This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Popups in IE, Can't seem to get rid of them...

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently I've started getting popups from Internet Explorer, as long as it's allowed to connect to the internet (no effects when set to offline). Usually ads and whatnot, and not sure where to go from here. McAfee is my antivirus program. Any help is appreciated, HJT log below.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:20 PM, on 9/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Support.com\bin\tgcmd.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=22028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRA~1\POPUPP~1\PopLib.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] "C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" /AUTORUN
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1813] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC315] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Download] "C:\Program Files\Bellsouth\HelpCenter\ssGet.exe" 120 "http://download.fastaccess.com/download/HC41SInstaller.exe" "HC41SInstaller.exe"
O4 - HKCU\..\Run: [Drmupgds] C:\Program Files\Drmupgds\Drmupgds.exe
O4 - HKCU\..\Run: [NoDNS] C:\Program Files\\NoDNS\\NoDNS.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB710] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7061] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Program Files\PopupPopper\SiteList.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.tricksteronline.com/control/KALogoutComponent.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 12981 bytes
Hi Pen,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.



Viewpoint Manager is considered as foistware instead of malware since it is often installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
It is STRONGLY recommended that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove the Viewpoint component
  • Do the same for each Viewpoint component.

A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

MCAFEE ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Exit."
  • a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.
You succesfully disabled the McAfee Guard.

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
SecurityCenter doesn't seem to have an exit function, so I disabled all of it's scanning and protection temporarily. HJT and Combofix logs are as following:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:37, on 2008-09-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=22028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRA~1\POPUPP~1\PopLib.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Program Files\PopupPopper\SiteList.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.tricksteronline.com/control/KALogoutComponent.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 11425 bytes

ComboFix 08-09-14.01 - Pen 2008-09-15 0:15:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1635 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Pen\Local Settings\Temporary Internet Files\CPV.stt
C:\Program Files\CPV
C:\Program Files\MapEDC
C:\Program Files\MapEDC\IDE.stt
C:\Program Files\NoDNS
C:\Program Files\nvcoi\mst.stt
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rtl60.bpl
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.

2008-09-15 00:24 . 2008-09-15 00:24 d——– C:\Temp\tn3
2008-09-14 22:13 . 2008-09-14 22:13 d——– C:\Program Files\ERUNT
2008-09-14 21:56 . 2008-09-14 21:56 d——– C:\Program Files\Trend Micro
2008-09-14 19:51 . 2008-09-14 19:53 d——– C:\Program Files\SpywareBlaster
2008-09-14 19:51 . 2008-09-14 19:51 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-14 19:31 . 2008-09-14 19:37 d——– C:\ie-spyad_zo
2008-09-14 19:30 . 2008-09-14 19:38 d——– C:\Program Files\ZonedOut
2008-09-12 15:09 . 2008-09-12 15:09 96 –ah—– C:\WINDOWS\system32\HsInfo.dat
2008-09-12 15:06 . 2008-09-12 15:06 d——– C:\Program Files\alaplaya
2008-09-11 09:37 . 2008-09-11 09:37 d——– C:\Documents and Settings\LocalService\Application Data\SACore
2008-08-21 17:08 . 2008-08-21 17:08 d——– C:\Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 04:16 ——— d—–w C:\Program Files\nvcoi
2008-09-15 03:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-15 03:41 ——— d—–w C:\Documents and Settings\Pen\Application Data\Viewpoint
2008-09-15 03:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-15 03:40 ——— d—–w C:\Program Files\Viewpoint
2008-09-15 00:58 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-09-15 00:56 ——— d—–w C:\Program Files\mIRC
2008-09-15 00:50 ——— d—–w C:\Program Files\Dl_cats
2008-09-13 00:07 ——— d—–w C:\Program Files\World of Warcraft
2008-09-12 19:06 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-11 10:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-09-11 07:13 ——— d—–w C:\Program Files\McAfee
2008-09-07 16:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-23 16:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-28 08:40 2,829 —-a-w C:\WINDOWS\War3Unin.pif
2008-06-28 08:40 139,264 —-a-w C:\WINDOWS\War3Unin.exe
2007-07-19 00:52 66,248 —-a-w C:\Program Files\INSTALL.LOG
2006-10-15 18:27 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2006-09-09 12:33 242,382,524 —-a-w C:\Program Files\NtreevSoft.zip
2006-09-09 12:25 271,650,129 —-a-w C:\Program Files\mIRC.zip
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 50528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-31 344064]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-07-06 169984]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728]
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 157592]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 289064]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BellSouthAlertManager.exe"="C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" /AUTORUN

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\NtreevSoft\\Albatross18\\ProjectG.exe"=
"C:\\Program Files\\mIRC\\download\\Bunny\\BuNNy Mark II v10-03-05\\mirc.exe"=
"C:\\Program Files\\Ruckus Player\\Ruckus.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.2.2.7318-to-2.2.3.7359-enUS-downloader.exe"=
"C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\javaw.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\alaplaya\\S4League\\S4Client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12433:TCP"= 12433:TCP:BitComet 12433 TCP
"12433:UDP"= 12433:UDP:BitComet 12433 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 netbioss;netbioss;C:\WINDOWS\system32\drivers\netbioss.sys [2008-01-08 86016]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-08-18 211232]
R2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]
S3 npkycryp;npkycryp;C:\Program Files\Gravity\RO\npkycryp.sys [ ]
S3 XDva193;XDva193;C:\WINDOWS\system32\XDva193.sys [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24ec5dcd-3c48-11db-ae4f-001372960240}]
\Shell\AutoRun\command - G:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24ec5dce-3c48-11db-ae4f-001372960240}]
\Shell\AutoRun\command - setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Download - C:\Program Files\Bellsouth\HelpCenter\ssGet.exe 120 http://download.fastaccess.com/download/HC41SInstaller.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Pen\Application Data\Mozilla\Firefox\Profiles\kq6ipiy4.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 00:25:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
-> C:\PROGRA~1\Google\GOOGLE~1\GOA66E~1.DLL
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
C:\Program Files\MATLAB\R2006a\bin\win32\MATLAB.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\BellSouth\HelpCenter\SSGet.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Support.com\bin\tgcmd.exe
.
**************************************************************************
.
Completion time: 2008-09-15 0:32:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-15 04:31:47

Pre-Run: 62,222,069,760 bytes free
Post-Run: 62,153,646,080 bytes free

206 — E O F — 2008-09-11 07:05:58
Pen,

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 7.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u7-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    Folder::
    C:\Temp\tn3
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "C:\\Program Files\\BitComet\\BitComet.exe"=-
    "C:\\Program Files\\uTorrent\\utorrent.exe"=-
    "C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\javaw.exe"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
ComboFix, Kaspersky, and HJT logs to follow…

ComboFix 08-09-14.01 - Pen 2008-09-15 1:46:22.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1635 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Pen\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.

2008-09-15 01:56 . 2008-09-15 01:56 d——– C:\Temp\tn3
2008-09-15 01:40 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-14 22:13 . 2008-09-14 22:13 d——– C:\Program Files\ERUNT
2008-09-14 21:56 . 2008-09-14 21:56 d——– C:\Program Files\Trend Micro
2008-09-14 19:51 . 2008-09-14 19:53 d——– C:\Program Files\SpywareBlaster
2008-09-14 19:51 . 2008-09-14 19:51 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-14 19:31 . 2008-09-14 19:37 d——– C:\ie-spyad_zo
2008-09-14 19:30 . 2008-09-14 19:38 d——– C:\Program Files\ZonedOut
2008-09-12 15:09 . 2008-09-12 15:09 96 –ah—– C:\WINDOWS\system32\HsInfo.dat
2008-09-12 15:06 . 2008-09-12 15:06 d——– C:\Program Files\alaplaya
2008-09-11 09:37 . 2008-09-11 09:37 d——– C:\Documents and Settings\LocalService\Application Data\SACore
2008-08-21 17:08 . 2008-08-21 17:08 d——– C:\Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 05:40 ——— d—–w C:\Program Files\Java
2008-09-15 04:16 ——— d—–w C:\Program Files\nvcoi
2008-09-15 03:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-15 03:41 ——— d—–w C:\Documents and Settings\Pen\Application Data\Viewpoint
2008-09-15 03:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-15 03:40 ——— d—–w C:\Program Files\Viewpoint
2008-09-15 00:58 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-09-15 00:56 ——— d—–w C:\Program Files\mIRC
2008-09-15 00:50 ——— d—–w C:\Program Files\Dl_cats
2008-09-13 00:07 ——— d—–w C:\Program Files\World of Warcraft
2008-09-12 19:06 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-11 10:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-09-11 07:13 ——— d—–w C:\Program Files\McAfee
2008-09-07 16:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-23 16:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-28 08:40 2,829 —-a-w C:\WINDOWS\War3Unin.pif
2008-06-28 08:40 139,264 —-a-w C:\WINDOWS\War3Unin.exe
2007-07-19 00:52 66,248 —-a-w C:\Program Files\INSTALL.LOG
2006-10-15 18:27 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2006-09-09 12:33 242,382,524 —-a-w C:\Program Files\NtreevSoft.zip
2006-09-09 12:25 271,650,129 —-a-w C:\Program Files\mIRC.zip
.

((((((((((((((((((((((((((((( snapshot@2008-09-15_ 0.31.15.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-15 00:02:01 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-15 04:51:01 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-15 00:02:01 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-15 04:51:01 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-15 00:02:01 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-15 04:51:01 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-02-22 05:23:35 135,168 —-a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 05:21:01 135,168 —-a-w C:\WINDOWS\system32\java.exe
- 2008-02-22 05:23:39 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 05:21:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
- 2008-02-22 06:33:32 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 06:32:34 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2008-09-15 05:52:39 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_1ec.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Download"="C:\Program Files\Bellsouth\HelpCenter\ssGet.exe 120 http://download.fastaccess.com/download/HC...aller.exe" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-31 344064]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-07-06 169984]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728]
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 157592]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BellSouthAlertManager.exe"="C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" /AUTORUN

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\NtreevSoft\\Albatross18\\ProjectG.exe"=
"C:\\Program Files\\mIRC\\download\\Bunny\\BuNNy Mark II v10-03-05\\mirc.exe"=
"C:\\Program Files\\Ruckus Player\\Ruckus.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.2.2.7318-to-2.2.3.7359-enUS-downloader.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\alaplaya\\S4League\\S4Client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12433:TCP"= 12433:TCP:BitComet 12433 TCP
"12433:UDP"= 12433:UDP:BitComet 12433 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 netbioss;netbioss;C:\WINDOWS\system32\drivers\netbioss.sys [2008-01-08 86016]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-08-18 211232]
R2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]
S3 npkycryp;npkycryp;C:\Program Files\Gravity\RO\npkycryp.sys [ ]
S3 XDva193;XDva193;C:\WINDOWS\system32\XDva193.sys [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24ec5dcd-3c48-11db-ae4f-001372960240}]
\Shell\AutoRun\command - G:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24ec5dce-3c48-11db-ae4f-001372960240}]
\Shell\AutoRun\command - setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 01:56:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
C:\Program Files\MATLAB\R2006a\bin\win32\MATLAB.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-09-15 2:01:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-15 06:01:25
ComboFix2.txt 2008-09-15 04:32:54

Pre-Run: 62,957,248,512 bytes free
Post-Run: 62,943,457,280 bytes free

204 — E O F — 2008-09-11 07:05:58


——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, September 15, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, September 15, 2008 07:31:39
Records in database: 1232290
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 208726
Threat name: 8
Infected objects: 12
Suspicious objects: 0
Duration of the scan: 02:56:21


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Start Menu\Programs\mIRC\backup\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.612 1
C:\Documents and Settings\All Users\Start Menu\Programs\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
C:\Documents and Settings\Pen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-5e000ca2-23ec5f29.zip Infected: Trojan-Downloader.Java.OpenStream.ac 1
C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Bunny.zip Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
C:\Program Files\mIRC\download\Bunny\BuNNy Mark II v10-03-05\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1
C:\Program Files\mIRC.zip Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
C:\Program Files\mIRC.zip Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1
C:\Program Files\MSN Gaming Zone\progyrt.html Infected: Trojan-Clicker.HTML.IFrame.dn 1
C:\WINDOWS\b143.exe_old Infected: Trojan-Downloader.Win32.Agent.kub 1
C:\WINDOWS\b149.exe_old Infected: not-a-virus:Downloader.Win32.Agent.ak 1
C:\WINDOWS\system32\cache3\vumpedll23.exe Infected: Trojan.Win32.Multis.bv 1

The selected area was scanned.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:26, on 2008-09-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Support.com\bin\tgcmd.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=22028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRA~1\POPUPP~1\PopLib.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Download] "C:\Program Files\Bellsouth\HelpCenter\ssGet.exe" 120 "http://download.fastaccess.com/download/HC43SInstaller.exe" "HC43SInstaller.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google; Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate; English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Program Files\PopupPopper\SiteList.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.tricksteronline.com/control/KALogoutComponent.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 11409 bytes
Pen,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\Documents and Settings\Pen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-5e000ca2-23ec5f29.zip
    C:\Program Files\MSN Gaming Zone\progyrt.html
    C:\WINDOWS\b143.exe_old
    C:\WINDOWS\b149.exe_old
    C:\WINDOWS\system32\cache3\vumpedll23.exe
    
    Folder::
    C:\Temp\tn3
    
    Rootkit::
    C:\WINDOWS\system32\drivers\core.cache.dsk
    
    Driver::
    npkycryp
    XDva193
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply along with a new HijackThis log.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 08-09-14.01 - Pen 2008-09-15 13:08:27.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1598 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Pen\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Pen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-5e000ca2-23ec5f29.zip
C:\Program Files\MSN Gaming Zone\progyrt.html
C:\Temp\tn3
C:\WINDOWS\b143.exe_old
C:\WINDOWS\b149.exe_old
C:\WINDOWS\system32\cache3\vumpedll23.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_XDVA193
——-\Service_npkycryp
——-\Service_XDva193


((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.

2008-09-15 13:18 . 2008-09-15 13:18 d——– C:\Temp\tn3
2008-09-15 13:14 . 2008-09-15 13:14 167,976 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-09-15 01:40 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-14 22:13 . 2008-09-14 22:13 d——– C:\Program Files\ERUNT
2008-09-14 21:56 . 2008-09-14 21:56 d——– C:\Program Files\Trend Micro
2008-09-14 19:51 . 2008-09-14 19:53 d——– C:\Program Files\SpywareBlaster
2008-09-14 19:51 . 2008-09-14 19:51 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-14 19:31 . 2008-09-14 19:37 d——– C:\ie-spyad_zo
2008-09-14 19:30 . 2008-09-14 19:38 d——– C:\Program Files\ZonedOut
2008-09-12 15:09 . 2008-09-12 15:09 96 –ah—– C:\WINDOWS\system32\HsInfo.dat
2008-09-12 15:06 . 2008-09-12 15:06 d——– C:\Program Files\alaplaya
2008-09-11 09:37 . 2008-09-11 09:37 d——– C:\Documents and Settings\LocalService\Application Data\SACore
2008-08-21 17:08 . 2008-08-21 17:08 d——– C:\Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 05:40 ——— d—–w C:\Program Files\Java
2008-09-15 04:16 ——— d—–w C:\Program Files\nvcoi
2008-09-15 03:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-15 03:41 ——— d—–w C:\Documents and Settings\Pen\Application Data\Viewpoint
2008-09-15 03:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-15 03:40 ——— d—–w C:\Program Files\Viewpoint
2008-09-15 00:58 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-09-15 00:56 ——— d—–w C:\Program Files\mIRC
2008-09-15 00:50 ——— d—–w C:\Program Files\Dl_cats
2008-09-13 00:07 ——— d—–w C:\Program Files\World of Warcraft
2008-09-12 19:06 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-11 10:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-09-11 07:13 ——— d—–w C:\Program Files\McAfee
2008-09-07 16:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-23 16:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-28 08:40 2,829 —-a-w C:\WINDOWS\War3Unin.pif
2008-06-28 08:40 139,264 —-a-w C:\WINDOWS\War3Unin.exe
2007-07-19 00:52 66,248 —-a-w C:\Program Files\INSTALL.LOG
2006-10-15 18:27 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2006-09-09 12:33 242,382,524 —-a-w C:\Program Files\NtreevSoft.zip
2006-09-09 12:25 271,650,129 —-a-w C:\Program Files\mIRC.zip
.

((((((((((((((((((((((((((((( snapshot@2008-09-15_ 0.31.15.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-15 00:02:01 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-15 14:29:02 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-15 00:02:01 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-15 14:29:02 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-15 00:02:01 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-15 14:29:02 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-02-22 05:23:35 135,168 —-a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 05:21:01 135,168 —-a-w C:\WINDOWS\system32\java.exe
- 2008-02-22 05:23:39 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 05:21:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
- 2008-02-22 06:33:32 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 06:32:34 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2008-09-15 17:15:09 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_1f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Download"="C:\Program Files\Bellsouth\HelpCenter\ssGet.exe 120 http://download.fastaccess.com/download/HC...aller.exe" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-31 344064]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-07-06 169984]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728]
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 157592]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BellSouthAlertManager.exe"="C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" /AUTORUN

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\NtreevSoft\\Albatross18\\ProjectG.exe"=
"C:\\Program Files\\mIRC\\download\\Bunny\\BuNNy Mark II v10-03-05\\mirc.exe"=
"C:\\Program Files\\Ruckus Player\\Ruckus.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.2.2.7318-to-2.2.3.7359-enUS-downloader.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\alaplaya\\S4League\\S4Client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12433:TCP"= 12433:TCP:BitComet 12433 TCP
"12433:UDP"= 12433:UDP:BitComet 12433 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 netbioss;netbioss;C:\WINDOWS\system32\drivers\netbioss.sys [2008-01-08 86016]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-08-18 211232]
R2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24ec5dcd-3c48-11db-ae4f-001372960240}]
\Shell\AutoRun\command - G:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24ec5dce-3c48-11db-ae4f-001372960240}]
\Shell\AutoRun\command - setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 13:19:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
-> ?:\WINDOWS\System32\CSCDLL.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\MATLAB\R2006a\bin\win32\MATLAB.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-09-15 13:24:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-15 17:24:38
ComboFix2.txt 2008-09-15 06:01:30
ComboFix3.txt 2008-09-15 04:32:54

Pre-Run: 62,970,109,952 bytes free
Post-Run: 62,998,794,240 bytes free

214 — E O F — 2008-09-11 07:05:58

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:26, on 2008-09-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Support.com\bin\tgcmd.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=22028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRA~1\POPUPP~1\PopLib.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Download] "C:\Program Files\Bellsouth\HelpCenter\ssGet.exe" 120 "http://download.fastaccess.com/download/HC43SInstaller.exe" "HC43SInstaller.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Program Files\PopupPopper\SiteList.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.tricksteronline.com/control/KALogoutComponent.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 11330 bytes
Pen,

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Does it? Actually, I still seem to be getting the popups from IE (the content within the windows sometimes doesn't load, but windows [complete with address bar and whatnot] are still appearing spontaneously).

For example, one with the url http://shopingplanete.com/?a=ignorebest just appeared as I typed this message.

Should I still go ahead and uninstall ComboFix?
Pen,

Nothing is showing so lets run a couple more scans to see what might not be showing.

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.
  • Close Gmer.
  • Open Command Prompt by going to Start > Run and type in cmd. Press Enter.
  • In Command Prompt, type in net stop gmer. Press Enter.
  • Type in exit to close Command Prompt.

Note: Do not run any programs while Gmer is running.

I need you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.

Then post me another HijackThis log.
MER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-09-15 15:14:23
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT B08639A8 ZwClose
SSDT B08637E4 ZwCreateKey
SSDT B0863900 ZwDeleteKey
SSDT B0863928 ZwDeleteValueKey
SSDT sptd.sys ZwEnumerateKey [0xB9EE4D1C]
SSDT sptd.sys ZwEnumerateValueKey [0xB9EE50BC]
SSDT B08639A2 ZwLoadKey
SSDT B0863687 ZwOpenKey
SSDT sptd.sys ZwQueryKey [0xB9EE5194]
SSDT B0863886 ZwQueryValueKey
SSDT B0863952 ZwReplaceKey
SSDT B086397A ZwRestoreKey
SSDT B0863834 ZwSetValueKey

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB07D997A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB07D9928]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB07D993C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB07D99BA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xB07D9900]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xB07D9914]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB07D998E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xB07D9966]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB07D9952]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB07D99E9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB07D99D0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB07D99A4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.14 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2D72 80503C4E 2 Bytes [ 86, B0 ]
.text ntkrnlpa.exe!ZwYieldExecution 805040F8 7 Bytes JMP B07D99A8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80577F46 5 Bytes JMP B07D997E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B0BC4 7 Bytes JMP B07D99BE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B19D2 5 Bytes JMP B07D99D4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B6F98 7 Bytes JMP B07D9992 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805C9EBA 5 Bytes JMP B07D9904 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CA146 5 Bytes JMP B07D9918 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CC904 5 Bytes JMP B07D9956 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805CFBDA 7 Bytes JMP B07D9940 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805CFC90 5 Bytes JMP B07D992C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D019A 5 Bytes JMP B07D996A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D13E4 5 Bytes JMP B07D99ED \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
? Combo-Fix.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B8CF768E 5 Bytes JMP 89C5C1B8
? System32\Drivers\az8gayvp.SYS The system cannot find the file specified. !
? C:\WINDOWS\System32\drivers\netbioss.sys The process cannot access the file because it is being used by another process.
? C:\DOCUME~1\Pen\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !

—- User code sections - GMER 1.0.14 —-

.text C:\WINDOWS\explorer.exe[256] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0FEF
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A004D
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F58
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0F69
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0F86
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A0FB2
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A0F20
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A0F31
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0F05
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0094
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A0EF4
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A0FA1
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0FDE
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0068
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0FC3
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A0014
.text C:\WINDOWS\explorer.exe[256] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A0083
.text C:\WINDOWS\explorer.exe[256] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0028000A
.text C:\WINDOWS\explorer.exe[256] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00280F57
.text C:\WINDOWS\explorer.exe[256] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00280FC3
.text C:\WINDOWS\explorer.exe[256] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00280FD4
.text C:\WINDOWS\explorer.exe[256] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00280F68
.text C:\WINDOWS\explorer.exe[256] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00280F83
.text C:\WINDOWS\explorer.exe[256] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00280FEF
.text C:\WINDOWS\explorer.exe[256] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00280F9E
.text C:\WINDOWS\explorer.exe[256] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002B0000
.text C:\WINDOWS\explorer.exe[256] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002B0FDB
.text C:\WINDOWS\explorer.exe[256] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002B0011
.text C:\WINDOWS\explorer.exe[256] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 002B0022
.text C:\WINDOWS\explorer.exe[256] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00FF0000
.text C:\WINDOWS\explorer.exe[256] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00FF0FE5
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[300] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[300] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 01040FEF
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 01040F55
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 01040F70
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 01040F81
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 01040FA8
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0104002F
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 01040F33
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 01040F44
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 010400A0
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01040F07
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 01040EEC
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 01040040
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 01040FDE
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 0104006F
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 01040014
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 01040FB9
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 01040F22
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 01030FCA
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 01030047
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 01030FE5
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 0103001B
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 01030F94
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 01030FAF
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 01030000
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 01030036
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] WS2_32.dll!socket 02AB3B91 5 Bytes JMP 01010FEF
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[496] WS2_32.dll!bind 02AB3E00 5 Bytes JMP 0101000A
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00B20000
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00B20F55
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00B20F66
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00B20F83
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00B20040
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00B20FB9
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00B20F16
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00B20F33
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00B20ECF
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00B20EE0
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00B2008D
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00B20F9E
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00B20FE5
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00B20F44
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00B20FCA
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00B2001B
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00B20EFB
.text C:\WINDOWS\system32\svchost.exe[680] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00B10FDE
.text C:\WINDOWS\system32\svchost.exe[680] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00B10065
.text C:\WINDOWS\system32\svchost.exe[680] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00B10025
.text C:\WINDOWS\system32\svchost.exe[680] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00B10FEF
.text C:\WINDOWS\system32\svchost.exe[680] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00B1004A
.text C:\WINDOWS\system32\svchost.exe[680] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00B10FB2
.text C:\WINDOWS\system32\svchost.exe[680] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00B1000A
.text C:\WINDOWS\system32\svchost.exe[680] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00B10FCD
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00ED0FEF
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00ED00A9
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00ED008E
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00ED007D
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00ED006C
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00ED005B
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00ED00C6
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00ED0F7E
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00ED00F2
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00ED0F63
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00ED0F3E
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00ED0FCA
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00ED000A
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00ED0F99
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00ED0040
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00ED0025
.text C:\WINDOWS\system32\services.exe[776] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00ED00D7
.text C:\WINDOWS\system32\services.exe[776] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00A8001B
.text C:\WINDOWS\system32\services.exe[776] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00A8004E
.text C:\WINDOWS\system32\services.exe[776] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00A8000A
.text C:\WINDOWS\system32\services.exe[776] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00A80FD4
.text C:\WINDOWS\system32\services.exe[776] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00A80F9B
.text C:\WINDOWS\system32\services.exe[776] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00A8003D
.text C:\WINDOWS\system32\services.exe[776] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00A80FEF
.text C:\WINDOWS\system32\services.exe[776] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00A8002C
.text C:\WINDOWS\system32\services.exe[776] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00A50FE5
.text C:\WINDOWS\system32\services.exe[776] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00A50FD4
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00DD0000
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00DD0090
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00DD0F9B
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00DD0FB6
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00DD0073
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00DD0047
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00DD00BC
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00DD00A1
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00DD0F23
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00DD0F34
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00DD0F12
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00DD0062
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00DD0FE5
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00DD0F76
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00DD0036
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00DD0025
.text C:\WINDOWS\system32\lsass.exe[788] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00DD0F4F
.text C:\WINDOWS\system32\lsass.exe[788] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00DC0FA8
.text C:\WINDOWS\system32\lsass.exe[788] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00DC0040
.text C:\WINDOWS\system32\lsass.exe[788] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00DC0FC3
.text C:\WINDOWS\system32\lsass.exe[788] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00DC0FDE
.text C:\WINDOWS\system32\lsass.exe[788] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00DC002F
.text C:\WINDOWS\system32\lsass.exe[788] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00DC001E
.text C:\WINDOWS\system32\lsass.exe[788] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\system32\lsass.exe[788] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00DC0F97
.text C:\WINDOWS\system32\lsass.exe[788] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00CA0FEF
.text C:\WINDOWS\system32\lsass.exe[788] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00CA000A
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00950FEF
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 009500A4
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00950089
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00950FAF
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00950062
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00950036
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 009500DC
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00950F94
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00950F5E
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 009500ED
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00950F4D
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00950047
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00950FD4
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 009500B5
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00950025
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 0095000A
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00950F79
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0094001B
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00940065
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00940FD4
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00940FE5
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0094004A
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00940FA8
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00940000
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00940FB9
.text C:\WINDOWS\system32\svchost.exe[1004] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00920FE5
.text C:\WINDOWS\system32\svchost.exe[1004] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00920000
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00B30000
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00B30F4D
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00B30F5E
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00B30F79
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00B30036
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00B30F94
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00B30F15
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00B30F26
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00B30EE6
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00B30089
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetProcAddress 7C80ADA0 1 Byte [ E9 ]
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetProcAddress + 2 7C80ADA2 3 Bytes [ 52, 32, 84 ]
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00B3001B
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00B30FE5
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00B3005D
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00B30FA5
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00B30FCA
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00B30078
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00B20FC0
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00B20F6F
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00B2001B
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00B20FE5
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00B20F8A
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00B2002C
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00B20000
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00B20FAF
.text C:\WINDOWS\system32\svchost.exe[1080] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00B00FE5
.text C:\WINDOWS\system32\svchost.exe[1080] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00B0000A
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 02480FEF
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 02480F50
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 02480F6B
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 02480F7C
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 02480039
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0248001E
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 02480F1A
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 02480F35
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 024800B3
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 02480098
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 024800CE
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 02480F97
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 02480FDE
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 02480060
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 02480FBC
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 02480FCD
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 0248007D
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 02640FC3
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0264005E
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 02640014
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 02640FDE
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 02640FA1
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 02640043
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 02640FEF
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 02640FB2
.text C:\WINDOWS\System32\svchost.exe[1176] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 02580FE5
.text C:\WINDOWS\System32\svchost.exe[1176] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 02580000
.text C:\WINDOWS\System32\svchost.exe[1176] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 02360000
.text C:\WINDOWS\System32\svchost.exe[1176] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 02360011
.text C:\WINDOWS\System32\svchost.exe[1176] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 02360FE5
.text C:\WINDOWS\System32\svchost.exe[1176] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 02360FD4
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 01210FEF
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 01210FA8
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0121009D
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 01210080
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 01210065
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 01210043
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 012100CB
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 012100BA
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01210F57
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01210F68
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 01210101
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 01210054
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 01210FDE
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 01210F8D
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 01210FCD
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 01210014
.text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 012100E6
.text C:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 01200040
.text C:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 01200091
.text C:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 01200025
.text C:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 01200FE5
.text C:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 01200076
.text C:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 0120005B
.text C:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 01200000
.text C:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 01200FCA
.text C:\WINDOWS\system32\svchost.exe[1240] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 011E0000
.text C:\WINDOWS\system32\svchost.exe[1240] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 011E0011
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 008B0FEF
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 008B0087
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 008B0F92
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 008B0076
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 008B0065
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 008B004A
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 008B00BF
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 008B0F77
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008B00DA
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008B0F41
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 008B00EB
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 008B0FCD
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 008B000A
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 008B0098
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 008B0039
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 008B0FDE
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 008B0F5C
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 008A0036
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 008A0069
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 008A001B
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 008A0FEF
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 008A0058
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 008A0FB6
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 008A0000
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 008A0047
.text C:\WINDOWS\system32\svchost.exe[1264] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 007B0FEF
.text C:\WINDOWS\system32\svchost.exe[1264] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 007B000A
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00A9000A
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00A90093
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00A90FA8
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00A90082
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00A90065
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00A90FC3
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00A900CB
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoA 7C801EEE 3 Bytes JMP 00A90F83
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoA + 4 7C801EF2 1 Byte [ 84 ]
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00A90F68
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00A900F7
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00A90F57
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00A9004A
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00A9001B
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00A900AE
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00A90FD4
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00A90FE5
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00A900DC
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00830FC0
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00830F6F
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00830011
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00830FE5
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00830F94
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00830FA5
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00830000
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 0083002C
.text C:\WINDOWS\system32\svchost.exe[1376] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 0081000A
.text C:\WINDOWS\system32\svchost.exe[1376] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00810FE5
.text C:\WINDOWS\system32\svchost.exe[1376] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00840FEF
.text C:\WINDOWS\system32\svchost.exe[1376] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00840014
.text C:\WINDOWS\system32\svchost.exe[1376] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00840FDE
.text C:\WINDOWS\system32\svchost.exe[1376] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 0084002F

—- Kernel IAT/EAT - GMER 1.0.14 —-

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EE0AB6] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EE0BEE] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EE0B76] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EE171C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EE15F2] sptd.sys

—- Devices - GMER 1.0.14 —-

Device \FileSystem\Ntfs \Ntfs 89DDF1D8

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \Driver\NetBT \Device\NetBT_Tcpip_{71754956-EFDF-45CA-B2F4-6B6C4801475F} 89530990
Device \Driver\usbuhci \Device\USBPDO-0 89C4D990
Device \Driver\usbuhci \Device\USBPDO-1 89C4D990
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89E4B1D8
Device \Driver\dmio \Device\DmControl\DmConfig 89E4B1D8
Device \Driver\dmio \Device\DmControl\DmPnP 89E4B1D8
Device \Driver\dmio \Device\DmControl\DmInfo 89E4B1D8
Device \Driver\usbuhci \Device\USBPDO-2 89C4D990
Device \Driver\usbuhci \Device\USBPDO-3 89C4D990
Device \Driver\usbehci \Device\USBPDO-4 89BBA1D8

AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \Driver\00000059 \Device\00000049 sptd.sys
Device \Driver\00000059 \Device\00000049 sptd.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 89DE11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 89DE11D8
Device \Driver\Cdrom \Device\CdRom0 899F2990
Device \Driver\Cdrom \Device\CdRom1 899F2990
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 89DE01D8
Device \Driver\atapi \Device\Ide\IdePort0 89DE01D8
Device \Driver\atapi \Device\Ide\IdePort1 89DE01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 89DE01D8
Device \Driver\Cdrom \Device\CdRom2 899F2990
Device \Driver\NetBT \Device\NetBt_Wins_Export 89530990
Device \Driver\NetBT \Device\NetbiosSmb 89530990

AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \Driver\usbuhci \Device\USBFDO-0 89C4D990
Device \Driver\usbuhci \Device\USBFDO-1 89C4D990
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89479990
Device \Driver\usbuhci \Device\USBFDO-2 89C4D990
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89479990
Device \Driver\netbioss \Device\netbioss B086158A
Device \Driver\usbuhci \Device\USBFDO-3 89C4D990
Device \Driver\usbehci \Device\USBFDO-4 89BBA1D8
Device \Driver\Ftdisk \Device\FtControl 89DE11D8
Device \Driver\az8gayvp \Device\Scsi\az8gayvp1Port2Path0Target0Lun0 899C41D8
Device \Driver\az8gayvp \Device\Scsi\az8gayvp1 899C41D8
Device \Driver\az8gayvp \Device\Scsi\az8gayvp1Port2Path0Target1Lun0 899C41D8
Device \FileSystem\Fastfat \Fat 886021D8
Device \FileSystem\Fastfat \Fat AD2EC1F9

AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

Device \FileSystem\Cdfs \Cdfs 894CA990
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 1237937862
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 1757561691
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x23 0xF1 0x8A 0xB2 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xCB 0x09 0xD8 0xFF …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x25 0x87 0x21 0x88 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xFD 0x23 0xD1 0x37 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x23 0xF1 0x8A 0xB2 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xCB 0x09 0xD8 0xFF …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x25 0x87 0x21 0x88 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xFD 0x23 0xD1 0x37 …

—- EOF - GMER 1.0.14 —-

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3443 (20080915)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=58ee805db4c3484eb9c9c55b6ab8c6c2
# end=finished
# remove_checked=false
# unwanted_checked=false
# utc_time=2008-09-15 09:06:43
# local_time=2008-09-15 05:06:43 (-0500, Eastern Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=627596
# found=5
# scan_time=6355
C:\Documents and Settings\Pen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-1f9869dc-57913eff.class Java/TrojanDownloader.OpenStream.NAC trojan DBEE24E93B7EFBC279DAA14F64E9575E
C:\QooBox\Quarantine\C\Documents and Settings\Pen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-5e000ca2-23ec5f29.zip.vir Java/TrojanDownloader.OpenStream.NAB trojan 5BABF8ACE8478245B729DE3314845E2B
C:\QooBox\Quarantine\C\Documents and Settings\Pen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-5e000ca2-23ec5f29.zip.vir »ZIP »OP.class Java/TrojanDownloader.OpenStream.NAB trojan 00000000000000000000000000000000
C:\QooBox\Quarantine\C\WINDOWS\b143.exe_old.vir a variant of Win32/TrojanDropper.Agent.NJY trojan A69017C2C9B94054FD0E9F9DAB68EA65
C:\QooBox\Quarantine\C\WINDOWS\b149.exe_old.vir a variant of Win32/TrojanDropper.Agent.NJY trojan D0597B62F0797AF3395CAB607D47E3A3


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:25, on 2008-09-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Support.com\bin\tgcmd.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=22028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRA~1\POPUPP~1\PopLib.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Download] "C:\Program Files\Bellsouth\HelpCenter\ssGet.exe" 120 "http://download.fastaccess.com/download/HC43SInstaller.exe" "HC43SInstaller.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Program Files\PopupPopper\SiteList.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.tricksteronline.com/control/KALogoutComponent.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 11583 bytes
Pen,

I'm still going through the logs you've posted. Meanwhile can you get me one more?

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.
SDFix: Version 1.225
Run by [removed] on 2008-09-15 at 18:09

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:



Could Not Remove C:\Program Files\nvcoi\???????
Could Not Remove C:\WINDOWS\system32\drivers\core.cache.dsk

Folder C:\Documents and Settings\Pen\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#w*w.redtube.com - Removed
Folder C:\Program Files\nvcoi - Removed
Folder C:\Temp\tn3 - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 18:22:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:49c96ec6
"s2"=dword:68c2435b
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:23,f1,8a,b2,08,1a,49,bc,e0,10,be,ea,8d,14,42,08,54,f0,81,d2,05,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,f1,ad,30,f2,3e,e9,61,3f,d1,72,39,5f,2f,a3,07,56,57,..
"khjeh"=hex:cb,09,d8,ff,cb,1e,9c,26,46,4b,61,c1,2d,4c,74,12,e9,40,cb,a4,d7,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:25,87,21,88,5f,5d,b7,03,5a,1e,d1,e5,71,74,78,ef,3e,59,e8,31,84,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:fd,23,d1,37,30,0d,e6,6f,83,fb,76,0a,68,11,c9,27,09,43,b4,26,67,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:23,f1,8a,b2,08,1a,49,bc,e0,10,be,ea,8d,14,42,08,54,f0,81,d2,05,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,f1,ad,30,f2,3e,e9,61,3f,d1,72,39,5f,2f,a3,07,56,57,..
"khjeh"=hex:cb,09,d8,ff,cb,1e,9c,26,46,4b,61,c1,2d,4c,74,12,e9,40,cb,a4,d7,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:25,87,21,88,5f,5d,b7,03,5a,1e,d1,e5,71,74,78,ef,3e,59,e8,31,84,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:fd,23,d1,37,30,0d,e6,6f,83,fb,76,0a,68,11,c9,27,09,43,b4,26,67,..

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\NtreevSoft\\Albatross18\\ProjectG.exe"="C:\\Program Files\\NtreevSoft\\Albatross18\\ProjectG.exe:*:Enabled:Pangya Executable"
"C:\\Program Files\\mIRC\\download\\Bunny\\BuNNy Mark II v10-03-05\\mirc.exe"="C:\\Program Files\\mIRC\\download\\Bunny\\BuNNy Mark II v10-03-05\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\Ruckus Player\\Ruckus.exe"="C:\\Program Files\\Ruckus Player\\Ruckus.exe:*:Enabled:Ruckus"
"C:\\Program Files\\Starcraft\\StarCraft.exe"="C:\\Program Files\\Starcraft\\StarCraft.exe:*:Enabled:Starcraft"
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"="C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe:*:Enabled:ET"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\java.exe"="C:\\WINDOWS\\system32\\java.exe:*:Enabled:java"
"C:\\Program Files\\World of Warcraft\\WoW-2.2.2.7318-to-2.2.3.7359-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.2.2.7318-to-2.2.3.7359-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\alaplaya\\S4League\\S4Client.exe"="C:\\Program Files\\alaplaya\\S4League\\S4Client.exe:*:Enabled:Project S4 Client.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :

C:\WINDOWS\system32\drivers\core.cache.dsk Found

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 23 Aug 2006 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 2 Aug 2007 20,487 A.SHR — "C:\Program Files\McAfee\MQC\MRU.bak"
Thu 2 Aug 2007 211 A.SHR — "C:\Program Files\McAfee\MQC\qcconf.bak"
Wed 6 Feb 2008 6,350,278 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\ert.zip"
Wed 6 Feb 2008 1,802,134 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\eumoneaneshika.zip"
Wed 6 Feb 2008 2,380,233 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\gijeto.zip"
Wed 6 Feb 2008 2,022,114 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\heavenly08.zip"
Wed 6 Feb 2008 6,406,691 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\pinkbomb.zip"
Wed 6 Feb 2008 5,541,218 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\raveout.zip"
Thu 9 Nov 2006 20,480 A..H. — "C:\Program Files\alaplaya\S4League\HShield\9abb02c.dll"
Thu 9 Nov 2006 20,480 A..H. — "C:\Program Files\alaplaya\S4League\HShield\c0a79ac.dll"
Thu 26 Jul 2007 857 …HR — "C:\Documents and Settings\Pen\Application Data\SecuROM\UserData\securom_v7_01.bak"
Wed 9 Apr 2008 7,607,935 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\Naruto\ketsumegaton_e.zip"
Wed 9 Apr 2008 4,537,093 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\Naruto\letsgotothejungle.zip"
Wed 9 Apr 2008 6,695,233 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\Naruto\loopandloop.zip"
Wed 9 Apr 2008 8,834,214 A..H. — "C:\Documents and Settings\Pen\My Documents\FLCL\Naruto\ryouboumochi_e.zip"
Sun 14 Aug 2005 1,949,696 A..H. — "C:\Program Files\mIRC\download\Bunny\BuNNy Mark II v10-03-05\mirc.exe"
Sun 20 Jan 2008 3,550,370 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\15498.zip"
Sun 20 Jan 2008 7,005,861 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\arrivalcall.zip"
Sun 20 Jan 2008 5,966,883 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\arterna02.zip"
Sun 20 Jan 2008 3,069,463 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\ash.zip"
Sun 20 Jan 2008 4,979,050 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\bcbleachch.zip"
Sun 20 Jan 2008 5,879,629 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\berrystrawberry.zip"
Sun 20 Jan 2008 6,450,190 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\######.zip"
Sun 20 Jan 2008 3,121,105 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\dlaction38.zip"
Sun 20 Jan 2008 6,289,792 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\dlaction37.zip"
Sun 20 Jan 2008 4,107,372 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\dlaction36.zip"
Sun 20 Jan 2008 2,310,059 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\dlaction39.zip"
Wed 16 Apr 2008 6,525,141 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\goteijuusan02.zip"
Sun 20 Jan 2008 1,518,051 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\haruh.zip"
Sun 20 Jan 2008 5,344,555 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\hsen11_e.zip"
Sun 20 Jan 2008 3,281,620 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\hsenvol08_e.zip"
Sun 20 Jan 2008 4,445,353 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\kurosakifamily.zip"
Sun 20 Jan 2008 3,576,702 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\petithoney.zip"
Sun 20 Jan 2008 6,177,869 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\rumblesex.zip"
Sun 20 Jan 2008 8,940,546 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\shinigamizukancrazy.zip"
Sun 20 Jan 2008 3,591,833 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\uncertainsister.zip"
Sun 20 Jan 2008 1,486,790 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\yoruichi01.zip"
Sun 20 Jan 2008 2,538,212 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\yoruichi02.zip"
Sun 20 Jan 2008 5,044,639 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\yukinagatodata45.zip"
Sun 30 Jul 2006 3,132,570 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\2308.zip"
Sun 30 Jul 2006 4,112,191 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\2436.zip"
Sun 30 Jul 2006 5,205,005 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\2457.zip"
Mon 2 Oct 2006 11,334,204 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\2484.zip"
Fri 31 Aug 2007 29,190,263 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\alicia_man.zip"
Sat 29 Jul 2006 231,127 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Anime_d20_SRD_v1.0_-_Chap01-12.zip"
Fri 22 Jun 2007 8,504,249 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\AskRay_Futabu_1.zip"
Tue 27 Feb 2007 24,409,690 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Barely18_Barbie.zip"
Thu 17 Aug 2006 2,850,477 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Bunny.zip"
Wed 26 Sep 2007 64,903,387 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\consolidate.zip"
Tue 4 Sep 2007 14,209,733 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Dirty_Feet.zip"
Sun 2 Sep 2007 8,270,834 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Endurance_Test_-_Naruto_English.zip"
Mon 23 Jul 2007 3,117,233 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Final_Half_Year_eng__loli_.zip"
Thu 27 Sep 2007 16,516,167 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Futa.zip"
Fri 9 Nov 2007 67,406,602 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Hamititi_Onyesan__The_Seiji_.zip"
Tue 11 Sep 2007 6,739,088 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Hunter.zip"
Mon 23 Jul 2007 13,880,133 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ilovegirls.zip"
Sun 7 Oct 2007 58,305,833 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\JukeBOX___Others.zip"
Mon 16 Apr 2007 12,010,007 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Kasimash.zip"
Wed 28 Mar 2007 9,214,277 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Queen_s_Blade_Cattleya.zip"
Thu 17 Aug 2006 288,170,540 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ROMS.zip"
Tue 27 Feb 2007 5,258,015 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\set70.zip"
Mon 10 Sep 2007 4,291,622 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\TrollsvsElves.zip"
Sun 11 Nov 2007 36,471,585 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\W.I.T.C.H.zip"
Wed 26 Sep 2007 18,232,411 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Xration_RO.zip"
Sat 30 Jun 2007 5,554,022 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\xtreme.zip"
Mon 12 Feb 2007 7,691,368 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Yukemuri_Nyan-nyan_Jiken__Bleach_Yoruichi_.zip"
Sat 17 Feb 2007 924,725 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Yuri_And_Friends_Mai_Special_An_Incest.zip"
Fri 7 Sep 2007 17,130,905 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Zelda_Hcg.zip"
Fri 22 Jun 2007 9,770,216 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\_AskRay__Futabu___2.zip"
Mon 12 Feb 2007 10,426,181 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\_C70___HAPPY_WATER__Colorful_Bleach.zip"
Sat 21 Apr 2007 8,301,310 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\_cottage__blc.zip"
Thu 20 Sep 2007 7,644,788 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\_Serious_Graphics__Kunoichi_Style_II.zip"
Wed 16 Apr 2008 5,628,602 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\blechch_e.zip"
Wed 16 Apr 2008 2,728,332 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\bravegirlkindgiant.zip"
Wed 16 Apr 2008 3,827,743 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\coolbeautysohot.zip"
Wed 16 Apr 2008 2,417,621 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\gratefuldead_e.zip"
Wed 16 Apr 2008 5,060,632 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\otherside.zip"
Wed 16 Apr 2008 3,535,564 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\yoruichinyannohon02.zip"
Wed 16 Apr 2008 4,435,031 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\yoruichimatsuri.zip"
Wed 12 Jul 2006 20,881,384 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\asian_kung-fu_generation_-_i'm_standing_here.zip"
Wed 12 Jul 2006 21,688,080 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\asian_kung-fu_generation_-_houkai_amplifier.zip"
Tue 11 Jul 2006 105,386,241 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\Black Eyed Peas - Monkey Business.zip"
Tue 11 Jul 2006 69,965,619 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\bloc_party_-_silent_alarm.zip"
Wed 12 Jul 2006 58,075,900 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\bond_-_remixed.zip"
Wed 12 Jul 2006 58,445,124 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\bond_-_born.zip"
Wed 12 Jul 2006 68,675,604 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\bond_-_classified.zip"
Wed 12 Jul 2006 52,899,168 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\bond_-_shine.zip"
Thu 13 Jul 2006 48,754,654 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\bravery_-_the_bravery.zip"
Tue 11 Jul 2006 102,309,941 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\coheed_and_cambria_-_good_apollo_i'm_burning_star_four.zip"
Wed 12 Jul 2006 78,587,563 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\death_cab_for_cutie_-_plans.zip"
Wed 12 Jul 2006 85,161,422 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\depeche_mode_-_playing_the_angel.zip"
Wed 12 Jul 2006 58,669,555 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\franz_ferdinand_-_you_could_have_it_so_much_better.zip"
Wed 12 Jul 2006 51,008,725 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\franz_ferdinand_-_self-titled.zip"
Thu 13 Jul 2006 83,603,011 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\frou_frou_-_details.zip"
Thu 13 Jul 2006 654,872,732 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\Games.zip"
Thu 13 Jul 2006 75,932,335 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\gorillaz_-_demon_days.zip"
Wed 12 Jul 2006 79,106,102 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\jimmy_eat_world_-_futures.zip"
Thu 13 Jul 2006 64,158,181 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\l'arc~en~ciel_-_smile.zip"
Wed 12 Jul 2006 71,093,290 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\lostprophets_-_the_fake_sound_of_progress.zip"
Thu 13 Jul 2006 76,568,395 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\milk_inc_-_closer.zip"
Tue 11 Jul 2006 76,465,181 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\My Chemical Romance-Discography.zip"
Wed 12 Jul 2006 38,104,577 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\panic!_at_the_disco_-_a_fever_you_cant_sweat_out.zip"
Wed 12 Jul 2006 103,528,494 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\tatu_-_200kmh_in_the_wrong_lane.zip"
Wed 12 Jul 2006 66,324,143 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\tatu_-_dangerous_and_moving.zip"
Wed 12 Jul 2006 56,276,866 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\the_faint_-_wet_from_birth.zip"
Wed 12 Jul 2006 33,476,664 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\the_faint_-_danse_macabre.zip"
Wed 12 Jul 2006 49,262,035 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\the_faint_-_blank-wave_arcade.zip"
Wed 12 Jul 2006 81,073,082 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\the_killers_-_hot_fuss.zip"
Wed 12 Jul 2006 74,826,083 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\the_strokes_-_first_impressions_of_earth.zip"
Wed 12 Jul 2006 44,310,764 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\the_unicorns_-_who_will_cut_our_hair_when_we're_gone.zip"
Tue 11 Jul 2006 57,325,397 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\the_used_-_in_love_and_death.zip"
Tue 11 Jul 2006 12,419,152 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\ZIP Archive\Winamp.zip"
Mon 21 Apr 2008 3,612,698 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\bals.zip"
Mon 21 Apr 2008 4,445,841 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\brownnewwife.zip"
Mon 21 Apr 2008 2,833,709 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\dailylife_.zip"
Mon 21 Apr 2008 828,701 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\nisemididoronokaicalendar2007.zip"
Mon 21 Apr 2008 4,849,010 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\sweet_e.zip"
Tue 15 May 2007 1,989,184 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Other stuff\Riviera\Riviera\Riviera_1YggdraUnion.zip"
Sat 3 May 2008 3,413,856 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\WAUU WAUU\congraturations.zip"
Sat 3 May 2008 3,276,944 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\WAUU WAUU\heavenly06.zip"
Sat 3 May 2008 3,425,597 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\WAUU WAUU\heavenly07.zip"
Sun 4 May 2008 5,080,278 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\WAUU WAUU\queensparty.zip"
Sat 3 May 2008 1,966,106 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\WAUU WAUU\yuriandfriendsfullcolor08.zip"
Sat 3 May 2008 3,438,181 A..H. — "C:\Documents and Settings\Pen\Desktop\Anime n Stuff\Stuff goes where\Bleach n Haruhi\New Folder\SHAZAM\WAUU WAUU\yuriandfriends06.zip"

Finished!
Pen,

Download and Run OTMoveIt2

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\Program Files\nvcoi
    C:\WINDOWS\system32\drivers\core.cache.dsk
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post another HijackThis log also.
Explorer killed successfully
File/Folder C:\Program Files\nvcoi not found.
File move failed. C:\WINDOWS\system32\drivers\core.cache.dsk scheduled to be moved on reboot.
< purity >
< EmptyTemp >
File delete failed. C:\WINDOWS\temp\mcmsc_YnKPDHKBnAnWGyv scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1dc.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_57cJVFgbJtu0b26 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_oICfltlamUv1LU0 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_X2RggGnghCs6LJY scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\hsperfdata_SYSTEM\2004 scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09152008_212747

Files moved on Reboot…
File move failed. C:\WINDOWS\system32\drivers\core.cache.dsk scheduled to be moved on reboot.
File C:\WINDOWS\temp\mcmsc_YnKPDHKBnAnWGyv not found!
File C:\WINDOWS\temp\Perflib_Perfdata_1dc.dat not found!
C:\WINDOWS\temp\sqlite_57cJVFgbJtu0b26 moved successfully.
C:\WINDOWS\temp\sqlite_oICfltlamUv1LU0 moved successfully.
C:\WINDOWS\temp\sqlite_X2RggGnghCs6LJY moved successfully.
File C:\WINDOWS\temp\hsperfdata_SYSTEM\2004 not found!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:41, on 2008-09-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Bellsouth\HelpCenter\ssGet.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\program files\mcafee\msc\mcuimgr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=22028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRA~1\POPUPP~1\PopLib.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Download] "C:\Program Files\Bellsouth\HelpCenter\ssGet.exe" 120 "http://download.fastaccess.com/download/HC43SInstaller.exe" "HC43SInstaller.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Program Files\PopupPopper\SiteList.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.tricksteronline.com/control/KALogoutComponent.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 11685 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI