.46.6



Pinging google.com [74.125.225.227] with 32 bytes of data:



Reply from 74.125.225.227: bytes=32 time=55ms TTL=52

Reply from 74.125.225.227: bytes=32 time=55ms TTL=52



Ping statistics for 74.125.225.227:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 55ms, Maximum = 55ms, Average = 55ms

DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 192.168.1.254

Name: yahoo.com
Addresses: 206.190.36.45, 98.138.253.109, 98.139.183.24



Pinging yahoo.com [98.138.253.109] with 32 bytes of data:



Reply from 98.138.253.109: bytes=32 time=66ms TTL=47

Reply from 98.138.253.109: bytes=32 time=69ms TTL=47



Ping statistics for 98.138.253.109:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 66ms, Maximum = 69ms, Average = 67ms



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ……………………… MS TCP Loopback interface
0x2 …00 11 2f 20 d2 f5 …… VIA Rhine II Fast Ethernet Adapter - Packet Scheduler Miniport
0x3 …00 30 bd 2d 31 f7 …… Realtek RTL8139 Family PCI Fast Ethernet NIC - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.64 1
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.64 192.168.1.64 20
192.168.1.64 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.1.255 255.255.255.255 192.168.1.64 192.168.1.64 20
224.0.0.0 240.0.0.0 192.168.1.64 192.168.1.64 20
255.255.255.255 255.255.255.255 192.168.1.64 2 1
255.255.255.255 255.255.255.255 192.168.1.64 192.168.1.64 1
Default Gateway: 192.168.1.254
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (01/20/2013 08:28:23 PM) (Source: Application Hang) (User: )
Description: Hanging application firefox.exe, version 18.0.1.4764, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (01/20/2013 08:28:20 PM) (Source: Application Hang) (User: )
Description: Hanging application firefox.exe, version 18.0.1.4764, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (01/20/2013 05:44:36 PM) (Source: Microsoft Security Client) (User: )
Description: mssecurityclientmsseces.exe2.1.1116.00x80070002updatecmainwindow__onsignatureupd
atestatus0security essentialsNILNILNIL

Error: (01/20/2013 05:44:05 PM) (Source: Microsoft Security Client) (User: )
Description: mssecurityclientmsseces.exe2.1.1116.00x80070002updatecmainwindow__onsignatureupd
atestatus0security essentialsNILNILNIL

Error: (01/20/2013 04:39:40 PM) (Source: Application Error) (User: )
Description: Faulting application 7cc910fc505d677500007cc894386c25.exe, version 0.0.0.0, faulting module kernel32.dll, version 5.1.2600.6293, fault address 0x00009e32.
Processing media-specific event for [7cc910fc505d677500007cc894386c25.exe!ws!]

Error: (01/12/2013 09:56:32 PM) (Source: crypt32) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/6252DC40F71143A22FDE9EF7348E064251B18118.crt> with error: The server name or address could not be resolved

Error: (01/12/2013 09:53:53 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8007043c, P2 beginsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.

Error: (01/12/2013 09:21:20 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8007043c, P2 beginsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.

Error: (01/12/2013 08:25:53 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8007043c, P2 beginsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.

Error: (01/08/2013 05:27:11 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 80244015, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.


System errors:
=============
Error: (01/24/2013 06:35:50 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (01/24/2013 06:34:39 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
AFD
AmdK7
Fips
IPSec
MpFilter
MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
Tcpip
WS2IFSL

Error: (01/24/2013 06:34:39 PM) (Source: Service Control Manager) (User: )
Description: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31

Error: (01/24/2013 06:34:39 PM) (Source: Service Control Manager) (User: )
Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
%%31

Error: (01/24/2013 06:34:39 PM) (Source: Service Control Manager) (User: )
Description: The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
%%31

Error: (01/24/2013 06:34:39 PM) (Source: Service Control Manager) (User: )
Description: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
%%31

Error: (01/24/2013 06:33:37 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (01/24/2013 06:33:36 PM) (Source: DCOM) (User: JOANIESYS)
Description: DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error: (01/20/2013 07:49:04 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (01/20/2013 07:30:39 PM) (Source: DCOM) (User: JOANIESYS)
Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}


Microsoft Office Sessions:
=========================
Error: (01/20/2013 08:28:23 PM) (Source: Application Hang)(User: )
Description: firefox.exe18.0.1.4764hungapp0.0.0.000000000

Error: (01/20/2013 08:28:20 PM) (Source: Application Hang)(User: )
Description: firefox.exe18.0.1.4764hungapp0.0.0.000000000

