This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Oyodomo redirect [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello bhp and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

We are going to need a little more information before we can figure out what is going on.

Please work through the following steps:

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • aswMBR


    • Download aswMBR.exe to your desktop.
    • Double click the aswMBR.exe to run it.
    • When asked if you want to download Avast's virus definitions please select Yes.
    • Click the "Scan" button to start scan.

    [external image: Posted Image]

    • On completion of the scan click save log, save it to your desktop and post in your next reply.

    [external image: Posted Image]

    Please post both DDS logs and the aswMBR log in your next reply.
DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.17.2 Run by [removed] at 10:29:28 on 2013-04-27 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1919.1009 [GMT -4:00] . AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: avast! Antivirus *Disabled* . ============== Running Processes ================ . C:\WINDOWS\system32\Ati2evxx.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\LSI SoftModem\agrsmsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe C:\Documents and Settings\All Users\Application Data\DatacardService\DCService.exe C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\AVAST Software\Avast\avastUI.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\program files\real\realplayer\update\realsched.exe C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Java\jre7\bin\jqs.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe C:\Documents and Settings\loaner\Local Settings\Application Data\Akamai\netsession_win.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Documents and Settings\loaner\Local Settings\Application Data\Akamai\netsession_win.exe C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe C:\WINDOWS\System32\alg.exe C:\Documents and Settings\loaner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\WINDOWS\system32\SNDVOL32.EXE C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = hxxp://google.com/ mStart Page = hxxp://search.thechatphone.com uProxyOverride = uURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll BHO: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll BHO: getsav-in 5.0: {496FAB4B-EBC6-4736-B237-87B9F41C8BD1} - c:\documents and settings\loaner\local settings\application data\getsav-in\ie\getsav-in_1366935302.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\14.2.0.1\AVG Secure Search_toolbar.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Help the General-Search Project: {CA4520F3-AE13-4FB1-A513-58E23991C86D} - c:\documents and settings\loaner\application data\media finder\extensions\gencrawler_gc.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: ChromeFrame BHO: {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - c:\program files\google\chrome\application\26.0.1410.64\npchrome_frame.dll TB: : {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\14.2.0.1\AVG Secure Search_toolbar.dll uRun: [cdloader] "c:\documents and settings\loaner\application data\mjusbsp\cdloader2.exe" MAGICJACK uRun: [Google Update] "c:\documents and settings\loaner\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [Facebook Update] "c:\documents and settings\loaner\local settings\application data\facebook\update\FacebookUpdate.exe" /c /nocrashserver uRun: [Akamai NetSession Interface] "c:\documents and settings\loaner\local settings\application data\akamai\netsession_win.exe" uRun: [Media Finder] "c:\program files\media finder\Media Finder.exe" /opentotray mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [UVS11 Preload] c:\program files\ulead systems\ulead videostudio 11\uvPL.exe mRun: [UpdatePDRShortCut] "c:\program files\cyberlink\powerdirector10\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector10" updatewithcreateonce "software\cyberlink\powerdirector\10.0" mRun: [DivXMediaServer] c:\program files\divx\divx media server\DivXMediaServer.exe mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [SMessaging] c:\documents and settings\loaner\local settings\application data\strongvault online backup\SMessaging.exe mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background mRun: [vProt] "c:\program files\avg secure search\vprot.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t uPolicies-Explorer: NoDriveAutoRun = dword:67108863 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 IE: Download with &Media Finder - c:\program files\media finder\hook.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll IE: {3B54DEAB-C6D4-48a8-8C32-A70558643400} - c:\program files\finalvideodownloader\fvdRunner.html IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1322613974125 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} - hxxp://photofinish.lifepics.com/net/Uploader/LPUploader57.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: NameServer = 192.168.168.1 TCP: Interfaces\{E5176C7B-AFFE-4E13-89C2-30FA3DBCEA41} : DHCPNameServer = 192.168.168.1 Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome\application\26.0.1410.64\npchrome_frame.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\14.2.0\ViProtocol.dll Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll LSA: Authentication Packages = msv1_0 nwprovau mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome . ============= SERVICES / DRIVERS =============== . R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-3-19 49248] R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 195296] R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2012-11-28 20624] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-12-2 765736] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-12-2 368176] R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-1-8 33112] R1 MpKsl1dedfefa;MpKsl1dedfefa;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{87e978e0-fb28-4227-aa3f-d1791e787d13}\MpKsl1dedfefa.sys [2013-4-26 29904] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-12-2 29816] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-3-19 66336] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-12-2 45248] R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\codemeter\runtime\bin\CodeMeter.exe [2012-8-6 2568120] R2 DCService.exe;DCService.exe;c:\documents and settings\all users\application data\datacardservice\DCService.exe [2010-5-8 229376] R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_2_1\bin\fbguard.exe -s defaultinstance –> c:\program files\firebird\firebird_2_1\bin\fbguard.exe -s DefaultInstance [?] R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2012-11-29 38608] R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\all users\application data\skype\toolbars\skype c2c service\c2c_service.exe [2013-3-19 3289208] R2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\14.2.0\ToolbarUpdater.exe [2013-2-19 968880] R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\firebird\firebird_2_1\bin\fbserver.exe -s defaultinstance –> c:\program files\firebird\firebird_2_1\bin\fbserver.exe -s DefaultInstance [?] R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2013-2-3 70656] R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2008-7-23 44800] RUnknown MpKsl93e93e05;MpKsl93e93e05; [x] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 Helix Mobile Server;Helix Mobile Server;c:\program files\real\helix server\bin\rmserver.exe [2011-5-19 3300352] S2 InetD;Pragma InetD;c:\program files\pragma\inetd\INETDSRV.exe [2012-11-28 129440] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-2-28 161384] S3 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-3-19 164736] S3 CXPLRCAP;Capture Device;c:\windows\system32\drivers\CxPlrCap.sys [2011-8-20 187776] S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2013-2-3 117504] S3 MediaMall Server;MediaMall Server;c:\program files\mediamall\MediaMallServer.exe [2012-12-11 3942704] S3 PPEMSCAN;Protector Plus Email Scan Driver;\??\c:\protector plus\ppemscan.sys –> c:\protector plus\PPEMSCAN.sys [?] S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [2010-11-25 606056] S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys –> c:\windows\system32\drivers\wg111v2.sys [?] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2013-04-26 14:54:11 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{87e978e0-fb28-4227-aa3f-d1791e787d13}\MpKsl1dedfefa.sys 2013-04-26 12:09:33 60872 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{87e978e0-fb28-4227-aa3f-d1791e787d13}\offreg.dll 2013-04-26 12:09:33 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{87e978e0-fb28-4227-aa3f-d1791e787d13}\MpKsl93e93e05.sys 2013-04-26 06:50:47 6906960 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{87e978e0-fb28-4227-aa3f-d1791e787d13}\mpengine.dll 2013-04-25 19:13:18 ——– d—–w- c:\documents and settings\loaner\local settings\application data\getsav-in 2013-04-25 19:02:58 ——– d—–w- c:\documents and settings\loaner\local settings\application data\Mozilla 2013-04-25 19:02:09 ——– d—–w- c:\program files\Mozilla Maintenance Service 2013-04-25 01:58:27 6906960 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2013-04-21 16:31:46 ——– d—–w- c:\program files\ASIO4ALL v2 2013-04-21 11:41:27 ——– d—–w- c:\program files\Mixxx 2013-04-21 07:37:52 ——– d—–w- c:\documents and settings\loaner\local settings\application data\Mixxx 2013-04-20 23:47:43 ——– d—–w- c:\documents and settings\all users\application data\Tarma Installer 2013-04-20 13:26:12 ——– d—–w- c:\program files\common files\Symantec Shared 2013-04-20 13:22:21 ——– d—–w- c:\documents and settings\all users\application data\Norton 2013-04-20 13:21:26 ——– d—–w- c:\documents and settings\all users\application data\NortonInstaller 2013-04-20 13:11:23 0 —-a-w- c:\windows\system32\TempWmicBatchFile.bat 2013-04-20 13:10:48 ——– d—–w- c:\windows\system32\Extensions 2013-04-20 13:10:44 ——– d—–w- c:\windows\system32\searchplugins 2013-04-20 13:10:07 ——– d—–w- c:\documents and settings\loaner\application data\Mipony 2013-04-20 13:08:58 ——– d—–w- c:\documents and settings\loaner\application data\DSite 2013-04-06 22:34:03 59888 ——w- c:\windows\system32\pxwma.dll 2013-04-03 23:39:28 ——– d—–w- C:\Torrent Downloading 2013-04-03 23:32:03 ——– d—–w- c:\documents and settings\loaner\application data\uTorrent 2013-04-02 17:45:47 ——– d—–w- c:\documents and settings\loaner\Downloads 2013-04-01 10:09:25 ——– d—–w- c:\documents and settings\loaner\local settings\application data\FinalMediaPlayer 2013-04-01 10:06:41 ——– d—–w- c:\documents and settings\all users\application data\APN . ==================== Find3M ==================== . 2013-04-23 17:15:00 691592 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-04-23 17:14:59 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-04-04 18:50:32 22856 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-04-02 10:33:22 237088 ——w- c:\windows\system32\MpSigStub.exe 2013-03-24 10:05:02 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-03-24 10:04:44 143872 —-a-w- c:\windows\system32\javacpl.cpl 2013-03-24 10:04:39 861088 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-03-24 10:04:39 782240 —-a-w- c:\windows\system32\deployJava1.dll 2013-03-08 08:36:22 293376 —-a-w- c:\windows\system32\winsrv.dll 2013-03-07 01:32:25 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-03-07 00:50:30 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-03-06 23:33:24 765736 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-03-06 23:33:24 49248 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-03-06 23:33:24 164736 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-03-06 23:33:23 66336 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-03-06 23:32:51 41664 —-a-w- c:\windows\avastSS.scr 2013-03-02 02:06:31 916480 —-a-w- c:\windows\system32\wininet.dll 2013-03-02 02:06:30 43520 —-a-w- c:\windows\system32\licmgr10.dll 2013-03-02 02:06:30 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2013-03-02 01:25:02 1867264 —-a-w- c:\windows\system32\win32k.sys 2013-03-02 01:08:47 385024 —-a-w- c:\windows\system32\html.iec 2013-02-27 07:56:51 2067456 —-a-w- c:\windows\system32\mstscax.dll 2013-02-19 12:10:02 33112 —-a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-02-12 00:32:23 12928 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-02-12 00:32:23 12928 ——w- c:\windows\system32\drivers\usb8023x.sys . ============= FINISH: 10:32:36.11 ===============
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 1/26/2011 10:23:04 AM System Uptime: 4/27/2013 3:25:29 AM (7 hours ago) . Motherboard: Hewlett-Packard | | 30C2 Processor: AMD Athlon™ 64 X2 Dual Core Processor TK-53 | U10 | 1695/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 112 GiB total, 6.482 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 1394 Net Adapter Device ID: V1394\NIC1394\295D0E1023F99 Manufacturer: Microsoft Name: 1394 Net Adapter PNP Device ID: V1394\NIC1394\295D0E1023F99 Service: NIC1394 . ==== System Restore Points =================== . RP502: 4/18/2013 8:19:28 AM - System Checkpoint RP503: 4/19/2013 6:55:03 PM - Software Distribution Service 3.0 RP504: 4/22/2013 12:07:39 AM - System Checkpoint RP505: 4/21/2013 1:07:43 AM - System Checkpoint RP506: 4/21/2013 3:26:29 AM - Installed Livestream Procaster RP507: 4/21/2013 5:46:37 AM - Software Distribution Service 3.0 RP508: 4/23/2013 11:45:12 PM - Software Distribution Service 3.0 RP509: 4/23/2013 7:45:00 AM - System Checkpoint RP510: 4/24/2013 9:58:10 PM - Software Distribution Service 3.0 RP511: 4/24/2013 7:50:13 PM - Removed Livestream Procaster RP512: 4/25/2013 8:02:04 PM - System Checkpoint RP513: 4/26/2013 2:19:54 AM - Software Distribution Service 3.0 RP514: 4/26/2013 2:50:33 AM - Software Distribution Service 3.0 RP515: 4/26/2013 4:25:23 AM - OTL Restore Point - 4/26/2013 4:25:16 AM RP516: 4/27/2013 8:25:47 AM - System Checkpoint . ==== Installed Programs ====================== . µTorrent 32 Bit HP CIO Components Installer 3D Home Architect 4 ACDSee 5.0 PowerPack Adobe AIR Adobe Community Help Adobe Content Viewer Adobe Download Assistant Adobe Flash Media Live Encoder 3.2 Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Media Player Adobe Photoshop 7.0 Adobe Premiere 6.0 Adobe Reader X (10.1.6) Adobe Shockwave Player 11.6 Advanced RealMedia Export Plug-in for Premiere 6.0 Akamai NetSession Interface AMD AVIVO Codecs Apple Application Support Apple Mobile Device Support Apple Software Update Art Effects for PDR10 ASIO4ALL ASUS RT-N10+ Wireless Router Utilities ATI Catalyst Control Center ATI Display Driver AuthenTec Fingerprint Sensor Minimum Install avast! Free Antivirus AVG Security Toolbar BlackBerry Desktop Software 4.7 Broadcom NetXtreme Ethernet Controller BufferChm Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Localization All ccc-core-preinstall ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CCleaner Cleaner 5 EZ Common Contents ConvertXtoDVD 4.1.19.365 Cool Edit Pro 2.0 Corel VideoStudio Pro X4 CyberLink PowerDirector 10 CyberLink WaveEditor DeviceIO DeviceManagementQFolder DivX Setup Driver Install 32-Bit Dropbox Embedded Security for HP ProtectTools Driver EZ Grabber Facebook Video Calling 1.2.0.287 File Type Assistant FileZilla Client 3.6.0.2 Final Media Player 2012 Final Video Downloader 2012 Firebird 2.1.0.16780 (Win32) FoxTab PDF Converter Free YouTube Downloader 3.5.134 getsav-in Google Chrome Google Chrome Frame Google Drive Google Talk Plugin Google Update Helper H.264 Encoder HandBrake 0.9.8 Helix Mobile Server 14.2 honestech VHS to DVD 3.0 SE Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB2756822) Hotfix for Windows XP (KB2779562) Hotfix for Windows XP (KB915800-v4) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976002-v5) HP Imaging Device Functions 7.0 HP Photosmart and Deskjet 7.0 Software HP Photosmart Printer Driver Software 10.0.02 hph_software_req ICA iLivid iMesh InterVideo DeviceService IPM_VS_Pro ISCOM Java 7 Update 17 Java Auto Updater Java™ 6 Update 29 jZip magicJack Malwarebytes Anti-Malware version 1.75.0.1300 McAfee Internet Security Medialooks MPlatform 1.2.1.21 MediaLooks QuickTime Source 1.7.0.15 (DirectShow Filter) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2698023) Microsoft .NET Framework 1.1 Security Update (KB2742597) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Automated Troubleshooting Services Shim Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office FrontPage 2003 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFCLOC_x86 Mixxx 1.10.1 MobileMe Control Panel Mozilla Firefox 20.0.1 (x86 en-US) Mozilla Maintenance Service MSN MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Notepad++ PlayOn Plex Media Server Pragma TelnetServer PS_SF_02_Software_min PureHD PxMergeModule QuickTime RealDownloader RealNetworks - Microsoft Visual C++ 2008 Runtime RealNetworks - Microsoft Visual C++ 2010 Runtime RealPlayer RealUpgrade 1.1 Recover My Files Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB2675157) Security Update for Windows Internet Explorer 8 (KB2699988) Security Update for Windows Internet Explorer 8 (KB2722913) Security Update for Windows Internet Explorer 8 (KB2744842) Security Update for Windows Internet Explorer 8 (KB2761465) Security Update for Windows Internet Explorer 8 (KB2792100) Security Update for Windows Internet Explorer 8 (KB2797052) Security Update for Windows Internet Explorer 8 (KB2799329) Security Update for Windows Internet Explorer 8 (KB2809289) Security Update for Windows Internet Explorer 8 (KB2817183) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Search 4 - KB963093 Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2416400) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2641653) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2647518) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2685939) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2695962) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2705219) Security Update for Windows XP (KB2707511) Security Update for Windows XP (KB2709162) Security Update for Windows XP (KB2712808) Security Update for Windows XP (KB2718523) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB2723135) Security Update for Windows XP (KB2724197) Security Update for Windows XP (KB2727528) Security Update for Windows XP (KB2731847) Security Update for Windows XP (KB2753842-v2) Security Update for Windows XP (KB2753842) Security Update for Windows XP (KB2757638) Security Update for Windows XP (KB2758857) Security Update for Windows XP (KB2761226) Security Update for Windows XP (KB2770660) Security Update for Windows XP (KB2778344) Security Update for Windows XP (KB2779030) Security Update for Windows XP (KB2780091) Security Update for Windows XP (KB2799494) Security Update for Windows XP (KB2802968) Security Update for Windows XP (KB2807986) Security Update for Windows XP (KB2808735) Security Update for Windows XP (KB2813170) Security Update for Windows XP (KB2813345) Security Update for Windows XP (KB2820917) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Setup Share SHOUTcast DSP Plug-in v2 Skype Click to Call Skype™ 6.3 SmartSound Common Data SmartSound Quicktracks 5 Strongvault Online Backup StrongVPN Client version 1.1 swMSM Synaptics Pointing Device Driver Toolbox Turbonett móvil Ulead VideoStudio 11 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2768021) 32-Bit Edition Update for Microsoft Windows (KB971513) Update for Windows Internet Explorer 8 (KB2447568) Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB2661254-v2) Update for Windows XP (KB2718704) Update for Windows XP (KB2736233) Update for Windows XP (KB2749655) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC80CRTRedist - 8.0.50727.6195 VidBlaster Video Downloader Suite V2.5.9 VideoStudio VIO Virtual DJ Pro Full - Atomix Productions vMix VSClassic VSPro WebFldrs XP Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Management Framework Core Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Player 11 Windows Search 4.0 Windows XP Service Pack 3 WinRAR 4.01 (32-bit) Yahoo! Detect . ==== Event Viewer Messages From Past Week ======== . 4/26/2013 7:00:46 AM, error: Service Control Manager [7034] - The DNS Client service terminated unexpectedly. It has done this 1 time(s). 4/23/2013 8:27:49 PM, error: Schannel [36884] - The certificate received from the remote server does not contain the expected name. It is therefore not possible to determine whether we are connecting to the correct server. The server name we were expecting is relay.l.google.com. The SSL connection request has failed. The attached data contains the server certificate. 4/22/2013 8:53:02 PM, error: DCOM [10000] - Unable to start a DCOM Server: {46986115-84D6-459C-8F95-52DD653E532E}. The error: "%2" Happened while starting this command: "C:\Program Files\Winamp\winamp.exe" -Embedding 4/21/2013 8:54:48 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Firebird Server - DefaultInstance service to connect. 4/21/2013 8:54:48 AM, error: Service Control Manager [7000] - The Firebird Server - DefaultInstance service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 4/21/2013 6:46:13 AM, error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 4/21/2013 6:46:12 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Search service to connect. 4/21/2013 6:33:35 AM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 4/21/2013 6:33:32 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the ImapiService service. 4/21/2013 5:29:48 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Yontoo Desktop Updater service to connect. 4/21/2013 5:29:48 AM, error: Service Control Manager [7000] - The Yontoo Desktop Updater service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 4/20/2013 9:30:11 AM, error: Service Control Manager [7031] - The avast! Antivirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 4/20/2013 9:16:24 AM, error: Service Control Manager [7024] - The Pragma InetD service terminated with service-specific error 1062 (0x426). . ==== End Of File ===========================
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-04-27 10:49:53 —————————– 10:49:53.328 OS Version: Windows 5.1.2600 Service Pack 3 10:49:53.328 Number of processors: 2 586 0x6801 10:49:53.328 ComputerName: BHPMOTORSPORTS UserName: loaner 10:50:06.687 Initialize success 10:50:07.265 AVAST engine defs: 13042700 10:50:19.125 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 10:50:19.125 Disk 0 Vendor: TOSHIBA_MK1237GSX DL132C Size: 114473MB BusType: 3 10:50:19.578 Disk 0 MBR read successfully 10:50:19.578 Disk 0 MBR scan 10:50:19.578 Disk 0 Windows XP default MBR code 10:50:19.593 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 114463 MB offset 63 10:50:19.640 Disk 0 scanning sectors +234420480 10:50:20.281 Disk 0 scanning C:\WINDOWS\system32\drivers 10:50:46.750 Service scanning 10:51:51.406 Modules scanning 10:52:02.109 Disk 0 trace - called modules: 10:52:02.140 ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys hal.dll ACPI.sys atapi.sys pciide.sys 10:52:02.140 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a994ab8] 10:52:02.140 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> [0x8aa00c58] 10:52:02.140 5 hpdskflt.sys[ba3395ae] -> nt!IofCallDriver -> \Device\00000096[0x8aa10f18] 10:52:02.140 7 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aa6a940] 10:52:08.671 AVAST engine scan C:\WINDOWS 10:52:21.078 AVAST engine scan C:\WINDOWS\system32 10:55:21.265 AVAST engine scan C:\WINDOWS\system32\drivers 10:55:54.359 AVAST engine scan C:\Documents and Settings\loaner 10:56:15.718 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\loaner\Desktop\MBR.dat" 10:56:15.718 The log file has been saved successfully to "C:\Documents and Settings\loaner\Desktop\aswMBR.txt"
Hello bhp

Thank you for the logs.

Did you run OTL on this machine recently?

If the answer is yes, please let me know if you are being helped at another forum.
Hello bhp

Thanks for letting me know.

Please work your way through the following steps:

  • Security Programs


    • You appear to have a number of real-time security programs installed, namely avast! Free Antivirus, McAfee Internet Security and Microsoft Security Essentials
    • Whilst both of these programs provide good security, they may clash with each other which can leave your system vulnerable to infection.
    • You are advised to remove two of these programs.
    • Please make sure that you only have ONE Firewall and ONE real-time Antivirus running on your system.

  • P2P Programs:


    • P2P programs are a major source of Malware infections.
    • From your log I see you have µTorrent. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • A list of currently installed programs will be displayed.
    • Find the "µTorrent" program, click on it once and then click on the "Remove" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.


      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Combofix


    • Download ComboFix from one of the following locations:

      Link 1
      Link 2

    • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

    • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]

    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
    • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
    • Should there be issues with internet afterward:

      In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

      In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

    Please post the Combofix log in your next reply.
I ran it as advised. It indicated that the log could or couldn' t be remaned to # 1. I choose Ok but I don't see the log file. I only ran it once, but chances are I downloaded it twice Despite Explorer is closing by itself, all the other browsers are working fine. I already noticed a great improvement in internet access and speed. .
Hello bhp

I choose Ok but I don't see the log file

If a log was created you will be able to find it here: C:\ComboFix.txt

If there is no Combofix log, please re-scan with DDS and post the logs for me to review.
ComboFix 11-11-30.01 - loaner 11/30/2011 9:26.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.895.203 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\schrauber.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-30 )))))))))))))))))))))))))))))))
.
.
2011-11-30 01:05 . 2011-11-30 01:05 ——– d—–w- c:\program files\CCleaner
2011-11-29 22:05 . 2011-11-30 13:18 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BCB87F85-8D07-4F99-AA74-4DE542336C64}\offreg.dll
2011-11-29 15:54 . 2011-10-07 00:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BCB87F85-8D07-4F99-AA74-4DE542336C64}\mpengine.dll
2011-11-28 13:18 . 2011-11-29 12:27 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-15 12:25 . 2011-11-15 12:25 ——– d—–w- c:\documents and settings\loaner\Local Settings\Application Data\PCHealth
2011-11-14 04:13 . 2011-11-17 16:37 ——– d—–w- C:\CMRC
2011-11-08 00:20 . 2011-11-28 15:16 ——– d—–w- C:\MS Torrent
2011-11-07 19:51 . 2011-11-07 19:51 ——– d—–w- c:\documents and settings\loaner\Application Data\Malwarebytes
2011-11-07 19:50 . 2011-11-07 19:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-07 19:50 . 2011-08-31 21:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-07 19:50 . 2011-11-07 19:50 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-03 18:06 . 2011-11-03 18:06 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2011-11-02 23:35 . 2011-10-07 00:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-02 14:05 . 2008-11-10 15:41 32656 —-a-w- c:\windows\system32\msonpmon.dll
2011-11-02 14:05 . 2006-10-26 23:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-11-02 09:32 . 2011-11-02 09:32 ——– d—–w- C:\backup
2011-11-02 09:09 . 2009-08-06 23:23 215904 —-a-w- c:\windows\system32\muweb.dll
2011-11-02 09:09 . 2009-08-06 23:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-11-02 03:10 . 2011-11-04 20:24 ——– d—–w- c:\windows\system32\NtmsData
2011-11-02 01:39 . 2011-11-02 01:39 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2011-11-01 20:00 . 2010-10-19 20:51 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-11-01 19:48 . 2011-11-01 19:50 ——– d—–w- c:\program files\Microsoft Security Client
2011-11-01 17:10 . 2011-11-25 02:20 ——– d—–w- C:\dvd convert
2011-11-01 13:08 . 2010-04-14 00:10 54776 —-a-w- c:\windows\system32\drivers\MOBK.sys
2011-11-01 13:06 . 2011-11-01 13:08 ——– d—–w- c:\program files\McAfee Online Backup
2011-11-01 13:02 . 2011-10-15 17:16 9608 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-11-01 13:02 . 2011-10-15 17:16 89792 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-11-01 13:02 . 2011-10-15 17:16 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2011-11-01 13:02 . 2011-10-15 17:16 83856 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2011-11-01 13:02 . 2011-10-15 17:16 59456 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2011-11-01 13:02 . 2011-10-15 17:16 57600 —-a-w- c:\windows\system32\drivers\cfwids.sys
2011-11-01 13:02 . 2011-10-15 17:16 338176 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2011-11-01 13:02 . 2011-10-15 17:16 180816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-11-01 13:02 . 2011-11-01 13:04 ——– d—–w- c:\program files\Common Files\Mcafee
2011-11-01 13:01 . 2011-11-10 15:45 ——– d—–w- c:\program files\McAfee
2011-11-01 12:25 . 2011-10-18 18:32 150856 —-a-w- c:\windows\system32\mfevtps.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-25 19:15 . 2011-10-25 19:15 30576 —-a-w- c:\windows\_SETUPD_.EXE
2011-10-15 17:16 . 2011-03-13 15:20 464176 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2011-10-15 17:16 . 2011-03-13 15:20 121256 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-10-10 14:22 . 2011-01-26 14:17 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-08 09:47 . 2011-05-17 07:23 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-03 09:06 . 2011-02-23 12:17 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 06:37 . 2011-02-23 12:17 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2006-02-28 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-29 23:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2006-02-28 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-29_15.42.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-30 13:19 . 2011-11-30 13:19 16384 c:\windows\Temp\Perflib_Perfdata_924.dat
+ 2011-11-30 13:19 . 2011-11-30 13:19 16384 c:\windows\Temp\Perflib_Perfdata_890.dat
+ 2011-11-30 13:19 . 2011-11-30 13:19 16384 c:\windows\Temp\Perflib_Perfdata_580.dat
- 2011-01-26 14:25 . 2011-11-29 13:26 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-01-26 14:25 . 2011-11-29 22:44 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-01-26 14:25 . 2011-11-29 22:44 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2011-01-26 14:25 . 2011-11-29 13:26 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2011-01-26 14:25 . 2011-11-29 13:26 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-11-29 22:42 . 2011-11-29 22:44 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2006-07-24 14:50 . 2006-07-24 14:50 47920 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBAME.DLL
+ 2009-02-26 19:24 . 2009-02-26 19:24 71536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ONFILTER.DLL
+ 2009-02-26 19:24 . 2009-02-26 19:24 97680 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ONENOTEM.EXE
+ 2006-07-24 14:50 . 2006-07-24 14:50 92976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSADDNDR.DLL
+ 2011-02-15 03:02 . 2011-02-15 03:02 35648 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLCTLPIA.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 56192 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
+ 2011-11-30 13:06 . 2011-11-30 13:06 63336 c:\windows\assembly\tmp\JZ5BO8MO\Microsoft.Vbe.Interop.dll
+ 2011-11-30 13:08 . 2011-11-30 13:08 11144 c:\windows\assembly\tmp\DAIAEPWL\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2011-11-30 13:08 . 2011-11-30 13:08 34696 c:\windows\assembly\tmp\6EXJ2RD9\Microsoft.Office.Interop.OutlookViewCtl.dll
- 2011-11-15 12:01 . 2011-11-15 12:01 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2011-11-30 12:05 . 2011-11-30 12:05 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2007-06-07 23:51 . 2007-06-07 23:51 125320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SSGEN.DLL
+ 2007-06-07 23:51 . 2007-06-07 23:51 465800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL
+ 2008-03-19 10:27 . 2008-03-19 10:27 661536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OGALEGIT.DLL
+ 2006-07-24 14:50 . 2006-07-24 14:50 125744 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL
+ 2008-10-25 10:18 . 2008-10-25 10:18 172880 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IEAWSDC.DLL
+ 2006-10-27 19:35 . 2006-10-27 19:35 436512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\UMOUTLOOKADDIN.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 764800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECNF.DLL
+ 2011-11-30 13:08 . 2011-11-30 13:08 870256 c:\windows\assembly\tmp\N9SC5APO\Microsoft.Office.Interop.Word.dll
+ 2011-11-30 13:08 . 2011-11-30 13:08 608136 c:\windows\assembly\tmp\ARO3279Y\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2011-11-30 13:08 . 2011-11-30 13:08 117160 c:\windows\assembly\tmp\ADSGSQZ0\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2011-11-30 13:09 . 2011-11-30 13:09 350080 c:\windows\assembly\tmp\687YNIEZ\Microsoft.Office.Interop.PowerPoint.dll
+ 2011-11-30 13:06 . 2011-11-30 13:06 149368 c:\windows\assembly\tmp\46WB6A5B\Microsoft.Office.Interop.Graph.dll
+ 2011-07-07 06:28 . 2011-07-07 06:28 1193320 c:\windows\system32\FM20.DLL
+ 2011-09-15 22:35 . 2011-09-15 22:35 1411072 c:\windows\Installer\9f6a2.msp
+ 2009-10-10 03:10 . 2009-10-10 03:10 2594632 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBE6.DLL
+ 2006-10-27 00:25 . 2006-10-27 00:25 2172688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSRCHFEA.DLL
+ 2011-11-30 13:08 . 2011-11-30 13:08 1279864 c:\windows\assembly\tmp\4E0I6596\Microsoft.Office.Interop.Excel.dll
+ 2011-09-15 22:37 . 2011-09-15 22:37 16691712 c:\windows\Installer\9f6bd.msp
+ 2011-09-15 22:37 . 2011-09-15 22:37 34428416 c:\windows\Installer\9f6a3.msp
+ 2011-09-15 22:34 . 2011-09-15 22:34 428804608 c:\windows\Installer\ab63f.msp
+ 2011-11-30 12:28 . 2011-11-30 12:28 409672484 c:\windows\Installer\854ff.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK]
@="{3c3f3c1a-9153-7c05-f938-622e7003894d}"
[HKEY_CLASSES_ROOT\CLSID\{3c3f3c1a-9153-7c05-f938-622e7003894d}]
2010-04-14 00:11 2872120 —-a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK2]
@="{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}"
[HKEY_CLASSES_ROOT\CLSID\{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}]
2010-04-14 00:11 2872120 —-a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK3]
@="{b4caf489-1eec-c617-49ad-8d7088598c06}"
[HKEY_CLASSES_ROOT\CLSID\{b4caf489-1eec-c617-49ad-8d7088598c06}]
2010-04-14 00:11 2872120 —-a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-03-30 399736]
"cdloader"="c:\documents and settings\loaner\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-08-07 273544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FinalTorrent\\FinalTorrent.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\FRONTPG.EXE"=
"c:\\Program Files\\Real\\Helix Server\\Bin\\rmserver.exe"=
"c:\\Documents and Settings\\loaner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\FinalMediaPlayer\\FMPCheckForUpdates.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
"c:\\Documents and Settings\\loaner\\Application Data\\mjusbsp\\magicJack.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [11/1/2011 9:02 AM 89792]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [11/1/2011 9:08 AM 54776]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance –> c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
R2 Helix Mobile Server;Helix Mobile Server;c:\program files\Real\Helix Server\Bin\rmserver.exe [5/19/2011 2:41 AM 3300352]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [11/1/2011 9:02 AM 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [11/1/2011 9:02 AM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [11/1/2011 9:03 AM 160608]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [11/1/2011 8:25 AM 150856]
R2 MOBKbackup;McAfee Online Backup;c:\program files\McAfee Online Backup\MOBKbackup.exe [4/13/2010 8:11 PM 229688]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [11/1/2011 9:02 AM 57600]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance –> c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [7/23/2008 11:31 AM 44800]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [11/1/2011 9:02 AM 338176]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [11/1/2011 9:02 AM 83856]
S1 MpKsl01286304;MpKsl01286304;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl01286304.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl01286304.sys [?]
S1 MpKsl0529931f;MpKsl0529931f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl0529931f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl0529931f.sys [?]
S1 MpKsl091f7d70;MpKsl091f7d70;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F5125E5-3149-44CC-8B7A-82910FE8D38C}\MpKsl091f7d70.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F5125E5-3149-44CC-8B7A-82910FE8D38C}\MpKsl091f7d70.sys [?]
S1 MpKsl206b40cc;MpKsl206b40cc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKsl206b40cc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKsl206b40cc.sys [?]
S1 MpKsl25af1a14;MpKsl25af1a14;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKsl25af1a14.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKsl25af1a14.sys [?]
S1 MpKsl2821f94a;MpKsl2821f94a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKsl2821f94a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKsl2821f94a.sys [?]
S1 MpKsl293256e5;MpKsl293256e5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKsl293256e5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKsl293256e5.sys [?]
S1 MpKsl2aa17a02;MpKsl2aa17a02;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsl2aa17a02.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsl2aa17a02.sys [?]
S1 MpKsl3128ccf5;MpKsl3128ccf5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{48F1EC8F-911F-4533-AEC0-3A1E1350092F}\MpKsl3128ccf5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{48F1EC8F-911F-4533-AEC0-3A1E1350092F}\MpKsl3128ccf5.sys [?]
S1 MpKsl3279af08;MpKsl3279af08;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl3279af08.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl3279af08.sys [?]
S1 MpKsl42f5af95;MpKsl42f5af95;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl42f5af95.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl42f5af95.sys [?]
S1 MpKsl4c7304df;MpKsl4c7304df;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl4c7304df.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl4c7304df.sys [?]
S1 MpKsl5c0bca57;MpKsl5c0bca57;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F5125E5-3149-44CC-8B7A-82910FE8D38C}\MpKsl5c0bca57.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F5125E5-3149-44CC-8B7A-82910FE8D38C}\MpKsl5c0bca57.sys [?]
S1 MpKsl5dcef7bc;MpKsl5dcef7bc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl5dcef7bc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl5dcef7bc.sys [?]
S1 MpKsl64380ef5;MpKsl64380ef5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsl64380ef5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsl64380ef5.sys [?]
S1 MpKsl691cbe5b;MpKsl691cbe5b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKsl691cbe5b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKsl691cbe5b.sys [?]
S1 MpKsl714f566e;MpKsl714f566e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl714f566e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl714f566e.sys [?]
S1 MpKsl74381e05;MpKsl74381e05;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl74381e05.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl74381e05.sys [?]
S1 MpKsl8366c0e0;MpKsl8366c0e0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl8366c0e0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl8366c0e0.sys [?]
S1 MpKsl83d78b4a;MpKsl83d78b4a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl83d78b4a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl83d78b4a.sys [?]
S1 MpKsl8612a10f;MpKsl8612a10f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CA18D9B1-5860-4FEB-8DDB-0541ADEB5B63}\MpKsl8612a10f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CA18D9B1-5860-4FEB-8DDB-0541ADEB5B63}\MpKsl8612a10f.sys [?]
S1 MpKsla364b468;MpKsla364b468;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsla364b468.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsla364b468.sys [?]
S1 MpKslae95932b;MpKslae95932b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKslae95932b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKslae95932b.sys [?]
S1 MpKslc4d51836;MpKslc4d51836;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F71F5E5-BEEC-41A8-BC77-33F90E015530}\MpKslc4d51836.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F71F5E5-BEEC-41A8-BC77-33F90E015530}\MpKslc4d51836.sys [?]
S1 MpKslc70de0e4;MpKslc70de0e4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKslc70de0e4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKslc70de0e4.sys [?]
S1 MpKslc9da35db;MpKslc9da35db;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKslc9da35db.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKslc9da35db.sys [?]
S1 MpKslcb5d34cc;MpKslcb5d34cc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C9688BD0-E77C-4B5F-94BC-B7EA51A47874}\MpKslcb5d34cc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C9688BD0-E77C-4B5F-94BC-B7EA51A47874}\MpKslcb5d34cc.sys [?]
S1 MpKsld1109001;MpKsld1109001;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsld1109001.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsld1109001.sys [?]
S1 MpKsld2e59fa1;MpKsld2e59fa1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F71F5E5-BEEC-41A8-BC77-33F90E015530}\MpKsld2e59fa1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F71F5E5-BEEC-41A8-BC77-33F90E015530}\MpKsld2e59fa1.sys [?]
S1 MpKsld9bfcea9;MpKsld9bfcea9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsld9bfcea9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsld9bfcea9.sys [?]
S1 MpKsldb18623e;MpKsldb18623e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKsldb18623e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKsldb18623e.sys [?]
S1 MpKsle7a962a9;MpKsle7a962a9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsle7a962a9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsle7a962a9.sys [?]
S1 MpKsle9507e44;MpKsle9507e44;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsle9507e44.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsle9507e44.sys [?]
S1 MpKslee39e17d;MpKslee39e17d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F46D6FC6-FEF2-4725-BF96-7B1E9B5E2183}\MpKslee39e17d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F46D6FC6-FEF2-4725-BF96-7B1E9B5E2183}\MpKslee39e17d.sys [?]
S1 MpKslef47bbf7;MpKslef47bbf7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{40D8BD0F-B3DA-4449-8D4E-DEA05ACEFDB9}\MpKslef47bbf7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{40D8BD0F-B3DA-4449-8D4E-DEA05ACEFDB9}\MpKslef47bbf7.sys [?]
S1 MpKslfca80051;MpKslfca80051;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKslfca80051.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKslfca80051.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 CXPLRCAP;Capture Device;c:\windows\system32\drivers\CxPlrCap.sys [8/20/2011 2:47 PM 187776]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [11/1/2011 9:02 AM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [11/1/2011 9:02 AM 87656]
S3 PPEMSCAN;Protector Plus Email Scan Driver;\??\c:\protector plus\PPEMSCAN.sys –> c:\protector plus\PPEMSCAN.sys [?]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [11/25/2010 6:59 AM 606056]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys –> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2/28/2006 8:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-22 c:\windows\Tasks\AdobeAAMUpdater-1.0-BHPMOTORSPORTS-loaner.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-07-14 21:42]
.
2011-11-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2011-11-30 c:\windows\Tasks\Final Media Player Update Checker.job
- c:\program files\FinalMediaPlayer\FMPCheckForUpdates.exe [2011-08-18 19:24]
.
2011-11-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-796845957-725345543-1003Core.job
- c:\documents and settings\loaner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-14 06:28]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-796845957-725345543-1003UA.job
- c:\documents and settings\loaner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-14 06:28]
.
2011-11-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1957994488-796845957-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-11-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1957994488-796845957-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-11-11 c:\windows\Tasks\SpeedMaxPc Defrag.job
- c:\program files\SpeedMaxPc\SpeedMaxPc\speedmaxpc.exe [2011-10-27 21:14]
.
2011-11-28 c:\windows\Tasks\SpeedMaxPc Registration3.job
- c:\program files\Common Files\SpeedMaxPc\UUS3\UUS3.dll [2010-11-02 18:09]
.
2011-11-22 c:\windows\Tasks\SpeedMaxPc Update3.job
- c:\program files\Common Files\SpeedMaxPc\UUS3\Update3.exe [2010-11-02 18:09]
.
2011-11-20 c:\windows\Tasks\SpeedMaxPc.job
- c:\program files\SpeedMaxPc\SpeedMaxPc\speedmaxpc.exe [2011-10-27 21:14]
.
2011-11-30 c:\windows\Tasks\User_Feed_Synchronization-{F1ACD361-4F07-41D5-B07C-FED2F57481E2}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/webhp?hl=en
mStart Page = hxxp://search.thechatphone.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{3B54DEAB-C6D4-48a8-8C32-A70558643400} - c:\program files\FinalVideoDownloader\fvdRunner.html
TCP: DhcpNameServer = 192.168.254.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-30 09:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1957994488-796845957-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EC68D8D0-C6CE-DCB9-3409-6509B88ABE66}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iakjloggoobbiggpaa"=hex:6a,61,62,6a,66,62,6c,65,67,65,62,61,68,6a,65,66,6a,6d,
61,61,00,fe
"haajjphdeoaadcbk"=hex:6a,61,67,6b,6d,61,6d,69,70,6f,66,64,6a,6b,66,65,62,6b,
6d,63,00,fe
"iagmfiigainoookjko"=hex:63,61,69,6b,6c,61,00,7c
"dbikmbpehfohcnelmnmnaodjegmcjcokblmfgemg"=hex:68,61,6a,6c,6e,6c,6e,69,62,63,
6f,6e,66,64,69,6a,00,01
"jbikmbpehfohcnelmnmnpmljicnpmbekblpociamacoipfdcagho"=hex:68,61,6a,6c,6e,6c,
6e,69,62,63,6f,6e,66,64,69,6a,00,01
"dbikmbpehfohcnelmnmnjmmjeekfkioaoijgoick"=hex:6c,61,61,68,6b,6b,68,63,63,63,
64,6a,69,64,6c,6f,62,6d,70,66,67,6f,6b,70,00,00
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1504)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3840)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\program files\McAfee Online Backup\MOBKshell.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-11-30 09:40:35
ComboFix-quarantined-files.txt 2011-11-30 13:40
ComboFix2.txt 2011-11-29 18:56
ComboFix3.txt 2011-11-29 16:01
.
Pre-Run: 49,175,506,944 bytes free
Post-Run: 49,579,405,312 bytes free
.
- - End Of File - - 4054C5A088BA11B7845C0C70A6B56A80
I have to run Utorrent on another machine before I delete it from this one as I really need it for my work.
Hello bhp

I have to run Utorrent on another machine before I delete it from this one as I really need it for my work

Only you can make that decision but you have been advised not to use it. Chances are high that you will pick up malware using P2P. Its not a questions of "if", just a question of when.

The log you have posted is not a recent Combofix log, but one that was created some time ago.

Please scan with DDS and post the new logs for me to review.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI