Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Found Exploit:JS/Blacole now computer virtually unusable


  • This topic is locked This topic is locked
27 replies to this topic

#1 Africanlion

Africanlion

  • Members
  • 45 posts
  • OFFLINE
  •  
  • Local time:09:43 AM

Posted 26 October 2011 - 10:23 PM

Microsoft Essentials detected what it reported as Exploit:JS/Blacole.O and i promptly removed it using Essentials. Since then the computer has not worked properly. The cursor has virtually stopped responding when i try and use the touchpad on my laptop. The cursor takes forever to respond when it does and it keeps going round spinning when i click on something. Web pages are taking very long to load and the computer keeps freezing and sometimes pages i am using just refresh for no apparent reason


The computer is almost unusable now. I have used Malwarebytes and Superantispyware and both are finding nothing. please help me

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.1.0
Run by Tendai at 22:34:38 on 2011-10-26
Microsoft Windows Vista Home Basic 6.0.6002.2.1252.44.1033.18.1917.438 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Toshiba TEMPRO\TemproTray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Windows\system32\agrsmsvc.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Synaptics\Scrybe\scrybe.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://mail.google.com/mail/?shva=1#inbox/131245e70ac32cba
uInternet Settings,ProxyOverride = *.local
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Speech Recognition] "c:\windows\speech\common\sapisvr.exe" -SpeechUX -Startup
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10x_Plugin.exe -update plugin
mRun: [Toshiba TEMPRO] c:\program files\toshiba tempro\TemproTray.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\scrybe.lnk - c:\windows\installer\{147dfad8-34c3-4de1-9fca-acefde9ef810}\NewShortcut11_8ACB210B42E44145A8C31F8E3DD765A3.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{64269981-636F-4FAD-B04A-F32E57C2C26A} : DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{85B9BBD9-7474-4605-8E3F-FE01B97288A7} : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{85B9BBD9-7474-4605-8E3F-FE01B97288A7} : DhcpNameServer = 194.168.4.100 194.168.8.100
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - No File
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\tendai\appdata\roaming\mozilla\firefox\profiles\rsun6w2c.default\
FF - plugin: c:\program files\canon\mycamera download plugin\NPCIG.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npvsharetvplg.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
.
============= SERVICES / DRIVERS ===============
.
R1 38013711;38013711;c:\windows\system32\drivers\38013711.sys [2011-6-24 128016]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2011-10-5 9216]
.
=============== Created Last 30 ================
.
2011-10-26 13:14:58 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{1568b82c-618e-4338-b61e-919eacdc98c0}\MpKslfcba78d4.sys
2011-10-26 13:14:46 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{1568b82c-618e-4338-b61e-919eacdc98c0}\offreg.dll
2011-10-25 15:55:14 -------- d-----r- c:\program files\Skype
2011-10-25 15:03:02 6668624 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{1568b82c-618e-4338-b61e-919eacdc98c0}\mpengine.dll
2011-10-21 01:17:54 -------- d-----w- c:\users\tendai\appdata\local\Rswsw
2011-10-19 21:39:50 -------- d-----w- c:\users\tendai\appdata\roaming\ZoomBrowser EX
2011-10-19 21:30:44 -------- d-----w- c:\programdata\ZoomBrowser
2011-10-19 21:28:47 -------- d-----w- c:\program files\common files\Canon
2011-10-19 19:10:58 611224 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-10-18 19:12:44 -------- d-----w- c:\program files\vShare.tv plugin
2011-10-17 22:16:54 -------- d-----w- c:\users\tendai\appdata\roaming\Synaptics
2011-10-17 22:10:35 218408 ----a-w- c:\windows\system32\SynCtrl.dll
2011-10-17 22:10:35 173352 ----a-w- c:\windows\system32\SynTPAPI.dll
2011-10-17 22:10:35 173352 ----a-w- c:\windows\system32\SynCOM.dll
2011-10-17 22:10:35 120104 ----a-w- c:\windows\system32\SynTPCo9.dll
2011-10-17 22:10:32 1335472 ----a-w- c:\windows\system32\drivers\SynTP.sys
2011-10-17 21:45:15 -------- d-----w- c:\programdata\Synaptics
2011-10-13 00:46:14 -------- d-----w- c:\users\tendai\.swt
2011-10-12 16:58:56 -------- d-----w- c:\program files\iPod
2011-10-12 16:58:50 -------- d-----w- c:\program files\iTunes
2011-10-12 16:50:34 -------- d-----w- c:\program files\Bonjour
2011-10-12 12:09:57 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-10-12 12:09:50 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-12 12:09:50 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-12 12:09:50 238080 ----a-w- c:\windows\system32\oleacc.dll
2011-10-12 12:09:49 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-10-12 12:09:36 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-12 12:09:36 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-12 12:09:35 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-12 12:09:35 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-10-12 12:09:33 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-10-11 17:21:35 703824 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{bb1d2ca6-53ed-4f69-b40d-78e9e6419609}\gapaengine.dll
2011-10-10 10:09:40 4550304 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2011-10-05 14:24:07 -------- d-----w- c:\programdata\Birdstep Technology
2011-10-05 14:23:23 9216 ----a-w- c:\windows\system32\drivers\massfilter.sys
2011-10-05 14:23:23 105088 ----a-w- c:\windows\system32\drivers\ZTEusbser6k.sys
2011-10-05 14:23:23 105088 ----a-w- c:\windows\system32\drivers\ZTEusbnmea.sys
2011-10-05 14:23:23 105088 ----a-w- c:\windows\system32\drivers\ZTEusbmdm6k.sys
2011-10-05 14:23:18 -------- d-----w- c:\program files\ZTE_1.2059.0.8
2011-10-03 09:14:54 83456 ----a-w- c:\program files\mozilla firefox\plugins\npvsharetvplg.dll
2011-10-02 19:07:37 -------- d-----w- c:\users\tendai\appdata\local\Apps
2011-10-02 14:53:54 -------- d-----w- c:\users\tendai\appdata\roaming\T-Mobile Internet Manager
2011-10-02 14:46:47 -------- d-----w- c:\users\tendai\appdata\roaming\T-Mobile
2011-10-02 14:46:09 -------- d-----w- c:\programdata\DataCardService
2011-10-02 14:45:30 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2011-10-02 14:45:30 1112288 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01007.dll
2011-10-02 14:36:14 -------- d-----w- c:\program files\T-Mobile
.
==================== Find3M ====================
.
2011-10-19 19:10:34 544656 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-12 19:43:58 1214976 ----a-w- c:\windows\system32\drivers\athr.sys
2011-09-29 00:16:46 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-01 02:35:59 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-08-31 16:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-30 22:05:04 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-08-30 22:05:04 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-08-30 22:05:04 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-08-30 22:05:04 178536 ----a-w- c:\windows\system32\dnssdX.dll
2011-08-06 12:33:13 100864 -c--a-w- C:\kgliipob.sys
.
============= FINISH: 22:37:16.70 ===============

Attached Files

  • Attached File  ark.txt   11.34KB   1 downloads

Edited by Africanlion, 27 October 2011 - 09:47 AM.


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,696 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:43 AM

Posted 31 October 2011 - 10:25 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

Posted Image In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/425205 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

Posted Image If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS and GMER log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


We also need a new log from the GMER anti-rootkit Scanner.

Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.

Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 Africanlion

Africanlion
  • Topic Starter

  • Members
  • 45 posts
  • OFFLINE
  •  
  • Local time:09:43 AM

Posted 02 November 2011 - 09:58 PM

Hi
Sorry for late reply. Yes i still desperately need help please


Thank you

#4 Casey_boy

Casey_boy

    Bleeping physicist


  • Malware Response Team
  • 7,765 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:09:43 AM

Posted 03 November 2011 - 07:12 AM

Hi,

Were you experiencing any problems before the removal?

Could you find the scan log which relates to the scan where you removed the Exploit - it should be located in this folder: C:\ProgramData\Microsoft\Microsoft Antimalware\Support.

I will also close your topic at Geeks2Go to avoid confusion.

Casey

If I have been helping you and I do not reply within 48hours, feel free to send me a PM.


* My Website * Am I Infected? * Malware Removal Help * If you'd like to say thanks *


#5 Africanlion

Africanlion
  • Topic Starter

  • Members
  • 45 posts
  • OFFLINE
  •  
  • Local time:09:43 AM

Posted 03 November 2011 - 12:52 PM

Hi,

Were you experiencing any problems before the removal?

Could you find the scan log which relates to the scan where you removed the Exploit - it should be located in this folder: C:\ProgramData\Microsoft\Microsoft Antimalware\Support.

I will also close your topic at Geeks2Go to avoid confusion.

Casey



Hi
I wasnt experiencing problems till Microsft found the infection and i deleted it. I restarted the machine and its not been working well since then. It found the infection a second time and this time it was reported as Exploit:JS/Blacole.N. First infection was Exploit:JS/Blacole.O


I have went into that folder but i dont know where to find the scan log. There are so many options
MPLog
MpDetection (2 of them)
MpCachestats

Edited by Africanlion, 03 November 2011 - 12:59 PM.


#6 Casey_boy

Casey_boy

    Bleeping physicist


  • Malware Response Team
  • 7,765 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:09:43 AM

Posted 03 November 2011 - 02:00 PM

Hi,

Sorry, an easier way may be to open Microsoft Security Essentials and then click History. List any details details there for me please :)

Casey

Edited by Casey_boy, 03 November 2011 - 02:01 PM.

If I have been helping you and I do not reply within 48hours, feel free to send me a PM.


* My Website * Am I Infected? * Malware Removal Help * If you'd like to say thanks *


#7 Africanlion

Africanlion
  • Topic Starter

  • Members
  • 45 posts
  • OFFLINE
  •  
  • Local time:09:43 AM

Posted 03 November 2011 - 03:24 PM

How do i paste a screenshot here mate? it wont let me paste the Security essentials history screenshot

#8 Africanlion

Africanlion
  • Topic Starter

  • Members
  • 45 posts
  • OFFLINE
  •  
  • Local time:09:43 AM

Posted 03 November 2011 - 03:30 PM

I have created a zip file for security essential so you can see the history

Attached Files



#9 Casey_boy

Casey_boy

    Bleeping physicist


  • Malware Response Team
  • 7,765 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:09:43 AM

Posted 03 November 2011 - 04:17 PM

Hmmm...OK well I don't see why removal of those would affect your PC, so let's just check for any more malware. If performance doesn't return to normal then we can try a system restore.

Download and run ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you are prompted to install the Recovery Console, then please do so.

Please include the C:\ComboFix.txt in your next reply for further review.

Note: If you have trouble running ComboFix, then please rename ComboFix.exe to Caseyboy.exe and re-run.

Casey

If I have been helping you and I do not reply within 48hours, feel free to send me a PM.


* My Website * Am I Infected? * Malware Removal Help * If you'd like to say thanks *


#10 Africanlion

Africanlion
  • Topic Starter

  • Members
  • 45 posts
  • OFFLINE
  •  
  • Local time:09:43 AM

Posted 04 November 2011 - 04:52 AM

ComboFix 11-11-03.05 - Tendai 04/11/2011 2:07.3.1 - x86
Microsoft Windows Vista Home Basic 6.0.6002.2.1252.44.1033.18.1917.486 [GMT 0:00]
Running from: c:\users\Tendai\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-10-04 to 2011-11-04 )))))))))))))))))))))))))))))))
.
.
2011-11-04 02:21 . 2011-11-04 02:21 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-11-04 02:21 . 2011-11-04 02:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-03 15:56 . 2011-11-03 15:56 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F9C19EF-DBAD-484F-9946-C64BD4049F01}\MpKsla6ae73ec.sys
2011-11-02 20:19 . 2011-11-02 20:19 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F9C19EF-DBAD-484F-9946-C64BD4049F01}\MpKslb0fbb775.sys
2011-11-02 20:07 . 2011-11-02 20:07 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F9C19EF-DBAD-484F-9946-C64BD4049F01}\MpKslaf371264.sys
2011-11-02 20:05 . 2011-11-03 15:56 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F9C19EF-DBAD-484F-9946-C64BD4049F01}\offreg.dll
2011-11-02 20:05 . 2011-10-07 03:48 6668624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F9C19EF-DBAD-484F-9946-C64BD4049F01}\mpengine.dll
2011-10-28 00:14 . 2011-10-28 00:14 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin7.dll
2011-10-28 00:14 . 2011-10-28 00:14 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin6.dll
2011-10-28 00:14 . 2011-10-28 00:14 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin5.dll
2011-10-28 00:14 . 2011-10-28 00:14 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin4.dll
2011-10-28 00:14 . 2011-10-28 00:14 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin3.dll
2011-10-28 00:14 . 2011-10-28 00:14 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin2.dll
2011-10-28 00:14 . 2011-10-28 00:14 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin.dll
2011-10-25 15:56 . 2011-10-27 22:52 -------- d-----w- c:\users\Tendai\AppData\Roaming\Skype
2011-10-25 15:55 . 2011-10-25 15:56 -------- d-----r- c:\program files\Skype
2011-10-25 15:54 . 2011-10-25 15:55 -------- d-----w- c:\programdata\Skype
2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-21 01:17 . 2011-10-21 01:17 -------- d-----w- c:\users\Tendai\AppData\Local\Rswsw
2011-10-19 21:39 . 2011-10-19 21:39 -------- d-----w- c:\users\Tendai\AppData\Roaming\ZoomBrowser EX
2011-10-19 21:30 . 2011-10-19 21:30 -------- d-----w- c:\programdata\ZoomBrowser
2011-10-19 21:28 . 2011-10-19 21:28 -------- d-----w- c:\program files\Common Files\Canon
2011-10-19 19:10 . 2011-10-19 19:10 611224 ----a-w- c:\program files\Mozilla Firefox\Plugins\npdeployJava1.dll
2011-10-18 19:12 . 2011-10-22 20:57 -------- d-----w- c:\program files\vShare.tv plugin
2011-10-17 22:16 . 2011-10-17 22:16 -------- d-----w- c:\users\Tendai\AppData\Roaming\Synaptics
2011-10-17 22:10 . 2011-03-31 18:30 173352 ----a-w- c:\windows\system32\SynTPAPI.dll
2011-10-17 22:10 . 2011-03-31 18:30 120104 ----a-w- c:\windows\system32\SynTPCo9.dll
2011-10-17 22:10 . 2011-03-31 18:30 218408 ----a-w- c:\windows\system32\SynCtrl.dll
2011-10-17 22:10 . 2011-03-31 18:30 173352 ----a-w- c:\windows\system32\SynCOM.dll
2011-10-17 22:10 . 2011-03-31 18:32 1335472 ----a-w- c:\windows\system32\drivers\SynTP.sys
2011-10-17 21:45 . 2011-10-17 21:45 -------- d-----w- c:\programdata\Synaptics
2011-10-13 00:46 . 2011-10-13 00:46 -------- d-----w- c:\users\Tendai\.swt
2011-10-12 16:58 . 2011-10-12 16:58 -------- d-----w- c:\program files\iPod
2011-10-12 16:58 . 2011-10-12 17:00 -------- d-----w- c:\program files\iTunes
2011-10-12 16:50 . 2011-10-12 16:50 -------- d-----w- c:\program files\Bonjour
2011-10-12 12:09 . 2011-09-14 10:51 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-10-12 12:09 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-12 12:09 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-12 12:09 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2011-10-12 12:09 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-10-12 12:09 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-12 12:09 . 2011-07-29 16:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-12 12:09 . 2011-07-29 16:00 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-10-12 12:09 . 2011-07-29 16:00 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-12 12:09 . 2011-09-06 13:30 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-10-11 17:21 . 2011-10-11 17:20 703824 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB1D2CA6-53ED-4F69-B40D-78E9E6419609}\gapaengine.dll
2011-10-10 10:09 . 2011-10-10 10:09 4550304 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2011-10-05 14:24 . 2011-10-17 21:37 -------- d-----w- c:\programdata\Birdstep Technology
2011-10-05 14:23 . 2010-01-19 11:49 9216 ----a-w- c:\windows\system32\drivers\massfilter.sys
2011-10-05 14:23 . 2010-01-19 11:49 105088 ----a-w- c:\windows\system32\drivers\ZTEusbser6k.sys
2011-10-05 14:23 . 2010-01-19 11:49 105088 ----a-w- c:\windows\system32\drivers\ZTEusbnmea.sys
2011-10-05 14:23 . 2010-01-19 11:49 105088 ----a-w- c:\windows\system32\drivers\ZTEusbmdm6k.sys
2011-10-05 14:23 . 2011-10-05 14:23 -------- d-----w- c:\program files\ZTE_1.2059.0.8
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-27 23:08 . 2011-06-21 23:50 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-19 19:10 . 2011-06-15 01:04 544656 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-12 19:43 . 2010-04-27 14:19 1214976 ----a-w- c:\windows\system32\drivers\athr.sys
2011-10-07 03:48 . 2011-08-29 23:52 6668624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-31 16:00 . 2011-08-13 14:51 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-30 22:05 . 2011-08-30 22:05 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-08-30 22:05 . 2011-08-30 22:05 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-08-30 22:05 . 2011-08-30 22:05 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-08-30 22:05 . 2011-08-30 22:05 178536 ----a-w- c:\windows\system32\dnssdX.dll
2011-08-16 07:48 . 2011-08-28 23:28 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E41E514E-3DB1-43C0-92B3-EF12B2DC3EC6}\mpengine.dll
2011-08-06 12:33 . 2011-06-29 18:42 100864 -c--a-w- C:\kgliipob.sys
2011-10-16 15:12 . 2011-06-15 01:32 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2008-01-19 49664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba TEMPRO"="c:\program files\Toshiba TEMPRO\TemproTray.exe" [2010-08-27 1050072]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-03-31 2221352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Scrybe.lnk - c:\windows\Installer\{147DFAD8-34C3-4DE1-9FCA-ACEFDE9EF810}\NewShortcut11_8ACB210B42E44145A8C31F8E3DD765A3.exe [2011-10-17 45056]
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-04 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00TCrdMain]
2006-12-11 17:27 530552 ----a-w- c:\program files\TOSHIBA\FlashCards\TCrdMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
2005-04-08 13:09 102400 ------w- c:\program files\epson\Creativity Suite\Event Manager\EEventManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 17:06 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-08-31 16:00 1047208 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 14:16 997920 ----a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 13:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2006-11-01 15:37 3772416 ----a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2006-12-14 19:09 493688 ----a-w- c:\program files\TOSHIBA\SmoothView\SmoothView.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\topi]
2006-12-15 17:11 577536 ----a-w- c:\program files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
2006-12-13 14:42 554640 ----a-w- c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSHIBA Volume Indicator]
2006-12-13 09:33 94208 ----a-w- c:\program files\TOSHIBA\Utilities\VolControl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
2006-12-14 19:07 411768 ----a-w- c:\program files\TOSHIBA\Power Saver\TPwrMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl04eaf06c;MpKsl04eaf06c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B27B764D-EBF1-4342-AF26-A1C2EE6F7DEE}\MpKsl04eaf06c.sys [x]
R1 MpKsl06a507d1;MpKsl06a507d1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBE2861F-2422-4A66-A572-9BD1DDF27015}\MpKsl06a507d1.sys [x]
R1 MpKsl2470f382;MpKsl2470f382;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6E1A5A2F-FEBA-4046-B2A9-7C6DD5A656D9}\MpKsl2470f382.sys [x]
R1 MpKsl26e70f11;MpKsl26e70f11;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5996A0FA-BBFC-4E49-A57C-C3146514C835}\MpKsl26e70f11.sys [x]
R1 MpKsl335422d6;MpKsl335422d6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB6A579E-6036-4E3D-98B0-A58A1CFE1D05}\MpKsl335422d6.sys [x]
R1 MpKsl60d4b5f6;MpKsl60d4b5f6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBE2861F-2422-4A66-A572-9BD1DDF27015}\MpKsl60d4b5f6.sys [x]
R1 MpKsl65d26787;MpKsl65d26787;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{799228E2-377F-4E67-B8C9-13D3C779151E}\MpKsl65d26787.sys [x]
R1 MpKsl6604fe8c;MpKsl6604fe8c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DD3E3D62-9FAE-4805-ACF2-9344343FFBEB}\MpKsl6604fe8c.sys [x]
R1 MpKsl7b84d449;MpKsl7b84d449;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{01D89368-EA7B-4100-A907-618E2B54E5FE}\MpKsl7b84d449.sys [x]
R1 MpKsl80d940e9;MpKsl80d940e9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBE2861F-2422-4A66-A572-9BD1DDF27015}\MpKsl80d940e9.sys [x]
R1 MpKsl82dde00e;MpKsl82dde00e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{802AEEB9-5FAF-49EB-9EBF-23838E304EB8}\MpKsl82dde00e.sys [x]
R1 MpKsl84a22a75;MpKsl84a22a75;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{90C35501-E546-4EBC-B49F-1C1B10D2F22B}\MpKsl84a22a75.sys [x]
R1 MpKsl99424f3a;MpKsl99424f3a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6E1A5A2F-FEBA-4046-B2A9-7C6DD5A656D9}\MpKsl99424f3a.sys [x]
R1 MpKsld687338f;MpKsld687338f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6E1A5A2F-FEBA-4046-B2A9-7C6DD5A656D9}\MpKsld687338f.sys [x]
R1 MpKslddad8878;MpKslddad8878;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2B52D0B1-47CB-4DBB-9218-2C13FC8F5EED}\MpKslddad8878.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-06-15 136176]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-06-15 136176]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys [x]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2010-01-19 9216]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe [2008-01-19 21504]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 38013711;38013711;c:\windows\system32\DRIVERS\38013711.sys [2009-09-25 128016]
S1 MpKsla6ae73ec;MpKsla6ae73ec;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F9C19EF-DBAD-484F-9946-C64BD4049F01}\MpKsla6ae73ec.sys [2011-11-03 28752]
S1 MpKslaf371264;MpKslaf371264;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F9C19EF-DBAD-484F-9946-C64BD4049F01}\MpKslaf371264.sys [2011-11-02 28752]
S1 MpKslb0fbb775;MpKslb0fbb775;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F9C19EF-DBAD-484F-9946-C64BD4049F01}\MpKslb0fbb775.sys [2011-11-02 28752]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-08-04 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-08-04 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-17 116608]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S2 ScrybeUpdater;Scrybe Updater;c:\program files\Synaptics\Scrybe\Service\ScrybeUpdater.exe [2011-05-27 1300264]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-04-19 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2011-04-19 399416]
S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [2010-08-27 124368]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSLA6AE73EC
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-15 01:17]
.
2011-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-15 01:17]
.
.
------- Supplementary Scan -------
.
uStart Page = https://mail.google.com/mail/?shva=1#inbox/131245e70ac32cba
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{85B9BBD9-7474-4605-8E3F-FE01B97288A7}: NameServer = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\Tendai\AppData\Roaming\Mozilla\Firefox\Profiles\rsun6w2c.default\
.
- - - - ORPHANS REMOVED - - - -
.
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
MSConfigStartUp-@OnlineArmor GUI - c:\program files\Online Armor\oaui.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-04 02:22
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\users\Tendai\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\0a\04\0d\00,-H"
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-11-04 02:37:44
ComboFix-quarantined-files.txt 2011-11-04 02:37
.
Pre-Run: 13,446,299,648 bytes free
Post-Run: 13,420,933,120 bytes free
.
- - End Of File - - 00F3B89798411A719FF811F5502F6F69

#11 Casey_boy

Casey_boy

    Bleeping physicist


  • Malware Response Team
  • 7,765 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:09:43 AM

Posted 04 November 2011 - 09:38 AM

Please visit the online Jotti Virus Scanner Posted Image<--link
  • Browse to the following filepath:

    c:\windows\system32\DRIVERS\38013711.sys

  • Click on the Posted Image button.
    The scanner will check the file with various AV companies.
  • Copy and paste the results box into a reply to this thread.
  • Repeat this for all the file listed above

Also, could you look inside this folder and see what's in it:

c:\users\Tendai\AppData\Local\Rswsw

Casey

If I have been helping you and I do not reply within 48hours, feel free to send me a PM.


* My Website * Am I Infected? * Malware Removal Help * If you'd like to say thanks *


#12 Africanlion

Africanlion
  • Topic Starter

  • Members
  • 45 posts
  • OFFLINE
  •  
  • Local time:09:43 AM

Posted 05 November 2011 - 02:23 PM

Jotti scanner found nothing on that file


That folder i just checked and its empty

#13 Casey_boy

Casey_boy

    Bleeping physicist


  • Malware Response Team
  • 7,765 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:09:43 AM

Posted 06 November 2011 - 10:06 AM

OK, let' get another scan to see if anything appears in there.

We need to create an OTL Report
  • Please download OTL from here
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
  • OTL.txt <-- Will be opened
  • Extra.txt <-- Will be minimized

Casey

If I have been helping you and I do not reply within 48hours, feel free to send me a PM.


* My Website * Am I Infected? * Malware Removal Help * If you'd like to say thanks *


#14 Africanlion

Africanlion
  • Topic Starter

  • Members
  • 45 posts
  • OFFLINE
  •  
  • Local time:09:43 AM

Posted 06 November 2011 - 04:08 PM

OTL logfile created on: 06/11/2011 20:58:33 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Tendai\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.87 Gb Total Physical Memory | 0.81 Gb Available Physical Memory | 43.22% Memory free
3.99 Gb Paging File | 2.59 Gb Available in Paging File | 64.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 54.42 Gb Total Space | 12.40 Gb Free Space | 22.78% Space Free | Partition Type: NTFS

Computer Name: TENDAI-PC | User Name: Tendai | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/06 20:58:13 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Tendai\Desktop\OTL.exe
PRC - [2011/11/04 21:54:42 | 003,293,784 | ---- | M] () -- C:\Users\Tendai\AppData\Local\Akamai\netsession_win.exe
PRC - [2011/10/16 15:12:22 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/08/17 18:01:17 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2011/06/15 14:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/05/27 15:23:00 | 004,999,976 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\Scrybe\scrybe.exe
PRC - [2011/05/27 15:23:00 | 001,300,264 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe
PRC - [2011/04/27 14:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
PRC - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2011/04/19 06:44:40 | 000,993,848 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psia.exe
PRC - [2011/04/19 06:44:40 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\sua.exe
PRC - [2011/04/19 06:44:40 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psi_tray.exe
PRC - [2010/08/27 12:14:48 | 001,050,072 | ---- | M] (Toshiba Europe GmbH) -- C:\Program Files\Toshiba TEMPRO\TemproTray.exe
PRC - [2010/08/27 12:14:42 | 000,124,368 | ---- | M] (Toshiba Europe GmbH) -- C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
PRC - [2009/04/11 06:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2006/12/14 19:06:14 | 000,428,152 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2006/11/14 19:33:10 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2006/09/12 07:03:20 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2006/08/23 16:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2006/05/25 18:30:16 | 000,114,688 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2006/04/28 09:14:44 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/04 21:54:42 | 003,293,784 | ---- | M] () -- C:\Users\Tendai\AppData\Local\Akamai\netsession_win.exe
MOD - [2011/10/27 23:08:17 | 008,522,400 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011/10/16 15:12:21 | 001,833,944 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/10/12 12:57:24 | 001,711,616 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\b67478ec034fdf811a748f1b6b5b1c95\Microsoft.VisualBasic.ni.dll
MOD - [2011/10/12 12:56:50 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6bc98e9b5eedaa8f71c5454d36a4b772\System.Management.ni.dll
MOD - [2011/10/12 12:55:22 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8645de531003807d00822e03986a075d\System.ServiceProcess.ni.dll
MOD - [2011/10/12 12:55:15 | 011,804,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\e00630ec1e225a2376fdd430645e20f7\System.Web.ni.dll
MOD - [2011/10/12 12:55:03 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll
MOD - [2011/10/12 12:54:34 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll
MOD - [2011/10/12 12:53:03 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll
MOD - [2011/10/12 12:52:36 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll
MOD - [2011/10/12 12:52:21 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll
MOD - [2011/10/12 12:47:56 | 012,216,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\53f949f4664bb316f9b7a00d73a6e290\PresentationCore.ni.dll
MOD - [2011/10/12 12:47:35 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd2c727bcef2e019eb96c1145f423701\WindowsBase.ni.dll
MOD - [2011/10/12 12:47:29 | 007,950,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll
MOD - [2011/10/12 12:47:11 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MOD - [2011/06/24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/03/31 18:31:02 | 000,066,856 | ---- | M] () -- C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll
MOD - [2006/11/24 20:37:38 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/11/05 19:43:25 | 003,298,392 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_d71b4a3.dll -- (Akamai)
SRV - [2011/08/17 18:01:17 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2011/05/27 15:23:00 | 001,300,264 | ---- | M] (Synaptics, Inc.) [Auto | Running] -- C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe -- (ScrybeUpdater)
SRV - [2011/05/25 14:14:34 | 000,053,248 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus®
SRV - [2011/04/27 14:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/04/19 06:44:40 | 000,993,848 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2011/04/19 06:44:40 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2010/08/27 12:14:42 | 000,124,368 | ---- | M] (Toshiba Europe GmbH) [Auto | Running] -- C:\Program Files\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO)
SRV - [2008/01/19 07:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006/12/14 19:06:14 | 000,428,152 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2006/11/14 19:33:10 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (CFSvcs)
SRV - [2006/09/12 07:03:20 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006/08/23 16:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2006/05/25 18:30:16 | 000,114,688 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)


========== Driver Services (SafeList) ==========

DRV - [2011/11/06 19:01:29 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{693CA64C-E3A2-4BF9-94A0-51CD85D165FB}\MpKsle7e00d70.sys -- (MpKsle7e00d70)
DRV - [2011/10/12 19:43:58 | 001,214,976 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2011/08/04 23:34:58 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/08/04 23:34:58 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2011/04/27 14:25:24 | 000,065,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/04/18 12:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2010/09/01 08:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\psi_mf.sys -- (PSI)
DRV - [2010/01/19 11:49:50 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2010/01/19 11:49:50 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2010/01/19 11:49:50 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2010/01/19 11:49:50 | 000,009,216 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter)
DRV - [2009/09/25 16:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\System32\drivers\38013711.sys -- (38013711)
DRV - [2007/11/09 04:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/07/13 07:18:20 | 000,050,688 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006/11/24 20:46:38 | 002,085,888 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006/11/20 17:14:28 | 000,033,792 | ---- | M] (TOSHIBA) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\qkbfiltr.sys -- (qkbfiltr)
DRV - [2006/10/18 11:50:04 | 000,016,128 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2006/10/12 08:18:14 | 000,007,680 | ---- | M] (Quanta Computer Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BoiHwSetup.sys -- (BoiHwsetup)
DRV - [2006/08/31 05:53:00 | 001,161,152 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/02/14 17:50:52 | 000,216,320 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\kr10i.sys -- (KR10I)
DRV - [2006/02/14 17:41:20 | 000,208,256 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\kr10n.sys -- (KR10N)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://mail.google.com/mail/?shva=1#inbox/131245e70ac32cba
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7B 2C C1 B1 C7 2C CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.103: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/16 15:12:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/28 00:14:41 | 000,000,000 | ---D | M]

[2011/06/15 01:35:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tendai\AppData\Roaming\mozilla\Extensions
[2011/09/18 17:06:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tendai\AppData\Roaming\mozilla\Firefox\Profiles\rsun6w2c.default\extensions
[2011/06/21 22:02:51 | 000,001,735 | ---- | M] () -- C:\Users\Tendai\AppData\Roaming\Mozilla\Firefox\Profiles\rsun6w2c.default\searchplugins\ask.uk.xml
[2011/10/25 15:56:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/25 15:56:13 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/06/23 00:36:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/19 19:18:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/10/19 19:11:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\TENDAI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RSUN6W2C.DEFAULT\EXTENSIONS\{CE6E6E3B-84DD-4CAC-9F63-8D2AE4F30A4B}.XPI
[2011/10/16 15:12:24 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/19 19:10:37 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/03 09:14:54 | 000,083,456 | ---- | M] (vShare.tv ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011/10/16 15:12:17 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/07/01 14:54:52 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Tendai\AppData\Local\Akamai\netsession_win.exe ()
O4 - HKCU..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64269981-636F-4FAD-B04A-F32E57C2C26A}: DhcpNameServer = 194.168.4.100 194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{85B9BBD9-7474-4605-8E3F-FE01B97288A7}: DhcpNameServer = 194.168.4.100 194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{85B9BBD9-7474-4605-8E3F-FE01B97288A7}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Tendai\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Tendai\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/06 20:57:59 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Tendai\Desktop\OTL.exe
[2011/11/04 10:31:15 | 000,000,000 | ---D | C] -- C:\Users\Tendai\AppData\Local\Akamai
[2011/11/04 02:37:58 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/11/04 02:35:04 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/11/04 01:52:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/11/04 01:52:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/11/04 01:52:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/11/04 01:28:40 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/04 01:19:25 | 004,282,413 | R--- | C] (Swearware) -- C:\Users\Tendai\Desktop\ComboFix.exe
[2011/10/26 21:33:39 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Tendai\Desktop\dds.scr
[2011/10/25 15:56:15 | 000,000,000 | ---D | C] -- C:\Users\Tendai\AppData\Roaming\Skype
[2011/10/25 15:55:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/10/25 15:55:14 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2011/10/25 15:54:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2011/10/24 13:29:02 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\Windows\System32\QuickTimeVR.qtx
[2011/10/24 13:29:02 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\Windows\System32\QuickTime.qts
[2011/10/21 01:17:54 | 000,000,000 | ---D | C] -- C:\Users\Tendai\AppData\Local\Rswsw
[2011/10/19 21:39:50 | 000,000,000 | ---D | C] -- C:\Users\Tendai\AppData\Roaming\ZoomBrowser EX
[2011/10/19 21:30:44 | 000,000,000 | ---D | C] -- C:\ProgramData\ZoomBrowser
[2011/10/19 21:28:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Canon
[2011/10/19 19:18:48 | 000,214,408 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2011/10/19 19:18:48 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2011/10/19 19:18:48 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2011/10/18 19:12:44 | 000,000,000 | ---D | C] -- C:\Program Files\vShare.tv plugin
[2011/10/17 22:16:54 | 000,000,000 | ---D | C] -- C:\Users\Tendai\AppData\Roaming\Synaptics
[2011/10/17 22:10:35 | 000,120,104 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\SynTPCo9.dll
[2011/10/17 21:45:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scrybe
[2011/10/17 21:45:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Synaptics
[2011/10/13 00:46:14 | 000,000,000 | ---D | C] -- C:\Users\Tendai\.swt
[2011/10/12 17:00:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/12 16:58:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/10/12 16:58:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/10/12 16:50:34 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/10/12 12:29:48 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/10/12 12:29:45 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/10/12 12:29:43 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/10/12 12:29:43 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/10/12 12:29:41 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/10/12 12:09:50 | 000,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
[2011/10/12 12:09:49 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
[2011/10/12 12:09:36 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2011/10/12 12:09:36 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2011/10/12 12:09:35 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
[2011/10/12 12:09:35 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2011/10/12 12:09:33 | 002,043,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys

========== Files - Modified Within 30 Days ==========

[2011/11/06 20:58:13 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Tendai\Desktop\OTL.exe
[2011/11/06 20:49:00 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/06 20:49:00 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/06 20:29:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/06 20:12:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/06 18:54:56 | 000,615,990 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/11/06 18:54:56 | 000,114,174 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/11/06 18:49:30 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/04 01:19:32 | 004,282,413 | R--- | M] (Swearware) -- C:\Users\Tendai\Desktop\ComboFix.exe
[2011/11/04 00:03:16 | 000,040,448 | ---- | M] () -- C:\Users\Tendai\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/03 20:28:28 | 000,256,678 | ---- | M] () -- C:\Users\Tendai\Documents\security essentials.zip
[2011/11/03 20:15:42 | 006,301,975 | ---- | M] () -- C:\Users\Tendai\Documents\security essentials.rtf
[2011/11/03 17:46:29 | 006,301,975 | ---- | M] () -- C:\Users\Tendai\Documents\screenshot.rtf
[2011/10/31 22:00:04 | 000,120,563 | ---- | M] () -- C:\Users\Tendai\Documents\untitled_2.odt
[2011/10/31 17:15:18 | 000,018,402 | ---- | M] () -- C:\Users\Tendai\Documents\untitled_0.odt
[2011/10/28 00:14:34 | 000,001,691 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/10/27 23:08:19 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/10/26 21:55:55 | 000,294,195 | ---- | M] () -- C:\Users\Tendai\Desktop\gmer.zip
[2011/10/26 21:34:24 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Tendai\Desktop\dds.scr
[2011/10/25 15:55:34 | 000,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/10/24 13:29:02 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\Windows\System32\QuickTimeVR.qtx
[2011/10/24 13:29:02 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\Windows\System32\QuickTime.qts
[2011/10/22 15:16:22 | 000,007,944 | ---- | M] () -- C:\Users\Tendai\AppData\Local\d3d9caps.dat
[2011/10/19 21:30:44 | 000,001,046 | ---- | M] () -- C:\Users\Public\Desktop\ZoomBrowser EX.lnk
[2011/10/19 19:41:31 | 000,000,769 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/10/19 19:10:35 | 000,214,408 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2011/10/19 19:10:35 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2011/10/19 19:10:34 | 000,544,656 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2011/10/19 19:10:34 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2011/10/17 22:14:08 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2011/10/17 21:45:30 | 000,001,878 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Scrybe.lnk
[2011/10/17 20:24:41 | 000,024,232 | ---- | M] () -- C:\Users\Tendai\Documents\sami draft.odt
[2011/10/13 00:44:42 | 000,001,598 | ---- | M] () -- C:\Users\Tendai\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011/10/13 00:44:42 | 000,001,598 | ---- | M] () -- C:\Users\Public\Desktop\Vuze.lnk
[2011/10/12 19:43:58 | 001,214,976 | ---- | M] (Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athr.sys
[2011/10/12 12:43:22 | 000,282,792 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2011/11/04 01:52:39 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/11/04 01:52:39 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/11/04 01:52:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/11/04 01:52:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/11/04 01:52:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/11/03 20:28:24 | 000,256,678 | ---- | C] () -- C:\Users\Tendai\Documents\security essentials.zip
[2011/11/03 20:15:42 | 006,301,975 | ---- | C] () -- C:\Users\Tendai\Documents\security essentials.rtf
[2011/11/03 17:46:28 | 006,301,975 | ---- | C] () -- C:\Users\Tendai\Documents\screenshot.rtf
[2011/11/02 23:22:44 | 000,120,563 | ---- | C] () -- C:\Users\Tendai\Documents\untitled_2.odt
[2011/11/02 23:22:44 | 000,018,402 | ---- | C] () -- C:\Users\Tendai\Documents\untitled_0.odt
[2011/10/26 21:55:41 | 000,294,195 | ---- | C] () -- C:\Users\Tendai\Desktop\gmer.zip
[2011/10/25 15:55:34 | 000,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/10/19 21:30:44 | 000,001,046 | ---- | C] () -- C:\Users\Public\Desktop\ZoomBrowser EX.lnk
[2011/10/17 22:14:08 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2011/10/17 21:45:30 | 000,001,878 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Scrybe.lnk
[2011/10/17 20:24:40 | 000,024,232 | ---- | C] () -- C:\Users\Tendai\Documents\sami draft.odt
[2011/07/07 23:32:27 | 000,000,000 | ---- | C] () -- C:\Windows\RAWImage.INI
[2011/06/30 16:01:58 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2011/06/30 16:01:56 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2011/06/30 16:01:56 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2011/06/30 16:01:56 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2011/06/30 16:01:55 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2011/06/30 16:01:55 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2011/06/30 16:01:55 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2011/06/30 16:01:55 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2011/06/30 16:01:55 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2011/06/30 16:01:55 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2011/06/30 16:01:55 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2011/06/30 16:01:55 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2011/06/30 16:01:54 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2011/06/30 16:01:54 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2011/06/30 16:01:54 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2011/06/30 16:01:54 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2011/06/30 16:01:53 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2011/06/30 16:01:53 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2011/06/30 16:01:53 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2011/06/29 18:25:53 | 000,000,000 | ---- | C] () -- C:\Windows\OpPrintServer.INI
[2011/06/26 18:18:16 | 000,007,944 | ---- | C] () -- C:\Users\Tendai\AppData\Local\d3d9caps.dat
[2011/06/17 08:55:58 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/06/17 08:55:57 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/06/16 22:16:32 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/06/16 21:19:45 | 000,000,309 | ---- | C] () -- C:\Users\Tendai\AppData\Local\HamsterVideoConverterSettings.cfg
[2011/06/15 01:48:31 | 000,000,027 | ---- | C] () -- C:\Windows\CDE RX640E.ini
[2011/06/15 01:33:03 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/06/15 00:59:49 | 000,040,448 | ---- | C] () -- C:\Users\Tendai\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/15 00:55:12 | 000,000,751 | ---- | C] () -- C:\Windows\Ulead32.ini
[2011/06/15 00:55:12 | 000,000,028 | ---- | C] () -- C:\Windows\Msdevctl.ini
[2010/01/19 11:49:54 | 000,466,944 | ---- | C] () -- C:\Windows\System32\RemoveDevice.dll
[2006/12/20 12:47:38 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2006/12/20 12:47:38 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2006/12/20 12:47:38 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2006/12/20 12:47:38 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2006/12/20 12:47:38 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2006/12/20 12:47:38 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2006/12/20 12:33:16 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2006/12/20 12:19:59 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2006/12/20 12:19:59 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2006/12/20 12:19:59 | 000,010,150 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2006/12/20 12:19:59 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2006/12/20 12:15:15 | 000,049,152 | ---- | C] () -- C:\Windows\System32\ChCfg.exe
[2006/12/20 11:49:23 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2006/12/20 11:49:23 | 000,138,101 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2006/11/02 12:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 12:44:53 | 000,282,792 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 10:33:01 | 000,615,990 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 10:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 10:33:01 | 000,114,174 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 10:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 10:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/02 10:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 08:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 08:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 07:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 07:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2005/06/29 05:16:00 | 000,159,744 | ---- | C] () -- C:\Windows\System32\EPSPTDV.DLL
[1996/04/03 19:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
[1995/10/21 09:37:52 | 000,035,328 | ---- | C] () -- C:\Windows\System32\INETWH32.DLL
[1995/10/21 09:37:52 | 000,035,328 | ---- | C] () -- C:\Windows\INETWH32.DLL

< End of report >



OTL Extras logfile created on: 06/11/2011 20:58:33 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Tendai\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.87 Gb Total Physical Memory | 0.81 Gb Available Physical Memory | 43.22% Memory free
3.99 Gb Paging File | 2.59 Gb Available in Paging File | 64.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 54.42 Gb Total Space | 12.40 Gb Free Space | 22.78% Space Free | Partition Type: NTFS

Computer Name: TENDAI-PC | User Name: Tendai | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{4DFFEC57-734A-4F93-9469-63346808BD15}" = lport=139 | protocol=6 | dir=in | app=system |
"{4EF4ADEE-5156-47ED-B0F5-69C1D889FA6B}" = rport=139 | protocol=6 | dir=out | app=system |
"{68846991-4501-420F-B9C2-A6D6819CE973}" = lport=445 | protocol=6 | dir=in | app=system |
"{6CCEA79D-11A6-425F-B9E4-D832B4DC26DC}" = rport=137 | protocol=17 | dir=out | app=system |
"{7B90C265-3514-4FDA-92E5-29E3B4DB802D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{913FDD4F-C347-49A3-9146-9B6D017D9F4B}" = rport=138 | protocol=17 | dir=out | app=system |
"{96DADB31-57A4-4D02-B443-74C0A1791AA0}" = rport=445 | protocol=6 | dir=out | app=system |
"{BBCBFE07-F887-4698-84F8-9D01A869B4FB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C9440A5D-1977-4CF2-A94B-23ABCD034873}" = lport=137 | protocol=17 | dir=in | app=system |
"{DCE752ED-6E21-44BE-8F6D-BC0C7D5AEAD3}" = lport=138 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1A03A11C-2159-491F-B064-92036ABBB8E9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{1D918305-0303-40E7-92BF-1CD35871B532}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{43284385-F595-4AAE-8C38-A5326717DC3D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{49A33164-6E66-45BE-96C8-2E4967E6FC20}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{60951A90-34E7-487B-8BB4-92D00F333A91}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{665AE219-7D29-4A89-BE82-83FAE3548B24}" = protocol=6 | dir=in | app=c:\program files\veetle\player\veetlenet.exe |
"{727636EC-300E-460F-B94E-7DE226CEDCDA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{78957D6C-38C2-48E8-B08E-CD0789C811C6}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{80D5F8E1-61C7-4947-A24D-792D8A94294B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{83459757-F719-46E8-999D-3164BBDC131A}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{8657477E-E36D-4D0B-8522-582DE485D44B}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{954FCC60-CAF5-4EE5-878F-B5CD0FA89D1F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9630058C-861D-4B5E-A763-5B50A3B9A228}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{9694D5AD-0056-40B0-ABD4-40C9D01D49A5}" = protocol=6 | dir=in | app=c:\program files\veetle\player\veetlenet.exe |
"{C90ED1D7-9068-4100-9180-8220FF21AF34}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{E2E37C46-E97F-426B-97A7-4BFBD5FF1168}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{F9AEB123-1402-4B5B-AE71-7B8C8564CC09}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"TCP Query User{26B1D2C0-715D-41DB-BDCC-09683EAF5939}C:\users\tendai\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\tendai\appdata\local\akamai\netsession_win.exe |
"TCP Query User{3C966334-DCDA-48F9-A136-0CE4117D060E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{4AC01A88-0E24-4731-85F6-826309808EE7}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{7C214A30-37CE-4D76-B210-1DFA02B17700}C:\program files\nero\nero 7\nero home\nerohome.exe" = protocol=6 | dir=in | app=c:\program files\nero\nero 7\nero home\nerohome.exe |
"UDP Query User{49963085-AFBA-44BA-9C44-2358AA6DF603}C:\users\tendai\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\tendai\appdata\local\akamai\netsession_win.exe |
"UDP Query User{74DCE256-EA8D-4EEE-B700-C936F110A340}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{A7931ECE-D7F7-42F6-B274-704C9541590F}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{C1F6F37B-62DD-4F86-9AE5-4BED5B121D43}C:\program files\nero\nero 7\nero home\nerohome.exe" = protocol=17 | dir=in | app=c:\program files\nero\nero 7\nero home\nerohome.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{0F4F4815-76AD-4B26-8763-72F3344041C2}" = TOSHIBA Manuals
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{147DFAD8-34C3-4DE1-9FCA-ACEFDE9EF810}" = Synaptics Gesture Suite featuring SYNAPTICS | Scrybe
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for TOSHIBA
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{26A24AE4-039D-4CA4-87B4-2F83217001FF}" = Java™ 7 Update 1
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2BA8A909-F17C-4AE5-85C1-9107B7A60D26}" = Toshiba TEMPRO
"{2C164906-E68F-462A-9010-70DD022223EF}" = RemoteCapture Task 1.0.2
"{314F6D08-A8B7-11D8-8446-0050BA1D384D}" = EPSON Image Clip Palette
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java™ SE Development Kit 7
"{32A3A4F4-B792-11D6-A78A-00B0D0170010}" = Java™ SE Development Kit 7 Update 1
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{44FEBA8C-2C89-E2A9-1423-AE5E5A42F472}" = ATI Catalyst Control Center Ex
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = EPSON Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{82AF3E91-57E1-4754-84D0-40A46E2479AB}" = OpenOffice.org 3.3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{847CAE64-4CD2-4B2D-AF00-978FF5431033}" = Nero 7 Premium
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{94FA9FA6-5294-494D-A8F1-1E654CBB5736}" = Epson Easy Photo Print 2
"{9518F764-C54D-47B2-9E73-154B21E79FD2}" = RAW Image Task 1.0
"{98708E86-46E1-479D-B897-9802E591E762}" = TOSHIBA Volume Indicator
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1" = Free YouTube Downloader 3.3.113
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype 5.5
"{AD13BFB0-FDD2-4AFA-A8AF-9F4A950D56B7}" = ArcSoft Camera Suite 1.3
"{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B90450DF-E781-46FD-B1F1-0C86DA40E443}" = PIF DESIGNER
"{B9B9863A-32FD-4133-ADB7-46244ED77694}" = Camera Support Core Library
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{BE998F99-4CEB-4E64-B717-493A2E9797F4}" = TOSHIBA Supervisor Password
"{BEF56F2D-56ED-4176-BF72-7B68D4A3B98D}" = Canon PhotoRecord
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D02F30FB-0BC4-419A-9B9C-ADC610029B50}" = EPSON File Manager
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EB0B41B1-E84F-483C-91FF-BB83019EE127}" = TOSHIBA Hardware Setup
"{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}" = PhotoStitch
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F19D07BC-6240-49D3-BA5C-59B015DF8916}" = EPSON Easy Photo Print
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"7-Zip" = 7-Zip 9.20
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = TOSHIBA Software Modem
"Akamai" = Akamai NetSession Interface Service
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"CCleaner" = CCleaner
"EOS Video Snapshot Task" = Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ESPRX640 User's Guide" = ESPRX640 User's Guide
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Foxit Reader_is1" = Foxit Reader 5.0
"GUI for dvdauthor" = GUI for dvdauthor 1.07
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for TOSHIBA
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{2C164906-E68F-462A-9010-70DD022223EF}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{9518F764-C54D-47B2-9E73-154B21E79FD2}" = Canon RAW Image Task for ZoomBrowser EX
"InstallShield_{98708E86-46E1-479D-B897-9802E591E762}" = TOSHIBA Volume Indicator
"InstallShield_{B9B9863A-32FD-4133-ADB7-46244ED77694}" = Canon Camera Support Core Library
"InstallShield_{BE998F99-4CEB-4E64-B717-493A2E9797F4}" = TOSHIBA Supervisor Password
"InstallShield_{EB0B41B1-E84F-483C-91FF-BB83019EE127}" = TOSHIBA Hardware Setup
"InstallShield_{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"JDownloader" = JDownloader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
"MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
"OpenDNS Updater" = OpenDNS Updater 2.2.1
"Secunia PSI" = Secunia PSI (2.0.0.3003)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Veetle TV" = Veetle TV
"vShare.tv plugin" = vShare.tv plugin 1.3
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
"ZTE_1.2059.0.8" = ZTE_1.2059.0.8

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 31/10/2011 09:42:22 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32069313

Error - 31/10/2011 09:42:25 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 31/10/2011 09:42:25 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 32072563

Error - 31/10/2011 09:42:25 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32072563

Error - 31/10/2011 09:42:27 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 31/10/2011 09:42:27 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 32074563

Error - 31/10/2011 09:42:27 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32074563

Error - 31/10/2011 09:42:30 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 31/10/2011 09:42:30 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 32077375

Error - 31/10/2011 09:42:30 | Computer Name = Tendai-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32077375

[ System Events ]
Error - 04/11/2011 06:33:20 | Computer Name = Tendai-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 05/11/2011 14:43:18 | Computer Name = Tendai-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0016E3B39510. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 05/11/2011 15:43:59 | Computer Name = Tendai-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 06/11/2011 07:28:10 | Computer Name = Tendai-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0016E3B39510. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 06/11/2011 14:06:45 | Computer Name = Tendai-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0016E3B39510. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 06/11/2011 14:06:45 | Computer Name = Tendai-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 06/11/2011 14:46:37 | Computer Name = Tendai-PC | Source = DCOM | ID = 10010
Description =

Error - 06/11/2011 14:48:52 | Computer Name = Tendai-PC | Source = R300 | ID = 43015
Description = I2c return failed

Error - 06/11/2011 14:48:52 | Computer Name = Tendai-PC | Source = R300 | ID = 43015
Description = I2c return failed

Error - 06/11/2011 16:12:46 | Computer Name = Tendai-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0016E3B39510. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.


< End of report >

#15 Casey_boy

Casey_boy

    Bleeping physicist


  • Malware Response Team
  • 7,765 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:09:43 AM

Posted 07 November 2011 - 09:13 AM

There doesn't appear to be much wrong there <_< We'll try this one fix and if you don't notice any improvement, I think we should try a system restore, give it a scan and then see how it's running.

We need to run an OTL Fix
  • Please reopen Posted Image on your desktop.
  • Copy and Paste the following code into the Posted Image textbox.
    :OTL
    [2011/10/21 01:17:54 | 000,000,000 | ---D | C] -- C:\Users\Tendai\AppData\Local\Rswsw
    
    :commands
    [CREATERESTOREPOINT]
    
  • Push Posted Image
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click Posted Image.
  • A report will open. Copy and Paste that report in your next reply.

Casey

If I have been helping you and I do not reply within 48hours, feel free to send me a PM.


* My Website * Am I Infected? * Malware Removal Help * If you'd like to say thanks *





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users