Error: (01/20/2013 05:44:36 PM) (Source: Microsoft Security Client)(User: )
Description: mssecurityclientmsseces.exe2.1.1116.00x80070002updatecmainwindow__onsignatureupd
atestatus0security essentialsNILNILNIL

Error: (01/20/2013 05:44:05 PM) (Source: Microsoft Security Client)(User: )
Description: mssecurityclientmsseces.exe2.1.1116.00x80070002updatecmainwindow__onsignatureupd
atestatus0security essentialsNILNILNIL

Error: (01/20/2013 04:39:40 PM) (Source: Application Error)(User: )
Description: 7cc910fc505d677500007cc894386c25.exe0.0.0.0kernel32.dll5.1.2600.629300009e32

Error: (01/12/2013 09:56:32 PM) (Source: crypt32)(User: )
Description: http://www.download.windowsupdate.com/msdo…51B18118.crtThe server name or address could not be resolved

Error: (01/12/2013 09:53:53 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8007043cbeginsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL

Error: (01/12/2013 09:21:20 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8007043cbeginsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL

Error: (01/12/2013 08:25:53 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8007043cbeginsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL

Error: (01/08/2013 05:27:11 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry80244015endsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL


=========================== Installed Programs ============================

Adobe Flash Player 11 ActiveX (Version: 11.5.502.146)
Adobe Reader XI (11.0.01) (Version: 11.0.01)
Canon MP Navigator EX 1.0
Canon MP470 series User Registration
Canon My Printer
Canon Utilities Easy-PhotoPrint EX
Canon Utilities Solution Menu
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
IrfanView (remove only) (Version: 4.35)
Java 7 Update 10 (Version: 7.0.100)
Java Auto Updater (Version: 2.1.9.0)
LightScribe 1.4.62.1 (Version: 1.4.62.1)
Microsoft Antimalware (Version: 3.0.8402.2)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000)
Microsoft Security Client (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 2.1.1116.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Works (Version: 9.7.0621)
Mozilla Firefox 18.0.1 (x86 en-US) (Version: 18.0.1)
Mozilla Maintenance Service (Version: 18.0.1)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Nero Suite
OpenOffice.org 3.0 (Version: 3.0.9358)
PIXMA Extended Survey Program
PowerDVD
Realtek AC'97 Audio
S3 S3Display
S3 S3Gamma2
S3 S3Overlay
S3GSetup (Version: 2.00.07.0709)
ScanSoft OmniPage SE 4 (Version: 15.2.0020)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2541763) (Version: 1)
Update for Windows XP (KB2607712) (Version: 1)
Update for Windows XP (KB2616676-v2) (Version: 2)
Update for Windows XP (KB2661254-v2) (Version: 2)
Update for Windows XP (KB2736233) (Version: 1)
Update for Windows XP (KB2749655) (Version: 1)
Update for Windows XP (KB898461) (Version: 1)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB955839) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
VIA Rhine-Family Fast-Ethernet Adapter
VIA/S3G Display Driver
WebFldrs XP (Version: 9.50.7523)
Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Internet Explorer 7 (Version: 20070813.185237)
Windows Internet Explorer 8 (Version: 20090308.140743)

========================= Devices: ================================


========================= Memory info: ===================================

Percentage of memory in use: 29%
Total physical RAM: 959.48 MB
Available physical RAM: 672.21 MB
Total Pagefile: 2317.28 MB
Available Pagefile: 2109.04 MB
Total Virtual: 2047.88 MB
Available Virtual: 1972.63 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:76.32 GB) (Free:61.54 GB) NTFS

========================= Users: ========================================

User accounts for \\JOANIESYS

Administrator Guest HelpAssistant
SUPPORT_388945a0 User

========================= Minidump Files ==================================

No minidump file found


**** End of log ****

Attachments:

Hi StellaLynn,

Go to http://helpx.adobe.com/flash-player/kb/uni…er-windows.html and follow the directions to Download the uninstaller for Flash Player.

