Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Visa Advanced Verification Pop-up, Possible Virus?


  • This topic is locked This topic is locked
29 replies to this topic

#1 Sazzaa

Sazzaa

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:28 PM

Posted 22 July 2011 - 07:45 AM

Have tried using a credit card on two different websites and the visa advanced verification pop-up has appeared asking for all card details plus ATM pin number. Visa say this is a possible virus, but AVG and Malwarebytes come up with nothing. My keyboard is also failing to type random characters and system has slowed down a bit, including browsing. DDS ran but the log was garbled nonsense.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:26:45, on 22/07/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Documents and Settings\All Users\Application Data\FileOpen\Services\FileOpenManagerSvc32.exe
C:\WINDOWS\system32\hpb2ksrv.exe
C:\WINDOWS\system32\hpbhksrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Smith Micro\StuffIt 2010\ArcNameService.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\hpstatus.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\Program Files\HP\HP UT\bin\hppusg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\HPBSPSVR.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe
C:\WINDOWS\system32\HPBJDSNT.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://companyweb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.uk.msn.com/USSMB/2
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [8169Diag] C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe /hw
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [\\server1\EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P34 "\\server1\EPSON Stylus Photo R1800" /O13 "LPT2:LK96C7A7" /M "Stylus Photo R1800"
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800 (from SERVER2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P39 "EPSON Stylus Photo R1800 (from SERVER2)" /O5 "TS002" /M "Stylus Photo R1800"
O4 - HKLM\..\Run: [HP Status] C:\WINDOWS\system32\hpstatus.exe
O4 - HKLM\..\Run: [ScanSoft PDF Create 3.0-reminder] "C:\Program Files\ScanSoft\PDF Create! 3\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PDF Create\3\Ereg\ereg.ini"
O4 - HKLM\..\Run: [HPPQVideo] "C:\Program Files\HP\ScheduledLaunch\HP LaserJet P2050 Series\bin\hppschlnch.exe" -r SOFTWARE\Hewlett-Packard\ScheduledLaunch\LJ_P2050_Series -f PQOptimizerVideo.xml -o RemindLater
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
O4 - HKLM\..\Run: [HPUsageTracking] "C:\Program Files\HP\HP UT\bin\hppusg.exe" "C:\Program Files\HP\HP UT\"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Nuance PDF Professional 6-reminder] "C:\Program Files\Nuance\PDF Professional 6\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\PDF Professional 6\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe
O4 - HKLM\..\Run: [PDF6 Registry Controller] C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Append the content of the link to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
O8 - Extra context menu item: Append to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
O8 - Extra context menu item: Create PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
O8 - Extra context menu item: Create PDF file from the content of the link - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
O8 - Extra context menu item: Create PDF files from the selected links - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - res://C:\Program Files\Nuance\PDF Professional 6\cnvres_eng.dll /100
O8 - Extra context menu item: Open with PDF Professional 6 - res://C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = clearwell.subsea.com
O17 - HKLM\Software\..\Telephony: DomainName = clearwell.subsea.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = clearwell.subsea.com
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: FileOpenManagerSvc - FileOpen Systems Inc. - C:\Documents and Settings\All Users\Application Data\FileOpen\Services\FileOpenManagerSvc32.exe
O23 - Service: HP Status - Hewlett-Packard Company - C:\WINDOWS\system32\hpb2ksrv.exe
O23 - Service: HP Status Print - Hewlett-Packard Company - C:\WINDOWS\system32\hpbhksrv.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program Files\Smith Micro\StuffIt 2010\ArcNameService.exe

--
End of file - 13341 bytes

EDIT: Posts merged ~Budapest

Attached Files

  • Attached File  ark.txt   38.09KB   3 downloads

Edited by Budapest, 22 July 2011 - 05:03 PM.


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,600 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:28 PM

Posted 02 August 2011 - 10:20 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you!

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

First, I need to know if you still need help! To tell me this, please click on http://www.bleepingcomputer.com/logreply/410678 and follow the instructions there. If you no longer need help, this is all you need to do. If you do need help please continue below.

***************************************************

If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS and GMER log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


We also need a new log from the GMER anti-rootkit Scanner.

Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.

Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 Sazzaa

Sazzaa
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:28 PM

Posted 03 August 2011 - 07:20 AM

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-03 13:17:11
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.GM2O
Running: gmer.exe; Driver: C:\DOCUME~1\sarah\LOCALS~1\Temp\pwlyqpow.sys


---- Kernel code sections - GMER 1.0.15 ----

? system32\drivers\xpsec.sys The system cannot find the path specified. !
? system32\drivers\xcpip.sys The system cannot find the path specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[168] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 013F9F7E
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[168] WS2_32.dll!send 71AB4C27 5 Bytes JMP 013F9B1B
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[168] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 013F9E30
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[168] WS2_32.dll!recv 71AB676F 5 Bytes JMP 013F9BFC
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[168] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 013F9CCF
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[412] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 015F9F7E
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[412] WS2_32.dll!send 71AB4C27 5 Bytes JMP 015F9B1B
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[412] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 015F9E30
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[412] WS2_32.dll!recv 71AB676F 5 Bytes JMP 015F9BFC
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[412] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 015F9CCF
.text C:\Program Files\AVG\AVG9\avgam.exe[504] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0C439F7E
.text C:\Program Files\AVG\AVG9\avgam.exe[504] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0C439B1B
.text C:\Program Files\AVG\AVG9\avgam.exe[504] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0C439E30
.text C:\Program Files\AVG\AVG9\avgam.exe[504] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0C439BFC
.text C:\Program Files\AVG\AVG9\avgam.exe[504] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0C439CCF
.text C:\WINDOWS\system32\winlogon.exe[764] Secur32.dll!LsaLogonUser 77FE33F1 5 Bytes JMP 01262C81
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[960] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes JMP 39008FA9 C:\Program Files\Common Files\Microsoft Shared\office14\mso.dll (Microsoft Office 2010 component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[960] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 395486A0 C:\Program Files\Common Files\Microsoft Shared\office14\mso.dll (Microsoft Office 2010 component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[960] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 07679F7E
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[960] WS2_32.dll!send 71AB4C27 5 Bytes JMP 07679B1B
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[960] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 07679E30
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[960] WS2_32.dll!recv 71AB676F 5 Bytes JMP 07679BFC
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[960] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 07679CCF
.text C:\WINDOWS\system32\SearchIndexer.exe[1156] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[1156] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0C1D9F7E
.text C:\WINDOWS\system32\SearchIndexer.exe[1156] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0C1D9B1B
.text C:\WINDOWS\system32\SearchIndexer.exe[1156] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0C1D9E30
.text C:\WINDOWS\system32\SearchIndexer.exe[1156] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0C1D9BFC
.text C:\WINDOWS\system32\SearchIndexer.exe[1156] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0C1D9CCF
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1676] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01BA9F7E
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1676] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01BA9B1B
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1676] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01BA9E30
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1676] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01BA9BFC
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1676] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01BA9CCF
.text C:\WINDOWS\system32\igfxsrvc.exe[1896] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E99F7E
.text C:\WINDOWS\system32\igfxsrvc.exe[1896] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E99B1B
.text C:\WINDOWS\system32\igfxsrvc.exe[1896] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E99E30
.text C:\WINDOWS\system32\igfxsrvc.exe[1896] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E99BFC
.text C:\WINDOWS\system32\igfxsrvc.exe[1896] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E99CCF
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[1936] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 03769F7E
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[1936] WS2_32.dll!send 71AB4C27 5 Bytes JMP 03769B1B
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[1936] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 03769E30
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[1936] WS2_32.dll!recv 71AB676F 5 Bytes JMP 03769BFC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[1936] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 03769CCF
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2024] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00F09F7E
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2024] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00F09B1B
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2024] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00F09E30
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2024] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00F09BFC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2024] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00F09CCF
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[2636] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 028F9F7E
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[2636] ws2_32.dll!send 71AB4C27 5 Bytes JMP 028F9B1B
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[2636] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 028F9E30
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[2636] ws2_32.dll!recv 71AB676F 5 Bytes JMP 028F9BFC
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[2636] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 028F9CCF
.text C:\WINDOWS\system32\SearchProtocolHost.exe[2740] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 03529F7E
.text C:\WINDOWS\system32\SearchProtocolHost.exe[2740] WS2_32.dll!send 71AB4C27 5 Bytes JMP 03529B1B
.text C:\WINDOWS\system32\SearchProtocolHost.exe[2740] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 03529E30
.text C:\WINDOWS\system32\SearchProtocolHost.exe[2740] WS2_32.dll!recv 71AB676F 5 Bytes JMP 03529BFC
.text C:\WINDOWS\system32\SearchProtocolHost.exe[2740] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 03529CCF
.text C:\WINDOWS\system32\igfxpers.exe[2916] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01229F7E
.text C:\WINDOWS\system32\igfxpers.exe[2916] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01229B1B
.text C:\WINDOWS\system32\igfxpers.exe[2916] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01229E30
.text C:\WINDOWS\system32\igfxpers.exe[2916] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01229BFC
.text C:\WINDOWS\system32\igfxpers.exe[2916] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01229CCF
.text C:\WINDOWS\system32\igfxtray.exe[2988] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01779F7E
.text C:\WINDOWS\system32\igfxtray.exe[2988] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01779B1B
.text C:\WINDOWS\system32\igfxtray.exe[2988] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01779E30
.text C:\WINDOWS\system32\igfxtray.exe[2988] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01779BFC
.text C:\WINDOWS\system32\igfxtray.exe[2988] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01779CCF
.text C:\WINDOWS\system32\hkcmd.exe[3164] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01209F7E
.text C:\WINDOWS\system32\hkcmd.exe[3164] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01209B1B
.text C:\WINDOWS\system32\hkcmd.exe[3164] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01209E30
.text C:\WINDOWS\system32\hkcmd.exe[3164] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01209BFC
.text C:\WINDOWS\system32\hkcmd.exe[3164] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01209CCF
.text C:\Program Files\Java\jre6\bin\jusched.exe[3188] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E99F7E
.text C:\Program Files\Java\jre6\bin\jusched.exe[3188] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E99B1B
.text C:\Program Files\Java\jre6\bin\jusched.exe[3188] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E99E30
.text C:\Program Files\Java\jre6\bin\jusched.exe[3188] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E99BFC
.text C:\Program Files\Java\jre6\bin\jusched.exe[3188] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E99CCF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] ADVAPI32.dll!CryptHashData 77DE9A9E 7 Bytes JMP 01C4AA8A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9A91 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD0CD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB04 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E25466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5329 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E525B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E52C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E512C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E518E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E538C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E51F0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB60 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E5691 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 01C4A575
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 01C4A646
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 01C4A116
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 01C4A030
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 01C4A33A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WININET.dll!HttpSendRequestA 3D95EE89 5 Bytes JMP 01C4A1E6
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01C49F7E
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01C49B1B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01C49E30
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01C49BFC
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3232] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01C49CCF
.text C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE[3320] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E59F7E
.text C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE[3320] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E59B1B
.text C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE[3320] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E59E30
.text C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE[3320] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E59BFC
.text C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE[3320] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E59CCF
.text C:\WINDOWS\Explorer.EXE[3460] USER32.dll!DisplayExitWindowsWarnings 7E459F91 5 Bytes JMP 00F72A93
.text C:\WINDOWS\Explorer.EXE[3460] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01B69F7E
.text C:\WINDOWS\Explorer.EXE[3460] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01B69B1B
.text C:\WINDOWS\Explorer.EXE[3460] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01B69E30
.text C:\WINDOWS\Explorer.EXE[3460] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01B69BFC
.text C:\WINDOWS\Explorer.EXE[3460] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01B69CCF
.text C:\Program Files\HP\HP UT\bin\hppusg.exe[3572] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 037F9F7E
.text C:\Program Files\HP\HP UT\bin\hppusg.exe[3572] WS2_32.dll!send 71AB4C27 5 Bytes JMP 037F9B1B
.text C:\Program Files\HP\HP UT\bin\hppusg.exe[3572] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 037F9E30
.text C:\Program Files\HP\HP UT\bin\hppusg.exe[3572] WS2_32.dll!recv 71AB676F 5 Bytes JMP 037F9BFC
.text C:\Program Files\HP\HP UT\bin\hppusg.exe[3572] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 037F9CCF
.text C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe[3580] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01859F7E
.text C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe[3580] ws2_32.dll!send 71AB4C27 5 Bytes JMP 01859B1B
.text C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe[3580] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01859E30
.text C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe[3580] ws2_32.dll!recv 71AB676F 5 Bytes JMP 01859BFC
.text C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe[3580] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01859CCF
.text C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe[3676] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 03D69F7E
.text C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe[3676] ws2_32.dll!send 71AB4C27 5 Bytes JMP 03D69B1B
.text C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe[3676] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 03D69E30
.text C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe[3676] ws2_32.dll!recv 71AB676F 5 Bytes JMP 03D69BFC
.text C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe[3676] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 03D69CCF
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[3824] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 010D9F7E
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[3824] WS2_32.dll!send 71AB4C27 5 Bytes JMP 010D9B1B
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[3824] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 010D9E30
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[3824] WS2_32.dll!recv 71AB676F 5 Bytes JMP 010D9BFC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[3824] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 010D9CCF
.text C:\WINDOWS\system32\SearchFilterHost.exe[3864] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01089F7E
.text C:\WINDOWS\system32\SearchFilterHost.exe[3864] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01089B1B
.text C:\WINDOWS\system32\SearchFilterHost.exe[3864] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01089E30
.text C:\WINDOWS\system32\SearchFilterHost.exe[3864] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01089BFC
.text C:\WINDOWS\system32\SearchFilterHost.exe[3864] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01089CCF
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[4220] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 012A9F7E
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[4220] WS2_32.dll!send 71AB4C27 5 Bytes JMP 012A9B1B
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[4220] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 012A9E30
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[4220] WS2_32.dll!recv 71AB676F 5 Bytes JMP 012A9BFC
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[4220] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 012A9CCF
.text C:\WINDOWS\system32\HPBSPSVR.EXE[4296] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DB9F7E
.text C:\WINDOWS\system32\HPBSPSVR.EXE[4296] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DB9B1B
.text C:\WINDOWS\system32\HPBSPSVR.EXE[4296] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DB9E30
.text C:\WINDOWS\system32\HPBSPSVR.EXE[4296] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DB9BFC
.text C:\WINDOWS\system32\HPBSPSVR.EXE[4296] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DB9CCF
.text C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe[4332] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01179F7E
.text C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe[4332] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01179B1B
.text C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe[4332] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01179E30
.text C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe[4332] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01179BFC
.text C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe[4332] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01179CCF
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[4748] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02F09F7E
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[4748] ws2_32.dll!send 71AB4C27 5 Bytes JMP 02F09B1B
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[4748] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02F09E30
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[4748] ws2_32.dll!recv 71AB676F 5 Bytes JMP 02F09BFC
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[4748] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 02F09CCF
.text C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE[4888] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes JMP 39008FA9 C:\Program Files\Common Files\Microsoft Shared\office14\mso.dll (Microsoft Office 2010 component/Microsoft Corporation)
.text C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE[4888] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 395486A0 C:\Program Files\Common Files\Microsoft Shared\office14\mso.dll (Microsoft Office 2010 component/Microsoft Corporation)
.text C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE[4888] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 06539F7E
.text C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE[4888] WS2_32.dll!send 71AB4C27 5 Bytes JMP 06539B1B
.text C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE[4888] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 06539E30
.text C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE[4888] WS2_32.dll!recv 71AB676F 5 Bytes JMP 06539BFC
.text C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE[4888] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 06539CCF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] ADVAPI32.dll!CryptHashData 77DE9A9E 7 Bytes JMP 029AAA8A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB04 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5329 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E525B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E52C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E512C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E518E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E538C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E51F0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 029AA575
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 029AA646
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 029AA116
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 029AA030
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 029AA33A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] WININET.dll!HttpSendRequestA 3D95EE89 5 Bytes JMP 029AA1E6
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 029A9F7E
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] ws2_32.dll!send 71AB4C27 5 Bytes JMP 029A9B1B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 029A9E30
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] ws2_32.dll!recv 71AB676F 5 Bytes JMP 029A9BFC
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[5636] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 029A9CCF
.text C:\Program Files\Java\jre6\bin\jucheck.exe[5836] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 023C9F7E
.text C:\Program Files\Java\jre6\bin\jucheck.exe[5836] ws2_32.dll!send 71AB4C27 5 Bytes JMP 023C9B1B
.text C:\Program Files\Java\jre6\bin\jucheck.exe[5836] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 023C9E30
.text C:\Program Files\Java\jre6\bin\jucheck.exe[5836] ws2_32.dll!recv 71AB676F 5 Bytes JMP 023C9BFC
.text C:\Program Files\Java\jre6\bin\jucheck.exe[5836] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 023C9CCF
.text C:\Program Files\Microsoft Office\Office14\EXCEL.EXE[5900] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes JMP 39008FA9 C:\Program Files\Common Files\Microsoft Shared\office14\mso.dll (Microsoft Office 2010 component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office14\EXCEL.EXE[5900] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 395486A0 C:\Program Files\Common Files\Microsoft Shared\office14\mso.dll (Microsoft Office 2010 component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office14\EXCEL.EXE[5900] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 08C99F7E
.text C:\Program Files\Microsoft Office\Office14\EXCEL.EXE[5900] WS2_32.dll!send 71AB4C27 5 Bytes JMP 08C99B1B
.text C:\Program Files\Microsoft Office\Office14\EXCEL.EXE[5900] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 08C99E30
.text C:\Program Files\Microsoft Office\Office14\EXCEL.EXE[5900] WS2_32.dll!recv 71AB676F 5 Bytes JMP 08C99BFC
.text C:\Program Files\Microsoft Office\Office14\EXCEL.EXE[5900] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 08C99CCF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] ADVAPI32.dll!CryptHashData 77DE9A9E 7 Bytes JMP 03B4AA8A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9A91 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD0CD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB04 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E25466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5329 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E525B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E52C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E512C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E518E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E538C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E51F0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB60 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E5691 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 03B4A575
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 03B4A646
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 03B4A116
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 03B4A030
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 03B4A33A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] WININET.dll!HttpSendRequestA 3D95EE89 5 Bytes JMP 03B4A1E6
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 03B49F7E
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] ws2_32.dll!send 71AB4C27 5 Bytes JMP 03B49B1B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 03B49E30
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] ws2_32.dll!recv 71AB676F 5 Bytes JMP 03B49BFC
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6204] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 03B49CCF

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\FileOpenWebPublisherScreenHookDriver \Device\FileOpenWebPublisherScreenHookDriver fowp32.sys

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
Device 97A74D20

AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Classes\CLSID\{69A150D8-5392-D6E5-4993-3AC61DEF6DD6}\RTFClassName@ WrdPrfctDos

---- Files - GMER 1.0.15 ----

File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\1JBFUF81\jpVSZVYulZg[1].png 2790 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\1JBFUF81\c1aaaa86-ce46-41fa-a29c-0e298ce2e0f4[1].swf 89001 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\1JBFUF81\__utm[2].gif 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\1JBFUF81\275022_691746406_2318030_q[1].jpg 2339 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\1JBFUF81\274745_576495216_6858743_q[1].jpg 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\1JBFUF81\211480_1486326566_4829192_q[1].jpg 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\72FAXW7O\x4Fr4DzyK5J[1].css 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\72FAXW7O\281292_2247352869119_1407094091_2596162_5890928_s[1].jpg 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\ILGBM7C7\bg_grad_blue[1].gif 1087 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\ILGBM7C7\bluemann[1].png 3279 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\ILGBM7C7\jumplist[1].jpg 11752 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\ILGBM7C7\pinning_bar_drag[1].jpg 5411 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\ILGBM7C7\ai[1].php 110 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\ILGBM7C7\211479_692166913_2401671_q[1].jpg 2478 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\ILRWIQ2U\fV6rAEg1AYr[1].js 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\KMYABI0T\TC_Family_June_V2_728x90[1].swf 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\KMYABI0T\showFolder;_ylc=X3oDMTBudnRhazAxBF9TAzM5ODMyOTAxNARhYwNjaGtNYWls[1].txt 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\KMYABI0T\st[3] 0 bytes
File C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.Word\~WRS{CBC82D22-4D5B-451D-B87D-B639FE40CA26}.tmp 0 bytes
File C:\WINDOWS\Temp\PF7A.pdf 0 bytes

---- EOF - GMER 1.0.15 ----

#4 pwgib

pwgib

  • Malware Response Team
  • 2,956 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:God's Country
  • Local time:06:28 PM

Posted 03 August 2011 - 07:59 AM

Hello Sazzaa,

I will be handling your log to help you get cleaned up. I apologize for the delay but the forum is very busy and as you can see the logs we ask for are very extensive and take a lot of time to investigate.

Please subscribe to this topic. Click on the Watch Topic button, select Immediate Notification and click on proceed.

Make sure Word Wrap in notepad is turned off. When copying and pasting logs paste them directly in the reply box only attach logs if asked to. Do not wrap logs in codebox or code tags. It makes it very difficult to read and analyze them. Please paste them directly into the reply box. Do not make any changes to your system until we are through. Fixes are based upon information that is current from your system so any changes can affect our strategy. Please refrain from running any tools we may use without specific instructions.

If your operating system is Windows Vista or Windows 7 it may be necessary to right click then choose Run as Administrator any programs we use.

Before we begin please check and follow the instructions on How to Show Hidden Files and Folders in Windows Vista and Windows XP and How to show hidden files in Windows 7

Because the e-mail notification system is not completely reliable, please check your topic once a day for responses.

Please read carefully all directions and instructions. If you are instructed to save a tool to the desktop please save it to the desktop. If you have since resolved the original problem you were having, we would appreciate you letting us know.

Step 1.

I need to see the current state of your machine.

  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


Step 2.


Please download Rootkit Unhooker from one of the following links and save it to your desktop.
Link 1 (.exe file)
Link 2 (zipped file)
Link 3 (.rar file)In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can downlaod, install and use the free 7-zip utility.

  • Double-click on RKUnhookerLE.exe to start the program.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth, and uncheck the rest.
  • Click OK.
  • Wait until it's finished and then go to File > Save Report.
  • Save the report to your Desktop.
  • Copy and paste the contents of the report into your next reply.
-- Note: You may get this warning...just ignore it, click OK and continue: "Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?".



In your next reply please Include the following:

DDS.txt
Attach.txt
RKUnhooker log



Thanks!!
PW

#5 Sazzaa

Sazzaa
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:28 PM

Posted 04 August 2011 - 05:04 AM

DDS comes up as garbled nonsense!

Rootkit Report....

RkU Version: 3.8.389.593, Type LE (SR2)
==============================================
OS Name: Windows XP
Version 5.1.2600 (Service Pack 3)
Number of processors #2
==============================================
>Drivers
==============================================
0xB8DCD000 C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 6045696 bytes (Intel Corporation, Intel Graphics Miniport Driver)
0xA3CEC000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 4923392 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver)
0xBF280000 C:\WINDOWS\System32\igxpdx32.DLL 3330048 bytes (Intel Corporation, DirectDraw® Driver for Intel® Graphics Technology)
0xBF04F000 C:\WINDOWS\System32\igxpdv32.DLL 2297856 bytes (Intel Corporation, Component GHAL Driver)
0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2154496 bytes (Microsoft Corporation, NT Kernel & System)
0x804D7000 PnpManager 2154496 bytes
0x804D7000 RAW 2154496 bytes
0x804D7000 WMIxWDM 2154496 bytes
0xBF800000 Win32k 1867776 bytes
0xBF800000 C:\WINDOWS\System32\win32k.sys 1867776 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0xB9E4A000 ZR`G\A@J@ 888832 bytes
0x9BA38000 C:\WINDOWS\System32\Drivers\dump_iaStor.sys 888832 bytes
0xB9D5D000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
0x9BB45000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xB8C74000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)
0x9BC64000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
0x9B781000 C:\WINDOWS\system32\drivers\xcpip.sys 364544 bytes
0x9B83D000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver)
0xBF5AD000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0x9A719000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x9BC2A000 C:\WINDOWS\System32\Drivers\avgtdix.sys 237568 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher)
0x9BB11000 C:\WINDOWS\System32\Drivers\avgldx86.sys 212992 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver)
0xB8CD2000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector)
0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
0x9B90D000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xB9D30000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
0xBF024000 C:\WINDOWS\System32\igxpgd32.dll 176128 bytes (Intel Corporation, Intel Graphics 2D Driver)
0x98889000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
0x9BBB5000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0xB8D6D000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a)
0x9BC02000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
0xB9F23000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver)
0xA3CC8000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0xB8D95000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0xB8D2A000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
0x9B2A6000 C:\WINDOWS\System32\Drivers\RDPWD.SYS 143360 bytes (Microsoft Corporation, RDP Terminal Stack Driver (US/Canada Only, Not for Export))
0x9BBE0000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x806E5000 ACPI_HAL 134528 bytes
0x806E5000 C:\WINDOWS\system32\hal.dll 134528 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0xB9E2A000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0xA3C08000 C:\WINDOWS\system32\drivers\IntcHdmi.sys 131072 bytes (Intel® Corporation, Intel® High Definition Audio HDMI)
0xB8D4D000 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 131072 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver )
0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
0xB9D16000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x9B9DF000 C:\WINDOWS\System32\Drivers\DLAIFS_M.SYS 102400 bytes (Roxio, Drive Letter Access Component)
0x9B9B2000 C:\WINDOWS\System32\Drivers\DLAUDF_M.SYS 94208 bytes (Roxio, Drive Letter Access Component)
0xB9E01000 DRVMCDB.SYS 94208 bytes (Sonic Solutions, Device Driver)
0xB9DEA000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xB8D13000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x9B9C9000 C:\WINDOWS\System32\Drivers\DLAUDFAM.SYS 90112 bytes (Roxio, Drive Letter Access Component)
0x9B129000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
0xB8DB9000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
0x9BCBD000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
0x9B802000 C:\WINDOWS\system32\drivers\xpsec.sys 77824 bytes
0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
0xBF012000 C:\WINDOWS\System32\igxprd32.dll 73728 bytes (Intel Corporation, Intel Graphics 2D Rotation Driver)
0xB9E18000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xB8D02000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
0xB8808000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xBA238000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xBA218000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)
0xB6432000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xBA248000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)
0xB62FE000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
0xBA2A8000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
0xBA0E8000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
0xBA258000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xBA0C8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xBA108000 avgrkx86.sys 49152 bytes (AVG Technologies CZ, s.r.o., AVG Anti-Rootkit Driver)
0xBA278000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x9C116000 C:\WINDOWS\System32\Drivers\DRVNDDM.SYS 45056 bytes (Roxio, Device Driver Manager)
0x9C8DE000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)
0xBA228000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)
0xBA0B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
0xBA268000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0xBA0A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)
0xB645C000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
0xBA298000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
0x99E36000 C:\WINDOWS\System32\Drivers\BlackBox.SYS 36864 bytes (RKU Driver)
0xBA0D8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
0xB93B1000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)
0xB9391000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
0x9A569000 C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 36864 bytes (Microsoft Corporation, IP FILTER DRIVER)
0xBA288000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
0x9C8EE000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
0xBA0F8000 PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xBA308000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0xB4C6F000 C:\WINDOWS\System32\Drivers\DLABMFSM.SYS 32768 bytes (Roxio, Drive Letter Access Component)
0xBA3E8000 C:\Documents and Settings\All Users\Application Data\FileOpen\Services\fowp32.sys 32768 bytes
0x9C99C000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
0xBA380000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0xB4C67000 C:\WINDOWS\System32\Drivers\DLABOIOM.SYS 28672 bytes (Roxio, Drive Letter Access Component)
0x9C9B4000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0x9C994000 C:\WINDOWS\System32\Drivers\avgmfx86.sys 24576 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver)
0xB4C77000 C:\WINDOWS\System32\Drivers\DLAOPIOM.SYS 24576 bytes (Roxio, Drive Letter Access Component)
0x9C9BC000 C:\WINDOWS\System32\Drivers\DLARTL_M.SYS 24576 bytes (Roxio, Shared Driver Component)
0xBA3A0000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
0xBA3A8000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
0xBA458000 C:\WINDOWS\System32\Drivers\TDTCP.SYS 24576 bytes (Microsoft Corporation, TCP Transport Driver)
0xBA378000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x9C9AC000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x9C9A4000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
0xBA328000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
0xBA390000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
0xBA398000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)
0xBA388000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
0x9C283000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
0x99DC6000 C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16384 bytes (Microsoft Corporation, MS Remote Access serial network driver)
0xB5FBF000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0x9E2E9000 C:\WINDOWS\system32\drivers\mbam.sys 16384 bytes (Malwarebytes Corporation, Malwarebytes' Anti-Malware)
0xB97CD000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
0xB4C3F000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
0xB9CBE000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)
0xB5FBB000 C:\WINDOWS\system32\DRIVERS\usbscan.sys 16384 bytes (Microsoft Corporation, USB Scanner Driver)
0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
0x9A671000 C:\WINDOWS\System32\Drivers\Diag69xp.sys 12288 bytes (Realtek Semiconductor Corporation, Realtek 10/100/1000 Ethernet Adapter Hardware Diagnostics Driver for Win2k/xp)
0x9D14D000 C:\WINDOWS\System32\Drivers\DLAPoolM.SYS 12288 bytes (Roxio, Drive Letter Access Component)
0xA3BE0000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
0x9C2DF000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0x9CC35000 C:\WINDOWS\System32\Drivers\i2omgmt.SYS 12288 bytes (Microsoft Corporation, I2O Utility Filter)
0x9A5DD000 C:\WINDOWS\system32\DRIVERS\LANPkt.sys 12288 bytes (Realtek Semiconductor Corporation, Realtek LAN Protocol Driver)
0x9C2CB000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0xB9CB6000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x9CC29000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x9D092000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
0xBA5AE000 DLACDBHM.SYS 8192 bytes (Roxio, Shared Driver Component)
0xBA5AC000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver)
0x9D094000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0x9D090000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
0x9D08E000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
0xBA5E6000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xBA5E8000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xBA71A000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
0x9BD1C000 C:\WINDOWS\System32\Drivers\DLADResM.SYS 4096 bytes (Roxio, Drive Letter Access Component)
0xBA7BA000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
0x9C788000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
==============================================
>Stealth
==============================================
0x88B8683E Unknown page with executable code, 1986 bytes
0x88B877F2 Unknown page with executable code, 2062 bytes
0x88B8662B Unknown page with executable code, 2517 bytes
0x88B4F20C Unknown page with executable code, 3572 bytes
0x88B8909E Unknown page with executable code, 3938 bytes
0x88B85DEE Unknown page with executable code, 530 bytes
0x88B93DB4 Unknown page with executable code, 588 bytes

#6 pwgib

pwgib

  • Malware Response Team
  • 2,956 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:God's Country
  • Local time:06:28 PM

Posted 04 August 2011 - 07:18 AM

Hi Sazzaa,

DDS comes up as garbled nonsense!

Did you try both links to DDS and then save to your desktop?


We need to create an OTL Report
  • Please download OTL from the following mirror:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized


In your next reply please include the following:


OTL.txt <-- Will be opened
Extra.txt <-- Will be minimized



Thanks!!
PW

#7 Sazzaa

Sazzaa
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:28 PM

Posted 04 August 2011 - 07:28 AM

Ok got DDS working on the second link...

.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by sarah at 13:21:04 on 2011-08-04
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3037.1480 [GMT 1:00]
.
AV: AVG Anti-Virus Business Edition *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Documents and Settings\All Users\Application Data\FileOpen\Services\FileOpenManagerSvc32.exe
C:\WINDOWS\system32\hpb2ksrv.exe
C:\WINDOWS\system32\hpbhksrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Smith Micro\StuffIt 2010\ArcNameService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\hpstatus.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\Program Files\HP\HP UT\bin\hppusg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\HPBSPSVR.EXE
C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe
C:\WINDOWS\system32\HPBJDSNT.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpmup091.bin
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.live.com
uStart Page = hxxp://companyweb
uDefault_Page_URL = hxxp://companyweb
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - c:\program files\nuance\pdf professional 6\bin\PlusIEContextMenu.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO: ZeonIEEventHelper Class: {da986d7d-ccaf-47b2-84fe-bfa1549bebf9} - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Nuance PDF: {e3286bf1-e654-42ff-b4a6-5e111731df6b} - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [msnmsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
uRun: [RoxioDragToDisc] c:\program files\roxio\drag-to-disc\Drgtodsc.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [8169Diag] c:\program files\realtek\diagnostics utility\8169Diag.exe /hw
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [\\server1\EPSON Stylus Photo R1800] c:\windows\system32\spool\drivers\w32x86\3\e_fati9le.exe /p34 "\\server1\EPSON Stylus Photo R1800" /O13 "LPT2:LK96C7A7" /M "Stylus Photo R1800"
mRun: [EPSON Stylus Photo R1800 (from SERVER2)] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9LE.EXE /P39 "EPSON Stylus Photo R1800 (from SERVER2)" /O5 "TS002" /M "Stylus Photo R1800"
mRun: [HP Status] c:\windows\system32\hpstatus.exe
mRun: [ScanSoft PDF Create 3.0-reminder] "c:\program files\scansoft\pdf create! 3\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\pdf create\3\ereg\ereg.ini"
mRun: [HPPQVideo] "c:\program files\hp\scheduledlaunch\hp laserjet p2050 series\bin\hppschlnch.exe" -r software\hewlett-packard\scheduledlaunch\LJ_P2050_Series -f PQOptimizerVideo.xml -o RemindLater
mRun: [ToolBoxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
mRun: [HPUsageTracking] "c:\program files\hp\hp ut\bin\hppusg.exe" "c:\program files\hp\hp ut\"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Nuance PDF Professional 6-reminder] "c:\program files\nuance\pdf professional 6\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\nuance\pdf professional 6\ereg\Ereg.ini"
mRun: [PDFHook] c:\program files\nuance\pdf professional 6\pdfpro6hook.exe
mRun: [PDF6 Registry Controller] c:\program files\nuance\pdf professional 6\RegistryController.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
IE: Append the content of the link to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Append the content of the selected links to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
IE: Append to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Create PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF file from the content of the link - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF files from the selected links - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: Open with Nuance PDF Converter 6.0 - c:\program files\nuance\pdf professional 6\cnvres_eng.dll /100
IE: Open with PDF Professional 6 - c:\program files\nuance\pdf professional 6\bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
IE: Se&nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{8B950FCD-15ED-4DE9-87AB-9112E7A5DF9D} : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2011-5-27 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2011-5-27 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2011-5-27 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2011-5-27 243152]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2011-5-27 308136]
R2 FileOpenManagerSvc;FileOpenManagerSvc;c:\documents and settings\all users\application data\fileopen\services\FileOpenManagerSvc32.exe [2011-3-9 212352]
R2 LANPkt;Realtek LANPkt Protocol Driver;c:\windows\system32\drivers\LANPkt.sys [2009-7-15 8960]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-10-19 366640]
R2 PDFProFiltSrv;PDFProFiltSrv;c:\program files\nuance\pdf professional 6\PDFProFiltSrv.exe [2009-7-27 134944]
R3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [2009-7-15 11264]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-7-16 110080]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-10-19 22712]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
R3 xcpip;TCP/IP Protocol Driver;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]
R3 xpsec;IPSEC driver;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]
S2 Norton Internet Security;Norton Internet Security;"c:\program files\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 --> c:\program files\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?]
S3 NAVENG;NAVENG;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090507.003\naveng.sys --> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090507.003\NAVENG.SYS [?]
S3 NAVEX15;NAVEX15;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090507.003\navex15.sys --> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090507.003\NAVEX15.SYS [?]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [2009-7-15 16640]
.
=============== File Associations ===============
.
.scr=DWGTrueViewScriptFile
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2011-07-06 18:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 18:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-27 13:45:19 243152 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2011-05-27 13:43:45 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-05-27 13:43:45 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2011-05-27 13:43:41 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
.
============= FINISH: 13:21:17.63 ===============


OTL....

OTL logfile created on: 04/08/2011 13:25:05 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\sarah\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 1.51 Gb Available Physical Memory | 50.81% Memory free
4.81 Gb Paging File | 2.99 Gb Available in Paging File | 62.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.75 Gb Total Space | 208.62 Gb Free Space | 89.63% Space Free | Partition Type: NTFS

Computer Name: CWS-PC01 | User Name: sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/08/04 13:23:25 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sarah\Desktop\OTL.exe
PRC - [2011/07/06 19:52:38 | 000,449,584 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/05/27 14:43:26 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2011/05/27 14:43:26 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2011/05/27 14:43:24 | 002,071,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2011/05/27 14:43:23 | 000,842,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2011/05/27 14:43:23 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2011/05/27 14:43:23 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2011/05/27 14:43:23 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2011/03/16 23:26:08 | 020,759,392 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
PRC - [2011/03/09 18:02:58 | 000,212,352 | ---- | M] (FileOpen Systems Inc.) -- C:\Documents and Settings\All Users\Application Data\FileOpen\Services\FileOpenManagerSvc32.exe
PRC - [2010/08/12 21:51:10 | 001,422,168 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
PRC - [2010/03/23 10:57:48 | 015,889,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
PRC - [2009/10/30 13:34:12 | 001,916,248 | ---- | M] (Smith Micro Software, Inc.) -- C:\Program Files\Smith Micro\StuffIt 2010\ArcNameService.exe
PRC - [2009/07/27 03:15:50 | 001,275,168 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe
PRC - [2009/07/27 03:15:30 | 000,134,944 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
PRC - [2009/07/15 21:04:33 | 000,386,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe
PRC - [2009/07/09 19:35:00 | 000,098,304 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpmup091.bin
PRC - [2008/12/04 13:00:26 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/12/04 13:00:20 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/09/02 12:55:24 | 000,036,864 | ---- | M] () -- C:\Program Files\HP\HP UT\bin\hppusg.exe
PRC - [2008/08/25 15:54:58 | 000,053,248 | ---- | M] (HP) -- C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe
PRC - [2008/05/23 14:06:08 | 000,128,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/04/14 13:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/26 16:15:30 | 000,909,312 | ---- | M] (Realtek) -- C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe
PRC - [2007/07/27 09:10:00 | 001,133,040 | ---- | M] (Roxio) -- C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
PRC - [2003/03/10 10:32:32 | 000,118,784 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpstatus.exe
PRC - [2003/03/10 10:31:34 | 000,053,248 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpbhksrv.exe
PRC - [2003/03/10 10:30:56 | 000,106,496 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpbjdsnt.exe
PRC - [2003/03/10 10:30:28 | 000,057,344 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpb2ksrv.exe
PRC - [2003/03/10 10:26:28 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpbspsvr.exe


========== Modules (SafeList) ==========

MOD - [2011/08/04 13:23:25 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sarah\Desktop\OTL.exe
MOD - [2010/08/23 17:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (Norton Internet Security)
SRV - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/05/27 14:43:23 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2011/03/09 18:02:58 | 000,212,352 | ---- | M] (FileOpen Systems Inc.) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\FileOpen\Services\FileOpenManagerSvc32.exe -- (FileOpenManagerSvc)
SRV - [2009/10/30 13:34:12 | 001,916,248 | ---- | M] (Smith Micro Software, Inc.) [Auto | Running] -- C:\Program Files\Smith Micro\StuffIt 2010\ArcNameService.exe -- (Stuffit Archive Name Service)
SRV - [2009/07/27 03:15:30 | 000,134,944 | ---- | M] (Nuance Communications, Inc.) [Auto | Running] -- C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe -- (PDFProFiltSrv)
SRV - [2008/12/04 13:00:26 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2003/03/10 10:31:34 | 000,053,248 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\WINDOWS\system32\hpbhksrv.exe -- (HP Status Print)
SRV - [2003/03/10 10:30:28 | 000,057,344 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\WINDOWS\system32\hpb2ksrv.exe -- (HP Status)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- -- (xpsec)
DRV - File not found [Kernel | On_Demand | Running] -- -- (xcpip)
DRV - [2011/07/06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/05/27 14:45:19 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2011/05/27 14:43:45 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\System32\Drivers\avgrkx86.sys -- (AvgRkx86)
DRV - [2011/05/27 14:43:41 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2011/05/27 14:43:40 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2009/05/04 02:57:54 | 000,130,688 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2008/08/18 23:21:20 | 000,110,080 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel®
DRV - [2008/08/18 23:20:06 | 004,752,896 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/12/03 11:13:48 | 000,011,264 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\diag69xp.sys -- (Diag69xp)
DRV - [2007/11/20 01:14:08 | 000,016,640 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTLVLAN.SYS -- (RTLVLAN)
DRV - [2007/11/20 01:04:50 | 000,008,960 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LANPkt.sys -- (LANPkt)
DRV - [2007/07/23 15:05:20 | 000,009,104 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLADResM.SYS -- (DLADResM)
DRV - [2007/07/23 15:04:58 | 000,037,360 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABMFSM.SYS -- (DLABMFSM)
DRV - [2007/07/23 15:04:56 | 000,098,448 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2007/07/23 15:04:56 | 000,093,552 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2007/07/23 15:04:54 | 000,027,216 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2007/07/23 15:04:52 | 000,032,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2007/07/23 15:04:52 | 000,016,304 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2007/07/23 15:04:50 | 000,108,752 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2007/07/23 14:49:44 | 000,030,064 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)
DRV - [2007/07/23 14:49:44 | 000,014,576 | ---- | M] (Roxio) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS -- (DLACDBHM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.uk.msn.com/USSMB/2
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.msn.com/sphome.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.uk.msn.com/USSMB/2


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USSMB/2
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/USSMB/2
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USSMB/2
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/USSMB/2
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/sphome.aspx
IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://companyweb
IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files\Nuance\PDF Professional 6\bin\nppdf.dll (Zeon Corporation)



O1 HOSTS File: ([2008/04/14 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Professional 6\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3 - HKU\S-1-5-21-842925246-926492609-725345543-1643\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [\\server1\EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [8169Diag] C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe (Realtek)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [EPSON Stylus Photo R1800 (from SERVER2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HP Status] C:\WINDOWS\system32\hpstatus.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPPQVideo] File not found
O4 - HKLM..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe ()
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nuance PDF Professional 6-reminder] C:\Program Files\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF6 Registry Controller] C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ScanSoft PDF Create 3.0-reminder] File not found
O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
O4 - HKU\S-1-5-21-842925246-926492609-725345543-1643..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-842925246-926492609-725345543-1643\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-842925246-926492609-725345543-1643\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append to existing PDF file - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file from the content of the link - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF files from the selected links - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files\Nuance\PDF Professional 6\cnvres_eng.dll ()
O8 - Extra context menu item: Open with PDF Professional 6 - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = clearwell.subsea.com
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\sarah\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\sarah\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 22:29:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/04 13:23:24 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\sarah\Desktop\OTL.exe
[2011/08/04 13:21:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\sarah\Start Menu\Programs\Administrative Tools
[2011/08/04 13:20:30 | 000,607,017 | R--- | C] (Swearware) -- C:\Documents and Settings\sarah\Desktop\dds.pif
[2011/08/03 13:37:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sarah\Start Menu\Programs\Flange Data System
[2011/08/03 13:37:58 | 000,000,000 | ---D | C] -- C:\Program Files\Flange Data System 5.0
[2011/08/03 13:37:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sarah\Desktop\Flange Data
[2011/07/22 11:58:11 | 000,606,738 | ---- | C] (Swearware) -- C:\Documents and Settings\sarah\Desktop\dds.scr
[2011/07/22 09:26:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sarah\Start Menu\Programs\HiJackThis
[2011/07/22 09:26:18 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/07/21 16:44:36 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/07/18 10:46:51 | 009,466,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\sarah\Desktop\mbam-setup-1.51.1.1800.exe
[2011/07/18 10:41:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/07/18 10:06:09 | 000,000,000 | ---D | C] -- C:\spoolerlogs
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/04 13:23:25 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sarah\Desktop\OTL.exe
[2011/08/04 13:20:36 | 000,607,017 | R--- | M] (Swearware) -- C:\Documents and Settings\sarah\Desktop\dds.pif
[2011/08/04 11:20:47 | 000,265,420 | ---- | M] () -- C:\Documents and Settings\sarah\My Documents\Reference.pdf
[2011/08/04 10:54:34 | 000,139,264 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\RKUnhookerLE.EXE
[2011/08/04 10:37:01 | 083,112,289 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/08/04 10:34:09 | 000,000,464 | ---- | M] () -- C:\WINDOWS\tasks\SDMsgUpdate (TE).job
[2011/08/04 09:10:29 | 000,000,022 | ---- | M] () -- C:\WINDOWS\hpjmonsv.ini
[2011/08/04 09:10:26 | 000,002,473 | ---- | M] () -- C:\WINDOWS\hpstatus.ini
[2011/08/04 09:10:11 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/08/04 09:09:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/08/04 09:09:44 | 3184,508,928 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/03 13:37:59 | 000,001,900 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\Flange Data System 5.lnk
[2011/08/03 13:32:52 | 013,792,698 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\flange_data.zip
[2011/07/22 12:03:41 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\gmer.zip
[2011/07/22 11:58:13 | 000,606,738 | ---- | M] (Swearware) -- C:\Documents and Settings\sarah\Desktop\dds.scr
[2011/07/22 11:55:45 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\sarah\defogger_reenable
[2011/07/22 11:54:36 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\Defogger.exe
[2011/07/22 09:26:25 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\HiJackThis.lnk
[2011/07/22 09:25:59 | 001,402,880 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\HijackThis.msi
[2011/07/18 10:46:51 | 009,466,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\sarah\Desktop\mbam-setup-1.51.1.1800.exe
[2011/07/16 22:21:04 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\gmer.exe
[2011/07/08 11:10:51 | 000,001,477 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\Windows Explorer.LNK
[2011/07/06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/06 10:26:57 | 000,087,228 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\DS 43-312-Line Pipe (HFI or ERW).pdf
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/04 11:20:46 | 000,265,420 | ---- | C] () -- C:\Documents and Settings\sarah\My Documents\Reference.pdf
[2011/08/04 10:54:32 | 000,139,264 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\RKUnhookerLE.EXE
[2011/08/03 13:37:59 | 000,001,900 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\Flange Data System 5.lnk
[2011/08/03 13:32:52 | 013,792,698 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\flange_data.zip
[2011/07/22 12:03:41 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\gmer.zip
[2011/07/22 11:55:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\sarah\defogger_reenable
[2011/07/22 11:54:36 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\Defogger.exe
[2011/07/22 09:26:19 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\HiJackThis.lnk
[2011/07/22 09:25:58 | 001,402,880 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\HijackThis.msi
[2011/07/16 22:21:04 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\gmer.exe
[2011/07/06 10:26:57 | 000,087,228 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\DS 43-312-Line Pipe (HFI or ERW).pdf
[2011/06/22 11:54:57 | 000,015,188 | -HS- | C] () -- C:\Documents and Settings\sarah\Local Settings\Application Data\4cr3j248u5w0p76767u737dq
[2011/06/22 11:54:57 | 000,015,188 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\4cr3j248u5w0p76767u737dq
[2010/10/28 10:34:05 | 000,000,194 | ---- | C] () -- C:\Documents and Settings\sarah\Application Data\wklnhst.dat
[2010/02/10 16:17:50 | 000,014,336 | ---- | C] () -- C:\Documents and Settings\sarah\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/05 13:44:13 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2010/02/05 13:44:13 | 000,000,205 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2010/02/05 13:43:19 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2010/02/05 13:43:19 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2010/02/05 13:43:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2010/02/05 13:43:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\serauth2.dll
[2010/02/05 13:43:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\serauth1.dll
[2010/02/05 13:43:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nsprs.dll
[2009/08/24 15:38:01 | 000,018,073 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2009/08/18 15:53:53 | 000,000,619 | R--- | C] () -- C:\WINDOWS\System32\hppapr13.dat
[2009/08/18 15:53:22 | 000,000,664 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2009/08/18 15:48:51 | 000,175,594 | ---- | C] () -- C:\WINDOWS\hppins13.dat
[2009/08/18 15:48:51 | 000,005,989 | ---- | C] () -- C:\WINDOWS\hppmdl13.dat
[2009/08/03 11:31:26 | 000,000,022 | ---- | C] () -- C:\WINDOWS\hpjmonsv.ini
[2009/08/03 11:27:23 | 000,002,473 | ---- | C] () -- C:\WINDOWS\hpstatus.ini
[2009/08/03 11:27:18 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\jfwapi.dll
[2009/07/27 11:17:18 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\PRTSERV.dll
[2009/07/26 17:34:54 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/07/21 14:16:37 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/07/16 05:51:21 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2009/07/16 05:51:19 | 002,026,604 | ---- | C] () -- C:\WINDOWS\System32\igkrng500.bin
[2009/07/16 05:51:19 | 000,442,964 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
[2009/07/16 05:51:19 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4977.dll
[2009/07/16 05:51:15 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2009/07/16 05:49:57 | 000,001,200 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2009/07/15 21:14:51 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/07/15 21:07:15 | 000,000,234 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/25 22:31:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/04/25 22:27:18 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/04/25 22:26:32 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 17:16:24 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/04/25 17:16:22 | 000,467,010 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/04/25 17:16:22 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/04/25 17:16:22 | 000,080,226 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/04/25 17:16:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/04/25 17:16:22 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/04/25 17:16:21 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/04/25 17:16:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/04/25 17:16:18 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/04/25 17:16:18 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/04/25 17:16:13 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/04/25 17:16:11 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/04/25 10:22:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/04/25 10:21:52 | 000,415,856 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/03/16 17:00:00 | 000,003,403 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 253 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E55808C
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:527B6DAD

< End of report >

EXTRAS....

OTL Extras logfile created on: 04/08/2011 13:25:05 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\sarah\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 1.51 Gb Available Physical Memory | 50.81% Memory free
4.81 Gb Paging File | 2.99 Gb Available in Paging File | 62.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.75 Gb Total Space | 208.62 Gb Free Space | 89.63% Space Free | Partition Type: NTFS

Computer Name: CWS-PC01 | User Name: sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"135:TCP:*:Enabled:Offer Remote Assistance - Port" = 135:TCP:*:Enabled:Offer Remote Assistance - Port

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings]
"Enabled" = 1
"RemoteAddresses" = localsubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = localsubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = localsubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\LMI25.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI25.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\WINDOWS\system32\hpbspsvr.exe" = C:\WINDOWS\system32\hpbspsvr.exe:*:Enabled:HP SocketPing Server -- (Hewlett-Packard Company)
"C:\WINDOWS\LMI17.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI17.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\WINDOWS\LMI1F.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI1F.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\WINDOWS\LMI22.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI22.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"D:\setup\HPPNIPRINT01.EXE" = D:\setup\HPPNIPRINT01.EXE:*:Enabled:hppniprint01.exe
"D:\setup\HPPNIPRINT64.EXE" = D:\setup\HPPNIPRINT64.EXE:*:Enabled:hppniprint64.exe
"D:\setup\HPPNICIFS01.EXE" = D:\setup\HPPNICIFS01.EXE:*:Enabled:hppnicifs01.exe
"D:\setup\CustomPrnDnld\HPPCSTPG.EXE" = D:\setup\CustomPrnDnld\HPPCSTPG.EXE:*:Enabled:hppcstpg.exe
"D:\setup\hpbtpg.exe" = D:\setup\hpbtpg.exe:*:Enabled:hpbtpg.exe
"D:\setup\LaunchApp.exe" = D:\setup\LaunchApp.exe:*:Enabled:launchapp.exe
"C:\WINDOWS\LMI67.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI67.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\WINDOWS\LMI3E.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3E.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\hpbspsvr.exe" = C:\WINDOWS\system32\hpbspsvr.exe:*:Disabled:HP SocketPing Server -- (Hewlett-Packard Company)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{05F26168-B5E6-4118-B510-FBD1BFB423FA}" = Microsoft Office Project 2007 Step by Step
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{0868BB9D-5EA0-40AF-A1CC-A38ED4E5BC67}" = 32 Bit HP CIO Components Installer
"{0AE19D89-17A9-404D-932A-FAAF43F3C77E}" = SPSS 14.0 for Windows
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{1093648B-1375-44BC-BC5E-39BF977D53FA}" = Nuance PDF Professional 6
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{26A7FC57-FC21-4CA9-85BD-4324B3294D8B}" = StuffIt 2010
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{51D5F2F7-18A9-4ABC-B1E8-BC3EC053C76E}" = hppPQVideoP2050
"{5783F2D7-8028-0409-0000-0060B0CE6BBA}" = DWG TrueView 2010
"{589F986E-5A4C-4D97-A755-8A3F57683A6D}" = hppTLBXFXP2050
"{5FDE3A66-69EF-4625-8490-EABF91E6B8A0}" = hpzTLBXFX
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6F801026-6AF0-4520-9153-4C9B4CAAB361}" = HP LaserJet P2050 Series 3.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{88253B77-33C9-4A9D-9E4C-4579E39D9158}" = Diagnostics Utility
"{89B6F63A-7E0C-424A-9D39-C4EF59E96D78}" = hppQFolderP2050
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PRJSTDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PRJSTDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJSTDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PRJSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJSTDR_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PRJSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-003A-0000-0000-0000000FF1CE}" = Microsoft Office Project Standard 2007
"{91120000-003A-0000-0000-0000000FF1CE}_PRJSTDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-003A-0000-0000-0000000FF1CE}_PRJSTDR_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F2783-8311-49BF-833E-DB659774B4F6}" = hppFonts
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{ABC082A6-A587-493C-83C1-5F2C60A8BAA8}" = FileOpen Client
"{ABEB838C-A1A7-4C5D-B7E1-8B4314600820}" = MSN Messenger 7.0
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AE60F600-FD60-40C4-A990-72F9BFEE475C}" = Dell Backup and Recovery Manager
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BD69DAB8-E483-4E45-A052-16D1C360B67D}" = hppusgP2050
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F181FBC3-C155-4FCB-AD46-9252440ACC5A}" = hppManualsP2050
"{FC1F6962-7737-11D3-A11A-0080AD78AADF}" = Flange Data System 5.0
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AVG9Uninstall" = AVG 9.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Diagram Designer" = Diagram Designer
"DWG TrueView 2010" = DWG TrueView 2010
"EPSON Printer and Utilities" = EPSON Printer Software
"HDMI" = Intel® Graphics Media Accelerator Driver
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office14.STANDARD" = Microsoft Office Standard 2010
"OU SPSS data for DSE212" = OU SPSS data for DSE212
"pdfFactory" = pdfFactory
"Print Server Driver" = Print Server Driver
"Printer Status and Alerts Uninstaller" = Printer Status and Alerts Uninstaller
"PRJSTDR" = Microsoft Office Project Standard 2007
"Shop for HP Supplies" = Shop for HP Supplies
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SmartDraw 2010" = SmartDraw 2010

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 18/07/2011 05:33:35 | Computer Name = CWS-PC01 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Application, SystemIndex
Catalog

Error - 18/07/2011 05:33:35 | Computer Name = CWS-PC01 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Application, SystemIndex
Catalog

Error - 18/07/2011 05:33:51 | Computer Name = CWS-PC01 | Source = Application Error | ID = 1004
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module unknown, version 0.0.0.0, fault address 0xc033742e.

Error - 18/07/2011 05:35:30 | Computer Name = CWS-PC01 | Source = Application Error | ID = 1004
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module unknown, version 0.0.0.0, fault address 0xc033742e.

Error - 18/07/2011 05:35:35 | Computer Name = CWS-PC01 | Source = Application Error | ID = 1004
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module unknown, version 0.0.0.0, fault address 0xc033742e.

Error - 19/07/2011 07:49:26 | Computer Name = CWS-PC01 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 21/07/2011 04:15:03 | Computer Name = CWS-PC01 | Source = ESENT | ID = 490
Description = svchost (1192) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 21/07/2011 04:15:03 | Computer Name = CWS-PC01 | Source = ESENT | ID = 439
Description = Catalog Database (1192) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb. Error
-1032.

Error - 21/07/2011 04:15:03 | Computer Name = CWS-PC01 | Source = ESENT | ID = 470
Description = Catalog Database (1192) Database C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
is partially attached. Attachment stage: 1. Error: -1032.

Error - 04/08/2011 08:24:48 | Computer Name = CWS-PC01 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.26.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 29/07/2011 04:23:59 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SRTSP SRTSPX

Error - 01/08/2011 04:10:09 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7000
Description = The Norton Internet Security service failed to start due to the following
error: %%3

Error - 01/08/2011 04:10:13 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SRTSP SRTSPX

Error - 02/08/2011 04:09:30 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7000
Description = The Norton Internet Security service failed to start due to the following
error: %%3

Error - 02/08/2011 04:09:34 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SRTSP SRTSPX

Error - 02/08/2011 04:11:05 | Computer Name = CWS-PC01 | Source = DCOM | ID = 10010
Description = The server {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} did not register
with DCOM within the required timeout.

Error - 03/08/2011 04:16:48 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7000
Description = The Norton Internet Security service failed to start due to the following
error: %%3

Error - 03/08/2011 04:16:51 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SRTSP SRTSPX

Error - 04/08/2011 04:09:53 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7000
Description = The Norton Internet Security service failed to start due to the following
error: %%3

Error - 04/08/2011 04:09:56 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SRTSP SRTSPX


< End of report >

#8 pwgib

pwgib

  • Malware Response Team
  • 2,956 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:God's Country
  • Local time:06:28 PM

Posted 04 August 2011 - 08:59 AM

Hi Sazzaa,

Before we begin, is this a business computer and if so have you contacted your IT department? :whistle:

Did you enable Remote Assistance and Remote Desktop on purpose?



Thanks!!
PW

#9 Sazzaa

Sazzaa
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:28 PM

Posted 04 August 2011 - 09:31 AM

Yeah it's a business computer and no I haven't told my IT people yet, we outsource it and they charge a fortune to clean a pc!!! We try and do things ourselves here as much as possible....

#10 pwgib

pwgib

  • Malware Response Team
  • 2,956 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:God's Country
  • Local time:06:28 PM

Posted 04 August 2011 - 10:29 AM

Hi Sazzaa,

Yeah it's a business computer and no I haven't told my IT people yet, we outsource it

I don't mind helping you but be aware that there are issues with working on a business computer. Please at the least contact your superior'(s) and advise them of your situation and that you are seeking other than your IT help.

Although I don't anticipate any problems you need to be aware that sometimes during the malware removal process things can go wrong.

If you haven't already please read this.

If you have any important data or documents you can not afford to lose I encourage you to back them up.

If you still wish to proceed then we will continue. :)


When you ran DDS an Attach.txt log was generated. Please attach it in your next reply. If you need to run DDS again only post Attach.txt. DDS.txt is not needed. :thumbup2:


Please answer my question about remote assistance and remote desktop.

Did you have Norton Internet Security installed? Have you tried to uninstall Norton/Symantec via Add/Remove programs?



Step. 1

We need to run an OTL Fix
  • Please reopen Posted Image on your desktop.
  • Copy and Paste the following code into the Posted Image textbox.

    :OTL
    O3 - HKU\S-1-5-21-842925246-926492609-725345543-1643\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    [2011/06/22 11:54:57 | 000,015,188 | -HS- | C] () -- C:\Documents and Settings\sarah\Local Settings\Application Data\4cr3j248u5w0p76767u737dq
    [2011/06/22 11:54:57 | 000,015,188 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\4cr3j248u5w0p76767u737dq
    @Alternate Data Stream - 253 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E55808C
    @Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:527B6DAD
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall"=-
    "DisableNotifications"=-
    
    :commands
    [EmptyTemp]
    
  • Push Posted Image
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click Posted Image.
  • A report will open. Copy and Paste that report in your next reply.


Step 2.

Please try aswMBR again. Make sure your antivirus is disabled and that it is saved to the desktop.

If no luck then:
  • Please download mbrcheck from Here
  • Save that file to your desktop and double click on it to run it.
  • It will show a Black screen with some data on it then hit any key to continue.
  • Once it finishes there will be a log produced on your desktop that is labeled mbrcheck*.txt (where the * is date)
  • Please post the contents of that log in your next reply.


Step 3.

================================OTL Follow up scan=================================

Please read the directions carefully as they have changed from the last scan.

We need to create an OTL Report
  • Please download OTL from the following mirror:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • In the Extra Registry box make sure that Use Safelist is checked.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTList.txt <-- Will be opened
    • Extra.txt <-- Will be minimized


If you decided to continue then in your next reply please answer my questions and include the following:

OTLFix report
OTList.txt <-- Will be opened
Extra.txt <-- Will be minimized

aswMBR or MBRCheck report.


Are you still getting the Visa warning? How is your computer running?


Thanks!!
PW

#11 Sazzaa

Sazzaa
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:28 PM

Posted 05 August 2011 - 07:16 AM

As far as I know, remote assistance and desktop has always been on this machine. I haven't enabled it myself, it's just there for when needed.

I wasn't aware Norton Security was on this machine, but it may have been at some point in the past. On checking Add/Remove programs it's not there.

I haven't tried using a credit card on the machine again, or even used any site involving payments, too scared to!! It seems to be running ok, but internet browsing is slower than usual and my keyboard seems to miss out random letters when I'm typing.

Attached File  attach.txt   16.71KB   1 downloads

OTL Report.....

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-842925246-926492609-725345543-1643\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
C:\Documents and Settings\sarah\Local Settings\Application Data\4cr3j248u5w0p76767u737dq moved successfully.
C:\Documents and Settings\All Users\Application Data\4cr3j248u5w0p76767u737dq moved successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:8E55808C deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:527B6DAD deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DisableNotifications deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes
->Flash cache emptied: 321 bytes

User: administrator.CLEARWELL
->Temp folder emptied: 1492670 bytes
->Temporary Internet Files folder emptied: 1016811 bytes
->Java cache emptied: 418 bytes
->Flash cache emptied: 321 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32969 bytes
->Flash cache emptied: 321 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: sarah
->Temp folder emptied: 202996896 bytes
->Temporary Internet Files folder emptied: 177320411 bytes
->Java cache emptied: 91175516 bytes
->Flash cache emptied: 142015 bytes

User: simblox
->Temp folder emptied: 592156 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 321 bytes

User: yvd
->Temp folder emptied: 594056 bytes
->Temporary Internet Files folder emptied: 37626 bytes
->Flash cache emptied: 321 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 44753215 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 154637944 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 6751152 bytes

Total Files Cleaned = 650.00 mb


OTL by OldTimer - Version 3.2.26.1 log created on 08052011_125742

Files\Folders moved on Reboot...
C:\Documents and Settings\sarah\Local Settings\Temporary Internet Files\Content.IE5\1JBFUF81\page__pid__2359112[1].txt moved successfully.
File move failed. C:\WINDOWS\temp\78d904e scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\8b2925a scheduled to be moved on reboot.

Registry entries deleted on Reboot...



MBRcheck Report....

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000000c

Kernel Drivers (total 134):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E5000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F79000 ACPI.sys
0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB9F68000 pci.sys
0xBA0A8000 isapnp.sys
0xBA0B8000 MountMgr.sys
0xB9F49000 ftdisk.sys
0xBA5AC000 dmload.sys
0xB9F23000 dmio.sys
0xBA328000 PartMgr.sys
0xBA0C8000 VolSnap.sys
0xB9E4A000 ZR`G\A@J@
0xBA0D8000 disk.sys
0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB9E2A000 fltMgr.sys
0xB9E18000 sr.sys
0xBA5AE000 DLACDBHM.SYS
0xB9E01000 DRVMCDB.SYS
0xBA0F8000 PxHelp20.sys
0xB9DEA000 KSecDD.sys
0xB9D5D000 Ntfs.sys
0xB9D30000 NDIS.sys
0xB9D16000 Mup.sys
0xBA108000 avgrkx86.sys
0xBA258000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB88EA000 \SystemRoot\system32\DRIVERS\igxpmp32.sys
0xB88D6000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xBA380000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB88B2000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA388000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB888A000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xB886A000 \SystemRoot\system32\DRIVERS\Rtenicxp.sys
0xBA268000 \SystemRoot\system32\DRIVERS\serial.sys
0xB9CBA000 \SystemRoot\system32\DRIVERS\serenum.sys
0xBA278000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA288000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xBA298000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB8847000 \SystemRoot\system32\DRIVERS\ks.sys
0xBA76E000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA2A8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xB9CB2000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB8830000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA2B8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA2C8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xBA390000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB881F000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA2D8000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xBA398000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xBA3A0000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB87EF000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xBA2E8000 \SystemRoot\system32\DRIVERS\termdd.sys
0xBA3A8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xBA3B0000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xBA5E0000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB8791000 \SystemRoot\system32\DRIVERS\update.sys
0xB967F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xBA2F8000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xBA5E2000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xB76D3000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA4F33000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xA41C4000 \SystemRoot\system32\drivers\portcls.sys
0xA4AE9000 \SystemRoot\system32\drivers\drmk.sys
0xA3510000 \SystemRoot\system32\drivers\IntcHdmi.sys
0x9C017000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0x9C4A5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x9BBD2000 \SystemRoot\System32\Drivers\Null.SYS
0x9C4A3000 \SystemRoot\System32\Drivers\Beep.SYS
0x9BF05000 \SystemRoot\System32\Drivers\DLARTL_M.SYS
0x9BC1D000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x9BC15000 \SystemRoot\System32\drivers\vga.sys
0x9C4A1000 \SystemRoot\System32\Drivers\mnmdd.SYS
0x9C25F000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x9BC0D000 \SystemRoot\System32\Drivers\Msfs.SYS
0x9BC05000 \SystemRoot\System32\Drivers\Npfs.SYS
0x9C00B000 \SystemRoot\system32\DRIVERS\rasacd.sys
0x9B078000 \SystemRoot\system32\DRIVERS\ipsec.sys
0x9B01F000 \SystemRoot\system32\DRIVERS\tcpip.sys
0x9AFE5000 \SystemRoot\System32\Drivers\avgtdix.sys
0x9AFBD000 \SystemRoot\system32\DRIVERS\netbt.sys
0x9AF9B000 \SystemRoot\System32\drivers\afd.sys
0x9BD82000 \SystemRoot\system32\DRIVERS\netbios.sys
0x9AF70000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x9AF00000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9BD72000 \SystemRoot\System32\Drivers\Fips.SYS
0x9BBFD000 \SystemRoot\System32\Drivers\avgmfx86.sys
0x9AECC000 \SystemRoot\System32\Drivers\avgldx86.sys
0x9B58E000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xB7713000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x9B58A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xB5E72000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xB5E6A000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xB7C9C000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xBA168000 \SystemRoot\System32\Drivers\Cdfs.SYS
0x9ADF3000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xA34FC000 \SystemRoot\System32\drivers\Dxapi.sys
0x9B6E5000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA7C9000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF024000 \SystemRoot\System32\igxpgd32.dll
0xBF012000 \SystemRoot\System32\igxprd32.dll
0xBF04F000 \SystemRoot\System32\igxpdv32.DLL
0xBF280000 \SystemRoot\System32\igxpdx32.DLL
0xBF5AD000 \SystemRoot\System32\ATMFD.DLL
0xB5E7A000 \??\C:\WINDOWS\system32\drivers\mbam.sys
0x9B618000 \SystemRoot\System32\Drivers\DRVNDDM.SYS
0x9BAD2000 \SystemRoot\System32\Drivers\DLADResM.SYS
0x9AD9A000 \SystemRoot\System32\Drivers\DLAIFS_M.SYS
0xA1131000 \SystemRoot\System32\Drivers\DLAOPIOM.SYS
0x9D863000 \SystemRoot\System32\Drivers\DLAPoolM.SYS
0xA1129000 \SystemRoot\System32\Drivers\DLABMFSM.SYS
0xA1121000 \SystemRoot\System32\Drivers\DLABOIOM.SYS
0x9AD84000 \SystemRoot\System32\Drivers\DLAUDFAM.SYS
0x9AD6D000 \SystemRoot\System32\Drivers\DLAUDF_M.SYS
0x9B59E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9ACC8000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xBA450000 \??\C:\Documents and Settings\All Users\Application Data\FileOpen\Services\fowp32.sys
0x9ABAF000 \SystemRoot\system32\DRIVERS\srv.sys
0x9AB74000 \SystemRoot\system32\drivers\xpsec.sys
0x9AAF3000 \SystemRoot\system32\drivers\xcpip.sys
0xBA3F0000 \SystemRoot\System32\Drivers\TDTCP.SYS
0x9A550000 \SystemRoot\System32\Drivers\RDPWD.SYS
0x9A35B000 \SystemRoot\system32\drivers\wdmaud.sys
0x9A74B000 \SystemRoot\system32\drivers\sysaudio.sys
0x99E1A000 \SystemRoot\System32\Drivers\HTTP.sys
0x99A04000 \SystemRoot\system32\DRIVERS\LANPkt.sys
0x99B5A000 \SystemRoot\System32\Drivers\Diag69xp.sys
0x99309000 \SystemRoot\system32\DRIVERS\ipfltdrv.sys
0x9906D000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x97EF8000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 72):
0 System Idle Process
4 System
688 C:\WINDOWS\system32\smss.exe
740 csrss.exe
764 C:\WINDOWS\system32\winlogon.exe
808 C:\WINDOWS\system32\services.exe
820 C:\WINDOWS\system32\lsass.exe
1036 C:\WINDOWS\system32\svchost.exe
1100 svchost.exe
1196 C:\WINDOWS\system32\svchost.exe
1320 svchost.exe
1392 svchost.exe
1496 C:\WINDOWS\system32\spoolsv.exe
1592 svchost.exe
1644 C:\Program Files\AVG\AVG9\avgwdsvc.exe
1732 C:\Documents and Settings\All Users\Application Data\FileOpen\Services\FileOpenManagerSvc32.exe
1772 C:\WINDOWS\system32\hpb2ksrv.exe
1820 C:\WINDOWS\system32\hpbhksrv.exe
1872 C:\Program Files\Java\jre6\bin\jqs.exe
1952 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
176 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
228 C:\WINDOWS\system32\svchost.exe
236 C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
256 C:\WINDOWS\system32\svchost.exe
412 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
508 C:\Program Files\AVG\AVG9\avgam.exe
528 C:\Program Files\AVG\AVG9\avgnsx.exe
672 C:\WINDOWS\system32\svchost.exe
724 C:\Program Files\Smith Micro\StuffIt 2010\ArcNameService.exe
1532 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
1680 C:\Program Files\AVG\AVG9\avgcsrvx.exe
2076 C:\WINDOWS\system32\searchindexer.exe
3732 C:\Program Files\AVG\AVG9\avgchsvx.exe
3744 C:\Program Files\AVG\AVG9\avgrsx.exe
3812 C:\Program Files\AVG\AVG9\avgcsrvx.exe
2396 C:\WINDOWS\system32\wscntfy.exe
2636 C:\WINDOWS\explorer.exe
3532 C:\Program Files\AVG\AVG9\avgcsrvx.exe
2100 C:\WINDOWS\RTHDCPL.EXE
2208 C:\WINDOWS\system32\igfxtray.exe
884 C:\WINDOWS\system32\hkcmd.exe
2556 C:\WINDOWS\system32\igfxpers.exe
3760 C:\WINDOWS\system32\igfxsrvc.exe
3820 C:\Program Files\Java\jre6\bin\jusched.exe
2668 C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe
2796 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3268 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
2040 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
1516 C:\WINDOWS\system32\hpstatus.exe
4248 C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe
4296 C:\Program Files\HP\HP UT\bin\hppusg.exe
4332 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
4404 C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe
4516 C:\PROGRA~1\AVG\AVG9\avgtray.exe
4560 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
4624 C:\WINDOWS\system32\ctfmon.exe
4724 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
4892 C:\WINDOWS\system32\hpbspsvr.exe
5036 C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
5176 C:\WINDOWS\system32\hpbjdsnt.exe
5196 C:\Program Files\Windows Desktop Search\WindowsSearch.exe
5452 wmiprvse.exe
4264 C:\Program Files\Internet Explorer\iexplore.exe
2348 C:\PROGRA~1\MICROS~3\Office14\OUTLOOK.EXE
4856 C:\Program Files\Internet Explorer\iexplore.exe
5284 OSPPSVC.EXE
4160 C:\Program Files\Internet Explorer\iexplore.exe
4348 C:\WINDOWS\system32\searchprotocolhost.exe
3388 C:\WINDOWS\system32\notepad.exe
2104 C:\Program Files\Internet Explorer\iexplore.exe
1284 searchfilterhost.exe
5392 C:\Documents and Settings\sarah\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`04e71400 (NTFS)

PhysicalDrive0 Model Number: HitachiHDP725025GLA380, Rev: GM2OA5BA

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 MBR Code Faked (known infection: Whistler / Black Internet)!
SHA1: 0CEFD8D44204B6423BDD943598F3B36E4B24EDDF


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:


OTL.txt Report...

OTL logfile created on: 05/08/2011 13:10:05 - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\sarah\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 2.09 Gb Available Physical Memory | 70.43% Memory free
4.81 Gb Paging File | 3.86 Gb Available in Paging File | 80.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.75 Gb Total Space | 209.38 Gb Free Space | 89.96% Space Free | Partition Type: NTFS

Computer Name: CWS-PC01 | User Name: sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/08/04 13:23:25 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sarah\Desktop\OTL.exe
PRC - [2011/07/06 19:52:38 | 000,449,584 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/05/27 14:43:26 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2011/05/27 14:43:26 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2011/05/27 14:43:24 | 002,071,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2011/05/27 14:43:23 | 000,842,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2011/05/27 14:43:23 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2011/05/27 14:43:23 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2011/05/27 14:43:23 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2011/03/09 18:02:58 | 000,212,352 | ---- | M] (FileOpen Systems Inc.) -- C:\Documents and Settings\All Users\Application Data\FileOpen\Services\FileOpenManagerSvc32.exe
PRC - [2010/03/23 10:57:48 | 015,889,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
PRC - [2009/10/30 13:34:12 | 001,916,248 | ---- | M] (Smith Micro Software, Inc.) -- C:\Program Files\Smith Micro\StuffIt 2010\ArcNameService.exe
PRC - [2009/07/27 03:15:50 | 001,275,168 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe
PRC - [2009/07/27 03:15:30 | 000,134,944 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
PRC - [2009/07/15 21:04:33 | 000,386,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe
PRC - [2008/12/04 13:00:26 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/12/04 13:00:20 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/09/02 12:55:24 | 000,036,864 | ---- | M] () -- C:\Program Files\HP\HP UT\bin\hppusg.exe
PRC - [2008/08/25 15:54:58 | 000,053,248 | ---- | M] (HP) -- C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe
PRC - [2008/05/23 14:06:08 | 000,128,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/04/14 13:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/26 16:15:30 | 000,909,312 | ---- | M] (Realtek) -- C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe
PRC - [2007/07/27 09:10:00 | 001,133,040 | ---- | M] (Roxio) -- C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
PRC - [2003/03/10 10:32:32 | 000,118,784 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpstatus.exe
PRC - [2003/03/10 10:31:34 | 000,053,248 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpbhksrv.exe
PRC - [2003/03/10 10:30:56 | 000,106,496 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpbjdsnt.exe
PRC - [2003/03/10 10:30:28 | 000,057,344 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpb2ksrv.exe
PRC - [2003/03/10 10:26:28 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\hpbspsvr.exe


========== Modules (SafeList) ==========

MOD - [2011/08/04 13:23:25 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sarah\Desktop\OTL.exe
MOD - [2010/08/23 17:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (Norton Internet Security)
SRV - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/05/27 14:43:23 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2011/03/09 18:02:58 | 000,212,352 | ---- | M] (FileOpen Systems Inc.) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\FileOpen\Services\FileOpenManagerSvc32.exe -- (FileOpenManagerSvc)
SRV - [2009/10/30 13:34:12 | 001,916,248 | ---- | M] (Smith Micro Software, Inc.) [Auto | Running] -- C:\Program Files\Smith Micro\StuffIt 2010\ArcNameService.exe -- (Stuffit Archive Name Service)
SRV - [2009/07/27 03:15:30 | 000,134,944 | ---- | M] (Nuance Communications, Inc.) [Auto | Running] -- C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe -- (PDFProFiltSrv)
SRV - [2008/12/04 13:00:26 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2003/03/10 10:31:34 | 000,053,248 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\WINDOWS\system32\hpbhksrv.exe -- (HP Status Print)
SRV - [2003/03/10 10:30:28 | 000,057,344 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\WINDOWS\system32\hpb2ksrv.exe -- (HP Status)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- -- (xpsec)
DRV - File not found [Kernel | On_Demand | Running] -- -- (xcpip)
DRV - [2011/07/06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/05/27 14:45:19 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2011/05/27 14:43:45 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\System32\Drivers\avgrkx86.sys -- (AvgRkx86)
DRV - [2011/05/27 14:43:41 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2011/05/27 14:43:40 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2009/05/04 02:57:54 | 000,130,688 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2008/08/18 23:21:20 | 000,110,080 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel®
DRV - [2008/08/18 23:20:06 | 004,752,896 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/12/03 11:13:48 | 000,011,264 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\diag69xp.sys -- (Diag69xp)
DRV - [2007/11/20 01:14:08 | 000,016,640 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTLVLAN.SYS -- (RTLVLAN)
DRV - [2007/11/20 01:04:50 | 000,008,960 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LANPkt.sys -- (LANPkt)
DRV - [2007/07/23 15:05:20 | 000,009,104 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLADResM.SYS -- (DLADResM)
DRV - [2007/07/23 15:04:58 | 000,037,360 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABMFSM.SYS -- (DLABMFSM)
DRV - [2007/07/23 15:04:56 | 000,098,448 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2007/07/23 15:04:56 | 000,093,552 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2007/07/23 15:04:54 | 000,027,216 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2007/07/23 15:04:52 | 000,032,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2007/07/23 15:04:52 | 000,016,304 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2007/07/23 15:04:50 | 000,108,752 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2007/07/23 14:49:44 | 000,030,064 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)
DRV - [2007/07/23 14:49:44 | 000,014,576 | ---- | M] (Roxio) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS -- (DLACDBHM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.uk.msn.com/USSMB/2
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.msn.com/sphome.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.uk.msn.com/USSMB/2


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USSMB/2
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/USSMB/2
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USSMB/2
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/USSMB/2
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/sphome.aspx
IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://companyweb
IE - HKU\S-1-5-21-842925246-926492609-725345543-1643\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files\Nuance\PDF Professional 6\bin\nppdf.dll (Zeon Corporation)



O1 HOSTS File: ([2008/04/14 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Professional 6\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O4 - HKLM..\Run: [\\server1\EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [8169Diag] C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe (Realtek)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [EPSON Stylus Photo R1800 (from SERVER2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HP Status] C:\WINDOWS\system32\hpstatus.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPPQVideo] File not found
O4 - HKLM..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe ()
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nuance PDF Professional 6-reminder] C:\Program Files\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF6 Registry Controller] C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ScanSoft PDF Create 3.0-reminder] File not found
O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
O4 - HKU\S-1-5-21-842925246-926492609-725345543-1643..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-842925246-926492609-725345543-1643\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-842925246-926492609-725345543-1643\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append to existing PDF file - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file from the content of the link - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF files from the selected links - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files\Nuance\PDF Professional 6\cnvres_eng.dll ()
O8 - Extra context menu item: Open with PDF Professional 6 - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = clearwell.subsea.com
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\sarah\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\sarah\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 22:29:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/05 12:57:42 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/08/04 13:23:24 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\sarah\Desktop\OTL.exe
[2011/08/04 13:21:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\sarah\Start Menu\Programs\Administrative Tools
[2011/08/04 13:20:30 | 000,607,017 | R--- | C] (Swearware) -- C:\Documents and Settings\sarah\Desktop\dds.pif
[2011/08/03 13:37:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sarah\Start Menu\Programs\Flange Data System
[2011/08/03 13:37:58 | 000,000,000 | ---D | C] -- C:\Program Files\Flange Data System 5.0
[2011/08/03 13:37:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sarah\Desktop\Flange Data
[2011/07/22 11:58:11 | 000,606,738 | ---- | C] (Swearware) -- C:\Documents and Settings\sarah\Desktop\dds.scr
[2011/07/22 09:26:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sarah\Start Menu\Programs\HiJackThis
[2011/07/22 09:26:18 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/07/21 16:44:36 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/07/18 10:46:51 | 009,466,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\sarah\Desktop\mbam-setup-1.51.1.1800.exe
[2011/07/18 10:41:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/07/18 10:06:09 | 000,000,000 | ---D | C] -- C:\spoolerlogs

========== Files - Modified Within 30 Days ==========

[2011/08/05 13:07:15 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\MBRCheck.exe
[2011/08/05 13:04:24 | 000,000,022 | ---- | M] () -- C:\WINDOWS\hpjmonsv.ini
[2011/08/05 13:04:20 | 000,002,473 | ---- | M] () -- C:\WINDOWS\hpstatus.ini
[2011/08/05 13:03:49 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/08/05 13:03:48 | 000,000,464 | ---- | M] () -- C:\WINDOWS\tasks\SDMsgUpdate (TE).job
[2011/08/05 13:03:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/08/05 13:03:24 | 3184,508,928 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/05 11:41:06 | 083,178,888 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/08/04 13:23:25 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sarah\Desktop\OTL.exe
[2011/08/04 13:20:36 | 000,607,017 | R--- | M] (Swearware) -- C:\Documents and Settings\sarah\Desktop\dds.pif
[2011/08/04 11:20:47 | 000,265,420 | ---- | M] () -- C:\Documents and Settings\sarah\My Documents\Reference.pdf
[2011/08/04 10:54:34 | 000,139,264 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\RKUnhookerLE.EXE
[2011/08/03 13:37:59 | 000,001,900 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\Flange Data System 5.lnk
[2011/08/03 13:32:52 | 013,792,698 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\flange_data.zip
[2011/07/22 12:03:41 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\gmer.zip
[2011/07/22 11:58:13 | 000,606,738 | ---- | M] (Swearware) -- C:\Documents and Settings\sarah\Desktop\dds.scr
[2011/07/22 11:55:45 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\sarah\defogger_reenable
[2011/07/22 11:54:36 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\Defogger.exe
[2011/07/22 09:26:25 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\HiJackThis.lnk
[2011/07/22 09:25:59 | 001,402,880 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\HijackThis.msi
[2011/07/18 10:46:51 | 009,466,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\sarah\Desktop\mbam-setup-1.51.1.1800.exe
[2011/07/16 22:21:04 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\gmer.exe
[2011/07/08 11:10:51 | 000,001,477 | ---- | M] () -- C:\Documents and Settings\sarah\Desktop\Windows Explorer.LNK
[2011/07/06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2011/08/05 13:07:15 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\MBRCheck.exe
[2011/08/04 11:20:46 | 000,265,420 | ---- | C] () -- C:\Documents and Settings\sarah\My Documents\Reference.pdf
[2011/08/04 10:54:32 | 000,139,264 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\RKUnhookerLE.EXE
[2011/08/03 13:37:59 | 000,001,900 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\Flange Data System 5.lnk
[2011/08/03 13:32:52 | 013,792,698 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\flange_data.zip
[2011/07/22 12:03:41 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\gmer.zip
[2011/07/22 11:55:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\sarah\defogger_reenable
[2011/07/22 11:54:36 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\Defogger.exe
[2011/07/22 09:26:19 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\HiJackThis.lnk
[2011/07/22 09:25:58 | 001,402,880 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\HijackThis.msi
[2011/07/16 22:21:04 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\sarah\Desktop\gmer.exe
[2010/10/28 10:34:05 | 000,000,194 | ---- | C] () -- C:\Documents and Settings\sarah\Application Data\wklnhst.dat
[2010/02/10 16:17:50 | 000,014,336 | ---- | C] () -- C:\Documents and Settings\sarah\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/05 13:44:13 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2010/02/05 13:44:13 | 000,000,205 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2010/02/05 13:43:19 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2010/02/05 13:43:19 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2010/02/05 13:43:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2010/02/05 13:43:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\serauth2.dll
[2010/02/05 13:43:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\serauth1.dll
[2010/02/05 13:43:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nsprs.dll
[2009/08/24 15:38:01 | 000,018,073 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2009/08/18 15:53:53 | 000,000,619 | R--- | C] () -- C:\WINDOWS\System32\hppapr13.dat
[2009/08/18 15:53:22 | 000,000,664 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2009/08/18 15:48:51 | 000,175,594 | ---- | C] () -- C:\WINDOWS\hppins13.dat
[2009/08/18 15:48:51 | 000,005,989 | ---- | C] () -- C:\WINDOWS\hppmdl13.dat
[2009/08/03 11:31:26 | 000,000,022 | ---- | C] () -- C:\WINDOWS\hpjmonsv.ini
[2009/08/03 11:27:23 | 000,002,473 | ---- | C] () -- C:\WINDOWS\hpstatus.ini
[2009/08/03 11:27:18 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\jfwapi.dll
[2009/07/27 11:17:18 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\PRTSERV.dll
[2009/07/26 17:34:54 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/07/21 14:16:37 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/07/16 05:51:21 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2009/07/16 05:51:19 | 002,026,604 | ---- | C] () -- C:\WINDOWS\System32\igkrng500.bin
[2009/07/16 05:51:19 | 000,442,964 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
[2009/07/16 05:51:19 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4977.dll
[2009/07/16 05:51:15 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2009/07/16 05:49:57 | 000,001,200 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2009/07/15 21:14:51 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/07/15 21:07:15 | 000,000,234 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/25 22:31:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/04/25 22:27:18 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/04/25 22:26:32 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 17:16:24 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/04/25 17:16:22 | 000,467,010 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/04/25 17:16:22 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/04/25 17:16:22 | 000,080,226 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/04/25 17:16:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/04/25 17:16:22 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/04/25 17:16:21 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/04/25 17:16:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/04/25 17:16:18 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/04/25 17:16:18 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/04/25 17:16:13 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/04/25 17:16:11 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/04/25 10:22:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/04/25 10:21:52 | 000,415,856 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/03/16 17:00:00 | 000,003,403 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:527B6DAD

< End of report >



Extras.txt Report.....

OTL Extras logfile created on: 05/08/2011 13:10:05 - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\sarah\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 2.09 Gb Available Physical Memory | 70.43% Memory free
4.81 Gb Paging File | 3.86 Gb Available in Paging File | 80.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.75 Gb Total Space | 209.38 Gb Free Space | 89.96% Space Free | Partition Type: NTFS

Computer Name: CWS-PC01 | User Name: sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"135:TCP:*:Enabled:Offer Remote Assistance - Port" = 135:TCP:*:Enabled:Offer Remote Assistance - Port

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings]
"Enabled" = 1
"RemoteAddresses" = localsubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = localsubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = localsubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\LMI25.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI25.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\WINDOWS\system32\hpbspsvr.exe" = C:\WINDOWS\system32\hpbspsvr.exe:*:Enabled:HP SocketPing Server -- (Hewlett-Packard Company)
"C:\WINDOWS\LMI17.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI17.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\WINDOWS\LMI1F.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI1F.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\WINDOWS\LMI22.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI22.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"D:\setup\HPPNIPRINT01.EXE" = D:\setup\HPPNIPRINT01.EXE:*:Enabled:hppniprint01.exe
"D:\setup\HPPNIPRINT64.EXE" = D:\setup\HPPNIPRINT64.EXE:*:Enabled:hppniprint64.exe
"D:\setup\HPPNICIFS01.EXE" = D:\setup\HPPNICIFS01.EXE:*:Enabled:hppnicifs01.exe
"D:\setup\CustomPrnDnld\HPPCSTPG.EXE" = D:\setup\CustomPrnDnld\HPPCSTPG.EXE:*:Enabled:hppcstpg.exe
"D:\setup\hpbtpg.exe" = D:\setup\hpbtpg.exe:*:Enabled:hpbtpg.exe
"D:\setup\LaunchApp.exe" = D:\setup\LaunchApp.exe:*:Enabled:launchapp.exe
"C:\WINDOWS\LMI67.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI67.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\WINDOWS\LMI3E.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3E.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\hpbspsvr.exe" = C:\WINDOWS\system32\hpbspsvr.exe:*:Disabled:HP SocketPing Server -- (Hewlett-Packard Company)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{05F26168-B5E6-4118-B510-FBD1BFB423FA}" = Microsoft Office Project 2007 Step by Step
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{0868BB9D-5EA0-40AF-A1CC-A38ED4E5BC67}" = 32 Bit HP CIO Components Installer
"{0AE19D89-17A9-404D-932A-FAAF43F3C77E}" = SPSS 14.0 for Windows
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{1093648B-1375-44BC-BC5E-39BF977D53FA}" = Nuance PDF Professional 6
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{26A7FC57-FC21-4CA9-85BD-4324B3294D8B}" = StuffIt 2010
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{51D5F2F7-18A9-4ABC-B1E8-BC3EC053C76E}" = hppPQVideoP2050
"{5783F2D7-8028-0409-0000-0060B0CE6BBA}" = DWG TrueView 2010
"{589F986E-5A4C-4D97-A755-8A3F57683A6D}" = hppTLBXFXP2050
"{5FDE3A66-69EF-4625-8490-EABF91E6B8A0}" = hpzTLBXFX
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6F801026-6AF0-4520-9153-4C9B4CAAB361}" = HP LaserJet P2050 Series 3.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{88253B77-33C9-4A9D-9E4C-4579E39D9158}" = Diagnostics Utility
"{89B6F63A-7E0C-424A-9D39-C4EF59E96D78}" = hppQFolderP2050
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PRJSTDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PRJSTDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJSTDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PRJSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJSTDR_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PRJSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-003A-0000-0000-0000000FF1CE}" = Microsoft Office Project Standard 2007
"{91120000-003A-0000-0000-0000000FF1CE}_PRJSTDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-003A-0000-0000-0000000FF1CE}_PRJSTDR_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F2783-8311-49BF-833E-DB659774B4F6}" = hppFonts
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{ABC082A6-A587-493C-83C1-5F2C60A8BAA8}" = FileOpen Client
"{ABEB838C-A1A7-4C5D-B7E1-8B4314600820}" = MSN Messenger 7.0
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AE60F600-FD60-40C4-A990-72F9BFEE475C}" = Dell Backup and Recovery Manager
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BD69DAB8-E483-4E45-A052-16D1C360B67D}" = hppusgP2050
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F181FBC3-C155-4FCB-AD46-9252440ACC5A}" = hppManualsP2050
"{FC1F6962-7737-11D3-A11A-0080AD78AADF}" = Flange Data System 5.0
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AVG9Uninstall" = AVG 9.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Diagram Designer" = Diagram Designer
"DWG TrueView 2010" = DWG TrueView 2010
"EPSON Printer and Utilities" = EPSON Printer Software
"HDMI" = Intel® Graphics Media Accelerator Driver
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office14.STANDARD" = Microsoft Office Standard 2010
"OU SPSS data for DSE212" = OU SPSS data for DSE212
"pdfFactory" = pdfFactory
"Print Server Driver" = Print Server Driver
"Printer Status and Alerts Uninstaller" = Printer Status and Alerts Uninstaller
"PRJSTDR" = Microsoft Office Project Standard 2007
"Shop for HP Supplies" = Shop for HP Supplies
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-842925246-926492609-725345543-1643\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SmartDraw 2010" = SmartDraw 2010

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 18/07/2011 05:33:35 | Computer Name = CWS-PC01 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Application, SystemIndex
Catalog

Error - 18/07/2011 05:33:35 | Computer Name = CWS-PC01 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Application, SystemIndex
Catalog

Error - 18/07/2011 05:33:51 | Computer Name = CWS-PC01 | Source = Application Error | ID = 1004
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module unknown, version 0.0.0.0, fault address 0xc033742e.

Error - 18/07/2011 05:35:30 | Computer Name = CWS-PC01 | Source = Application Error | ID = 1004
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module unknown, version 0.0.0.0, fault address 0xc033742e.

Error - 18/07/2011 05:35:35 | Computer Name = CWS-PC01 | Source = Application Error | ID = 1004
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module unknown, version 0.0.0.0, fault address 0xc033742e.

Error - 19/07/2011 07:49:26 | Computer Name = CWS-PC01 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 21/07/2011 04:15:03 | Computer Name = CWS-PC01 | Source = ESENT | ID = 490
Description = svchost (1192) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 21/07/2011 04:15:03 | Computer Name = CWS-PC01 | Source = ESENT | ID = 439
Description = Catalog Database (1192) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb. Error
-1032.

Error - 21/07/2011 04:15:03 | Computer Name = CWS-PC01 | Source = ESENT | ID = 470
Description = Catalog Database (1192) Database C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
is partially attached. Attachment stage: 1. Error: -1032.

Error - 04/08/2011 08:24:48 | Computer Name = CWS-PC01 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.26.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 05/08/2011 07:57:43 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7031
Description = The AVG WatchDog service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 0 milliseconds: Restart
the service.

Error - 05/08/2011 07:57:43 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7034
Description = The HP Status service terminated unexpectedly. It has done this 1
time(s).

Error - 05/08/2011 07:57:43 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 05/08/2011 07:57:43 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7034
Description = The HP Status Print service terminated unexpectedly. It has done
this 1 time(s).

Error - 05/08/2011 07:57:43 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7034
Description = The MBAMService service terminated unexpectedly. It has done this
1 time(s).

Error - 05/08/2011 07:57:43 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7034
Description = The PDFProFiltSrv service terminated unexpectedly. It has done this
1 time(s).

Error - 05/08/2011 07:57:43 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7034
Description = The Stuffit Archive Name Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 05/08/2011 07:57:44 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7034
Description = The Intel® Matrix Storage Event Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 05/08/2011 08:03:32 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7000
Description = The Norton Internet Security service failed to start due to the following
error: %%3

Error - 05/08/2011 08:03:36 | Computer Name = CWS-PC01 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SRTSP SRTSPX


< End of report >

#12 pwgib

pwgib

  • Malware Response Team
  • 2,956 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:God's Country
  • Local time:06:28 PM

Posted 05 August 2011 - 07:56 AM

Hi Sazzaa,

I have some bad news. :(

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall


We can still clean this machine but I can't guarantee that it will be 100% secure afterwards.

Since this is a business computer and if it is on a network there is the possibility other machines on the network could be infected. If you have any clients' sensitive or financial information on this computer you should notify them immediatly that their information may have been compromised.

Let me know what you decide to do.

If you decide to continue with cleaning please do the following:


Step 1.


Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
Be sure to download TDSSKiller.exe (v2.5.13.0) from Kaspersky's website.
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.5.13.0_27.07.2011_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.


Step 2.


Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
  • Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to Disable your Security Applications


    Note - If you have CA installed, due to recent changes in how this AV targets the tool's internal files, it must be uninstalled before running ComboFix. If you have difficulty uninstalling the AV, download Opswat AppRemover http://www.appremover.com/supported-applications <----Important
    Refer to this page if you are not sure how.
  • Close any open windows, including this one.
  • Double click on ComboFix.exe & follow the prompts.
  • For XP users only, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • If you did not have it installed, you will see the prompt below. Choose YES.
  • Posted Image
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    Posted Image
  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running.
ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.


Note: After running Combofix, you may receive an error about "illegal operation on a registry key that has been marked for deletion." If you receive this error, please reboot and it should disappear.


How is your computer running now?


In your next reply please include the following:

TDSSKiller log
Combofix.txt



Thanks!!

Edited by pwgib, 05 August 2011 - 07:57 AM.

PW

#13 Sazzaa

Sazzaa
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:28 PM

Posted 05 August 2011 - 08:12 AM

Malicious objects found with TDSSKiller - Backdoor.Win32.Sinowal.knf , I hit 'continue' to cure and a warning appears saying - "cant cure MBR. Write standard boot code? Yes or no." Should I click Yes?

Edited by Sazzaa, 05 August 2011 - 08:21 AM.


#14 pwgib

pwgib

  • Malware Response Team
  • 2,956 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:God's Country
  • Local time:06:28 PM

Posted 05 August 2011 - 08:35 AM

Hi Sazzaa,


Please follow the instructions for ComboFix and post the log. :thumbup2:



Thanks!!
PW

#15 pwgib

pwgib

  • Malware Response Team
  • 2,956 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:God's Country
  • Local time:06:28 PM

Posted 05 August 2011 - 12:03 PM

Hi Sazzaa,


If you are having trouble with ComboFix then do the following. :)


Rerun MBRCheck.exe again by double-clicking on it. Vista/Windows 7 users right-click and select Run As Administrator.
  • Wait until you see the following line: Enter 'Y' and hit ENTER for more options, or 'N' to exit:
  • Enter 'Y' and then press Enter.
  • When asked: 'Enter your choice:', select option [2] (Restore the MBR of a physical disk with a standard boot code) and press the Enter key.
  • Now the program will ask: 'Enter the physical disk number to fix (0-99, -1 to cancel)'
  • Enter [0] (for PhysicalDrive0) and press the Enter key.
  • The program will show Available MBR codes followed by a list of operating systems as shown below.

    Available MBR codes:
    [ 0] Default (Windows XP)
    [ 1] Windows XP
    [ 2] Windows Server 2003
    [ 3] Windows Vista
    [ 4] Windows 2008
    [ 5] Windows 7
    [-1] Cancel
    Please select the MBR code to write to this drive:

  • Please select your version of Windows, (in your case Windows XP), from the list and enter the corresponding number (For example, type 0 or 1 for XP, type 3 for Vista, type 5 for Windows 7, etc) and then press Enter. Be careful...if the wrong OS is used, it will render the computer unbootable.
  • When prompted for confirmation: 'Do you want to fix the MBR code?'. Type the full word Yes (not Y or the fix will not work) and press Enter.
  • Restart your PC.


After you restart the PC

  • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
  • It will show a Black screen with some data on it
  • A report called MBRcheck will be on your desktop
  • Open this report
  • Right click on the screen and select > Select All
  • Press Control+C
  • Please copy that report to this thread




Thanks!!
PW




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users