Hi here are the logs you requested. MBAM detected a malware trace but the redirects still exist. The Extras.txt from OTL is attached as a file.
MBAM Log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4428
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18928
8/14/2010 10:56:47 AM
mbam-log.txt
Scan type: Quick scan
Objects scanned: 145608
Time elapsed: 6 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\registrymonitor2 (Malware.Trace) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER Log
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-08-14 14:13:10
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\CHRIST~1\AppData\Local\Temp\kwddipod.sys
---- System - GMER 1.0.15 ----
INT 0x51 ? 86FB3BF8
INT 0x62 ? 86FB3BF8
INT 0x72 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x92 ? 86FB3BF8
---- Kernel code sections - GMER 1.0.15 ----
? System32\Drivers\spew.sys The system cannot find the path specified. !
PAGE ataport.SYS!DllUnload 82D68B2E 5 Bytes JMP 8555C1D8
.text USBPORT.SYS!DllUnload 8F95241B 5 Bytes JMP 86FB31D8
PAGE spsys.sys!?SPVersion@@3PADA + 1ABF A045003F 110 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F A04500AF 1 Byte [16]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F A04500AF 128 Bytes [16, 3B, C8, 75, E2, B0, 01, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB0 A0450130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB7 A0450137 2298 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 0092000A
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 0093000A
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0063000A
.text C:\Windows\system32\svchost.exe[1184] ole32.dll!CoCreateInstance 766B9EA6 5 Bytes JMP 0099000A
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!GetCursorPos 77980B88 5 Bytes JMP 013A000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 0048000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 0049000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0047000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 016B000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 016C000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0050000A
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 85EE51F8
Device \FileSystem\udfs \UdfsCdRom 8769A1F8
Device \FileSystem\udfs \UdfsDisk 8769A1F8
Device \Driver\volmgr \Device\VolMgrControl 8555E1F8
Device \Driver\usbuhci \Device\USBPDO-0 86E871F8
Device \Driver\usbuhci \Device\USBPDO-1 86E871F8
Device \Driver\usbuhci \Device\USBPDO-2 86E871F8
Device \Driver\usbehci \Device\USBPDO-3 86F2F1F8
Device \Driver\usbuhci \Device\USBPDO-4 86E871F8
Device \Driver\usbuhci \Device\USBPDO-5 86E871F8
Device \Driver\usbuhci \Device\USBPDO-6 86E871F8
Device \Driver\volmgr \Device\HarddiskVolume1 8555E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbehci \Device\USBPDO-7 86F2F1F8
Device \Driver\volmgr \Device\HarddiskVolume2 8555E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom1 871761F8
Device \Driver\netbt \Device\NetBt_Wins_Export 876A6500
Device \Driver\Smb \Device\NetbiosSmb 872EE1F8
Device \Driver\iScsiPrt \Device\RaidPort0 871831F8
Device \Driver\netbt \Device\NetBT_Tcpip_{28B3D8F2-F0FB-4318-9417-7F3739B50CB4} 876A6500
Device \Driver\usbuhci \Device\USBFDO-0 86E871F8
Device \Driver\usbuhci \Device\USBFDO-1 86E871F8
Device \Driver\usbuhci \Device\USBFDO-2 86E871F8
Device \Driver\usbehci \Device\USBFDO-3 86F2F1F8
Device \Driver\usbuhci \Device\USBFDO-4 86E871F8
Device \Driver\usbuhci \Device\USBFDO-5 86E871F8
Device \Driver\usbuhci \Device\USBFDO-6 86E871F8
Device \Driver\usbehci \Device\USBFDO-7 86F2F1F8
Device \Driver\VClone \Device\Scsi\VClone1Port5Path0Target0Lun0 871A81F8
Device \Driver\VClone \Device\Scsi\VClone1 871A81F8
Device \FileSystem\cdfs \Cdfs 881CD1F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0x07 0xF8 0x54 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0x07 0xF8 0x54 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
---- EOF - GMER 1.0.15 ----
OTL Log
OTL logfile created on: 8/14/2010 2:15:32 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Christian\Downloads
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 174.80 Gb Total Space | 123.28 Gb Free Space | 70.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CHRISTIAN
Current User Name: Christian
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Users\Christian\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Modules (SafeList) ========== MOD - C:\Users\Christian\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Stereo Service) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (aspnet_state) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (nmservice) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AEADIFilters) -- C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Driver Services (SafeList) ========== DRV - (SjyPkt) -- C:\Windows\System32\Drivers\SjyPkt.sys File not found
DRV - (pcmcia) -- C:\Windows\System32\drivers\pcmcia.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (atapi) -- C:\Windows\system32\drivers\kav_atapi.sys ()
DRV - (WsAudio_DeviceS(5)) WsAudio_DeviceS(5) -- C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys (Wondershare)
DRV - (WsAudio_DeviceS(4)) WsAudio_DeviceS(4) -- C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys (Wondershare)
DRV - (WsAudio_DeviceS(3)) WsAudio_DeviceS(3) -- C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys (Wondershare)
DRV - (WsAudio_DeviceS(2)) WsAudio_DeviceS(2) -- C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys (Wondershare)
DRV - (WsAudio_DeviceS(1)) WsAudio_DeviceS(1) -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV - (taphss) -- C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (truecrypt) -- C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (VBoxNetAdp) -- C:\Windows\System32\drivers\VBoxNetAdp.sys (Sun Microsystems, Inc.)
DRV - (VBoxUSBMon) -- C:\Windows\System32\drivers\VBoxUSBMon.sys (Sun Microsystems, Inc.)
DRV - (VBoxDrv) -- C:\Windows\System32\drivers\VBoxDrv.sys (Sun Microsystems, Inc.)
DRV - (VBoxNetFlt) -- C:\Windows\System32\drivers\VBoxNetFlt.sys (Sun Microsystems, Inc.)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (purendis) -- C:\Windows\System32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) -- C:\Windows\System32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTL8187) -- C:\Windows\System32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (tapvpn) -- C:\Windows\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell)
DRV - (ADIHdAudAddService) -- C:\Windows\System32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 64 BF F1 EB D8 C9 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: Strata40@SpewBoy.au:0.6.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/09 19:59:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/09 19:59:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/08/07 10:46:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/08/04 18:45:49 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions
[2010/08/04 18:45:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/01/17 22:01:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
[2010/08/14 10:57:15 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions
[2010/08/12 10:17:59 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/02 20:58:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}
[2010/07/14 20:19:29 | 000,000,000 | ---D | M] (Readability) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}(19)
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/02/07 23:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{989e9382-d540-4189-88d1-fc54a949a387}
[2010/07/15 23:25:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{ABAD4342-3FDA-4ccf-80AC-B6D0EECACA07}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/08/10 18:01:54 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/19 20:59:44 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(10606)
[2010/07/11 20:55:30 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(36)
[2009/09/17 21:57:06 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(37)
[2009/12/02 20:57:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{de5809e0-2b07-11dd-bd0b-0800200c9a66}
[2009/12/15 21:33:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\bettergmail2@ginatrapani.org
[2009/08/24 11:57:09 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\chromifox@altmusictv(91).com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\firebug@software.joehewitt.com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\grwatcher@ajnasz.hu
[2009/09/17 22:23:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\LogMeInClient@logmein(36).com
[2010/07/15 12:55:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\omnibar@ajitk(35).com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\omnibar@ajitk.com
[2010/02/14 00:25:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\opera10skin@firefox.theme
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\Strata40@SpewBoy.au
[2010/07/16 14:27:47 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\Strata40@SpewBoy.au\chrome\mozapps\extensions
[2009/06/20 11:10:42 | 000,002,164 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\bing.xml
[2010/08/11 14:16:09 | 000,001,879 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\skreemr-audio-search.xml
[2009/06/20 11:11:43 | 000,001,980 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\wolframalpha.xml
[2010/08/14 10:57:15 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/06 12:05:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/03/17 17:44:32 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitR
Hi here are the logs you requested. MBAM detected a malware trace but the redirects still exist. The Extras.txt from OTL is attached as a file.
MBAM Log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4428
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18928
8/14/2010 10:56:47 AM
mbam-log.txt
Scan type: Quick scan
Objects scanned: 145608
Time elapsed: 6 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\registrymonitor2 (Malware.Trace) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER Log
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-08-14 14:13:10
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\CHRIST~1\AppData\Local\Temp\kwddipod.sys
---- System - GMER 1.0.15 ----
INT 0x51 ? 86FB3BF8
INT 0x62 ? 86FB3BF8
INT 0x72 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x92 ? 86FB3BF8
---- Kernel code sections - GMER 1.0.15 ----
? System32\Drivers\spew.sys The system cannot find the path specified. !
PAGE ataport.SYS!DllUnload 82D68B2E 5 Bytes JMP 8555C1D8
.text USBPORT.SYS!DllUnload 8F95241B 5 Bytes JMP 86FB31D8
PAGE spsys.sys!?SPVersion@@3PADA + 1ABF A045003F 110 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F A04500AF 1 Byte [16]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F A04500AF 128 Bytes [16, 3B, C8, 75, E2, B0, 01, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB0 A0450130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB7 A0450137 2298 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 0092000A
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 0093000A
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0063000A
.text C:\Windows\system32\svchost.exe[1184] ole32.dll!CoCreateInstance 766B9EA6 5 Bytes JMP 0099000A
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!GetCursorPos 77980B88 5 Bytes JMP 013A000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 0048000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 0049000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0047000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 016B000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 016C000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0050000A
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 85EE51F8
Device \FileSystem\udfs \UdfsCdRom 8769A1F8
Device \FileSystem\udfs \UdfsDisk 8769A1F8
Device \Driver\volmgr \Device\VolMgrControl 8555E1F8
Device \Driver\usbuhci \Device\USBPDO-0 86E871F8
Device \Driver\usbuhci \Device\USBPDO-1 86E871F8
Device \Driver\usbuhci \Device\USBPDO-2 86E871F8
Device \Driver\usbehci \Device\USBPDO-3 86F2F1F8
Device \Driver\usbuhci \Device\USBPDO-4 86E871F8
Device \Driver\usbuhci \Device\USBPDO-5 86E871F8
Device \Driver\usbuhci \Device\USBPDO-6 86E871F8
Device \Driver\volmgr \Device\HarddiskVolume1 8555E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbehci \Device\USBPDO-7 86F2F1F8
Device \Driver\volmgr \Device\HarddiskVolume2 8555E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom1 871761F8
Device \Driver\netbt \Device\NetBt_Wins_Export 876A6500
Device \Driver\Smb \Device\NetbiosSmb 872EE1F8
Device \Driver\iScsiPrt \Device\RaidPort0 871831F8
Device \Driver\netbt \Device\NetBT_Tcpip_{28B3D8F2-F0FB-4318-9417-7F3739B50CB4} 876A6500
Device \Driver\usbuhci \Device\USBFDO-0 86E871F8
Device \Driver\usbuhci \Device\USBFDO-1 86E871F8
Device \Driver\usbuhci \Device\USBFDO-2 86E871F8
Device \Driver\usbehci \Device\USBFDO-3 86F2F1F8
Device \Driver\usbuhci \Device\USBFDO-4 86E871F8
Device \Driver\usbuhci \Device\USBFDO-5 86E871F8
Device \Driver\usbuhci \Device\USBFDO-6 86E871F8
Device \Driver\usbehci \Device\USBFDO-7 86F2F1F8
Device \Driver\VClone \Device\Scsi\VClone1Port5Path0Target0Lun0 871A81F8
Device \Driver\VClone \Device\Scsi\VClone1 871A81F8
Device \FileSystem\cdfs \Cdfs 881CD1F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0x07 0xF8 0x54 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0x07 0xF8 0x54 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
---- EOF - GMER 1.0.15 ----
OTL Log
OTL logfile created on: 8/14/2010 2:15:32 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Christian\Downloads
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 174.80 Gb Total Space | 123.28 Gb Free Space | 70.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CHRISTIAN
Current User Name: Christian
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Users\Christian\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Modules (SafeList) ========== MOD - C:\Users\Christian\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Stereo Service) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (aspnet_state) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (nmservice) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AEADIFilters) -- C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Driver Services (SafeList) ========== DRV - (SjyPkt) -- C:\Windows\System32\Drivers\SjyPkt.sys File not found
DRV - (pcmcia) -- C:\Windows\System32\drivers\pcmcia.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (atapi) -- C:\Windows\system32\drivers\kav_atapi.sys ()
DRV - (WsAudio_DeviceS(5)) WsAudio_DeviceS(5) -- C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys (Wondershare)
DRV - (WsAudio_DeviceS(4)) WsAudio_DeviceS(4) -- C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys (Wondershare)
DRV - (WsAudio_DeviceS(3)) WsAudio_DeviceS(3) -- C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys (Wondershare)
DRV - (WsAudio_DeviceS(2)) WsAudio_DeviceS(2) -- C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys (Wondershare)
DRV - (WsAudio_DeviceS(1)) WsAudio_DeviceS(1) -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV - (taphss) -- C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (truecrypt) -- C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (VBoxNetAdp) -- C:\Windows\System32\drivers\VBoxNetAdp.sys (Sun Microsystems, Inc.)
DRV - (VBoxUSBMon) -- C:\Windows\System32\drivers\VBoxUSBMon.sys (Sun Microsystems, Inc.)
DRV - (VBoxDrv) -- C:\Windows\System32\drivers\VBoxDrv.sys (Sun Microsystems, Inc.)
DRV - (VBoxNetFlt) -- C:\Windows\System32\drivers\VBoxNetFlt.sys (Sun Microsystems, Inc.)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (purendis) -- C:\Windows\System32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) -- C:\Windows\System32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTL8187) -- C:\Windows\System32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (tapvpn) -- C:\Windows\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell)
DRV - (ADIHdAudAddService) -- C:\Windows\System32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 64 BF F1 EB D8 C9 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: Strata40@SpewBoy.au:0.6.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/09 19:59:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/09 19:59:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/08/07 10:46:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/08/04 18:45:49 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions
[2010/08/04 18:45:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/01/17 22:01:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
[2010/08/14 10:57:15 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions
[2010/08/12 10:17:59 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/02 20:58:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}
[2010/07/14 20:19:29 | 000,000,000 | ---D | M] (Readability) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}(19)
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/02/07 23:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{989e9382-d540-4189-88d1-fc54a949a387}
[2010/07/15 23:25:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{ABAD4342-3FDA-4ccf-80AC-B6D0EECACA07}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/08/10 18:01:54 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/19 20:59:44 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(10606)
[2010/07/11 20:55:30 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(36)
[2009/09/17 21:57:06 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(37)
[2009/12/02 20:57:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{de5809e0-2b07-11dd-bd0b-0800200c9a66}
[2009/12/15 21:33:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\bettergmail2@ginatrapani.org
[2009/08/24 11:57:09 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\chromifox@altmusictv(91).com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\firebug@software.joehewitt.com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\grwatcher@ajnasz.hu
[2009/09/17 22:23:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\LogMeInClient@logmein(36).com
[2010/07/15 12:55:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\omnibar@ajitk(35).com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\omnibar@ajitk.com
[2010/02/14 00:25:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\opera10skin@firefox.theme
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\Strata40@SpewBoy.au
[2010/07/16 14:27:47 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\Strata40@SpewBoy.au\chrome\mozapps\extensions
[2009/06/20 11:10:42 | 000,002,164 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\bing.xml
[2010/08/11 14:16:09 | 000,001,879 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\skreemr-audio-search.xml
[2009/06/20 11:11:43 | 000,001,980 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\wolframalpha.xml
[2010/08/14 10:57:15 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/06 12:05:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/03/17 17:44:32 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitR
Hi here are the logs you requested. MBAM detected a malware trace but the redirects still exist. The Extras.txt from OTL is attached as a file.
MBAM Log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4428
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18928
8/14/2010 10:56:47 AM
mbam-log.txt
Scan type: Quick scan
Objects scanned: 145608
Time elapsed: 6 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\registrymonitor2 (Malware.Trace) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER Log
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-08-14 14:13:10
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\CHRIST~1\AppData\Local\Temp\kwddipod.sys
---- System - GMER 1.0.15 ----
INT 0x51 ? 86FB3BF8
INT 0x62 ? 86FB3BF8
INT 0x72 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x92 ? 86FB3BF8
---- Kernel code sections - GMER 1.0.15 ----
? System32\Drivers\spew.sys The system cannot find the path specified. !
PAGE ataport.SYS!DllUnload 82D68B2E 5 Bytes JMP 8555C1D8
.text USBPORT.SYS!DllUnload 8F95241B 5 Bytes JMP 86FB31D8
PAGE spsys.sys!?SPVersion@@3PADA + 1ABF A045003F 110 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F A04500AF 1 Byte [16]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F A04500AF 128 Bytes [16, 3B, C8, 75, E2, B0, 01, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB0 A0450130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB7 A0450137 2298 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 0092000A
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 0093000A
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0063000A
.text C:\Windows\system32\svchost.exe[1184] ole32.dll!CoCreateInstance 766B9EA6 5 Bytes JMP 0099000A
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!GetCursorPos 77980B88 5 Bytes JMP 013A000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 0048000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 0049000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0047000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 016B000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 016C000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0050000A
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 85EE51F8
Device \FileSystem\udfs \UdfsCdRom 8769A1F8
Device \FileSystem\udfs \UdfsDisk 8769A1F8
Device \Driver\volmgr \Device\VolMgrControl 8555E1F8
Device \Driver\usbuhci \Device\USBPDO-0 86E871F8
Device \Driver\usbuhci \Device\USBPDO-1 86E871F8
Device \Driver\usbuhci \Device\USBPDO-2 86E871F8
Device \Driver\usbehci \Device\USBPDO-3 86F2F1F8
Device \Driver\usbuhci \Device\USBPDO-4 86E871F8
Device \Driver\usbuhci \Device\USBPDO-5 86E871F8
Device \Driver\usbuhci \Device\USBPDO-6 86E871F8
Device \Driver\volmgr \Device\HarddiskVolume1 8555E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbehci \Device\USBPDO-7 86F2F1F8
Device \Driver\volmgr \Device\HarddiskVolume2 8555E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom1 871761F8
Device \Driver\netbt \Device\NetBt_Wins_Export 876A6500
Device \Driver\Smb \Device\NetbiosSmb 872EE1F8
Device \Driver\iScsiPrt \Device\RaidPort0 871831F8
Device \Driver\netbt \Device\NetBT_Tcpip_{28B3D8F2-F0FB-4318-9417-7F3739B50CB4} 876A6500
Device \Driver\usbuhci \Device\USBFDO-0 86E871F8
Device \Driver\usbuhci \Device\USBFDO-1 86E871F8
Device \Driver\usbuhci \Device\USBFDO-2 86E871F8
Device \Driver\usbehci \Device\USBFDO-3 86F2F1F8
Device \Driver\usbuhci \Device\USBFDO-4 86E871F8
Device \Driver\usbuhci \Device\USBFDO-5 86E871F8
Device \Driver\usbuhci \Device\USBFDO-6 86E871F8
Device \Driver\usbehci \Device\USBFDO-7 86F2F1F8
Device \Driver\VClone \Device\Scsi\VClone1Port5Path0Target0Lun0 871A81F8
Device \Driver\VClone \Device\Scsi\VClone1 871A81F8
Device \FileSystem\cdfs \Cdfs 881CD1F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0x07 0xF8 0x54 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0x07 0xF8 0x54 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
---- EOF - GMER 1.0.15 ----
OTL Log
OTL logfile created on: 8/14/2010 2:15:32 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Christian\Downloads
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 174.80 Gb Total Space | 123.28 Gb Free Space | 70.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CHRISTIAN
Current User Name: Christian
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Users\Christian\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Modules (SafeList) ========== MOD - C:\Users\Christian\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Stereo Service) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (aspnet_state) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (nmservice) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AEADIFilters) -- C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Driver Services (SafeList) ========== DRV - (SjyPkt) -- C:\Windows\System32\Drivers\SjyPkt.sys File not found
DRV - (pcmcia) -- C:\Windows\System32\drivers\pcmcia.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (atapi) -- C:\Windows\system32\drivers\kav_atapi.sys ()
DRV - (WsAudio_DeviceS(5)) WsAudio_DeviceS(5) -- C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys (Wondershare)
DRV - (WsAudio_DeviceS(4)) WsAudio_DeviceS(4) -- C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys (Wondershare)
DRV - (WsAudio_DeviceS(3)) WsAudio_DeviceS(3) -- C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys (Wondershare)
DRV - (WsAudio_DeviceS(2)) WsAudio_DeviceS(2) -- C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys (Wondershare)
DRV - (WsAudio_DeviceS(1)) WsAudio_DeviceS(1) -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV - (taphss) -- C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (truecrypt) -- C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (VBoxNetAdp) -- C:\Windows\System32\drivers\VBoxNetAdp.sys (Sun Microsystems, Inc.)
DRV - (VBoxUSBMon) -- C:\Windows\System32\drivers\VBoxUSBMon.sys (Sun Microsystems, Inc.)
DRV - (VBoxDrv) -- C:\Windows\System32\drivers\VBoxDrv.sys (Sun Microsystems, Inc.)
DRV - (VBoxNetFlt) -- C:\Windows\System32\drivers\VBoxNetFlt.sys (Sun Microsystems, Inc.)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (purendis) -- C:\Windows\System32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) -- C:\Windows\System32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTL8187) -- C:\Windows\System32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (tapvpn) -- C:\Windows\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell)
DRV - (ADIHdAudAddService) -- C:\Windows\System32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 64 BF F1 EB D8 C9 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: Strata40@SpewBoy.au:0.6.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/09 19:59:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/09 19:59:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/08/07 10:46:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/08/04 18:45:49 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions
[2010/08/04 18:45:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/01/17 22:01:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
[2010/08/14 10:57:15 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions
[2010/08/12 10:17:59 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/02 20:58:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}
[2010/07/14 20:19:29 | 000,000,000 | ---D | M] (Readability) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}(19)
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/02/07 23:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{989e9382-d540-4189-88d1-fc54a949a387}
[2010/07/15 23:25:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{ABAD4342-3FDA-4ccf-80AC-B6D0EECACA07}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/08/10 18:01:54 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/19 20:59:44 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(10606)
[2010/07/11 20:55:30 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(36)
[2009/09/17 21:57:06 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(37)
[2009/12/02 20:57:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{de5809e0-2b07-11dd-bd0b-0800200c9a66}
[2009/12/15 21:33:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\bettergmail2@ginatrapani.org
[2009/08/24 11:57:09 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\chromifox@altmusictv(91).com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\firebug@software.joehewitt.com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\grwatcher@ajnasz.hu
[2009/09/17 22:23:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\LogMeInClient@logmein(36).com
[2010/07/15 12:55:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\omnibar@ajitk(35).com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\omnibar@ajitk.com
[2010/02/14 00:25:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\opera10skin@firefox.theme
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\Strata40@SpewBoy.au
[2010/07/16 14:27:47 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\Strata40@SpewBoy.au\chrome\mozapps\extensions
[2009/06/20 11:10:42 | 000,002,164 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\bing.xml
[2010/08/11 14:16:09 | 000,001,879 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\skreemr-audio-search.xml
[2009/06/20 11:11:43 | 000,001,980 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\wolframalpha.xml
[2010/08/14 10:57:15 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/06 12:05:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/03/17 17:44:32 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitR
Hi here are the logs you requested. MBAM detected a malware trace but the redirects still exist. The Extras.txt from OTL is attached as a file.
MBAM Log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4428
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18928
8/14/2010 10:56:47 AM
mbam-log.txt
Scan type: Quick scan
Objects scanned: 145608
Time elapsed: 6 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\registrymonitor2 (Malware.Trace) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER Log
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-08-14 14:13:10
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\CHRIST~1\AppData\Local\Temp\kwddipod.sys
---- System - GMER 1.0.15 ----
INT 0x51 ? 86FB3BF8
INT 0x62 ? 86FB3BF8
INT 0x72 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x82 ? 86FB3BF8
INT 0x92 ? 86FB3BF8
---- Kernel code sections - GMER 1.0.15 ----
? System32\Drivers\spew.sys The system cannot find the path specified. !
PAGE ataport.SYS!DllUnload 82D68B2E 5 Bytes JMP 8555C1D8
.text USBPORT.SYS!DllUnload 8F95241B 5 Bytes JMP 86FB31D8
PAGE spsys.sys!?SPVersion@@3PADA + 1ABF A045003F 110 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F A04500AF 1 Byte [16]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F A04500AF 128 Bytes [16, 3B, C8, 75, E2, B0, 01, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB0 A0450130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB7 A0450137 2298 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 0092000A
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 0093000A
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0063000A
.text C:\Windows\system32\svchost.exe[1184] ole32.dll!CoCreateInstance 766B9EA6 5 Bytes JMP 0099000A
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!GetCursorPos 77980B88 5 Bytes JMP 013A000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 0048000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 0049000A
.text C:\Windows\explorer.exe[1700] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0047000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!NtProtectVirtualMemory 77C44D34 5 Bytes JMP 016B000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!NtWriteVirtualMemory 77C45674 5 Bytes JMP 016C000A
.text C:\Windows\Explorer.EXE[1992] ntdll.dll!KiUserExceptionDispatcher 77C45DC8 5 Bytes JMP 0050000A
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 85EE51F8
Device \FileSystem\udfs \UdfsCdRom 8769A1F8
Device \FileSystem\udfs \UdfsDisk 8769A1F8
Device \Driver\volmgr \Device\VolMgrControl 8555E1F8
Device \Driver\usbuhci \Device\USBPDO-0 86E871F8
Device \Driver\usbuhci \Device\USBPDO-1 86E871F8
Device \Driver\usbuhci \Device\USBPDO-2 86E871F8
Device \Driver\usbehci \Device\USBPDO-3 86F2F1F8
Device \Driver\usbuhci \Device\USBPDO-4 86E871F8
Device \Driver\usbuhci \Device\USBPDO-5 86E871F8
Device \Driver\usbuhci \Device\USBPDO-6 86E871F8
Device \Driver\volmgr \Device\HarddiskVolume1 8555E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbehci \Device\USBPDO-7 86F2F1F8
Device \Driver\volmgr \Device\HarddiskVolume2 8555E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom1 871761F8
Device \Driver\netbt \Device\NetBt_Wins_Export 876A6500
Device \Driver\Smb \Device\NetbiosSmb 872EE1F8
Device \Driver\iScsiPrt \Device\RaidPort0 871831F8
Device \Driver\netbt \Device\NetBT_Tcpip_{28B3D8F2-F0FB-4318-9417-7F3739B50CB4} 876A6500
Device \Driver\usbuhci \Device\USBFDO-0 86E871F8
Device \Driver\usbuhci \Device\USBFDO-1 86E871F8
Device \Driver\usbuhci \Device\USBFDO-2 86E871F8
Device \Driver\usbehci \Device\USBFDO-3 86F2F1F8
Device \Driver\usbuhci \Device\USBFDO-4 86E871F8
Device \Driver\usbuhci \Device\USBFDO-5 86E871F8
Device \Driver\usbuhci \Device\USBFDO-6 86E871F8
Device \Driver\usbehci \Device\USBFDO-7 86F2F1F8
Device \Driver\VClone \Device\Scsi\VClone1Port5Path0Target0Lun0 871A81F8
Device \Driver\VClone \Device\Scsi\VClone1 871A81F8
Device \FileSystem\cdfs \Cdfs 881CD1F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0x07 0xF8 0x54 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0x07 0xF8 0x54 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x14 0x76 0x44 0x6C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x64 0x1B 0x19 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x51 0x0E 0x28 0x6F ...
---- EOF - GMER 1.0.15 ----
OTL Log
OTL logfile created on: 8/14/2010 2:15:32 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Christian\Downloads
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 174.80 Gb Total Space | 123.28 Gb Free Space | 70.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CHRISTIAN
Current User Name: Christian
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Users\Christian\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Modules (SafeList) ========== MOD - C:\Users\Christian\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Stereo Service) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (aspnet_state) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (nmservice) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AEADIFilters) -- C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Driver Services (SafeList) ========== DRV - (SjyPkt) -- C:\Windows\System32\Drivers\SjyPkt.sys File not found
DRV - (pcmcia) -- C:\Windows\System32\drivers\pcmcia.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (atapi) -- C:\Windows\system32\drivers\kav_atapi.sys ()
DRV - (WsAudio_DeviceS(5)) WsAudio_DeviceS(5) -- C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys (Wondershare)
DRV - (WsAudio_DeviceS(4)) WsAudio_DeviceS(4) -- C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys (Wondershare)
DRV - (WsAudio_DeviceS(3)) WsAudio_DeviceS(3) -- C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys (Wondershare)
DRV - (WsAudio_DeviceS(2)) WsAudio_DeviceS(2) -- C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys (Wondershare)
DRV - (WsAudio_DeviceS(1)) WsAudio_DeviceS(1) -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV - (taphss) -- C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (truecrypt) -- C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (VBoxNetAdp) -- C:\Windows\System32\drivers\VBoxNetAdp.sys (Sun Microsystems, Inc.)
DRV - (VBoxUSBMon) -- C:\Windows\System32\drivers\VBoxUSBMon.sys (Sun Microsystems, Inc.)
DRV - (VBoxDrv) -- C:\Windows\System32\drivers\VBoxDrv.sys (Sun Microsystems, Inc.)
DRV - (VBoxNetFlt) -- C:\Windows\System32\drivers\VBoxNetFlt.sys (Sun Microsystems, Inc.)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (purendis) -- C:\Windows\System32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) -- C:\Windows\System32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTL8187) -- C:\Windows\System32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (tapvpn) -- C:\Windows\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell)
DRV - (ADIHdAudAddService) -- C:\Windows\System32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 64 BF F1 EB D8 C9 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: Strata40@SpewBoy.au:0.6.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/09 19:59:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/09 19:59:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/08/07 10:46:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/08/04 18:45:49 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions
[2010/08/04 18:45:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/01/17 22:01:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
[2010/08/14 10:57:15 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions
[2010/08/12 10:17:59 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/02 20:58:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}
[2010/07/14 20:19:29 | 000,000,000 | ---D | M] (Readability) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}(19)
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/02/07 23:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{989e9382-d540-4189-88d1-fc54a949a387}
[2010/07/15 23:25:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{ABAD4342-3FDA-4ccf-80AC-B6D0EECACA07}
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/08/10 18:01:54 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/19 20:59:44 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(10606)
[2010/07/11 20:55:30 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(36)
[2009/09/17 21:57:06 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(37)
[2009/12/02 20:57:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\{de5809e0-2b07-11dd-bd0b-0800200c9a66}
[2009/12/15 21:33:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\bettergmail2@ginatrapani.org
[2009/08/24 11:57:09 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\chromifox@altmusictv(91).com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\firebug@software.joehewitt.com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\grwatcher@ajnasz.hu
[2009/09/17 22:23:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\LogMeInClient@logmein(36).com
[2010/07/15 12:55:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\omnibar@ajitk(35).com
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\omnibar@ajitk.com
[2010/02/14 00:25:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\opera10skin@firefox.theme
[2010/08/07 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\Strata40@SpewBoy.au
[2010/07/16 14:27:47 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\extensions\Strata40@SpewBoy.au\chrome\mozapps\extensions
[2009/06/20 11:10:42 | 000,002,164 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\bing.xml
[2010/08/11 14:16:09 | 000,001,879 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\skreemr-audio-search.xml
[2009/06/20 11:11:43 | 000,001,980 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\v862mytj.default\searchplugins\wolframalpha.xml
[2010/08/14 10:57:15 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/06 12:05:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/03/17 17:44:32 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
O1 HOSTS F