Next

Adobe Flash Player: Go to http://get.adobe.com/flashplayer
  • Remove the check mark from the box "Free! McAfee Security Scan Plus"
  • Click the Download button, and follow the onscreen directions to complete the installation.
Next

After you have reinstalled Adobe Flash Player please check how it is working by visiting this link : http://kb2.adobe.com/cps/155/tn_15507.html

Device Manager
  • Click Start, Run and type DEVMGMT.MSC
  • In the View menu, click Show hidden devices
  • Double-click Non-Plug and Play drivers section
  • Double-click the entry AFD, and click the Driver tab (Ancillary Function Encryption Driver)
  • Set the Startup type to System.
  • Start the service. Note down the error message if any.
  • Similarly start the two other drivers namely:
  • TCP/IP Protocol Driver
  • NetBios over Tcpip
  • Close Device Manager and restart Windows.
Next

System File Checker
  • Click Start, in the run box:
  • Type: sfc /scannow (There's a space between sfc and /scannow.)
  • Type: exit to close the command prompt window
  • Include the findings in your next reply
In your next post please provide the following:
  • Flash Player results
  • Any issues found during the Device Manager step?
  • SFC results
  • How is the computer running, any issues?
Sorry about the long delay, had a medical emergency today. All fixed now, won't run off on you again. The adobe flash player installed fine, but I never got an option not to install mcafee. Just the screen asking weather or not I wanted to be notified of new Flash updates before download, and then they both started downloading. Possibly because McAfee was already on the computer and it was an update instead of an install? I didn't click on anything but the trusted links you provided, and it's not doing anything suspicious like the original "antivirus" that messed up the computer. Think I should just uninstall it regularly from add/remove programs in the control panel? In the device manager, all three show that they are already started, the option to start them is greyed out and there is only an option to close them. The sfc scan asks me for the original windows CDs, which may be a problem with as old as the computer is. Is there some simple fix I'm overlooking or is this a built-in handicap as a way of making sure you have a genuine version of windows?
Hi StellaLynn,

Does Adobe Flash work normally now?

= = = = = = = = = = = = = = = = = = = =

How to display Hidden Files & Folders XP
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a check mark in the check box labeled "Display the contents of system folders".
  • Under the Hidden files and folders section select the radio button labeled "Show hidden files and folders".
  • Remove the check mark from the check box labeled "Hide file extensions for known file types".
  • Remove the check mark from the check box labeled "Hide protected operating system files".
  • Press the Apply button and then the OK button and shutdown My Computer.
Next

Since you don't have the Windows disks to run the System File Checker, let's try and locate the following folder on your computer.
  • You'll have to search for a folder on your hard drive that's named "i386" (without the quotes).
  • Once you find that, copy it to your hard drive at the root (C:\i386).
  • Make sure that the directory is located at the root of your C: drive (C:\i386)
Next

Backing Up Your Registry with ERUNT
ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed. Compatible with Windows NT, 2000, 2003, XP, Vista, 7, 32 & 64-bit versions.
**Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
  • Download ERUNT (save to your desktop)
  • Double-click erunt_setup.exe to run.
  • Follow the prompts and install using the default configuration:
  • Select your preferred Setup language.

    [external image: Posted Image]

  • At the Setup screen click Next.

    [external image: Posted Image]

  • Accept the default destination folder by clicking Next.

    [external image: Posted Image]

  • Accept the default Start Menu Folder.

    [external image: Posted Image]

  • Accept the default Additional Tasks by Clicking Next.

    [external image: Posted Image]

  • Ready to Install. Click the Install button.

    [external image: Posted Image]

  • Say No to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later.

    [external image: Posted Image]

  • Setup has completed. Tick the check boxes to Show documentation, or Launch.

    [external image: Posted Image]

  • Start ERUNT

    [external image: Posted Image]

  • Choose a location for the backup

    • The default location C:\WINDOWS\ERDNT\[today's date] is preferred
    • The first two check boxes are ticked by default (System registry and Current user registry).
  • Press OK

    [external image: Posted Image]

  • When prompted, click YES to create a new folder.

    [external image: Posted Image]

  • Progress bars will show backup status.

    [external image: Posted Image]

  • A confirmation window will popup when complete.

    [external image: Posted Image]

  • Click OK to close.
Next

Open Notepad, and copy and paste the text below in the code box into Notepad. (do not copy the word code)

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup]
"Sourcepath"="C:\"

Save the file to your desktop as fix.reg (be sure to name the file with the .reg extension)
Double click the file [external image: Posted Image] to update the changes to the Registry.Next

Next

System File Checker
  • Click Start, in the run box:
  • Type: sfc /scannow (There's a space between sfc and /scannow.)
  • Type: exit to close the command prompt window
  • Include the findings in your next reply
Next

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

Firefox::
FF - ExtSQL: 2013-01-20 16:56; {3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}; c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Referring to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.

In your next post please provide the following:
  • Flash progress report
  • SFC results
  • ComboFix.txt
  • How is the computer running, any remaining issues?
The flash works perfect on the test page you gave me and youtube. Thanks!

