Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Red Dot in system trey and it wont go away


  • This topic is locked This topic is locked
15 replies to this topic

#1 nycpsychic

nycpsychic

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Local time:11:12 PM

Posted 05 January 2010 - 11:22 AM

hi and thanks for helping.

I got this red dot and says your acivity is being recorded everytime i click it it tells me to put password to access viewer.I know its a keylogger but i don't how to get it off, im sure there more here too.
I'm using windows xp
i treid kaspersky, spy bot and still its on. here's my hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:12:13 AM, on 1/5/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\TuneUp Utilities 2009\MemOptimizer.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\BitTorrent1\bittorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.savewealth.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - *{44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
R3 - URLSearchHook: (no name) - *~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: CleanupHelper Class - {6DFD889B-7F81-44C4-BC1F-06A857C01C41} - C:\Program Files\ArmorIE\SX.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2009\MemOptimizer.exe" autostart
O4 - HKLM\..\Policies\Explorer\Run: [Lsass Service] C:\Documents and Settings\Us\Application Data\Microsoft\Windows\lsass.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ArmorIE - {0565CF3E-6070-4272-8EEF-51E5083BE3D9} - C:\Program Files\ArmorIE\SX.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O15 - Trusted Zone: http://members.freeservers.com
O15 - Trusted Zone: http://us.mcafee.com
O15 - Trusted Zone: http://webmaila.netzero.net
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - D:\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O20 - Winlogon Notify: c001F05F - c001F05F.mat (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SMART Mirror Driver Monitor Service - SMART Technologies - C:\Documents and Settings\Us\Application Data\Bridgit\monitorservice.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 10662 bytes

Edited by nycpsychic, 05 January 2010 - 11:46 AM.


BC AdBot (Login to Remove)

 


#2 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:12 AM

Posted 12 January 2010 - 04:59 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#3 nycpsychic

nycpsychic
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Local time:11:12 PM

Posted 14 January 2010 - 09:39 PM

ran dds and it stays stuck on seven :: .
I disabled antivirus

#4 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:12 AM

Posted 15 January 2010 - 01:25 PM

Hi,

  • Please download OTL from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#5 nycpsychic

nycpsychic
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Local time:11:12 PM

Posted 16 January 2010 - 12:47 PM

ok i ran it like you said here r the results..thanks

Attached Files



#6 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:12 AM

Posted 16 January 2010 - 12:49 PM

Hi,

Please don't attach the logfiles, just post it here in your thread.


Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



--------------------------------------------------------------------

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#7 nycpsychic

nycpsychic
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Local time:11:12 PM

Posted 16 January 2010 - 01:54 PM

ok thaks here is the log

ComboFix 10-01-16.01 - Us 01/16/2010 13:12:51.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.470 [GMT -5:00]
Running from: c:\documents and settings\Us\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Images
c:\images\index.html
C:\Thumbs.db
C:\VDM5.tmp
C:\VDM6.tmp
c:\windows\jestertb.dll
c:\windows\system32\LnpsvGgh.ini
c:\windows\system32\Thumbs.db
c:\windows\system32\twain_32.dll
c:\windows\unins000.dat
c:\windows\unins000.exe
F:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-12-16 to 2010-01-16 )))))))))))))))))))))))))))))))
.

2010-01-16 17:07 . 2010-01-16 18:17 8693760 ----a-w- c:\windows\system32\{E39AB999-4BA8-1D3E-6646-651C0F466F1C}.dat
2010-01-16 17:07 . 2010-01-16 18:17 1093632 ----a-w- c:\windows\system32\{DC3E0E62-FC53-229A-9DF1-C123EEF1CB23}.dat
2010-01-11 19:25 . 2010-01-16 18:17 5213184 ----a-w- c:\windows\system32\{DE674FFC-D44D-20A1-03B0-982177B19221}.dat
2010-01-10 05:01 . 2003-03-19 09:05 89088 ----a-w- c:\windows\system32\ATL71.DLL
2010-01-10 04:39 . 2010-01-16 18:17 1093632 ----a-w- c:\windows\system32\{8E44C6CA-E590-714E-3539-BB71533AB171}.dat
2010-01-10 04:27 . 2010-01-10 05:01 -------- d-----w- c:\program files\Common Files\cdrdao
2010-01-09 23:09 . 2010-01-09 23:10 -------- d-----w- c:\program files\NewsBin
2010-01-09 16:15 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 01:37 . 2010-01-16 18:17 2177024 ----a-w- c:\windows\system32\{BF1DB0E8-2470-4057-174F-E2407AB8E840}.dat
2010-01-07 01:37 . 2010-01-16 18:17 1093632 ----a-w- c:\windows\system32\{E19704D5-9195-1EDD-2AFB-681E4F0C621E}.dat
2010-01-07 01:24 . 2010-01-16 18:17 2193408 ----a-w- c:\windows\system32\{397BE972-ABDB-C630-8D16-84C6E0E08EC6}.dat
2010-01-07 01:24 . 2010-01-16 18:17 1110016 ----a-w- c:\windows\system32\{FCCFC19D-8334-0384-623E-300307C83A03}.dat
2010-01-05 16:17 . 2010-01-16 18:17 1093632 ----a-w- c:\windows\system32\{1E509674-58C3-E103-8B69-AFE1E07BA5E1}.dat
2010-01-05 16:12 . 2010-01-16 18:17 5032960 ----a-w- c:\windows\system32\{019533D2-FD69-FEC6-2DCC-6AFE5ADE60FE}.dat
2010-01-02 22:48 . 2010-01-16 18:17 5017600 ----a-w- c:\windows\system32\{85673128-BC97-7A06-D7CE-987AA7FD927A}.dat
2010-01-02 04:43 . 2010-01-11 03:28 -------- d-----w- c:\documents and settings\Us\Application Data\NewsBin
2010-01-02 04:43 . 2010-01-02 04:43 -------- d-----w- c:\documents and settings\All Users\Application Data\NewsBin
2009-12-27 18:09 . 2009-12-27 18:09 -------- d-----w- c:\program files\Seagate
2009-12-27 18:09 . 2009-12-27 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Seagate
2009-12-19 03:08 . 2003-06-23 06:44 1415680 ----a-w- c:\windows\system32\wmv9vcm.dll
2009-12-19 02:01 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-16 18:26 . 2009-11-26 23:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-01-10 04:48 . 2009-10-24 18:26 -------- d-----w- c:\documents and settings\Us\Application Data\BitTorrent
2010-01-07 21:07 . 2008-10-03 02:31 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-27 18:31 . 2004-11-16 12:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-14 19:06 . 2004-11-19 00:17 -------- d-----w- c:\documents and settings\Us\Application Data\AdobeUM
2009-12-03 22:41 . 2009-12-03 22:41 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2009-12-03 22:41 . 2009-12-03 22:41 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2009-11-30 01:36 . 2009-11-30 01:36 932368 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2009-11-30 01:36 . 2009-11-30 01:36 678416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2009-11-30 01:36 . 2009-11-30 01:36 604688 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2009-11-30 01:36 . 2009-11-30 01:35 1096208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2009-11-30 01:35 . 2009-11-30 01:35 522768 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2009-11-27 01:44 . 2009-11-27 01:44 397328 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\oeas.dll
2009-11-27 01:44 . 2009-11-27 01:44 17936 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\kloehk.dll
2009-11-27 01:44 . 2009-11-27 01:44 109072 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mzvkbd3.dll
2009-11-27 01:44 . 2009-11-27 01:44 315408 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\sys\i386\5.1\klif.sys
2009-11-26 23:09 . 2009-11-26 23:09 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-11-26 23:09 . 2009-11-26 23:09 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-11-26 23:08 . 2009-11-26 23:08 -------- d-----w- c:\program files\Kaspersky Lab
2009-11-26 23:02 . 2008-06-01 03:12 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-11-26 22:52 . 2009-01-27 00:52 0 ----a-w- c:\documents and settings\Us\Local Settings\Application Data\prvlcl.dat
2009-11-26 22:49 . 2009-11-26 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-11-19 16:48 . 2009-12-28 19:48 872960 ----a-w- c:\documents and settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-19 16:48 . 2009-12-28 19:48 43008 ----a-w- c:\documents and settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-19 16:48 . 2009-12-28 19:48 340480 ----a-w- c:\documents and settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-19 16:48 . 2009-12-28 19:48 346624 ----a-w- c:\documents and settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-10-29 07:45 . 2004-08-04 11:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-24 16:34 . 2004-11-24 20:41 173448 ----a-w- c:\documents and settings\Us\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-24 01:01 . 2009-10-24 01:01 17217008 ----a-w- c:\documents and settings\Us\Application Data\Real\Update\setup\rp\RealPlayerSPGold.exe
2009-10-24 01:01 . 2009-10-24 01:01 8406648 ----a-w- c:\documents and settings\Us\Application Data\Real\Update\setup\gtb_us\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2009-10-24 01:01 . 2009-10-24 01:01 10309448 ----a-w- c:\documents and settings\Us\Application Data\Real\Update\setup\chr\ChromeInstaller.exe
2009-10-24 01:01 . 2009-10-24 01:01 64000 ----a-w- c:\documents and settings\Us\Application Data\Real\Update\setup\RUP\inst_config\gcapi_dll.dll
2009-10-24 01:01 . 2009-10-24 01:01 52288 ----a-w- c:\documents and settings\Us\Application Data\Real\Update\setup\RUP\inst_config\gtapi.dll
2009-10-24 01:01 . 2009-10-24 01:01 50688 ----a-w- c:\documents and settings\Us\Application Data\Real\Update\setup\RUP\inst_config\fftbapi.dll
2009-10-24 01:01 . 2009-10-24 01:01 114688 ----a-w- c:\documents and settings\Us\Application Data\Real\Update\setup\RUP\inst_config\compat.dll
2009-10-24 01:00 . 2008-09-15 22:15 488968 ----a-w- c:\documents and settings\Us\Application Data\Real\Update\setup\setup.exe
2009-10-21 05:38 . 2004-08-04 11:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 11:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-21 01:34 . 2009-10-21 01:34 219664 ----a-w- c:\windows\system32\klogon.dll
2009-10-20 16:54 . 2009-10-20 16:54 59992 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\English\setup.exe
2009-10-20 16:20 . 2004-08-04 11:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-07-25 15:04 . 2009-07-25 15:04 774144 ----a-w- c:\program files\RngInterstitial.dll
1999-04-30 20:00 . 2005-10-29 14:57 98304 ----a-w- c:\program files\internet explorer\plugins\UPjpeg.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 21:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Ddebin]
@="{298B49CE-6DBA-4919-B5D8-591A4171CC88}"
[HKEY_CLASSES_ROOT\CLSID\{298B49CE-6DBA-4919-B5D8-591A4171CC88}]
2006-07-05 10:55 1250641 ----a-w- c:\windows\SYSTEM32\odbcie.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TuneUp MemOptimizer"="c:\program files\TuneUp Utilities 2009\MemOptimizer.exe" [2008-12-12 155904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 1388544]
"Dell Photo AIO Printer 922"="c:\program files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-06-18 290816]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-11-16 77824]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-21 340456]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-9-11 972064]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Forget Me Not.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetZero_uoltray]
2005-11-15 19:12 776704 ----a-w- c:\program files\NetZero\exec.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2007-11-03 16:02 185632 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" /r
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"Omnipage"=c:\program files\ScanSoft\OmniPageSE\opware32.exe
"SMART Mirror Driver Monitor Service"="c:\documents and settings\Us\Application Data\Bridgit\monitorservice.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ScanSoft\\OmniPageSE\\EregEng\\NAVBrowser.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"d:\\Qwix.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\BitTorrent\\bittorrent.exe"=
"d:\\Program Files\\IBP 10\\IBP.exe"=
"c:\\Program Files\\BitTorrent1\\bittorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\SYSTEM32\DRIVERS\klbg.sys [10/14/2009 9:18 PM 36880]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/25/2009 11:32 PM 189736]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\SYSTEM32\DRIVERS\klim5.sys [9/14/2009 2:42 PM 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\SYSTEM32\DRIVERS\klmouflt.sys [10/2/2009 7:39 PM 19472]
R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\SYSTEM32\DRIVERS\lne100v5.sys [7/22/2006 3:36 PM 36224]
S2 SMART Mirror Driver Monitor Service;SMART Mirror Driver Monitor Service;c:\documents and settings\Us\Application Data\Bridgit\monitorservice.exe [10/1/2005 9:26 AM 135680]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [3/20/2007 9:45 PM 1527900]
S3 USB-100;USB 10/100 Ethernet Adapter;c:\windows\SYSTEM32\DRIVERS\USBER100.SYS [12/22/2004 5:12 PM 23938]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
tapisrv REG_MULTI_SZ Tapisrv
.
Contents of the 'Scheduled Tasks' folder

2010-01-16 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 02:36]

2010-01-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-07-10 21:29]

2010-01-16 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-06-25 14:05]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
LSP: c:\windows\system32\mclsp.dll
Trusted Zone: freeservers.com\members
Trusted Zone: godaddy.com\idp
Trusted Zone: hostgator.com\secure
Trusted Zone: mcafee.com\us
Trusted Zone: netzero.net\webmaila
Trusted Zone: yahoo.com\games
FF - ProfilePath - c:\documents and settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2077878&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Queens_Psychic Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2077878&q=
FF - component: c:\documents and settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\program files\Google\Google Updater\1.4.681.27779\npCIDetect7.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: d:\divx\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: d:\divx\DivX Web Player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-*~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Notify-c001F05F - c001F05F.mat
AddRemove-Scooby-Doo™, Phantom of the Knight™ - c:\program files\The Learning Company\Scooby-Doo™
AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-16 13:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="0B8342DCF11AE30FC2DC2B6F3DC6C17AC3716422523943B313145CE51681EA14E258D5057ADD3D4CFE56121B0D0E519C85024F1FD42D35B1ED93927E072227FD60F749C9849F923463612DEAABB0EAFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667A6A0AC4980AC7933FEBC9E127BECC74CA6A0AC4980AC7933BC175EE16FD527531641583FDE21547B8B371FE95F252FDD0F140614DB9B11E50A29FE9A097202F6C6ACA8F6211D4FC5F42F59F42A34A0F3C2E6D147D566AF0F7542695AE5397FCBA35A5C8BAA1AAEA0721F9B1B8DBCD5286DEC39012ACC74546259DB06796FF1F65AE244AE8993A61018E6E6F94F8E82F8AC6B0F6EF813365317B618F3DB6DEFD27B36B3057095AF4A5F39BE235A0CA11B047CA62D83918D5D40F86573C89FD5EDF91782A8314105BDA5202B1E3A2B6EF7D80B5BCFB1315AF7EB110EC0A186C20B301B8CA547CC28072CF43BE3A2756BABF558895F8DF1BC5D0FC6E012E7B41921592FB0FC4D80DCFA99E87E62E90ADD070AF994D447689CF900B1B10F44D401DB949052A386BA2AA0F47E887C089BCD0FA858DF20313AA2EFF9C0D4538421649669525B04D6EBDDB32D8FF3879CEF887A452F57A441A3BE159CB527EF956A7366BD5B34FAC69986A413C55CCD68DF20B73C9067B793F32271EB2685670E16A0905FE64FD6835D7995DD23628DD25C69E64CE10227E68EC245CEFBD2B2A49BA311FD821FDFDC64CD5E24F8A9F76365FCDA16591DAF9D6AD9FE907477BEB386F715AD929ACC4A6EE08B65EFDCB34A93B81E220631053F91E846E0A1DCE83E78DBFEE74CBECC62D3D2DB0305A75BD80F3EEDD9483D4EF5252EF35469F088662553E508BB0B7E647B0742BF06BAFB849571B78A54C1A711D7B295DF06A762F3D42494CFBE8279AEE2A4E7C819CA97677CFA22E8B2C51D84F0BEECDF0577355363DA89E1082C44C69B1BA6293410A43FA8C9850A415134E4CBE0EE14C65AAF9442C576472016DD56CB968ED2A3488D6E928E6EE7307364EED66CC6A083CE76EA7478C2ED5FCD36AAAB0F631B86B32FF9CA3D1DE184BD17819776CE0B4359202E92CA09A3F567323389B99C3B52165D8C729006B916C4AB9DA2599BC064FD3A5BC9D6961F667A2C864593E551CC38DC74C08451169323F4ECA433F10F97C9451258FAEFF607A2EF5B545D1FDD136767227E5BDC017BF53AB7DBE5C9ABE4C9B315955CC92904803E11C19BDA4715F42BAC8A993869235FB76F9D98D2AC24906ECCE6618F155A37CD26A815E0D516344B4E5908A8A135859B25CEB3EC8D833650C64A34DFFEDDED46C13CD6ACB8AC7EDCE2EDB3A4E02D8F878F6D672FAC85D4AB304FC50D10B5D0C4AB4030EEFE47B069EEE3EE5B3FDA2E940B8625E14F"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(1084)
c:\windows\system32\mclsp.dll
c:\windows\system32\SPORDER.dll

- - - - - - - > 'explorer.exe'(3200)
c:\windows\system32\WININET.dll
c:\windows\system32\odbcie.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\System32\TUProgSt.exe
c:\windows\wanmpsvc.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Dell Photo AIO Printer 922\dlbtbmon.exe
c:\progra~1\MICROS~2\rapimgr.exe
.
**************************************************************************
.
Completion time: 2010-01-16 13:41:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-16 18:41

Pre-Run: 4,219,723,776 bytes free
Post-Run: 4,135,645,184 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 9A356C256139AE1F2964B2DE2F9D2828

#8 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:12 AM

Posted 16 January 2010 - 02:38 PM

Hi,


Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.




  • Please download OTL from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#9 nycpsychic

nycpsychic
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Local time:11:12 PM

Posted 16 January 2010 - 05:11 PM

ok

walware was clean.



OTL logfile created on: 1/16/2010 4:23:57 PM - Run 2
OTL by OldTimer - Version 3.1.25.0 Folder = C:\Documents and Settings\Us\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 454.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.94 Gb Total Space | 3.64 Gb Free Space | 5.13% Space Free | Partition Type: NTFS
Drive D: | 279.46 Gb Total Space | 61.61 Gb Free Space | 22.05% Space Free | Partition Type: NTFS
Drive E: | 4.11 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 931.51 Gb Total Space | 509.43 Gb Free Space | 54.69% Space Free | Partition Type: NTFS
Drive G: | 14.97 Gb Total Space | 11.36 Gb Free Space | 75.85% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: UNITED
Current User Name: Us
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/01/15 12:42:10 | 00,546,816 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Us\Desktop\OTL.exe
PRC - [2010/01/07 18:10:07 | 00,307,672 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/10/20 20:39:28 | 00,340,456 | ---- | M] (Kaspersky Lab) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
PRC - [2009/10/20 20:34:38 | 00,207,376 | ---- | M] (Kaspersky Lab) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
PRC - [2009/09/25 23:32:18 | 00,189,736 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2009/01/24 20:53:02 | 00,603,904 | ---- | M] (TuneUp Software) -- C:\WINDOWS\SYSTEM32\TUProgSt.exe
PRC - [2008/12/11 21:36:16 | 00,155,904 | ---- | M] (TuneUp Software GmbH) -- C:\Program Files\TuneUp Utilities 2009\MemOptimizer.exe
PRC - [2008/04/13 19:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\wscntfy.exe
PRC - [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/09/05 09:53:48 | 00,020,480 | ---- | M] (Intuit) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2005/11/15 19:44:14 | 01,200,128 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PRC - [2005/11/15 19:42:22 | 00,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe
PRC - [2005/09/20 09:32:24 | 00,077,824 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\hkcmd.exe
PRC - [2004/06/30 14:33:04 | 01,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
PRC - [2004/06/18 10:46:00 | 00,102,400 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
PRC - [2004/06/18 10:30:26 | 00,290,816 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
PRC - [2003/01/10 17:13:04 | 00,065,536 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\wanmpsvc.exe


========== Modules (SafeList) ==========

MOD - [2010/01/15 12:42:10 | 00,546,816 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Us\Desktop\OTL.exe
MOD - [2006/07/05 05:55:01 | 01,250,641 | ---- | M] () -- C:\WINDOWS\SYSTEM32\odbcie.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/10/20 20:39:28 | 00,340,456 | ---- | M] (Kaspersky Lab) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe -- (AVP)
SRV - [2009/09/25 23:32:18 | 00,189,736 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)
SRV - [2009/01/24 20:53:02 | 00,603,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\SYSTEM32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2009/01/24 20:52:55 | 00,360,192 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2007/09/05 09:53:48 | 00,020,480 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2007/05/24 07:08:44 | 00,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2007/03/14 18:19:10 | 00,779,824 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService)
SRV - [2007/03/12 12:49:46 | 00,271,920 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2007/02/04 13:17:36 | 00,138,168 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2006/05/14 20:00:32 | 00,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2005/11/17 13:18:52 | 01,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2005/10/01 09:26:35 | 00,135,680 | ---- | M] (SMART Technologies) [Auto | Stopped] -- C:\Documents and Settings\Us\Application Data\Bridgit\monitorservice.exe -- (SMART Mirror Driver Monitor Service)
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005/03/02 19:19:06 | 00,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service)
SRV - [2004/03/16 15:33:24 | 00,421,888 | ---- | M] (Dell) [On_Demand | Stopped] -- C:\WINDOWS\System32\dlbtcoms.exe -- (dlbt_device)
SRV - [2003/12/17 14:59:48 | 00,143,360 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc)
SRV - [2003/08/12 12:50:40 | 01,376,360 | ---- | M] (America Online, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\AOL\ACS\acsd.exe -- (AOL ACS)
SRV - [2003/01/10 17:13:04 | 00,065,536 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\WINDOWS\wanmpsvc.exe -- (WANMiniportService) WAN Miniport (ATW)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: *{44F9B173-041C-4825-A9B9-D914BD9DCBB3} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaultthis.engineName: "Queens_Psychic Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2077878&SearchSource=3&q="
FF - prefs.js..browser.search.selectedEngine: "Queens_Psychic Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.736
FF - prefs.js..extensions.enabledItems: {b2509cd4-17cd-45ed-8146-a82af038f493}:1.22
FF - prefs.js..extensions.enabledItems: seo4firefox@seobook.com:3.1.3
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2077878&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/07 18:10:23 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/07 18:10:23 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2009/11/26 18:09:06 | 00,000,000 | ---D | M]

[2009/03/01 14:19:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Mozilla\Extensions
[2010/01/16 14:03:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions
[2009/01/03 21:41:22 | 00,000,000 | ---D | M] (Queens Psychic Toolbar) -- C:\Documents and Settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions\{ae96ef81-a22f-43a0-8e7d-34dc977754d3}
[2009/06/14 08:00:06 | 00,000,000 | ---D | M] (Power Twitter) -- C:\Documents and Settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions\{b2509cd4-17cd-45ed-8146-a82af038f493}
[2009/04/25 18:44:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\extensions\seo4firefox@seobook.com
[2009/07/10 16:26:08 | 00,002,257 | ---- | M] () -- C:\Documents and Settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\searchplugins\askcom.xml
[2009/01/04 02:31:00 | 00,000,890 | ---- | M] () -- C:\Documents and Settings\Us\Application Data\Mozilla\Firefox\Profiles\pjrvpk45.default\searchplugins\conduit.xml
[2010/01/16 14:03:05 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/11/26 18:10:06 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2009/07/25 10:04:15 | 00,024,576 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npgcplug.dll
[2005/04/27 15:10:49 | 00,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npracplug.dll

O1 HOSTS File: (27 bytes) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (CleanupHelper Class) - {6DFD889B-7F81-44C4-BC1F-06A857C01C41} - C:\Program Files\ArmorIE\SX.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll ()
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [Dell Photo AIO Printer 922] C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe ()
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\SYSTEM32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\SYSTEM32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [TuneUp MemOptimizer] C:\Program Files\TuneUp Utilities 2009\MemOptimizer.exe (TuneUp Software GmbH)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000055 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O12 - Plugin for: .UVR - C:\Program Files\Internet Explorer\PLUGINS\NPUPano.dll (Ulead Systems, Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: freeservers.com ([members] http in Trusted sites)
O15 - HKCU\..Trusted Domains: godaddy.com ([idp] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hostgator.com ([secure] https in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([us] http in Trusted sites)
O15 - HKCU\..Trusted Domains: netzero.net ([webmaila] http in Trusted sites)
O15 - HKCU\..Trusted Domains: pcsecuritynews.com ([www] http in Internet)
O15 - HKCU\..Trusted Domains: yahoo.com ([games] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 61 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 207.69.188.185 207.69.188.186 207.69.188.187
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - D:\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: <Company name>)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\SYSTEM32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Documents and Settings\Us\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Us\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/01/02 10:44:02 | 00,003,072 | ---- | M] () - D:\AutoRAR.db3 -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2005/05/12 14:43:25 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)

========== Files/Folders - Created Within 14 Days ==========

[2010/01/16 16:22:27 | 00,546,816 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Us\Desktop\OTL.exe
[2010/01/16 16:04:36 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2010/01/16 13:41:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/01/16 13:06:12 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2010/01/16 13:05:05 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/01/16 13:05:05 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/01/16 13:05:05 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/01/16 13:05:05 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/01/16 13:04:55 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/01/16 13:04:40 | 00,000,000 | ---D | C] -- C:\Qoobox
[2010/01/09 23:27:12 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\cdrdao
[2010/01/09 20:49:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Us\My Documents\My Karaoke
[2010/01/09 18:09:22 | 00,000,000 | ---D | C] -- C:\Program Files\NewsBin
[2010/01/09 11:15:46 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/09 10:44:31 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/07/25 10:04:33 | 00,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2009/06/11 19:26:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\AVGTOOLBAR
[2009/02/23 20:37:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/01/11 10:05:31 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/01/11 09:45:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Intuit
[2008/10/13 18:05:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2008/10/13 18:05:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
[2008/05/31 22:11:41 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/05/31 22:11:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2007/10/19 20:49:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2007/10/19 20:49:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2007/04/01 14:32:42 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Us\Application Data\pcouffin.sys
[2007/04/01 13:19:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Ahead
[2006/12/18 10:25:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2006/12/18 10:25:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Google
[2005/10/17 20:26:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\EarthLink Toolbar
[2005/03/02 19:24:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\McAfee.com
[2004/12/23 16:07:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2004/11/18 19:00:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/01/16 16:26:26 | 08,693,760 | ---- | M] () -- C:\WINDOWS\System32\{E39AB999-4BA8-1D3E-6646-651C0F466F1C}.dat
[2010/01/16 16:26:26 | 05,394,432 | ---- | M] () -- C:\WINDOWS\System32\{DE674FFC-D44D-20A1-03B0-982177B19221}.dat
[2010/01/16 16:26:26 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{DC3E0E62-FC53-229A-9DF1-C123EEF1CB23}.dat
[2010/01/16 16:21:06 | 05,050,368 | ---- | M] () -- C:\WINDOWS\System32\{85673128-BC97-7A06-D7CE-987AA7FD927A}.dat
[2010/01/16 16:07:39 | 05,049,344 | ---- | M] () -- C:\WINDOWS\System32\{019533D2-FD69-FEC6-2DCC-6AFE5ADE60FE}.dat
[2010/01/16 16:03:16 | 19,136,512 | ---- | M] () -- C:\Documents and Settings\Us\NTUSER.DAT
[2010/01/16 16:02:36 | 08,792,064 | ---- | M] () -- C:\WINDOWS\System32\{64F5EE63-E28D-89D3-9C11-0A9BF516009B}.dat
[2010/01/16 16:02:36 | 08,792,064 | ---- | M] () -- C:\WINDOWS\System32\{248723A3-C348-C9AC-5CDC-78DB35DB72DB}.dat
[2010/01/16 16:02:36 | 08,775,680 | ---- | M] () -- C:\WINDOWS\System32\{49BC4675-3801-A498-8AB9-43B6E3B249B6}.dat
[2010/01/16 16:02:36 | 08,742,912 | ---- | M] () -- C:\WINDOWS\System32\{02929157-3348-EFBA-A86E-6DFDC16F67FD}.dat
[2010/01/16 16:02:36 | 08,726,528 | ---- | M] () -- C:\WINDOWS\System32\{A023A2AE-0025-4D65-515D-DC5F385FD65F}.dat
[2010/01/16 16:02:36 | 08,726,528 | ---- | M] () -- C:\WINDOWS\System32\{651D4C5A-EFD7-8823-A5B3-E29ACCB9E89A}.dat
[2010/01/16 16:02:36 | 08,710,144 | ---- | M] () -- C:\WINDOWS\System32\{C6468298-680F-2B02-677D-B9390E7BB339}.dat
[2010/01/16 16:02:36 | 08,710,144 | ---- | M] () -- C:\WINDOWS\System32\{B4DA1989-9F5E-59ED-76E6-254B1FE72F4B}.dat
[2010/01/16 16:02:36 | 08,710,144 | ---- | M] () -- C:\WINDOWS\System32\{B0A870DD-EBCE-5D87-228F-574F4B8B5D4F}.dat
[2010/01/16 16:02:36 | 08,710,144 | ---- | M] () -- C:\WINDOWS\System32\{5BD43ECB-E63A-B6F9-34C1-2BA45DC321A4}.dat
[2010/01/16 16:02:36 | 08,693,760 | ---- | M] () -- C:\WINDOWS\System32\{370052B0-BC3A-DA22-4FAD-FFC826A2F5C8}.dat
[2010/01/16 16:02:36 | 02,193,408 | ---- | M] () -- C:\WINDOWS\System32\{F8CAD7EA-CC6C-0402-1528-350761283F07}.dat
[2010/01/16 16:02:36 | 02,193,408 | ---- | M] () -- C:\WINDOWS\System32\{AD52C8DA-0944-401B-2537-AD525137A752}.dat
[2010/01/16 16:02:36 | 02,193,408 | ---- | M] () -- C:\WINDOWS\System32\{9AC1F6C3-8849-77FC-3C09-3E6548063465}.dat
[2010/01/16 16:02:36 | 02,193,408 | ---- | M] () -- C:\WINDOWS\System32\{397BE972-ABDB-C630-8D16-84C6E0E08EC6}.dat
[2010/01/16 16:02:36 | 02,193,408 | ---- | M] () -- C:\WINDOWS\System32\{215643AB-1364-CC7A-54BC-A9DE20BAA3DE}.dat
[2010/01/16 16:02:36 | 02,177,024 | ---- | M] () -- C:\WINDOWS\System32\{BF1DB0E8-2470-4057-174F-E2407AB8E840}.dat
[2010/01/16 16:02:36 | 02,177,024 | ---- | M] () -- C:\WINDOWS\System32\{AEAAE604-8EEF-4388-FB19-55518F095F51}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{FCCFC19D-8334-0384-623E-300307C83A03}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{C1019B70-A0DF-2C42-8F64-FE3EFC67F43E}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{A2F3B963-B915-4F9F-9C46-0C5DEC42065D}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{832D6115-5E3C-6E10-EA9E-D27C9D88D87C}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{76E25FCD-9B0E-9BDC-32A0-1D8945A81789}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{590875E0-0335-B469-1F8A-F7A66C89FDA6}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{4C63A992-D773-A15E-6D56-9CB31D5996B3}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{4B1876A9-057D-A645-5689-E7B4218DEDB4}.dat
[2010/01/16 16:02:36 | 01,110,016 | ---- | M] () -- C:\WINDOWS\System32\{0D8A36D6-7166-E0D4-29C9-75F242CB7FF2}.dat
[2010/01/16 16:02:36 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{E19704D5-9195-1EDD-2AFB-681E4F0C621E}.dat
[2010/01/16 16:02:36 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{B11D0872-F054-5C33-8DF7-E24EE6F2E84E}.dat
[2010/01/16 16:02:36 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{9FC0C11B-3EA5-72E7-E43E-3F60973D3560}.dat
[2010/01/16 16:02:36 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{9A2EAB3F-2936-7713-C054-D165AC5ADB65}.dat
[2010/01/16 16:02:36 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{8E44C6CA-E590-714E-3539-BB71533AB171}.dat
[2010/01/16 16:02:36 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{32E75315-AAAF-DFDB-EAAC-18CD9DB112CD}.dat
[2010/01/16 16:02:36 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{1E509674-58C3-E103-8B69-AFE1E07BA5E1}.dat
[2010/01/16 16:02:36 | 01,093,632 | ---- | M] () -- C:\WINDOWS\System32\{022B43D1-6B24-EF0D-2EBC-D4FD5EBBDEFD}.dat
[2010/01/16 16:01:16 | 00,000,228 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/01/16 16:00:03 | 00,000,480 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/01/16 13:53:47 | 00,000,426 | ---- | M] () -- C:\WINDOWS\tasks\XoftSpySE 2.job
[2010/01/16 13:26:59 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/01/16 13:26:11 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2010/01/16 13:24:44 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2010/01/16 13:23:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/01/16 13:22:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/01/16 13:22:58 | 10,716,97920 | -HS- | M] () -- C:\hiberfil.sys
[2010/01/16 13:21:41 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Us\NTUSER.INI
[2010/01/16 13:06:24 | 00,000,281 | RHS- | M] () -- C:\BOOT.INI
[2010/01/16 13:02:58 | 03,827,010 | R--- | M] () -- C:\Documents and Settings\Us\Desktop\ComboFix.exe
[2010/01/15 12:42:10 | 00,546,816 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Us\Desktop\OTL.exe
[2010/01/13 23:29:06 | 00,003,823 | ---- | M] () -- C:\Documents and Settings\Us\My Documents\ISO1_DVD.nri
[2010/01/10 17:27:03 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/01/09 10:53:47 | 00,000,851 | ---- | M] () -- C:\WINDOWS\WIN.INI
[2010/01/09 10:53:47 | 00,000,211 | ---- | M] () -- C:\Boot.bak
[2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/05 13:26:49 | 00,000,610 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\View Recorded Data.lnk
[2010/01/05 11:11:42 | 00,000,815 | ---- | M] () -- C:\Documents and Settings\Us\Desktop\HijackThis.lnk
[2010/01/04 18:39:31 | 00,001,037 | ---- | M] () -- C:\WINDOWS\dellstat.ini
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/16 13:06:24 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2010/01/16 13:06:20 | 00,260,272 | ---- | C] () -- C:\cmldr
[2010/01/16 13:05:05 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/01/16 13:05:05 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/01/16 13:05:05 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/01/16 13:05:05 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/01/16 13:05:05 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/01/16 13:02:53 | 03,827,010 | R--- | C] () -- C:\Documents and Settings\Us\Desktop\ComboFix.exe
[2010/01/16 12:07:26 | 08,693,760 | ---- | C] () -- C:\WINDOWS\System32\{E39AB999-4BA8-1D3E-6646-651C0F466F1C}.dat
[2010/01/16 12:07:26 | 01,093,632 | ---- | C] () -- C:\WINDOWS\System32\{DC3E0E62-FC53-229A-9DF1-C123EEF1CB23}.dat
[2010/01/13 23:29:06 | 00,003,823 | ---- | C] () -- C:\Documents and Settings\Us\My Documents\ISO1_DVD.nri
[2010/01/11 14:25:43 | 05,394,432 | ---- | C] () -- C:\WINDOWS\System32\{DE674FFC-D44D-20A1-03B0-982177B19221}.dat
[2010/01/09 23:39:07 | 01,093,632 | ---- | C] () -- C:\WINDOWS\System32\{8E44C6CA-E590-714E-3539-BB71533AB171}.dat
[2010/01/09 10:53:46 | 00,002,109 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2010/01/06 20:37:00 | 02,177,024 | ---- | C] () -- C:\WINDOWS\System32\{BF1DB0E8-2470-4057-174F-E2407AB8E840}.dat
[2010/01/06 20:37:00 | 01,093,632 | ---- | C] () -- C:\WINDOWS\System32\{E19704D5-9195-1EDD-2AFB-681E4F0C621E}.dat
[2010/01/06 20:24:02 | 02,193,408 | ---- | C] () -- C:\WINDOWS\System32\{397BE972-ABDB-C630-8D16-84C6E0E08EC6}.dat
[2010/01/06 20:24:02 | 01,110,016 | ---- | C] () -- C:\WINDOWS\System32\{FCCFC19D-8334-0384-623E-300307C83A03}.dat
[2010/01/05 13:26:49 | 00,000,610 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\View Recorded Data.lnk
[2010/01/05 11:17:40 | 01,093,632 | ---- | C] () -- C:\WINDOWS\System32\{1E509674-58C3-E103-8B69-AFE1E07BA5E1}.dat
[2010/01/05 11:12:28 | 05,049,344 | ---- | C] () -- C:\WINDOWS\System32\{019533D2-FD69-FEC6-2DCC-6AFE5ADE60FE}.dat
[2010/01/05 11:11:42 | 00,000,815 | ---- | C] () -- C:\Documents and Settings\Us\Desktop\HijackThis.lnk
[2010/01/02 17:48:26 | 05,050,368 | ---- | C] () -- C:\WINDOWS\System32\{85673128-BC97-7A06-D7CE-987AA7FD927A}.dat
[2009/06/12 21:44:21 | 00,000,029 | ---- | C] () -- C:\WINDOWS\ua.ini
[2009/04/21 18:57:24 | 00,000,049 | -H-- | C] () -- C:\Documents and Settings\Us\Application Data\MaxBulk registration.ini
[2009/03/10 22:15:57 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\snEUps.dll
[2009/03/10 22:15:26 | 00,282,624 | ---- | C] () -- C:\WINDOWS\System32\AOSMTPEX.dll
[2009/03/10 22:15:23 | 00,678,682 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\unins000.exe
[2009/03/10 22:15:23 | 00,026,160 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\unins000.dat
[2009/01/26 19:52:46 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Us\Local Settings\Application Data\prvlcl.dat
[2008/10/05 09:40:36 | 00,000,125 | ---- | C] () -- C:\Documents and Settings\Us\Local Settings\Application Data\fusioncache.dat
[2008/09/19 08:30:43 | 00,001,367 | ---- | C] () -- C:\WINDOWS\pixcache.ini
[2008/09/16 19:12:50 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2008/09/15 19:29:36 | 00,000,068 | ---- | C] () -- C:\WINDOWS\System32\fs_di002.dll
[2008/08/23 13:08:48 | 00,000,133 | ---- | C] () -- C:\WINDOWS\padadd.INI
[2008/07/13 11:47:51 | 00,000,291 | ---- | C] () -- C:\Documents and Settings\Us\Local Settings\Application Data\rssbuilder.ftpconfig
[2008/07/13 11:42:10 | 00,000,033 | ---- | C] () -- C:\Documents and Settings\Us\Local Settings\Application Data\rssbuilder.config
[2008/07/04 13:30:53 | 00,000,095 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/03/31 16:25:46 | 00,831,488 | ---- | C] () -- C:\WINDOWS\System32\divx_xx0a.dll
[2008/03/31 15:33:28 | 01,060,864 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2008/03/31 15:33:28 | 00,909,312 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2008/03/31 15:33:28 | 00,182,784 | ---- | C] () -- C:\WINDOWS\System32\DGVorbis.dll
[2008/03/31 15:33:28 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\Mp3dec.dll
[2008/03/31 15:33:28 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2008/03/31 15:33:28 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\DGRip.dll
[2008/03/31 15:33:28 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\vorbisfile.dll
[2008/03/26 16:13:46 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\mp3enc.dll
[2008/03/21 15:30:08 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/03/21 15:28:54 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/03/21 15:28:54 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/03/21 15:28:20 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/12/09 17:12:28 | 00,002,508 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\$_hpcst$.hpc
[2007/10/29 08:42:52 | 00,000,785 | ---- | C] () -- C:\WINDOWS\News Manager.ini
[2007/10/02 14:02:16 | 00,004,081 | ---- | C] () -- C:\WINDOWS\WinSig.Ini
[2007/10/02 14:02:16 | 00,000,046 | ---- | C] () -- C:\WINDOWS\Reader.Ini
[2007/10/02 14:01:14 | 00,002,191 | ---- | C] () -- C:\WINDOWS\WinRos.Ini
[2007/04/01 14:32:45 | 00,000,055 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\pcouffin.log
[2007/04/01 14:32:43 | 00,087,608 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\ezpinst.exe
[2007/04/01 14:32:43 | 00,007,824 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\pcouffin.cat
[2007/04/01 14:32:42 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\pcouffin.inf
[2007/03/20 21:43:28 | 00,005,817 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2007/02/09 19:23:40 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2007/01/14 17:23:06 | 00,002,162 | ---- | C] () -- C:\WINDOWS\System32\tmmute.ini
[2006/10/10 09:31:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2006/09/18 14:37:50 | 00,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx12_ic.ini
[2006/09/18 14:37:48 | 00,667,280 | ---- | C] () -- C:\WINDOWS\System32\tx12.dll
[2006/05/16 20:04:29 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll
[2006/03/11 19:19:56 | 00,000,223 | ---- | C] () -- C:\WINDOWS\Clony2.ini
[2006/03/11 18:59:36 | 00,000,067 | ---- | C] () -- C:\WINDOWS\A1 DVD Ripper.INI
[2006/02/12 19:47:46 | 00,000,120 | ---- | C] () -- C:\WINDOWS\PbkUser.INI
[2005/11/19 15:25:39 | 00,000,151 | ---- | C] () -- C:\WINDOWS\disney.ini
[2005/11/16 09:15:04 | 00,164,112 | ---- | C] () -- C:\WINDOWS\System32\awmpi.dll
[2005/10/29 10:18:45 | 00,000,108 | ---- | C] () -- C:\WINDOWS\Vstudio.INI
[2005/10/29 10:12:09 | 00,000,045 | ---- | C] () -- C:\WINDOWS\dswplug.ini
[2005/10/29 10:03:23 | 00,001,199 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2005/10/29 10:03:23 | 00,000,040 | ---- | C] () -- C:\WINDOWS\Msdevctl.ini
[2005/09/30 14:04:03 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Bridgit.INI
[2005/02/28 20:01:34 | 00,000,070 | ---- | C] () -- C:\WINDOWS\ARFolder.INI
[2005/02/28 19:59:02 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\edtExt.dll
[2005/02/20 10:55:21 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2005/02/05 13:31:08 | 00,001,436 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2005/01/29 11:43:50 | 00,054,784 | ---- | C] () -- C:\Documents and Settings\Us\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/25 10:31:54 | 00,025,713 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2005/01/17 22:17:27 | 00,095,232 | ---- | C] () -- C:\WINDOWS\System32\LFKODAK.DLL
[2005/01/17 22:17:26 | 00,306,688 | ---- | C] () -- C:\WINDOWS\System32\LFFPX7.DLL
[2005/01/17 22:17:21 | 01,483,776 | ---- | C] () -- C:\WINDOWS\MGXRDR32.DLL
[2005/01/13 20:48:52 | 00,000,034 | ---- | C] () -- C:\WINDOWS\AuthMgr.INI
[2005/01/09 13:18:52 | 00,001,037 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/01/09 13:18:05 | 00,143,360 | R--- | C] () -- C:\WINDOWS\System32\dlbtcoin.dll
[2005/01/09 13:18:05 | 00,126,976 | R--- | C] () -- C:\WINDOWS\System32\dlbtsnls.dll
[2005/01/09 13:17:39 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbtvs.dll
[2005/01/09 13:17:37 | 00,114,688 | ---- | C] () -- C:\WINDOWS\System32\dlbtcur.dll
[2005/01/09 13:17:37 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\dlbtcu.dll
[2005/01/09 13:17:35 | 00,557,056 | ---- | C] () -- C:\WINDOWS\System32\dlbtjswr.dll
[2005/01/09 13:17:32 | 00,401,408 | ---- | C] () -- C:\WINDOWS\System32\dlbtutil.dll
[2004/12/16 22:13:29 | 00,385,024 | ---- | C] () -- C:\WINDOWS\System32\GM4S32.dll
[2004/11/26 09:37:23 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/11/26 09:35:56 | 00,000,049 | ---- | C] () -- C:\WINDOWS\SGEDIT.INI
[2004/11/26 09:35:52 | 00,000,768 | ---- | C] () -- C:\WINDOWS\mpass.ini
[2004/11/26 09:23:36 | 00,000,090 | ---- | C] () -- C:\WINDOWS\Tbplus.ini
[2004/11/26 09:23:30 | 00,046,512 | ---- | C] () -- C:\WINDOWS\System32\EPSN.DLL
[2004/11/26 09:23:30 | 00,012,126 | ---- | C] () -- C:\WINDOWS\System32\PIXPCZ.DLL
[2004/11/26 09:23:30 | 00,011,934 | ---- | C] () -- C:\WINDOWS\System32\PIXPNR.DLL
[2004/11/26 09:23:29 | 00,000,001 | ---- | C] () -- C:\WINDOWS\TB96.INI
[2004/11/26 08:09:32 | 00,061,678 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\PFP120JPR.{PB
[2004/11/26 08:09:32 | 00,012,358 | ---- | C] () -- C:\Documents and Settings\Us\Application Data\PFP120JCM.{PB
[2004/11/24 17:42:43 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\IPPCPUID.DLL
[2004/11/24 17:42:25 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmsbfn32.dll
[2004/11/24 17:41:14 | 00,000,931 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2004/11/23 21:19:52 | 00,114,688 | ---- | C] () -- C:\WINDOWS\System32\wmatime.dll
[2004/11/21 16:21:25 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2004/11/19 21:48:51 | 00,000,618 | ---- | C] () -- C:\WINDOWS\wencyc99.ini
[2004/11/19 21:48:51 | 00,000,012 | ---- | C] () -- C:\WINDOWS\timeline.ini
[2004/11/19 21:48:51 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2004/11/19 21:06:43 | 00,009,136 | ---- | C] () -- C:\WINDOWS\System32\Inetwh16.dll
[2004/11/19 21:05:56 | 00,000,114 | ---- | C] () -- C:\WINDOWS\kpcms.ini
[2004/11/19 21:05:55 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2004/11/19 21:05:53 | 00,100,864 | ---- | C] () -- C:\WINDOWS\System32\Dc50ip32.dll
[2004/11/19 21:05:53 | 00,006,144 | ---- | C] () -- C:\WINDOWS\System32\ImgLibLead.dll
[2004/11/19 21:04:43 | 00,043,008 | ---- | C] () -- C:\WINDOWS\System32\LTFIL62N.DLL
[2004/11/19 21:04:43 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\LTTWN62N.DLL
[2004/11/19 21:04:43 | 00,016,896 | ---- | C] () -- C:\WINDOWS\System32\ftpclient.dll
[2004/11/19 21:04:43 | 00,003,200 | ---- | C] () -- C:\WINDOWS\System32\LTTHK62W.DLL
[2004/11/16 07:43:05 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/11/16 07:10:54 | 00,000,520 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 14:13:12 | 00,000,780 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/04 06:00:00 | 01,250,641 | ---- | C] () -- C:\WINDOWS\System32\odbcie.dll
[2004/08/04 06:00:00 | 00,003,523 | ---- | C] () -- C:\WINDOWS\System32\lockdhcp.dll
[2004/08/04 06:00:00 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2003/03/23 20:35:20 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2002/05/24 01:00:00 | 00,208,896 | ---- | C] () -- C:\WINDOWS\System32\lockout.dll
[2002/05/24 01:00:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\lockres.dll
[2002/03/13 16:46:46 | 00,053,248 | R--- | C] () -- C:\WINDOWS\System32\zlib.dll
[1999/01/22 13:46:58 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 03:00:00 | 00,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL
[1980/01/01 01:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2007/04/01 17:24:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
[2008/11/09 18:18:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Agama Web Menus
[2006/10/24 21:32:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avanquest Software
[2009/06/12 16:41:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2007/01/23 15:51:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/01/10 12:04:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2007/03/20 21:45:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
[2007/10/14 09:17:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/01/01 23:43:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NewsBin
[2009/01/10 11:20:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Palo Alto Software
[2009/01/10 11:07:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PAS
[2005/01/02 23:20:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBT
[2005/02/19 11:22:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/12/27 13:09:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2008/04/12 10:21:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2006/05/01 08:52:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/12/03 08:59:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2008/04/12 11:21:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/08/22 15:41:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2009/03/14 11:23:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/09/08 15:55:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Learning Company
[2006/12/09 12:32:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2006/05/14 09:55:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/01/21 16:42:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\AVGTOOLBAR
[2010/01/09 23:48:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\BitTorrent
[2008/04/26 13:20:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Blackberry Desktop
[2008/08/23 18:08:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Blumentals
[2005/10/01 09:26:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Bridgit
[2005/02/04 20:57:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Canon
[2009/01/31 16:06:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\DNA
[2005/01/13 20:46:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Earthlink
[2005/01/13 20:46:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\EarthLink Toolbar
[2008/08/25 19:43:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Ewen Chia's My Free Website Builder
[2006/05/03 16:15:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Good Keywords v2
[2009/02/20 16:20:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\IBP
[2004/11/24 17:31:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\InterTrust
[2005/10/30 09:47:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Leadertech
[2007/03/20 21:46:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\MAGIX
[2009/04/21 18:55:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Maxprog
[2007/10/26 16:07:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Micro-Sys
[2007/10/14 09:17:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\NCH Swift Sound
[2010/01/16 16:02:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\NewsBin
[2004/11/24 17:41:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\NewSoft
[2005/11/14 17:56:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Opera
[2008/08/21 21:08:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\PADGen
[2009/01/10 11:12:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Palo Alto Software
[2007/03/24 18:13:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Publish Providers
[2008/09/07 12:23:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Quick Search And Replace
[2007/06/28 18:01:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Research In Motion
[2004/11/24 17:41:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\ScanSoft
[2008/08/27 21:11:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Serif
[2009/02/27 18:08:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Software Defender
[2007/03/24 18:08:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Sony
[2006/02/12 19:04:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\TuneUp Software
[2007/02/20 21:18:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Uniblue
[2004/11/21 16:29:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\VERITAS
[2007/04/01 17:24:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\Vso
[2008/04/12 10:29:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Us\Application Data\win third book
[2010/01/16 16:00:03 | 00,000,480 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010/01/16 16:01:16 | 00,000,228 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 06:00:00 | 18,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2004/08/04 06:00:00 | 18,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2009/03/27 20:37:55 | 23,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2009/03/27 20:37:55 | 23,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 00:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\I386\AGP440.SYS
[2004/08/04 00:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 06:00:00 | 18,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2004/08/04 06:00:00 | 18,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2009/03/27 20:37:55 | 23,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2009/03/27 20:37:55 | 23,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/03 23:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\I386\atapi.sys
[2004/08/03 23:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/03 23:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 06:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\I386\EVENTLOG.DLL
[2004/08/04 06:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SYSTEM32\netlogon.dll
[2004/08/04 06:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\I386\NETLOGON.DLL
[2004/08/04 06:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 06:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\I386\SCECLI.DLL
[2004/08/04 06:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SYSTEM32\scecli.dll

< %systemroot%\*. /mp /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 174 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F5A61FDD
@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC3571BD
< End of report >

#10 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:12 AM

Posted 17 January 2010 - 03:41 PM

Hi,


I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#11 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:12 AM

Posted 22 January 2010 - 12:41 PM

Due to the lack of feedback, this topic is now closed.
If you need this topic reopened, please PM a staff member and we will reopen it for you (include the address of this thread in your request). This applies to the original topic starter only. Everyone else with similar problems, please start a new topic.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#12 nycpsychic

nycpsychic
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Local time:11:12 PM

Posted 24 January 2010 - 05:21 PM

i did the eset scan here is the log

C:\Documents and Settings\All Users\Start Menu\Programs\Power CD+G Burner\Keygen.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
C:\Documents and Settings\Us\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Inbox.dbx HTML/Phishing.gen trojan unable to clean
C:\Documents and Settings\Us\My Documents\programs\Gsa Auto Submiter\gsa\GSA Auto Softsubmit 5.62\auto_softsubmit_demo.exe a variant of Win32/Packed.Themida application deleted - quarantined
C:\I386\GTDownDE_87.ocx probably a variant of Win32/Adware.Agent application cleaned by deleting - quarantined
C:\Program Files\Banner Maker Pro 7\bannermaker.exe probably a variant of Win32/TrojanDownloader.Agent trojan cleaned by deleting - quarantined
C:\Program Files\NewsBin\nb535-crack.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\LnpsvGgh.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
D:\cracks\ADB_KG_Collection\ADOBE _CS 3_ KeyGens COLLECTION\2007-04-20 Adobe.Fireworks.CS3.Keymaker.Only-ZWT\keygen.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
D:\cracks\ADB_KG_Collection\ADOBE _CS 3_ KeyGens COLLECTION\2007-04-21 Adobe.Dreamweaver.CS3.Keymaker.Only-ZWT\Keygen.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
D:\cracks\ADB_KG_Collection\ADOBE _CS 3_ KeyGens COLLECTION\Adobe.Dreamweaver.CS3.v9.0.3453.Incl.Keygen.INTERNAL.READ.NFO-SSG\keygen.exe probably a variant of Win32/Spy.Agent trojan cleaned by deleting - quarantined
D:\cracks\ADB_KG_Collection\ADOBE _CS 3_ KeyGens COLLECTION\Adobe.Flash.CS3.Keymaker.Only-ZWT\Keygen.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
D:\cracks\Banner_Maker_Pro_v7.0.3_2b\Crack\bannermaker.exe probably a variant of Win32/TrojanDownloader.Agent trojan cleaned by deleting - quarantined
D:\cracks\VIDEO_TS\AtoWsSbmi307cw\AtoWsSbmi307cw\auto_websubmit_demo.exe a variant of Win32/Packed.Themida application deleted - quarantined
D:\music\dance\hack\alt.binaries.warez\Hackers_toolkit_2005\appz\CrackersKit 2005\CrackersKit.1.1-DappA.exe multiple threats deleted - quarantined
D:\music\dance\hack\alt.binaries.warez\Hackers_toolkit_2005\appz\Net Tools Suite Pack Abril\NetTools3.exe probably a variant of Win32/Genetik trojan deleted - quarantined
D:\newdownloads\email_spider_demo.exe a variant of Win32/Packed.Themida application deleted - quarantined
G:\.wd_tv\Karaoke CDG Creator PRO 2.1.6 + CRACK [Create Karaoke versions of Your Favourite Songs]\karaokecdgcreatorprosetup 2.1.6.exe multiple threats deleted - quarantined
G:\charts\msr.exe probably a variant of Win32/Genetik trojan cleaned by deleting - quarantined
G:\kareoke\web submit tools\Hello Engine! 5 Professional (Submitting your Site 700 search engine)\crack\Hello_Engines_Professional_v5_1_3_0_patch.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
G:\Newsbin Pro 5.35 Build 1842\nb535-crack.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
G:\Power CD+G burner 1.4.6 + keygen\Keygen.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined

#13 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,947 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:12:12 AM

Posted 24 January 2010 - 05:49 PM

Hello nycpsychic,

I have merged your new topic with your previously existing topic which I have reopened. If you know you will be gone for a while, please inform your helper so he knows you haven't abandoned the topic.

Back to you Schrauber,

Orange Blossom :(
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#14 nycpsychic

nycpsychic
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Local time:11:12 PM

Posted 25 January 2010 - 07:53 PM

THANK U

#15 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:12 AM

Posted 26 January 2010 - 03:57 PM

Hi,


The practice of using cracking tools, keygens, warez or any pirated software is not only considered illegal activity but it is a serious security risk.

Cracking applications are used for illegally breaking (cracking) various copy-protection and registration techniques used in commercial software. These programs may be distributed via Web sites, Usenet, and P2P networks.

http://www.trendmicro.com/vinfo/grayware/v...=CRCK_KEYGEN.BB

...warez and crack web pages are being used by cybercriminals as download sites for malware related to VIRUT and VIRUX. Searches for serial numbers, cracks, and even antivirus products like Trend Micro yield malcodes that come in the form of executables or self-extracting files...quick links in these sites also lead to malicious files. Ads and banners are also infection vectors...

http://blog.trendmicro.com/crack-sites-dis...rux-and-fakeav/ When you use these kind of programs, be forewarned that some of the worst types of malware infections can be contracted and spread by visiting crack, keygen, warez and other pirated software sites. In many cases, those sites are infested with a lot of malware and an increasing source of system infection. Those who attempt to get software for free can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS. If you still need assistance please remove all cracked software from your system.




Please post back with a fresh OTl logfile.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users