I noticed a single google redirect yesterday after I posted, and dad says the internet went out twice yesterday and once again this morning (I iunderstand the hardware may be the problem, but it was fairly new, zero problems before and this started happening with the virus). Those are really infrequent problems, so I'm having trouble testing them. Also I understand this might coincidentally be the time our router decided to start dying, we'll be looking into buying another one just to have as a backup soon so we can troubleshoot them.

It's kind of a weird redirect, it takes my search term and gives me it's ad results, it goes right away with no "are you sure you want to leave" message when I alt+f4 or anything fishy, and then the next time I click on that same link (something trusted like wikipedia or whatthetech), it will actually go to the site the second time. The overwhelming majority of my searches don't redirect at all. If it weren't for clicking on links from trusted places like this site that I know shouldn't be pulling up that same style of ads, I might not have noticed it at all. It's pretty hard to test. Thought that stopped, sorry.

I put the i386 folder in c:\, but sfcscan won't run. Same CD error "skip this file" loop I got in before.
All the file's contents looked like they copied normally, but I deleted the C:\i386 folder, recopied it from windows search, checked to make sure all the files were there, and had another unsuccessful sfc scan with the same CD issues as before. Triple checked your directions, made sure I spelled "sfc /scannow" right with the space in the middle (and no quotes of course), and I can't find my problem.

ComboFix 13-01-27.03 - User 01/27/2013 10:17:59.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.623 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi
.
.
((((((((((((((((((((((((( Files Created from 2012-12-27 to 2013-01-27 )))))))))))))))))))))))))))))))
.
.
2013-01-27 18:16 . 2013-01-27 18:16 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4E7F8C14-57D5-4252-B341-07461BF1CE88}\MpKsl63b03e4b.sys
2013-01-27 18:10 . 2013-01-27 18:10 ——– d—–w- c:\program files\ERUNT
2013-01-27 18:03 . 2013-01-27 18:03 ——– d—–w- C:\i386
2013-01-26 18:47 . 2013-01-08 04:57 6991832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4E7F8C14-57D5-4252-B341-07461BF1CE88}\mpengine.dll
2013-01-26 18:39 . 2013-01-26 18:39 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-26 18:39 . 2013-01-26 18:39 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-21 01:44 . 2013-01-21 01:44 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\PCHealth
2013-01-21 01:08 . 2013-01-21 01:08 ——– d—–w- c:\documents and settings\User\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-01-13 04:17 . 2012-12-15 00:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-01-13 04:15 . 2013-01-21 03:20 ——– d—–w- c:\documents and settings\Administrator
2013-01-11 18:50 . 2013-01-11 18:50 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Scansoft
2013-01-11 05:03 . 2013-01-21 01:18 ——– d—–w- c:\documents and settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
2013-01-11 05:01 . 2013-01-11 05:01 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Sun
2013-01-11 02:22 . 2013-01-11 02:22 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2013-01-10 02:22 . 2013-01-10 02:22 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Adobe
2013-01-10 02:16 . 2013-01-10 02:16 ——– d—–w- c:\program files\Common Files\Adobe
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\MSXML 4.0
2013-01-10 00:19 . 2013-01-10 00:19 ——– d—–w- c:\program files\IrfanView
2013-01-10 00:02 . 2013-01-10 00:02 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Ahead
2013-01-09 22:45 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2013-01-09 22:45 . 2008-04-14 13:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2013-01-09 20:40 . 2013-01-09 20:39 779704 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 859072 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 93640 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-09 20:39 . 2013-01-09 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2013-01-09 20:35 . 2013-01-22 02:27 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-01-09 18:37 . 2013-01-09 18:37 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2013-01-09 18:35 . 2008-04-14 08:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2013-01-09 18:35 . 2008-04-14 08:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\User\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\ScanSoft
2013-01-09 18:33 . 2013-01-09 18:33 ——– d—–w- c:\program files\Common Files\CANON
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2013-01-09 18:30 . 2007-04-02 05:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 215040 —-a-w- c:\windows\system32\CNMLM8U.DLL
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-09 18:30 . 2007-03-23 16:29 98304 —-a-w- c:\windows\system32\CNC470I.DLL
2013-01-09 18:30 . 2007-03-19 10:21 200704 —-a-w- c:\windows\system32\CNC470L.DLL
2013-01-09 18:30 . 2007-03-15 14:12 188416 —-a-w- c:\windows\system32\CNC470O.DLL
2013-01-09 18:30 . 2007-03-23 16:30 1400832 —-a-w- c:\windows\system32\CNC470C.DLL
2013-01-09 18:30 . 2013-01-09 18:37 ——– d—–w- c:\program files\Canon
2013-01-09 01:35 . 2012-11-01 12:17 521728 -c—-w- c:\windows\system32\dllcache\jsdbgui.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2013-01-09 01:30 . 2012-11-19 09:04 6812136 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-09 00:59 . 2008-04-14 08:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2013-01-09 00:04 . 2013-01-09 00:04 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Mozilla
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 20:39 . 2008-12-27 20:36 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-12-16 12:23 . 2008-04-14 12:39 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-13 01:25 . 2008-04-14 08:00 1866368 —-a-w- c:\windows\system32\win32k.sys
2012-11-06 02:01 . 2008-04-14 12:42 1371648 —-a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:02 . 2008-04-14 12:41 375296 —-a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 12:42 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-01 12:17 . 2008-04-14 12:42 916992 —-a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 12:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-11-01 00:35 . 2008-04-14 07:07 385024 —-a-w- c:\windows\system32\html.iec
2013-01-21 02:52 . 2013-01-21 02:50 262552 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R1 MpKsl63b03e4b;MpKsl63b03e4b;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4E7F8C14-57D5-4252-B341-07461BF1CE88}\MpKsl63b03e4b.sys [1/27/2013 10:16 AM 29904]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL63B03E4B
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-27 c:\windows\Tasks\defrag.job
- c:\windows\system32\cmd.exe [2008-04-14 12:42]
.
2013-01-27 c:\windows\Tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
——- Supplementary Scan ——-
.
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\
FF - ExtSQL: 2013-01-20 16:56; {3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}; c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-27 10:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2013-01-27 10:23:48
ComboFix-quarantined-files.txt 2013-01-27 18:23
ComboFix2.txt 2013-01-25 03:51
ComboFix3.txt 2013-01-23 23:30
.
Pre-Run: 65,233,903,616 bytes free
Post-Run: 65,277,849,600 bytes free
.
- - End Of File - - B14D209AA4DBADB4A5AF9A483FFA0D39
Hi StellaLynn,

Do the redirects happen in a particular web browser? If so, select the applicable step below for Internet Explorer, Firefox or Chrome. If it happens in multiple browsers then complete as many of these steps as necessary.

If Firefox set to synchronize? more information here

= = = = = = = = = = = = = = = = = = = =

Option #1

To Reset Internet Explorer Settings
  • Close all Internet Explorer and Windows Explorer windows that are currently open.
  • Open Internet Explorer.
  • Click the Tools button [external image: Posted Image], and then click Internet Options.
  • Click the Advanced tab, and then click Reset.
  • Select the Delete personal settings check box if you would also like to remove browsing history, search providers, Accelerators, home pages, Tracking Protection, and ActiveX Filtering data.
  • In the Reset Internet Explorer Settings dialog box, click Reset.
  • When Internet Explorer finishes applying default settings, click Close, and then click OK.
  • Close Internet Explorer.
= = = = = = = = = = = = = = = = = = = =

Option #2

Reset Firefox to its default state
  • At the top of the Firefox window, click the Firefox button, go over to the Help sub-menu
    (on Windows XP, click the Help menu at the top of the Firefox window) and select Troubleshooting Information.
    [external image: Posted Image]

  • Click the Reset Firefox button in the upper-right corner of the Troubleshooting Information page.
    [external image: Posted Image]

  • To continue, click Reset Firefox in the confirmation window that opens.
  • Firefox will close and be reset. When it's done, a window will list the information that was imported. Click Finish and Firefox will open.
= = = = = = = = = = = = = = = = = = = =

Option #3

Delete cache and other browser data in Chrome
  • Click the Chrome menu [external image: Posted Image] on the browser toolbar.
  • Select Tools.
  • Select Clear browsing data.
  • In the dialogue that appears, select the highlighted check-boxes for the types of information that you want to remove.
    • Clear browsing history
    • Clear download history
    • Empty the cache
    • Delete cookies and other site and plug-in data
    • Clear saved passwords
    • Clear saved Autofill form data
    • Clear data from hosted apps
    • Deauthorize content licenses
  • Use the menu at the top to select the amount of data that you want to delete. Select beginning of time to delete everything.
  • Click Clear browsing data.
Next

Reboot and check to see if you still experience the redirects.

Next

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

File::
c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi

Firefox::
FF - ExtSQL: 2013-01-20 16:56; {3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}; c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi

ClearJavaCache::

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.

Next
  • Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.

In your next post please provide the following:
  • Still getting redirected?
  • ComboFix.txt
  • OTL.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI